Tether Records Raise AML Questions After Early USDT Buyers Linked to Financial Crime
- 1 day ago
- 9 min read
Newly examined financial records from Tether's early years have raised questions about the effectiveness of customer due diligence surrounding the issuance of USDT, after several entities and individuals that purchased the stablecoin directly from the company were later connected to sanctions evasion, money laundering, drug trafficking and other financial crimes.

The records provide an unusual look at Tether's primary customer base during a period in which USDT was undergoing rapid expansion. They cover transactions from 2019 and 2020, when the amount of USDT in circulation increased from less than $2 billion to more than $20 billion.
The significance of the records lies in the distinction between customers that acquire USDT directly from Tether and users who obtain the stablecoin later through cryptocurrency exchanges or secondary markets.
Direct customers are closer to the point at which new tokens enter circulation. As a result, the due diligence conducted at that stage can play an important role in preventing high-risk actors from accessing freshly issued digital assets through the issuer itself.
The documents identify a number of customers whose activities subsequently attracted attention from law enforcement and sanctions authorities. Among them were companies incorporated in jurisdictions including the Cayman Islands, British Virgin Islands, Seychelles and Hong Kong, alongside individuals and entities later associated with significant illicit-finance investigations.
One of the cases highlighted involves Nikita Krasnov, a Russian national who purchased approximately $1.16 million worth of newly issued USDT during 2020. More than four years later, US authorities sanctioned Krasnov over his alleged involvement in a sanctions-evasion network serving Russian elites.
The timing is important. The later sanctions designation does not by itself establish that the person was engaged in illicit activity at the time the USDT was purchased, nor does it demonstrate that Tether knew of future conduct. However, the case illustrates the difficulty financial institutions and digital-asset businesses face when assessing customers whose risk profile may become apparent only years after a transaction.
Other examples identified in the records involve corporate entities that were later linked to much more serious criminal activity.
Two Hong Kong companies, Lucky DC Trade Pty Limited and Tomorrow Good Limited, collectively purchased more than $100 million in USDT directly from Tether. Both companies subsequently appeared in investigations or enforcement actions involving cryptocurrency laundering networks.
Lucky DC purchased almost $47 million in USDT from Tether during 2020. Its director, Cheng Hung Man, was later indicted in the United States for allegedly laundering cryptocurrency proceeds connected with North Korean cyber operations.
Tomorrow Good purchased more than $66 million in USDT during 2019. The company was subsequently associated with investigations concerning cryptocurrency laundering for the Sinaloa Cartel and North Korean-linked illicit finance.
These cases have renewed attention on the controls that should apply when stablecoins are issued directly to customers.
Tether has previously stated that its primary customers undergo due diligence comparable to practices used by sophisticated financial institutions. Such procedures are intended to include checks relating to customer identity, source of funds, sanctions exposure and potential links to illicit activity.
The newly examined records have prompted questions about how effectively those controls operated during the company's earlier period of rapid growth.
It is important, however, to distinguish between evidence that a customer was later implicated in criminal activity and evidence that the customer was knowingly accepted despite an established criminal profile.
Financial crime risk is dynamic. A customer who passes screening at onboarding can subsequently become sanctioned, investigated or criminally implicated. A transaction occurring before such developments does not automatically establish that the transaction itself was unlawful.
For AML professionals, the more relevant question is whether the available information at the time should reasonably have resulted in enhanced scrutiny or rejection.
That question is particularly difficult in cryptocurrency because customer relationships can involve substantial sums and rapidly changing transactional networks. A company may appear legitimate at incorporation but subsequently become a vehicle for laundering funds or facilitating sanctions evasion.
Corporate structures can also complicate risk assessment.
The records show substantial direct purchases by offshore companies, including entities incorporated in jurisdictions commonly used for international corporate structures. Incorporation in one of these jurisdictions is not, by itself, evidence of criminal activity. Such jurisdictions are routinely used for legitimate investment, trading and international business purposes.
The compliance challenge is determining the underlying purpose of the entity, identifying its beneficial owners and controllers, understanding the source of its funds and establishing why it requires access to a particular financial product.
For a stablecoin issuer, this can be particularly important because the issuer has visibility over the point at which new tokens are created and distributed.
Once USDT has entered circulation, it can be transferred repeatedly between wallets and exchanges. The issuer may no longer have a direct relationship with every subsequent holder.
This makes primary customer due diligence a critical first line of defence.
The importance of that control has increased as stablecoins have become more prominent in global financial crime.
Blockchain analytics companies have identified stablecoins as a major component of illicit cryptocurrency activity. Stablecoins offer criminal networks several characteristics that can make them attractive, including price stability, liquidity, global transferability and compatibility with a large number of cryptocurrency exchanges and payment services.
USDT in particular has become one of the most widely used digital assets in the global cryptocurrency market.
Its broad adoption means that it can be used for legitimate payments and trading as well as for illicit purposes. The existence of criminal use therefore does not imply that the asset itself is inherently illicit.
Instead, the scale of its legitimate use makes effective monitoring particularly important.
A significant development in recent years has been the increasing ability of law enforcement and private-sector blockchain analysts to trace cryptocurrency transactions. Unlike cash, many blockchain transactions create a permanent public record that can be analysed retrospectively.
This means that a wallet that appears anonymous today may potentially be connected to an identifiable individual or entity at a later stage.
That characteristic can work against criminals who attempt to exploit stablecoins for laundering or sanctions evasion.
Tether itself has increasingly cooperated with law enforcement agencies to freeze USDT associated with illicit activity. In April 2026, the company said it had assisted US authorities in freezing more than $344 million in USDT across two addresses after information about unlawful activity was provided to the company. It also stated that it works with hundreds of law enforcement agencies internationally.
The company's ability to freeze tokens is an important difference between certain stablecoins and traditional cryptocurrencies that operate without a central issuer capable of taking such action.
However, freezing funds after suspicious activity has been identified is different from preventing high-risk customers from obtaining newly issued tokens in the first place.
The latest scrutiny therefore raises questions about both sides of the compliance equation: the effectiveness of onboarding controls and the effectiveness of post-issuance monitoring and intervention.
The issue is particularly relevant to the concept of "know your customer" in digital-asset markets.
For regulated financial institutions, KYC does not end after collecting an identity document and proof of address. Effective customer due diligence involves understanding the nature and purpose of the relationship, assessing expected activity, identifying beneficial owners and applying enhanced measures where risk warrants them.
The same principles become increasingly important when dealing with institutional cryptocurrency customers seeking to purchase millions of dollars in newly issued stablecoins.
A corporate customer requesting tens of millions of dollars in USDT should reasonably generate a different level of scrutiny from an individual purchasing a small amount for ordinary trading activity.
The customer's business model, expected transaction volumes, counterparties, jurisdictions and source of wealth or funds all become relevant.
The presence of complex ownership structures should also prompt additional questions.
Where an entity is incorporated in one jurisdiction, controlled from another and conducting cryptocurrency transactions involving several further jurisdictions, a compliance team needs sufficient information to establish who ultimately controls the relationship.
This is where beneficial ownership requirements become particularly significant.
A corporate structure can obscure the identity of the individuals who ultimately benefit from or control a cryptocurrency transaction. Shell companies and nominee arrangements can make this more difficult, particularly where information is spread across several jurisdictions.
Strong AML programmes therefore need to combine corporate registry information, customer-provided documentation, sanctions screening, adverse-media checks and transaction intelligence rather than relying on a single source.
The records also illustrate the importance of ongoing monitoring.
Even if a customer is legitimately onboarded, subsequent developments may materially change the risk profile. New sanctions, criminal investigations, changes in ownership, unusual transactions or links to previously identified illicit wallets can all require reassessment.
This is particularly important for businesses dealing with customers over several years.
A KYC file that was considered adequate in 2019 may no longer be sufficient in 2026.
For cryptocurrency businesses, continuous screening against sanctions and other relevant risk indicators is therefore increasingly important.
The retrospective nature of the information also highlights a difficult aspect of AML enforcement: regulators and investigators often have access to information that was not available to compliance departments at the time a transaction occurred.
A company can therefore face scrutiny years after the original customer relationship was established.
This creates a strong incentive for firms to maintain detailed records demonstrating why customers were accepted, what information was reviewed and how risk decisions were reached.
Good documentation can be critical when explaining historical decisions to regulators or law enforcement.
The case also raises questions about the role of intermediaries.
A company purchasing USDT directly from an issuer may subsequently transfer the tokens to another exchange or wallet. That secondary recipient may have no direct relationship with the issuer.
The financial-crime risk therefore moves through the ecosystem.
Exchanges, OTC brokers, custodians and payment providers may each have their own obligations to identify customers and monitor transactions. Effective AML compliance requires controls at multiple points rather than assuming that one participant in the transaction chain will identify every risk.
The evolution of cryptocurrency regulation has increasingly reflected this reality.
Regulators are moving toward frameworks in which digital-asset service providers are expected to apply formal AML and sanctions controls similar to those already established in traditional finance.
Stablecoin issuers are consequently facing growing expectations concerning customer due diligence, sanctions screening, transaction monitoring and cooperation with authorities.
The increased scrutiny also comes at a time when authorities are becoming more aggressive in targeting cryptocurrency-enabled sanctions evasion.
US authorities have identified digital assets as an important component of certain sanctions-evasion networks, while Treasury officials have indicated that additional measures targeting digital assets could form part of future pressure campaigns against sanctioned jurisdictions.
For compliance professionals, one of the most important lessons is that cryptocurrency risk cannot be assessed purely by looking at the technology.
The underlying risk comes from the people and businesses using the technology, the jurisdictions involved, the origin and destination of funds, the purpose of transactions and the ability of criminals to exploit legitimate infrastructure.
Stablecoins can be particularly attractive because they combine many of the advantages of cryptocurrency with a value designed to remain relatively stable against a fiat currency.
That makes them useful for legitimate international commerce, but also potentially attractive for illicit actors seeking to move large amounts of value without exposure to cryptocurrency price volatility.
The challenge for issuers is therefore to preserve legitimate access while preventing the financial infrastructure from being exploited by criminal networks.
Tether's subsequent cooperation with law enforcement demonstrates that the company has developed stronger capabilities to identify and freeze illicit USDT. Yet the historical records show why regulators and compliance professionals continue to examine the effectiveness of controls at the point of issuance.
The distinction between historical onboarding failures, subsequent criminal conduct and deliberate facilitation is critical. The records alone do not establish that Tether knowingly facilitated criminal activity when the transactions occurred.
They do, however, provide a rare view into the types of customers that were able to purchase substantial quantities of USDT directly from the issuer during the stablecoin's formative years.
For the wider digital-asset industry, that history provides an important compliance lesson.
The growth of a financial product can create risks that were not fully apparent when the product was first introduced. As transaction volumes increase and criminal networks become more sophisticated, customer due diligence and transaction monitoring must evolve accordingly.
The increasing use of blockchain analytics, sanctions intelligence and automated transaction monitoring can provide firms with tools that were not widely available during USDT's early years.
But technology alone is unlikely to eliminate the risk.
Effective controls still depend on understanding customers, identifying beneficial owners, challenging unusual activity and escalating concerns when the available information does not support the stated purpose of a relationship.
The scrutiny surrounding Tether's early customers therefore highlights a broader transformation in cryptocurrency compliance.
Digital assets are increasingly being treated not as an alternative to the financial system's AML framework, but as part of that system.
As stablecoins become more deeply integrated into payments, trading and international transfers, issuers and service providers will face increasing expectations to demonstrate that they know who is accessing their infrastructure and how their products are being used.
The experience of USDT's early customer base shows why that responsibility is particularly important at the point where new digital value enters circulation. Once tokens have been distributed across a global network, tracing and freezing illicit funds can still be possible, but preventing problematic customers from accessing the system in the first place remains a far more effective AML control.
By fLEXI tEAM





Comments