Centralized exchanges remain attractive because they provide a practical path from crypto into fiat, which is the end goal of laundering. They also concentrate activity into a limited number of services and deposit addresses, creating scale for criminals. At the same time, exchanges can freeze suspicious funds, so they are a high-value target for both laundering attempts and compliance enforcement.
Why This Matters for Security Teams
Centralized exchanges sit at the intersection of liquidity, compliance, and conversion, which makes them structurally useful for laundering. They aggregate enormous transaction volume, provide a familiar path from crypto into fiat, and create a choke point where investigators, analysts, and law enforcement can correlate activity. That same concentration also makes exchanges a place where laundering attempts, account abuse, and compliance controls collide.
For security teams, the practical issue is not just whether illicit funds pass through, but whether the exchange can still distinguish routine customer movement from layering, structuring, rapid hop patterns, or account takeover activity. This is why strong customer due diligence and transaction monitoring matter as much as custody controls. The FATF Recommendations on AML and KYC expectations are the clearest baseline for that control model, because they tie virtual asset oversight to screening, ownership transparency, and suspicious activity reporting.
In practice, many security and compliance teams discover the abuse pattern only after funds have already been fragmented across multiple accounts or jurisdictions.
How It Works in Practice
The laundering value of a centralized exchange comes from utility, not stealth alone. Criminals need somewhere to realize value, and exchanges offer deep order books, fast conversion, and access to regulated rails. That makes them useful at several stages of a laundering chain: initial placement, rapid conversion between assets, layering through multiple deposits and withdrawals, and eventual cash-out. The exchange does not have to be the only venue in the chain, but it is often the most practical endpoint because it bridges crypto and the traditional financial system.
From a control perspective, the exchange becomes a concentration point for identity, transaction, and device signals. Good programs look for inconsistent account behavior, deposit patterns that do not match customer profile, repeated use of newly created wallets, rapid asset swaps, and attempts to evade velocity checks. They also watch for signs that an account is being used as a transit point rather than a normal trading account. The security challenge is that the same infrastructure that supports legitimate high-volume users also supports fast-moving abuse.
- Customer onboarding should reduce anonymous access and establish a defensible ownership baseline.
- Monitoring should correlate wallet origin, behavioral anomalies, and withdrawal destinations, not just single transactions.
- Escalation should be triggered by pattern changes, not only by a single large transfer.
- Freezing logic should be fast enough to preserve funds without overblocking ordinary trading activity.
FATF guidance is useful here because it frames exchanges as obliged entities with concrete expectations around CDD, beneficial ownership, sanctions screening, and suspicious transaction reporting. These controls tend to break down when exchanges scale faster than their monitoring, especially in cross-border environments where fiat off-ramps, wallet clustering, and customer verification standards do not align.
Common Variations and Edge Cases
Tighter exchange controls often increase friction, manual review, and customer drop-off, so organisations have to balance laundering resistance against usability and market competitiveness. That trade-off becomes sharper when the exchange serves both retail users and institutional clients, because the same control thresholds will not fit both populations well.
Some laundering activity bypasses large exchanges entirely and uses OTC brokers, DeFi protocols, peer-to-peer markets, or cross-chain swaps for part of the chain. Even then, centralized exchanges often reappear at the endpoint because regulated cash-out remains the hardest step to replace. There is no universal standard for exactly where monitoring should stop, but a strong rule is to follow the funds until the conversion risk drops materially, not until the first suspicious hop is seen.
High-liquidity exchanges also face a second edge case: legitimate bursty activity can look laundering-like. That is why volume alone is a weak signal. The better discriminator is whether the activity is coherent with the customer’s known profile, funding source, and withdrawal behavior over time.
Risk and Threat Considerations
Centralized exchanges are attractive because they compress many laundering opportunities into a single control plane: custody, identity verification, transaction surveillance, and fiat conversion. That concentration creates both exposure and adversarial value, because a compromised or weakly monitored exchange can absorb illicit flow at scale and help move it into regulated money rails.
Failure mechanism: Laundering succeeds when fragmented deposits, rapid asset conversion, layered transfers, and account abuse outrun monitoring thresholds or review capacity. Attackers and criminal operators exploit the gap between transaction volume and human scrutiny, then use the exchange’s own liquidity and off-ramp access to finish the conversion.
Impact: Funds become harder to trace, compliance obligations become reactive instead of preventive, and the exchange can be forced into freezes, investigations, or de-risking decisions that affect legitimate customers as well as suspicious ones.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Exchange laundering risk depends on regulated money movement and customer trust. |
| DE.CM-01 — Continuous Monitoring | Monitoring transaction and account behavior is central to spotting laundering patterns. | |
| Recommendation — Define exchange laundering exposure as a core business risk and align controls to the money-flow context. Monitor deposits, swaps, and withdrawals continuously for anomalous laundering indicators. | ||
| CIS Controls v8 | 8 — Audit Log Management | Exchange surveillance relies on retaining transaction and account evidence for investigation. |
| 6 — Access Control Management | Account abuse and compromised exchange access often enable laundering at scale. | |
| Recommendation — Log and retain exchange activity needed to investigate suspicious conversion and cash-out paths. Restrict and review access paths that could be abused to move funds or override controls. | ||
| NIST SP 800-63 | AAL2 — Authenticator Assurance Level 2 | Exchange onboarding and account access need stronger identity assurance for higher-risk flows. |
| IAL2 — Identity Assurance Level 2 | KYC-style identity confidence is central to exchange customer risk decisions. | |
| Recommendation — Use stronger authentication assurance for accounts that can move or cash out significant value. Verify customer identity to a level that supports risk-based review of high-value activity. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Compromised exchange accounts can be used to move or obscure illicit funds. |
| T1110 — Brute Force | Account compromise can provide the access path used to launder through exchanges. | |
| Recommendation — Hunt for abuse of valid accounts that can disguise laundering as normal customer activity. Detect credential attacks that may precede exchange account takeover and fund movement. | ||
Practitioner Guidance
What to prioritise: Treat the fiat off-ramp, customer verification, and withdrawal monitoring as one control chain. If those three layers are not linked, laundering detection becomes fragmented and criminals will route around the weakest handoff.
What to verify: Confirm that transaction monitoring can connect deposits, swaps, and withdrawals across accounts, wallets, and time windows. If the tooling only scores individual events, it will miss the layered patterns that make exchange-based laundering effective.
Practitioner takeaway: The main objective is not to block every suspicious transaction, but to make the exchange unable to serve as a reliable conversion endpoint for illicit value without leaving a reviewable trail.