Unlicensed exchanges and nested services

LayeringIntegrationCryptoModern

How do unlicensed crypto exchanges and nested services launder money?

An unlicensed exchange lets people trade and cash out crypto without registering with regulators or checking who its customers are. A nested service is a smaller business that operates through a large exchange's deposit addresses, so the exchange sees one account while many hidden customers sit behind it. Criminals use both to convert illicit coins into cash or clean assets.

As of September 2026: Sanctions lists, seizures and indictments in this area change often. The Garantex indictment was unsealed in March 2025; no conviction of the defendants was found in this review. Successor services and their status may have changed since the OFAC action of August 14, 2025.

What are unlicensed exchanges and nested services?

Most crypto exchanges that serve people in the United States or Europe are regulated. They register, verify customers, screen transactions, and report suspicious activity. That makes them the choke point where crypto meets bank accounts and cash. An unlicensed exchange is one that operates without that registration or licensing, and usually without real identity checks. Its customers get a place to swap and cash out where nobody asks who they are or where the money came from.

A nested exchange or nested service is a different animal. It is a business built on top of a larger exchange. Chainalysis describes such services as ones that use a big exchange’s deposit addresses to reach its liquidity and trading pairs. Most nested services are legitimate: over-the-counter brokers are the common example. The problem is the ones that are not. The host exchange sees deposits into one account. The people and businesses behind that account, and where the funds came from, are invisible to it.

Both belong to layering and, at the end of the chain, integration, because they turn crypto into something spendable. The other crypto techniques on this site, like chain-hopping and mixers, move value around. These are the doors that let it leave.

How do unlicensed exchanges and nested services work?

  1. Light or no onboarding. A rogue exchange advertises quick sign-up. FinCEN’s list of red flags for kiosk businesses includes advertising that customers can transact with no ID, or with only a phone number or email address. The same pattern applies to online platforms. Where verification exists on paper, it may not be enforced.
  2. Hidden or borrowed infrastructure. A rogue exchange may run from a jurisdiction with weak supervision. A nested service instead borrows a legitimate exchange’s infrastructure by using its deposit addresses, which means the host’s compliance team cannot easily tell who is who.
  3. Volume. Criminals send proceeds from ransomware, darknet markets, scams, or sanctioned sources in bulk. Treasury said Suex’s history included at least eight ransomware variants and that more than 40 percent of its transactions involved illicit actors.
  4. Cash-out. The platform converts coins to another asset or to fiat, often through a partner gateway, a payment processor, or an over-the-counter desk. The related pages on stablecoins and OTC brokers cover that leg in more detail.
  5. Re-emerge. If the platform is sanctioned or seized, the same people may relaunch under another name. Treasury said this is what happened between Garantex and Grinex.
Two routes from crypto proceeds to cash without identity checks Criminal proceeds either pass through a nested service that uses a large exchange's deposit addresses, or go straight to an unlicensed no-KYC exchange that cashes out through an offshore gateway, while regulators sanction, seize or indict the rogue venue. coins sent in uses host's deposit address or direct to no-KYC venue cash-out via gateway withdrawal fiat out fiat out sanction, seize, indict Ransomware or fraud proceeds OFAC, FinCEN, DOJ Nested service (hidden customers) Unlicensed no-KYC exchange Large host exchange Offshore fiat gateway Bank account Clean funds
The nested route hides customers behind a real exchange. The rogue route needs no host at all.

Why do unlicensed exchanges and nested services work?

Regulation applies where the entity is, not where the customer is. An exchange incorporated in a country that does not enforce anti-money-laundering rules can serve customers anywhere. The international standard setter, the FATF, has pushed countries to license and supervise crypto businesses, and its July 2026 update on virtual assets reportedly flags offshore unlicensed platforms as a continuing risk. But gaps remain, and those gaps are the market.

Demand is concentrated. Criminals need to convert large sums fast and safely. The right nested service or rogue exchange gives them scale. Chainalysis found that in 2022 four exchange deposit addresses alone received just over $1 billion in illicit funds, and that a small group of nested services facilitate the majority of crypto money laundering. That concentration is a weakness for criminals too, because it gives investigators a short list to watch.

The host cannot see through the account. A large exchange applies its controls to its own customer. If the customer is a nested service, the exchange may know only the service, not the service’s users. That gap is what makes a nested service useful to a criminal and hard for the host to police.

Weak controls can be disguised. FinCEN warns that non-compliant operators may tell banks and exchanges they are registered while failing to run the required controls. In the Garantex indictment, prosecutors said that when Russian authorities asked for records on an account tied to a co-defendant, Garantex gave incomplete information and falsely said the account was not verified.

Real cases: Suex, Garantex and Grinex

Suex. On September 21, 2021, the Treasury’s Office of Foreign Assets Control designated Suex OTC, S.R.O., calling it the first sanctions designation of a virtual currency exchange. It acted under an executive order aimed at supporting ransomware actors. Treasury said at least eight ransomware variants had transacted through Suex and that more than 40 percent of its known transaction history was linked to illicit actors. Everything Suex owned that touched the US was blocked, and Americans were barred from dealing with it.

Garantex. OFAC sanctioned Garantex on April 5, 2022 under an order about Russia’s financial services sector. It kept operating. In March 2025 the US Secret Service, working with German and Finnish authorities, seized the exchange’s web domains, froze more than $26 million, and obtained copies of servers holding customer and accounting databases. It said Garantex had processed at least $96 billion in crypto since April 2019. An indictment unsealed in the Eastern District of Virginia charged Aleksej Besciokov, whom it called the exchange’s primary technical administrator, and Aleksandr Mira Serda with conspiracy to commit money laundering. Besciokov was also charged with conspiracy to violate sanctions law and to operate an unlicensed money transmitting business. Those are allegations.

Grinex. Treasury said Grinex was created after the March 2025 disruption to continue Garantex’s business and take over customer deposits. Customers who lost access to funds were given the A7A5 token, a ruble-backed digital asset issued by a Kyrgyz firm named Old Vector. On August 14, 2025 OFAC sanctioned Grinex, the co-founder Sergey Mendeleev, Mira Serda, another Garantex co-owner named Pavel Karavatsky, and companies including Old Vector and InDeFi Bank. Treasury said Garantex had processed over $100 million in transactions linked to illicit activity since 2019, including millions from ransomware groups.

Beyond exchanges. The same logic reaches the big platforms. See the case pages on Binance and on the Huione and Prince Group networks for how regulators treated an exchange that did not register as a money services business and a payments group that FinCEN said laundered at least $4 billion.

How does it get caught?

Sanctions and designation. OFAC’s actions make every dealing with a named exchange a possible violation, and blockchain analytics firms then label its addresses so banks and other exchanges can block them. Grinex shows the limits: designation of a successor comes months after the original problem.

Law enforcement takedowns. Seizing domains and copying servers, as in the Garantex operation, turns a “no logs” promise into an evidence trove. It also gives investigators the customer and accounting databases they could not get from anyone else.

Analytics that see nested accounts. Because a small group of nested services handle much of the laundering, analytics firms such as Chainalysis label their deposit addresses. That lets an exchange spot a customer that is really a service, and lets investigators tell one business’s flows from another’s.

Bank and exchange due diligence. FinCEN’s guidance says financial institutions should check whether a customer is registered as a money services business and holds required state licenses, and should look at whether the customer collects identification. These are the same detection habits that catch other unregistered money transmitters.

Travel Rule and standards. The Travel Rule requires virtual asset providers to pass sender and receiver details along with transfers. Unlicensed services sit outside that system, so transfers from regulated venues to unlicensed ones draw attention.

Frequently asked questions

What makes a crypto exchange 'unlicensed'?

In the US, a business that exchanges or transmits crypto for customers is generally a money services business. It must register with FinCEN, run an anti-money-laundering program, verify customers and report suspicious activity. An exchange that operates without registering, or without the state licenses that apply, is unlicensed. Operating an unlicensed money transmitting business is itself a federal crime.

What is a nested service?

It is a business that sits inside a bigger exchange, using the big exchange's deposit addresses to reach its liquidity and trading pairs. Most nested services, such as over-the-counter brokers, are legitimate. But Chainalysis found that a small group of them account for most crypto money laundering, because the host exchange sees one account rather than the many customers behind it.

Why do sanctioned exchanges keep coming back under new names?

The customers, balances and staff are what have value, not the brand. Treasury said Grinex was created by Garantex employees right after Garantex was disrupted in March 2025, and that users were given the A7A5 token to regain access to their funds. Sanctioning the successor and its executives is how authorities respond.

Are the Garantex charges resolved?

Not as of September 2026, so far as this review could confirm. The indictment against Aleksej Besciokov and Aleksandr Mira Serda was unsealed in March 2025. The US Secret Service wanted page for Besciokov lists him as a fugitive, and no conviction of either defendant was found. An indictment is an accusation, not a finding of guilt.

Cases that used this technique

  • Binance · The world's largest crypto exchange pleaded guilty to AML and sanctions failures and paid about US$4.3 billion, and its founder was later pardoned.
  • Huione and Prince Group · A Cambodian financial group and a conglomerate tied to forced-labor scam compounds drew the largest sanctions and forfeiture actions ever aimed at Southeast Asian scam networks.

Related techniques

  • Stablecoins and OTC brokers · Moving illicit value through dollar-pegged stablecoins (above all USDT on Tron) and converting it to cash through over-the-counter brokers and guarantee marketplaces with little or no KYC.
  • Chain hopping and cross-chain bridges · Swapping illicit crypto across blockchains through bridges and no-KYC swap services so that no single chain's analytics tell the whole story.
  • Mixers, tumblers, and CoinJoin · Services that pool many users' coins and pay out equivalent amounts from the pool, breaking the on-chain link between where crypto came from and where it went.
  • Sanctions evasion · Hiding who really owns or benefits from assets and payments so sanctions do not bite, using many of the same tools as money laundering but often with lawfully earned money.
  • Crypto ATMs and peer-to-peer trades · Turning cash into cryptocurrency at a kiosk or with a peer-to-peer trader, so that dirty cash or scam payments land in a wallet the criminal controls.
  • Currency exchanges and MSBs · Using currency exchange houses, remitters, and other money services businesses to convert and send cash abroad, either through complicit operators or through firms whose controls are too weak to notice.

Glossary

Sources

  1. Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs (Financial Action Task Force, July 2026).
  2. Treasury Sanctions Cryptocurrency Exchange and Network Enabling Sanctions Evasion and Cyber Criminals (US Department of the Treasury, August 14, 2025).
  3. Treasury Takes Robust Actions to Counter Ransomware (Suex designation) (US Department of the Treasury, September 21, 2021).
  4. US Secret Service seizes Russian cryptocurrency exchange websites (US Secret Service, March 6, 2025).
  5. Aleksej Besciokov (most wanted) (US Secret Service, accessed September 2026).
  6. Four Exchange Deposits Received +$1B in Illicit Funds in 2022 (nested services analysis) (Chainalysis, January 26, 2023).
  7. FinCEN Notice on the Use of Convertible Virtual Currency Kiosks for Scam Payments and Other Illicit Activity (FIN-2025-NTC1) (US Department of the Treasury, FinCEN, August 4, 2025).
  8. Huione Group Final Rule (Section 311) (US Department of the Treasury, FinCEN, October 2025).