Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do centralized exchanges remain such a common…
Identity Beyond IAM

Why do centralized exchanges remain such a common endpoint for crypto money laundering?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Identity Beyond IAM

Centralized exchanges remain attractive because they provide a practical path from crypto into fiat, which is the end goal of laundering. They also concentrate activity into a limited number of services and deposit addresses, creating scale for criminals. At the same time, exchanges can freeze suspicious funds, so they are a high-value target for both laundering attempts and compliance enforcement.

Why This Matters for Security Teams

Centralized exchanges sit at the intersection of liquidity, compliance, and conversion, which makes them structurally useful for laundering. They aggregate enormous transaction volume, provide a familiar path from crypto into fiat, and create a choke point where investigators, analysts, and law enforcement can correlate activity. That same concentration also makes exchanges a place where laundering attempts, account abuse, and compliance controls collide.

For security teams, the practical issue is not just whether illicit funds pass through, but whether the exchange can still distinguish routine customer movement from layering, structuring, rapid hop patterns, or account takeover activity. This is why strong customer due diligence and transaction monitoring matter as much as custody controls. The FATF Recommendations on AML and KYC expectations are the clearest baseline for that control model, because they tie virtual asset oversight to screening, ownership transparency, and suspicious activity reporting.

In practice, many security and compliance teams discover the abuse pattern only after funds have already been fragmented across multiple accounts or jurisdictions.

How It Works in Practice

The laundering value of a centralized exchange comes from utility, not stealth alone. Criminals need somewhere to realize value, and exchanges offer deep order books, fast conversion, and access to regulated rails. That makes them useful at several stages of a laundering chain: initial placement, rapid conversion between assets, layering through multiple deposits and withdrawals, and eventual cash-out. The exchange does not have to be the only venue in the chain, but it is often the most practical endpoint because it bridges crypto and the traditional financial system.

From a control perspective, the exchange becomes a concentration point for identity, transaction, and device signals. Good programs look for inconsistent account behavior, deposit patterns that do not match customer profile, repeated use of newly created wallets, rapid asset swaps, and attempts to evade velocity checks. They also watch for signs that an account is being used as a transit point rather than a normal trading account. The security challenge is that the same infrastructure that supports legitimate high-volume users also supports fast-moving abuse.

  • Customer onboarding should reduce anonymous access and establish a defensible ownership baseline.
  • Monitoring should correlate wallet origin, behavioral anomalies, and withdrawal destinations, not just single transactions.
  • Escalation should be triggered by pattern changes, not only by a single large transfer.
  • Freezing logic should be fast enough to preserve funds without overblocking ordinary trading activity.

FATF guidance is useful here because it frames exchanges as obliged entities with concrete expectations around CDD, beneficial ownership, sanctions screening, and suspicious transaction reporting. These controls tend to break down when exchanges scale faster than their monitoring, especially in cross-border environments where fiat off-ramps, wallet clustering, and customer verification standards do not align.

Common Variations and Edge Cases

Tighter exchange controls often increase friction, manual review, and customer drop-off, so organisations have to balance laundering resistance against usability and market competitiveness. That trade-off becomes sharper when the exchange serves both retail users and institutional clients, because the same control thresholds will not fit both populations well.

Some laundering activity bypasses large exchanges entirely and uses OTC brokers, DeFi protocols, peer-to-peer markets, or cross-chain swaps for part of the chain. Even then, centralized exchanges often reappear at the endpoint because regulated cash-out remains the hardest step to replace. There is no universal standard for exactly where monitoring should stop, but a strong rule is to follow the funds until the conversion risk drops materially, not until the first suspicious hop is seen.

High-liquidity exchanges also face a second edge case: legitimate bursty activity can look laundering-like. That is why volume alone is a weak signal. The better discriminator is whether the activity is coherent with the customer’s known profile, funding source, and withdrawal behavior over time.

Risk and Threat Considerations

Centralized exchanges are attractive because they compress many laundering opportunities into a single control plane: custody, identity verification, transaction surveillance, and fiat conversion. That concentration creates both exposure and adversarial value, because a compromised or weakly monitored exchange can absorb illicit flow at scale and help move it into regulated money rails.

Failure mechanism: Laundering succeeds when fragmented deposits, rapid asset conversion, layered transfers, and account abuse outrun monitoring thresholds or review capacity. Attackers and criminal operators exploit the gap between transaction volume and human scrutiny, then use the exchange’s own liquidity and off-ramp access to finish the conversion.

Impact: Funds become harder to trace, compliance obligations become reactive instead of preventive, and the exchange can be forced into freezes, investigations, or de-risking decisions that affect legitimate customers as well as suspicious ones.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextExchange laundering risk depends on regulated money movement and customer trust.
DE.CM-01 — Continuous MonitoringMonitoring transaction and account behavior is central to spotting laundering patterns.
Recommendation — Define exchange laundering exposure as a core business risk and align controls to the money-flow context. Monitor deposits, swaps, and withdrawals continuously for anomalous laundering indicators.
CIS Controls v88 — Audit Log ManagementExchange surveillance relies on retaining transaction and account evidence for investigation.
6 — Access Control ManagementAccount abuse and compromised exchange access often enable laundering at scale.
Recommendation — Log and retain exchange activity needed to investigate suspicious conversion and cash-out paths. Restrict and review access paths that could be abused to move funds or override controls.
NIST SP 800-63AAL2 — Authenticator Assurance Level 2Exchange onboarding and account access need stronger identity assurance for higher-risk flows.
IAL2 — Identity Assurance Level 2KYC-style identity confidence is central to exchange customer risk decisions.
Recommendation — Use stronger authentication assurance for accounts that can move or cash out significant value. Verify customer identity to a level that supports risk-based review of high-value activity.
MITRE ATT&CKT1078 — Valid AccountsCompromised exchange accounts can be used to move or obscure illicit funds.
T1110 — Brute ForceAccount compromise can provide the access path used to launder through exchanges.
Recommendation — Hunt for abuse of valid accounts that can disguise laundering as normal customer activity. Detect credential attacks that may precede exchange account takeover and fund movement.

Practitioner Guidance

What to prioritise: Treat the fiat off-ramp, customer verification, and withdrawal monitoring as one control chain. If those three layers are not linked, laundering detection becomes fragmented and criminals will route around the weakest handoff.

What to verify: Confirm that transaction monitoring can connect deposits, swaps, and withdrawals across accounts, wallets, and time windows. If the tooling only scores individual events, it will miss the layered patterns that make exchange-based laundering effective.

Practitioner takeaway: The main objective is not to block every suspicious transaction, but to make the exchange unable to serve as a reliable conversion endpoint for illicit value without leaving a reviewable trail.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org