CIGI Papers No. 362 — September 2026
Governing Digital Assets and Crypto-Enabled Financial Crime S. Yash Kalash
CIGI Papers No. 362 — September 2026
Governing Digital Assets and Crypto-Enabled Financial Crime S. Yash Kalash
About CIGI
Credits
The Centre for International Governance Innovation (CIGI) is an independent, non-partisan think tank whose peer-reviewed research and trusted analysis influence policy makers to innovate. Our global network of multidisciplinary researchers and strategic partnerships provide policy solutions for the digital era with one goal: to improve people’s lives everywhere. Headquartered in Waterloo, Canada, CIGI has received support from the Government of Canada, the Government of Ontario and founder Jim Balsillie.
President Paul Samson Research Director, Digital Economy Odun Olowookere Director, Programs Dianna H. English Program Manager Morgan Fox Publications Editor Christine Robertson Publications Editor Lynn Schellenberg Graphic Designer Sami Chouhdary
À propos du CIGI Le Centre pour l’innovation dans la gouvernance internationale (CIGI) est un groupe de réflexion indépendant et non partisan dont les recherches évaluées par des pairs et les analyses fiables incitent les décideurs à innover. Grâce à son réseau mondial de chercheurs pluridisciplinaires et de partenariats stratégiques, le CIGI offre des solutions politiques adaptées à l’ère numérique dans le seul but d’améliorer la vie des gens du monde entier. Le CIGI, dont le siège se trouve à Waterloo, au Canada, bénéficie du soutien du gouvernement du Canada, du gouvernement de l’Ontario et de son fondateur, Jim Balsillie.
Human Analysis Standard
This publication’s analysis was developed and approved by the named human authors under documented review controls; AI assistance was judicious, disclosed and verified.
Copyright © 2026 by the Centre for International Governance Innovation The opinions expressed in this publication are those of the author and do not necessarily reflect the views of the Centre for International Governance Innovation or its Board of Directors. For publications enquiries, please contact publications@cigionline.org.
The text of this work is licensed under CC BY 4.0. To view a copy of this licence, visit http://creativecommons.org/licenses/by/4.0/. For reuse or distribution, please include this copyright notice. This work may contain content (including but not limited to graphics, charts and photographs) used or reproduced under licence or with permission from third parties. Permission to reproduce this content must be obtained from third parties directly.
Centre for International Governance Innovation and CIGI are registered trademarks. 67 Erb Street West Waterloo, ON, Canada N2L 6C2 cigionline.org
Table of Contents vi
About the Author
vi
Acronyms and Abbreviations
1
Executive Summary
1
Introduction
2
Understanding Crypto-Enabled Financial Crime
4
The Technical Architecture of Digital Assets and Crime Risks
6
Institutional Landscape: FATF, INTERPOL and the Multilateral Enforcement Gap
9
National-Level Governance Strategies
13
Multilateral-Level Governance Strategies
20
Governance of Permissionless Innovation
22
Conclusion
23
Works Cited
About the Author
Acronyms and Abbreviations
S. Yash Kalash is a senior fellow at CIGI and an expert in strategy, public policy, digital technology and financial services. He has experience in emerging markets across India, MENA (Middle East and North Africa) and the Asia-Pacific and a distinguished track record advising governments and the private sector on emerging technologies. His expertise spans various industries, including fintech, AI and digital assets, and their impact on geopolitics. His career includes key roles at Roland Berger, the Government of India, Adani Group and KPMG, where he spearheaded strategic digital projects, advised clients on their digital assets and AI strategy, and informed policy and regulatory developments. With an M.Sc. in management from Imperial College London and a B.Sc. in international relations and politics from the University of Bath, Yash combines deep strategic insight with strong training, making him a versatile and impactful leader in the field of digital economy.
AI
artificial intelligence
AML
anti-money laundering
API
application programming interface
BIS
Bank for International Settlements
CBDCs
central bank digital currencies
CFTC
Commodity Futures Trading Commission
CTF
counter-terrorist financing
DAIF
digital asset integrity framework
DAOs
decentralized autonomous organizations
DeFi
decentralized finance
DEXs
decentralized exchanges
DLTs
distributed ledger technologies
Europol
European Union Agency for Law Enforcement Cooperation
FATF
Financial Action Task Force
FIUs
financial intelligence units
FSB
Financial Stability Board
G20
Group of Twenty
GDPR
General Data Protection Regulation
HKMA
Hong Kong Monetary Authority
IMF
International Monetary Fund
INTERPOL International Criminal Police Organization
vi
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
KYC
know your customer
MEV
maximal extractable value
MiCA
Markets in Crypto-Assets Regulation
multisig
multi-signature
PETs
privacy-enhancing technologies
SEC
US Securities and Exchange Commission
STR
suspicious transaction reporting
SWIFT
Society for Worldwide Interbank Financial Telecommunication
UNODC
United Nations Office on Drugs and Crime
VASPs
virtual asset service providers
Executive Summary The rapid expansion of blockchain-based financial ecosystems has created unprecedented opportunities for economic innovation, but it has also enabled new vectors of financial crime, from money laundering and sanctions evasion to ransomware, terrorist financing, market manipulation and sophisticated whitecollar schemes. As illicit activity increasingly exploits the borderless, pseudonymous and technologically diverse nature of digital assets, traditional enforcement frameworks designed for centralized intermediaries and jurisdictionbound financial systems are proving insufficient. This paper examines how the international community can build a coherent, effective and innovation-preserving governance regime for crypto-enabled financial crime enforcement. Focusing on the emerging roles of international organizations such as the Financial Action Task Force (FATF), the International Criminal Police Organization (INTERPOL), the European Union Agency for Law Enforcement Cooperation (Europol), the United Nations Office on Drugs and Crime (UNODC) and regional supervisory bodies, the paper analyzes how global institutions can harmonize standards, enhance cross-border data sharing and coordinate operational responses to digital asset misuse. It further explores how permissionless and permissioned distributed ledger technologies (DLTs), decentralized autonomous organizations (DAOs) and blockchain analytics firms can be integrated into a multi-layered enforcement architecture without stigmatizing the underlying technology. By combining institutional analysis with technical insights, the paper outlines pathways toward a multilateral governance regime capable of safeguarding digital asset integrity while enabling responsible innovation in an increasingly fragmented geopolitical landscape.
Introduction The rapid growth of blockchain-based financial systems has reshaped how value is created, transferred and stored across the world (Javaid et al. 2022). What began as an experiment in decentralized payments has evolved into a complex digital asset ecosystem that now spans cryptocurrencies, stablecoins, decentralized finance (DeFi), non-fungible tokens, permissioned distributed ledgers and algorithmically governed DAOs. This ecosystem has unlocked new possibilities for financial inclusion, programmable commerce and globalized innovation. Yet the same characteristics that make digital assets transformative — such as borderlessness, composability, pseudonymity and automation — have also enabled a new generation of financial crimes. Crypto-enabled illicit activity increasingly spans a wide spectrum: terrorist financing through pseudonymous wallets; organized crime groups using privacy-enhancing technologies (PETs); state-backed actors employing ransomware as a geopolitical tool; white-collar criminals manipulating digital markets; and sanctioned regimes exploiting stablecoin liquidity to bypass the traditional financial system. These developments challenge the assumptions embedded in pre-crypto financial regulation. Governance frameworks designed for centralized intermediaries such as banks, money service businesses and securities exchanges struggle to operate effectively in systems where the intermediary may be a smart contract, a decentralized liquidity pool or a DAO collectively governed by token holders dispersed across hundreds of jurisdictions (Ahmed 2022). The result is a widening governance gap. National regulators have adopted divergent approaches to digital assets, creating opportunities for regulatory arbitrage and safe havens for illicit activity (International Monetary Fund [IMF] and Financial Stability Board [FSB] 2023). Multilateral institutions have attempted to respond but each faces structural constraints. The FATF sets global anti-moneylaundering (AML) and counter-terrorist-financing (CTF) standards yet relies on voluntary compliance and uneven national implementation (Arctic Intelligence 2025). INTERPOL and Europol have formed specialized crypto-crime units but lack unified technical architectures and real-time data-
Governing Digital Assets and Crypto-Enabled Financial Crime
1
sharing agreements (Pessarlay 2022; Basel Institute on Governance 2025; Basel Institute on Governance and Europol 2022). Meanwhile, the UNODC, the Egmont Group of Financial Intelligence Units, the IMF and the World Bank all play fragmented roles in capacity building and regulatory harmonization. Against this backdrop of fragmented governance and rising digital asset misuse, the international system must confront a pressing challenge: how to build a coherent, interoperable and innovationpreserving multilateral governance regime for crypto-enabled financial crime enforcement. Such a regime must be technologically informed, geopolitically realistic and grounded in institutional cooperation. It should integrate permissionless and permissioned DLTs, leverage the capabilities of blockchain analytics firms and incorporate decentralized actors such as DAOs, not as adversaries, but as participants in a shared framework for digital asset integrity. This paper argues that achieving such a regime requires moving beyond compliance checklists toward a multi-layered governance architecture in which global standards, operational enforcement, technical infrastructure and decentralized ecosystems work in concert. It outlines a pathway toward a more coordinated global response to crypto-enabled crime, one that protects financial integrity without undermining the permissionless innovation that underpins the blockchain revolution. It is important to note that while digital assets introduce novel technical and governance challenges, many of the institutional constraints identified in this paper are not unique to crypto. Fragmented authority, inconsistent regulatory implementation, uneven enforcement capacity, jurisdictional arbitrage and cross-border information-sharing challenges have long characterized traditional financial systems. Digital assets do not create these problems from scratch; rather, they amplify existing weaknesses by increasing transaction speed, reducing reliance on centralized intermediaries and expanding the number of actors operating across jurisdictions.
2
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
Understanding CryptoEnabled Financial Crime The digitization of value has expanded both the scale and sophistication of financial crime. While early discourse around cryptocurrency often framed illicit activity as a niche concern, the evolution of blockchain ecosystems has transformed crypto-enabled crime into a complex, multi-layered phenomenon that intersects with terrorism, cybercrime, white-collar misconduct and geopolitical competition. Understanding this landscape requires distinguishing between types of illicit activity, analyzing how blockchain architectures enable new crime patterns and explaining why existing financial crime frameworks struggle to address them.
Typologies of Crypto‑Enabled Financial Crime Financial and White-Collar Crimes Crypto markets have become fertile ground for traditional financial misconduct, often amplified by the structural features of DeFi. Market manipulation through wash trading, spoofing, insider trading and coordinated pumpand-dump schemes occur at a frequency and transparency level that outpaces the capacity of regulators (Clapham et al. 2023). The absence of clear disclosure obligations for token issuers and protocols enables fraudulent fundraising schemes, rug-pulls and misappropriation of customer funds (Zetzsche et al. 2019). Additionally, algorithmic stablecoins and yield-bearing products introduce quasi-securities that fall outside established regulatory classifications, creating blind spots for both market surveillance and consumer protection (Ocampo 2025).
Illicit Finance and Terrorism Cryptocurrencies have been adopted selectively by terrorist organizations and transnational criminal networks seeking to move value across borders with reduced detection risk. Although the absolute volume of terrorist financing through crypto remains low compared to traditional channels, encrypted communications, highfrequency wallet turnover, and the use of mixers, tumblers and privacy coins complicate
attribution (U.S. Department of the Treasury 2023). Notably, emerging extremist groups have exploited decentralized platforms to solicit microdonations globally, leveraging the visibility of public blockchains to broadcast pseudo-proof of activity without revealing operational details (Chainanalysis Team 2025b; Jammot 2025).
Cyber-Enabled Crimes Ransomware has emerged as one of the most consequential crypto-enabled crimes. Stateaffiliated actors, particularly in North Korea, leverage ransomware payments, DeFi exploits and bridge hacks to circumvent sanctions and generate foreign currency reserves (Chainanalysis Team 2024; U.S. Department of the Treasury 2025). Smart contract vulnerabilities — including re-entrancy attacks, oracle manipulation, cross-chain bridge compromises and maximal extractable value (MEV) exploits — have become routine targets due to the high-value liquidity pools available in DeFi systems (De.Fi Security 2025). Automation and composability, while central to decentralized innovation, also allow attackers to weaponize protocol interoperability for rapid, high-volume theft (Qin et al. 2020; Kumar and Choudhary 2025).
Sanctions Evasion and Geopolitical Abuse Digital assets have become tools of geopolitical strategy. Sanctioned regimes — including Russia, Iran and Venezuela — have increasingly used crypto rails, over-the-counter brokers, privacy tools and stablecoin liquidity to obscure international financial flows (Tsentsura 2025). The rise of central bank digital currencies (CBDCs) and state-directed DLT infrastructures introduce new vectors for sanctions arbitrage. Initiatives associated with national interbank payment systems, regional currency settlement arrangements and emerging BRICS+1 discussions on alternative payment architectures reflect broader shifts toward a more multipolar financial landscape. While these developments may create opportunities for some actors to reduce exposure to sanctions or other forms of financial coercion, they also represent legitimate efforts by states to enhance payment efficiency, monetary sovereignty and cross-border interoperability. As a result, the
1
BRICS+ is an intergovernmental organization comprising 11 countries: Brazil, China, Egypt, Ethiopia, India, Indonesia, Iran, Russia, Saudi Arabia, South Africa and the United Arab Emirates.
governance implications of digital assets extend beyond financial crime and regulatory compliance, increasingly touching on questions of economic security, geopolitical competition and the future architecture of the international monetary system.
Why Traditional AML/CTF Frameworks Fall Short Centralized versus Decentralized System Mismatches Conventional AML/CTF regimes assume that intermediaries such as banks, payment providers and custodians are capable of monitoring customers and reporting suspicious activity (Aldasoro et al. 2025). In permissionless blockchains, however, intermediaries may be absent, shifting or algorithmic. A liquidity pool or DAO cannot perform due diligence in the traditional sense, and regulators cannot compel a smart contract to comply with reporting obligations, so the lack of a proper know-yourcustomer (KYC) mechanism and processes remains a structural problem. This creates a structural mismatch between enforcement expectations and the realities of decentralized architecture.
The Obsolescence of “Intermediary,” “Custody” and “Beneficial Ownership” In blockchain systems, custody can be noncustodial, algorithmic or shared across multisignature (multisig) structures (Safeheron Team 2025). Beneficial ownership is obscured by cryptographic keys rather than corporate entities. Intermediaries may be geographically dispersed validators or even automated protocols with no legal personality. These differences undermine foundational assumptions of global AML frameworks, such as customer identification, beneficial ownership disclosure and traceability of funds through fixed account structures.
Insufficient Cross-Border Coordination Because crypto transactions are inherently transnational, national authorities often lack jurisdictional reach and operational coordination. Law enforcement agencies may struggle to obtain timely information from foreign exchanges, mining pools, custody providers or mixers, particularly in jurisdictions with weak AML compliance or unclear legal authority. Divergent regulatory standards further incentivize “jurisdiction shopping,” allowing
Governing Digital Assets and Crypto-Enabled Financial Crime
3
illicit actors to exploit regulatory arbitrage by operating across permissive borders (Chao 2023).
Data-Sharing Asymmetries and Analytical Gaps Although blockchains are transparent, attribution, or the process of linking a pseudonymous wallet address, transaction or on-chain activity to a specific individual, organization or real-world entity, remains one of the central challenges of crypto-financial crime enforcement. The majority of suspicious activity requires proprietary analytics tools, off-chain metadata and intelligence-sharing arrangements among exchanges, blockchain forensic firms and enforcement authorities. Many countries lack access to such tools or lack the institutional capacity to use them effectively. PETs, while legitimate in many contexts, further obscure transaction flows. The absence of common global data-sharing standards exacerbates these asymmetries, creating uneven enforcement and fragmented intelligence networks.
The Implications of This Evolving Crime Landscape Crypto-enabled crime is not merely a digitized version of traditional financial crime; it represents a structural shift in how illicit actors behave, coordinate and exploit global systems. The convergence of cybercrime, financial crime and geopolitical strategy means that enforcement cannot rely solely on national regulations or isolated institutional mandates. Instead, a comprehensive understanding of the technical, legal and behavioural dimensions of crypto-enabled crime is essential to crafting a governance regime that is both globally coherent and technologically grounded. At the same time, many of the vulnerabilities associated with digital assets are not entirely new. Money laundering, sanctions evasion, fraud, regulatory arbitrage and beneficial ownership concealment have long challenged traditional financial systems. The principal distinction is often not the existence of risk but rather the speed, programmability and cross-jurisdictional nature of digital asset ecosystems. Governance frameworks should therefore focus on adapting established financial integrity principles to new technological environments rather than assuming a complete break between traditional and digital finance.
4
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
The Technical Architecture of Digital Assets and Crime Risks Crypto-enabled financial crime cannot be understood, much less effectively governed, without examining the technical architecture that makes these systems possible. Blockchains and DLTs are not uniform. They differ in design philosophy, trust assumptions, governance models and data structures. These differences shape how illicit actors operate, how regulators can intervene and how enforcement agencies can collect evidence or attribute wrongdoing. This section analyzes the architecture of permissionless and permissioned DLTs, the role of PETs, and the significance of blockchain analytics in detecting and mitigating crime. It highlights both the opportunities and constraints that these technologies create for global financial integrity.
Permissionless Blockchains Permissionless blockchains such as bitcoin and Ethereum are characterized by open participation: anyone can create a wallet, initiate transactions or validate blocks. This architecture is grounded in decentralization, censorship resistance and transparency. Yet the very features that support innovation also create vectors for illicit activity.
Public Ledgers and Pseudonymity While all transactions are visible on public block explorers, identities are not. Users interact with the system through pseudonymous wallet addresses, and the on-chain footprints they leave behind often require sophisticated heuristics to link to real-world actors. Criminals exploit this pseudonymity by using disposable wallets, automated address generation and highfrequency chain hopping to break transaction traces (Siron and Paesano 2022; Elliptic 2025).
Composability and Protocol Interoperability DeFi systems run on smart contracts that are composable, meaning they can interact programmatically with other contracts. Criminals exploit this interoperability to automate laundering operations, leveraging decentralized exchanges (DEXs), bridges, yield protocols and liquidity pools to rapidly obfuscate fund
flows. Because many of these operations occur in milliseconds, regulators cannot intervene manually or freeze funds in real time. The interoperability of blockchain ecosystems also facilitates transaction-obfuscation techniques that are significantly easier and less costly to execute than in traditional financial systems. Common patterns include fan-out structures, where funds from a single source are dispersed across numerous wallets; fan-in structures, where assets from multiple addresses are consolidated into a smaller number of destinations; and gather-and-scatter techniques, which combine both approaches to fragment and recombine transaction flows across multiple intermediaries and blockchains. When combined with automated smart contracts and cross-chain infrastructure, these methods can enable the rapid movement and layering of funds across jurisdictions in a matter of seconds.
Cross-Chain Bridges as Systemic Vulnerability Points Bridges that enable value transfer across blockchains — say, from Ethereum to Solana, bitcoin to Polygon, and so on — have become primary targets for sophisticated hacks. Many bridges rely on multisig or validator-based architectures that represent single points of failure. Beyond theft, bridges also facilitate cross-chain laundering, whereby illicit funds are routed through multiple ecosystems to bypass enforcement detection models calibrated to single-chain behaviour (Elliptic 2023).
Permissioned DLTs Permissioned blockchains such as Hyperledger Fabric, R3 Corda or JP Morgan’s Onyx network require participants to undergo identity verification before accessing the system. This creates more structured governance and compliance opportunities compared to permissionless chains but also introduces new cross-system risks.
Identity Management and Compliance Advantages Because wallets and nodes in permissioned systems are tied to known entities, banks, enterprises or government bodies, regulators can enforce onboarding rules, transaction monitoring and access-level controls. This significantly reduces the scope for pseudonymous crime and improves auditability.
Fragmentation Across Enterprise Consortia Unlike permissionless blockchains, permissioned systems do not form a single global network (Helliar et al. 2020). They exist as siloed architecture operated by sectoral consortia, banks, logistics providers or government agencies. Illicit actors exploit this fragmentation by arbitraging differences in governance rules or exploiting weak consortium members with limited cybersecurity capacity.
Interoperability Challenges and Risk Spillovers As private-sector and public-sector DLTs increasingly interconnect through tokenized deposits, wholesale CBDCs and cross-border payment corridor security risks in one permissioned network can propagate through bridges or application programming interface (API) connections. The emerging hybrid landscape complicates enforcement because crime in one system can have ramifications in others, yet authorities may lack jurisdictional or technical access to those environments.
PETs PETs play a dual role in digital asset ecosystems: they protect legitimate privacy rights for individuals and enterprises but also offer tools for illicit actors seeking to evade detection. Understanding these technologies is essential for designing governance frameworks that avoid stigmatizing cryptographic privacy while mitigating its misuse.
Zero-Knowledge Proofs and Shielded Transactions Protocols such as Zcash use zk-SNARKs to enable shielded addresses and transactions. Instead of revealing transaction metadata, zero-knowledge, or ZK, systems allow users to prove the validity of a transaction without divulging sender, receiver or amount (Banerjee, Clear and Tewari 2020). These tools have legitimate uses — for example, protecting trade secrets or salary information — but they also complicate forensic analysis by erasing observable transaction patterns.
Mixers, Tumblers and Advanced Obfuscation Techniques Mixing protocols pool incoming funds and redistribute them to new addresses, breaking deterministic transaction links. While some mixers claim to offer privacy as a service, others
Governing Digital Assets and Crypto-Enabled Financial Crime
5
have become key infrastructure for ransomware syndicates and darknet marketplaces. Law enforcement’s recent takedowns of major mixers such as Samourai Wallet, Helix, Bitcoin Fog and Chip Mixer illustrate both the operational challenge these services present and the geopolitical complexities of shutting them down (Elliptic Global Policy and Research Group 2024).
Privacy Coins and Layer-2 Scaling Solutions Privacy-focused cryptocurrencies (such as Monero) and layer-2 scaling systems (such as zk‑rollups) introduce additional obfuscation layers beyond chain hopping. By compressing multiple transactions into aggregated proofs, rollups reduce the observability of transactional flows, requiring analysts to rely on probabilistic rather than deterministic tracing (Jamwal et al. 2024).
Blockchain Analytics As digital asset ecosystems expand, blockchain analytics firms have become indispensable to regulators, law enforcement agencies and financial institutions. They play a role analogous to credit bureaus or Society for Worldwide Interbank Financial Telecommunication (SWIFT) analytics in the traditional financial system but operate within a more dynamic and technically demanding environment.
capabilities vary significantly by region, creating asymmetries that adversaries exploit.
Governance Challenges Because blockchain analytics rely on proprietary data sets and black-box algorithms, questions arise regarding transparency, due process and accountability (Sharma, Singh and Singh 2025). The extent to which states should depend on private companies for core investigative functions remains contested. Moreover, without global data-sharing standards, analytics remain uneven and jurisdictionally fragmented.
Implications for Enforcement and Multilateral Governance The diversity of DLT architectures and privacy tools means there is no one-size-fits-all enforcement strategy. Permissionless systems require different tools than permissioned networks; privacy-preserving technologies demand new approaches for lawful access; and cross-chain dynamics necessitate coordination that goes far beyond national borders. As a result, any credible governance regime must integrate technical realities into regulatory design, enforcement mandates and international coordination (see Table 1).
Heuristic-Based Attribution Models Analytics firms apply clustering algorithms, behavioural heuristics and transaction-pattern matching to link wallets to individuals or entities (Nansen Intern 2025; Chegenizadeh, Niya and Tessone 2025). These models underpin risk scoring, AML monitoring and sanctions screening for virtual asset service providers (VASPs). However, attribution is not infallible: false positives can lead to over-enforcement, while sophisticated laundering schemes can evade detection.
Integration with Law Enforcement Modern investigations often rely on coordinated real-time analytics between exchanges, regulators and agencies such as INTERPOL. Chain-splitting, velocity analysis and transaction graph visualization enable authorities to spot emerging patterns across jurisdictions (Basel Institute on Governance 2025). Yet analytic
6
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
Institutional Landscape: FATF, INTERPOL and the Multilateral Enforcement Gap The global response to crypto-enabled financial crime is distributed across a patchwork of institutions, each with distinct mandates, jurisdictional limits and operational capabilities. While these organizations play crucial roles in shaping standards, coordinating enforcement and sharing intelligence, none possesses the comprehensive authority needed to govern an inherently borderless digital asset ecosystem. This institutional fragmentation contributes to regulatory arbitrage, inconsistent enforcement and uneven global capacity to detect, investigate and prosecute crypto-related crimes. Understanding the institutional landscape is
Table 1: Heat-Map: Vulnerability Comparison — Permissionless Versus Permissioned DLTs Category
Permissionless DLTs
Risk Level
Permissioned DLTs
Risk Level
Identity and Access Controls
Pseudonymous users; unlimited wallets; no onboarding
High
Verified identities; controlled access
Medium (insider risk)
Consensus and Network Security
Open validator set; varying decentralization
High
Small validator set; controlled consensus
Medium–high (collusion risk)
Smart Contract Security
Open deployment; high composability; DeFi risk
High
Controlled deployment; enterprise workflows
Medium
Data Privacy and Confidentiality
Fully public ledger; PETs obscure activity
Medium– high
Encrypted private channels
Medium–high
Interoperability and Bridges
Public cross-chain bridges; wrapped tokens
High
Enterprise APIs and connectors
Medium
Governance and Upgrades
DAO governance; tokenweighted voting
High
Consortium governance; controlled upgrades
Medium
Operational Resilience
Highly decentralized but fragmented risk
Medium
Centralized infrastructure; fewer nodes
High (single points of failure)
Overall Enforcement Difficulty
Attribution challenges; high laundering risk
High
Investigation possible but dependent on consortium access
Medium
Source: Author.
therefore essential to designing a multilateral governance regime for digital asset integrity.
involve self-hosted wallets, decentralized protocols or jurisdictions with differing regulatory standards.
The FATF: Standard‑Setter, Not Enforcer
Strengths: Global Norms and Political Signalling
The FATF is the most influential international body shaping global AML and CTF standards. Its recommendations — especially Recommendation 15 on new technologies and its VASPs framework — provide the baseline for national legislation (FATF 2025a). The Travel Rule, requiring synchronized sharing of sender and receiver information for cryptocurrency transfers, remains the FATF’s most controversial and technically challenging mandate (FATF 2025b). Similar to informationsharing requirements in traditional banking, the rule is intended to create a traceable record of transactions across institutions, enabling regulators and law enforcement agencies to identify suspicious patterns, reconstruct transaction chains and detect potential money laundering, terrorist financing, sanctions evasion or other illicit activity. However, implementing the Travel Rule across a fragmented ecosystem of exchanges, custodians and cross-border digital asset providers has proven considerably more complex than in traditional financial systems, particularly where transfers
The FATF’s soft-law model is highly effective in influencing national legislation because: → its evaluations and “grey list/black list” classifications carry strong reputational and economic consequences; → it provides a common vocabulary and risk taxonomy for digital asset oversight; and → its guidance is continually updated to reflect evolving typologies of crypto-enabled crime. The FATF’s normative reach shapes everything from licensing requirements for exchanges to supervisory expectations for blockchain analytics integration.
Limitations: Voluntary Compliance and Uneven Implementation The FATF has no binding enforcement power (Pavlidis 2023). National adoption of FATF standards varies dramatically:
Governing Digital Assets and Crypto-Enabled Financial Crime
7
→ Some jurisdictions (the European Union, Singapore, Japan) implement FATF rules rigorously. → Others apply minimal or delayed compliance, creating regulatory arbitrage that criminals exploit. → Travel Rule interoperability remains limited, with incompatible protocols and fragmented private-sector tools. This uneven implementation creates a patchwork of compliance islands, allowing illicit actors to route funds through weak jurisdictions while accessing global liquidity through crypto exchanges.
The Structural Constraint: The FATF Does Not Operate in Real Time The FATF’s processes, including mutual evaluations, follow-up reports and typology updates, operate on timescales that are significantly slower than the pace of modern digital asset markets. DeFi exploits, cross-chain laundering operations and stablecoin-based value transfers can occur within minutes, while the FATF’s governance mechanisms are designed to shape regulatory frameworks over months or years. The FATF can establish standards and influence national legislation but it cannot respond operationally to real-time cyber-financial threats. This limitation reflects a broader distinction between reactive and proactive AML/CTF approaches. Traditional financial crime frameworks are largely reactive: suspicious activity is detected after a transaction has occurred, reported to relevant authorities and subsequently investigated. While this model remains effective in many areas of conventional finance, it is less suited to blockchain ecosystems where assets can move rapidly across protocols, chains and jurisdictions before intervention is possible. Once funds have been dispersed through mixers, PETs, cross-chain bridges or complex fan-in/fan-out structures, tracing and recovery become significantly more difficult and costly. As a result, digital asset ecosystems increasingly require proactive risk mitigation mechanisms that operate before or during transaction execution rather than solely after the fact.
INTERPOL: Operational Coordination for Transnational Crime INTERPOL plays a complementary but distinct role. Its mandate encompasses cross-border criminal investigations, intelligence sharing and coordination among national police forces. In recent years, INTERPOL has expanded its cybercrime and cryptocurrency expertise, establishing dedicated units and forensic capabilities.
Strengths: Global Reach and Investigative Capabilities INTERPOL provides: → global investigative support through notices, diffusion alerts and joint operations; → access to blockchain forensic tools, enabling real-time tracing of suspicious transactions; and → operational capabilities for takedowns of darknet markets, ransomware networks and mixing services. Unlike the FATF, INTERPOL, which is an international law enforcement coordination agency, operates in real time, which is crucial for rapid fund freezing, seizure and recovery.
Limitations: No Mandate to Set Regulatory Standards INTERPOL cannot: → define compliance rules for exchanges or DeFi protocols; → shape supervisory frameworks for national regulators; or → enforce AML obligations across jurisdictions. It relies entirely on national authorities to act on intelligence, which can be hampered by local political constraints, lack of capacity or noncooperation.
Key Challenge: Data Access and Technical Fragmentation INTERPOL’s ability to investigate depends on: → exchange cooperation; → access to analytics tools;
8
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
→ legal frameworks for cross-border subpoenas; and → technical interoperability with multiple blockchain ecosystems. Fragmented technical environments impede seamless tracing and synchronized enforcement across borders.
Europol, UNODC and the Egmont Group: Specialized but Fragmented Roles Europol: Regional Strength with Limited Global Scope Europol’s European Cybercrime Centre is a leader in: → crypto-forensics; → ransomware investigations; → coordinated takedowns of illicit infrastructure; and → public-private intelligence exchanges. However, Europol’s mandate is regionally bounded and cannot substitute for global coordination.
UNODC: Mandate for Transnational Organized Crime UNODC provides: → technical assistance to developing countries; → training in cybercrime investigations; and → policy guidance on digital evidence frameworks. Its strength lies in capacity building but not in enforcement or standard setting.
The Egmont Group: FIU-to-FIU Intelligence Exchange The Egmont Group connects more than 160 financial intelligence units (FIUs). It enables: → suspicious transaction reporting (STR) exchanges;
However, many FIUs lack crypto expertise, reporting standards vary substantially and data-sharing processes remain slow relative to the speed of digital assets.
The Multilateral Governance Gap Despite these institutions’ efforts, a structural governance gap persists due to three fundamental constraints, as outlined in Table 2:
Implications for a Multilateral Digital Asset Integrity Regime The institutional landscape demonstrates why current arrangements cannot adequately address crypto-enabled financial crime: mandates are distributed, coordination is voluntary and enforcement is fragmented across jurisdictions and technologies. The following would be required for a robust global regime: → The FATF needs stronger implementation incentives by moving beyond assessments of legal adoption toward evaluations of operational effectiveness. → INTERPOL requires deeper integration with analytics ecosystems. → FIUs need standardized crypto-reporting frameworks. → Permissioned and permissionless systems should adopt common compliance and investigative standards, including interoperable risk-scoring methodologies, suspicious activity reporting frameworks and blockchain forensic protocols. This would enable more effective cross-chain monitoring, asset tracing and international enforcement coordination without requiring convergence toward a single technological architecture. → Private-sector and DAO actors must be recognized as essential components of the governance architecture.
→ cross-border case collaboration; and → harmonized financial intelligence protocols.
Governing Digital Assets and Crypto-Enabled Financial Crime
9
Table 2: The Multilateral Governance Gap — Key Structural Constraints Constraint
Description
Institutional Implications → FATF sets standards but cannot enforce them. → INTERPOL investigates but cannot regulate.
No single body has composite authority
Governance functions are fragmented across institutions with complementary but siloed mandates.
→ Europol builds regional capacity but lacks global scope. → UNODC trains but does not supervise. → Egmont Group shares intelligence but not policy. Result: No integrated architecture capable of governing crypto crime on a scale. → No global data lakes for crypto crime intelligence.
Fragmented data and technical interoperability
Digital asset flows span multiple chains, jurisdictions and public/private networks; institutions lack a shared technical infrastructure.
→ No standardized wallet-risk scoring or attribution metrics. → No unified forensic frameworks across public and permissioned DLTs. → No common APIs for analytics exchange. Result: Operational blind spots across tracing, freezing, seizure and recovery. → Conflicts between AML policies and strategic autonomy agendas. → Geopolitical tensions shape cooperation on sanctions, CBDCs and data sharing.
Divergent national priorities and geopolitics
National strategies for crypto governance differ due to domestic politics, economic interests and security considerations.
→ Privacy regimes (such as the General Data Protection Regulation [GDPR]) complicate cross-border intelligence flows. → FATF alignment occurs “in principle” but not consistently “in practice.” Result: Weak standardization and inconsistent enforcement across jurisdictions.
Source: Author.
National-Level Governance Strategies While crypto-enabled financial crime is inherently transnational, the first line of defence remains national regulatory, supervisory and law enforcement systems. The effectiveness of a future multilateral governance regime will depend heavily on the strength, consistency and interoperability of national frameworks. Yet countries vary widely in their regulatory maturity, technical capabilities, institutional coordination and political priorities. This section analyzes the core components of a robust national governance strategy such as legal and regulatory
10
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
frameworks, supervisory and technological tools, enforcement capacity and approaches to balancing innovation with risk mitigation.
Legal and Regulatory Frameworks Comprehensive Licensing Regimes for Virtual Asset Service Providers The foundation of national crypto governance rests on licensing and registration regimes for VASPs. Effective frameworks specify: → regulation should follow the principle of “same activity, same risk, same regulatory outcome,” ensuring that actors performing economically equivalent functions face comparable compliance obligations, reducing regulatory
arbitrage and providing greater certainty for both supervisors and market participants; → AML/CTF obligations; → capital adequacy and risk management requirements; → consumer protection standards; and → cybersecurity obligations. Some jurisdictions, such as Singapore, the European Union (under Markets in Crypto-Assets Regulation [MiCA]), Japan and the United Arab Emirates have implemented detailed frameworks with clear licensing pathways (Shala 2025). Others have enacted partial or fragmented regimes, creating loopholes for shadow operators and cross-border arbitrage.
Treatment of DAOs, DeFi Protocols and Algorithmic Intermediaries A major challenge is how to regulate decentralized financial services. Traditional legal categories such as custodians, brokers and exchanges do not neatly apply to: → DEXs;
Travel Rule compliance, sanctions screening and cross-border investigations.
Stablecoin Regulation and Tokenized Money Stablecoins are increasingly used for payments, settlements and cross-border value transfer, both legitimate and illicit in nature. Key regulatory questions include: → reserve backing and disclosure requirements; → redemption guarantees; → systemic risk thresholds; → treatment of algorithmic stablecoins; and → oversight of foreign-issued stablecoins used domestically. The divergence between developed economies such as the United States, the European Union, Singapore and emerging market frameworks illustrates the complexity of building harmonized standards.
Supervisory Technology and Regulatory Technology National regulators increasingly rely on data-driven technologies to monitor digital asset activity.
→ liquidity pools; → automated market makers;
Blockchain Monitoring and Forensic Integration
→ autonomous smart contracts; or
Modern supervisory models require integration with:
→ DAO-governed platforms.
→ blockchain analytics platforms;
Jurisdictions vary in their approach:
→ risk-scoring systems;
→ Some treat DeFi front-end operators as VASPs.
→ sanctions-screening engines; and
→ Others impose obligations on protocol developers or node operators.
→ anomaly detection algorithms.
→ A few adopt a “function over form” framework that focuses on the activity, not the entity (Kumar et al. 2025).
Artificial Intelligence (AI-)Driven Surveillance and Risk Classification
Without clarity at the national level, enforcing global standards becomes nearly impossible. More fundamentally, effective AML/CTF enforcement depends on the ability to link digital asset activity to real-world actors. Robust KYC frameworks, interoperable digital identity systems and verifiable credentials therefore represent a foundational layer of digital asset governance, supporting attribution,
→ high-risk wallet identification;
Machine learning models can support:
→ transaction-pattern clustering; → typology updates for emerging threats (bridges, privacy layers); and → automated detection of smart contract vulnerabilities. Governing Digital Assets and Crypto-Enabled Financial Crime
11
While these tools improve efficiency, they also raise questions about transparency, due process, algorithmic bias, false positives and the public-private data relationships that underpin enforcement. Thus, using them with significant guardrails would be worth noting.
Public-Private Intelligence Networks Effective national supervision increasingly relies on partnerships between: → regulators; → law enforcement agencies; → VASPs; → banks and financial services institutions; → telecom operators; and → blockchain analytics companies. Public-private data fusion centres mirroring cyberthreat intelligence models are emerging as a critical enabler for digital asset oversight.
Enforcement and Investigative Capacity A national regulatory framework is only as strong as the enforcement infrastructure behind it. Crypto-enabled financial crimes require specialized investigative tools, legal authorities and interagency coordination.
Specialized Law Enforcement Units Successful national models include: → dedicated crypto forensic units; → cybercrime task forces; → financial intelligence specialists embedded with investigators; and → joint operations with national security agencies. Countries such as South Korea, the United States and the United Kingdom have built advanced crypto-focused crime units capable of seizure, tracing and disruption (Marc 2024; Hume and News Agencies 2025).
12
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
Inter-Agency Coordination Crypto crime spans: → financial regulators; → securities regulators; → tax authorities; → cybercrime bureaus; and → anti-corruption agencies. National coordination mechanisms such as joint intelligence cells and rapid response task forces are essential for: → freezing assets before they move cross-chain; → coordinating subpoenas across multiple exchanges; and → differentiating civilian cybercrime from statebacked activity.
Prosecutorial Training and Legal Modernization Because digital assets blur the lines between commodities, securities, money and digital property, prosecutors must adapt to: → new definitions of beneficial ownership; → digital asset seizure and forfeiture procedures; → evidentiary standards for blockchain data; and → the role of algorithmic and autonomous systems in criminal conduct. Legal modernization is required to ensure courts can adjudicate complex crypto cases without relying solely on expert testimony.
Balancing Innovation and Oversight Governments face multiple strategic tensions in the governance of digital assets. Overregulation risks stifling innovation and driving talent offshore, while underregulation can invite systemic risk, criminal activity and reputational harm. At the same time, policy makers must balance transparency requirements designed to support AML/CTF objectives with legitimate expectations of privacy. As in traditional financial systems, individuals and businesses have valid interests in protecting financial information, commercial relationships and sensitive transaction data.
Effective national strategies must therefore pursue technology neutrality, risk sensitivity, proportionality and privacy-preserving compliance mechanisms that enable oversight without unnecessarily compromising confidentiality.
→ supporting open-source security audits;
Avoiding the Stigmatization of Blockchain Technology
The goal is to create a regulatory environment where compliance is not a punitive requirement but a competitive advantage.
Regulations should be distinguished between the illicit use of blockchain systems and the legitimate advantages of decentralized technologies (auditability, programmability, transparency). Blanket restrictions on privacy tools, mining or DeFi can undermine beneficial innovation while doing little to deter sophisticated criminals.
Preserving Privacy While Enabling Compliance Privacy should not be viewed solely as a regulatory challenge. It is also an important feature of wellfunctioning financial systems and a legitimate expectation for law-abiding individuals and businesses. The objective of digital asset governance should therefore not be maximum transparency but rather accountable transparency that enables lawful oversight while protecting sensitive information. Emerging technologies such as zeroknowledge proofs, decentralized identity systems and verifiable credentials offer promising pathways to reconcile AML/CTF requirements with privacy rights by allowing compliance to be demonstrated without requiring full disclosure of underlying data.
Sandbox and Innovation Frameworks Regulatory sandboxes allow: → controlled experimentation; → supervised testing of DeFi protocols or stablecoin systems; and → accelerated learning for both regulators and innovators. These models reduce uncertainty and improve compliance outcomes while nurturing domestic financial technology ecosystems.
Incentivizing Compliance Through Market Design Governments can encourage responsible innovation by: → rewarding VASPs that implement advanced compliance-by-design solutions;
→ promoting adoption of secure-by-default protocol standards; and → aligning tax incentives with good governance.
Implications for Multilateral Alignment National frameworks form the substrate upon which multilateral coordination must be built. Without coherent, interoperable and technically informed national regimes, it will be difficult for multilateral agencies to set standards and implement them consistently; investigations will face barriers in data access and jurisdiction; blockchain analytics will not operate uniformly across borders; and DAOs and DeFi platforms will remain outside institutional governance structures.
Multilateral-Level Governance Strategies Even the strongest national frameworks cannot, on their own, address the fundamentally transnational nature of crypto-enabled financial crime. Digital assets move across jurisdictions and chains at machine speed, while regulatory, supervisory and enforcement structures remain largely organized along national lines. Recognizing this challenge, international bodies including the Group of Twenty (G20), the Group of Seven, the FATF, the FSB, the IMF and the Bank for International Settlements (BIS) have expanded cooperation on digital asset governance, ranging from AML/CTF standards and financial stability frameworks to cross-border payment initiatives and crypto-asset regulatory road maps. While these efforts represent important progress, they remain fragmented across institutions and mandates. A functional global response therefore requires a more integrated multilateral governance architecture capable of harmonizing standards, coordinating enforcement and synchronizing technical infrastructures without undermining permissionless innovation. This section outlines the components of such a
Governing Digital Assets and Crypto-Enabled Financial Crime
13
regime, offering a blueprint for deeper international cooperation.
A Multilateral “Digital Asset Integrity Framework” A coherent global governance structure must begin with a unified conceptual framework for risk identification, compliance obligations and cross-border cooperation. A digital asset integrity framework (DAIF) would establish the foundational architecture for global alignment.
DAIF as a Coordinating Mechanism Rather Than a New Institution The DAIF should not be understood as a new supranational regulator. Rather, it would function as a coordination framework linking existing institutions, including the FATF, INTERPOL, the FSB, the BIS, the IMF, regional supervisory bodies and relevant private-sector stakeholders through shared standards, technical protocols and operational coordination mechanisms. Governance could be supported through a combination of member-state contributions, multilateral funding mechanisms and voluntary participation by regulated market actors. This approach focuses on building on existing institutional structures rather than on attempting to replace them, recognizing both the political realities of international governance and the decentralized nature of digital asset ecosystems.
Unified Standards and Definitions Today’s regulatory vocabulary varies widely: what counts as a VASP, a mixer, a DeFi protocol or a DAO differs by jurisdiction. A unified standard would create: → consistent definitions for digital asset intermediaries and infrastructures; → standardized typologies for crypto-enabled crime; → harmonized risk categories (such as high-risk privacy assets, sanctioned clusters or crosschain laundering typologies); and → baseline compliance expectations across jurisdictions. These shared definitions are prerequisites for effective enforcement and technical interoperability.
14
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
Multilateral Risk Assessment and Reporting Templates Borrowing from the FATF’s mutual evaluation process (FATF 2025b), the DAIF could introduce: → standardized reporting metrics for suspicious crypto activity; → global wallet-risk scoring benchmarks; → cross-border typology libraries updated in real time; and → template-based risk assessments for national regulators. This would reduce uneven implementation and create measurable compliance baselines across countries.
Incentive Mechanisms for Compliance Without incentives, multilateral frameworks often remain aspirational. Compliance mechanisms could include: → alignment with FATF mutual evaluations; → access to multilateral investigative support; → inclusion in secure blockchain analytics datasharing networks; and → preferential treatment in cross-border digital asset licensing. These incentives should create a governance ecosystem where compliance is beneficial rather than burdensome.
Data Sharing and Technical Interoperability Standards Crypto-enabled crime cannot be addressed without a shared technical infrastructure for data exchange. Unlike traditional payment systems, where interoperability generally increases network utility, digital asset ecosystems often compete through liquidity concentration, proprietary standards and ecosystem-specific network effects. As a result, interoperability cannot be assumed as a natural market outcome. Governance frameworks should therefore focus on enabling interoperability where it materially improves financial integrity, investigative cooperation and risk management, rather than
assuming universal technical convergence across competing blockchain ecosystems.
Common Principles for Wallet-Risk Assessment Rather than establishing a single global walletrisk score, a more realistic objective is the development of common principles for wallet-risk assessment. Given differing regulatory priorities, privacy frameworks and analytic methodologies across jurisdictions, complete standardization is unlikely. Instead, multilateral efforts should focus on harmonizing core risk indicators, attribution methodologies and information-sharing practices while allowing individual regulators, exchanges and analytics providers to maintain their own risk models. Developing the following principles, for example, would be helpful: → behavioural indicators (address clustering, transaction velocity, mixer interaction); → association with high-risk smart contracts or known exploit addresses; → cross-chain risk propagation; and → privacy-preserving scoring mechanisms using zero-knowledge proofs. Standardization ensures that risk scores are portable and interoperable across exchanges, regulators and jurisdictions
Federated Information-Sharing Architectures and Secure Analytics Exchanges A fully centralized global data lake is unlikely to be politically or operationally feasible given national sovereignty concerns, privacy regulations and the diversity of market participants. A more practical approach would involve federated informationsharing architectures that allow regulators, FIUs, law enforcement agencies and private-sector actors to exchange relevant intelligence through interoperable standards and secure interfaces while retaining control over their underlying data sets. This could include information such as: → federated data lakes for suspicious transaction patterns; → secure APIs allowing regulators and FIUs to exchange risk intelligence;
→ common data schemas for transaction metadata; and → cryptographically verifiable audit trails. Federated models avoid the risks of centralization while enabling cross-border intelligence flows.
Privacy-Preserving Information-Sharing Protocols To support both proactive compliance activities (such as Travel Rule compliance, sanctions screening and risk monitoring) as well as reactive investigative functions (such as asset tracing and cross-border enforcement), data exchange among regulators, FIUs, law enforcement agencies, VASPs and analytics providers should increasingly incorporate: → zero-knowledge proofs for compliance attestation; → differential privacy for batch analysis; → encrypted multiparty computation for joint investigations; and → privacy-safe audit logs. These tools allow regulators to verify compliance without accessing unnecessary personal data.
Joint Enforcement Mechanisms Global institutions must move beyond standard setting toward operational coordination. Effective multilateral enforcement combines intelligence exchange, coordinated action and synchronized legal processes.
INTERPOL-Led Rapid Response Taskforces A multilateral rapid response mechanism would allow: → real-time freezing and seizure of illicit digital assets; → coordinated takedowns of cross-border laundering networks; → accelerated subpoena processes synchronized across jurisdictions; and → direct integration with blockchain analytics systems.
Governing Digital Assets and Crypto-Enabled Financial Crime
15
Such a task force could resemble INTERPOL’s cybercrime model but be expanded to include DeFi, CBDCs, stablecoins and hybrid systems.
Such protocols reduce opportunities for criminals to exploit jurisdictional delays.
FATF Implementation Scorecards with Operational Indicators
The private sector controls much of the global digital asset infrastructure. Exchanges, stablecoin issuers, blockchain analytics firms, custodians, node operators and DAOs possess essential data and operational capabilities. However, decentralized systems present unique governance challenges because responsibility is often distributed across software developers, governance participants, validators and protocol users rather than concentrated in a single legal entity. The extent to which developers or DAO participants should be held accountable for activities occurring through decentralized protocols remains an evolving area of law and policy. Despite these uncertainties, no multilateral governance regime can succeed without meaningful engagement with both centralized intermediaries and decentralized ecosystem participants.
FATF compliance is currently measured by legal adoption rather than operational effectiveness. A multilateral regime could introduce metrics for: → rate of Travel Rule interoperability (for instance, the proportion of regulated entities able to securely exchange originator and beneficiary information across jurisdictions and compliance networks); → speed of STR/currency transaction report crossborder exchange (such as the time required for suspicious transaction reports or currency transaction reports to be transmitted and acted upon by relevant authorities); → quality of blockchain analytics integration (including the extent to which regulators, FIUs and law enforcement agencies utilize blockchain forensic tools for risk monitoring, attribution and investigations); and
Blockchain Analytics Firms as Governance Intermediaries These firms act as quasi-regulatory bodies by:
→ national enforcement actions linked to FATF standards (for example, asset freezes, prosecutions, sanctions-related investigations and successful recovery of illicit digital assets resulting from FATF-aligned frameworks).
→ identifying illicit clusters;
This transforms the FATF from a purely normative body into a performance-oriented governance institution.
→ supporting law enforcement investigations.
Global Freezing, Forfeiture and Recovery Protocols Digital assets are inherently mobile and liquid; freezing and recovery require coordinated jurisdictional responses. A multilateral protocol would align: → legal standards for seizure and forfeiture; → evidentiary rules for blockchain data; → processes for rapid asset freezing across exchanges and custodians; and → mechanisms for victims to claim recovered funds.
16
Role of the Private Sector
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
→ providing attribution intelligence; → monitoring high-risk smart contracts; and
Multilateral frameworks should formalize their role through standardized audit obligations, transparency requirements and interoperability benchmarks.
Exchanges, Custodians and Stablecoin Issuers These entities serve as enforcement gateways, performing: → sanctions screening; → Travel Rule compliance; → suspicious activity reporting; and → transaction monitoring.
Multilateral governance should establish uniform reporting templates and risk thresholds to prevent weak points in global supervision.
DAOs Some DAOs may voluntarily adopt governance mechanisms that facilitate compliance, transparency and risk management, while others may intentionally remain outside traditional institutional structures. The objective of governance should therefore not be to force institutional convergence but rather to identify practical points of engagement where decentralized communities and public authorities share interests in preventing illicit activity, enhancing ecosystem resilience and preserving market legitimacy. In this context, DAOs should be
viewed not as future regulated institutions but as governance actors whose participation in integrity frameworks may vary according to their design, incentives and community preferences.
Toward a Layered Multilateral Governance Architecture To integrate standards, enforcement, technical systems and private sector roles, this paper proposes a four-layer model, as outlined in Table 3:
Remaining Challenges and Forward Risks: Geopolitical Tensions and Fragmented Digital Sovereignty Geopolitics poses one of the most significant obstacles to multilateral governance of digital assets. The world is already fragmenting into
Table 3: Four-Layer Multilateral Governance Architecture for Digital Asset Integrity Layer
Layer 1: International Standard-Setting
Institutions / Actors
FATF, G20, Organisation for Economic Co-operation and Development, BIS
Core Functions
Governance Outputs
→ Define global terminology and classifications
→ Standardized definitions (VASPs, mixers, DAOs, DeFi)
→ Establish risk taxonomies for digital assets
→ Global AML/CTF frameworks
→ Set minimum compliance baselines
Layer 2: Operational Enforcement
INTERPOL, Europol, national law enforcement and FIUs
→ Conduct joint investigations
→ Real-time investigative actions
→ Share tactical and strategic intelligence
→ Multijurisdictional takedowns
→ Coordinate cross-border freezing, seizure and recovery → Provide foundational data and analytics
Layer 3: Technical Infrastructure
Layer 4: Market Actors and Decentralized Systems
Blockchains (permissioned and permissionless), blockchain analytics firms, standards bodies
VASPs, custodians, exchanges, stablecoin issuers, DAOs, validators
→ International benchmarks for regulatory implementation
→ Develop global technical standards → Enable compliance-bydesign tools
→ Enhanced FIU-to-FIU intelligence exchange
→ Global wallet-risk scoring standards → Shared data lakes and forensic protocols → Compliance APIs → Privacy-preserving attestation mechanisms (such as ZK-proofs)
→ Implement compliance rules
→ STRs
→ Conduct transaction monitoring and reporting
→ On-chain compliance automation
→ Execute programmatic enforcement in decentralized systems
→ Protocol-level safeguards and sanctions screening
Source: Author.
Governing Digital Assets and Crypto-Enabled Financial Crime
17
competing technological and financial blocs: the United States, the European Union, China and an increasingly assertive global majority predominantly constituting the Global South. Each bloc has differing motives, regulatory philosophies and national security priorities. → US policy is oriented around sanctions enforcement, anti-terrorism and the preservation of dollar hegemony. → EU policy emphasizes consumer protection, privacy and market stability through structured frameworks such as MiCA. → Mainland China rejects permissionless crypto entirely, while aggressively expanding statecontrolled blockchain and CBDC infrastructure. → With Hong Kong operating under a distinct regulatory framework, it has emerged as a controlled environment for Web3 innovation, virtual asset licensing, tokenization pilots and digital asset market development under the leadership of the Hong Kong Monetary Authority (HKMA) and Securities and Futures Commission. → Russia, Iran and the Democratic People’s Republic of Korea seek to exploit digital assets for sanctions evasion and asymmetric finance. → Offshore financial centres such as Malta, Bermuda, the Cayman Islands and the British Virgin Islands have sought to position themselves as digital asset hubs through relatively permissive regulatory frameworks. While these jurisdictions often provide valuable regulatory experimentation and innovation-friendly environments, differences in supervisory capacity, licensing standards and enforcement practices can create opportunities for regulatory arbitrage, allowing firms and illicit actors to exploit gaps between national regimes. These divergent strategies create political friction in harmonizing cross-border data sharing, enforcement operations and technical standards. Countries may be reluctant to share sensitive transaction data, analytics tools or investigative insights with geopolitical adversaries, undermining the effectiveness of a global integrity regime.
Divergent Privacy Regimes and Fundamental Rights Frameworks Governance frameworks must navigate dramatic differences in privacy expectations and legal protections across jurisdictions. The European Union’s GDPR imposes stringent limits on data retention and cross-border sharing, while the United States applies a sectoral approach with broad law-enforcement access. In contrast, China deploys pervasive state surveillance and mandates centralized control over data flows. These disparities complicate efforts to: → build shared data lakes; → standardize wallet attribution practices; → operationalize global analytics APIs; → exchange suspicious transaction reports efficiently; and → conduct joint blockchain investigations. The tension is especially stark in relation to PETs. Some jurisdictions view PETs as legitimate tools for civil liberties, while others could potentially consider them inherently suspicious. A multilateral regime must support privacypreserving compliance mechanisms to bridge these philosophical divides but disagreements will remain a recurring friction point.
Uneven Technological Maturity and Capacity Gaps The effectiveness of any global governance system relies on the capacity of national regulators, law enforcement agencies and FIUs to participate fully. Yet technological maturity varies dramatically. → Advanced jurisdictions have access to cuttingedge analytics tools, AI systems, real-time dashboards and skilled cyber-forensics experts. → Developing countries, by contrast, may lack blockchain forensics capabilities, sufficient training or even basic legal frameworks for digital assets. This disparity creates operational asymmetry: → Illicit actors exploit weaker jurisdictions as regulatory havens. → Investigations stall when data must pass through under-resourced authorities.
18
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
→ Weak enforcement in one jurisdiction undermines global resilience.
→ social or token-holder governance attacks against proposals perceived as centralizing;
Bridging these gaps requires sustained investment, capacity-building programs led by multilateral agencies and public–private partnerships that democratize access to analytic tools.
→ migration of non-compliant protocols to jurisdictions or networks resistant to regulation; and
The Challenge of Governing Rapidly Evolving Technology Blockchain ecosystems evolve far more quickly than governance structures. New technologies such as cross-chain bridges, layer-2 roll-ups, multi-party computation wallets, intent-based architectures and autonomous agents can reshape illicit finance dynamics in ways regulators have not anticipated. This presents several risks: → Rules or standards may become obsolete within months. → Smart contract vulnerabilities may cascade through ecosystems faster than investigators can respond. → Emerging technologies such as AI-driven laundering systems (autonomous mixers) may outpace current detection capabilities. → Decentralized governance mechanisms evolve unpredictably. The pace of innovation demands a multilateral regime that is not static but capable of continuous iteration, incorporating feedback loops from enforcement, analytics and market behaviour.
Ideological Resistance and Governance Fatigue Within Decentralized Communities A portion of the crypto ecosystem is motivated by anti-establishment and anti-regulatory ideologies. Segments of developer communities, DAO participants and privacy enthusiasts reject government involvement on principle. While these perspectives have legitimate historical contexts rooted in concerns about surveillance, political overreach and centralized control, they can produce resistance to even well-designed compliance mechanisms. This resistance manifests in: → reluctance to adopt compliance-by-design tools;
→ the proliferation of shadow tools (stealth addresses, cross-chain mixers, privacy coins). Governance must therefore be designed to minimize friction with decentralization values by emphasizing privacy-preserving, automated and non-intrusive compliance models.
Legal Fragmentation and Inconsistent Classifications of Digital Assets Digital assets are treated differently across jurisdictions as commodities (US Commodity Futures Trading Commission [CFTC]) and securities (US Securities and Exchange Commission [SEC]), although as of March 2026, the CFTC and SEC have finalized a joint framework confirming that many non-security crypto-assets are classified as digital commodities under the Commodity Exchange Act. This regulation covers assets whose value is derived from functional, decentralized and programmatic operations rather than managerial efforts, granting the CFTC authority to police fraud and manipulation in these markets (CFTC 2026). In the United Kingdom, digital assets have often been classified as property (Wagner 2025) or even been seen as contraband in Mainland China. Meanwhile, Hong Kong has emerged as a significant testing ground for Web3 innovation, virtual asset regulation, tokenization initiatives and digital finance under the supervision of the HKMA and other regulators, reflecting a broader strategy of regulated experimentation rather than outright technological rejection (He 2025). These inconsistencies complicate: → asset seizure, freezing and forfeiture; → tax reporting and cross-border investigations; → classification of intermediaries and obligations; and → supervision of stablecoin issuers and custodians. Without harmonized asset definitions, enforcement efforts frequently stall due to conflicting legal interpretations.
Governing Digital Assets and Crypto-Enabled Financial Crime
19
Risks of Regulatory Overreach and Chilling Effects on Innovation There is a real danger that policy makers, motivated by fear of illicit activity, may adopt overly broad or punitive regimes that:
governance architecture resilient enough to operate within them. Understanding these constraints is crucial for anticipating future vulnerabilities and ensuring that the regime can adapt alongside rapidly evolving digital asset ecosystems.
→ restrict legitimate privacy tools; → impose excessive burdens on small developers; → drive innovation offshore; → create de facto centralization through compliance costs; and → incentivize users to migrate to unregulated networks. Such scenarios can ironically increase illicit activity by pushing it into less transparent spaces.
Risks of Centralization Through Multilateral Infrastructure Different jurisdictions maintain distinct privacy standards, regulatory priorities and national security considerations. Likewise, blockchain analytics providers employ differing attribution methodologies and proprietary data sets. As a result, the objective should not be the creation of a single global database or universal risk score but rather the development of interoperable mechanisms that enable information exchange across diverse systems. This practice would also minimize systemic risks such as: → over-reliance on a small number of analytics firms; → concentration of sensitive financial data in shared systems; → potential weaponization of data during geopolitical conflict; and → vulnerability to coordinated cyberattacks. Even a sophisticated multilateral governance regime will confront enduring structural constraints that arise from political dynamics, technological complexity, legal fragmentation and ideological resistance. These challenges do not negate the value of a multilayered system; rather, they underscore why such an approach is essential. The goal is not to eliminate constraints, which remains a nearly impossible task, but to design a
20
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
Governance of Permissionless Innovation Designing effective governance for digital assets requires more than a regulatory response to emerging forms of financial crime. It demands a principled approach to innovation, one that recognizes the transformative potential of permissionless blockchain systems while addressing the risks associated with their misuse. Too often, policy discourse has been polarized between those who view cryptocurrencies as intrinsically dangerous and those who dismiss any form of oversight as antithetical to decentralization. Neither position offers a viable path forward. Instead, a sustainable governance strategy must balance the imperatives of financial integrity, consumer protection and technological progress. A central challenge is avoiding the stigmatization of permissionless blockchains. Public debate frequently frames these systems as opaque or criminal by design yet this perception overlooks a fundamental reality: blockchains are among the most transparent financial infrastructures ever created. Every transaction is recorded immutably on a public ledger, auditable by anyone with an internet connection. While pseudonymity complicates attribution, it does not eliminate traceability; with the aid of blockchain analytics, investigators can reconstruct transactional histories with a degree of granularity rarely possible in traditional finance. In fact, the proportion of illicit activity in the crypto ecosystem remains significantly smaller than commonly assumed, especially when compared to the trillions of dollars laundered annually through conventional banking channels (Chainanalysis Team 2025b). Misuse is real and growing but it does not define the technology. The argument for a non-stigmatizing governance approach is further strengthened by the substantial benefits that permissionless innovation has delivered. Open blockchain networks have
enabled low-friction, cross-border payments, democratized access to financial services, introduced programmable instruments that automate economic coordination and inspired new models of decentralized governance (Javaid et al. 2022). These innovations have already begun reshaping the architecture of the digital economy. Overly restrictive or poorly informed regulatory interventions risk displacing these innovations into unregulated jurisdictions or confining development to institutional settings that replicate the very centralization these technologies were designed to overcome. The objective must therefore be to regulate harmful behaviours without constraining the system’s capacity for legitimate and beneficial experimentation. Achieving this balance requires a set of governance principles that are technologically neutral, proportionate to risk and respectful of privacy. Technology neutrality means that regulation should target the nature of the activity, whether it presents risks of money laundering, terrorist financing, consumer harm or systemic instability, rather than the specific tools used to carry it out (Ojanen 2025). Permissionless blockchains, PETs or decentralized applications should not be presumed harmful simply because they are new or complex. Instead, risk should be judged within the context of actual use patterns and threat assessments. It is also important to distinguish between permissioned and permissionless systems, as the governance challenges they present are fundamentally different. Permissioned networks — including institutional DLT platforms, tokenized deposit systems and many CBDC infrastructures — contain identifiable participants and can generally be governed through approaches analogous to existing financial market infrastructure oversight. Permissionless networks present a different challenge. In many cases, there may be no operator, administrator or legal entity capable of implementing regulatory directives. For such systems, governance may more closely resemble the evolution of the public internet, where standards bodies, open-source communities, market incentives and layered governance mechanisms collectively shape behaviour without centralized control. Effective governance frameworks should therefore avoid assuming that models designed for permissioned financial infrastructures can be directly applied to decentralized public networks.
Proportionality is equally important. Not all digital asset activities pose the same risks. Retail payments on a well-audited stablecoin network differ markedly from high-risk transactions flowing through unregulated mixers or privacyfocused protocols. Governance frameworks must therefore allow for differentiated obligations that reflect the diverse risk profiles within the ecosystem. A blunt one-size-fits-all approach not only burdens low-risk activity but often fails to deter high-risk behaviour effectively. Privacy itself must be treated as a public good, not an obstacle to regulation. Individuals and businesses require confidentiality for legitimate reasons, ranging from commercial competition to personal security. Emerging technologies such as zero-knowledge proofs allow regulators to verify compliance without accessing sensitive underlying data, demonstrating that privacy and enforcement need not be mutually exclusive. Embedding such privacy-preserving compliance mechanisms into governance frameworks can align individual rights with public safety. One of the most promising paths toward governing permissionless innovation lies in embedding compliance directly into code. Programmable compliance transforms regulatory obligations into automated functions that operate within blockchain protocols themselves (Chainlink 2025). Smart contracts can be designed to detect sanctioned or high-risk wallets, enforce behavioural thresholds or trigger alerts when suspicious patterns emerge. Protocols can include circuit breakers that halt anomalous market behaviour or route transactions through risk screens. Over time, these mechanisms can evolve from manual oversight tools into algorithmic safeguards that operate continuously and transparently. Zero-knowledge proofs further enable privacypreserving compliance. They allow users to demonstrate that they meet regulatory requirements, such as passing sanctions checks or proving the legitimacy of funds, without revealing the underlying data (Burleson, Korver and Boneh 2022). This reconciles two fundamental but often competing objectives: preserving user privacy and ensuring regulatory assurance. By integrating these cryptographic tools into permissionless systems, compliance becomes not an external imposition but an inherent feature of the infrastructure.
Governing Digital Assets and Crypto-Enabled Financial Crime
21
DAOs also have an important role to play; rather than viewing them as ungovernable or beyond regulatory reach, they can be engaged as partners in shaping responsible innovation. DAOs can adopt internal compliance norms, create governance modules for risk management or incorporate emergency authority measures to address emerging threats. Regulators, in turn, can interact with DAOs through formal governance proposals, transparency attestations, or public consultation processes. Such engagement transforms DAOs from potential adversaries into participants in a shared governance ecosystem. A governance model that embraces permissionless innovation without stigmatizing it yields substantial benefits. It potentially enhances compliance outcomes by leveraging the programmability and transparency of blockchain systems, strengthens market integrity through robust yet flexible oversight and promotes regulatory legitimacy by aligning enforcement with the technology’s inherent characteristics. Most importantly, it encourages responsible innovation by allowing legitimate developers and users to operate within a clear, predictable and supportive regulatory environment. Taken together, these principles and mechanisms demonstrate that permissionless innovation is not incompatible with strong governance. On the contrary, it offers an opportunity to build a more transparent, inclusive and resilient financial system, one in which compliance can be enhanced through technological design rather than enforced solely through institutional authority. These insights set the stage for the final section of this paper, which outlines a multilayered international governance architecture capable of operationalizing these ideas on a global scale.
Conclusion Digital assets represent a profound shift in the structure of global finance. Their emergence has enabled new forms of economic coordination, programmable value transfer and cross-border inclusion, while simultaneously expanding the terrain of financial crime and introducing complex governance challenges. This paper has argued that addressing these risks requires moving beyond traditional regulatory models and embracing a multilayered governance architecture capable of aligning international standards, cross-border enforcement, technical infrastructure and decentralized market actors. Effective oversight need not rely on prohibitions or centralized controls. Instead, it must integrate technological tools such as blockchain analytics, zero-knowledge compliance mechanisms and programmable risk controls with institutional coordination and clear, adaptive regulatory standards. The four-layer model proposed here offers such a structure: global bodies set definitions and risk expectations; enforcement agencies coordinate operations across borders; shared technical systems provide real-time intelligence; and market participants embed compliance into the infrastructure itself. Persistent constraints remain. Geopolitical rivalries, divergent privacy laws, uneven regulatory capacity and ideological resistance within decentralized communities will continue to complicate cooperation. Yet these challenges reinforce the need for a flexible, interoperable governance regime rather than one that is centralized or static. A distributed system rooted in common standards but adaptable to technological evolution offers the best chance of safeguarding financial integrity without suppressing innovation. Ultimately, the question is not whether digital assets can be governed but how governance can evolve to reflect the realities of a borderless, programmable financial system. If global institutions, national regulators and decentralized networks can converge around shared principles of interoperability, proportionality and privacy protection, the result will be a governance model that mitigates illicit finance while enabling digital assets to contribute meaningfully to a more transparent, inclusive and resilient global economy.
22
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
Works Cited Ahmed, Shehnaz. 2022. “Rise of Decentralised Finance: Reimagining Financial Regulation.” Indian Journal of Law and Technology 17 (1): Article 1. https://doi.org/10.55496/GBYY2818. Aldasoro, Iñaki, Jon Frost, Sang Hyuk Lim, Fernando Perez-Cruz and Hyun Song Shin. 2025. “An approach to anti-money laundering compliance for cryptoassets.” BIS Bulletin No. 111, August 13. www.bis.org/publ/bisbull111.htm. Arctic Intelligence. 2025. “The Evolving Role of the Financial Action Task Force (FATF) in Global AML/CTF Governance.” Arctic Intelligence, April 9. https://arctic-intelligence.com/insights/ financial-action-task-force-fatf-global-aml-ctf-governance. Banerjee, Aritra, Michael Clear and Hitesh Tewari. 2020. “Demystifying the Role of zk-SNARKs in Zcash.” In 2020 IEEE Conference on Application, Information and Network Security (AINS), 12–19. https://doi.org/10.1109/ AINS50155.2020.9315064. Basel Institute on Governance. 2025. “Smarter blockchain investigations: insights from INTERPOL.” Basel Institute on Governance (blog), March 12. https://baselgovernance.org/ blog/smarter-blockchain-investigations-insights-interpol. Basel Institute on Governance and Europol. 2022. Seizing the opportunity: 5 recommendations for crypto assets-related crime and money laundering. 2022 Recommendations of the Joint Working Group on Criminal Finances and Cryptocurrencies. December 7. https://baselgovernance.org/resources/ publications/seizing-opportunity-5-recommendationscrypto-assets-related-crime-and-money-laundering/. Burleson, Joseph, Michele Korver and Dan Boneh. 2022. “PrivacyProtecting Regulatory Solutions Using Zero-Knowledge Proofs.” a16zcrypto, November 15. https://a16zcrypto.com/ posts/article/privacy-protecting-regulatory-solutionsusing-zero-knowledge-proofs-full-paper/. CFTC. 2026. “CFTC Joins SEC to Clarify the Application of Federal Securities Laws to Crypto Assets.” Press Release, March 17. www.cftc.gov/PressRoom/PressReleases/9198-26. Chainanalysis Team. 2024. “$2.2 Billion Stolen from Crypto Platforms in 2024, but Hacked Volumes Stagnate Toward Year-End as DPRK Slows Activity Post-July.” Chainanalysis (blog), December 19. www.chainalysis.com/blog/ crypto-hacking-stolen-funds-2025/.
———. 2025a. “2025 Crypto Crime Trends: Illicit Volumes Portend Record Year as On-Chain Crime Becomes Increasingly Diverse and Professionalized.” Chainanalysis (blog), January 15. www.chainalysis.com/blog/2025-crypto-crimereport-introduction/. ———. 2025b. “Cryptocurrency donations to extremist groups dip globally, but white supremacism, nationalism, and anti-Semitism grow across Europe.” Chainanalysis (blog), January 23. www.chainalysis.com/blog/extremism-crypto-2025/. Chainlink. 2025. “Automating Policy Enforcement With Smart Contracts.” Chainlink (blog), July 11. https://chain.link.blog/ policy-enforcement-via-smart-contracts/. Chao, William. 2023. “Crypto exchange’s jurisdiction-shopping: a regulatory problem that requires a global response.” Columbia Journal of Transnational Law, February 23. www.jtl.columbia.edu/bulletin-blog/ crypto-exchanges-jurisdiction-shopping-a-regulatoryproblem-that-requires-a-global-response. Chegenizadeh, Mostafa, Sina Rafati Niya and Claudio J. Tessone. 2025. “Heuristic-Based Address Clustering in Cardano Blockchain.” Preprint, arXiv, March 12. https://arxiv.org/abs/2503.09327. Clapham, Benjamin, Jenny Jakobs, Julian Schmidt, Peter Gomber and Jan Muntermann. 2023. “A Taxonomy of Violations in Digital Asset Markets.” Rising like a Phoenix: Emerging from the Pandemic and Reshaping Human Endeavors with Digital Technologies ICIS 2023. December 11. https://d-nb.info/131588674X/34. De.Fi Security. 2025. “DeFi Rekt Report Q3 2025: $434M Lost Across 40+ Exploits.” De.Fi (blog), October 1. https://de.fi/blog/defi-rekt-report-q32025-434m-lost-across-40-exploits. Elliptic. 2023. “Cross-chain crime: over half a billion dollars laundered through a cross-chain bridge.” Elliptic (blog), May 9. www.elliptic.co/blog/analysis/ cross-chain-crime-more-than-half-a-billion-dollars-hasbeen-laundered-through-a-cross-chain-bridge. ———. 2025. “Chain-hopping emerges as defining money laundering method of 2025.” Elliptic (blog), November 18. www.elliptic.co/blog/chain-hoppingdefining-money-laundering-method-of-2025. Elliptic Global Policy and Research Group. 2024. “Crypto regulatory affairs: Crackdown on crypto mixers and privacy wallets continues with Samourai Wallet takedown.” Elliptic (blog), April 30. www.elliptic.co/blog/crackdown-on-crypto-mixersand-privacy-wallets-continues-with-samurai-wallet-takedown.
Governing Digital Assets and Crypto-Enabled Financial Crime
23
FATF. 2025a. Best Practices: Travel Rule Supervision. June. Paris, France: FATF. www.fatf-gafi.org/content/dam/fatf-gafi/ recommendations/Best-Practices-Travel-Rule-Supervision.pdf. ———. 2025b. Targeted Update on Implementation of the FATF Standards on Virtual Assets and Virtual Asset Service Providers. June. Paris, France: FATF. www.fatf-gafi.org/ content/dam/fatf-gafi/recommendations/2025Targeted-Upate-VA-VASPs.pdf.coredownload.pdf. ———. 2026. Procedures For the FATF AML/CFT/CPF Mutual Evaluations, Follow-Up and ICRG. June. Paris, France: FATF. www.fatf-gafi.org/en/publications/ Mutualevaluations/5th-Round-Procedures.html. He, Alex. 2025. “Digital Assets Regulation: Lessons from Mainland China and Hong Kong.” CIGI Paper No. 329. Waterloo, ON: Centre for International Governance Innovation. www.cigionline.org/static/documents/no.329He.pdf. Helliar, Christine V., Louise Crawford, Laura Rocca, Claudio Teodori and Monica Veneziani. 2020. “Permissionless and permissioned blockchain diffusion.” International Journal of Information Management 54: 102136. https://doi.org/10.1016/j.ijinfomgt.2020.102136.
Kumar, Reddy Pawan, Athif Ahmed, Aabha Dixit and Armaan Mistry. 2025. “Blockchain & Cryptocurrency Laws and Regulations 2026 — India.” Global Legal Insights, October 21. www.globallegalinsights.com/practice-areas/blockchaincryptocurrency-laws-and-regulations/india/. Marc. 2024. “South Korea Establishes New Cybersecurity Task Force to Combat Cryptocurrency-Related Cybercrime.” Cybersec Asia, August 26. https://cybersec-asia.net/ south-korea-establishes-new-cybersecurity-task-forceto-combat-cryptocurrency-related-cybercrime/. Nansen Intern. 2025. “What Is Transaction Clustering in Crypto?” Nansen.AI, July 31. www.nansen.ai/post/whatis-transaction-clustering-in-crypto-address-analysis. Ocampo, Denise Garcia. 2025. “Stablecoin-related yields: some regulatory approaches.” Financial Stability Institute Brief No. 27. Bank for International Settlements. October. www.bis.org/fsi/fsibriefs27.pdf.
Hume, Tim and News Agencies. 2025. “US, UK sanction huge Southeast Asian crypto scam network.” Al Jazeera, October 15. www.aljazeera.com/news/2025/10/15/us-uksanction-huge-southeast-asian-crypto-scam-network.
Ojanen, Atte. 2025. “Technology Neutrality as a Way to FutureProof Regulation: The Case of the Artificial Intelligence Act.” European Journal of Risk Regulation 16 (4): 1440–55. https://doi.org/10.1017/err.2025.10024.
IMF and FSB. 2023. “IMF-FSB Synthesis Paper: Policies for CryptoAssets.” September 7. www.fsb.org/uploads/R070923-1.pdf.
Pavlidis, Georgios. 2023. “The dark side of anti-money laundering: Mitigating the unintended consequences of FATF standards.” Journal of Economic Criminology 2: 100040. https://doi.org/10.1016/j.jeconc.2023.100040.
Jammot, Clara. 2025. “Cryptocurrency and Extremism: How Social Network Analysis is Used to Track Extremist Cryptocurrency Donations.” Global Network on Extremism and Technology, March 24. https://gnet-research.org/2025/03/24/ cryptocurrency-and-extremism-how-social-network-analysisis-used-to-track-extremist-cryptocurrency-donations/. Jamwal, Shivani, José Cano, Gyu Myoung Lee, Nguyen H. Tran and Nguyen Troung. 2024. “A survey on Ethereum pseudonymity: Techniques, challenges, and future directions.” Journal of Network and Computer Applications 232: 104019. https://doi.org/10.1016/j.jnca.2024.104019. Javaid, Mohd, Abid Haleem, Ravi Pratap Singh, Rajiv Suman and Shahbaz Khan. 2022. “A review of Blockchain Technology applications for financial services.” BenchCouncil Transactions on Benchmarks, Standards and Evaluations 2 (3): 100073. https://doi.org/10.1016/j.tbench.2022.100073.
24
Kumar, Amrendra and Sagar Choudhary. 2025. “Decentralized Finance (Defi) Security: Ai-Based Risk Detection.” International Journal of Engineering Development and Research 13 (3): 121–38. https://rjwave.org/ijedr/papers/IJEDR2503016.pdf.
CIGI Papers No. 362 — September 2026 • S. Yash Kalash
Pessarlay, Wahid. 2022. “Interpol sets up specialized unit to crack down on illegal digital asset activities.” CoinGeek, October 22. https://coingeek.com/interpol-sets-up-specialized-unitto-crack-down-on-illegal-digital-asset-activities/. Qin, Kaihua, Liyi Zhou, Benjamin Livshits and Arthur Gervais. 2020. “Attacking the DeFi Ecosystem with Flash Loans for Fun and Profit.” Preprint, arXiv, March 8. https://arxiv.org/abs/2003.03810. Safeheron Team. 2025. “What Are the Different Types of Crypto Custody and How Do They Work?” Web3Learning (blog), July 1. https://safeheron.com/blog/types-ofcrypto-custody-self-partial-third-party-explained/. Shala, Atis. 2025. “VASP KYC in 2025: The New Standard for Crypto Compliance.” Coincub, September 7. https://coincub.com/vasp-kyc-2025/.
Sharma, Arpit, Sanyukta Singh and Adwait Pratap Singh. 2025. “Blockchain and Cryptocurrency Tracing as Evidence — Legal Frameworks for Using On-Chain Data in Financial Crime Investigations.” International Journal of Innovative Research in Technology 12 (6): 2253–61. https://ijirt.org/ publishedpaper/IJIRT186636_PAPER.pdf. Siron, Dorothy and Federico Paesano. 2022. “Cryptocurrencies in Asia and beyond: law, regulation and enforcement.” Working Paper 38, Basel Institute on Governance. https://baselgovernance.org/publications/wp-38. Tsentsura, Kostiantyn. 2025. “Crypto Under Sanctions: How Restricted Nations Are Adopting Bitcoin and Stablecoins.” Yellow, September 12. https://yellow.com/research/ crypto-under-sanctions-how-restricted-nationsare-adopting-bitcoin-and-stablecoins. U.S. Department of the Treasury. 2023. Illicit Finance Risk Assessment of Decentralized Finance. April. Washington D.C.: U.S. Department of the Treasury. https://home.treasury.gov/ system/files/136/DeFi-Risk-Full-Review.pdf. — — — . 2025. “Treasury Sanctions DPRK Bankers and Institutions Involved in Laundering Cybercrime Proceeds and IT Worker Funds.” Press Release, November 4. https://home.treasury.gov/news/press-releases/sb0302. Wagner, Elizabeth. 2025. “The Property (Digital Assets etc) Act 2025 — What it means for crypto assets.” Clyde&Co, December 3. www.clydeco.com/en/insights/2025/08/ the-property-bill-impact-on-crypto-assets-market. Zetzsche, Dirk A., Ross P. Buckley, Douglas W. Arner and Linus Föhr. 2019. “The ICO Gold Rush: It’s a Scam, It’s a Bubble, It’s a Super Challenge for Regulators.” Harvard International Law 60 (2): 267–315. https://journals.law.harvard.edu/ ilj/wp-content/uploads/sites/84/3_ICO_60.2.pdf.
Governing Digital Assets and Crypto-Enabled Financial Crime
25
Human Analysis Standard For AI Use in Policy Research
67 Erb Street West Waterloo, ON, Canada N2L 6C2 cigionline.org