Skip to content
EBA · EU-wide

Crypto laundering typologies — what the AMLR names

Fintech Passport
August 20, 2026 · 4-min read
Crypto laundering typologies — what the AMLR names

EU law now names crypto laundering techniques directly, rather than leaving them to guidance. Regulation (EU) 2024/1624 carries a dedicated article on transfers to and from self-hosted addresses, extends the shell-institution prohibition into crypto-asset services, and requires providers to have controls capable of detecting attempts to misuse their accounts. Those are the three techniques the Regulation treats as structural — and they are the ones a crypto-asset service provider’s risk assessment has to answer.

1. Self-hosted addresses — Article 40

Crypto-asset service providers must identify and assess the risk of money laundering and terrorist financing associated with transfers of crypto-assets directed to or originating from a self-hosted address, and must have internal policies, procedures and controls to do so. They must then apply mitigating measures commensurate with the risks identified, including one or more of:

LimbMeasure
(a)Risk-based measures to identify and verify the identity of the originator or beneficiary of the transfer, or their beneficial owner — including through reliance on third parties
(b)Requiring additional information on the origin and destination of the crypto-assets
(c)Enhanced ongoing monitoring of transactions with a self-hosted address
(d)Any other measure to mitigate and manage ML/TF risks and the risk of non-implementation and evasion of targeted financial sanctions

AMLA is due to issue guidelines specifying these measures by 10 July 2027, so the current freedom to design the approach comes with a known review point.

2. Nested exchanges and shell institutions — Article 39

The shell-institution prohibition runs in both directions. Under Article 39(1), credit and financial institutions shall not enter into, or continue, a correspondent relationship with a shell institution, and must take appropriate measures to avoid relationships with institutions known to allow their accounts to be used by a shell institution.

Article 39(2) adds the crypto-specific limb: crypto-asset service providers must ensure their accounts are not used by shell institutions to provide crypto-asset services, and must have internal policies, procedures and controls in place to detect any attempt to use their accounts for the provision of unregulated crypto-asset services.

That is a detection duty, and it is the answer the Regulation gives to nesting — an unregulated service operated on top of a regulated provider’s account, so that the nested operator’s customers transact without ever being the provider’s customers. A prohibition in the terms of service is a policy; Article 39(2) asks for a procedure that finds the behaviour.

3. What “detecting an attempt” looks like

Nesting has an observable signature, because a nested operator’s account behaves like a small exchange rather than like a customer:

  • Counterparty fan-out. A single account transacting with an unusually wide and constantly changing set of counterparties, in both directions.
  • Netting behaviour. Inbound and outbound flows of similar aggregate value with a small retained margin, repeated over time.
  • Pattern regularity. Round-the-clock activity, or activity in denominations and intervals characteristic of automated order handling rather than personal use.
  • Profile mismatch. Volume inconsistent with the customer’s declared activity captured under Article 20(1)(e) — which is where the control connects back to ordinary due diligence.

4. Correspondent relationships in crypto

Article 37 carries specific enhanced due diligence measures for cross-border correspondent relationships involving crypto-asset services, alongside the general correspondent regime in Article 36 — under which the five standing measures include gathering enough information to understand the respondent’s business, determining its reputation and the quality of its supervision from publicly available information, assessing its AML/CFT controls, obtaining senior management approval, and documenting each institution’s responsibilities.

Read together with Article 40, the structure is coherent: the Regulation treats the boundary of the regulated system — self-hosted addresses on one side, unregulated or shell operators on the other — as the point where obligations concentrate.

FAQ

Does the AMLR ban transfers to self-hosted addresses?

No. Article 40 requires the risk to be identified and assessed and mitigating measures to be applied commensurately, choosing one or more from a named list.

What is required about nested services?

Article 39(2) requires crypto-asset service providers to ensure their accounts are not used by shell institutions, and to have policies, procedures and controls to detect any attempt to use their accounts to provide unregulated crypto-asset services.

When will AMLA specify the self-hosted address measures?

Article 40(2) provides for AMLA guidelines by 10 July 2027.


Related: The MiCA travel rule · Correspondent relationships · DAC8 crypto reporting

Related reads.