The new year began with news that well-known Web3 entrepreneur Kevin Rose was the victim of a phishing scam in which he lost over $1 million in non-fungible tokens (NFTs).
When established financial institutions start offering services related to Web3, crypto and NFTs, they would be custodians of client assets. They need to protect their clients from bad actors and determine if client assets have been obtained through illegal activities.
The crypto industry has not made it easy for anti-money laundering (AML) functions within organizations. The sector has developed constructs like cross-chain bridges, mixers and privacy chains that hackers and crypto thieves can use to obfuscate stolen assets. Very few technical tools or frameworks can help navigate this rabbit hole.
Regulators have recently cracked down on some crypto platforms and pressured centralized exchanges to delist privacy tokens. In August 2022, Dutch police arrested Tornado Cash developer Alexey Pertsev and have been working to control transactions through Mixer ever since.
While centralized governance is seen as antithetical to the Web3 ethos, the pendulum may need to swing the other way before a balance is struck that protects users and doesn’t limit innovation.
And while large institutions and banks must grapple with the technological complexities of Web3 to offer digital asset services to their customers, they can only provide adequate customer protection if they have a robust AML framework in place.
AML frameworks require several features that banks need to evaluate and build. These functions can be developed in-house or achieved by working with third-party solutions.
Some vendors in this space are Solidus Labs, Moralis, Cipher Blade, Elliptic, Quantumstamp, TRM Labs, Crystal Chain, and Chainalysis. These companies focus on providing banks and financial institutions with holistic (full-stack) AML frameworks.
In order for these provider platforms to deliver a holistic approach to AML around digital assets, they need to have multiple inputs. The provider provides several of these, while others are sourced from the bank or institution they work with.
Data Sources and Inputs
Institutions need a lot of data from different sources to effectively identify AML risks. The breadth and depth of data an institution can access determines the effectiveness of its AML function. Some of the key inputs needed for AML and fraud detection are listed below.
The AML policy is often a broad definition of what a company should look out for. This is generally broken down into rules and thresholds that help enforce the policy.
An AML policy could state that all digital assets associated with a sanctioned nation-state such as North Korea must be labeled and addressed.
The policy could also provide that transactions would be flagged if more than 10% of the transaction value could be traced back to a wallet address containing the proceeds of a known asset theft.
For example, if 1 bitcoin (BTC) is sent for custody at a tier one bank and if 0.2 BTC had its source in a wallet containing the proceeds from the Mt. Gox hack, even if an attempt was made to hiding the source By going through 10 or more hops before reaching the bank, this would trigger an AML red flag to alert the bank to this potential risk.
Recent: Death in the metaverse: Web3 aims to offer new answers to old questions
AML platforms use various methods to tag wallets and identify the source of transactions. This includes consulting third party information such as government lists (sanctions and other bad actors); web-scraping crypto addresses, the dark web, terrorist financing sites, or Facebook pages; Using common output heuristics that can identify crypto addresses controlled by the same person; and machine learning techniques like clustering, which can identify cryptocurrency addresses controlled by the same person or group.
The data collected through these techniques is the building block for the basic capabilities of AML functions within banks and financial services institutions that need to be created to deal with digital assets.
Wallet monitoring and screening
Banks must conduct proactive monitoring and verification of customer wallets, being able to assess whether a wallet has directly or indirectly interacted with illegal actors such as hackers, sanctions, terror networks, mixers, etc.
Representation of assets in a wallet, categorized and labeled. Source: Elliptical
Once tags are attached to wallets, AML rules are applied to ensure wallet screening is within risk limits.
Blockchain investigation
Blockchain investigation is crucial to ensure that transactions taking place on the network do not involve illegal activity.
Blockchain transactions are examined from final source to final destination. Provider platforms offer features such as filtering by transaction value, number of hops, or even the ability to automatically identify on-off-ramp transactions as part of an investigation.
Illustration of an elliptical platform tracing a transaction back to the dark web. Source: Elliptical
Platforms provide a pictorial hop chart showing each and every hop a digital asset has taken through the network to get from the first wallet to the newest. Platforms like Elliptic can identify transactions even originating from the dark web.
Multi-Asset Monitoring
Monitoring the risk when multiple tokens are used to launder money on the same blockchain is another important capability that AML platforms must have. Most Layer 1 protocols have multiple applications that have their own tokens. Illegal transactions could take place with any of these tokens, and monitoring needs to be broader than just a basic token.
Cross-chain monitoring
Cross-chain transaction monitoring has been on the minds of data analysts and AML professionals for some time. Aside from mixers and dark web transactions, cross-chain transactions are perhaps the most difficult problem to solve. Unlike mixers and dark web transactions, cross-chain asset transfers are commonplace and a real use case driving interoperability.
Also, wallets with assets that have bounced through Mixer and the dark web can be tagged and flagged with a red flag, as these immediately count as yellow flags from an AML perspective. It would not be possible to simply tag a cross-chain transaction as this is fundamental to interoperability.
AML initiatives around cross-chain transactions have historically been challenging because cross-chain bridges can be opaque in the way they move assets from one blockchain to another. Because of this, Elliptic has developed a multi-step approach to solving this problem.
An illustration of how a cross-chain transaction between Polygon and Ethereum is identified as a source with a crypto mixer – a sanctioned entity. Source: Elliptical
The simplest scenario is when the bridge provides end-to-end visibility across chains for each transaction and the AML platform can inherit it from the chains. When such traceability is not possible due to the nature of the bridge, AML algorithms use time value matching, which matches assets that have left one chain and arrived on another based on the time of transmission and the value of the transmission.
The most difficult scenario is when none of these techniques can be used. For example, transfers of wealth from Ethereum to the Bitcoin Lightning Network can be opaque. In such cases, cross-bridge transactions can be treated like those in Mixer and the dark web, and are generally flagged by the algorithm for lack of transparency.
Intelligent Contract Screening
Smart contract screening is another crucial area to protect decentralized finance (DeFi) users. This is where smart contracts are checked to ensure there is no illegal activity involving the smart contracts that institutions need to know about.
This is perhaps most relevant for hedge funds looking to participate in liquidity pools in a DeFi solution. It is less important for banks at this point, since they usually do not participate directly in DeFi activities. However, as banks delve into institutional DeFi, screening at the smart contract level would become extremely critical.
VASP due diligence
Exchanges are classified as Virtual Assets Service Providers (VASPs). Due diligence examines the overall risk of the exchange based on all addresses associated with the exchange.
Some AML vendor platforms provide a view of risk based on country of incorporation, know-your-customer requirements, and in some cases the status of financial crime programs. Unlike previous features, VASP checks include both on-chain and off-chain data.
Recent: Tel Aviv Stock Exchange’s crypto trading proposal is a ‘closed-loop system’
AML and on-chain analytics is a rapidly evolving field. Multiple platforms are working to solve some of the most complex technology problems that would help institutions protect their client assets. However, this is still a work in progress and much needs to be done to have robust AML controls on digital assets.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.