I work in crypto AML — here’s how Binance and others actually flag your wallets

AlexAML

Newbie
Joined
Nov 3, 2025
Messages
9
Reaction score
3
Hello everyone,

I have been in AML (Anti-Money Laundering) compliance officer in the crypto industry for several years now.
You would be shocked at the number of wallets that get flagged, frozen, or permanently blacklisted daily — not only for scams — simply because of a user’s mistake.
I see the ins and outs of how exchanges and blockchain analytics tools actually decide what to block in compliance to AML.

Sometimes it’s easy; stolen funds, mixer trails, ransomware, darknet, etc.
But, other times it’s simply a bad AML score because the user had a few “dirty hops” in the transaction history. After your wallet hits a certain threshold, it will get flagged across multiple exchanges.
Most of the time, users have no idea what occurs after they are frozen, or flagged for that matter, let alone how to avoid triggering the AML systems in the first place.
So, without further ado, please feel free to ask me anything about:
  • How AML tracking works in crypto
  • Why exchanges freeze wallets
  • How blockchain analytics tools determine risk scores
  • What “dirty coins” really mean
While I am unable to share confidential specifics, I can explain how things operate from the compliance side and more importantly what is the patterns that create flags.
Let’s see what myths can be busted in compliance in crypto in any context.
 
Sure why don't you start with these as you offered:

1 How AML tracking works in crypto
2. Why exchanges freeze wallets
3. How blockchain analytics tools determine risk scores
4. What “dirty coins” really mean
 
Hello everyone,

I have been in AML (Anti-Money Laundering) compliance officer in the crypto industry for several years now.
You would be shocked at the number of wallets that get flagged, frozen, or permanently blacklisted daily — not only for scams — simply because of a user’s mistake.
I see the ins and outs of how exchanges and blockchain analytics tools actually decide what to block in compliance to AML.

Sometimes it’s easy; stolen funds, mixer trails, ransomware, darknet, etc.
But, other times it’s simply a bad AML score because the user had a few “dirty hops” in the transaction history. After your wallet hits a certain threshold, it will get flagged across multiple exchanges.
Most of the time, users have no idea what occurs after they are frozen, or flagged for that matter, let alone how to avoid triggering the AML systems in the first place.
So, without further ado, please feel free to ask me anything about:
  • How AML tracking works in crypto
  • Why exchanges freeze wallets
  • How blockchain analytics tools determine risk scores
  • What “dirty coins” really mean
While I am unable to share confidential specifics, I can explain how things operate from the compliance side and more importantly what is the patterns that create flags.
Let’s see what myths can be busted in compliance in crypto in any context.
Why, if usdt has been stolen, is there no way to freeze the coins or terminate them right away? Tether will say they cant do anything, which is BS, Binance is redirecting users to a police contact form, which is pretty hopeless.

Hows the CEO doing in jail, was he still running daily business?
 
Let me first say, I appreciate an AML person jumping into the hornets nest here, but lets have some fun. I have compiled a few questions.

A few things a lot of us in the space are curious about:


1. Compliance vs. real-world behavior

• How does Binance handle users who originally registered before mandatory KYC, but now interact through VPNs or privacy tools?
• Is legacy data still being rescored for AML risk?
• What’s the process if a verified user later interacts with mixers or privacy wallets off exchange?


2. Transaction monitoring

• What triggers a “source of funds” check? Specific patterns, or just amounts?
• How does the system distinguish normal chain-hopping from actual laundering behavior?
• What’s the false-positive rate from the chain-analysis vendors you use?


3. Jurisdiction and data retention

• When data is collected under one legal entity (e.g., Binance Poland or Dubai), can it be queried by other regional entities?
• How long is metadata from closed accounts stored?
• For an EU user trading via a non-EU entity, which region’s retention laws apply?


4. Chain surveillance

• Are withdrawal addresses tagged automatically or only after a report from a vendoror regulator?
• Do you share address clusters with other exchanges?
• How are mixed deposits (mostly clean, partly tainted) handled in practice?


5. Transparency

• Roughly how many account closures end up being false positives? How many never get a chance to make it right, what happens to the funds?
• Can users ever see the specific tag or reason they were flagged?
• Does Binance track the actual impact AML controls have on stopping real criminal flow, or is it mainly about meeting regulator expectations?

That is all for now
 
Back
Top