Banking and Finance Law Daily Wrap Up, FINANCIAL TECHNOLOGY—FinCEN issues notice on illicit use of convertible virtual currency kiosks, (Aug 5, 2025)
Organizations Mentioned:Financial Crimes Enforcement Network
By Shashi Kant, BALLB, LLM.
FinCEN warns financial institutions of rising fraud, elder exploitation, and money laundering risks linked to the misuse of crypto kiosks.
The Financial Crimes Enforcement Network (FinCEN) has released a notice alerting financial institutions to the growing misuse of Convertible Virtual Currency (CVC) kiosks, commonly known as crypto ATMs, for laundering illicit funds and facilitating scam payments. The notice responds to escalating concerns surrounding consumer fraud, elder exploitation, and transnational criminal activity linked to these devices.
Background. CVC kiosks are self-service terminals that allow users to convert fiat currency into digital assets such as Bitcoin, Litecoin, and USDC, and vice versa. These kiosks are often located in high-traffic retail environments like gas stations and convenience stores, providing a simple and anonymous point of access to digital currencies. While they can serve legitimate financial needs, FinCEN warns that their anonymity, accessibility, and speed make them attractive tools for criminal enterprises (see Banking and Finance Law Daily, July 1, 2021).
Magnitude of the problem. Citing data from the FBI’s Internet Crime Complaint Center (IC3), FinCEN notes that more than 10,956 complaints involving CVC kiosks were received in 2024 alone, with reported victim losses totaling approximately $246.7 million, a 99% increase in complaint volume and a 31% rise in losses compared to 2023. The Federal Trade Commission similarly reported a sharp increase in fraud losses via CVC kiosks, particularly in cases involving elder abuse. In regions with a high density of kiosks, such as Chicago, kiosks have become preferred tools for cash-to-crypto laundering, prompting concerns about regional vulnerability.
Typologies and red flags. FinCEN identifies several typologies of illicit activity facilitated by CVC kiosks. These include consumer fraud schemes, such as romance scams, tech support scams, and government impersonation, as well as money laundering by transnational criminal organizations. In a particular case cited by FinCEN, a retiree in California was defrauded of $1.49 million through a scam that involved both CVC kiosk deposits and bulk gold purchases. To assist financial institutions in detecting and reporting suspicious activity, FinCEN’s notice includes an extensive list of red flag indicators. These include structured transactions below reporting thresholds, use of multiple kiosks or transactions, and repeated high-value transactions by customers with little or no prior virtual currency activity. Additionally, CVC kiosk operators who fail to register as Money Services Businesses (MSBs) or advertise transaction anonymity are flagged as high-risk entities.
Non-compliance among kiosk operators. The notice highlights widespread non-compliance among CVC kiosk operators. Many operate without registering with FinCEN or obtaining the requisite state licenses, despite their classification as MSBs under the Bank Secrecy Act (BSA). A 2021 report from the New Jersey Commission of Investigation found that over one-third of kiosk operators in the state failed to register with FinCEN. Some operators have even misrepresented their compliance status to financial institutions to open accounts or conduct large cash transactions. FinCEN notes that such non-compliant operators often lack appropriate Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) programs and are unable or unwilling to respond to law enforcement requests. They may also use personal or fictitious business accounts to disguise the origin and purpose of transactions, further complicating enforcement efforts.
Elder fraud and CVC kiosks. The FTC reports that individuals over 60 are more than three times as likely as younger adults to report fraud involving CVC kiosks. Scammers often use phone calls and pop-up ads to direct victims to withdraw cash and deposit it at CVC kiosks using Quick Response (QR) codes linked to the scammers’ wallets. Victims are sometimes coerced into making repeated transactions or redirected to use alternative methods like wire transfers and gold purchases when kiosk transactions are exhausted.
Regulatory guidance. FinCEN urges financial institutions to reference the keyword “FIN-2025-CVCKIOSK” in Suspicious Activity Reporting (SAR) when reporting suspicious activity related to the misuse of CVC kiosks. Institutions are reminded to fulfil their obligations under the BSA, including customer due diligence, SAR and Currency Transaction Report (CTR) filing, and maintaining five-year records of such reports. The notice also emphasizes the role of voluntary information sharing under Section 314(b) of the USA PATRIOT Act as a tool to detect and mitigate illicit financial flows.
RegulatoryActivity: BankingOperations BankSecrecyAct CrimesOffenses FinTech GCNNews OversightInvestigations