Skip to content

Risk operations

Crypto AML Red Flags: 12 Transaction Patterns Businesses Should Review

admin · 8/31/2026 · 7 min read

Woven transaction paths with knots, loops, splits, and sudden changes

Learn 12 crypto transaction patterns that deserve a closer AML review, why each matters, and what evidence your team should examine before making a decision.

A red flag is a question, not a verdict

Crypto payments can move quickly, cross several services, and arrive from an address a business has never seen before. A split payment may reflect a wallet limit. A new address may be routine treasury practice. A rapid transfer may be necessary.

The Financial Action Task Force makes the distinction clear in its virtual asset red flag report. One indicator does not necessarily mean criminal activity. Concern becomes stronger when several indicators appear together, the transaction has no logical business purpose, or the explanation conflicts with the available evidence.

The following twelve patterns are therefore prompts for a proportionate review. They are not a universal checklist and do not determine whether a report must be filed. Your obligations depend on your role, jurisdiction, customer relationship, and internal policy.

12 crypto transaction patterns worth reviewing

1. One payment is split into many smaller transfers

Why it matters: Repeated transfers just below a limit, or an invoice settled through many small amounts without a practical reason, can resemble structuring. FATF identifies small transfers designed around record keeping or reporting thresholds as a red flag.

Review next: Compare the combined value with the invoice, timing, sender addresses, stated wallet limits, and previous payment behavior. Document a credible operational explanation rather than judging each transfer in isolation.

2. A new or inactive wallet suddenly becomes very active

Why it matters: A large first transfer, or a burst of high value activity after a long quiet period, can be inconsistent with the expected profile. It can also indicate a newly prepared pass through wallet.

Review next: Establish when the address first became active, how it was funded, whether the volume fits the customer, and why this wallet is being used now.

3. Funds are forwarded almost immediately after receipt

Why it matters: Immediate movement through several wallets or services may be an attempt to add layers between the source and destination. Speed alone is not suspicious, especially for payment processors and treasury systems. The absence of a business reason is what raises the question.

Review next: Map the first relevant hops, measure timing, identify known counterparties, and ask what commercial purpose each movement serves.

4. Many unrelated wallets feed one address, followed by consolidation

Why it matters: FATF highlights small incoming transfers from many unrelated wallets followed by a transfer to another wallet or conversion to fiat. The same pattern may also occur legitimately in merchant collection or platform deposit systems.

Review next: Determine whether the address has a documented collection role. Compare sender relationships, payment references, values, and the final destination with the stated business model.

5. The route uses repeated swaps, bridges, or network changes

Why it matters: Multiple asset conversions or cross network movements that add fees without an apparent economic purpose can make the trail harder to understand. A bridge or swap is not inherently risky. Unnecessary complexity is the relevant signal.

Review next: Reconstruct the route across supported networks, note where traceability changes, and ask why the chosen asset and route were necessary for this payment.

6. There is material exposure to a mixer or obfuscation service

Why it matters: FATF and FinCEN guidance on convertible virtual currency both discuss mixing as a way to obscure the connection between sending and receiving addresses. Privacy can have legitimate uses, so the finding still needs context.

Review next: Distinguish direct use from a distant indirect connection. Consider value, timing, transaction distance, source explanation, and whether the exposure is material to the payment under review.

7. The wallet connects to an identified illicit or restricted service

Why it matters: Direct links to known fraud, theft, ransomware, darknet, or sanctioned activity deserve prompt attention. An indirect connection several steps away is not equivalent to receiving funds directly from an identified service.

Review next: Verify the attribution, its date and source, the direction of funds, exposure distance, relevant amount, and the legal regime that applies. AML and sanctions controls may require different actions.

8. The service or geography does not fit the customer story

Why it matters: Transfers through providers or jurisdictions with no relationship to where the customer lives or does business can increase risk, particularly where oversight is weak. Geography should not become a shortcut for judging nationality.

Review next: Ask for the commercial reason, identify the service involved, check its current regulatory status, and compare the route with the customer profile and invoice.

9. The payer unexpectedly changes the wallet, asset, or network

Why it matters: A last minute change can be harmless, but it can also result from compromised communications, address substitution, or an attempt to avoid a previous review. The FBI recommends independent verification when payment instructions change in business email compromise scenarios.

Review next: Verify the change through a trusted second channel, check the complete address and token contract, confirm the network, and screen the new destination or source before proceeding.

10. The transaction conflicts with the stated source of funds

Why it matters: An exchange receipt, invoice, or verbal explanation may not match the wallet history, amount, timing, or named account. Incomplete, inaccurate, or changing explanations are more concerning when other transaction signals are present.

Review next: Request evidence that connects the person, account, wallet, and specific transaction. The goal is to make the explanation testable. See why source of funds matters in crypto.

11. A third party appears to control or fund the payment

Why it matters: The named customer may present an exchange account, bank account, or wallet belonging to someone else without a clear relationship. This can signal a mule, concealed beneficial ownership, or simple payment on behalf of a related company.

Review next: Identify the third party, establish the relationship and authority, check whether third party payments are allowed by policy, and review both the customer context and relevant wallet evidence.

12. Someone creates urgency, secrecy, or pressure to bypass checks

Why it matters: Fraudsters often use urgency to prevent verification or intervention. Pressure to release goods, refund to a different address, ignore an alert, or describe a payment inaccurately should be treated as part of the evidence, not merely poor communication.

Review next: Slow the process down, preserve messages, verify instructions independently, and follow the normal approval path. The FBI and IC3 warning about exchange impersonation shows how urgency is used to obtain access and steal crypto.

How to respond when a pattern appears

  1. Preserve the identifiers: Record the full addresses, network, asset, amount, transaction hash, timestamps, customer reference, communications, and the exact reason for the alert.
  2. Screen the correct target: Confirm whether you need to examine the sender, destination, transaction, or several connected addresses. A copied address on the wrong network can invalidate the review.
  3. Compare evidence with context: Place wallet findings beside KYC information, invoice details, expected activity, source of funds evidence, and previous customer behavior. KYC, KYT, and AML answer different questions.
  4. Assess materiality: Consider direction, value, recency, exposure distance, attribution confidence, and whether several indicators form a coherent pattern.
  5. Clarify before concluding: Ask a focused question or request a relevant document. Avoid collecting information without a defined purpose.
  6. Decide and document: Accept, pause, reject, or escalate according to policy. Record what was reviewed, who decided, and why. If an alert arrives after payment, follow a structured first hour response.

Where Farona fits

Farona helps teams investigate wallet and transaction risk signals in a structured report. It converts available blockchain evidence into a Farona score, Farona level, plain language verdict, and supporting details that a reviewer can compare with customer and payment context.

Farona does not identify the legal owner of every wallet, prove criminal intent, or replace an AML program. It should help decide what deserves attention and support a documented human review. A stronger signal may justify a deeper investigation. It should not trigger automatic rejection without considering the evidence and the rules that apply to your business.

Sources and further reading

Sources were checked on 31 August 2026. This article provides general information and is not legal advice. Red flags, reporting duties, and permitted actions vary by jurisdiction and business model.

Related posts

More from the same category.