Crypto exposure can sit inside an apparÂently convenÂtional payment chain even when the merchant never prices goods in cryptocurÂrency. A customer may pay by card, an acquirer may settle in fiat, and a later treasury transfer may convert proceeds into a stablecoin. InvesÂtiÂgators therefore need to trace the full flow of value, not merely search the merchant’s website for a crypto-payment button.
Map the payment chain before analysing wallets
Start with the commercial transÂaction and identify every role: merchant, payment gateway, payment facilÂiÂtator, acquirer, bank or electronic-money instiÂtution, exchange or other virtual-asset service provider, custodian, wallet controller and final benefiÂciary. Record the contracting entity, regulated entity, account name and jurisÂdiction for each step. Similar trading names can hide different legal entities.
Draw separate paths for customer payment, merchant settlement, refunds, chargeÂbacks, reserves and intra-group transfers. This approach builds on the same disciÂpline used when tracing cash through payment facilÂiÂtators. It also reveals where a fiat transÂaction becomes a virtual-asset transfer—or where claimed crypto exposure never occurs at all.
Distinguish direct and indirect exposure
Direct exposure includes holding cryptoassets, controlling a wallet, accepting a token from a customer or receiving settlement in a token. Indirect exposure can arise when a processor or treasury provider converts funds, a counterÂparty relies on crypto liquidity, or a group company handles the virtual-asset leg.
Do not equate crypto accepÂtance with price risk. A processor may convert the customer’s asset immediÂately and pay the merchant a fixed fiat amount. Conversely, an ordinary card-acquiring arrangement can create crypto exposure if merchant proceeds are later settled in stableÂcoins. Malta Media’s report on PAYSTRAX adding optional stablecoin settlement is a useful illusÂtration of the distinction between the payment method and the settlement asset. Provider claims should still be checked against contracts, regulator records and transÂaction evidence.
Collect evidence from both sides of the bridge
For the fiat side, examine bank stateÂments, processor stateÂments, merchant descriptors, settlement reports, invoices, reserve movements and foreign-exchange entries. For the crypto side, preserve wallet addresses, transÂaction hashes, chain, token contract, timestamp, amount and transÂaction fees. Confirm that the token is genuine; ticker symbols and copied logos are not reliable identiÂfiers.
A blockchain record can show transfers between addresses, but it does not automatÂiÂcally identify the person controlling an address. Custodial platforms often use omnibus wallets and keep decisive ownership inforÂmation off-chain. Bridges, mixers, decenÂtralised exchanges, internal exchange ledgers and address rotation can further interrupt a simple trail. AttriÂbution from an analytics provider should be recorded with its source, date and confiÂdence level rather than presented as certain fact.
Link the two sides using several corrobÂoÂrators: matching amounts after fees, narrow timestamps, repeated deposit addresses, exchange reference numbers, counterÂparty names, withdrawal confirÂmaÂtions and Travel Rule inforÂmation where available through lawful channels. A flow-of-funds diagram should mark verified links differÂently from inferred ones.
Check the service providers and controls
Verify each provider in the relevant regulator’s register and check whether the legal entity is authoÂrised for the service and territory in question. A group company’s licence does not automatÂiÂcally cover its affilÂiates. The FCA’s current cryptoasset regisÂtration expecÂtaÂtions specifÂiÂcally call for monitoring of both fiat, off-chain activity and cryptoasset, on-chain activity, supported by a detailed flow-of-funds diagram.
Review onboarding, source-of-funds records, sanctions screening, counterÂparty due diligence, wallet screening, alert dispoÂsition and escalation logs. Examine whether the business can identify origiÂnators and benefiÂciaries rather than merely generÂating risk scores. When shell entities appear in the chain, apply the ownership checks described in our guide to tracing the owners of a crypto brokerage.
Treat red flags as prompts for verification
The FATF virtual-asset red-flag report highlights unusual transÂaction patterns, anonymity-enhancing features, geographical risk and activity without a logical business explaÂnation. None proves wrongÂdoing on its own. High-frequency transfers may reflect legitÂimate treasury operaÂtions; a bridge may be used for cost or liquidity reasons; and one exchange deposit address may represent many customers.
Stronger findings usually combine indicators: unexplained converÂsions shortly after card settlement, funds routed through an unrelated group company, repeated exposure to sanctioned or illicitly attributed services, inconÂsistent invoices, or a provider operating outside its permisÂsions. Compare those facts with how payment instiÂtuÂtions allocate strucÂtural risk before assigning responÂsiÂbility.
Report the result with clear limits
State the period reviewed, chains covered, data sources and missing records. Separate confirmed transfers, provider attriÂbution, analytical inference and unresolved gaps. Calculate exposure using a consistent valuation time and distinÂguish gross flows from balances actually held.
A defenÂsible invesÂtiÂgation may conclude that the merchant had direct exposure, indirect counterÂparty exposure, settlement-only exposure or no demonÂstrated crypto exposure. That calibrated answer is more valuable than claiming the blockchain makes every payment transÂparent.