These combined factors can attract both privacy-focused investors eager to gamble on favourable cryptocurrency market trends and also lure fraudsters who hope to hide their identities while conducting financial crimes. The cryptocurrency frenzy is further creating a lucrative environment in which cybercriminals can carry out their schemes.
Balancing fraud-fighting without intimidating real customers
Fraudsters’ abuse of cryptocurrency is not a new phenomenon. Between 2011 and 2021, criminals operating worldwide reportedly scammed users out of nearly $5 billion worth of cryptocurrency and stole another $3 billion through security breaches, according to Pyments.
The regulatory requirements facing the exchanges that facilitate the purchase and trade of these tokens have been evolving in recent years, partly in response to growing concern over fraudsters’ efforts.
Many crypto exchanges around the world still have relatively lax security measures, however, which could put them and their users at greater risk. Many consumers are interested in cryptocurrencies for legitimate reasons but may be wary of platforms that put them at risk of unwittingly trading with scammers.
The cryptocurrency sector's security challenges
Transactions made with digital assets are tracked and recorded on the blockchain, but users themselves remain anonymous by trading under pseudonyms and usernames. This opacity can make it easier for criminals to onboard and scam unwitting victims or conduct money laundering.
Cryptocurrency transactions are also irreversible, meaning that victims may have no recourse should they be tricked into sending digital tokens to fraudsters. Factors like these — plus the currently high value of many cryptocurrencies — make the space tempting for bad actors.
Exchanges that want to gain legitimate users’ trust must prove that it is safe to transact without introducing frictions that turn customers off, and each platform must find an approach that suits its unique customer base.
Some platforms may feel that they cannot simply copy the Know Your Customer (KYC) playbooks of their traditional, regulated financial institution counterparts without modifying the nature of their offerings. Users may therefore be reluctant to hand over many of the personally identifying details typically collected in financial institutions' customer verification processes.
Crypto exchanges recognize that many cryptocurrencies are also subject to rapid value fluctuations, and customers often want to be able to trade quickly so they can take advantage of current prices. This puts the obligation on platforms to handle their verification and security checks swiftly to avoid making users suffer through painful delays.
What types of ID verification checks can crypto exchanges rely on?
Crypto platforms are adopting a variety of strategies for confirming customers’ identities while providing compelling experiences. Some exchanges may ask new customers to proceed through light initial onboarding processes but then require deeper ID verification before taking more financially risky actions, increasing the amount of identifying information that customers must provide as the value of their deposits and withdrawals rise.
Platforms may use contextual onboarding in which they allow customers to onboard without going through any identity verification but enable only very limited functionalities while customers who provide photo IDs may be permitted to conduct low-level withdrawals and deposits and full KYC adherence may allow users to transfer, deposit or withdraw significant sums.
Other exchanges seek to build trust by requiring all new customers to pass through robust KYC procedures right off the bat, including any or all of the following:
- Background searches
- Checks against sanction lists
- Verification of government-issued IDs
- Live phone calls
Each platform must determine the customer verification approach that best suits its business model and complies with local regulations.
Why crypto exchanges have an advantage in identifying fraud in real-time
Cryptocurrency platforms can also look out for red flags that — if detected and acted upon — allow them to nip fraud in the bud. Detecting when a customer signs up using one name while uploading funds from bank accounts bearing a different name can ring alarm bells. So can the detection of users with IP addresses that have been associated with suspicious activities in the past.
Such occurrences can prompt crypto exchanges to intervene or monitor the accounts more closely as they work to determine whether criminal activity is underway or if the events are simply false positives.
Platforms can work to improve the precision and accuracy of their fraud detection measures as well by monitoring and analyzing transactions in real-time for fraud indicators. Automation-powered solutions can help make this rapid-fire analysis possible and support firms in identifying potential fraud even earlier.
Furthermore, crypto exchanges are the target of a new hard-to-detect type of identity fraud that is commonly known as "synthetic fraud", also known as "deep fakes". Synthetic fraud is mass-scale identity fraud that creates "deep fakes" that are nearly impossible for the human eye to detect. This presents a major challenge as synthetic identities are created with advanced computer software, mixing fake and real information.
Fraudsters can take an image of a person and manipulate it and create multiple new images that change facial features. Fake IDs are created 'production-line style' – hundreds or even thousands at a time.
Crypto exchanges are especially vulnerable to synthetic fraud attacks because they are considered the weak link in the financial chain – easier to trick than institutional banks.
What crypto exchanges should look for in ID verification
Cryptocurrency advocates seeking more widespread adoption of private tokens must also address the balance between fighting fraud and user anonymity.
The best identity verification solutions should comprise the following elements in order to fulfill the unique requirements of the cryptocurrency sector:
- 100% automation – Crypto exchanges will lose customers if they offer slow new customer onboarding which requires human intervention
- Synthetic fraud detection – Crypto exchanges are the targets of financial fraud and require a high level of identity fraud detection capabilities.
- Selfie liveness – Verify that a selfie is indeed a live image and compare it to photo IDs.
- Customization – As regulation and ID verification requirements evolve, crypto exchanges need a solution that is tailor-made for their current needs and is easily adjusted when verification rules are changed.
Serving cryptocurrency users’ security and convenience needs – now and in the future – requires exchanges to explore revamping their customer authentication toolkits. Powerful automated identity verification tools can help platforms keep onboarding seamless while enabling them to catch and thwart potential fraud and build trust with regulators and legitimate users alike.
New ID verification strategies and technology developments are also likely to continue to promote innovative ways of meeting regulators’ security demands and users’ privacy desires.
Written by Doron Mutsafi, Chief Customer Success Officer, AU10TIX