Security and Regulatory Compliance Flashcards
7 cards from real Cryptocurrency practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security and Regulatory Compliance flashcards as text
What does 'SAR' stand for and when must a crypto business file one?
Answer: Suspicious Activity Report — filed when transactions suggest money laundering or other crimes
SARs (Suspicious Activity Reports) must be filed with FinCEN within 30 days when a crypto business detects transactions involving $5,000+ that may involve criminal activity.
Which type of crypto scam involves offering guaranteed high returns through a fake investment platform that pays early investors with new investors' funds?
Answer: Ponzi scheme
A crypto Ponzi scheme promises high returns and uses new investor deposits to pay earlier investors until the scheme collapses—BitConnect was a famous example.
What security vulnerability does a 'reentrancy attack' exploit in smart contracts?
Answer: It calls back into the vulnerable contract before the first execution finishes, draining funds
Reentrancy attacks (famously used in The DAO hack) call a vulnerable function recursively before the contract updates its internal state, allowing repeated fund withdrawals.
Under the U.S. Infrastructure Investment and Jobs Act (2021), which parties were controversially designated as 'brokers' required to report crypto transactions to the IRS?
Answer: Broadly defined parties including potentially miners, validators, and wallet developers
The law's broad 'broker' definition sparked controversy as it could apply to miners, validators, and software developers who don't have customer information to report.
What is the purpose of a 'crypto mixer' or 'tumbler,' and why is it legally problematic?
Answer: A service that pools and shuffles transactions to obscure their origin, raising money laundering concerns
Mixers obscure the blockchain trail between sender and recipient; OFAC sanctioned Tornado Cash in 2022 for facilitating over $7 billion in money laundering.
What is 'whaling' in the context of cryptocurrency phishing attacks?
Answer: Highly targeted phishing attacks aimed at high-value individuals like executives or large investors
Whaling is spear-phishing specifically targeting high-value individuals (whales), using highly personalized deception to steal large crypto holdings or compromise organizational systems.
What does FATF's 'Travel Rule' Recommendation 16 require of Virtual Asset Service Providers (VASPs)?
Answer: VASPs must collect and share originator and beneficiary information for transfers above $1,000
FATF Recommendation 16 requires VASPs to obtain, hold, and transmit originator and beneficiary information with transfers of $1,000 or more to combat money laundering.