Fraud Doesn't Start on Crypto Exchanges, So Why Do They Carry the Burden?

Arturs Linde, Head of Fraud Prevention at Paybis, discusses why crypto exchanges are the last line of defense against fraud and why that's unsustainable.

Fraud Doesn't Start on Crypto Exchanges, So Why Do They Carry the Burden?

The economics of online fraud have changed faster than the systems designed to stop it. A decade ago, running a convincing investment scam required technical expertise, time, and infrastructure. Today, AI-generated websites, cloned voices, phishing kits, and fake identity documents can all be purchased or created at minimal cost. Criminals no longer need advanced technical skills to operate at scale. They need automation.

Last year, scammers stole $17 billion in crypto using tools that cost $15 and an afternoon. In 2025, fraudsters stole $2.87 billion across nearly 150 hacks, which is fewer incidents than last year, but the Bybit breach alone accounted for $1.46 billion (51%) of the increase in total losses. 

We're dealing with industrialized fraud, not masterminds, and exchanges are quietly picking up the bill alone.

The result is an arms race that increasingly favors attackers. Fraud campaigns can be launched in hours, adjusted in real time, and replicated almost endlessly. Every improvement in generative AI lowers the cost of convincing deception while increasing the number of potential victims.

For crypto exchanges, that shift has created an uncomfortable reality in which they have become the industry's last line of defense. That expectation is becoming impossible to meet alone.

Crypto exchanges face two fundamentally different risks

For years, exchanges invested heavily in identity verification. The assumption was straightforward: if you could reliably verify who was entering your platform, you could significantly reduce financial crime.

That assumption still holds, but today's threat landscape is more complex because exchanges are dealing with two very different problems: fraud against the platform and fraud conducted through it.

Fraud against an exchange targets the platform itself. Criminals open accounts using stolen identities and AI-generated faces, then use them to take over legitimate customer accounts through phishing or SIM swapping. They use these accounts to purchase crypto with stolen payment credentials or abuse referral and promotional programs through networks of linked accounts.

Fraud conducted through the exchange is a different challenge. The customer and the transaction seem legitimate, while the exchange is unknowingly being used as part of a much larger fraud the whole time. For example, a money mule may receive funds from multiple unrelated parties before converting them into crypto, and criminal groups may use verified accounts to layer proceeds, evade sanctions screening, or move funds between fiat and crypto.

Treating both as one problem leads to the wrong controls.

Fraud directed at the exchange can often be stopped with stronger identity verification, device intelligence, payment risk analysis, and account takeover detection. Fraud conducted through the exchange is much harder to fight because the customer may appear entirely legitimate.

Modern fraud prevention increasingly depends on continuous monitoring because of this. Behavioral monitoring can detect when account activity suddenly changes. Device intelligence can identify suspicious login environments. Session monitoring is more important than ever because it can uncover signs of account takeover long after an identity has been verified.

Building and maintaining those systems, however, is expensive. Large global exchanges continue putting a lot of money into increasingly sophisticated defenses, while mid-sized platforms face a much harder calculation. Fraud prevention has evolved into an infrastructure challenge that very few companies can solve independently.

Exchanges didn't create the fraud, but they inherit the responsibility

The exchange then becomes the final checkpoint before funds leave the regulated financial system. The situation creates two separate responsibilities.

From a fraud perspective, on the one hand, the exchange has to determine whether a customer is acting under manipulation, whether an account has been compromised, or whether the user is knowingly participating in abusive activity.

From a compliance perspective, on the other hand, the exchange must assess whether the transaction may involve money laundering, sanctions exposure, mule activity, illicit counterparties, or other suspicious movement of funds.

Those decisions require different data, teams, and technologies, but they all arrive at the exchange, regardless of where the criminal activity actually started.

Regulation alone can’t stop fraud

The regulatory landscape for digital assets has matured considerably over the past several years. Jurisdictions around the world have introduced stronger AML requirements, licensing regimes, and customer due diligence obligations. These measures make regulated providers more accountable and make it harder for illicit funds to move through legitimate businesses.

However, regulation is still uneven. Rules vary across countries, and regulation alone cannot prevent every type of fraud. Its impact depends on effective supervision, enforcement, international cooperation, and how quickly firms update their own fraud controls.

Fraud methods evolve fast, especially as criminals take advantage of AI and new technologies, new payment methods, and regulatory differences between markets. That’s why regulation must be supported by adaptable fraud controls instead of being treated as the complete solution.

Continuous monitoring is now becoming just as important as onboarding. Identity verification is still essential, but it’s no longer enough on its own.

Companies increasingly need to monitor customer behavior, transactions, devices, and wallet activity long after an account has been opened. Their controls must also be flexible enough to respond to emerging fraud patterns and changing criminal tactics. When there’s suspicious activity, firms must be able to investigate quickly, apply additional verification, delay or block high-risk transactions, and update their detection models before the same technique can be repeated at a larger scale.

All of this shows how dramatically the threat landscape has changed.

Attackers continue to collaborate, share tools, and commercialize fraud-as-a-service models that lower barriers for new criminal groups. Defenders, on the other hand, remain fragmented.

Fraud requires a shared defense

Other industries have already begun recognizing that fraud cannot be treated as a responsibility of a single participant.

In countries such as the UK and Australia, policymakers have increasingly moved toward frameworks that distribute fraud prevention responsibilities across banks, payment providers, and digital platforms rather than concentrating liability in one place. Crypto should be moving in the same direction.

If scams routinely begin on social media platforms, those platforms should play a greater role in identifying fraudulent advertising and coordinated scam networks. If messaging services are repeatedly used to facilitate investment fraud, they should be part of broader disruption efforts. Payment processors and card schemes—including global networks such as Visa and Mastercard—also possess transaction intelligence that can strengthen fraud prevention.

The crypto industry itself also has opportunities to collaborate more effectively.

Cross-platform intelligence sharing could help identify fraudulent wallets before stolen funds move through multiple exchanges. Industry-wide standards for detecting AI-generated identities would reduce duplicated effort while strengthening overall resilience. Closer cooperation between exchanges, blockchain analytics providers, regulators, and law enforcement would make investigations faster and more effective.

None of these measures eliminates fraud, but together, they make it significantly harder for criminals to exploit the gaps between organizations.

Fraud prevention should be a collective responsibility

Fraudsters already operate as an ecosystem. They move seamlessly between advertising platforms, messaging apps, payment networks, and digital assets, taking advantage of every disconnect between industries.

Crypto exchanges will remain one of the most important safeguards protecting users. They should continue investing in stronger verification, continuous monitoring, and better fraud detection. But expecting exchanges alone to compensate for failures that occur across the wider digital economy is neither practical nor sustainable.

Fraud prevention will depend less on building another defensive layer inside individual exchanges and more on recognizing that fraud prevention is a shared responsibility. Social platforms, messaging services, payment processors, card networks, regulators, law enforcement, and crypto businesses all see different parts of the same attack chain.

The industry doesn't need another isolated line of defense: it needs those lines to connect.

Be one step ahead of fraudsters

Try Sumsub Fraud Prevention and protect your business from the newest types of fraud

Book a demo
Be one step ahead of fraudsters