The Hidden Layer: How Crypto Exchanges Are Losing Visibility Into $8 Billion in Nested Transactions
Crypto exchanges are facing a major compliance blind spot: $8 billion in transactions flowing through third-party services operating inside their own platforms, with little visibility into who the actual users are. A new analysis from Crystal Intelligence reveals how this nested arrangement creates gaps in financial crime detection, even as regulators tighten oversight of the crypto industry.
What Are Nested Crypto Services and Why Should You Care?
Imagine a smaller crypto exchange or payment processor that doesn't want to build its own infrastructure. Instead, it opens an account at a major, regulated exchange like Coinbase or Kraken and routes customer transactions through that account. The host exchange knows the nested service as a customer, but has no direct relationship with the nested service's end users. This arrangement is called a nested structure, and it's become a significant regulatory challenge.
The problem is straightforward: when a host exchange performs Know Your Customer (KYC) checks and transaction monitoring, it's checking the nested service itself, not the thousands of actual users behind it. If that nested service is operating in a high-risk jurisdiction or handling illicit activity, the host exchange may never know. This creates what regulators call "concentration risk" and compliance gaps that can expose major exchanges to sanctions violations, money laundering, and other financial crimes.
How Big Is the Nested Transaction Problem?
Crystal Intelligence analyzed 2.275 million transactions across 2,052 attributed wallet addresses spanning more than 330 blockchains between 2017 and 2025. The findings are striking: $8 billion in total volume moved through nested services at 39 regulated host exchanges. Transaction volume peaked in 2021 at $3.12 billion, and nested services were identified across 63 countries.
The concentration is even more alarming. A single host exchange handled 87 percent of the total nested volume, creating a single point of failure for compliance monitoring. Two legitimate services, ChangeNow and SimpleSwap, together accounted for $5.4 billion, or 54.2 percent of all identified nested flows.
What Types of High-Risk Activity Are Hidden in These Flows?
The research identified several categories of concerning activity routed through nested arrangements. Iran-facing nested services moved approximately $239 million across 17 entities, with at least one remaining active through December 2025. An unlicensed cash desk processed $395 million through a regulated exchange across 11,153 transactions, averaging around $33,300 per transaction, a pattern typical of over-the-counter (OTC) activity for high-net-worth clients. In this case, the host exchange held KYC records only on the cash desk itself, not on the underlying customers.
The report also flagged emerging multi-host strategies, in which entities operate simultaneously across several exchanges. This approach leaves no single exchange with a complete view of their activity, making it nearly impossible for regulators to detect suspicious patterns.
How Are Regulators Responding to This Gap?
Crystal Intelligence linked its findings to two major regulatory developments: the European Union's Markets in Crypto-Assets Regulation (MiCA) and Travel Rule requirements. These rules require exchanges to share customer information when processing transactions, but they assume that transactions originating from a licensed exchange are inherently low-risk. The nested service problem breaks that assumption. A transaction from a regulated exchange can now be traced back to an unregistered broker operating in a high-risk jurisdiction, yet compliance teams may never see that connection.
The company argues that entity-level attribution at the nested-service level, rather than address-level screening alone, is necessary to make these risks visible to compliance teams. Without this shift, regulators and exchanges will continue to miss financial crime signals hidden inside legitimate-looking transactions.
Steps Regulators and Exchanges Can Take to Close the Gap
- Optimized Detection: Regulated exchanges should implement blockchain analytics capable of identifying nested services using shared infrastructure, rather than relying on address-level screening alone.
- Mandatory Disclosure: Permissioned nested arrangements should require mandatory disclosure obligations, including KYC requirements applied directly to end customers, not just the nested service operator.
- Risk-Based Monitoring: Exchanges need to deploy entity-level attribution tools that can track beneficial originators across multiple transactions and jurisdictions, enabling risk-based monitoring tailored to the actual user profile.
- Cross-Exchange Information Sharing: Centralized monitoring or information-sharing mechanisms between exchanges would help detect entities operating across multiple host platforms simultaneously.
Crystal Intelligence emphasized that these four areas require immediate attention from both regulated exchanges and supervisory authorities. Without action, the nested service model will continue to create blind spots in the global financial system, even as crypto adoption accelerates.
What Does This Mean for the Broader Crypto Ecosystem?
The nested service problem highlights a fundamental tension in crypto regulation: as exchanges become more regulated and compliance-heavy, smaller players find ways to operate through their infrastructure without full transparency. This isn't necessarily illegal, but it creates systemic risk. If a major exchange unknowingly hosts billions in transactions from high-risk jurisdictions or unlicensed operators, it could face sanctions, enforcement action, or reputational damage.
For users and institutions, the takeaway is that regulatory compliance at the exchange level doesn't guarantee visibility into all activity flowing through that exchange. The crypto industry is maturing, but the infrastructure for detecting financial crime is still catching up to the complexity of how transactions actually move through the system.