Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileindustries

When Your Platform Is Used to Move Someone Else's Money

Financial technology companies inherit the compliance exposure of their users. The abuse patterns and the controls that detect them.

Priya Raman · 2 min read

A platform that lets users hold and move value will be used by someone to move value that is not theirs. The question is whether you detect it before a regulator does. Read this against a regulated crypto payment provider with fiat settlement, whose authorisation and permissions are on a public register you can check.

The patterns

Layering through many accounts. Funds arrive, split across accounts, recombine and leave. Each individual movement is unremarkable.

Accounts opened with borrowed identities. Real documents belonging to real people, supplied by someone else. Common where identity verification is automated and document-only.

Rapid pass-through. Deposits that leave within minutes, repeatedly, with no other activity. The account is a conduit rather than a wallet.

Structuring below thresholds. Amounts consistently just under whatever level triggers additional checks.

A dormant account that activates at volume. Often an account that was sold.

Why it matters to you rather than only to the user

A licensed platform carries obligations regardless of who initiated the transaction. Failing to detect and report can cost the licence, not just the relationship.

And practically: the banking partner that supports your platform is watching the aggregate. Patterns visible to them and not to you end the banking relationship.

What detection requires

Monitoring the shape, not just the amounts. Velocity, ratio of in to out, time held, counterparty concentration.

Linking accounts. Shared devices, addresses, funding sources and behaviour patterns. Fraud rings look unremarkable per account and obvious in aggregate.

Screening counterparties on both sides. Incoming and outgoing, against sanctions and risk data.

Escalation that actually happens. An alert nobody reviews is worse than no alert, because it evidences that you knew.

The controls users experience

Limits that rise with verification. Delays on first withdrawals to new destinations. Additional checks on unusual patterns. The same attack targets businesses harder, which is what crypto rails built for fintech companies is built to resist.

These generate complaints from legitimate users, and removing them to reduce friction is how platforms end up with the problem.

The account selling problem

Verified accounts have resale value. Users are approached and paid to hand over access.

Detection is behavioural: a change in device, location and pattern simultaneously, on an account that was previously consistent.

The terms should prohibit it explicitly and the enforcement should be immediate, because an account knowingly transferred is no longer verified regardless of the documents on file.

What to build first

Transaction monitoring with rules you can explain to a regulator. A case management system with a record of what was reviewed and decided. And a reporting path that someone is actually responsible for.

The order matters. Platforms that build volume before building this find that retrofitting it while under supervision is considerably harder than building it early. Verify rather than assume. an exchange that publishes its full terms can be checked on a public register in about five minutes.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

fintechcompliancemonitoring

Related cases