Intelligence Brief
Crypto firms are entering a stricter compliance environment while fraud tactics become harder to detect.
Sumsub’s State of the Crypto Industry 2026 report found that 55% of crypto companies experienced fraud last year. Travel Rule readiness remains another weak point: only 23% of firms report full compliance, while 43% do not know whether they meet the requirements.
The threat has also changed. Fraud operations increasingly combine deepfakes, synthetic identities, account takeovers and mule networks. Instead of attacking only during onboarding, criminals can target accounts months after they pass KYC.
Stablecoin activity adds another layer. Sumsub’s research found stablecoins accounted for 36% of crypto transactions in 2025, up from 31% a year earlier, driven partly by payments, settlement and treasury use.
Strategic Assessment
Regulatory clarity does not automatically mean compliance readiness.
In the U.S., frameworks such as the GENIUS Act are raising expectations around reserves, redemption, AML controls and consumer protection. Market structure legislation could add further requirements.
Yet implementation remains uneven. Sumsub found 62% of surveyed businesses cited data security as a Travel Rule challenge, while 52% pointed to implementation costs and 50% to regulatory fragmentation.
The larger security problem sits beyond initial verification. An account that passes KYC can later be compromised, sold or incorporated into a mule network.
That makes continuous monitoring more important. Identity checks, device activity, transaction patterns and wallet exposure increasingly need to be assessed together rather than through isolated compliance systems.
Risk Signals
AI lowers the cost of producing convincing fraudulent identities while stablecoins increase the speed and reach of cross-border transactions.
For exchanges and payment firms, the exposure is straightforward: transaction volume can scale faster than compliance infrastructure.
The firms best positioned for the next regulatory phase will not simply have KYC procedures on paper. They will need systems capable of detecting when previously legitimate accounts stop behaving like legitimate users.