Latest from Hypernative
Webinar: Digital Asset Risk for Traditional Finance
September 10, 2026
Insights

FinCEN just documented the fraud problem. Institutions are finding it after the money leaves.

The tooling most institutions run was built to be right after the fact. Stopping a payment before it leaves is a different control, and it already runs in production.

Hypernative

On 3 September 2026, FinCEN published an analysis of digital asset investment scams alongside an alert on overseas scam centers. Reported US victim losses have risen from $907 million in 2021 to $7.2 billion in 2025, according to the FBI's Internet Crime Complaint Center. Over roughly the same period, institutions filed 33,904 reports covering $12.7 billion in suspected scam-related financial activity.

BSA filings and reported amounts both climbed through FinCEN’s review period, from 590 reports worth $485.7 million in Oct 2023 to 2,482 reports worth $833.5 million in Dec 2025. Source: FinCEN Financial Trend Analysis, Sep 2026

The losses are high, but what the report actually illuminates is when institutions find out about them. Tucked away on page 11 shows how they are typically becoming aware only after the conclusion of the scam, or once a victim has already lost a significant sum and was still in the process of being manipulated into sending more. 

That makes this a detection problem as much as a crime problem, and it persists because the market has spent a decade building for post-facto investigation. We believe fraud cases can and should be prevented, not only documented after the fact. The reported losses are evidence that the institutions best placed to stop it are finding out too late. Scam infrastructure is deployed onchain before it takes a first victim, which means it can be found there. We built our Fraud Prevention application to find it at that point, and it runs live today at banks, central banks, exchanges and payment providers, inside their own controls and not in a vendor's investigation queue.

Why existing controls today do not eliminate the risk

How a customer fraud happens

In the pattern FinCEN identifies as dominant, the scammer directs the victim to open an account at a money services business offering digital asset services, buy a specific asset, and send it to an address the scammer controls. The customer is doing exactly what they intend to do, in their own account, with their own funds. That is what separates this from phishing, where the defence works by blocking an action the user never intended. Here the only leverage is what you know about the destination at the moment it is submitted.

Learn more: Fraud vs. Phishing: Why Insitutions Need Different Defenses for Different Threats

Intervening late doesn’t close the gap. FinCEN reports that when institutions spotted a scam early and tried to stop the payment, customers frequently completed it anyway. While this leads to a filing, the organization exposes itself to the reputational hit when a customer loses their savings on its platform, the churn that comes after, the operational spend on investigation and remediation, and liability for the loss itself. Regulators are adding to that bill, with UK reimbursement rules for authorised push payment fraud from 2024 and Singapore's Shared Responsibility Framework since December 2024.

The institution is the only party that can actually save the customer

Attempted fraud is not going away. Scam centres are an industry with revenue in the tens of billions, and no institution controls whether its customers get targeted. What it does control is whether the payment completes. A blocked scam withdrawal protects the person, at the only moment the money is still there, and it is the rare piece of compliance infrastructure a customer would thank you for if they knew it was running. The customer keeps their savings, and they keep them because of where they chose to hold them.

Prevented losses are easy to count, but the retained customer, the support ticket that never opens, the case that never reaches the investigation queue, and the regulatory position of being ahead of the reimbursement rules are all downstream of the same intervention.

Why existing tooling fails on fraud

Existing tooling can’t solve for this. Sanctions screening and fund tracing protect the institution from regulatory risk, which is a different job from protecting the customer from losing money. Screening is deterministic by design, because a sanctions hit has to be defensible against a published list. Fraud detection has to be predictive, because the address a victim is about to pay has usually never appeared on any list. That difference sets the timing. An investigation platform works from reports and traced flows, so the signal only exists once somebody has already lost money. If the first ten users pay a scam cluster before anyone reports it, an investigation-led stack will only protect the eleventh.

It’s fixable, and the control already sits with the institution

The institution is the one positioned to act. Every withdrawal already passes through gates you own, including limits, authentication and AML screening, and you can see the destination address before anything is sent. Adding a destination risk decision is one more check in a sequence that already runs.

Meeting the brief FinCEN has set takes four things:

  • Move the decision before the transaction, while funds are still in the customer's account. Screening after execution is investigation, and in digital assets there is no reversal mechanism to fall back on.

  • Detect networks, not addresses. FinCEN reports that scammers reuse collection addresses across victims and rotate to fresh wallets, across at least 22 assets, with near-universal conversion to USDT and cross-chain swaps through DeFi before off-ramping. Meeting the standard FinCEN sets requires graph analysis that maps relationships continuously, including for addresses with no individual history, across full chain coverage rather than partial. Onchain signals alone are not enough, so attribution also depends on proprietary scam flagging and offchain sources such as scam reports, phishing domains and OSINT.

  • Measure prevented value, not flagged value as prevention has different metrics from investigation. Detection and false positive rates, time to detection, and prevented value should be measured as distinct from flagged value. A prevention layer that works reduces the volume of avoidable cases reaching the investigation team, and precision should be a property of the detection layer rather than something the team absorbs.
  • Provide the right solution for your team needs. This decision usually spans fraud, compliance and operations, and those teams have different success criteria. Institutions that treat it as a single compliance purchase tend to end up with a control optimised for filing rather than for stopping payments.

Supervisors are reaching the same conclusion. Like FinCEN, Banco Central do Brasil identified scam and fraud losses as a problem it wanted out of its ecosystem, and is advancing to contract Hypernative as its build partner for continuous onchain monitoring and fraud intelligence covering the Brazilian financial sector, on the strength of a proof of value that developed a methodology specific to that market.

Learn more: Banco Central do Brasil Advances to Contracting Hypernative to Support Real-Time Crypto Fraud Intelligence

How we approach it

The engine behind Hypernative’s Fraud Prevention application is the most battle-tested in digital asset security, running across more than 75 chains for over 350 institutions and preventing over $3 billion in losses. Fraud Prevention sits on that same infrastructure, which is why it behaves like a threat detection system rather than a screening list. In production across leading exchanges it now prevents more than $100M a year in user losses, as net-new detections that existing screening controls had already passed.

We continuously monitor onchain activity alongside offchain and Web2 sources, using machine learning and graph analysis to identify fraud infrastructure as it is deployed rather than after it is reported, the same approach we use to catch attacker preparation before an exploit executes, applied to scam networks. The output is clusters, so an address that has never been individually flagged can still be identified through the network it belongs to in real time.

Part of what makes that possible is that the detections are not chain-specific. A scam cluster is identified by behaviour, being how wallets are created, funded, connected and consolidated, and that behaviour looks the same whether it plays out on Ethereum, Tron or anywhere else. A control that reasons about behaviour follows a cluster across that path. A control that reasons about addresses loses it at the first bridge.

The vantage point compounds it as we work with chains, issuers, exchanges, asset managers, wallets and protocols simultaneously, so a cluster surfacing at one institution informs the model everywhere else. An investigation platform sees the problem through whatever its customers report. We see it from every direction at once. 

Hypernative's Fraud Prevention solution is built for the specific decision FinCEN describes as the difficult one.

When a withdrawal is initiated the destination is scored against that intelligence, returning an approve or deny recommendation at sub-second latency inside the flow. Every deny carries an investigation summary covering wallet labels, cluster analysis and fund tracing, so your analysts can action it and defend it to the customer. You configure your own allow and deny policies on top.

4x the detection rate of the incumbents

Source: Independent head-to-head evaluation conducted by a top-five global cryptocurrency exchange, August 2025. Three vendors queried live against the same withdrawal traffic over three weeks. Vendor names withheld.

A top-five global cryptocurrency exchange ran this against its incumbent stack for three weeks. Every withdrawal was queried live against Hypernative and two established blockchain analytics vendors at the same time, so each system was asked what it knew at the moment the customer hit withdraw rather than in hindsight. Our engines identified 96% of the confirmed scam addresses. The two incumbents identified 28% and 40%, and raised their alerts a month or more after the first transaction while ours landed at or before it. Across the same dataset, that resulted in $1.8 million in prevented user losses versus $65,000 and $110,000 with the other vendor solutions, respectively.

Three things we have learned running this in production:

  • Net-new detection is the honest test. In every production test we have run, nearly all our detections were fraud that had already passed the platform's existing vendor protections and screening controls. The question worth asking a vendor is not what they catch, but what they catch that your current stack does not.

  • Precision is a dial, and it should be set by the institution. One leading exchange specified 90% precision before going live, so we tuned the threshold against their own withdrawal history to meet it. Pareto-optimised alerting means reviewing 3 to 5 accounts a day. Once you are blocking withdrawals in real time, a false positive lands on the customer.

  • Screening at the moment of transaction is not enough on its own. A fraud network operating across several chains shows up inside a chain-partitioned control as a handful of unrelated fragments, none of which justify flagging.Institutions remain with part controls because widening scope is genuinely difficult as without a shared viewport, linking addresses across chains means inferring relationships, and done haphazardly inflates false positives enough to make real-time blocking unusable. Building structure to detect networks as they are deployed, wherever they are deployed, without paying for it in operational overhead is the harder problem and defines whether a prevention layer covers the actual activity or just the chain.

How to start protecting your customers funds against fraud and scams

FinCEN has handed every fraud, risk and compliance team in digital assets an unusually clear brief. The typology is documented, the red flags are published, and the agency has stated on the record that institutions are mostly finding this activity after the money is gone.

So the question is narrow. Of the value that left your platform to fraud-connected destinations in the last six months, how much was already knowable at the moment of withdrawal? Most institutions cannot answer that, because the tooling was not built to record it.

Send us a sample of your outgoing transaction history and we will return what we detected, what was preventable at the time, and how that compares with what your stack surfaced. We will also send you addresses we have flagged so you can validate them against your own records. No integration required.

Stay ahead of the curve, subscribe for the latest in Web3 security