THE $4.3 BILLION COMPLIANCE FAILURE

- But they were not the most significant part of the case.
- The Justice Department’s central allegation—ultimately admitted through Binance’s guilty plea—was that compliance failure was not merely an accidental consequence of extraordinary growth.
- Authorities said Binance deliberately prioritised growth, market share and profits over compliance with U.S. law while seeking the economic benefits of U.S. customers.
- Treasury described Binance as responsible for an estimated 60% of centralised virtual-currency spot trading at the time of the resolution.
- This means the case is not simply about a crypto startup whose compliance department failed to keep pace.
EXECUTIVE FINDING
On 21 November 2023, Binance Holdings Limited, operator of the world’s largest cryptocurrency exchange, pleaded guilty in the United States to criminal offences involving anti-money-laundering controls, unlicensed money transmission and sanctions violations.
Its founder and chief executive, Changpeng Zhao, known throughout the cryptocurrency industry as CZ, separately pleaded guilty to violating the Bank Secrecy Act by causing Binance to fail to maintain an effective anti-money-laundering programme.
Zhao resigned as chief executive.
The coordinated resolutions with the U.S. Department of Justice, Financial Crimes Enforcement Network, Office of Foreign Assets Control and Commodity Futures Trading Commission required Binance and Zhao to resolve liabilities exceeding $4.3 billion.
The numbers were historic.
But they were not the most significant part of the case.
The Justice Department’s central allegation—ultimately admitted through Binance’s guilty plea—was that compliance failure was not merely an accidental consequence of extraordinary growth.
Authorities said Binance deliberately prioritised growth, market share and profits over compliance with U.S. law while seeking the economic benefits of U.S. customers.
Treasury described Binance as responsible for an estimated 60% of centralised virtual-currency spot trading at the time of the resolution.
This means the case is not simply about a crypto startup whose compliance department failed to keep pace.
It raises a more consequential question:
WHAT HAPPENS WHEN NON-COMPLIANCE BECOMES PART OF THE GROWTH STRATEGY?
That distinction matters.
A company can fail despite a genuine attempt to comply.
Or a company can calculate that effective compliance would exclude profitable customers, reduce transaction volume and slow expansion.
The second scenario is fundamentally different.
It transforms compliance from an operational weakness into a strategic conflict.
That is the central subject of this dossier.
THE FINDING
Every financial institution eventually faces the same tension.
The commercial side asks:
How do we acquire more customers?
Compliance asks:
Which customers should we refuse?
The commercial side asks:
How do we increase transaction volume?
Compliance asks:
Which transactions should we block or investigate?
The commercial side asks:
How do we enter more markets?
Compliance asks:
Where are we legally permitted to operate?
Those questions can coexist.
They do at thousands of regulated institutions.
The danger begins when the organisation consistently resolves the conflict in only one direction:
REVENUE WINS.
According to the Justice Department, Binance understood that serving U.S. customers required registration and an effective AML programme but chose not to implement the necessary controls because management believed compliance would impede growth, profits, market share and trading volume.
That is what makes Binance a landmark compliance case.
The problem was not simply that criminals managed to use the platform.
Criminals attempt to use every major financial institution.
The deeper issue is whether the institution constructed controls proportionate to the risk—or viewed those controls as obstacles to commercial expansion.
THE COMPANY
BINANCE HOLDINGS LIMITED
Binance emerged from the 2017 cryptocurrency boom and rapidly became the dominant global crypto exchange.
Its product offered users the ability to:
- buy digital assets
- sell them
- trade pairs
- move crypto internationally
- hold balances
and access a rapidly expanding digital-asset ecosystem.
By November 2023, Treasury described Binance as the world’s largest virtual-currency exchange and estimated that approximately 60% of centralised spot trading occurred through the platform.
Scale matters in compliance.
A weakness affecting a small exchange may expose thousands of transactions.
A weakness affecting the world’s largest exchange may expose millions.
CHANGPENG ZHAO
FOUNDER AND CEO
Changpeng Zhao built Binance into the dominant global exchange and became one of the most recognisable figures in cryptocurrency.
On 21 November 2023, Zhao pleaded guilty to violating the Bank Secrecy Act by causing Binance to fail to maintain an effective AML programme.
He resigned as CEO as part of the resolution.
This was not merely a corporate settlement.
The Justice Department emphasised that it represented its largest corporate guilty plea resolution that also included the guilty plea of the company’s chief executive.
That distinction is important.
Compliance accountability reached the founder.
SAMUEL LIM
FORMER CHIEF COMPLIANCE OFFICER
The CFTC separately announced a proposed settlement with former Binance Chief Compliance Officer Samuel Lim.
Lim agreed to pay a $1.5 million civil monetary penalty to resolve CFTC claims that he willfully aided and abetted Binance’s violations of the Commodity Exchange Act.
His role provides an important contrast with conventional compliance-failure cases.
Usually the question is:
Did management ignore compliance?
The Binance litigation raised another:
What happens when regulators allege that senior compliance leadership itself participated in strategies designed to evade regulatory requirements?
The CFTC resolution with Lim was civil rather than the DOJ criminal plea entered by Zhao.
The legal statuses should not be conflated.
THE BUSINESS MODEL CONFLICT
A global exchange makes money when people trade.
More users.
More volume.
More fees.
More markets.
More products.
Compliance produces the opposite effect in certain cases.
KYC creates friction.
Sanctions screening removes users.
Geographic blocking limits markets.
Suspicious transaction monitoring produces investigations.
Account closures reduce customer count.
Source-of-funds requests can drive users elsewhere.
That creates a basic commercial equation:
HIGHER FRICTION
can mean
LOWER CONVERSION.
For a legitimate regulated institution, that is accepted as the cost of access to the financial system.
The Binance resolution suggests U.S. authorities believed the company attempted instead to capture the commercial benefit while avoiding much of the regulatory cost.
THE COMPLIANCE EQUATION
A financial company has two ways to increase profit.
MODEL A — COMPLIANT GROWTH
- More customers
- effective KYC
- AML monitoring
- sanctions controls
- regulatory registration
- =
slower but lawful expansion.
MODEL B — CONTROL AVOIDANCE
- More customers
- less friction
- more jurisdictions
- fewer exclusions
- higher volume
- =
accelerated growth but increasing enforcement exposure.
According to DOJ, Binance followed the second model in significant respects affecting the United States.
THE U.S. CUSTOMER QUESTION
Binance was not a traditional American bank headquartered in New York.
That did not eliminate U.S. obligations.
The Justice Department’s position was straightforward:
Binance deliberately served U.S. customers.
Serving those customers made the applicable U.S. financial laws relevant.
Attorney General Merrick Garland stated that Binance’s decision to serve U.S. users meant the company was required to comply with U.S. financial law, including registration and AML requirements.
This is a critical lesson for borderless financial businesses.
The question is not simply:
WHERE IS THE COMPANY INCORPORATED?
It is also:
WHERE ARE ITS CUSTOMERS?
DIGITAL JURISDICTION
Traditional finance makes jurisdiction relatively visible.
A bank opens a branch.
The branch stands physically inside a country.
A crypto exchange can reach the same customer through a website or application without opening a single branch.
This creates the illusion that the company is operating from somewhere else.
Economically, however, it may be operating inside the market.
Kleptik defines this as:
DIGITAL JURISDICTION
A business acquires regulatory exposure through whom it serves, what services it provides and how it accesses the country’s financial system—not merely where its headquarters are located.
THE GEOGRAPHIC CONTROL PROBLEM
A digital financial institution must therefore know something traditional banks have always known:
where the customer is.
That sounds simple.
It is not.
A user can appear through:
- IP address
- registered residence
- identification document
- telephone number
- payment method
- device information
- bank account
- VPN
- corporate entity
or travel pattern.
Those signals may conflict.
A user may provide:
UAE passport.
Cayman company.
U.S. IP address.
European telephone number.
Singapore bank account.
Where is the customer?
The compliance system must decide.
VPNs AND GEOGRAPHIC EVASION
The CFTC’s original action against Binance alleged that the company and senior personnel were aware that U.S. customers could use virtual private networks to conceal their location and access the platform.
The November settlement reflected the broader claim that Binance knowingly evaded U.S. regulatory requirements in operating its derivatives business.
This introduces an important compliance question.
If a company technically blocks a country but tells or allows users to bypass that block, is the geographic control real?
The answer is obvious.
A control cannot be evaluated by whether it exists on the website.
It must be evaluated by whether management intends it to work.
THE PAPER CONTROL
Kleptik distinguishes between:
PAPER CONTROL
A rule exists.
and
EFFECTIVE CONTROL
The rule changes behaviour.
Example:
Terms of service state:
U.S. PERSONS PROHIBITED.
That is a paper control.
An effective control would additionally consider:
- IP detection
- device intelligence
- residency verification
- payment instruments
- known VPN indicators
- account behaviour
and enforcement against circumvention.
The difference is critical.
KYC
Know Your Customer procedures answer a deceptively simple question:
WHO ARE YOU?
For traditional institutions, that generally means verifying:
- legal name
- date of birth
- address
- identification
- beneficial ownership
and, depending upon risk, source of funds or wealth.
Crypto initially developed with a culture that often regarded identification requirements as incompatible with financial freedom.
But once an exchange becomes a large centralised intermediary, the operational risk changes.
It controls customer assets.
Processes transactions.
Converts value.
Interfaces with banks.
And can provide financial services at enormous scale.
At that point, anonymity is no longer an abstract philosophical issue.
It is a financial-crime control.
AML IS NOT KYC
The two are frequently confused.
KYC asks:
Who is the customer?
AML monitoring asks:
What is the customer doing?
A perfectly identified customer can still:
- launder money
- finance terrorism
- move ransomware proceeds
- receive fraud proceeds
or evade sanctions.
That means a complete control framework needs both.
TRANSACTION MONITORING
Crypto transaction monitoring has unusual advantages.
The blockchain can record transfers permanently.
Investigators may see:
- wallet
- amount
- time
- transaction hash
and subsequent movement.
But the blockchain usually does not automatically reveal:
- the person behind the wallet
- purpose
- relationship
- source of wealth
or economic rationale.
A compliance programme must combine:
blockchain intelligence
with
customer intelligence.
Neither is enough alone.
THE SANCTIONS PROBLEM
The Binance resolution was also historically significant because of its sanctions component.
OFAC announced a $968,618,825 settlement covering potential civil liability for 1,667,153 apparent violations of multiple U.S. sanctions programmes.
The agency said that between 2017 and 2022 Binance provided services involving users in sanctioned jurisdictions or blocked persons and caused U.S. persons to participate in transactions involving such users.
OFAC determined that the apparent violations were:
egregious
and
not voluntarily self-disclosed.
That number—more than 1.6 million apparent violations—shows what scale does to sanctions risk.
ONE BAD TRANSACTION VERSUS A SYSTEM
Sanctions enforcement changes fundamentally with volume.
A bank accidentally processes one prohibited transaction.
That may represent an isolated failure.
A platform processes large numbers of prohibited transactions over several years.
The question becomes systemic.
- Were relevant geographies blocked?
- Were sanctioned persons screened?
- Were wallet addresses monitored?
- Were account locations verified?
- Did management know?
- Were alerts resolved?
The investigation moves from:
transaction failure
to
control architecture.
SANCTIONS ARE A LOCATION PROBLEM
Some sanctions target specific people.
Others affect jurisdictions, sectors or prohibited services.
This means location itself becomes compliance data.
Crypto complicates that because digital assets move without correspondent banks at every stage.
A blockchain transaction can occur directly between wallets.
The exchange therefore becomes one of the principal control points capable of identifying the user.
If that control point fails, the transaction may proceed without many of the traditional financial-system barriers.
THE BLOCKED-PERSON PROBLEM
Sanctions screening cannot rely only on names.
A designated person can use:
- company
- nominee
- wallet
- new email
- different transliteration
or third-party account.
The proper model is network-based.
This resembles PEP screening.
Again, the risk is a network, not a name.
THE FINCEN SETTLEMENT
Treasury announced a $3.4 billion FinCEN settlement, at the time the agency’s largest settlement.
The action concerned violations of U.S. anti-money-laundering requirements under the Bank Secrecy Act.
The scale of the settlement reflected more than an administrative registration problem.
FinCEN’s mandate concerns the architecture designed to prevent the financial system from becoming infrastructure for criminal money.
A crypto exchange facilitating global value transfer performs a function increasingly similar to traditional payment institutions.
That creates equivalent responsibilities.
THE SAR PROBLEM
A major consequence of the DOJ resolution was a requirement that Binance conduct retrospective review and file Suspicious Activity Reports required under U.S. law.
Attorney General Garland emphasised that the company would be required to review past transactions and report suspicious activity to federal authorities.
This is especially significant.
Ordinary remediation fixes future controls.
Retrospective SAR review attempts to repair the historical intelligence gap.
WHY SARs MATTER
A suspicious activity report does not declare someone guilty.
It tells law enforcement:
This activity deserves attention.
SARs can connect otherwise unrelated investigations.
One bank sees:
wire transfer.
Another sees:
cash deposit.
Exchange sees:
crypto withdrawal.
Law enforcement sees:
all three.
The value lies in aggregation.
If a major exchange fails to produce those reports, law enforcement may lose an important source of financial intelligence.
THE RETROSPECTIVE REVIEW
A historical review requires asking:
- Which transactions would have triggered alerts under a compliant programme?
- Which users should have been investigated?
- Which accounts should have been restricted?
- Which activity should have generated SARs?
The exercise effectively reconstructs a missing compliance system after the fact.
That can generate intelligence years after the transaction itself occurred.
ILLEGAL FINANCE
DOJ and Treasury described serious illicit-finance exposure associated with Binance.
Authorities referred to transactions connected with:
- terrorist organisations
- cybercriminals
- ransomware
- darknet markets
- scams
- narcotics
and sanctioned actors.
The key analytical distinction is important:
A criminal using Binance does not itself establish corporate criminal responsibility.
Large financial institutions inevitably attract criminals.
Corporate liability arose from the failures and conduct admitted in the resolutions concerning the controls the company was required to maintain.
THE HYDRA EXAMPLE
U.S. officials identified Hydra, the darknet marketplace, among illicit actors whose activity touched Binance.
The relevance is structural.
Darknet markets need an exit from criminal activity into usable financial value.
Crypto exchanges can function as:
- entry point
- conversion point
- liquidity source
or exit point.
If a criminal receives crypto but wants:
- dollars
- euros
- stablecoins
- other tokens
- or commercially usable funds,
an exchange becomes highly valuable.
THE TERRORISM FINANCING QUESTION
DOJ referenced terrorism financing in explaining the importance of Binance’s future SAR obligations.
This area requires particularly careful reporting.
Finding a transaction involving an address associated with an organisation does not automatically establish that an exchange knowingly financed terrorism.
Blockchain attribution can also evolve.
Kleptik should distinguish:
- known customer
- known wallet
- suspected wallet cluster
- transaction exposure
and proven knowledge.
Terminology matters enormously.
THE COMPLIANCE TEAM
The central organisational question is:
What happens when compliance identifies risk?
There are three possibilities.
MODEL 1 — CONTROL HAS AUTHORITY
Compliance says no.
Transaction stops.
MODEL 2 — CONTROL ADVISES
Compliance says no.
Commercial management overrides.
MODEL 3 — CONTROL ADAPTS TO BUSINESS
Compliance redesigns the process so commercial activity can continue.
The third is the most dangerous.
The function still exists.
Its purpose has changed.
THE REAL TEST OF COMPLIANCE
An institution does not demonstrate strong compliance by employing:
- a Chief Compliance Officer
- a sanctions officer
- AML analysts
- consultants
or sophisticated software.
The real test is:
CAN COMPLIANCE STOP REVENUE?
- If a high-value customer fails due diligence, can compliance terminate the account?
- If a major jurisdiction creates sanctions exposure, can compliance exit it?
- If management wants to launch a product, can compliance delay the launch?
- If a CEO objects, can the compliance officer prevail?
If the answer is no, the compliance department may exist principally as documentation.
THE INCENTIVE PROBLEM
Employee incentives can undermine control systems.
Imagine a sales executive compensated by:
trading volume.
New customers.
Revenue.
Market share.
Then compliance says:
Close the account.
The salesperson suffers economically.
This creates structural conflict.
A mature institution must ensure that compensation does not reward employees for defeating the control environment.
THE CEO PROBLEM
The Zhao guilty plea is particularly significant because tone at the top determines how organisations perceive compliance.
If senior management views compliance as:
protection,
employees learn to escalate problems.
If management views compliance as:
friction,
employees learn to minimise problems.
The policy manual may remain identical.
The culture changes everything.
CULTURE IS A CONTROL
Compliance programmes frequently focus on:
- policies
- training
- screening
- software
and audit.
But culture is equally important.
Culture answers informal questions:
- What gets rewarded?
- What gets punished?
- Who gets promoted?
- What happens when compliance blocks a profitable client?
- What happens when someone raises a concern?
- Do employees hide problems?
- Do managers expect workarounds?
These questions often predict control effectiveness better than the written policy.
THE CFTC CASE
The CFTC’s November 2023 resolution addressed Binance’s derivatives activities and alleged deliberate evasion of U.S. commodities law.
Binance and Zhao agreed to a proposed resolution valued at approximately $2.85 billion, including disgorgement and civil monetary penalties.
The CFTC also required changes involving KYC controls and removal of accounts that did not comply with those controls.
The significance is broader than derivatives.
The case illustrates how product design and customer access can create jurisdictional obligations even where an exchange presents itself as globally distributed.
REGULATORY ARBITRAGE
Regulatory arbitrage means exploiting differences between legal systems.
It can be legitimate.
Companies choose jurisdictions every day based on:
- tax
- capital requirements
- licensing
- labour law
and business environment.
The problem arises where corporate or technical structures are designed principally to enjoy access to a regulated market without accepting its regulatory obligations.
The Binance case is therefore a useful case study in the boundary between:
international structuring
and
regulatory evasion.
THE ENTITY PROBLEM
Global crypto businesses frequently contain:
- holding companies
- regional affiliates
- licence holders
- service entities
- technology companies
- marketing companies
and trading platforms.
The company may argue:
This entity does not serve U.S. customers.
Another entity may operate separately.
The investigator must therefore map actual economic activity rather than relying only on corporate descriptions.
THE KLEPTIK ENTITY TEST
For every Binance-related legal entity:
- JURISDICTION
- Where incorporated?
- FUNCTION
- What does it actually do?
- CUSTOMERS
- Whom does it contract with?
- EMPLOYEES
- Who works there?
- BANKING
- Where are its accounts?
- TECHNOLOGY
- What platform does it operate?
- REVENUE
- What fees does it earn?
- REGULATOR
- Who supervises it?
- CONTROL
- Who ultimately directs it?
Only then can legal separateness be compared with operational reality.
THE CUSTOMER JOURNEY
To understand AML effectiveness, follow one customer from start to finish.
At every stage ask:
- What control exists?
- Can it be bypassed?
- Who can override it?
- Is the override logged?
That is more useful than asking whether the company “has KYC.”
THE CONTROL-BYPASS MAP
Compliance failures often involve bypass routes.
For example:
GEOGRAPHIC BLOCK
→ VPN.
IDENTITY REQUIREMENT
→ weak verification.
TRANSACTION LIMIT
→ multiple accounts.
SANCTIONS SCREEN
→ alternate spelling or nominee.
ACCOUNT CLOSURE
→ new account.
HIGH-RISK CUSTOMER BAN
→ offshore corporate entity.
A mature system monitors for the bypass.
A weak system monitors only the stated rule.
THE $4.3 BILLION NUMBER
The frequently cited $4.3 billion represented the combined financial impact of coordinated U.S. resolutions, not one single fine imposed by one agency.
Treasury announced:
FinCEN: approximately $3.4 billion.
OFAC: approximately $968.6 million.
The Justice Department resolution involved penalties and forfeiture coordinated with the other agencies, and the CFTC resolution added its own disgorgement and civil-penalty framework with offsets and coordination among regulators.
This distinction matters.
Headline numbers in multinational enforcement actions can involve overlapping credits.
Kleptik should always identify:
- gross announced penalties
- credits
- forfeiture
- disgorgement
- civil penalties
- criminal penalties
and actual net economic payment.
THE PENALTY MAP
A proper enforcement graphic should show:
DOJ
criminal prosecution.
↓
FINCEN
Bank Secrecy Act / AML.
↓
OFAC
sanctions.
↓
CFTC
derivatives and Commodity Exchange Act.
↓
BINANCE
single institution subject to different regulatory frameworks.
This demonstrates another important point:
Financial regulation is not one body of law.
One transaction can simultaneously create:
- criminal
- AML
- sanctions
- registration
and market-regulation exposure.
THE FIVE-YEAR MONITOR
OFAC required Binance to retain an independent compliance monitor for five years as part of its sanctions settlement.
A monitorship is not merely punishment.
It changes corporate governance.
An independent monitor can evaluate:
- sanctions controls
- AML systems
- management accountability
- data
- testing
- remediation
and ongoing compliance.
The existence of a monitor means the government no longer relies exclusively upon the company’s self-assessment.
WHAT THE MONITOR SHOULD ASK
GOVERNANCE
Does compliance report independently?
RESOURCES
Is staffing proportional to transaction volume?
TECHNOLOGY
Do systems capture all relevant data?
KYC
Are customers genuinely identified?
SANCTIONS
Are geographic and name-based controls effective?
TRANSACTION MONITORING
Are alerts timely and properly closed?
ESCALATION
Can high-risk accounts be terminated?
MANAGEMENT OVERRIDE
Who can override controls?
COMPENSATION
Are employees incentivised to defeat compliance?
HISTORICAL REVIEW
Have past deficiencies been remediated?
THE DATA PROBLEM
Crypto exchanges generate extraordinary volumes of information.
User logins.
IP addresses.
Wallet addresses.
Trade histories.
Deposit addresses.
Withdrawal addresses.
Device identifiers.
KYC files.
Support tickets.
Blockchain transaction data.
That should create excellent financial-crime intelligence.
But data only matters if:
- collected
- retained
- integrated
- analysed
and escalated.
A company can possess enormous datasets while remaining blind if systems are fragmented.
BLOCKCHAIN TRANSPARENCY IS NOT AML
A common claim is that public blockchains make cryptocurrency inherently traceable.
They often do make transaction histories visible.
But visibility is not identity.
Consider:
Wallet A sends to Wallet B.
That is transparent.
Who owns Wallet A?
Unknown.
Who controls Wallet B?
Unknown.
Why was the transfer made?
Unknown.
Was either person sanctioned?
Unknown.
That is where exchange KYC becomes critical.
The exchange connects:
wallet
to
identity.
CRYPTO’S CENTRALISATION PARADOX
Cryptocurrency was designed partly around decentralisation.
Yet large exchanges became highly centralised.
Millions of users entrusted:
- assets
- identity
- transaction execution
- and market access
to a small number of companies.
This creates an irony.
The blockchain may be decentralised.
The gateway is not.
The exchange becomes a new financial institution whether or not it calls itself one.
THE BANK ANALOGY
Imagine a bank that:
- serves millions of customers
- moves billions internationally
- converts assets
- holds balances
- facilitates transfers
but argues that traditional AML principles should not fully apply because its assets are digital.
Economically, the argument becomes increasingly difficult to sustain.
The Binance settlement represents a decisive enforcement response:
FUNCTION MATTERS MORE THAN LABEL.
If an institution behaves like financial infrastructure, authorities will regulate the risks associated with financial infrastructure.
FOLLOW THE USERS
A Kleptik investigation should map high-risk Binance customer populations by:
- country
- account-opening year
- transaction volume
- asset type
- sanctions exposure
- wallet risk
and account closure date.
The objective is not to publish innocent customers.
It is to understand the control environment statistically.
Questions include:
- How many users came from prohibited jurisdictions?
- How long were they active?
- How much volume did they generate?
- Were they profitable customers?
- When were controls tightened?
- Did activity fall afterward?
FOLLOW THE REVENUE
One of the most important unanswered questions is:
HOW MUCH REVENUE DID NON-COMPLIANT ACTIVITY GENERATE?
Compliance failures become more analytically significant when the company economically benefited from them.
For each category:
U.S. users.
Sanctioned jurisdiction exposure.
High-risk customers.
Unregistered derivatives activity.
Calculate:
- transaction volume
- fees
- spread
- financing revenue
and other income.
Then compare revenue against eventual enforcement cost.
THE COMPLIANCE PROFIT-AND-LOSS STATEMENT
A true compliance P&L should include:
REVENUE GAINED FROM RISKY ACTIVITY
Trading fees.
Customer growth.
Market share.
COST OF COMPLIANCE AVOIDANCE
Penalty.
Forfeiture.
Legal fees.
Monitorship.
Management distraction.
Lost licences.
Executive departure.
Reputational damage.
Future operating restrictions.
That allows boards to see the real economics.
THE MARKET-SHARE INCENTIVE
Crypto markets have powerful winner-take-most dynamics.
Liquidity attracts traders.
Traders create liquidity.
More liquidity attracts more institutional users.
That creates a feedback loop.
A strict compliance programme that excludes customers may reduce this growth loop in the short term.
That makes the incentive to defer controls particularly strong during rapid expansion.
GROW FIRST, REGULATE LATER
Technology businesses often embrace:
grow first, solve problems later.
That philosophy may work for:
social media;
consumer software;
online marketplaces.
It becomes dangerous in finance.
A compliance debt accumulates like technical debt.
The longer controls are postponed:
- more customers require remediation
- more transactions require retrospective review
- more historic violations accumulate
and greater liabilities develop.
Binance demonstrates that compliance debt compounds.
THE NATIONAL-SECURITY DIMENSION
The Binance resolution went beyond consumer protection.
Treasury and DOJ repeatedly described the conduct as implicating national security because sanctions and AML laws restrict access to the financial system by hostile states, terrorists and organised criminal actors.
This changes the enforcement philosophy.
A weak compliance programme is not viewed merely as poor corporate housekeeping.
At sufficient scale it can be viewed as allowing adversaries access to financial infrastructure.
THE SANCTIONS GATEWAY
A centralised exchange can function as a gateway between:
crypto economy
and
traditional financial system.
The gateway may allow:
- conversion
- liquidity
- custody
- stablecoins
and transfers.
If sanctioned actors can use that gateway, the issue becomes one of access.
The enforcement question is therefore:
Who was allowed through?
MANAGEMENT KNOWLEDGE
Compliance prosecutions become far more serious when authorities can prove management knew of obligations and consciously avoided them.
DOJ stated that Zhao and senior Binance management understood relevant U.S. registration and AML requirements.
This distinguishes:
negligence
from
willfulness.
The guilty pleas necessarily reflected the latter legal framework.
THE INTERNAL COMMUNICATION TEST
When investigating corporate knowledge, Kleptik should prioritise:
- emails
- internal chats
- executive presentations
- risk memoranda
- compliance escalation
- legal advice
- product launch discussions
and board materials.
The strongest evidence of culture frequently appears not in formal policy but in informal communication.
The compliance manual says what the company was supposed to do.
Internal messages may reveal what employees understood they were actually expected to do.
THE BOARD QUESTION
A company of Binance’s scale presents obvious governance questions.
- What did senior management know?
- What oversight existed?
- How was compliance performance reported?
- What risk metrics were used?
- Were sanctions exposures discussed?
- Who approved geographic strategy?
- Was regulatory risk quantified?
- Was the board independent?
These questions are especially important in founder-controlled technology companies where strategic power may be highly concentrated.
FOUNDER CONTROL
Founder-driven businesses can achieve extraordinary speed because decision-making is concentrated.
That same concentration creates governance risk.
When the founder controls:
- strategy
- capital
- product
- culture
- and senior appointments,
institutional challenge becomes difficult.
The question becomes:
WHO CAN TELL THE FOUNDER NO?
In regulated finance, someone must be able to.
CHRONOLOGY
2017
Binance launches and begins rapid global expansion.
2017–2022
OFAC says Binance provides services in circumstances generating more than 1.66 million apparent sanctions violations involving sanctioned jurisdictions or blocked persons.
2018 onward
U.S. regulatory exposure grows as Binance serves American users and expands its global derivatives and trading businesses.
2020–2022
Regulatory scrutiny intensifies across multiple jurisdictions.
March 2023
The CFTC files an enforcement action against Binance, Zhao and former chief compliance officer Samuel Lim alleging willful evasion of U.S. commodities law and operation of an illegal derivatives exchange.
21 November 2023
Binance pleads guilty to:
conspiracy to violate the Bank Secrecy Act and fail to register as a money-transmitting business;
failure to register as a money-transmitting business;
and
violating the International Emergency Economic Powers Act.
21 November 2023
Changpeng Zhao pleads guilty to causing Binance to fail to maintain an effective AML programme and resigns as CEO.
21 November 2023
Treasury announces historic FinCEN and OFAC resolutions, including approximately $3.4 billion under FinCEN and $968.6 million under OFAC.
21 November 2023
The CFTC announces its proposed settlement with Binance and Zhao, while former chief compliance officer Samuel Lim separately agrees to resolve CFTC claims against him.
As of this archive date, the coordinated enforcement package has been announced and the relevant criminal guilty pleas entered.
DOCUMENTARY RECORD
DEPARTMENT OF JUSTICE
The DOJ case record establishes Binance’s criminal guilty plea and Zhao’s separate guilty plea.
It records the government’s position that Binance prioritised growth, market share and profits over compliance with U.S. law.
FINCEN / TREASURY
Treasury’s 21 November 2023 announcement provides the principal record concerning Binance’s AML settlement with FinCEN.
Treasury described the actions as the largest settlements in FinCEN and OFAC history at the time.
OFAC
OFAC’s settlement identifies 1,667,153 apparent sanctions violations and a settlement amount of $968,618,825.
OFAC classified the apparent violations as egregious and not voluntarily self-disclosed.
CFTC
The CFTC announced a proposed approximately $2.85 billion resolution concerning Binance and Zhao for violations involving the operation of an illegal digital-asset derivatives exchange and willful evasion of U.S. law.
Former Chief Compliance Officer Samuel Lim separately agreed to a proposed $1.5 million civil penalty.
WHAT THE AUTHORITIES SAY
DOJ says Binance built its dominant market position while intentionally failing to implement controls required for access to U.S. customers and financial infrastructure.
Treasury says the company’s AML and sanctions failures allowed prohibited and illicit activity to move through the platform and imposed historic penalties and monitoring requirements.
OFAC says Binance’s sanctions-related conduct generated more than 1.66 million apparent violations over the relevant period.
The CFTC says Binance and Zhao knowingly disregarded U.S. derivatives regulation in pursuit of profits.
These are no longer merely allegations as to the core DOJ offences.
Binance and Zhao entered guilty pleas.
The CFTC and Treasury components have different legal structures, and Kleptik should identify those separately.
WHAT BINANCE ACKNOWLEDGED
The criminal resolution establishes Binance’s admission to violations of:
- the Bank Secrecy Act
- money-transmission registration requirements
- and
the International Emergency Economic Powers Act.
The resolution also imposed:
- financial penalties
- compliance remediation
- reporting obligations
and independent monitoring.
The precise scope of admissions should be described from the plea documents rather than expanded into claims concerning every suspicious transaction that passed through Binance.
WHAT THIS DOSSIER DOES NOT ESTABLISH
This dossier does not establish that:
- every Binance customer engaged in suspicious activity
- every U.S. Binance user intentionally violated law
- every employee knew about the company’s regulatory failures
- every transaction involving a sanctioned geography constituted terrorism financing
- every crypto exchange has similar deficiencies
- every blockchain transaction identified by analytics companies is correctly attributed
- Binance knowingly supported every criminal actor who used the platform
or cryptocurrencies themselves are inherently money-laundering instruments.
The report also distinguishes criminal guilty pleas from civil and administrative settlements.
Legal status matters.
RIGHT OF REPLY
Before publication, Kleptik should seek comment from:
- Binance Holdings Limited
- Changpeng Zhao and counsel
- Samuel Lim and counsel
relevant Binance regional entities where specifically discussed
For future transaction-level investigations:
financial institutions processing identified fiat flows;
customers specifically identified in official records;
blockchain analytics providers where attribution methodology is relied upon.
If Kleptik intends to state that a specific account was controlled by a sanctioned or criminal actor, attribution must be independently verified wherever possible and the affected subject should receive an opportunity to respond where practicable.
UNANSWERED QUESTIONS
The enforcement settlements resolve substantial legal issues.
They also create an enormous investigative field.
1. U.S. REVENUE
How much Binance revenue was generated from U.S.-linked customers during periods of non-compliance?
2. SANCTIONS REVENUE
How much fee income arose from transactions involving sanctioned jurisdictions or blocked persons?
3. CUSTOMER MIGRATION
What happened when Binance restricted U.S. access?
Did customers migrate to other entities, VPNs or accounts?
4. VPN KNOWLEDGE
What internal communications existed concerning geographic circumvention?
5. MANAGEMENT
Which senior executives understood the U.S. regulatory exposure?
6. COMPLIANCE
How often did compliance recommendations conflict with commercial objectives?
7. OVERRIDES
Who could override geographic, KYC or AML controls?
8. HIGH-VALUE CUSTOMERS
Were certain customers given exceptions because of transaction volume?
9. MARKET MAKERS
How were major trading firms treated differently from ordinary users?
10. SAR BACKLOG
How many retrospective suspicious activity reports will ultimately be required?
11. TERROR FINANCE
Which specific historical transactions generate credible terrorism-financing concerns?
12. DARKNET MARKETS
What share of identified darknet-market proceeds moved through Binance?
13. RANSOMWARE
How significant was Binance as a conversion or liquidity point for ransomware proceeds?
14. SANCTIONS
Which sanctioned jurisdictions generated the largest volume?
15. BANKING
Which banks provided fiat infrastructure to Binance entities during the relevant periods?
16. CORRESPONDENT BANKS
Did those institutions understand Binance’s complete geographic customer profile?
17. CORPORATE STRUCTURE
Which Binance entity actually earned revenue from each customer class?
18. BOARD OVERSIGHT
What governance structure existed above senior management?
19. COMPLIANCE RESOURCES
How did compliance staffing compare with user growth and transaction volume?
20. CORE QUESTION
Did Binance become the largest exchange despite its compliance failures—or partly because inadequate compliance allowed it to grow faster?
The U.S. government’s resolution strongly suggests the latter formed part of its prosecutorial theory.
KLEPTIK INTELLIGENCE ASSESSMENT
ASSESSMENT: ESTABLISHED
Binance pleaded guilty to federal criminal violations involving the Bank Secrecy Act, money-transmitter registration and sanctions law.
Changpeng Zhao separately pleaded guilty to causing Binance to fail to maintain an effective AML programme.
ASSESSMENT: HIGH CONFIDENCE
Compliance failures at Binance were economically material rather than peripheral.
The company was the world’s largest crypto exchange, and Treasury estimated it represented approximately 60% of centralised virtual-currency spot trading.
ASSESSMENT: HIGH CONFIDENCE
U.S. authorities concluded that commercial growth objectives repeatedly conflicted with legal compliance and that management chose growth.
This characterization is explicit in DOJ’s criminal case record.
ASSESSMENT: ESTABLISHED / OFAC
Binance resolved potential liability involving 1,667,153 apparent sanctions violations, which OFAC characterised as egregious and not voluntarily self-disclosed.
ASSESSMENT: HIGH CONFIDENCE
The Binance case demonstrates that geographic location of incorporation does not insulate a digital financial company from laws applicable to the customers and markets it deliberately serves.
ASSESSMENT: HIGH CONFIDENCE
KYC alone would not have solved Binance’s compliance problems.
Effective sanctions screening, transaction monitoring, suspicious-activity reporting, geographic controls and management governance were all necessary components.
ASSESSMENT: MODERATE-TO-HIGH CONFIDENCE
The most important institutional failure was likely cultural as well as technical.
A sophisticated compliance programme cannot work where senior management regards successful enforcement of controls as an obstacle to growth.
THE KLEPTIK VIEW
The Binance case is often described with one number:
$4.3 billion.
But the penalty is the consequence.
The story is the incentive.
Financial companies make money when customers transact.
Compliance sometimes tells those companies:
Do not accept this customer.
Do not enter this country.
Do not process this transaction.
Do not launch this product.
Report this activity.
Close this account.
That creates tension between two legitimate corporate functions.
Commercial growth generates revenue.
Compliance protects the institution from legal and financial-crime risk.
The institution becomes dangerous when one function is not merely stronger than the other, but structurally incapable of losing.
If commercial management always wins, the compliance programme does not control the company.
It documents the company.
Binance became the largest cryptocurrency exchange on earth.
That scale created extraordinary liquidity.
Liquidity created users.
Users created more liquidity.
Every excluded customer potentially weakened the growth loop.
Every blocked geography reduced market share.
Every KYC requirement created friction.
Every sanctions control rejected transactions.
That is exactly why controls matter most when a company is growing fastest.
The critical compliance question is therefore not:
Does the company have policies?
Binance unquestionably had compliance personnel and systems.
The better question is:
WHAT HAPPENS WHEN COMPLIANCE SAYS NO?
- Does the business stop?
- Does management override?
- Does the customer receive an exception?
- Does someone develop a workaround?
- Does geographic blocking exist only technically?
- Does the employee who raises the problem get rewarded—or ignored?
That is how compliance effectiveness should be measured.
The Binance case also destroys one of the more persistent myths of cryptocurrency:
that decentralised technology somehow eliminates the need for financial intermediaries.
Binance was an intermediary.
A massive one.
It knew customers.
Held assets.
Matched trades.
Moved value.
Connected wallets.
Provided liquidity.
And served as a bridge between digital assets and traditional finance.
Once an institution performs those functions at global scale, society will ask it the same questions it asks a bank:
- Who are your customers?
- Where did their money come from?
- Where is it going?
- Are they sanctioned?
- Is the transaction suspicious?
- Did you report it?
And if the answer is that those questions interfere with growth, the regulator will ask one more:
DID YOU BUILD THE BUSINESS BY NOT ASKING THEM?
That is the real significance of the Binance resolution.
The $4.3 billion penalty may be remembered.
The more important precedent is simpler:
COMPLIANCE IS NOT A DEPARTMENT.
IT IS A LIMIT ON WHAT THE BUSINESS IS ALLOWED TO DO.
If that limit cannot stop revenue, it is not a control.
KLEPTIK METHODOLOGY
This dossier is dated 21 November 2023 and is intentionally fixed to the legal and evidentiary position existing on that date.
Kleptik distinguishes between:
- criminal guilty pleas
- civil enforcement resolutions
- administrative settlements
- apparent sanctions violations
- regulatory findings
- government characterisations
- and
Kleptik analytical conclusions.
The principal evidentiary sources for this dossier are:
United States Department of Justice criminal case materials concerning Binance Holdings Limited and Changpeng Zhao;
- Financial Crimes Enforcement Network and U.S. Treasury settlement materials
- Office of Foreign Assets Control enforcement materials
- and
Commodity Futures Trading Commission enforcement records.
Where DOJ’s criminal resolution establishes admitted conduct, Kleptik describes that conduct as such.
Where OFAC refers to apparent violations, Kleptik preserves that regulatory terminology rather than converting every event into a criminal violation.
Where the CFTC announces civil settlements or allegations, those are distinguished from the separate DOJ guilty pleas.
Kleptik does not infer criminality merely because a cryptocurrency address:
- received funds from a high-risk source
- transacted with a darknet-linked wallet
- was associated by analytics software with a sanctioned actor
or subsequently moved assets through Binance.
Wallet attribution should be assigned a confidence level.
CONFIRMED
Ownership established through court records, exchange records or authoritative admission.
STRONGLY ATTRIBUTED
Multiple reliable datasets identify the same controller.
SERVICE-LEVEL ATTRIBUTION
Wallet identified as belonging to an exchange, mixer, payment processor or similar service without necessarily identifying the underlying customer.
PROBABLE CLUSTER
Blockchain analytics suggest common control but ownership is not independently confirmed.
UNATTRIBUTED
Controller unknown.
Kleptik should never convert a probabilistic wallet attribution into a definitive accusation concerning an identifiable person without independent evidence.
For compliance investigations, policies should be analysed separately from operational implementation.
Evidence should include, where available:
- written policies
- KYC requirements
- sanctions rules
- geographic controls
- transaction-monitoring logic
- alert data
- staffing levels
- internal communications
- management overrides
- customer exceptions
and regulatory correspondence.
The most important evidence is often not whether a control existed.
It is whether employees were expected to enforce it.
Where financial penalty figures overlap among coordinated agencies, Kleptik should identify credits and offsets rather than summing every headline amount and presenting the result as the company’s actual net payment.
Subjects facing transaction-specific criticism should receive meaningful right of reply.
EVIDENTIARY LABELS
ESTABLISHED — GUILTY PLEA
Conduct admitted through a criminal guilty plea.
REGULATORY SETTLEMENT
Matter resolved with a competent regulator under the terms of the relevant settlement.
APPARENT SANCTIONS VIOLATION
OFAC terminology identifying conduct creating potential civil sanctions liability; it should not automatically be described as a criminal offence.
CFTC FINDING / ALLEGATION
Matter arising under Commodity Exchange Act enforcement and distinguished from DOJ criminal liability.
COMPLIANCE FAILURE INDICATOR
Operational weakness relevant to AML or sanctions effectiveness.
MANAGEMENT-KNOWLEDGE INDICATOR
Evidence relevant to whether senior decision-makers understood the risk or requirement.
KLEPTIK VERIFIED
Independently corroborated through primary documentation.
KLEPTIK ASSESSMENT
Analytical conclusion derived from identified evidence.
TRANSACTION LEAD
Wallet, payment or account requiring additional attribution and documentary explanation.
UNVERIFIED
Information not sufficiently corroborated for factual publication.
DOCUMENT STATUS
KLTK-2023-008
Subject: Binance / Changpeng Zhao / AML and Sanctions Compliance
Archive date: 21 November 2023
Status at archive date: Binance and Zhao guilty pleas entered; coordinated U.S. resolutions announced
Historical treatment: Fixed to report date
© KLEPTIK — Investigations into Power, Money and the Systems Designed to Hide Both
