On 9 June, during ITU Legal Talks organised by IT Ukraine Association with the participation of its legal partner Juscutum, Oleksandr Horobets, Partner and Head of Business Security Practice at Juscutum, explored how cryptocurrency transactions can become exposed to criminal risks and what businesses should monitor to protect their assets.
What an Incident Looks Like in Practice
A typical scenario begins when an exchange or regulator freezes an account, restricts transactions, and requests documentation confirming the source of funds and the rationale behind transactions. For businesses, this may result in:
- Temporary or complete loss of liquidity and working capital;
- A chain reaction involving the freezing of related accounts and payments;
- Escalation through increased scrutiny from judicial and law enforcement authorities.
Why Crypto Transactions Enter the “Red Zone”
The speaker identified five primary risk triggers:
- Counterparties with a high-risk profile;
- Documentation that does not align with the economic substance of transactions;
- Rapid transfers without a clear business rationale (“transit activity”);
- Discrepancies between the source of funds and their actual movement;
- Sanctions-related, geographical, and behavioural risk indicators.
How Cryptocurrency Becomes Involved in Illicit Schemes
The session also examined common mechanisms through which cryptocurrency becomes associated with unlawful activities:
- Conversion and cash-out operations through exchanges and P2P platforms;
- Wallet fragmentation, where assets are distributed across multiple addresses before being transferred further;
- Mixing services designed to obscure the origin of funds;
- Ransom payments following cyberattacks, where cryptocurrency becomes part of an illicit financial flow;
- Transactions conducted through illegal platforms.
The Line Between Compliance and Criminal Risk
A situation may escalate when risks become systemic, external inquiries emerge, or sanctions-related concerns are identified. For executives, this can lead to procedural involvement, the risk of searches, seizures, and asset freezes, as well as personal accountability for decision-making and communications.
A key takeaway from the speaker was that compliance responses should not be confused with legal defence strategies.
Key Considerations for Business Leaders
Oleksandr Horobets highlighted three critical points:
- Exchange algorithms assess cases through KYC, KYB, and KYT frameworks; the issue is not anonymity but how a transaction appears to compliance providers.
- Even legitimate assets can become high-risk cases due to counterparties, insufficient supporting evidence, or communication failures.
- Decisions are made on the basis of documented evidence, not verbal explanations.
The 24–72 Hour Response Protocol
In the event of an incident, the speaker recommended a structured approach:
- Within the first 0–2 hours: record the account status, transactions, correspondence, and access logs;
- On Day 1: map the case, including the provider, jurisdiction, applicable rules, and affected assets;
- On Days 2–3: prepare the evidence package, establish a legal position, and maintain communication control.
The guiding principle is simple: less emotion, more structure.
Building a Control System Before an Incident Occurs
To reduce the likelihood of asset freezes, Juscutum recommends implementing a preventive framework that includes:
- A crypto asset policy defining who may conduct transactions, under what circumstances, and on what grounds;
- Counterparty screening based on minimum KYC/KYB requirements before every transaction;
- Internal or external transaction risk monitoring;
- Segregation of access rights, logging, and internal audit procedures;
- Regular training for finance, legal, and security teams.
Use Є-Support — the free legal consultation service, also offering cybersecurity consultations for ITU Members.