Sanctuary Compliance Team

P2P cryptocurrency trading is projected to expand significantly in 2026, driven by banking restrictions, emerging market demand, and stablecoin adoption. But the risks are expanding too.
Unprotected P2P merchants lose an estimated 3–8% of monthly volume to fraud. For a merchant trading $200k/month, that translates to $6,000–$16,000 annually in direct losses. Add chargebacks, frozen bank accounts, and compliance penalties, and the true cost can reach 10–15% of revenue.
In 2024, U.S. crypto fraud losses hit $9.3 billion (FBI IC3). Investment scams led at $5.8 billion. P2P fraud, while harder to quantify precisely, is estimated at $1.7–2.5 billion annually according to multiple industry reports.
Regulatory pressure on P2P operators has intensified:
• EU: MiCA fully enforceable since December 30, 2024. CASP licensing required. Grandfathering expires July 1, 2026 — after that, unlicensed operators must cease activity in the EU. • U.S.: The GENIUS Act (signed July 2025) mandates sanctions compliance for stablecoin issuers. The CLARITY Act clarifies SEC/CFTC jurisdiction. OFAC enforcement is at record levels. • FATF: Travel Rule (Recommendation 16) requires VASPs to exchange originator/beneficiary information for transactions above $1,000. • OFAC: The SDN list now contains 1,245 cryptocurrency wallet addresses. $1.8 billion in crypto assets frozen as of Q1 2025.
P2P operators are increasingly treated as money services businesses. Operating without AML controls is no longer a gray area — it's a compliance risk.
Sanctuary offers three integration paths for P2P operators:
• Telegram Bot: use the bot for quick pre-trade triage inside the workflow your operators already use.
• REST API: a single screening request returns a risk verdict, evidence families, and an action-ready review posture for automated deposit and withdrawal flows.
• Web Dashboard: for manual checks when you need the full picture. Includes check history, watchlists, PDF report export, and bulk upload.
Recommended setup for a mid-volume P2P desk: 1. Telegram Bot for quick pre-trade checks 2. API integration for automated policy actions above your review threshold 3. Dashboard Watchlist for ongoing counterparty monitoring
Every P2P merchant should maintain auditable records of their AML due diligence. Sanctuary generates these automatically:
• Timestamped check records — every query is logged with address, chain, risk score, risk level, and detected patterns • Cryptographic snapshots — an independently verifiable signature proving the check was performed at a specific time with specific data • PDF compliance reports — downloadable reports showing your due diligence history (Pro tier) • Watchlist alerts — notifications when a previously-clean counterparty wallet gets flagged retroactively
This paper trail is critical if you face a bank review, exchange compliance inquiry, or regulatory audit. Sanctuary's reports have been used as supporting evidence in exchange dispute resolution and compliance reviews.
1. Before every trade: Run /check on the counterparty wallet before funds move. Low-risk results can proceed under your policy; elevated-risk results should move to enhanced review, pause, decline, or counterparty replacement.
2. For new counterparties: Request a small test transaction, then run a full check. Verify that the wallet has reasonable transaction history.
3. After trades: Add counterparty to your Watchlist for ongoing monitoring. If their risk level changes, you will be notified.
4. Weekly: Review your Sanctuary dashboard for any retroactive flags on past counterparties.
5. Monthly: Export your compliance report as a PDF and archive it. If using the API, your check logs are retained automatically per your retention settings.
6. On suspicious activity: Report to Sanctuary immediately. This protects the entire network and contributes to faster response times for the community.
If you list your exchange service on BestChange (or similar aggregators like ExchangeSumo, OKchanger, or Kurs.expert), you face a distinct risk profile that most generic AML advice doesn't address.
The aggregator model means your customers are anonymous by default. They find you through a rate comparison, send funds, and expect the exchange within minutes. You have no KYC relationship, no repeat-customer trust signals, and no ability to interview the sender. This is exactly the setup that triangle scammers, mixer operators, and sanctions evaders exploit.
Here is the BestChange-specific AML checklist:
1. Pre-trade wallet check on every inbound address. Not optional. Not "for large amounts only." Every single one. Make the wallet review part of the order flow before you release funds.
2. Set hard volume limits per wallet per day. If the same wallet sends you more than $10,000 in 24 hours, that is elevated risk regardless of the individual check score. Structuring detection matters.
3. Track your aggregator reputation score. BestChange ratings are public. If you start getting disputes from counterparties who claim they never received funds, that is a triangle scam pattern. Document every trade with Sanctuary check timestamps.
4. Maintain separate bank accounts for P2P operations. When (not if) a bank asks questions about crypto-related inflows, you want your personal finances insulated. The compliance documentation from Sanctuary check logs becomes your primary defense.
5. Monitor your receiving wallets retroactively. Add your own operational wallets to Sanctuary Watchlist. If a wallet that sent you funds gets flagged after the trade, you will know — and can proactively disclose to your bank before they discover it themselves.
6. Report every confirmed scam attempt. BestChange has a claims system. Sanctuary has community reporting. Use both. Every report strengthens the intelligence network for all operators.
7. Consider jurisdiction. BestChange operators in the EU face MiCA requirements as of July 2026. Operators in the CIS are subject to increasing local AML regulations. Your compliance records are your insurance policy.
Scam alerts, new sanctions, and investigation techniques. One email per week. Unsubscribe anytime.