Beware of scammers impersonating Crystal Intelligence

Thought Leadership | September 16, 2026

Nested exchanges: why one compliance check is not enough

By The Crystal Intelligence Research Team   

Share via:

Crystal’s latest Compliance Blind Spot webinar put one question to a global panel: are nested exchanges a niche onboarding problem, or a systemic one? 

Key Takeaways 

  • Concentration is the finding, not the total. 87% of $8B traced nested volume sits behind one host exchange: a single point of systemic exposure.  
  • Nested relationships get one compliance check at onboarding, rarely revisited. Business models change; the host’s assessment does not. The gap is structural rather than individual.  
  • Pooled accounts collapse thousands of customers into one identity in the host’s logs. Forensic reconstruction becomes near impossible; one customer’s trigger can freeze everyone behind them.  
  • Value thresholds miss nesting. Detection runs on behavior: automated sweeps, deposit substitution, near-zero balances. Screening only declared relationships lets the compliance perimeter be rented out. 

Harvesh Kumar Seegolam, former Governor of the Bank of Mauritius, moderated a panel hosted by Crystal Intelligence whose combined expertise spans four continents and two major global policy frameworks. 

It included Marc Krisjanous, Founder and Principal Consultant at Zanarc, from New Zealand; Loretta Joseph, Lead Expert for the Commonwealth Model Laws on both Virtual Assets and Stablecoins, from Australia, who joined from the Caribbean; Mu’azu Umaru, Acting Secretary General of the Economic Community of West African States (ECOWAS), from Nigeria; and Crystal’s Compliance Advisory Manager, Irina Gorbach. 

Live polls conducted throughout the discussion were also revealing: 

Poll #1 

Poll chart showing that 6 in 10 webinar attendees were from supervisory backgroundsAbove: A regulator-heavy room: six in ten attendees supervise rather than operate, which is why the session’s framing ran to policy and enforcement as well as tooling. Source: Crystal Intelligence. 

What exactly is a nested exchange? 

Marc opened with the structural definition. A nested exchange arrangement lets a smaller operator – a broker, payment service or OTC desk – use infrastructure it could not affordably build itself: a trading engine, a policy engine, funds transfer and wallet infrastructure. 

What separates it from an ordinary corporate account is that the customer relationship and the underlying exchange activity are split. The nested service knows its customers and tracks their balances on its own internal ledger; the host executes the activity. 

“The first real structural question,” Marc said, “is whether the host exchange knows the account or the nested exchange is supporting downstream customers as well.” Marc’s recommendation was to treat it as a shared service across several organizations rather than as a customer relationship. 

Loretta, a regulatory policy expert on the Commonwealth Model Law on Virtual Assets, described the same structure from the supervisory side. Behind a single institutional account may sit thousands of corporate and personal accounts. The host sees a single customer, not that this customer is a gateway for further financial services businesses, or whether anyone behind it has been KYC’d at all. 

Infographic showing that Direct customers face one exchange; nested customers' custody hides with unseen host.Above: A direct customer faces one licensed counterparty. A nested customer faces an operator, while custody actually sits at the host exchange they never see. Source: Crystal Intelligence. 

Mu’azu Umaru, a former FIU official, built on the point with a pre-crypto analogy: cooperative savings through a money collector – esusu in Nigeria. Members contribute, the collector banks the pooled funds and keeps the ledger, and the bank knows one person rather than the thirty behind him. “So, the bank is taking a lot of risk without knowing those who are behind the collection,” Mu’azu said. 

The technology is new; the structure is not: It’s the same pooled-account problem that banks and payment providers faced before the advent of virtual assets. 

How much nested service volume is there, and where does it sit? 

Irina supplied the scale. Crystal’s research recently identified around $8B in nested-service activity across 39 host exchanges and more than 2.27 million transactions. Roughly 87% of the identified volume was concentrated at a single host exchange. 

Infographic showing that $8B in nested service activity across 2.27 million transactions went through a single host, making it a supervisory issue.Above: Scale alone is not the story. Nearly $8B across 2.27 million transactions poses a supervisory problem because 87% of it rests on a single host. Source: Crystal Intelligence. 

Some nested services declare themselves; others do not, which is why Crystal’s blockchain analytics platform compares declared business models against observed transactional behavior. When that much volume sits behind one host, the exposure stops being an individual customer risk and becomes a concentration and supervisory issue. 

Mu’azu added a regional figure – Nigeria alone saw $92B in flows within one year – and noted that stablecoins now account for over 80% of exchange instruments in Africa. He warned against importing typologies wholesale: geographical risk analysis matters, particularly for parallel peer-to-peer settlement, where the offsetting leg is invisible to regulators and banks. 

Where does nested exchange risk concentrate? 

Nested services typically reach the host through its API, often with weak privileges, sometimes through a single account. Hundreds of thousands of customer transactions therefore resolve to one identity in the host’s logs, making incident response and forensic reconstruction close to impossible. Custody consequences follow from the same architecture: if the nested service fails, its customers have no relationship with the host to claim against – and because funds are pooled, one downstream customer’s fraud or sanctions trigger can freeze everyone else’s. 

Asked what failure looks like from the inside, Marc named three governance patterns he sees when auditing exchanges and custodians:  

  • Control concentrated in very few hands, sometimes one or two people running the entire host relationship;  
  • Weak internal policy and cybersecurity hygiene, on the assumption that the host’s controls will do the work; and, worst,  
  • Founders who close shop with the funds, leaving customers no route to the host. 

Why does one-time VASP due diligence miss nesting? 

Loretta’s central argument was that nested relationships receive a single compliance assessment and are rarely revisited. An entity may onboard as a proprietary trader or liquidity provider, then add exchange, brokerage, custody or payment services for its own clients – without the host re-examining anything. 

Three failures compound it: 

  • Transaction monitoring examines individual transactions rather than the relationship structure, so pass-through flows and shifting business models get assessed one transaction at a time. 
  • Fragmentation means the host assumes the intermediary has done customer due diligence while regulators supervise the two entities separately – often with the intermediary offshore and unlicensed. 
  • Regulatory returns report aggregated volumes without identifying which institutional customers provide downstream access, so supervisors cannot see the relationship at all. 

Her recommendations: 

  • Supervision that is dynamic, technology-led, relationship-based and genuinely cross-border.  
  • MOUs are useful but insufficient – requests that take months to answer are no match for the value moving across jurisdictions in seconds. 
  • Regulators need statutory authority to exchange information rapidly, run coordinated inspections, and act – freeze, restrict, seize records – without waiting on court timelines. 

She positioned the Commonwealth Model Law on Virtual Assets as the mechanism – consistent definitions, licensing, risk-based supervision, Travel Rule obligations, reliance controls, enforcement powers – available to 58 countries and 2.7 billion people. 

Cross-border oversight, she said, must follow the service, the customer, and the flow of value, not the place of incorporation. And regulatory equivalence must not become automatic passporting: it should be evidence-based, continually reviewed, and capable of being withdrawn. 

Mu’azu put it more bluntly: “The car has already left the station,” he said – governments are managing the wreckage of a system built beyond their control. What is needed is a global coalition because most host exchanges sit outside the regions that carry the risk. 

Suex–Chatex: What does nesting look like under sanctions? 

Irina used a 2021 enforcement case to show what nesting looks like when it fails. Three layers: a large global exchange providing infrastructure; Suex operating as a nested service on it; Chatex, a layer below, using Suex’s nested function to serve its own customers. The host sees Suex as a direct customer while the economic activity originates with Chatex’s. 

OFAC sanctioned Suex in September 2021, by which time it had processed $1.86B in nested volume, then sanctioned Chatex in November 2021, explicitly citing its direct ties to Suex and its use of Suex’s nested exchange function. The further down the chain, the weaker the host’s visibility into originator, beneficiary and purpose. Crystal’s earlier sanctions compliance briefing found the same: attendees named nested exposure their biggest screening challenge. 

Crystal's

What should compliance teams watch for, and what do regulators require? 

Poll #2

Poll result showing that 39% of the audience don;t screen for nested services at all.Above: Just 11% screen systematically; 39% do not screen at all. Absence and uncertainty cover nearly two-thirds of the room – that is the blind spot. Source · Crystal Intelligence. 

Irina’s guidance came in three parts: 

  • Check whether the declared business model matches observed activity – a self-described small broker generating high-frequency retail-style flows, repeated stablecoin transactions or activity in unexpected jurisdictions warrants review. 
  • Watch the on-chain behavior: automated sweeping shortly after receipt, aggregation of multiple deposit addresses, threshold-triggered batch movements, withdrawals paid from the host’s hot wallet rather than the service’s own infrastructure, near-zero running balances. 
  • Do not rely on the direct customer’s KYC alone – establish whether that customer serves other brokers, OTC desks or VASPs beneath it. 

She used the following example to illustrate the point: 

  • One customer deposits $6,000,  
  • Another $8,000,  
  • A third requests a $10,000 withdrawal. 
  • Instead of paying from treasury, the service combines the $6,000 with $4,000 of another deposit through a temporary intermediate wallet.  

One transaction proves nothing. Repeated short-lived wallets, deposit substitution, rapid aggregation, no residual balance – it becomes an operational fingerprint. This is why nested exposure cannot be supervised through value thresholds alone. 

For regulators, she set out four requirements: 

  • Require VASPs to identify and disclose nested relationships; 
  • Ask for periodic nested-service exposure assessments, not generic AML policies;  
  • Require firms to show how they detect undeclared nesting through behavioral and blockchain indicators;  
  • Ensure VASPs hold contractual rights to underlying customer information when a risk trigger fires. 

Frequently asked questions 

Is nested activity illegal? No. Nesting is a legitimate service model. The risk arises when the host cannot see who the operator’s downstream customers are. 

Does the host’s KYC cover downstream customers? No. It reaches the direct customer only. Thousands of end users can sit behind that single account, unscreened. 

Can we rely on an intermediary’s license? Verify where it is actually regulated, and for what. Equivalence should be evidence-based and withdrawable, never automatic passporting. 

What happens if a nested service fails? Its customers have no relationship with the host to claim against. Pooled funds make unwinding individual balances nearly impossible. 

In conclusion, do nested exchanges pose systemic risk? 

Legitimate nesting has a purpose – smaller exchanges need liquidity, custody and infrastructure they cannot build, and every panelist accepted that. The objective, as Irina put it, is to make sure a regulated VASP’s compliance perimeter cannot be rented out to an unknown third party. 

The regulator-heavy audience was asked what their next steps after the discussion would be: 

Poll #3

Poll result showing that two thirds of the audience want to Above: Two-thirds asked for the underlying research rather than general updates – a signal that this audience wants the dataset and typologies, not another awareness session. Crystal listened:

Chart showing that nested services volume peaked 2021 ($2.64B); transactions peaked 2025 (1M+), showing shift to smaller, frequent transfers.Above: Nested services activity versus transaction value chart timeline – volume peaked in 2021 ($2.64B, fewer transactions), while the transaction count peaked in 2025 (1M+ transactions, lower volume) – nested activity shifted toward smaller, more frequent transfers, which volume-based monitoring misses. Our full report unpacks the fine details. Find out more below. Source: Crystal Intelligence.

Harvesh then closed the session by thanking Crystal for hosting it and recording his disagreement with the quarter of the online audience who didn’t feel that nested exchanges necessarily pose systemic risk. On his reading, they do, and closing the gap will require coalition, coordination, and harmonization among regulators, law enforcement, and operators alike. 

Watch the full webinar here. 

Disclaimer: Views expressed by panelists are their own and do not necessarily reflect the position of Crystal Intelligence. This summary is for informational purposes only and is not legal, compliance, financial or investment advice.

One host exchange carried 87% of all traced nested volume. Whether that venue is your counterparty, your licensee or your client, the Nested Services report has the detail, and our team can map your exposure. 

Summarize with AI
On this page
Subscribe to our newsletter

Stablecoin | September 10, 2026

What tokenized real-world assets actually look like on-chain

We read the holder data behind $18B in tokenized real-world assets to see who actually holds them - and it isn't retail.

Investigations | September 7, 2026

Crypto card services double in five months

Crystal's follow-up finds 150 new crypto card services in five months, with non-custodial wallets driving much of the growth

Decision Intelligence | September 2, 2026

Decision intelligence for threat detection vs. blockchain analytics

A risk score tells you a wallet looks risky. Here's what decision intelligence adds on top of blockchain analytics for threat detection teams.