FATF July 2026: Stablecoins Fuel 84% of Crypto Crime
FATF's July 2026 report reveals stablecoins now drive 84% of illicit crypto flows, with $154 billion laundered in 2025. What every CASP must do now.

The Financial Action Task Force published its latest virtual assets typologies report on July 17, 2026. The headline finding should alarm every crypto-asset service provider operating in a regulated market: stablecoins now account for 84% of all illicit virtual asset transaction volume globally. That figure, drawn from Chainalysis data covering 2025 activity, marks a structural shift in how criminal networks move money — and a direct challenge to how most CASPs have designed their KYC and transaction monitoring programs.
The report does not describe an emerging trend. It documents a fait accompli. Stablecoins are already the primary money laundering instrument in the virtual asset sector. The compliance infrastructure most CASPs built for Bitcoin-era risk profiles is increasingly misaligned with the actual threat environment they operate in.
The Scale of the Problem
The raw numbers demand attention. Illicit virtual asset transaction volume reached $154 billion in 2025, according to Chainalysis data cited in the FATF report. TRM Labs, using a parallel methodology, estimated the figure at $158 billion — a difference that reflects differing data access rather than analytical disagreement. Both estimates represent a near-doubling of illicit flows compared to 2024 levels.
Stablecoins drove that surge. Approximately $51 billion of the illicit total in 2024 was linked to fraud and scam operations, with stablecoin rails providing the primary settlement layer. The structural logic is clear: stablecoins offer the price stability that large-scale commercial crime requires, the settlement speed that enables rapid layering across multiple addresses, and enough pseudonymity from external oversight while maintaining internal auditability within criminal networks.
| Metric | Figure |
|---|---|
| Illicit virtual asset volume (2025) | $154 billion (Chainalysis) / $158 billion (TRM Labs) |
| Stablecoin share of illicit flows | 84% |
| Illicit funds linked to fraud and scams | ~$51 billion (2024) |
| Year-over-year growth in illicit flows | ~145% |
| Jurisdictions largely FATF-compliant | 34% (51 of 149 assessed) |
FATF's analysis identifies scam compounds and investment fraud networks as the primary drivers of laundering flows — sophisticated operations that use stablecoin rails to collect victim proceeds, layer funds, and move value across jurisdictions without ever touching the traditional banking system.
Criminal-Engineered Stablecoins: The Unsolvable Problem
The most alarming finding in the July 2026 report is not the volume figures. It is FATF's identification of what can only be described as compliance-resistant stablecoin infrastructure: instruments deliberately engineered by criminal networks to be impossible to freeze or seize.
Major stablecoin issuers — Tether, Circle, and comparable operators — maintain compliance programs that allow them to freeze wallet addresses linked to confirmed illicit activity. Law enforcement agencies have used these mechanisms with meaningful results, recovering funds in significant cases. Criminal networks have responded by issuing their own stablecoins. These instruments carry no compliance infrastructure by design: no issuer to compel, no freeze mechanism to invoke, and no KYC database that can be subpoenaed.
The Cambodia-based financial services conglomerate identified in the FATF report illustrates the scale this infrastructure has reached. The network laundered at least $4 billion in illicit proceeds between 2021 and 2025, serving both organized crime fraud operations and North Korean state-linked cyber theft through the same settlement rails. It is not an isolated case study. It is the documented operational template of a growing sector.
This is categorically different from the opportunistic use of pseudonymous Bitcoin that defined the first generation of crypto money laundering. It is engineered, industrial-scale circumvention of compliance mechanisms — and it is scaling in parallel with legitimate stablecoin adoption.
The Global Compliance Gap That Enables This
FATF's report is explicit about the compliance failure that makes this threat landscape possible. As of April 2026, only 51 of 149 assessed jurisdictions — 34%, up from 29% a year earlier — were rated "largely compliant" with FATF's Recommendation 15 governing virtual assets. Progress is real, but so is the remaining gap.
FATF identifies five areas where significant failures persist:
- Licensing and registration standards for virtual asset service providers
- Beneficial ownership transparency of VASPs themselves
- Travel Rule implementation across jurisdictions
- Suspicious transaction reporting frameworks calibrated to virtual asset patterns
- Cross-border information sharing between financial intelligence units
The Travel Rule failure is the most operationally consequential. FATF's Recommendation 16 requires that verified originator and beneficiary identity data accompany every qualifying virtual asset transfer. In practice, as covered in our analysis of the MiCA Travel Rule implementation, approximately 35% of EU-registered CASPs had not fully operationalized Travel Rule data transmission by the July 2026 deadline — and the EU is one of the more advanced regulatory environments globally.
When identity data does not travel with transfers, stablecoin transactions become effectively opaque between jurisdictions. Criminal networks exploit this systematically: layering transactions are routed through chains of counterparty CASPs selected specifically because those institutions have weak Travel Rule infrastructure.
What CASPs Must Do: A Practical Response Framework
FATF's July report is the predicate for enforcement action. Based on the typical FATF typology-to-enforcement cycle, national supervisors and — in the EU, the newly operational Anti-Money Laundering Authority (AMLA) — typically intensify examination activity 12 to 18 months after a major typologies publication. CASPs that fail to recalibrate their compliance programs now will be poorly positioned when that cycle arrives.
For a comprehensive overview of how AMLA is operationalizing its supervisory mandate, see our coverage of AMLA and EU crypto KYC compliance.
The specific program elements that need attention:
Stablecoin-Specific Transaction Monitoring
Transaction monitoring rule sets built for Bitcoin or Ethereum retail patterns are not calibrated for stablecoin risk. The velocity, sizing, and layering patterns used by organized crime in stablecoin transactions look materially different from the retail crypto activity those rules were designed to detect.
Monitoring programs need to be recalibrated to flag:
- Rapid cycling between stablecoin instruments, particularly obscure or newly issued ones
- High-velocity transfers to self-hosted wallets
- Transfers to counterparty CASPs in FATF-identified high-risk jurisdictions
- Unusual concentration of activity in stablecoin instruments with no established compliance infrastructure
Travel Rule Remediation
Gaps in Travel Rule compliance are now directly connected to the typologies FATF has published. A stablecoin transfer that cannot be accompanied by verified originator data is a stablecoin transfer that money laundering infrastructure is designed to exploit. For a full breakdown of what Travel Rule-ready KYC infrastructure requires, see the State of KYC in Crypto 2026.
Counterparty CASP Risk Assessment
FATF identifies that criminal networks deliberately route transactions through CASPs with weak compliance posture, using better-supervised institutions as exit ramps. This means that counterparty risk — assessing the compliance posture of other CASPs from which you receive stablecoin transfers — needs to be embedded in your AML program architecture, not treated as an afterthought to onboarding controls.
Novel Stablecoin Instrument Screening
The emergence of criminal-issued stablecoins creates a new screening requirement: identifying when customers are transacting in instruments that have no identifiable compliant issuer. If a stablecoin cannot be attributed to a licensed and FATF-compliant issuer, that fact itself is a risk indicator warranting enhanced due diligence.
Why Continuous Monitoring Changes the Calculus
The stablecoin laundering patterns documented in the July 2026 report are not detectable at onboarding. A customer who passes all identity verification checks and presents a clean risk profile at the point of account opening may be recruited, compromised, or coerced into facilitating criminal transactions months later. The Cambodia conglomerate's infrastructure operated through exactly this mechanism: legitimate customers whose accounts were subsequently used to layer criminal proceeds.
This is the foundational argument for continuous, autonomous monitoring rather than periodic review cycles tied to KYC refresh schedules. Our analysis of agentic KYC and AI-driven compliance automation explains in detail how systems that monitor customer behavior continuously — detecting anomalies in real time rather than flagging accounts only at annual refresh — are better positioned to identify the behavioral signatures of account misuse.
Joinble's AI Agents are built for this operating model: ongoing identity and behavioral monitoring across the full customer lifecycle, with automated escalation when transaction patterns deviate from expected behavior for a given risk profile. In the context of stablecoin laundering, that means catching the signal when a previously dormant account begins receiving high-velocity stablecoin transfers from counterparties in high-risk jurisdictions — and triggering enhanced due diligence before the pattern accumulates into regulatory exposure.
The US Dimension
The FATF findings arrive against a backdrop of parallel regulatory development in the United States. The GENIUS Act stablecoin KYC framework, implemented through a proposed rulemaking by FinCEN and four co-agencies published in June 2026, introduces bank-grade Customer Identification Program requirements for US Permitted Payment Stablecoin Issuers. Our coverage of the GENIUS Act KYC requirements details what compliance programs must include.
The convergence of FATF guidance and US regulatory action signals a global move toward treating stablecoin issuers and CASPs as the load-bearing compliance layer for a financial instrument that has demonstrably become the primary vehicle for large-scale money laundering. The window for treating stablecoins as standard crypto assets — from a risk calibration standpoint — has closed.
Examination Readiness Checklist
Before the next supervisory examination cycle, compliance teams should be able to answer affirmatively to the following:
| Control | Status Check |
|---|---|
| Stablecoin transaction monitoring rules calibrated separately from general crypto rules | Can you demonstrate this to a supervisor? |
| Travel Rule compliance for all stablecoin outbound transfers | No exceptions for "minor" transfers? |
| Self-hosted wallet verification for stablecoin withdrawals | Applied consistently? |
| Counterparty CASP risk scoring methodology | Are high-risk-jurisdiction CASPs flagged? |
| Screening for unlicensed or compliance-resistant stablecoins | Any process for this? |
| Continuous behavioral monitoring between KYC refresh cycles | Or still batch/annual? |
AMLA's examination focus for 2026 and 2027 is expected to track closely with FATF's published risk typologies. CASPs that cannot demonstrate they have read and operationalized the July 2026 report will face harder questions than those who can show a documented response.
FAQ
Why are stablecoins now the primary money laundering vehicle? Stablecoins offer price stability that volatile cryptocurrencies cannot match — critical for large-scale commercial fraud operations that collect, hold, and convert proceeds over extended periods. Combined with high settlement speed, programmability, and the existence of compliant-free stablecoin variants in criminal jurisdictions, they are structurally better suited to commercial-scale laundering than Bitcoin or Ethereum.
What are criminal-engineered stablecoins and can they be traced? These are instruments issued specifically without compliance infrastructure: no KYC, no freeze mechanisms, no identifiable issuer to compel. On-chain transactions are visible on the blockchain, but traceability without a compliance-capable issuer provides limited practical enforcement leverage. The distinction from mainstream stablecoins like USDT or USDC — which can and have been frozen at regulators' request — is fundamental.
Does the FATF July 2026 report create new legal obligations for CASPs? FATF recommendations are not law. However, FATF typologies directly inform how national supervisors and AMLA structure examination priorities. CASPs whose compliance programs do not reflect documented risk typologies face elevated examination risk and reduced supervisory tolerance when deficiencies are identified.
Is Travel Rule compliance enough to address the stablecoin laundering threat? Travel Rule compliance is necessary but not sufficient. It creates the audit trail that connects transactions to verified individuals. It does not by itself detect suspicious activity — that requires transaction monitoring specifically calibrated to stablecoin-specific layering patterns. Both layers are required, and both need to be stablecoin-aware rather than generic.
What is the risk of receiving transfers from non-compliant counterparty CASPs? Receiving transfers from CASPs in low-compliance jurisdictions is itself a risk factor that FATF typologies specifically identify. Regulators examine whether receiving institutions have counterparty risk controls calibrated to this. If incoming stablecoin transfers from high-risk-jurisdiction CASPs are not being treated as elevated risk, that gap will be visible during examination.
How quickly do FATF typology reports translate into enforcement action? Historically, major FATF typologies publications translate into supervisor examination focus within 12 to 18 months. AMLA, which became operational in July 2025 and is still establishing its examination rhythm, is expected to align supervisory priorities with FATF guidance as a core part of its mandate. The July 2026 publication sets the clock.
Related Articles

PSD3 and PSR: What Payments Firms Must Know About KYC
PSD3 and PSR shift fraud liability to PSPs who miss identity checks. Here is what payment firms need before late-2026 enforcement kicks in.

FATF June 2026 Grey List: Iraq, Bosnia & KYC EDD
FATF added Iraq and Bosnia-Herzegovina to its June 2026 grey list. Here is what compliance teams must update in their KYC programs and EDD workflows.

Perpetual KYC: One-Time Verification Is Dead
Perpetual KYC replaces annual reviews with continuous monitoring. AMLA's July 2026 guidelines make it a compliance imperative — here's the operational case.