Quick overview
Crypto money laundering is a large and growing problem, and an unusually visible one. The sums involved run high, and every credible estimate of them is treated as a lower bound, because an address is only counted as illicit once it has been identified. Yet unlike cash, every transfer is recorded on a public ledger that never forgets. That tension, between money that moves in seconds across borders and a record that is permanent and open, is what defines the field. This guide explains how criminals launder crypto, the stages and methods they use, the red flags that give them away, and how blockchain analytics traces the funds back.
What is crypto money laundering?
Laundering is not the crime itself, it is what comes after. The predicate offence, a scam, a ransomware payment, a darknet sale, a theft, generates funds that are traceable to that act. Laundering is the work of separating the money from its source so it can be spent or banked without raising questions. It is worth keeping this distinct from crypto theft and fraud, which are how the funds are obtained, and from sanctions evasion, which is a related but separate compliance concern.
Crypto is attractive to launderers for reasons that are easy to state: transfers settle in minutes, they cross borders without a correspondent bank, and an address is not a name. But those same properties cut the other way. The ledger is public and permanent, addresses can be clustered and labelled, and the moment illicit funds touch a regulated exchange to become spendable, they meet Know Your Customer checks. Laundering crypto is therefore less about hiding money and more about buying distance from its origin, which is exactly what on-chain analysis is built to measure.
Crypto versus traditional money laundering
The comparison matters because it explains where the risk actually sits. In the cash world, the hard part for an investigator is obtaining usable records at all. On-chain, the records already exist and are permanent, so the difficulty shifts to interpretation: clustering addresses, labelling actors, and following funds through deliberate obfuscation. A launderer gains speed and reach but loses deniability, because the ledger keeps a copy of every move.
Traditional versus crypto money laundering
How the threat is shifting
The first shift changes what a team must screen for. As sanctioned and state-linked entities account for more of the illicit flow, a growing proportion of laundering carries strict-liability sanctions risk rather than ordinary AML risk. A programme calibrated only for classic laundering typologies, and not for sanctions exposure, is calibrated for last year's threat.
The second is a measurement reality with an operational consequence. Illicit-volume figures are lower bounds by construction, they count only the addresses identified so far, and they are routinely revised upward as attribution improves, sometimes substantially, for years already closed. The implication is not to chase a headline number but to assume under-counting: exposure that looks marginal today can be reclassified as clearly illicit once an address is labelled, which is an argument for continuous re-screening rather than a one-time check.
The three stages of money laundering
The three-stage model predates crypto, but it maps onto the blockchain cleanly, and knowing which stage a flow is in tells an investigator what to look for.
The three stages, on-chain. Placement gets illicit funds into the system, layering buys distance from their origin, and integration returns them as clean-looking value. Layering is where crypto-specific obfuscation concentrates.
Placement is the entry point. Proceeds from a scam or a hack are moved from where they were obtained into an account or wallet the launderer controls, often a deposit at an exchange or an over-the-counter desk. In crypto this step is sometimes skipped, because the funds are already on-chain the moment the crime occurs.
Layering is where the real work happens, and where crypto offers a toolkit cash never did. The launderer runs the funds through mixers, hops them across blockchains using bridges, splits them across dozens or hundreds of wallets, and cycles them through decentralised exchanges, each step adding distance and noise between the money and its source.
Integration is the exit. The layered funds are converted back into usable value, cashed out to a bank through an exchange, spent on goods, or moved into assets, at which point they look like the proceeds of ordinary activity. Integration is usually where laundered crypto meets a regulated institution again, and so where a compliance control has its clearest shot.
One feature of crypto shifts the emphasis. In traditional laundering, placement is the riskiest step, because getting large amounts of cash into the banking system is hard. In crypto, the proceeds of many crimes are born on-chain, so placement is often trivial or skipped, and the launderer's effort concentrates in layering. That is why on-chain investigation focuses there: it is where the obfuscation lives, and where tracing does the most work.
How do criminals launder crypto? Methods and typologies
The methods below are the common typologies a compliance team encounters. They are rarely used alone, a serious laundering operation chains several together, which is what the layering stage looks like in practice.
Layering, and the trace that undoes it. Each hop, mixer, bridge, and wallet split, is meant to add distance. Indirect exposure tracing reconnects the path across every hop, which is what turns a clean-looking deposit into a flagged one.
Common crypto laundering methods and how each is detected
A few of these deserve a closer look. Mixers, also called tumblers, are the signature crypto laundering tool: they pool funds from many users and pay out coins of equal value from the shared pool, severing the direct on-chain link. Cross-chain bridges pursue the same goal by moving value onto a different blockchain, betting that tracing stops at the chain boundary. Peel chains take the opposite tack, shedding small amounts through a long sequence of hops so no single transaction looks significant. None of these breaks the trail permanently, they raise the cost of following it, which is a different thing.
Two further routes round out the picture. Privacy coins use protocols that conceal amounts and counterparties on their own chains, though the points where value enters from or exits to a transparent chain stay visible. And peer-to-peer trades and services with weak Know Your Customer controls let funds change hands with little friction, which is why exposure to unregulated or nested exchanges is treated as a risk signal in its own right.
A worked pattern
Consider a typical laundering chain after an exchange hack. The attacker splits the stolen funds across fresh wallets, runs them through a mixer, bridges the mixed output to a second blockchain, shreds it through a peel chain of many small transfers, and cashes out via a nested exchange with weak checks. Every step is designed to add distance, and every step is a labelled, traceable event that clustering and cross-chain tracing can reconnect.
Where laundered crypto comes from
Understanding the source matters because it changes the nature of the risk, not just its level. Funds traced to ransomware or a darknet market are a serious AML finding; funds traced to a sanctioned address are a potential violation regardless of intent, and carry strict liability. A compliance programme that only asks whether funds are risky, without asking where the risk comes from, misses that distinction, and with it the difference between a case to monitor and a case to escalate at once.
The practical implication is that source attribution, tracing a flow back to a labelled origin, is not an academic exercise. It is what tells a compliance team whether it is looking at an elevated-risk counterparty to keep monitoring or a sanctioned exposure to escalate at once.
Red flags of crypto money laundering
A transaction monitoring programme watches for indicators like these, weighs them together, and scores the risk rather than reacting to any single one.
- Direct or indirect exposure to a mixer, tumbler, or sanctioned address
- Funds tracing back to darknet markets, ransomware, or known theft
- Rapid movement through a long chain of newly created wallets
- Chain-hopping across bridges with no apparent economic purpose
- Structuring, splitting a sum into many small transfers below a threshold
- A long-dormant wallet suddenly moving significant value
- Cash-out through nested, unregulated, or high-risk exchanges
How is crypto money laundering detected and traced?
The launderer's whole strategy is distance, so the analyst's whole job is to reconnect it. The public ledger makes that possible in a way the cash economy never allowed, but it takes more than reading a single transaction. The three capabilities that matter are clustering, labelling, and multi-hop tracing.
Indirect exposure is the whole game. A wallet can screen clean against its direct counterparty and still be funded, a few hops back, by a sanctioned or illicit source. Multi-hop tracing is what surfaces that hidden link.
Clustering groups the many addresses a single actor controls into one entity, using heuristics such as common-input ownership and change-address detection, so an investigator reasons about a party rather than a scatter of wallets. Labelling attaches identity and risk to known actors, exchanges, mixers, sanctioned entities, darknet markets, so exposure to them can be measured. Multi-hop tracing, the detection of indirect exposure, follows funds across intermediaries and across chains to find risk that a direct-counterparty check would never see.
Detection happens at two moments, and a mature programme does both. Retrospective investigation traces a suspicious flow after the fact, reconstructing the path for a report or a law-enforcement referral. Real-time monitoring scores transactions as they happen, so a risky deposit is flagged before a payout clears rather than discovered afterward. The same clustering and labelling feeds both, but real-time monitoring is what actually stops laundered funds being cashed out, which is the outcome a regulator cares about.
How exposure is weighed matters as much as whether it is found. Not all indirect exposure is equal: funds one hop from a sanctioned address are a different risk from funds five hops away through high-volume intermediaries, where the illicit share may be negligible. A defensible methodology weights exposure by proximity and by the proportion of a wallet's funds that trace to a risky source, rather than treating any historical contact as disqualifying. That is what keeps a monitoring programme from drowning in exposure that is technically present but practically immaterial, the crypto equivalent of a false positive.
Those signals are combined into a risk score. Scorechain scores risk on a scale of 0 to 100, where a lower score means higher risk, across 47 risk categories, drawing on a base of more than 939,000 labelled on-chain entities. A transaction that breaches the firm's risk appetite is surfaced as an alert, and a human analyst decides what to do with it. This is the same machinery covered in our guide to AI in crypto compliance, applied to the specific problem of laundering. You can see it in Scorechain's transaction monitoring and sanctions screening.
From detection to a filed report
What turns a risk score into a defensible outcome is the workflow around it. An analyst reviewing an alert needs the evidence assembled, the exposure path, the entities involved, and the proportion of funds implicated, so the disposition can be justified later. Clearing, continued monitoring, and escalation are all legitimate outcomes, and the record of why one was chosen is as important as the choice itself.
Where the funds are reportable, the team files a suspicious activity report (SAR) or suspicious transaction report (STR) with its financial intelligence unit and preserves the supporting analysis. Two obligations sit alongside this. The Travel Rule requires originator and beneficiary information to accompany transfers above the FATF threshold of USD or EUR 1,000, and record-keeping rules require the audit trail to be retained. A programme that detects laundering but cannot evidence what it did about it has met only half of its obligation.
The rules against crypto money laundering
For crypto-asset service providers (CASPs) in the European Union, the anti-money laundering obligation is now explicit. The Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114, has applied in full since December 30, 2024, and the EU anti-money laundering package tightens the regime further: the Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, applies from July 10, 2027, supervised by the new Anti-Money Laundering Authority (AMLA) in Frankfurt. Globally, FATF Recommendation 15 brings virtual assets into the perimeter, and its Travel Rule requires identifying information to accompany transfers. See the FATF guidance on virtual assets and, in the United States, the Financial Crimes Enforcement Network (FinCEN) reporting rules.
Two obligations deserve emphasis. The Travel Rule, FATF Recommendation 16, requires identifying information on the originator and beneficiary to travel with a transfer, which is what lets one regulated institution pass risk context to the next. And sanctions screening sits alongside AML: the US Office of Foreign Assets Control (OFAC) enforces sanctions on a strict-liability basis, so exposure to a sanctioned address is a violation whether or not the firm knew. In the United Kingdom, the Financial Conduct Authority (FCA) registers and supervises cryptoasset firms under the money laundering regulations. The through-line is the same everywhere: a firm must detect the exposure and evidence what it did about it.
Beyond the EU, UK, and US, the same FATF baseline is implemented by a national regulator in every major market, and a firm operating across borders answers to each. In Asia-Pacific, Singapore supervises providers through the Monetary Authority of Singapore (MAS) under the Payment Services Act, Hong Kong licenses virtual asset trading platforms through the Securities and Futures Commission (SFC), and Australia registers digital-currency exchanges with AUSTRAC. In the Middle East, Dubai regulates virtual assets through the Virtual Assets Regulatory Authority (VARA). In the Americas, Canada requires crypto firms to register as money services businesses with FINTRAC, and in Latin America, Brazil supervises the sector through its central bank, Banco Central do Brasil. The regimes differ in detail, but the obligation to detect, prevent, and report laundering is common to all of them.
Why it matters for firms
A virtual asset service provider that fails to detect laundering does not just face reputational damage, it faces regulatory penalties and, where sanctions exposure is involved, strict liability. Effective transaction monitoring is a legal obligation, not a nice-to-have.
How Scorechain detects money laundering on-chain
Scorechain is a blockchain analytics and crypto AML compliance platform, headquartered in Luxembourg, serving more than 350 clients across over 45 countries. Its Digital Asset Intelligence is built for exactly the problem this guide describes: following value through the layering stage, across wallets and across chains, to the point where laundered funds try to re-enter the regulated system.
The platform clusters addresses into entities, labels known illicit and regulated actors from a base of more than 939,000 entities, and traces indirect exposure across 23 blockchains and more than 470 stablecoins. It scores risk on a transparent, configurable 0 to 100 scale, where a lower score means higher risk, across 47 risk categories, so a compliance team can tune detection to its own risk appetite and explain every decision to a supervisor. Being European-native and MiCA-ready, it frames detection around the rules its clients answer to first. You can explore the approach in Scorechain AI and the wider crypto compliance resources.
The risk methodology is transparent rather than a black box. A compliance analyst can see why a wallet scored as it did, which hop introduced the exposure, and which entity sits at the end of the trail. That is what makes a finding defensible in front of a supervisor and usable as the basis for a suspicious activity report.
Frequently asked questions
What is crypto money laundering?
Crypto money laundering is the process of moving cryptocurrency obtained from crime through a series of transactions to disguise its origin and make it look legitimate. It follows the same three stages as traditional laundering, placement, layering, and integration, using on-chain tools such as mixers, bridges, and exchanges.
What are the three stages of money laundering?
Placement, where illicit funds enter the financial system; layering, where they are moved through many transactions to obscure their origin; and integration, where the distanced funds re-enter the economy as apparently clean assets. In crypto, layering is where most of the on-chain complexity sits.
How do criminals launder cryptocurrency?
Mainly through layering: running funds through mixers and tumblers, hopping them across blockchains with bridges, splitting them across many wallets in peel chains, using privacy coins, and cashing out through nested or unregulated exchanges. Serious operations chain several of these methods together to add distance from the source.
Can crypto money laundering be traced?
Yes. Because the blockchain is public and permanent, analytics can cluster an actor's addresses, label known illicit and regulated entities, and trace funds across multiple hops and chains to measure indirect exposure. That reconnects the trail the layering stage tries to break, and surfaces risk a direct-counterparty check would miss.
Is crypto money laundering illegal?
Yes, everywhere. Money laundering is a criminal offence, and virtual assets are in scope of FATF standards, the EU's MiCA and anti-money laundering package, and national regimes such as the US Bank Secrecy Act. Crypto-asset service providers are legally required to detect, prevent, and report it.




