These factors combined can attract both privacy-conscious investors willing to bet on favorable cryptocurrency market trends and also attract fraudsters hoping to hide their identities while committing financial crimes. The cryptocurrency frenzy further creates a lucrative environment in which cyber criminals can carry out their schemes.
Balance the fight against fraud without intimidating real customers
Cryptocurrency abuse by scammers is not a new phenomenon. Between 2011 and 2021, criminals operating around the world allegedly defrauded users out of nearly $5 billion worth of cryptocurrency and stole another $3 billion through security breaches, according to Pyments.
The regulatory requirements facing exchanges that facilitate the purchase and trade of these tokens have evolved in recent years, in part in response to growing concern over the efforts of fraudsters.
However, many crypto exchanges around the world still have relatively lax security measures, which could put them and their users at increased risk. Many consumers are interested in cryptocurrencies for legitimate reasons, but may be wary of platforms that put them at risk of unwittingly trading with scammers.
Cryptocurrency Industry Security Challenges
Transactions made with digital assets are tracked and recorded on the blockchain, but the users themselves remain anonymous by trading under pseudonyms and usernames. This opacity can make it easier for criminals to onboard and defraud unwitting victims or launder money.
Cryptocurrency transactions are also irreversible, meaning victims may have no recourse if tricked into sending digital tokens to fraudsters. Factors like these – along with the currently high value of many cryptocurrencies – make the space tempting for bad actors.
Exchanges that wish to earn the trust of legitimate users must prove that it is safe to transact without introducing friction that discourages customers, and each platform must find an approach that suits its unique customer base.
Some platforms may think that they cannot simply copy the Know Your Customer (KYC) playbooks of their traditional, regulated financial institution counterparts without changing the nature of their offerings. Users may therefore be reluctant to hand over many of the personally identifying details typically collected in financial institutions’ customer verification processes.
Crypto exchanges recognize that many cryptocurrencies are also subject to rapid fluctuations in value, and clients often want to be able to trade quickly so they can take advantage of current prices. This forces platforms to quickly manage their security checks and checks to avoid inflicting painful delays on users.
What types of identity verifications can crypto exchanges rely on?
Crypto platforms adopt a variety of strategies to confirm customer identities while delivering compelling experiences. Some exchanges may require new customers to go through light initial onboarding processes, but then require more thorough identity verification before taking financially riskier steps, increasing the amount of credentials that exchanges customers must provide as the value of their deposits and withdrawals increases.
Platforms can use contextual onboarding in which they allow customers to onboard without going through any identity verification, but only allow very limited functionality, while customers who provide IDs with photo may be allowed to make low-level withdrawals and deposits and full KYC membership may allow users to transfer, deposit or withdraw large sums.
Other exchanges seek to build trust by requiring all new customers to go through robust KYC procedures from the outset, including some or all of the following:
- Background searches
- Checks against sanctions lists
- Verification of government-issued IDs
- Live phone calls
Each platform should determine the customer verification approach that best suits its business model and complies with local regulations.
Why Crypto Exchanges Have an Advantage in Identifying Fraud in Real Time
Cryptocurrency platforms can also look for red flags which, if detected and addressed, allow them to nip fraud in the bud. Detecting when a customer is signing up using one name while downloading funds from bank accounts with a different name can raise alarm bells. The same goes for detecting users whose IP addresses have been associated with suspicious activity in the past.
Such events can prompt crypto exchanges to intervene or monitor accounts more closely as they work to determine if criminal activity is taking place or if the events are simply false positives.
Platforms can work to improve the precision and accuracy of their fraud detection metrics as well as monitoring and analyzing real-time transactions for indicators of fraud. Automated solutions can help make this rapid analysis possible and help businesses identify potential fraud even earlier.
Additionally, crypto exchanges are the target of a new type of hard-to-detect identity fraud commonly referred to as “synthetic fraud”, also known as “deep fakes”. Synthetic fraud is large-scale identity fraud that creates “deep fakes” that are nearly impossible for the human eye to detect. This presents a major challenge as synthetic identities are created with advanced computer software, mixing fake and real information.
Fraudsters can take an image of a person and manipulate it to create several new images that alter facial features. Fake IDs are created “on the production line” – hundreds or even thousands at a time.
Crypto exchanges are particularly vulnerable to synthetic fraud attacks because they are considered the weakest link in the financial chain – easier to cheat than institutional banks.
What Crypto Exchanges Should Look For in Identity Verification
Cryptocurrency advocates seeking more widespread adoption of private tokens must also balance combating fraud with user anonymity.
The best identity verification solutions should include the following elements in order to meet the unique requirements of the cryptocurrency industry:
- 100% automation – Crypto exchanges will lose customers if they offer slow onboarding of new customers that requires human intervention
- Synthetic fraud detection – Crypto exchanges are targets of financial fraud and require a high level of identity fraud detection capabilities.
- Liveliness Selfie – Verify that a selfie is a live image and compare it to passport photos.
- Personalization – As identity verification regulations and requirements evolve, crypto exchanges need a solution that fits their current needs and is easily adjustable when verification rules change.
To meet the security and convenience needs of cryptocurrency users – now and in the future – exchanges should consider revamping their client authentication toolkits. Powerful automated identity verification tools can help platforms ensure seamless onboarding while enabling them to detect and thwart potential fraud and build trust with regulators and legitimate users.
New identity verification strategies and technological developments should also continue to promote innovative ways to meet regulators’ security requirements and users’ privacy wishes.
Written by Doron Mutsafi, chef Customer Hit Officer, AU10TIX