Constatum
Compliance

Source of Funds: What Your Exchange Actually Wants

Constatum Team5 min read
A machined titanium document sleeve holding a squared stack of gunmetal plates, one edge lit by a thin orange line.

You held ETH since 2021. You moved it to an exchange in June, sold part of it, and asked to withdraw euros to your bank. The withdrawal did not go out. Instead a ticket appeared: please provide documentation showing the source of these funds.

Nothing about you changed. The rules around you did.

Why you are being asked now

Two things landed in Europe within eighteen months of each other.

Since 30 December 2024, the EU's revised Transfer of Funds Regulation has required crypto-asset service providers to collect and pass on full originator and beneficiary details for every transfer they handle. Name, account number, address or national ID, date of birth. There is no minimum amount. A €40 transfer carries the same data obligation as a €400,000 one.

Then MiCA's grandfathering window closed on 1 July 2026. Firms operating on old national registrations had to be fully authorised or stop serving EU customers. Of the 3,000-plus crypto firms active across Europe, roughly 290 held full MiCA authorisation by that deadline. The ones still standing are the ones now applying the rules properly, because their licence depends on it.

The next step is already dated. The EU's Anti-Money Laundering Regulation, (EU) 2024/1624, applies to crypto firms from 10 July 2027. It requires full customer due diligence on occasional transactions of €1,000 or more, and it bans anonymous accounts and privacy coins outright. No compliance team is waiting until 2027 to build the habit.

What actually sets it off

Source-of-funds reviews are rarely random, and they are usually not about you. They are about where your coins have been.

A request is likely if your deposit arrived from a mixer, a bridge, a gambling platform, a peer-to-peer trade, a third party who is not you, or an exchange the receiving platform rates as high risk. A large deposit that does not match the profile you gave at signup does the same thing. So does a wallet that sat still for years and suddenly moved.

The reason those filters tightened is visible in the numbers. Chainalysis put illicit crypto inflows at at least $154 billion for 2025, a 162 percent jump on the previous year. Sanctions evasion accounted for roughly $104 billion of that, stolen funds $3.4 billion, ransomware around $820 million. Stablecoins carried 84 percent of illicit transaction volume. North Korea-linked hackers alone took $2.02 billion in 2025, 51 percent more than in 2024, with the February Bybit breach worth close to $1.5 billion by itself.

The ground also keeps moving. On 7 August 2026 the US Treasury sanctioned two more crypto exchanges, Shelbit and Aban Tether, under its Economic Fury campaign against Iranian financial networks. TRM Labs traced more than $6.3 billion in flows through Shelbit, a Dubai-registered platform, between May 2024 and March 2026. OFAC also designated its operator and a set of front companies across Georgia, Poland and the UAE.

Read that as a user, not a policy analyst. Every wallet that traded through those platforms was clean by the screening tools of 6 August. On 8 August it was one hop from a sanctioned entity. Your history does not stay still, because the lists do not.

Documents, not explanations

The most common mistake is answering the question in prose. A compliance team cannot file a paragraph. They need artefacts.

What usually satisfies a request:

  • Bank statements showing the fiat that bought the crypto in the first place.
  • Trade history or a CSV export from the exchange where you originally bought.
  • Payslips, invoices, or a signed contract if the crypto was income.
  • A tax return or a sale agreement if it came from a property sale, a business exit, or an inheritance.
  • The on-chain trail: transaction hashes connecting the original purchase to the wallet you deposited from.

If the original records are gone — an exchange that shut down, a wallet from 2016 — say so plainly and give secondary evidence. A written statement plus partial records is often accepted. Silence is not.

Two practical notes. Answer inside the window they give you even if the answer is incomplete; a late perfect reply is worse than an early partial one. And keep the account consistent with what you declared at signup. Most escalations come from a mismatch, not from a missing document.

The half most people skip

People prove the fiat side well. They almost never prove the chain side, because they never looked at it.

If you take crypto from clients, sell on peer-to-peer markets, or accept payment from someone you met online, you inherit their history along with their money. That is the part an exchange will ask about, and by then it is too late to choose differently.

Before you accept a payment from an address you do not know, run the address through a check and read what comes back: sanctions matches, mixer exposure, links to reported thefts, how old the wallet really is. It takes seconds, and it happens while you can still say no. Doing it afterwards only tells you how bad the problem already is.

Keep the output. A dated screening report from the moment you accepted funds is the strongest thing you can hand a compliance team, because it shows you checked when it mattered instead of assembling a defence later.

If the account is already frozen

Do not open a second account elsewhere and start moving funds around. That reads as layering, and it makes everything worse.

Reply to the ticket with files attached. Ask, in writing, exactly which deposit is under review and which documents would close it. You are entitled to a specific answer, and a specific question is harder to leave sitting in a queue. Keep every message.

If the platform holds your funds for weeks with no defined process, escalate to its regulator in its home member state, and take legal advice before you sign or agree to anything. An authorised EU firm has a named supervisor and a complaints route. Use them.

None of this means you are suspected of something. The exchange is answering a question its own regulator will put to it, and it is passing that question to you. The people who get through it in days rather than months are the ones who kept receipts — for the euros and for the addresses. Start keeping both now, while nobody is asking.

Sources

  1. 1.Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assetsEUR-Lex (Official Journal of the European Union)
  2. 2.Statement on the End of Transitional Periods under MiCA (ESMA75-113276571-1679, 17 April 2026)European Securities and Markets Authority (ESMA)
  3. 3.Interim MiCA Register — Authorised crypto-asset service providers (Title V), CASPS.csvEuropean Securities and Markets Authority (ESMA)
  4. 4.Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (AMLR)EUR-Lex (Official Journal of the European Union)
  5. 5.2026 Crypto Crime Report IntroductionChainalysis
  6. 6.Crypto Sanctions: 2026 Crypto Crime ReportChainalysis
  7. 7.2025 Crypto Theft Reaches $3.4 Billion (Crypto Hacking: 2026 Crypto Crime Report)Chainalysis
  8. 8.Treasury Sanctions Crypto Exchanges Funding Iran's IRGC and Enabling Illicit Finance (press release sb0598)U.S. Department of the Treasury / OFAC
  9. 9.How Shelbit Became a USD 6.3 Billion Settlement Layer for Iran's Illicit EconomyTRM Labs

This article is general information, not legal, tax, financial, or investment advice. Crypto carries risk — do your own research and consult a qualified professional before acting. Constatum makes no warranty as to accuracy or completeness and accepts no liability for decisions made based on it.

Keep reading