Identity Verification and KYC for Cryptocurrency Exchanges;

Cryptocurrency exchanges are magnets for fraudsters – and regulators.

Let’s learn how to beat the former and appease the latter with better crypto KYC and identity verification tools. 

What Is Identity Verification & KYC in Crypto?

KYC, or Know Your Customer, refers to the legal requirement for certain types of businesses to verify their users’ identities. It is designed to reduce fraud, money laundering, and other illicit activities. 

With their inherent relationship with money and pseudonymous digital assets, crypto exchanges are particularly targeted by fraudsters and criminals, which is why governments have imposed growing KYC and identity verification regulations in recent years.  

However, KYC is still seen as an unwelcome obstacle by crypto exchanges and crypto enthusiasts. A 2019 report by the regtech Coinfirm claimed that 69% of crypto businesses did not have “complete and transparent” KYC procedures. 

Challenges and Risks of IDV & KYC for Crypto Exchanges

Even with the best of intentions, crypto exchanges face an uphill battle when it comes to KYC.

Here are four reasons why:

  1. A plethora of fake ID types: Fraudsters are aware of KYC procedures and have plenty of weapons at their disposal. From synthetic IDs to deepfake videos, it’s easier than you might think to be accepted on a crypto exchange using a fake profile.
  2. The need to balance friction and security: Users want quick access to the markets – especially when they’re as volatile as crypto. So if you put too many obstacles in the way at the onboarding stage, you risk increasing churn and losing potential loyal customers in the long run.
  3. Going against crypto ideals: Enthusiasts often regard crypto as an innovative technology that shouldn’t be subjected to the same rules as traditional financial institutions. Unfortunately, regulators see it differently, which is why you, as a crypto exchange, might have to sweeten the deal when asking users to submit official documents. Many crypto exchanges, for instance, offer special deals for users who complete the KYC process.
  4. Last but not least are compliance fines. Fail to deploy the right KYC checks and you could be on the hook for a hefty fine.

It’s not just crypto exchanges that are under growing scrutiny from regulators either, but many more crypto-related companies. In 2020, for instance, a crypto tumbler was fined $60M for failing to meet AML requirements.

crypto reward

A reward offered by a crypto exchange for completing the KYC process.

What Does KYC Look Like for Crypto Exchanges?

In concrete terms, KYC (which is closely linked to AML), will take on the form of identity verification (IDV). You will usually check for:

  • a full name
  • a residential address
  • date of birth
  • an ID document confirming the above

How you perform these checks will depend on your KYC software capabilities. Then, there are internal risk management processes, such as:

  • writing a Customer Acceptance Policy (CAP)
  • creating a Customer Identification Program (CIP)
  • training staff and laying out your risk management procedures

You can read more in our more general AML checklist here.

How Can Crypto Exchanges Perform KYC/IDV Checks?

Whether the KYC and identity verification tools are integrated from third-party software or deployed locally, crypto exchanges will tend to use four types of checks:

holding IDs

1. ID Selfie and Video Verification

Anyone who’s had to open an important online account lately will be familiar with video verification. It’s quickly becoming the norm for a number of financial services and products and is increasingly popular with crypto exchanges. 

The pros?

A new generation of identity verification software vendors makes it easy to integrate this kind of software into your platform as part of the onboarding process. 

Unfortunately, there are a number of downsides, too.

Firstly, it adds a ton of friction to the customer journey. Not only does the user have to locate a relevant ID document, but they also have to submit the image or video according to strict algorithmic requirements, which often takes multiple tries and significant time commitment (light level, no flare, right angle…). 

Then there is the issue of falsification. It is becoming increasingly affordable to create a deepfake video. Photoshopping ID services is so prevalent that a quick Google search will point you in the direction of dozens of websites.

Last but not least, these checks are expensive. Each automated document check is estimated to cost $2 on average.

2. Digital Footprint Analysis

An alternative comes from digital footprint analysis.

Digital footprint analysis allows companies to learn more about users based on hidden digital and social signals. It works by gathering data around things like an email address, IP address, phone number, or the kind of browser and device used to connect to a site.

This is much harder for fraudsters to falsify, and such efforts bring little RoI.

The fact is, legitimate consumers are much more likely to have a digital footprint than criminals.

This can make all the difference when you’re separating the wheat from the chaff and looking to stop bad actors from reaching the full KYC/IDV stage.

Here’s the thing with digital footprint analysis: It won’t replace a KYC check. But there are multiple reasons why crypto exchanges such as Xcoins rely on it on a daily basis – and not just for identity verification:

  • It can reduce KYC costs by blocking access to bad actors.
  • It is completely frictionless as it relies on information the consumer has provided already.
  • It can prevent various types of fraud, including account takeovers.
  • It can work in tandem with KYC solutions, as an extra defense.
  • It reduces overall risk to both the platform and its users.

Let’s look at an example below, using three types of data enrichment.

IP Lookup for Digital Footprint Analysis

IP Lookup for digital footprint analysis

By running an IP data enrichment check, we found that the user is connecting via a datacenter proxy, which increased our risk score. 

An email check lets us know that the user has a few social media accounts, but not a heavy online presence. 

Email Lookup for Digital Footprint Analysis

email lookup for digital footprint analysis

Based on the email address only, we can see that the user has an online presence.

Even if they are not registered on many social sites, the footprint appears consistent with what we’d expect, with registered accounts on Twitter, Instagram, Facebook, etc.

BIN Lookup for Digital Footprint Analysis

The credit card BIN lookup, however, highlights some potentially troubling information.

Why is it registered in the US when the IP points to Australia? And why did the CVV not work?

Armed with all the information above, we can now get a better picture of who we’re dealing with. This is what we call digital footprint analysis. 

And, in this case, you should have reasonable doubts at this stage, and possibly conclude that the user should not go through with a KYC check on your crypto exchange – as it would be a waste of a KYC check or also potentially result in onboarding a fraudster.

Or. at the very least, you should be extra vigilant about the ID details they will give you in the next stages…

3. Manual Checks

Of course, crypto exchanges don’t need to integrate automated KYC software. They can also verify IDs manually against databases. 

Unfortunately, there are few advantages to the method, except maybe if you only verify a very low volume of IDs. The accuracy rate doesn’t improve, it’s not scalable, and the pressure on your manual review team will only get worse with time.

4. Blockchain ID Validation

Finally, a fairly new proposition in the world of ID verification is using the power of blockchain technology. There are certainly a number of advantages – in theory at least. Since blockchain tech is at the core of the Web 3.0 ecosystem, it might be an attractive solution for crypto enthusiasts who value their anonymity

Blockchain IDs have also been shown to deliver excellent results in terms of affordability and efficiency. A study by Finextra, for instance, revealed that HSBC experimented with KYC blockchain successfully in the UAE in 2021.

Blockchain KYC is still new, though – which is one of its major drawbacks. Until the technology is adopted by the masses, you may struggle to find one good service that has enough ID data to validate users from around the world. 

And, no matter whether this method works, authorities need to explicitly allow this type of KYC in your locale for you to use it to fulfill your legal obligations.

Why Use SEON’s Digital Footprint Analysis for Crypto KYC?

SEON has proven results with crypto exchanges in helping KYC checks and reducing chargebacks due to bad credit card purchases. But when it comes to ID verification, here’s why it works:

  1. It removes all kinds of friction: It’s all real-time data, which you can gather via API.
  2. It saves you money: Crucially, it is a pre-filter to block junk users before performing expensive KYC checks. This means you don’t have to waste your money vetting obvious fraudsters.
  3. It gives you extra intelligence: You can use it to augment your KYC or AML during manual reviews. For instance, even if a user passes the ID verification check, you could still increase your suspicions should they have no social media profiles or hide their connection behind a VPN and emulator – and monitor them more closely.

And that’s before we even mention the flexible 30-day SEON trial and cancel-anytime contracts, designed to let you fight ID fraud however you see fit.

You can give this a try below. Just enter someone’s email address or phone number and you’ll discover their digital footprint and how much it can tell us about whether they are a legitimate customer.

 

If you would like to find out more about how SEON can streamline your crypto KYC efforts, book a demo today.

Cryptocurrency KYC and Crypto IDV FAQ

Why do crypto exchanges ask for KYC?

Crypto exchanges have to verify IDs and perform KYC checks as a legal requirement. They face hefty fines from authorities if they don’t, regardless of where they are based.

Can you buy crypto without KYC?

Yes, you can buy crypto without KYC checks by using peer-to-peer marketplaces. Automated market makers (AMMs) also let you exchange crypto without identity verification. So-called bitcoin ATMs also let you buy multiple cryptocurrencies with cash (for a higher fee). 

What is KYC in crypto?

KYC checks, or Know Your Customer, are identity verification steps that finance-related businesses must make in order to avoid government fines. Crypto exchanges are under heavy scrutiny due to the fact that they tend to attract fraudsters, criminals and money laundering

Sources

  • CoinDesk: Most Crypto Exchanges Still Don’t Have Clear KYC Policies: Report
  • Compliance Week: Bitcoin platform operator fined $60M for AML violations
  • Finextra: HSBC joins UAE KYC Blockchain platform

Share article

See a live demo of our product

Click here

Author avatar
Tamas Kadar
CEO

Tamas is the founder and CEO of SEON and an expert in all the technological aspects of fraud prevention.


Get our latest newsletter

Join over 6000 companies in getting the latest fraud-fighting tips