How crypto money laundering works and how it's detected

The blockchain is public, so laundering crypto is a game of breaking the trail faster than an investigator can follow it. Here is how that game is played, and how it is won.
Written by
Scorechain Compliance & Research Team
August 28, 2026
13
min read

Quick overview

Crypto money laundering is a large and growing problem, and an unusually visible one. The sums involved run high, and every credible estimate of them is treated as a lower bound, because an address is only counted as illicit once it has been identified. Yet unlike cash, every transfer is recorded on a public ledger that never forgets. That tension, between money that moves in seconds across borders and a record that is permanent and open, is what defines the field. This guide explains how criminals launder crypto, the stages and methods they use, the red flags that give them away, and how blockchain analytics traces the funds back.

What is crypto money laundering?

Crypto money laundering is the process of moving cryptocurrency gained from crime through a series of transactions to disguise its origin and make it appear legitimate. It follows the same three stages as traditional laundering, placement, layering, and integration, but uses on-chain tools such as mixers, bridges, and exchanges to break the audit trail.

Laundering is not the crime itself, it is what comes after. The predicate offence, a scam, a ransomware payment, a darknet sale, a theft, generates funds that are traceable to that act. Laundering is the work of separating the money from its source so it can be spent or banked without raising questions. It is worth keeping this distinct from crypto theft and fraud, which are how the funds are obtained, and from sanctions evasion, which is a related but separate compliance concern.

Crypto is attractive to launderers for reasons that are easy to state: transfers settle in minutes, they cross borders without a correspondent bank, and an address is not a name. But those same properties cut the other way. The ledger is public and permanent, addresses can be clustered and labelled, and the moment illicit funds touch a regulated exchange to become spendable, they meet Know Your Customer checks. Laundering crypto is therefore less about hiding money and more about buying distance from its origin, which is exactly what on-chain analysis is built to measure.

Crypto versus traditional money laundering

Crypto laundering follows the same three-stage logic as traditional laundering, but the tools differ. Cash laundering hides money in an opaque web of shell companies and cash-heavy businesses; crypto laundering moves value fast across a transparent ledger, trading the secrecy of cash for the speed of code. That transparency is the launderer's problem and the investigator's advantage.

The comparison matters because it explains where the risk actually sits. In the cash world, the hard part for an investigator is obtaining usable records at all. On-chain, the records already exist and are permanent, so the difficulty shifts to interpretation: clustering addresses, labelling actors, and following funds through deliberate obfuscation. A launderer gains speed and reach but loses deniability, because the ledger keeps a copy of every move.

Traditional versus crypto money laundering

Dimension Traditional (cash) Crypto
Record Opaque, often no usable trail Public, permanent ledger
Speed and reach Slow, geographically bound Minutes, borderless
Obfuscation Shell companies, cash businesses Mixers, bridges, wallet splitting
Cash-out point Banks Exchanges with Know Your Customer checks
Investigator's task Obtain the records Interpret and trace the records

How the threat is shifting

Two shifts matter for a compliance programme. Sanctions evasion by state-linked actors is a growing share of illicit crypto activity, which moves a large part of the risk from ordinary money laundering into strict-liability sanctions exposure. And published estimates of illicit volume are lower bounds, revised upward over time, so exposure should be treated as under-counted rather than settled.

The first shift changes what a team must screen for. As sanctioned and state-linked entities account for more of the illicit flow, a growing proportion of laundering carries strict-liability sanctions risk rather than ordinary AML risk. A programme calibrated only for classic laundering typologies, and not for sanctions exposure, is calibrated for last year's threat.

The second is a measurement reality with an operational consequence. Illicit-volume figures are lower bounds by construction, they count only the addresses identified so far, and they are routinely revised upward as attribution improves, sometimes substantially, for years already closed. The implication is not to chase a headline number but to assume under-counting: exposure that looks marginal today can be reclassified as clearly illicit once an address is labelled, which is an argument for continuous re-screening rather than a one-time check.

The three stages of money laundering

Money laundering has three stages: placement, where illicit funds enter the financial system; layering, where they are moved through many transactions to obscure the trail; and integration, where the now-distanced funds re-enter the economy as apparently clean assets. In crypto, layering is where most of the effort and most of the on-chain complexity sits.

The three-stage model predates crypto, but it maps onto the blockchain cleanly, and knowing which stage a flow is in tells an investigator what to look for.

The three stages of crypto money laundering

01 Placement
Funds enter

deposit to exchange,
OTC desk, or wallet

03 Integration
Funds re-enter

cash-out, spending,
apparently clean

The three stages, on-chain. Placement gets illicit funds into the system, layering buys distance from their origin, and integration returns them as clean-looking value. Layering is where crypto-specific obfuscation concentrates.

Placement is the entry point. Proceeds from a scam or a hack are moved from where they were obtained into an account or wallet the launderer controls, often a deposit at an exchange or an over-the-counter desk. In crypto this step is sometimes skipped, because the funds are already on-chain the moment the crime occurs.

Layering is where the real work happens, and where crypto offers a toolkit cash never did. The launderer runs the funds through mixers, hops them across blockchains using bridges, splits them across dozens or hundreds of wallets, and cycles them through decentralised exchanges, each step adding distance and noise between the money and its source.

Integration is the exit. The layered funds are converted back into usable value, cashed out to a bank through an exchange, spent on goods, or moved into assets, at which point they look like the proceeds of ordinary activity. Integration is usually where laundered crypto meets a regulated institution again, and so where a compliance control has its clearest shot.

One feature of crypto shifts the emphasis. In traditional laundering, placement is the riskiest step, because getting large amounts of cash into the banking system is hard. In crypto, the proceeds of many crimes are born on-chain, so placement is often trivial or skipped, and the launderer's effort concentrates in layering. That is why on-chain investigation focuses there: it is where the obfuscation lives, and where tracing does the most work.

How do criminals launder crypto? Methods and typologies

Criminals launder crypto mainly through layering techniques: mixers and tumblers that pool and redistribute funds, cross-chain bridges that hop value between blockchains, peel chains that shed small amounts across many hops, privacy coins, and nested or unregulated exchanges. Each method breaks the trail differently, and each leaves a different signature for analytics to catch.

The methods below are the common typologies a compliance team encounters. They are rarely used alone, a serious laundering operation chains several together, which is what the layering stage looks like in practice.

Illicit source Mixer Bridge chain hop wallet wallet wallet Exchange cash-out multi-hop tracing follows the funds back to source
Illicit source
Mixer
Bridge chain hop
wallet wallet wallet
Exchange cash-out

multi-hop tracing follows the funds back to source

Layering, and the trace that undoes it. Each hop, mixer, bridge, and wallet split, is meant to add distance. Indirect exposure tracing reconnects the path across every hop, which is what turns a clean-looking deposit into a flagged one.

Common crypto laundering methods and how each is detected

Method How it obscures the trail How analytics catches it
Mixers and tumblers Pool many users' funds and redistribute them, cutting the direct link. Mixer addresses are labelled, and exposure to them is itself a risk signal.
Cross-chain bridges Move value to another blockchain to escape single-chain tracing. Cross-chain tracing follows value across bridge contracts.
Peel chains Shed small amounts across a long series of hops. Pattern recognition flags the repetitive peeling structure.
Nested or unregulated exchanges Cash out through services with weak or no KYC. Counterparty and entity labelling exposes the service.
Privacy coins Use protocols that hide amounts and parties. Entry and exit points to transparent chains remain visible.
Gambling and gaming services Cycle funds through deposits and withdrawals to add distance. Service addresses are labelled, and flow-through patterns stand out.
NFT and marketplace wash trading Move value through self-dealing trades disguised as sales. Repeated trades between linked wallets are detectable on-chain.

A few of these deserve a closer look. Mixers, also called tumblers, are the signature crypto laundering tool: they pool funds from many users and pay out coins of equal value from the shared pool, severing the direct on-chain link. Cross-chain bridges pursue the same goal by moving value onto a different blockchain, betting that tracing stops at the chain boundary. Peel chains take the opposite tack, shedding small amounts through a long sequence of hops so no single transaction looks significant. None of these breaks the trail permanently, they raise the cost of following it, which is a different thing.

Two further routes round out the picture. Privacy coins use protocols that conceal amounts and counterparties on their own chains, though the points where value enters from or exits to a transparent chain stay visible. And peer-to-peer trades and services with weak Know Your Customer controls let funds change hands with little friction, which is why exposure to unregulated or nested exchanges is treated as a risk signal in its own right.

A worked pattern
Consider a typical laundering chain after an exchange hack. The attacker splits the stolen funds across fresh wallets, runs them through a mixer, bridges the mixed output to a second blockchain, shreds it through a peel chain of many small transfers, and cashes out via a nested exchange with weak checks. Every step is designed to add distance, and every step is a labelled, traceable event that clustering and cross-chain tracing can reconnect.

Where laundered crypto comes from

Laundered crypto originates in predicate crimes: investment and romance scams, ransomware, darknet market sales, exchange and protocol hacks, and increasingly sanctions evasion by state-linked actors. The laundering methods are broadly the same across these sources; what differs is the urgency and the sanctions exposure some of them carry.

Understanding the source matters because it changes the nature of the risk, not just its level. Funds traced to ransomware or a darknet market are a serious AML finding; funds traced to a sanctioned address are a potential violation regardless of intent, and carry strict liability. A compliance programme that only asks whether funds are risky, without asking where the risk comes from, misses that distinction, and with it the difference between a case to monitor and a case to escalate at once.

The practical implication is that source attribution, tracing a flow back to a labelled origin, is not an academic exercise. It is what tells a compliance team whether it is looking at an elevated-risk counterparty to keep monitoring or a sanctioned exposure to escalate at once.

Red flags of crypto money laundering

The clearest red flags are direct or indirect exposure to mixers, sanctioned entities, or darknet markets; rapid movement of funds through many wallets; cross-chain hopping without economic purpose; structuring into small amounts; sudden activity from a dormant wallet; and cash-out through services with weak Know Your Customer controls. Rarely does one flag decide a case, a cluster of them does.

A transaction monitoring programme watches for indicators like these, weighs them together, and scores the risk rather than reacting to any single one.

  • Direct or indirect exposure to a mixer, tumbler, or sanctioned address
  • Funds tracing back to darknet markets, ransomware, or known theft
  • Rapid movement through a long chain of newly created wallets
  • Chain-hopping across bridges with no apparent economic purpose
  • Structuring, splitting a sum into many small transfers below a threshold
  • A long-dormant wallet suddenly moving significant value
  • Cash-out through nested, unregulated, or high-risk exchanges

How is crypto money laundering detected and traced?

Crypto money laundering is detected with blockchain analytics: clustering addresses into entities, labelling known illicit and regulated actors, and tracing funds across multiple hops and chains to measure a wallet's indirect exposure to risk. That exposure is scored, and transactions that breach a firm's risk appetite are surfaced for a compliance analyst to review.

The launderer's whole strategy is distance, so the analyst's whole job is to reconnect it. The public ledger makes that possible in a way the cash economy never allowed, but it takes more than reading a single transaction. The three capabilities that matter are clustering, labelling, and multi-hop tracing.

clean at the direct counterparty, exposed three hops back Sanctioned source hop 3 hop 2 hop 1 Wallet under review

clean at the direct counterparty,
exposed three hops back

Sanctioned source
hop 3
hop 2
hop 1
Wallet under review

Indirect exposure is the whole game. A wallet can screen clean against its direct counterparty and still be funded, a few hops back, by a sanctioned or illicit source. Multi-hop tracing is what surfaces that hidden link.

Clustering groups the many addresses a single actor controls into one entity, using heuristics such as common-input ownership and change-address detection, so an investigator reasons about a party rather than a scatter of wallets. Labelling attaches identity and risk to known actors, exchanges, mixers, sanctioned entities, darknet markets, so exposure to them can be measured. Multi-hop tracing, the detection of indirect exposure, follows funds across intermediaries and across chains to find risk that a direct-counterparty check would never see.

Detection happens at two moments, and a mature programme does both. Retrospective investigation traces a suspicious flow after the fact, reconstructing the path for a report or a law-enforcement referral. Real-time monitoring scores transactions as they happen, so a risky deposit is flagged before a payout clears rather than discovered afterward. The same clustering and labelling feeds both, but real-time monitoring is what actually stops laundered funds being cashed out, which is the outcome a regulator cares about.

How exposure is weighed matters as much as whether it is found. Not all indirect exposure is equal: funds one hop from a sanctioned address are a different risk from funds five hops away through high-volume intermediaries, where the illicit share may be negligible. A defensible methodology weights exposure by proximity and by the proportion of a wallet's funds that trace to a risky source, rather than treating any historical contact as disqualifying. That is what keeps a monitoring programme from drowning in exposure that is technically present but practically immaterial, the crypto equivalent of a false positive.

Those signals are combined into a risk score. Scorechain scores risk on a scale of 0 to 100, where a lower score means higher risk, across 47 risk categories, drawing on a base of more than 939,000 labelled on-chain entities. A transaction that breaches the firm's risk appetite is surfaced as an alert, and a human analyst decides what to do with it. This is the same machinery covered in our guide to AI in crypto compliance, applied to the specific problem of laundering. You can see it in Scorechain's transaction monitoring and sanctions screening.

From detection to a filed report

A detection is the start of a process, not the end. The compliance team reviews the alert, builds a case from the on-chain evidence, decides whether to clear, monitor, or escalate, and where warranted files a suspicious activity or transaction report with its financial intelligence unit, all within record-keeping and Travel Rule obligations.

What turns a risk score into a defensible outcome is the workflow around it. An analyst reviewing an alert needs the evidence assembled, the exposure path, the entities involved, and the proportion of funds implicated, so the disposition can be justified later. Clearing, continued monitoring, and escalation are all legitimate outcomes, and the record of why one was chosen is as important as the choice itself.

Where the funds are reportable, the team files a suspicious activity report (SAR) or suspicious transaction report (STR) with its financial intelligence unit and preserves the supporting analysis. Two obligations sit alongside this. The Travel Rule requires originator and beneficiary information to accompany transfers above the FATF threshold of USD or EUR 1,000, and record-keeping rules require the audit trail to be retained. A programme that detects laundering but cannot evidence what it did about it has met only half of its obligation.

The rules against crypto money laundering

Money laundering is a criminal offence everywhere, and crypto is squarely in scope. The Financial Action Task Force (FATF) sets the global standards for virtual assets, the European Union enforces them through the Markets in Crypto-Assets Regulation (MiCA) and its anti-money laundering package, and regulators such as FinCEN apply their own reporting regimes. Firms must detect, prevent, and report it.

For crypto-asset service providers (CASPs) in the European Union, the anti-money laundering obligation is now explicit. The Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114, has applied in full since December 30, 2024, and the EU anti-money laundering package tightens the regime further: the Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, applies from July 10, 2027, supervised by the new Anti-Money Laundering Authority (AMLA) in Frankfurt. Globally, FATF Recommendation 15 brings virtual assets into the perimeter, and its Travel Rule requires identifying information to accompany transfers. See the FATF guidance on virtual assets and, in the United States, the Financial Crimes Enforcement Network (FinCEN) reporting rules.

Two obligations deserve emphasis. The Travel Rule, FATF Recommendation 16, requires identifying information on the originator and beneficiary to travel with a transfer, which is what lets one regulated institution pass risk context to the next. And sanctions screening sits alongside AML: the US Office of Foreign Assets Control (OFAC) enforces sanctions on a strict-liability basis, so exposure to a sanctioned address is a violation whether or not the firm knew. In the United Kingdom, the Financial Conduct Authority (FCA) registers and supervises cryptoasset firms under the money laundering regulations. The through-line is the same everywhere: a firm must detect the exposure and evidence what it did about it.

Beyond the EU, UK, and US, the same FATF baseline is implemented by a national regulator in every major market, and a firm operating across borders answers to each. In Asia-Pacific, Singapore supervises providers through the Monetary Authority of Singapore (MAS) under the Payment Services Act, Hong Kong licenses virtual asset trading platforms through the Securities and Futures Commission (SFC), and Australia registers digital-currency exchanges with AUSTRAC. In the Middle East, Dubai regulates virtual assets through the Virtual Assets Regulatory Authority (VARA). In the Americas, Canada requires crypto firms to register as money services businesses with FINTRAC, and in Latin America, Brazil supervises the sector through its central bank, Banco Central do Brasil. The regimes differ in detail, but the obligation to detect, prevent, and report laundering is common to all of them.

Why it matters for firms
A virtual asset service provider that fails to detect laundering does not just face reputational damage, it faces regulatory penalties and, where sanctions exposure is involved, strict liability. Effective transaction monitoring is a legal obligation, not a nice-to-have.

How Scorechain detects money laundering on-chain

Scorechain is a blockchain analytics and crypto AML compliance platform, headquartered in Luxembourg, serving more than 350 clients across over 45 countries. Its Digital Asset Intelligence is built for exactly the problem this guide describes: following value through the layering stage, across wallets and across chains, to the point where laundered funds try to re-enter the regulated system.

The platform clusters addresses into entities, labels known illicit and regulated actors from a base of more than 939,000 entities, and traces indirect exposure across 23 blockchains and more than 470 stablecoins. It scores risk on a transparent, configurable 0 to 100 scale, where a lower score means higher risk, across 47 risk categories, so a compliance team can tune detection to its own risk appetite and explain every decision to a supervisor. Being European-native and MiCA-ready, it frames detection around the rules its clients answer to first. You can explore the approach in Scorechain AI and the wider crypto compliance resources.

The risk methodology is transparent rather than a black box. A compliance analyst can see why a wallet scored as it did, which hop introduced the exposure, and which entity sits at the end of the trail. That is what makes a finding defensible in front of a supervisor and usable as the basis for a suspicious activity report.

Scorechain CTA

Trace laundering on your own data

See how Scorechain clusters wallets, labels entities, and traces indirect exposure across chains, with your compliance team keeping the decision. A short, practical demo.

Book a demo

Frequently asked questions

What is crypto money laundering?

Crypto money laundering is the process of moving cryptocurrency obtained from crime through a series of transactions to disguise its origin and make it look legitimate. It follows the same three stages as traditional laundering, placement, layering, and integration, using on-chain tools such as mixers, bridges, and exchanges.

What are the three stages of money laundering?

Placement, where illicit funds enter the financial system; layering, where they are moved through many transactions to obscure their origin; and integration, where the distanced funds re-enter the economy as apparently clean assets. In crypto, layering is where most of the on-chain complexity sits.

How do criminals launder cryptocurrency?

Mainly through layering: running funds through mixers and tumblers, hopping them across blockchains with bridges, splitting them across many wallets in peel chains, using privacy coins, and cashing out through nested or unregulated exchanges. Serious operations chain several of these methods together to add distance from the source.

Can crypto money laundering be traced?

Yes. Because the blockchain is public and permanent, analytics can cluster an actor's addresses, label known illicit and regulated entities, and trace funds across multiple hops and chains to measure indirect exposure. That reconnects the trail the layering stage tries to break, and surfaces risk a direct-counterparty check would miss.

Is crypto money laundering illegal?

Yes, everywhere. Money laundering is a criminal offence, and virtual assets are in scope of FATF standards, the EU's MiCA and anti-money laundering package, and national regimes such as the US Bank Secrecy Act. Crypto-asset service providers are legally required to detect, prevent, and report it.

Scorechain Compliance & Research Team
Blockchain analytics and crypto AML, Luxembourg

Scorechain's compliance and research team writes on AML, transaction monitoring, and digital-asset regulation, drawing on the platform's work with more than 350 supervised clients and an ISO/IEC 27001:2022 certified security programme. Framework citations reflect the versions current as of the last-updated date above.

Share