What Happened
In 2025, the FBI's Internet Crime Complaint Center received over 181,000 cryptocurrency-related fraud complaints, totaling approximately $11.366 billion in losses. Investment fraud accounted for more than $7 billion of that total. The majority of these cases involved social engineering schemes. Victims were manipulated over weeks or months through dating apps, social media, professional networks, and fake investment communities before sending funds to fraudulent crypto platforms.
Older Americans suffered disproportionately, with individuals aged 60 and older losing billions. Scammers impersonated law enforcement, banks, or fraud departments, convincing victims to move their savings through crypto ATMs or digital asset platforms under the false belief they were protecting their money.
Timeline of Control Failures
The fraud pattern reveals a consistent sequence where traditional compliance controls failed to intervene:
Weeks 1-4: Criminals establish contact through legitimate platforms like dating sites, LinkedIn, and WhatsApp. No blockchain activity occurs yet. Your customer due diligence processes don't flag anything because no transaction has occurred.
Weeks 4-8: Trust-building phase. Scammers share fake investment advice or create urgency around a "limited opportunity." Your transaction monitoring systems remain silent because no funds have moved through your platform.
Week 8+: Victim initiates the first transfer. By this point, the manipulation is complete. Your monitoring rules may flag unusual activity, but the victim believes they're making a legitimate investment. When your support team reaches out, the customer insists everything is fine.
Post-transaction: Funds move rapidly across wallets, bridges, or mixers. Your blockchain analytics tools can trace the movement, but recovery is difficult. The victim realizes they've been scammed only when withdrawal requests are denied or the "investment platform" disappears.
The critical failure point isn't during the transaction. It's in the weeks before your systems ever see suspicious activity.
Which Controls Failed or Were Missing
Behavioral risk indicators at onboarding: Most firms screen for sanctions matches and verify identity documents. Few evaluate whether a new customer's stated investment experience matches their actual transaction behavior, whether their funding sources align with their risk profile, or whether their communication patterns suggest external influence.
Cross-functional fraud coordination: AML teams monitored transactions. Cybersecurity teams handled technical threats. Fraud teams investigated chargebacks. But nobody connected the dots when a customer suddenly began making large crypto purchases after years of dormancy, or when multiple customers exhibited identical behavioral patterns suggesting coordinated manipulation.
Customer intervention protocols: When monitoring systems flagged unusual activity, most firms sent generic warnings or required additional verification. They didn't have structured procedures for identifying victims of ongoing social engineering or protocols for escalating suspected manipulation to specialized fraud investigators before funds left the platform.
Crypto ATM safeguards: Kiosk operators focused on identity verification and transaction limits. They didn't implement real-time behavioral analytics to identify customers being coached through transactions by someone off-camera, or velocity checks that flagged users making multiple high-value deposits within short timeframes at different locations.
AI-enhanced impersonation detection: As criminals began using deepfakes and AI-generated communications to impersonate customer support staff or law enforcement, most firms lacked tools to verify the authenticity of third-party communications their customers referenced during transactions.
What the Standards Require
The Bank Secrecy Act requires financial institutions to establish risk-based AML programs designed to prevent money laundering and terrorist financing. This includes customer due diligence, ongoing monitoring, and suspicious activity reporting. However, the BSA doesn't explicitly define how far firms must go in protecting customers from manipulated decisions.
FinCEN's Customer Due Diligence Rule (31 CFR 1010.230) requires institutions to understand the nature and purpose of customer relationships and maintain risk profiles. When a customer's transaction activity becomes inconsistent with their stated purpose or risk profile, that's your trigger for enhanced due diligence.
FATF Recommendation 1 requires countries to assess money laundering and terrorist financing risks and apply a risk-based approach. As fraud methodologies evolve, your risk assessment must evolve with them. If your 2024 risk assessment doesn't address AI-enhanced social engineering or romance scams targeting elderly customers, it's already outdated.
These standards were primarily written for traditional money laundering typologies. They don't explicitly address manipulation-based fraud where the customer genuinely believes they're making a legitimate investment. You're left interpreting how existing obligations apply to emerging threats.
Lessons and Action Items for Your Team
Expand your risk assessment beyond traditional AML typologies. Your next annual risk assessment should explicitly address social engineering fraud, romance scams, impersonation schemes, and AI-enhanced manipulation tactics. Document how your controls detect these threats and where gaps exist.
Build behavioral analytics into your monitoring program. Don't just monitor transaction patterns. Track changes in customer behavior: dormant accounts suddenly activating, customers making urgent requests outside normal patterns, users repeatedly asking how to move funds quickly, or multiple customers exhibiting identical behavioral sequences. These patterns often indicate external coaching.
Create cross-functional fraud response teams. Your AML analyst shouldn't be making intervention decisions alone. When monitoring flags potential manipulation, escalate to a team that includes fraud investigators, customer support specialists familiar with scam tactics, and compliance officers who understand your reporting obligations. Different expertise catches different warning signs.
Develop customer intervention protocols. Write specific procedures for what happens when you suspect a customer is being manipulated. This isn't just asking "are you sure?" It's providing specific information about common scam tactics, asking targeted questions about how they learned about the investment, and documenting their responses. If they mention being coached by someone they met online, that's your red flag for enhanced scrutiny.
Implement velocity and pattern controls at crypto ATMs. If you operate or partner with crypto kiosk providers, add transaction velocity monitoring across locations, behavioral analytics for coached transactions, and mandatory cooling-off periods for high-risk demographic groups making large first-time purchases.
Train your entire organization on manipulation tactics. Your customer support team talks to potentially manipulated customers every day, but they may not recognize the warning signs. Train them to identify common phrases scammers use, behavioral indicators of coaching, and escalation procedures when they suspect fraud in progress.
Update your Suspicious Activity Report procedures. When you file a SAR for suspected fraud, include behavioral indicators and communication patterns in your narrative, not just transaction details. FinCEN needs to understand how the manipulation occurred, not just where the funds went.
The $11.3 billion in losses isn't just a consumer protection problem. It's a financial crime risk management problem that requires your AML/CFT Framework to expand beyond traditional monitoring into behavioral risk detection. The criminals have already made that shift. Your controls need to catch up.



