Crypto exchanges should combine identity verification, liveness checks, non-document verification, and database validation to detect synthetic identities and replayed faces before accounts are activated. The goal is not to rely on a single signal but to layer controls that challenge impersonation at multiple points in the onboarding flow. That approach lowers fraud exposure while preserving a smoother customer experience.
Why This Matters for Security Teams
Deepfake-based onboarding fraud is not just a customer verification problem. For crypto exchanges, it is an account integrity issue that can lead to mule accounts, sanctioned activity, stolen funds, and difficult remediation after funds move on-chain. A single compromised onboarding step can defeat downstream controls if the identity presented to the platform is synthetic but appears consistent across checks. Current guidance from NIST Cybersecurity Framework 2.0 and FATF-aligned AML programs points toward layered verification, not single-point trust.
NHIMG research shows how fragile identity assumptions become when credentials, accounts, or identities are accepted without strong validation. The Ultimate Guide to NHIs notes that 68% of organisations do not know how to fully address identity risk, which is a useful warning for onboarding design: weak identity controls tend to compound. In practice, many security teams encounter fraud only after an account has already been funded or used for abuse, rather than through intentional prevention at the verification layer.
How It Works in Practice
Crypto exchanges reduce deepfake risk by treating onboarding as a decisioning workflow, not a single identity check. The first layer should confirm that the applicant is a real, live person. Liveness checks should be resistant to replayed video, injected media, and scripted prompts. The second layer should validate the identity document or equivalent credential against trusted data sources, then compare it with non-document signals such as phone tenure, email reputation, device consistency, and address history where permitted.
That approach aligns with the broader principle in NIST SP 800-53 Rev. 5 Security and Privacy Controls: verification should be risk-based and support trustworthy authorization decisions. For exchanges, the practical test is whether the onboarding flow can distinguish a legitimate user from a synthetic identity assembled to pass a single provider’s checks. The 52 NHI Breaches Analysis is a reminder that adversaries repeatedly exploit control gaps once a trust boundary is crossed.
- Use step-up verification when risk signals increase, such as proxy use, device mismatch, or repeated retries.
- Correlate identity proofing results with fraud telemetry before activating trading or withdrawal privileges.
- Separate onboarding approval from account activation so suspicious cases can be queued for review.
- Log all verification outcomes for model tuning, analyst review, and dispute handling.
These controls tend to break down when the exchange relies on a single vendor score or when onboarding must complete instantly for high-volume markets because fraudsters adapt faster than static thresholds do.
Common Variations and Edge Cases
Tighter onboarding often increases friction and review workload, requiring exchanges to balance fraud reduction against conversion rates and customer support cost. That tradeoff is real, especially for legitimate users in low-data or high-privacy environments. Best practice is evolving, but current guidance suggests that high-risk geographies, VPN-heavy traffic, and fast-repeat signups deserve stronger step-up controls than routine retail onboarding.
There is no universal standard for deepfake screening yet, so teams should combine vendor signals with internal policy and manual escalation paths rather than assume one model is sufficient. Some applicants may fail document checks because their identity documents are limited, expired, or issued in regions with weaker data coverage. In those cases, exchanges should use additional non-document verification and manual review instead of auto-rejecting every exception.
For broader risk governance, Top 10 NHI Issues is a useful reminder that overtrusting static identity artifacts creates systemic exposure. Exchanges that map onboarding thresholds to AML/KYC requirements, including the FATF Recommendations, are better positioned to distinguish legitimate customer friction from unresolved fraud risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Deepfake onboarding is an identity validation failure that relies on weak trust signals. |
| OWASP Agentic AI Top 10 | A1 | Fraudsters use autonomous tooling to automate synthetic identity abuse at onboarding. |
| CSA MAESTRO | ID-01 | MAESTRO addresses identity assurance and abuse resistance in AI-enabled workflows. |
| NIST AI RMF | AI RMF applies to risk governance for biometric and model-assisted identity decisions. | |
| NIST CSF 2.0 | PR.AA | Identity proofing and access authorization are central to account onboarding controls. |
Require stronger identity proofing and remove single-signal trust from account activation decisions.
Related resources from NHI Mgmt Group
- How should crypto exchanges reduce account takeover and fraud risk at scale?
- How should crypto platforms reduce fraud risk when onboarding volumes spike during major market events?
- How should security teams reduce identity-based breach risk?
- How should organisations reduce the risk of identity-based attacks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org