The conventional wisdom says cryptocurrency firms need to "get serious" about fraud detection and adopt the same controls traditional banks use. FinCEN recently reported $12.7 billion in cryptocurrency investment scam losses, reinforcing this view. The Treasury Department wants better scam reporting, and the regulatory conversation keeps circling back to crypto platforms as the weak link.
But here's what that framing misses: traditional banks detected $6.4 billion in potential fraud in the same period, and they only spotted it when victims were already deep into the scam lifecycle, sending wire transfers or liquidating retirement accounts. The problem isn't that crypto firms lack controls. It's that banks and crypto platforms each see half the picture, and neither can act on what they can't see.
The Visibility Problem
The "crypto needs better controls" argument treats this as a technology problem when it's actually a visibility problem. Traditional financial institutions told FinCEN they "often detected schemes when a victim sent funds to a financial institution in the digital asset sector to purchase digital assets." By that point, the scammer has already spent weeks or months building trust, the victim has made the decision to invest, and the money is moving.
Crypto firms, meanwhile, reported $5.5 billion in suspected scam activity, but they're seeing the transaction after the bank approved the initial transfer. One platform can't tell whether a $640,000 retirement fund withdrawal is legitimate retirement planning or the result of a romance scam that started on social media.
The conventional wisdom assumes each sector should independently build better detection. What we actually need is for both sectors to share what they're seeing in real time. Banks know the victim's baseline behavior and can spot unusual liquidations. Crypto platforms see the destination patterns and can identify scam-affiliated wallets. Neither institution has the full context alone.
The Evidence
FinCEN's analysis of over 33,000 incident reports shows exactly where the visibility gaps create risk. The agency noted that "typically financial institutions only had visibility into one phase of a scam's lifecycle." That's not a compliance failure; it's a structural limitation.
Consider what banks can see: A customer who's held steady account balances for years suddenly applies for a home equity line of credit, gets denied for a personal loan twice, and then withdraws $150,000 from a retirement account. That's a clear behavioral anomaly. But without knowing the customer is communicating with a romance scammer who's positioning this as a "digital asset investment," the bank might interpret it as poor financial planning rather than fraud in progress.
Crypto platforms see different signals: Multiple deposits from the same individual over compressed timeframes, immediate conversion to USDT (which scammers almost always use for laundering), and transfers to wallet addresses that match known scam patterns. But they don't know whether the customer liquidated a 401(k) or took out a second mortgage to fund those deposits.
The report documents cases where victims submitted loan applications as part of scam participation. Those applications went to traditional lenders who had no visibility into the crypto wallet receiving the eventual funds. The crypto platform processing the deposit had no visibility into the loan origination that funded it.
When each institution only files a Suspicious Activity Report after seeing its piece of the pattern, law enforcement gets fragmented intelligence. FinCEN received nearly 11% more reports each month compared to the prior month, which sounds like improved detection until you realize it also means scammers are successfully scaling operations faster than detection capabilities.
What to Do Instead
Start with transaction correlation, not just transaction monitoring. If your institution serves as the fiat on-ramp or off-ramp for digital asset activity, you need real-time data sharing agreements with the crypto platforms your customers use most frequently. This isn't about regulatory reporting after the fact; it's about operational intelligence while the scam is active.
Build cross-sector fraud consortiums that share wallet addresses, beneficiary account patterns, and behavioral indicators. The sanctioning of Xinbi Guarantee (which laundered over $36 billion) happened after scammers had already migrated from the previously disrupted Huione platform. That migration was visible to crypto firms tracking on-chain flows, but traditional banks had no mechanism to receive those early warnings.
Implement behavioral triggers that account for cross-platform activity. When a customer requests multiple loan products in rapid succession and references "digital asset investments," that should trigger outreach before the funds move, not a SAR filing three days later. Your fraud detection rules need to recognize that retirement account liquidations followed by same-day wire transfers to crypto exchanges represent a different risk profile than liquidations followed by reinvestment in traditional securities.
Require transaction purpose disclosure at the point of unusual activity, not just at account opening. When a customer who's never mentioned cryptocurrency suddenly wants to wire $100,000 to a digital asset platform, a brief conversation can distinguish between informed investing and active victimization. The report notes that some victims only realized they were in a scam when asked to pay "fees" to recover their funds, but banks had already processed multiple withdrawals by that point.
Crypto platforms need to implement deposit source verification. If you're receiving large transfers from customers who've recently opened accounts, who are liquidating retirement funds, or who are taking out loans specifically to fund crypto purchases, those deposits warrant enhanced due diligence before processing. Your KYC process should capture not just identity verification but funding source legitimacy.
The Right Controls
Crypto platforms do need stronger controls, just not the controls everyone keeps demanding. Digital asset firms should implement robust transaction monitoring, maintain comprehensive audit trails, and file SARs when they detect suspicious patterns. FinCEN's analysis shows crypto firms are filing reports, which means detection capabilities exist.
Emerging technologies create new fraud vectors. Scammers exploit the speed of blockchain transactions, the perceived anonymity of digital assets, and the knowledge gap between victim sophistication and platform complexity. Crypto firms that don't invest in fraud detection infrastructure are leaving their customers vulnerable.
Where the conventional wisdom breaks down is in assuming that better controls within each sector will solve a problem that spans both sectors. You can't solve a visibility problem by improving what you do with partial information. You solve it by sharing intelligence across the visibility gap.
The report found victims across all 50 states and U.S. territories, with adults over 60 accounting for about 25% of cases, meaning 75% of victims are younger demographics who supposedly understand technology better. That distribution suggests the problem isn't customer education or platform security in isolation. It's the structural gap between where trust is built (social media, messaging apps), where funds originate (traditional banks), and where they're converted (crypto platforms).
Until banks and crypto firms treat each other as necessary partners in fraud detection rather than separate regulatory domains, scammers will keep exploiting the seam between them. The $12.7 billion in losses isn't a crypto problem or a banking problem. It's a collaboration problem.



