Skip to main content
Crypto Fraud Winding-Up Reveals Why You Need Relational Transaction MonitoringSuspicious Activity Reporting
5 min readFor AML Compliance Officers

Crypto Fraud Winding-Up Reveals Why You Need Relational Transaction Monitoring

The UK Insolvency Service wound up Key Coin Assets Ltd on 11 August 2026 after investigators found no evidence the firm conducted genuine cryptocurrency trading. This case highlights a critical gap in how financial institutions monitor crypto-related customers: they're focusing on individual transactions when they should be tracking relationships, behavioral patterns, and entity networks.

Investigation Insights

The Key Coin Assets investigation revealed transaction patterns that traditional threshold-based monitoring would have missed. Nine investors collectively paid over £300,000 to the firm, which promised returns between 40% and 100%. Bank records showed funds from new investors were transferred to the director's personal account within hours, with newer investor funds allegedly used to pay earlier investors.

The firm instructed investors to avoid using terms like "crypto" or "investment" in bank payment references. Investigators also found the company claimed assets of up to £42 million despite banking activity that didn't support those figures. The company repeatedly changed its registered address and failed to provide accounting records.

Key Findings

1. Rapid Beneficiary Concentration Signals Risk

When multiple unrelated individuals send funds to the same account or business within short timeframes, your transaction monitoring system should flag it. The Key Coin Assets case showed investor funds moving to a single director's personal account quickly. This pattern doesn't necessarily breach a single transaction threshold, but the velocity and convergence create a behavioral signature.

Your monitoring rules need to track beneficiary frequency across customer portfolios, not just within individual customer profiles. If ten different customers all send payments to the same entity within 24 hours, that's a relationship pattern your system should surface.

2. Payment Instruction Anomalies Indicate Concealment

Instructions to remove or disguise transaction purposes reduce transparency and complicate your ability to assess risk. When a crypto business tells customers to avoid using "crypto" or "investment" in payment references, they're actively undermining your transaction monitoring controls.

This finding shifts due diligence from the transaction itself to the customer's instructions around the transaction. Your Customer Due Diligence should include questions about how the business instructs its customers to describe payments. If a crypto investment firm can't articulate a legitimate reason for sanitizing payment descriptions, that's a risk rating escalation.

3. Asset-to-Activity Mismatches Warrant Investigation

Key Coin Assets claimed assets of up to £42 million while banking activity didn't support that figure. This type of discrepancy requires you to compare what the customer tells you during onboarding against what their transaction history reveals.

Build a control that compares stated business scale against observed transaction volumes. If a crypto firm claims £40 million in assets under management but processes £200,000 in monthly transactions, your Periodic Review should escalate that customer for enhanced scrutiny.

4. Personal Account Commingling Creates Red Flags

Corporate funds moving quickly from investors into a director's personal account may indicate misappropriation or a Ponzi-style structure. Your Know Your Business process should document the business's stated fund flow, then your transaction monitoring should alert when actual flows deviate.

If your customer is a registered crypto investment firm, funds should flow through corporate accounts with clear segregation. Transfers to personal accounts within hours of investor deposits represent a material deviation from expected business practice.

5. Behavioral Inconsistency Compounds Risk

The company repeatedly changed its registered address and failed to provide accounting records. These aren't transaction monitoring findings, but they're behavioral indicators that should trigger enhanced transaction scrutiny.

Your Ongoing Due Diligence framework should include non-financial behavioral triggers: repeated address changes, failure to provide requested documents, inconsistent explanations of business operations, or material changes to ownership structure. When these triggers fire, your transaction monitoring thresholds for that customer should tighten.

Implications for Your Team

You can't detect relational fraud patterns if your monitoring system treats each transaction as an isolated event. The Key Coin Assets case demonstrates why crypto-related fraud requires you to analyze networks, not just nodes.

Traditional transaction monitoring focuses on threshold breaches: a payment over £10,000, a customer who receives more than 20 transactions per day, or a sudden spike in transaction volume. These rules work for certain typologies, but they miss patterns that only become visible when you map relationships across your customer base.

The Financial Conduct Authority currently regulates cryptoasset businesses for AML and financial promotions, with broader regulation scheduled for 25 October 2027. As that regulatory framework expands, your monitoring obligations will likely include more explicit requirements for relational analysis.

Action Items By Priority

Immediate (this quarter):

Review your transaction monitoring rules for crypto-related customers. Add a rule that flags when five or more customers send payments to the same beneficiary within a 48-hour period. Set the threshold based on your customer volume, but prioritize velocity over value.

Document how your KYB process captures expected fund flows for crypto investment firms. Your onboarding questionnaire should ask: "Describe the typical path of customer funds from receipt to deployment" and "Under what circumstances do company funds transfer to director or employee personal accounts?"

Short-term (next six months):

Build a control that compares customer-stated business scale against observed transaction activity. During Periodic Review, generate a report showing claimed assets or customer counts alongside actual transaction volumes. Flag discrepancies exceeding 50% for investigation.

Train your transaction monitoring analysts to recognize payment instruction anomalies. If a customer asks counterparties to obscure transaction purposes, that's a behavioral red flag that should trigger a case review, even if no individual transaction breaches a threshold.

Medium-term (next year):

Implement network analysis capabilities in your transaction monitoring system. You need technology that can identify clusters of customers sending to common beneficiaries, shared directors across multiple crypto businesses, or coordinated timing patterns across seemingly unrelated accounts.

Integrate non-financial behavioral triggers into your customer risk rating model. Repeated address changes, document provision failures, or inconsistent business explanations should automatically increase a customer's risk score and tighten their transaction monitoring thresholds.

You Might Also Like