Join our Newsletter — 33% off our NHI Course

Travel rule expansion for crypto transfers: where do controls fail?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: South Korea’s FIU wants FATF travel rule requirements extended to smaller crypto transfers after identifying smurfing tactics that split transactions to avoid identity checks and reporting thresholds, according to SumSub. The policy gap shows why threshold-based AML controls can be bypassed by transaction fragmentation and cross-border routing.

Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “South Korea Seeks Tighter Travel Rule Requirements for Crypto Transfers”.

Key questions

Q: What breaks when Travel Rule controls rely on a fixed transfer threshold?

A: Fixed thresholds break when attackers split value into smaller transfers that never trigger identity collection or reporting.

Q: Why do small crypto transfers still matter for AML and identity checks?

A: Small transfers matter because criminals can distribute larger illicit flows across many sub-threshold transactions to avoid scrutiny.

Q: How should organisations detect smurfing in crypto transactions?

A: They should monitor repeated low-value transfers across the same wallets, counterparties, IP ranges, or time windows, rather than relying only on single-transaction thresholds.

Practitioner guidance

  • Monitor for fragmentation patterns Flag repeated sub-threshold transfers from the same wallet, customer, or counterparty cluster across short time windows and related destinations.
  • Extend controls to both transfer endpoints Require sender and recipient data exchange wherever the Travel Rule applies, including internal policy for receiving-side verification and case handling.
  • Add jurisdiction and provider risk scoring Weight offshore, unregistered, or weakly supervised counterparties more heavily in monitoring and escalation workflows.

Bottom line: Crypto AML controls that depend on a fixed reporting threshold can be bypassed by splitting transfers into smaller amounts.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 16 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Threshold-based AML controls create a smurfing window: When identity checks begin only after a transfer exceeds a fixed value, transaction sizing becomes an evasion tactic. The control is technically correct but structurally incomplete because the attacker can stay under the line indefinitely. Practitioners should treat the threshold itself as part of the attack surface, not just the reporting rule.

A question worth separating out:

Q: What happens when offshore crypto platforms sit outside Travel Rule oversight?

A: When offshore platforms are weakly supervised or unregistered, the transfer chain loses continuity. That makes attribution, case building, and information sharing harder even if one jurisdiction has strong controls. The result is regulatory arbitrage, where criminals move activity to the least constrained part of the network.

👉 Read our full editorial: South Korea’s travel rule push exposes smurfing gaps in crypto AML


This post was modified 16 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.