Cryptocurrency Exchange Investigations Flashcards
6 cards from real CCI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cryptocurrency Exchange Investigations flashcards as text
What is an address 'cluster' in the context of blockchain exchange investigations?
Answer: A group of addresses identified as controlled by the same entity through heuristics like common-input ownership
A cluster is a group of cryptocurrency addresses attributed to the same controlling entity, most commonly identified through common-input-ownership heuristics.
When investigating a cryptocurrency exchange, which legal instrument prevents the exchange from alerting the customer that their records are being sought?
Answer: Non-disclosure order (gag order) accompanying the subpoena
A non-disclosure order (gag order) accompanying a subpoena legally prohibits the exchange from notifying the account holder that their records are under investigation.
What is 'smurfing' in the context of cryptocurrency exchange investigations?
Answer: Breaking large amounts into smaller transactions to stay below reporting thresholds
Smurfing is a structuring technique that breaks large amounts into smaller transactions specifically to avoid triggering mandatory reporting thresholds like the $10,000 CTR.
Which US government agency maintains primary AML/KYC regulatory authority over domestic cryptocurrency exchanges?
Answer: FinCEN (Financial Crimes Enforcement Network)
FinCEN, a bureau of the US Treasury Department, holds primary AML/KYC regulatory authority over cryptocurrency exchanges registered as MSBs in the United States.
What is a Suspicious Activity Report (SAR) and who is required to file it?
Answer: A confidential report filed by financial institutions including exchanges with FinCEN when suspicious activity is detected
A SAR is a confidential report that financial institutions (including crypto exchanges) must file with FinCEN when transactions suggest potential money laundering or other criminal activity.
An investigator receives exchange records showing a customer used a US driver's license but IP login records show consistent logins from a foreign country. What does this most likely indicate?
Answer: Possible identity fraud, a synthetic identity, or a money mule account
Consistent foreign IP logins despite US identity documentation suggests potential use of a fraudulent or synthetic identity, or that the account belongs to a money mule.