FATF July 2026: Stablecoins Fuel 84% of Crypto Crime

FATF's July 2026 report reveals stablecoins now drive 84% of illicit crypto flows, with $154 billion laundered in 2025. What every CASP must do now.

Emily Carter
By Emily CarterAI Strategy Consultant at Joinble
·10 min read
Share
FATF July 2026: Stablecoins Fuel 84% of Crypto Crime
imageUse this imagedownloadDownload

On July 17, 2026, the Financial Action Task Force released its latest virtual assets typologies report. Every crypto-asset service provider in a regulated market should treat the headline finding as an alarm: 84% of all illicit virtual asset transaction volume globally now runs through stablecoins. Chainalysis data covering 2025 activity produced that figure. Criminal networks have structurally changed how they move money, and most CASPs now face a direct challenge to the KYC and transaction monitoring programs they designed.

This is not an emerging trend described in passing. The report records a fait accompli. Inside the virtual asset sector, stablecoins already function as the primary money laundering instrument. Bitcoin-era risk profiles shaped the compliance infrastructure most CASPs still run, and that infrastructure sits increasingly out of step with the threat environment they actually operate in.

How Large the Problem Has Become

The raw numbers leave little room to look away. Chainalysis data cited in the FATF report put illicit virtual asset transaction volume at $154 billion in 2025. TRM Labs, using a parallel methodology, estimated the figure at $158 billion — a gap that tracks differing data access rather than analytical disagreement. Relative to 2024 levels, both estimates amount to a near-doubling of illicit flows.

That surge was driven by stablecoins. Of the illicit total in 2024, approximately $51 billion was linked to fraud and scam operations, with stablecoin rails providing the primary settlement layer. The structural logic is straightforward: large-scale commercial crime needs the price stability stablecoins offer, the settlement speed that lets funds layer rapidly across multiple addresses, and enough pseudonymity from external oversight while criminal networks keep internal auditability.

Metric Figure
Illicit virtual asset volume (2025) $154 billion (Chainalysis) / $158 billion (TRM Labs)
Stablecoin share of illicit flows 84%
Illicit funds linked to fraud and scams ~$51 billion (2024)
Year-over-year growth in illicit flows ~145%
Jurisdictions largely FATF-compliant 34% (51 of 149 assessed)

Scam compounds and investment fraud networks sit at the center of FATF's analysis as the primary drivers of laundering flows — sophisticated operations that collect victim proceeds, layer funds, and move value across jurisdictions on stablecoin rails without ever touching the traditional banking system.

Criminal-Engineered Stablecoins: The Unsolvable Problem

Volume figures are not the most alarming finding in the July 2026 report. FATF identifies what can only be described as compliance-resistant stablecoin infrastructure: instruments criminal networks deliberately engineered so they cannot be frozen or seized.

Tether, Circle, and comparable operators — the major stablecoin issuers — run compliance programs that let them freeze wallet addresses linked to confirmed illicit activity. Law enforcement agencies have used these mechanisms with meaningful results, recovering funds in significant cases. Criminal networks answered by issuing their own stablecoins. Those instruments carry no compliance infrastructure by design: no issuer to compel, no freeze mechanism to invoke, and no KYC database that can be subpoenaed.

Scale is illustrated by the Cambodia-based financial services conglomerate identified in the FATF report. Between 2021 and 2025 the network laundered at least $4 billion in illicit proceeds, serving both organized crime fraud operations and North Korean state-linked cyber theft through the same settlement rails. Isolated case study is the wrong frame. The documented operational template of a growing sector is the right one.

Opportunistic use of pseudonymous Bitcoin, which defined the first generation of crypto money laundering, is a different category. This is engineered, industrial-scale circumvention of compliance mechanisms — and it is scaling in parallel with legitimate stablecoin adoption.

The Global Compliance Gap That Makes This Possible

The compliance failure that lets this threat landscape exist is stated explicitly in FATF's report. Only 51 of 149 assessed jurisdictions — 34%, up from 29% a year earlier — were rated "largely compliant" with FATF's Recommendation 15 governing virtual assets as of April 2026. Progress is real. The remaining gap is real as well.

Five areas of persistent, significant failure are identified by FATF:

  • Licensing and registration standards for virtual asset service providers
  • Beneficial ownership transparency of VASPs themselves
  • Travel Rule implementation across jurisdictions
  • Suspicious transaction reporting frameworks calibrated to virtual asset patterns
  • Cross-border information sharing between financial intelligence units

Operationally, the Travel Rule failure carries the most weight. Verified originator and beneficiary identity data must accompany every qualifying virtual asset transfer under FATF's Recommendation 16. In practice, as covered in our analysis of the MiCA Travel Rule implementation, approximately 35% of EU-registered CASPs had not fully operationalized Travel Rule data transmission by the July 2026 deadline — and the EU ranks among the more advanced regulatory environments globally.

Stablecoin transactions become effectively opaque between jurisdictions when identity data does not travel with transfers. Criminal networks exploit this systematically: layering transactions are routed through chains of counterparty CASPs selected specifically because those institutions have weak Travel Rule infrastructure.

What CASPs Must Do: A Practical Response Framework

Enforcement action has its predicate in FATF's July report. National supervisors and — in the EU, the newly operational Anti-Money Laundering Authority (AMLA) — typically intensify examination activity 12 to 18 months after a major typologies publication, based on the typical FATF typology-to-enforcement cycle. Recalibrating compliance programs now is how CASPs avoid being poorly positioned when that cycle arrives.

How AMLA is putting its supervisory mandate into practice is covered at length in AMLA and EU crypto KYC compliance.

These program elements need attention:

Stablecoin-Specific Transaction Monitoring

Rule sets built for Bitcoin or Ethereum retail patterns are not calibrated for stablecoin risk. Organized crime's velocity, sizing, and layering patterns in stablecoin transactions look materially different from the retail crypto activity those rules were designed to detect.

Recalibrate monitoring programs so they flag:

  • Rapid cycling among stablecoin instruments, especially obscure or newly issued ones
  • High-velocity transfers into self-hosted wallets
  • Transfers toward counterparty CASPs in FATF-identified high-risk jurisdictions
  • Unusual concentration of activity in stablecoin instruments that lack established compliance infrastructure

Travel Rule Remediation

Travel Rule compliance gaps now map directly onto the typologies FATF has published. Money laundering infrastructure is built to exploit any stablecoin transfer that cannot travel with verified originator data. What Travel Rule-ready KYC infrastructure actually requires is broken down in the State of KYC in Crypto 2026.

Counterparty CASP Risk Assessment

Criminal networks deliberately route transactions through CASPs with weak compliance posture, FATF identifies, using better-supervised institutions as exit ramps. Counterparty risk — assessing the compliance posture of other CASPs from which you receive stablecoin transfers — therefore needs to sit inside your AML program architecture, not as an afterthought to onboarding controls.

Novel Stablecoin Instrument Screening

A new screening requirement follows from criminal-issued stablecoins: spotting when customers transact in instruments that have no identifiable compliant issuer. Inability to attribute a stablecoin to a licensed and FATF-compliant issuer is itself a risk indicator that warrants enhanced due diligence.

Why Continuous Monitoring Changes the Calculus

Onboarding does not catch the stablecoin laundering patterns documented in the July 2026 report. A customer who passes all identity verification checks and presents a clean risk profile at account opening may be recruited, compromised, or coerced into facilitating criminal transactions months later. Legitimate customers whose accounts were subsequently used to layer criminal proceeds — that is exactly the mechanism the Cambodia conglomerate's infrastructure operated through.

Periodic review cycles tied to KYC refresh schedules are the wrong unit of time. Continuous, autonomous monitoring is the foundational argument. How systems that watch customer behavior without pause — catching anomalies in real time rather than flagging accounts only at annual refresh — sit in a better position to read the behavioral signatures of account misuse is laid out in our analysis of agentic KYC and AI-driven compliance automation.

That operating model is what Joinble's AI Agents are built for: identity and behavioral monitoring that runs across the full customer lifecycle, with automated escalation once transaction patterns drift from expected behavior for a given risk profile. Against stablecoin laundering, the practical meaning is catching the moment a previously dormant account starts receiving high-velocity stablecoin transfers from counterparties in high-risk jurisdictions — and opening enhanced due diligence before the pattern hardens into regulatory exposure.

The US Dimension

Parallel regulatory development in the United States forms the backdrop against which the FATF findings arrive. Bank-grade Customer Identification Program requirements for US Permitted Payment Stablecoin Issuers are introduced by the GENIUS Act stablecoin KYC framework, implemented through a proposed rulemaking by FinCEN and four co-agencies published in June 2026. What those compliance programs must include is detailed in our coverage of the GENIUS Act KYC requirements.

FATF guidance and US regulatory action converging signal a global move toward treating stablecoin issuers and CASPs as the load-bearing compliance layer for a financial instrument that has demonstrably become the primary vehicle for large-scale money laundering. From a risk calibration standpoint, the window for treating stablecoins as standard crypto assets has closed.

Examination Readiness Checklist

Compliance teams should be able to answer affirmatively to the following before the next supervisory examination cycle:

Control Status Check
Stablecoin transaction monitoring rules calibrated separately from general crypto rules Can you demonstrate this to a supervisor?
Travel Rule compliance for all stablecoin outbound transfers No exceptions for "minor" transfers?
Self-hosted wallet verification for stablecoin withdrawals Applied consistently?
Counterparty CASP risk scoring methodology Are high-risk-jurisdiction CASPs flagged?
Screening for unlicensed or compliance-resistant stablecoins Any process for this?
Continuous behavioral monitoring between KYC refresh cycles Or still batch/annual?

FATF's published risk typologies are expected to shape AMLA's examination focus for 2026 and 2027 closely. CASPs that cannot show they have read and operationalized the July 2026 report will face harder questions than those who can produce a documented response.

FAQ

Why are stablecoins now the primary money laundering vehicle? Price stability that volatile cryptocurrencies cannot match is what stablecoins offer — critical for large-scale commercial fraud operations that collect, hold, and convert proceeds over extended periods. High settlement speed, programmability, and the existence of compliant-free stablecoin variants in criminal jurisdictions, taken together, make them structurally better suited to commercial-scale laundering than Bitcoin or Ethereum.

What are criminal-engineered stablecoins and can they be traced? Instruments issued specifically without compliance infrastructure: no KYC, no freeze mechanisms, no identifiable issuer to compel. On-chain transactions remain visible on the blockchain, yet traceability without a compliance-capable issuer supplies limited practical enforcement leverage. The distinction from mainstream stablecoins like USDT or USDC — which can and have been frozen at regulators' request — is fundamental.

Does the FATF July 2026 report create new legal obligations for CASPs? FATF recommendations are not law. How national supervisors and AMLA structure examination priorities is, however, informed directly by FATF typologies. Elevated examination risk and reduced supervisory tolerance when deficiencies are identified await CASPs whose compliance programs do not reflect documented risk typologies.

Is Travel Rule compliance enough to address the stablecoin laundering threat? Necessary, not sufficient. The audit trail that connects transactions to verified individuals is what Travel Rule compliance creates. Suspicious activity detection is a different job — it requires transaction monitoring specifically calibrated to stablecoin-specific layering patterns. Both layers are required, and both need to be stablecoin-aware rather than generic.

What is the risk of receiving transfers from non-compliant counterparty CASPs? Transfers arriving from CASPs in low-compliance jurisdictions are themselves a risk factor that FATF typologies specifically identify. Whether receiving institutions have counterparty risk controls calibrated to this is something regulators examine. Incoming stablecoin transfers from high-risk-jurisdiction CASPs that are not treated as elevated risk will show as a gap during examination.

How quickly do FATF typology reports translate into enforcement action? Major FATF typologies publications historically translate into supervisor examination focus within 12 to 18 months. AMLA, which became operational in July 2025 and is still establishing its examination rhythm, is expected to align supervisory priorities with FATF guidance as a core part of its mandate. The clock starts with the July 2026 publication.

Emily CarterEmily Carter
Share

Related Articles

DORA and KYC: Identity Vendors Are Now ICT Third Parties
Compliance31 Aug, 2026

DORA and KYC: Identity Vendors Are Now ICT Third Parties

DORA's ICT third-party rules apply to KYC vendors from 2025. Here's what financial firms must audit, contract, and monitor to stay compliant in 2026.

SR 26-2: The Governance Gap in AI-Powered KYC
Compliance17 Aug, 2026

SR 26-2: The Governance Gap in AI-Powered KYC

The Fed's new model risk guidance explicitly excludes generative and agentic AI. For banks using AI in KYC, that gap is now a compliance liability.

KYB Under AMLR: The UBO Threshold Trap of 2027
Compliance13 Aug, 2026

KYB Under AMLR: The UBO Threshold Trap of 2027

44% of KYB processes will fail the EU AMLR's new UBO threshold rules from July 2027. Here's how to audit your beneficial ownership verification now.