AML Freezes on Crypto Exchanges: The $154B Problem Behind Your Locked Account
Picture a nightclub bouncer with a clipboard. He doesn't know if you're a troublemaker, but he knows the guy who vouched for you got barred last week, and the guy who vouched for him is on a watchlist in three countries. That's roughly the position a compliance engine at a crypto exchange is in when it looks at your deposit. And in 2025, according to Chainalysis, addresses linked to illicit activity received at least $154 billion in cryptocurrency. That's the number that keeps the bouncer's clipboard growing.
The Numbers
$154 billion is the headline figure worth sitting with. As incrypted reported, that's the volume Chainalysis attributes to illicit-linked addresses across the full year of 2025. It's a small slice of total on-chain volume, but it's more than the annual GDP of a mid-sized European country moving through wallets that any compliance officer would flag on sight.
That's the pressure behind every "AML freeze" a user sees. And the term itself covers a spectrum: holding a deposit, suspending withdrawals, requesting additional documents, or temporarily restricting an account. Four distinct actions, all bundled under one scary phrase, and each triggered by a different signal in the risk engine.
The regulatory backdrop matters here because it explains why exchanges have gone from "we'll take a look" to "prove it or we hold it." In the European Union, crypto-asset service providers now sit under the Markets in Crypto-Assets Regulation (MiCA), and transfer-of-information rules for digital asset transactions fall under Regulation (EU) 2023/1113. In the United States, the Bank Secrecy Act, FinCEN, and OFAC's sanctions regimes are the three legs of the stool. At the global layer, the FATF sets the baseline: Recommendation 15 pulls virtual assets and VASPs into the AML/CFT tent, and Recommendation 16 forces the Travel Rule onto VASP transfers.
Anyone who has tried to reconcile a MiCA-compliant deposit flow against a FinCEN money-transmitter checklist knows these frameworks don't overlap cleanly. The same transaction can be green on one exchange and yellow on another, purely because the internal risk policies were tuned by different lawyers in different jurisdictions. That's not a bug in the system. That's the system.
The mechanics under the hood are consistent though. Exchanges analyze four things: addresses, transaction history, account behaviour, and the source of funds. Cross-checks run against on-chain data, sanctions lists, and customer information the exchange already holds. One risk indicator alone doesn't prove wrongdoing, but it's enough to trigger a deeper look, and a deeper look is what most users experience as "my account got frozen for no reason."
What's Actually New
The genuine shift isn't that AML exists on crypto exchanges. It's that the risk-based approach has matured to the point where behavioural drift alone can trigger a hold. Deposit patterns that don't match your KYC profile, a sudden spike in counterparty diversity, an inbound transfer from a wallet three hops away from a mixer: any of these can flip the switch.
KYC used to be the gate. Pass it once, get your ID and proof of address on file, and you were considered cleared. That's no longer how it works. Successful KYC verification does not mean the exchange stops analysing your subsequent activity. The monitoring is continuous, and the risk score attached to your account is a living document that updates every time you move funds.
The second real change is jurisdictional weight. MiCA came into force with teeth, and the companion Regulation (EU) 2023/1113 turned the Travel Rule from a FATF suggestion into a European legal obligation. Exchanges operating in the bloc now have to pass originator and beneficiary information on transfers between VASPs, and that data has to be stored, retrievable, and cross-referenced. Incrypted's earlier piece from June, "Time is Up: What Awaits the EU Crypto Market After July 1," flagged this deadline as the point where the grace period ended. It has ended.
The third shift is the death of the single "AML rating." Users still ask which service gives them a definitive risk score for a wallet. There isn't one. Different chain analytics providers weight heuristics differently, exchanges layer their own policies on top, and a wallet that scores 20/100 on one platform can score 65/100 on another. Pre-checking an address helps you spot obviously risky histories, but it's a smoke detector, not a certificate of good standing.
For engineering teams building on-ramps, off-ramps, or custody products, the practical implication is that compliance is no longer a bolt-on. It sits in the transaction path, adds latency, and needs its own SRE discipline. The compliance engine is now a first-class service in the architecture, and if it goes down, withdrawals go down with it.
What's Priced In for Crypto and DeFi
Most of the CTO-level readership already expected MiCA to bite. The Travel Rule was telegraphed for years. What's priced in: the fact that CEXes will freeze funds, request source-of-funds documentation, and share information with authorities when required. Nobody serious in the industry is surprised by that anymore.
What's less priced in, in my view, is the second-order effect on DeFi front-ends and non-custodial services. If a user cashes out from a DeFi position into a compliant exchange, the exchange doesn't care that the funds came from a legitimate liquidity provision. It cares about the on-chain path. Two hops from a sanctioned address is two hops from a sanctioned address, whether or not you touched it knowingly. Any team building a DeFi product that expects users to eventually off-ramp needs to think about path hygiene, not just protocol correctness. The EIP process has spent years standardising how tokens behave; it has spent very little time standardising how they explain their provenance.
Also underpriced: the operational cost of responding to a freeze. When a user gets held up, the exchange typically wants documents. Source of funds. Proof that the counterparty is who they say they are. Screenshots of trading history from another platform. For institutional users moving eight-figure sums, that's a compliance ops workflow that has to exist on both sides. Retail users mostly just give up and eat the loss, which is arguably the worst outcome for everyone.
The SEC's enforcement posture in the US adds another layer, but that's more about securities classification than AML strictly. The Bank Secrecy Act and OFAC do the heavy lifting on the money-laundering side.
Contrarian View
Here's the uncomfortable counter-argument. The risk-based approach, applied at scale by exchanges optimising for their own regulatory survival, is a blunt instrument that catches more good-faith users than actual bad actors. Sophisticated launderers know exactly how heuristics work. They fragment transactions, use fresh wallets, route through chains with weaker analytics coverage. The people who get caught in the net are, disproportionately, users who accepted a P2P payment from someone whose wallet had a bad history two years ago.
The $154 billion figure is real, but the recovery rate on frozen funds tied to actual criminal proceedings is a small fraction of the total value that gets held up in AML review each year. The rest is friction, imposed on legitimate activity, to satisfy a regulatory posture that measures effort rather than outcome. That's not an argument against AML. It's an argument that the current implementation is closer to security theatre at an airport than to targeted investigation, and the industry rarely says so out loud because saying so out loud draws regulator attention nobody wants.
Key Takeaways
- The $154 billion Chainalysis figure for 2025 illicit-linked receipts is the political justification for every freeze policy currently in production.
- An "AML freeze" is four different actions bundled under one term: deposit hold, withdrawal suspension, document request, or account restriction. Knowing which one you're facing determines the response.
- MiCA and Regulation (EU) 2023/1113 in the EU, plus the Bank Secrecy Act, FinCEN, and OFAC in the US, are the frameworks setting the floor. FATF Recommendations 15 and 16 set the global baseline.
- There is no single AML rating for a wallet. Pre-checking helps but doesn't insulate you, because every exchange weights its own risk model differently.
- Passing KYC once is not the end of scrutiny. Behavioural monitoring is continuous, and drift from your established pattern is itself a trigger.
Back to the bouncer with the clipboard. He isn't going to get smarter overnight, and the list of names he's checking against is only going to get longer. The realistic job for engineering teams and users alike is to understand how he thinks, keep your own paperwork tidy, and accept that occasionally the queue is going to move slowly through no fault of your own. That's the cost of the door staying open at all.
Frequently Asked Questions
Q: What actually triggers an AML freeze on a crypto exchange?
Usually one of two things: a link between your transaction and a high-risk or sanctioned address, or account behaviour that differs from your established pattern. A single risk indicator doesn't prove wrongdoing, but it's enough to trigger a deeper review that a user experiences as a freeze.
Q: Can I check a wallet's AML rating before sending funds?
You can pre-check an address against public analytics tools to spot obviously risky transaction history, but there is no single universal AML rating. Different exchanges and analytics providers weight risk factors differently, so a wallet clean on one platform may still be flagged on another.
Q: Does passing KYC mean I won't get frozen later?
No. Successful KYC verification confirms your identity at that moment but does not stop the exchange from analysing your subsequent activity. Monitoring is continuous under the risk-based approach that regulators like FATF, MiCA, and FinCEN require.
Solana Pulls $348M in RWA Flows, Still 4x Behind Ethereum
Solana captured $348M in RWA net flows over 30 days and now hosts $4.23B in tokenized assets. Ethereum still holds $17.2B, more than 4x the stock.
Robinhood's L2 Bet: What Platform Leads Should Ask This Week
Robinhood's move into its own blockchain reframes the build-vs-buy question for every fintech platform lead weighing Solana, Ethereum, or a rolled L2 in 2026.
Ethereum Gas at 5-Year Low: The L2 Revenue Problem
Ethereum median gas fees hit 1.9 gwei, a 98% drop from March. The technical win is real. The revenue model underneath it is starting to crack.




