Cryptocurrency and Casino AML: What Online Operators Must Do Under FINTRAC, FinCEN, and Global Frameworks
Crypto deposits trigger distinct AML obligations under FINTRAC's PCMLTFA, FinCEN's BSA rules, and FATF's Travel Rule. Here's exactly what online casinos must implement.
An online casino accepting Bitcoin, Ethereum, or stablecoin deposits is simultaneously a reporting entity under financial crimes law. That dual status carries obligations that run parallel to gaming licence conditions and, in some jurisdictions, compound them. Compliance teams that treat virtual currency solely as a payment-method question will miss a distinct layer of AML law with its own thresholds, record-keeping requirements, and enforcement teeth.
This article sets out what online casino operators must do under the four frameworks that matter most: FINTRAC’s regime under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) in Canada, FinCEN’s Bank Secrecy Act rules in the United States, FATF’s Travel Rule as implemented by VASP regulators globally, and the emerging sector-specific requirements from gaming regulators including the MGA/FIAU, AGCO, and Curaçao Gaming Authority.
How Virtual Currency Enters the AML Framework
FINTRAC defines a money services business (MSB) as, among other things, a person or entity that is “dealing in virtual currencies”, understood as buying or selling virtual currency, or exchanging one form of virtual currency for another. Under the PCMLTFA and the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations (SOR/2002-184), “dealing in virtual currencies” is an MSB-triggering activity. An online casino that accepts cryptocurrency deposits directly, converts them to fiat, and credits player accounts may therefore qualify as an MSB in addition to its casino status, triggering separate FINTRAC registration and a parallel compliance programme.
The distinction matters operationally. A casino registered solely as a casino-sector reporting entity under paragraphs 5(k) to (k.3) of the PCMLTFA has specific obligations aligned to casino operations. An MSB registration adds a separate set of reporting, record-keeping, and risk-assessment requirements oriented to virtual currency dealing. Operators that accept cryptocurrency through a third-party VASP intermediary rather than handling the conversion themselves can often avoid the MSB dual-registration issue, but they remain subject to enhanced due diligence obligations and must confirm that the VASP they use is itself FINTRAC-registered. Compliance counsel should assess the specific business model before filing.
In the United States, FinCEN established the foundational framework for virtual currency and AML in its March 2013 guidance, FIN-2013-G001, Application of FinCEN’s Regulations to Persons Administering, Exchanging, or Using Virtual Currencies. The guidance determined that “administrators” and “exchangers” of convertible virtual currency are money transmitters under the Bank Secrecy Act and subject to BSA registration and programme requirements. A casino that itself exchanges virtual currency for fiat falls within that perimeter. One that receives virtual currency through a registered money transmitter processor sits outside it but remains subject to all existing BSA casino obligations under 31 CFR Part 1021.
What Does FINTRAC Require for Virtual Currency Transactions?
Casinos subject to FINTRAC must maintain a large virtual currency transaction record for every receipt of CAD 10,000 or more in virtual currency in a single transaction. The required record must capture the date of receipt, the name and address of every other person or entity involved, the type and amount of each virtual currency, the exchange rates used and their source, every other account affected, every reference number that is connected to the transaction and has a function equivalent to an account number, and, critically, every transaction identifier, including the sending and receiving addresses. That last element is the operational differentiator from fiat cash transactions: the blockchain address must be recorded as a matter of regulatory obligation, not merely operational good practice.
Source: FINTRAC, Suspicious Transaction Reporting Requirements, Virtual Currency, and PCMLTFR SOR/2002-184, confirmed in the Large Virtual Currency Transaction Record requirements specifying wallet address capture as a mandatory field.
FINTRAC applies the same 24-hour aggregation rule to virtual currency that it applies to large cash transactions. Where two or more virtual currency amounts received within a consecutive 24-hour window total CAD 10,000 or more and are known to be by or for the same person or entity, they must be reported as a single large virtual currency transaction. This rule requires that monitoring systems be capable of real-time or near-real-time aggregation across deposit events, not merely per-transaction screening.
Suspicious transaction reporting under FINTRAC carries no minimum threshold. A casino must submit a Suspicious Transaction Report to FINTRAC where it determines there are reasonable grounds to suspect that a transaction is related to the commission or attempted commission of a money laundering or terrorist financing offence. For virtual currency transactions, the FINTRAC guidance specifically identifies indicators including clients who exchange large amounts of cash into virtual currency and transfer to external wallets, who use virtual currency received from one address to fund multiple player accounts, and who conduct structured virtual currency transfers designed to stay below reporting thresholds.
FinCEN’s Casino Rules and Virtual Currency: 31 CFR Part 1021
US casinos with gross annual gaming revenue exceeding USD 1,000,000 are subject to the BSA and must comply with 31 CFR Part 1021. The Currency Transaction Report (CTR) requirement under 31 CFR 1021.311 applies to cash transactions exceeding USD 10,000 in a gaming day. Cryptocurrency received as a deposit does not constitute “cash” under the statutory definition and is therefore not a CTR-triggering event in itself, but the SAR obligation under 31 CFR 1021.320 applies to any transaction, whether in cash or other assets, that involves or aggregates at least USD 5,000, where the casino knows, suspects, or has reason to suspect the activity involves funds derived from illegal activity, is designed to evade BSA requirements, or serves no apparent lawful purpose.
“A transaction requires reporting under the terms of this section if it is conducted or attempted by, at, or through a casino, and involves or aggregates at least $5,000 in funds or other assets, and the casino knows, suspects, or has reason to suspect…”, 31 CFR 1021.320(a)(2)
The SAR threshold of USD 5,000 is materially lower than the CTR cash threshold. A pattern of cryptocurrency deposits that individually fall below USD 5,000 but aggregate above it, or that individually exceed USD 5,000 with suspicious characteristics, triggers mandatory SAR reporting within 30 calendar days of detection, or within 60 days if no suspect has been identified. Casinos must retain a copy of every SAR filed and the original or equivalent of all supporting documentation for five years from the date of filing, per 31 CFR 1021.320(d).
The aggregation rule under 31 CFR 1021.313 requires that multiple transactions by or on behalf of any person during a gaming day be treated as a single transaction where the casino has knowledge of that connection. For cryptocurrency, this means that monitoring systems must be capable of linking transactions not just by player account but by wallet address, device fingerprint, or other attribution signals, because a structurer will use different wallets intentionally.
The FATF Travel Rule and What It Means for Casinos
FATF Recommendation 16, as updated in FATF’s 2021 Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers, requires that originator and beneficiary information accompany virtual asset transfers of USD or EUR 1,000 or more between VASPs and other covered institutions. This is the Travel Rule applied to virtual assets. A casino that deposits or withdraws cryptocurrency through a VASP rail sits within the data-sharing chain this rule creates.
The practical consequence for online casino operators is twofold. Where the casino uses a regulated VASP payment processor to accept deposits, that VASP must transmit originator information, name, account number, and wallet address, to any receiving VASP. The casino’s obligation is to ensure its VASP processor is compliant with Travel Rule requirements in the relevant jurisdiction and to confirm that originator information it provides is accurate and complete. Where the casino itself is registered as a VASP (as some operators are in jurisdictions that issue VASP licences), the casino becomes a direct Travel Rule obligor and must implement the technical infrastructure, commonly using messaging protocols such as OpenVASP, TRP, or TRISA, to transmit required data on every qualifying outbound transfer.
Travel Rule compliance has a specific complication in the casino context: the unhosted wallet problem. When a player deposits cryptocurrency from a self-custodied wallet rather than an exchange account, there is no receiving VASP to transmit to, and no counterparty VASP to confirm the beneficiary’s identity. FATF guidance and most implementing jurisdictions require enhanced due diligence for transfers involving unhosted wallets above threshold, including wallet ownership verification and source-of-funds enquiry. This obligation falls on the casino or its VASP processor at point of deposit.
Wallet Attribution and the Limits of On-Chain Data
Blockchain transparency is often cited as a compliance advantage: every transaction is recorded permanently and publicly. That advantage is real but partial. Raw on-chain data tells you that a wallet address sent 0.5 BTC to a deposit address at a certain time. It does not, without attribution, tell you who controls that wallet, whether it has been previously used in sanctioned activity, or whether it has passed through a mixing service designed to obscure its history.
Blockchain analytics platforms, including Chainalysis Reactor, Elliptic Investigator, and TRM Labs, provide risk-scoring engines that attribute wallet addresses to known entities: exchanges, darknet markets, ransomware operators, sanctioned addresses, and mixers. Under the Curaçao Gaming Authority’s crypto policy guidelines issued in June 2026, all B2C licensees must implement mandatory wallet screening, risk-scoring, and transaction monitoring at both deposit and withdrawal. The CGA’s guidelines additionally prohibit acceptance of funds linked to mixers or sanctioned addresses and require exclusion or specific assessment of privacy coins and wrapped tokens of unclear origin, with full compliance required by June 2027.
Curaçao CGA Crypto Mandate (June 2026): B2C licensees must implement blockchain analytics for wallet screening and risk-scoring at every deposit and withdrawal. Funds linked to mixers or sanctioned addresses must be blocked. Privacy coins require specific assessment or exclusion. Full compliance deadline: June 2027.
The UKGC has identified cryptoasset-linked funds as a heightened ML/TF risk in its sector risk assessment, noting that e-wallets and cryptoasset-linked payment methods present greater opportunities for concealment in remote gambling. In practice, operators licensed in Great Britain that accept cryptocurrency via e-wallet or payment provider routes must ensure their transaction monitoring is configured to flag cryptoasset-origin flows at the customer risk profile level, even where the player-facing deposit method appears to be a fiat transfer. The iGamingBusiness report from July 2026 on the UKGC’s risk report noted specifically that the Commission has flagged “the rising use of e-wallets, pre-paid cards and cryptoasset-linked funds, especially in remote sectors, as these present greater opportunities for nefarious activity.”
AGCO and PCMLTFA: Ontario’s Layered Framework
Ontario-registered online operators operate under a layered framework. The AGCO’s Registrar’s Standards for Internet Gaming require, under Standard 6.02, that anti-money laundering policies and procedures supporting obligations under the PCMLTFA be implemented and enforced. Standard 6.02 specifically mandates that copies of all reports filed with FINTRAC and supporting records be made available to the Registrar in accordance with the established notification matrix, and that operators ensure their AML internal controls align with those of the designated reporting entity under the PCMLTFA.
Standard 6.03 extends this: operators must implement policies, procedures, and controls that specify times and situations, based on risk assessment, where they will ascertain and corroborate a player’s source of funds. For cryptocurrency deposits, this creates a direct obligation to conduct source-of-funds enquiry when risk indicators are present, an obligation that blockchain analytics alone cannot satisfy. Wallet risk-scoring must be combined with player-level investigation where the risk score exceeds the operator’s defined threshold.
The enforcement record underlines that regulators treat casino AML failures seriously irrespective of whether virtual currency is involved. Atlantic Lottery Corporation paid a CAD 212,025 FINTRAC fine in July 2026 after violations that included failure to report suspicious transactions, outdated compliance policies, and inadequate risk assessments. FINTRAC issued a record 35 notices of violation across all industries totalling CAD 247 million in the 2025-26 fiscal year, according to reporting by iGamingBusiness. The Alcohol and Gaming Commission of Ontario proposed a CAD 170,000 fine against Great Canadian Entertainment in July 2026 specifically for failures in identifying high-risk patrons and reporting suspicious transactions, the second major penalty against that operator in nine days. Casinos adding virtual currency rails without upgrading their monitoring and documentation architectures are compounding an already-elevated regulatory risk.
MGA and FIAU: Malta’s Approach to Virtual Financial Assets
The Malta Gaming Authority and the Financial Intelligence Analysis Unit (FIAU) jointly supervise AML/CFT compliance for MGA-licensed operators. Under the FIAU’s Implementing Procedures for the Remote Gaming sector, the CDD threshold that triggers customer due diligence obligations is EUR 150. Under MGA sandbox provisions for Virtual Financial Assets (VFAs), licensees must incorporate a separate player-specified ceiling for VFA deposits distinct from fiat currency limits, and during the sandbox period licensees may not accept VFA deposits exceeding the equivalent of EUR 1,000 per month per player.
Where smart contracts are used to automate withdrawals, the MGA’s FAQs require that identity verification be fully completed before any wager may be made. Operators accepting VFA deposits must also maintain player-specified limits for VFAs separately from fiat limits, and unverified wallet attribution, where a player claims control of a wallet but has not completed verification, means any pending funds may not be wagered until control is confirmed. The FIAU requires MGA licensees to register a Money Laundering Reporting Officer (MLRO) with the FIAU directly, and the MLRO must be knowledgeable of AML, KYC, and funds management procedures as they apply to both fiat and VFA flows.
| Jurisdiction | Regulator | VC/Crypto AML Trigger | Key Obligation |
|---|---|---|---|
| Canada | FINTRAC (PCMLTFA) | CAD 10,000 single VC receipt | Large VC Transaction Record incl. wallet addresses, STR at any amount on reasonable grounds |
| United States | FinCEN (BSA / 31 CFR Part 1021) | USD 5,000 aggregated suspicious activity | SAR within 30 days of detection, 5-year record retention |
| Malta | MGA / FIAU | EUR 150 CDD trigger, EUR 1,000/month VFA cap (sandbox) | MLRO FIAU registration, separate VFA player limits, pre-wager verification |
| Curaçao | CGA (post-LOK) | All crypto deposits/withdrawals | Blockchain analytics mandatory from June 2026, privacy coin exclusion, wallet segregation |
| Netherlands | KSA (KOA) | Not applicable | Virtual/digital currencies prohibited in licensed gambling market |
| Global (FATF) | FATF Recommendation 16 | USD/EUR 1,000 per VC transfer | Travel Rule: originator/beneficiary data transmitted between VASPs, enhanced DD for unhosted wallets |
Transaction Monitoring Architecture for Crypto Casinos
GLI-19 Standards for Interactive Gaming Systems, the international technical standard most widely referenced by gaming regulators for online casino certification, sets out minimum AML programme requirements at section A.8.2. These include a system of internal controls assuring ongoing compliance with local AML regulations, up-to-date employee training in unusual or suspicious transaction identification, monitoring of player accounts for opening and closing in short timeframes and for deposits and withdrawals without associated game play, and ensuring that aggregate transactions over a defined period may require further due diligence where they exceed the threshold prescribed by the regulatory body. The standard explicitly requires use of automated data processing systems to aid compliance.
For cryptocurrency specifically, the transaction monitoring architecture must address two layers that fiat monitoring does not face. The first is on-chain layer monitoring: every deposit address must be screened before funds are credited, and every withdrawal address must be screened before funds are sent. This is the wallet screening and risk-scoring function that the CGA has now mandated and that competent operators in regulated markets have been implementing. Screening must cover OFAC and UN sanctions lists, FATF-identified high-risk jurisdictions, and entity-level attributions to known illicit actors. The second is the player-account layer: on-chain risk scores must feed into the player risk profile used by the compliance team to determine when enhanced due diligence, source-of-funds enquiry, or transaction blocking is triggered. Decoupling these two layers, running blockchain analytics without integrating results into player-level monitoring, is a common architecture failure that regulators are beginning to identify in audit findings.
Monitoring systems must link wallet addresses to player accounts and aggregate across both layers, on-chain signals and player-account behaviours, to detect structuring and layering attempts that exploit the boundary between the two.
Privacy coins, including Monero (XMR), Zcash (ZEC) in shielded mode, and Dash (DASH) using PrivateSend, present a categorical problem: the on-chain layer monitoring function cannot be performed because transaction detail is obfuscated by design. The CGA has explicitly addressed this by requiring that privacy coins be assessed for exclusion. In practice, most compliant operators either exclude privacy coins entirely or require that they be converted to a transparent blockchain before deposit. Mixing services and tumbling services present an equivalent risk for Bitcoin and Ethereum deposits: funds that have passed through a mixer cannot be attributed with confidence, and high-quality blockchain analytics tools will flag mixer exposure directly. Acceptance of funds with mixer attribution should be treated as a high-risk indicator triggering mandatory enhanced due diligence and, where FINTRAC or FinCEN obligations apply, a suspicious transaction report at the appropriate threshold.
Does Accepting Crypto Create an MSB Registration Obligation?
Many online casino compliance teams ask this question when designing their cryptocurrency payment infrastructure. The short answer under FINTRAC is: it depends on whether the casino itself is dealing in virtual currencies. If the casino directly exchanges crypto to fiat and credits the fiat equivalent to player accounts, it is dealing in virtual currencies and should seek legal advice on whether MSB registration under the PCMLTFA is required. If the casino routes all conversion through a FINTRAC-registered MSB/VASP and receives only fiat settlement, the casino itself is not dealing in virtual currencies and the MSB registration issue does not arise, though the casino must still satisfy all casino-sector AML obligations with respect to those player deposits.
Under FinCEN’s framework in the United States, the same bifurcation applies. A casino that contracts with a registered money transmitter to process cryptocurrency payments and receives only USD settlement is not itself a money transmitter. A casino that directly converts cryptocurrency for players or holds cryptocurrency balances on behalf of players may be operating as a money transmitter and must register with FinCEN accordingly. State-level money transmitter licences add a further layer: most US states require a money transmitter licence for any entity engaged in money transmission, and cryptocurrency conversion typically falls within that definition. Operators should obtain legal advice in each state where they are licensed before accepting direct cryptocurrency payments.
Dual-Registration Risk (Canada): An online casino that directly converts, transfers, or deals in virtual currency may qualify as both a casino reporting entity and an MSB under the PCMLTFA. Both registrations trigger separate FINTRAC compliance programmes. Legal advice is required before deploying a direct-conversion payment model. Operators routing through a registered VASP and receiving only fiat settlement generally avoid this dual obligation.
Source-of-Funds Obligations for Cryptocurrency Deposits
Source-of-funds enquiry for cryptocurrency deposits is operationally distinct from fiat source-of-funds enquiry, but the underlying regulatory obligation is identical. Under FINTRAC guidance and the AGCO’s Standard 6.03, operators must ascertain and corroborate a player’s source of funds based on risk assessment. For cryptocurrency, source-of-funds enquiry has a specific meaning: the player must be able to demonstrate that the cryptocurrency they are depositing was lawfully acquired. This may involve evidence of purchase from a regulated exchange (showing fiat debit), payroll or business income evidence where the crypto was received as payment, or mining income documentation.
Blockchain analytics provides a useful pre-screening function, a wallet with a clean attribution history to a regulated exchange strengthens the source-of-funds picture. It does not substitute for documentary source-of-funds evidence at the player level where the risk profile warrants it. Operators that rely solely on wallet attribution scores without requesting player-level documentation at the appropriate risk threshold are likely underperforming their PCMLTFA and gaming-licence AML obligations. The AGCO’s enforcement pattern, including the Great Canadian Entertainment fines for failure to identify high-risk patrons and report suspicious transactions, confirms that transaction monitoring gaps at the player-account level are a primary enforcement focus even before any virtual currency dimension is added.
For the Ontario and Alberta markets, compliance teams should note that both AGCO Standard 6.03 and the AGLC’s equivalent standard in the Standards and Requirements for Internet Gaming (SRIG) require risk-based policies and procedures providing for escalating measures, including refusal of transactions and exclusion of players, where behaviour is consistent with money laundering indicators. Cryptocurrency deposit patterns that exhibit known laundering typologies (rapid deposit-and-withdrawal without gameplay, multi-wallet structuring, or deposits from sanctioned-address-adjacent wallets) must feed directly into these escalation procedures.
Key Resources
FINTRAC, Reporting Large Virtual Currency Transactions: fintrac-canafe.gc.ca, primary guidance on the CAD 10,000 record requirement and mandatory fields including wallet addresses.
FINTRAC, Suspicious Transaction Reporting (Virtual Currency scenarios): fintrac-canafe.gc.ca, worked examples for virtual currency MSB and casino STR submissions.
31 CFR Part 1021, FinCEN Rules for Casinos and Card Clubs (current to May 2026): ecfr.gov, SAR and CTR obligations for US casinos including the USD 5,000 SAR threshold.
FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (2021): fatf-gafi.org, authoritative Travel Rule implementation guidance including treatment of unhosted wallets.
AGCO, Registrar’s Standards for Internet Gaming (Standards 6.01, 6.03): agco.ca, AML and source-of-funds requirements for Ontario-registered operators under the PCMLTFA.
For an overview of how AML obligations interact with the broader iGaming compliance framework, the AML and Financial Compliance hub on this site covers FATF, FINTRAC, FIAU, and FinCEN requirements across jurisdictions.
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.
The Tuesday brief, every week.
One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.
Unsubscribe with one click. We'll never share your address.