AML red flags in crypto are warning signs that a transaction or customer may be linked to money laundering or terrorist financing: deposits split into small amounts to stay under reporting thresholds, coins that pass through mixers, a new account that suddenly moves large sums, or funds tied to high-risk jurisdictions. The reference list is the FATF's Virtual Assets Red Flag Indicators report, published on 14 September 2020, which groups them into six categories.
A red flag is not proof of a crime, only a reason to look closer. This guide walks through each FATF category, explains what an exchange does when something is flagged, and answers the question users actually ask: why was my account frozen?
What are AML red flags?
Anti-money-laundering (AML) rules require regulated crypto businesses, which FATF calls virtual asset service providers (VASPs), to watch for suspicious activity and report it. Red flags are the patterns, drawn from real cases submitted by FATF members, that tell an analyst where to look.
The FATF is explicit about how they should be used. In the report's conclusion it says the indicators are "neither exhaustive nor applicable in every situation", and that no single indicator should be viewed in isolation. The FATF handout for VASPs adds that a transaction with multiple indicators and little or no logical business explanation needs further monitoring and, where appropriate, reporting.
The real question is "does this activity make sense for this customer?" That is why red flags sit on top of KYC and customer due diligence: the firm can only judge what is unusual if it knows what is normal for you.
The six FATF red-flag categories
The FATF report organises its indicators into six groups. The examples below are taken from it, lightly paraphrased.
1. Transaction size and frequency
- Structuring: breaking crypto exchanges or transfers into small amounts, or amounts under record-keeping or reporting thresholds, the same technique long used with cash.
- Multiple high-value transactions in short succession, such as within 24 hours, or in a staggered, regular pattern followed by a long period of no activity. FATF notes the latter is particularly common in ransomware cases.
- Transferring coins immediately to multiple VASPs, especially in other jurisdictions with no link to where the customer lives or works, or with weak AML regulation.
- Depositing coins and immediately withdrawing them without trading, or converting them into several other coins for no clear reason. FATF says this "effectively turns the exchange/VASP into an ML mixer".
2. Transaction patterns
- A new user makes a large initial deposit that is inconsistent with their profile.
- A new user funds the whole deposit on day one and trades or withdraws all of it the same day or the next.
- A new user tries to trade the entire balance, or send it all off the platform.
- Transactions involving several virtual assets or accounts with no logical business explanation.
Blockchain analytics firms add their own pattern detection on top, such as "peel chains", where a large balance is moved through a long series of wallets, shaving off a small amount at each hop. For how that tooling works, see blockchain analytics explained.
3. Anonymity
- Using more than one type of crypto asset despite the extra fees, especially anonymity-enhanced cryptocurrencies (privacy coins).
- Moving coins from a transparent public blockchain to a centralised exchange and immediately trading them for a privacy coin.
- Customers acting as an unregistered or unlicensed VASP on peer-to-peer (P2P) platforms, handling large volumes for others and charging high fees.
- Funds sent to or received from mixing or tumbling services, or with direct or indirect exposure to darknet markets, ransomware, questionable gambling sites or reported thefts.
FATF stresses that these features are not always illicit and must be weighed against the customer's profile and any legitimate explanation.
4. Senders and recipients
- At account creation: opening several accounts under different names to get around limits, connecting from IP addresses in sanctioned jurisdictions or previously flagged ones, or repeatedly trying to open accounts from the same IP address.
- During due diligence: incomplete KYC information, refusing to answer questions about source of funds, inaccurate answers about a transaction or counterparty, or forged and edited identity documents.
- Profile mismatches: identifiers or credentials shared with another account, IP addresses that do not match the profile, or a wallet address that appears on forums associated with illegal activity.
- Possible money mules or scam victims: a sender unfamiliar with crypto, a customer much older than the platform's typical user making many transactions, or large purchases not supported by the customer's known wealth.
- Other unusual behaviour: frequently changing email, IP or financial details (which may also indicate account takeover), or message fields that reference illicit goods.
5. Source of funds or wealth
- Transacting with addresses or bank cards connected to fraud, extortion, ransomware, sanctioned addresses or darknet markets.
- Deposits much larger than usual from an unknown source, quickly converted to fiat, which may indicate stolen funds.
- Funds coming directly from mixers or tumblers, or a source of wealth drawn mostly from crypto, ICOs, or platforms without AML controls.
This is where red flags lead into source-of-funds requests. Our guide to source of funds vs source of wealth explains what evidence answers them.
6. Geographical risks
- Funds coming from, or going to, an exchange not registered in the jurisdiction where the customer or the exchange is located.
- Using an exchange or money transfer service in a high-risk jurisdiction with weak or no AML rules for crypto.
- Sending funds to VASPs in jurisdictions with no crypto regulation, or a business relocating to such jurisdictions.
How exchanges detect red flags
Most red flags are caught by software. A typical stack has three layers:
- Onboarding checks: document and selfie verification, sanctions and PEP screening, and device or IP signals that catch duplicate accounts and sanctioned locations.
- Transaction monitoring: rules that look at amounts, velocity and patterns across a customer's history, for example "total deposits over 24 hours" or "withdrawal within an hour of deposit with no trade". See our guide to AML transaction monitoring in crypto.
- Blockchain analytics (KYT): screening the addresses a customer sends to and receives from, and scoring exposure to mixers, darknet markets, sanctioned wallets and stolen funds.
Alerts go into a review queue, where an analyst decides whether the activity has an innocent explanation. iDenfy's transaction monitoring software, for example, combines custom and velocity rules with sanctions, PEP and adverse media screening, and routes alerts through a tiered review workflow that ends in an exportable SAR. For a wider comparison, see the best crypto transaction monitoring software in 2026.
What happens when activity is flagged
If the review does not clear the alert, the firm has a legal duty to report it. The details differ by country:
- European Union. Under Article 33 of the Anti-Money Laundering Directive (EU) 2015/849, obliged entities must promptly report to the national financial intelligence unit (FIU) when they know, suspect or have reasonable grounds to suspect that funds are the proceeds of crime, "regardless of the amount involved". Attempted transactions must be reported too. The new AML Regulation (EU) 2024/1624 restates this in Article 69 and applies from 10 July 2027. Its Article 71 requires firms to hold back a transaction they suspect until they have reported it; they may proceed if the FIU has not instructed otherwise within three working days.
- United States. FinCEN's 2019 guidance confirms that crypto exchangers generally qualify as money transmitters, a type of money services business. Under 31 CFR 1022.320, a money services business must file a suspicious activity report (SAR) for suspicious transactions involving at least USD 2,000, no later than 30 calendar days after first detecting the facts. Structuring to evade federal reporting requirements is itself an offence under 31 U.S.C. 5324.
Firms are also barred from telling you. EU law prohibits disclosing to the customer that a report has been or will be made, or that an analysis is under way (Article 39 of the Directive, Article 73 of the AMLR). In the US, a SAR and any information that would reveal its existence are confidential under 31 CFR 1022.320(d). This "tipping-off" ban is why support agents often give vague answers about a frozen account.
"Why was my account frozen?"
For users, a red flag shows up as a withdrawal on hold, a restricted account or a request for documents. Common innocent triggers:
- A first deposit much larger than the income or occupation you declared at signup.
- Depositing and withdrawing quickly without trading, often while moving coins between platforms.
- Receiving coins from an address that analytics tools link, directly or several hops back, to a mixer, a hacked exchange or a sanctioned entity.
- Sending money for someone else, which looks the same as money-mule activity.
What to do:
- Reply through the exchange's official app or support portal, and answer exactly what is asked.
- Provide the full chain for the funds in question: where the money came from, which exchanges and wallets it passed through, with transaction hashes and statements.
- Do not open a second account to get around the restriction. Creating separate accounts to evade limits is one of FATF's listed red flags.
- Ignore anyone offering to "unfreeze" your account for a fee. That is a common scam; see crypto recovery scams.
Red flags and DeFi
The FATF indicators are written for VASPs, the regulated intermediaries. Non-custodial DeFi protocols have no account to freeze and generally do not run KYC. JewelSwap's DeFi apps are non-custodial and do not run KYC themselves; see KYC in DeFi explained. But any regulated exchange you later send funds to will screen your on-chain history, so the same red flags apply at that point.
Frequently asked questions
What are AML red flags in crypto?
They are warning signs that a crypto transaction or customer may be linked to money laundering or terrorist financing, such as structuring deposits under thresholds, using mixers, moving funds in and out without trading, or activity that does not match the customer's profile.
What are the FATF red flag indicators for virtual assets?
The FATF's September 2020 report groups them into six categories: transaction size and frequency, transaction patterns, anonymity, senders or recipients, source of funds or wealth, and geographical risks.
Does one red flag mean my transaction is illegal?
No. FATF says the indicators are not exhaustive, do not apply in every situation and should not be viewed in isolation. A red flag prompts a closer look, and many alerts are cleared after review.
Will an exchange tell me if it filed a suspicious activity report?
No. EU and US rules prohibit firms from telling customers that a suspicious activity report has been or will be filed, so support teams often cannot explain why an account is under review.
What is structuring in crypto?
Structuring means splitting transactions into smaller amounts to stay below record-keeping or reporting thresholds. FATF lists it as a red flag for crypto, and in the US structuring to evade federal reporting requirements is itself a crime.
What should I do if my crypto account is frozen for AML reasons?
Respond through the exchange's official channels, provide documents showing where the funds came from and how they moved, do not open another account to get around the restriction, and ignore anyone offering to unfreeze it for a fee.
Keep reading
This article is educational and is not legal or financial advice. Red flag indicators are summarised from the FATF report Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing (September 2020) and the FATF handout for VASPs. Legal references are to Directive (EU) 2015/849, Regulation (EU) 2024/1624, 31 CFR 1022.320, 31 U.S.C. 5324 and FinCEN guidance FIN-2019-G001, all checked on 8 October 2026. Other sources are linked inline.