Donald Trump Oval Office Speech Today at 2 PM: What to Expect
Bitget has opened BTC withdrawal services as scheduled
The CLARITY Act failed because Democrats opposed President Trump more than they...
Upbit crypto exchange reported a weekly volume of $11.7 billion in week ended Sept.
California Governor Gavin Newsom Signs Law Banning Public…
Quant rises after The Clearing House selects it for On Chain Money Initiative and UK banks...
Bitcoin Price Crashes to $82,780 as Gold and Silver Lose $550B in Hours
4 Major Events to Watch for Bitcoin and Crypto Markets This Week
RedotPay Delays US IPO to 2027 Following Financial Audit and Legal Challenges
XRP Ledger’s Batch Upgrade Slips From September 29 to…
Crypto Sentiment Flipped“F&G has moved from around 30 to 74 in a relatively short period, while...
RedotPay completes financial audit as it presses ahead with U.S. IPO plans
BitMine's MAVAN Emerges as Key Revenue Driver with $357 Million Projection
A newly created wallet "0x80Fa" just withdrew 10,390 $QNT($2.87M) from...
THORChain Rejects Bitget’s Call to Block Attacker Funds After $387.5M HackTHORChain responded to...
Fake GIWA Chain Drained 766 ETH After 1,335 Addresses Bridged Into It
BlackRock Says AI Agents Could Become Crypto’s Next Demand Engine
616 $BTC (51,101,051 USD) transferred from Coinbase Institutional to unknown wallet...
Bitget hacker is swapping ETH for BTC via THORChain
Strategy to Hold Online Special Shareholders' Meeting on October 28
The #Bitget hacker, who stole $351.6M, is now swapping $ETH for $BTC through...
Vitalik Buterin Says Hegota Will Be Ethereum's Last 'Normal' Fork
The CLARITY Act failed because Democrats opposed President Trump more...
South Korea Considers Lifting Crypto Market-Making Ban to…
Hangzhou Yushu Robotics Increases Registered Capital to 25.1 Million Yuan
Aave Founder Envisions Expansion of Collateral Assets to Include Renewable Energy and Technology
799 $BTC (66,509,492 USD) transferred from unknown wallet to Coinbase Institutional...
Apple, Nvidia and Tesla Tokenized Stocks Can Now Back USDC Loans on Aave
NEAR Price Climbs as Bitwise ETF Gets Green Light: $155 Target Sparks Fresh Rally
Binance Wallet Removes Native Gas Token Requirement With…
THORChain Rejects Bitget CEO’s Request to Block $387.5M Hacker Wallets
Bitcoin Price Today: BTC Slips to $83,200 After a Quiet Weekend
Unitree's Hangzhou robotics subsidiary increases registered capital 250-fold, from 100,000 yuan to 25.1 million yuan
Orca API: 14 keyless endpoints, no candles, no trade feed
Meteora API for DLMM, DAMM and DBC pools on Solana
THORChain clarifies network pause mechanism, emphasizes protocol remains permissionless and neutral
Will AMD Stock Keep Going Up? The Bull and Bear Cases
ThorChain Implements Network Interruption as Security Measure
Binance Will Support the Base Network Upgrade & Hard Fork - 2026-09-30Starting at approximately ...
Zero-Knowledge Breakthrough Makes Bridge Hacks ‘Unviable’
WuBlockchain Weekly Outlook: The macro trade is about to be stress-tested. U.S. payrolls, ISM,...
THORChain Refuses to Block Bitget Hackers Moving $387.5M to Bitcoin
California Bans Official Meme Coins, Cites Trump’s Crypto Venture
Big institutional money is split on Bitcoin’s next move as massive market bets shift
Vitalik: Ethereum Is Evolving Beyond a Blockchain Into a…
Apple, Nvidia and Tesla Tokenized Stocks Can Now Be Used to Borrow USDC on AaveSeven Coinbase...
American Companies Significantly Increase Mentions of Open-Source Models
Circle Internet Group Co-Founder Resigns, CFO to Depart by Year-End
U.S. spot Solana ETFs pull in record $188 million in weekly inflows, led by BitwiseRead...
Does Brad Garlinghouse See XRP As Digital Gold? Here’s What He Said
Why Is Bitcoin Price Going Down Today?
799 $BTC (66,508,104 USD) transferred from unknown wallet to Coinbase Institutional...
Circle Co-founder Sean Neville Resigns from Board; CFO Plans Departure, to Remain Until End of 2026
Chuan Dou Bao Develops Competing Product to Meta Muse in Six Days
California Bans Public Officials From Issuing Their Own Meme Coins
53 Robinhood Chain Token Launches Linked to Rug-Pull…
California's Newsom signs memecoin ban and calls it 'The Opposite of Trump'
Solana ETFs draw record $188 million in a week as Bitwise takes two-thirds of inflows
615 $BTC (51,127,057 USD) transferred from Coinbase Institutional to unknown wallet...
XRP Price Analysis for Today 28th Sept
Vitalik Buterin Says Ethereum Is Becoming a Cryptographic World Computer
Crypto Week Ahead: PCE, Jobs Report & Korea Blockchain Week
Capital B acquires 13 more bitcoins, now holding 3,538 BTC
1,700 $BTC (141,199,275 USD) transferred from Coinbase Institutional to unknown...
WTI and Brent Crude Oil Prices Increase Over 2%
Nano Labs founder's X account has been recovered
GoPlus Challenges THORChain’s Decentralization Claims Over…
Coinbase CEO Stands by His $400K Bitcoin Prediction for 2030
Scammers Launch Fake ETH L2 to Steal $2M From Crypto Traders
From AML Screening to Lazarus Investigations: Interview with AMLBot CEO Viacheslav Demchuk
• AMLBot’s Evolution: From Address Screening to Full AML Infrastructure
• Small Businesses: The Same Risks, Far Fewer Resources
• Compliance as a Continuous Process
• How Investigations Shape Risk-Scoring Systems
• AI Speeds Up Processes but Does Not Replace Investigators
• Bybit, Lazarus, and the Gap Between Analysis and Platform Response
Crypto companies are finding it increasingly difficult to detect and stop suspicious transactions. Criminals are moving funds faster across addresses, networks, bridges and other services, leaving less and less time to detect and block them. The record-breaking Bybit hack in February 2025 made this especially clear.
At the same time, regulatory requirements for market participants are growing. As of July 1, 2026, the MiCA framework is fully in effect in the EU, while companies must also comply with rules on transmitting information about the originator and beneficiary of crypto-asset transfers under the Travel Rule.
Incrypted spoke with AMLBot CEO and co-founder Viacheslav Demchuk about how the blockchain analytics market has changed over the past several years, the role AI now plays in investigations, and why detecting a theft is not enough.
AMLBot’s Evolution: From Address Screening to Full AML Infrastructure
When you first started AMLBot, what year was it? Do you remember what the market looked like back then and what exactly prompted you to launch your new solution?
The idea was first conceived in 2017, before AMLBot’s full-fledged launch in 2019. At that time, blockchain analytics was already developing, but most serious compliance tools were designed for large exchanges, financial institutions and government agencies.
If you were a medium-sized or smaller crypto company — or simply an individual who wanted to understand whether funds coming into your wallet had exposure to illicit activity — the options were limited, quite expensive and technically difficult to use.
That was the gap we saw. The idea was that blockchain compliance shouldn’t only be accessible to companies with large compliance departments and enterprise budgets.
What started as a relatively simple screening tool eventually became a much broader infrastructure. As crypto became more regulated and financial crime became more sophisticated, our clients needed transaction monitoring, KYC and KYB, investigations and eventually cross-chain tracing and asset recovery. So AMLBot essentially grew together with the compliance requirements of the industry.
What was AMLBot like when you started, and what is it like now, in numbers: clients, team, markets?
Back in 2019, we were a small team with one core idea: make AML screening simple enough that practically any crypto business could use it.
Today, AMLBot has more than 60 global team members, including expert compliance officers, analysts, customer service and onboarding teams, and certified investigators. Our platform is used by more than 1,000 businesses across 25 jurisdictions.
We have also expanded from wallet screening into transaction monitoring, KYC/KYB, blockchain investigations, asset recovery and AI-assisted tracing. It’s a complete AML services suite in one product.
For me, though, the biggest change isn’t simply the numbers. In 2019 we were giving people a way to check an address. Today, our infrastructure is involved throughout the compliance lifecycle — from preventing suspicious funds from entering a platform to investigating where stolen assets went after an incident.
Small business: the same risks, but far fewer resources
Most compliance companies grow by targeting the largest exchanges. At what point did you decide that AMLBot would build a product for small and medium-sized businesses?
It wasn’t really one moment when we decided, “Now we’re going after small and medium-sized businesses.” It came from listening to customers and seeing the same pain points repeatedly.
If you ask our client success team what they hear from medium-sized crypto businesses, the frustrations are remarkably consistent. They know they need serious AML infrastructure, but many existing solutions were built around the budgets, compliance teams and technical resources of major exchanges. They can be expensive to implement, complicated to integrate, and often require considerable compliance expertise to operate effectively.
At the same time, smaller companies are dealing with increasingly complex risks. They still have to screen wallets, understand indirect exposure, monitor transactions and investigate suspicious activity — but they may have only one or two people handling compliance rather than several specialized teams.
We wanted AMLBot to give a growing exchange, payment provider, OTC desk or other crypto business access to sophisticated blockchain analytics without requiring an enterprise-sized compliance department.
So we started designing around the problems those customers were actually bringing to us: faster integration, understandable risk data, automation that reduces manual work, flexible pricing and the ability to scale the compliance stack as the company grows.
For me, democratizing access to blockchain analytics has always been part of AMLBot’s DNA. Compliance shouldn’t become effective only once a company is large enough to afford it.
There was an assumption in the market that sophisticated compliance had to be enterprise software: expensive contracts, long integrations and specialist teams operating it. But regulation doesn’t really care whether you have 20 employees or 20,000. If you’re handling customer assets, you still have responsibilities around sanctions, money laundering and suspicious transactions.
So our philosophy became: the technology should scale with the business. A small company might begin with individual wallet checks and later move into API screening and continuous transaction monitoring without having to rebuild its entire compliance stack.
Budget aside, how do compliance processes for smaller companies differ from those of large exchanges?
The biggest difference is usually not the risks they face; it is the resources available to respond to those risks.
A major exchange can have separate teams for sanctions, transaction monitoring, investigations, regulatory reporting and law-enforcement requests. At a small or medium-sized company, several of those responsibilities may sit with one compliance officer.
That means automation and prioritization become much more important. You cannot ask a three-person compliance team to manually investigate every alert.
The system has to explain why something is risky, distinguish signals that require immediate escalation from lower-risk exposure, and give the compliance officer enough context to make a defensible decision.
In some ways, smaller companies need good compliance technology even more because they have much less human capacity to compensate for inefficient tooling.
Compliance as a Continuous Process
Which regulatory requirement is currently the hardest for small crypto companies to meet, including under MiCA?
I would start by reinforcing the previous point: compliance is much more complex than the average founder may initially imagine. And for any new crypto business, regardless of its size, building the right compliance infrastructure from the beginning can be a significant operational burden.
The difficult part is not necessarily one isolated regulatory requirement; it is building a continuous compliance process around every transaction.
If we take the EU as an example, crypto-asset service providers have to manage multiple layers of compliance — from AML risk assessment and transaction monitoring to sanctions screening, customer due diligence and the Travel Rule. The Travel Rule, in particular, can create operational challenges because information about the originator and beneficiary needs to accompany crypto-asset transfers, while companies also need procedures for handling cases where that information is incomplete or missing.
For a large institution, you can assign dedicated people, technology and infrastructure to each layer. For a startup or smaller crypto company, many of these responsibilities may fall on a very small compliance team while the company is simultaneously trying to build and grow the business.
That is why integration and automation matter so much. KYC, KYT, sanctions screening and Travel Rule processes cannot operate as completely separate islands. The challenge for smaller companies is building a compliance framework that meets regulatory expectations without creating an operational burden that prevents the business from scaling.
How Investigations Shape Risk-Scoring Systems
AMLBot has both a compliance product and an investigations team. How does what your investigators see in real cases shape the risk scoring your clients rely on?
The two sides feed each other daily. Our investigators trace stolen funds hop by hop until they reach a service, and every perpetrator wallet, laundering intermediary and cash-out point they confirm goes into the same database that powers the scoring our clients use.
That is a very different quality of signal than scraping public lists: it is attribution verified by a human on a live case, often before the incident is public at all.
It also works in reverse. When a client’s screening blocks an address, the Investigations team can tell them who reported it and what stage the case is at — a police report, a freeze request, a court order — so ‘high risk’ stops being an abstract label and becomes an actionable one.
And what investigators see in the field, such as new bridge routes or fresh-address splitting patterns, is what we prioritise in the risk model next.
AI Speeds Up Processes but Does Not Replace Investigators
AMLBot is developing its investigations arm with the AI-powered Tracer tool. How exactly do AI technologies speed up money laundering investigations?
The biggest advantage of AI is reducing the amount of repetitive analytical work an investigator has to do.
Imagine stolen funds are moved from one wallet into ten addresses, some of those addresses interact with bridges, the assets change chains and then split again. Manually reconstructing that flow can mean following hundreds of transactions and constantly deciding which branch is relevant.
AI can help automate that first layer of investigation: following visible fund flows, identifying relationships between wallets, recognizing laundering patterns, mapping cross-chain movements and surfacing likely destinations.
Another important application is semi-automated labeling and blockchain attribution. Similar algorithms can analyze transaction patterns and relationships between addresses to help investigators identify clusters of wallets that may belong to the same entity or service. Instead of manually examining every address from scratch, investigators can use these signals to prioritize connections that warrant deeper analysis and verification.
With AI Tracer, for example, a user can start with a transaction ID and the system can map the visible movement of those funds across supported wallets, bridges, exchanges and blockchains, producing a visual investigation trail.
But AI doesn’t eliminate investigators — and attribution still requires verification. What AI changes is where investigators spend their time. Instead of spending hours reconstructing basic transaction paths or manually examining thousands of addresses, they can focus on validating attribution, building evidence, coordinating with exchanges and law enforcement, and making the decisions that actually require human judgment.
Bybit, Lazarus, and the Gap Between Analysis and Platform Response
AMLBot’s investigations arm is involved in the biggest active crypto investigation of the past year (Bybit/Lazarus). What exactly does your team do in this process?
We are one of the contributors to Bybit’s LazarusBounty programme, working alongside their blockchain risk control team. In practice, our job is unglamorous and fast: track the stolen assets as they move through bridges, swaps and mixers.
We identify the moment a portion lands at a service that can actually act — an exchange, an OTC desk, a stablecoin issuer — and get an evidence-ready request to that counterparty’s compliance team quickly enough for a freeze to happen.
Speed decides everything here; Lazarus moves funds in minutes and a freeze window can be hours.
We also share the confirmed addresses with the wider ecosystem so that smaller platforms can block them proactively. Bybit publishes the overall numbers, and one year on the honest picture is that the majority of funds remain traceable but only a small share is frozen — which tells you the bottleneck is not tracing, it is response time across the industry.
The fastest laundering cycles now take minutes. Can AI close this gap, or is the real bottleneck how quickly exchanges and law enforcement respond?
AI can dramatically reduce the detection gap, but detection is only half of the problem.
What has changed recently is that AI is becoming available to both sides. The growing availability of AI coding tools and autonomous agents — including tools such as Claude Code — can lower the barrier to automating increasingly sophisticated activity. We are seeing the threat landscape accelerate, and defenders cannot realistically respond to machine-speed threats with predominantly manual processes.
The only feasible technological moat is to use AI for protection as well.
AI can identify suspicious fund movements, follow complex transaction paths and surface potential destinations much faster than an investigator working manually. But an analytics company cannot simply freeze someone else’s wallet. Once funds reach a centralized service, there are compliance procedures, evidence requirements, jurisdictional questions and, in some cases, law-enforcement processes before action can be taken.
So the next challenge is connecting machine-speed detection with machine-speed — or as close as possible to it — response. If an AI system identifies a suspicious flow in minutes but actionable intelligence takes a day to reach the right exchange, criminals still have an enormous advantage.
The future of blockchain security therefore isn’t just faster analytics. It is AI-powered detection combined with much faster coordination between analytics providers, exchanges, stablecoin issuers and law enforcement. If attackers are increasingly using automation, the defensive infrastructure has to operate at comparable speed.
How Not to Become an “Accidental Gateway” for Dirty Funds
Lazarus and other sophisticated groups keep changing their mixing and transaction obfuscation patterns. What should compliance officers at smaller platforms prepare for today to avoid becoming an accidental gateway for “dirty” funds?
Assume the funds will come to you, because they do: state-sponsored groups deliberately route through platforms with small or no compliance teams, and they arrive already split across hundreds of fresh addresses so that no single deposit looks alarming. Three practical things.
First, screen the counterparty address, not just the transaction — by the time funds have moved once, the risk sits in the wallet history.
Second, use a blocklist that updates in near real time from active investigations, not a monthly list; a Lazarus laundering cycle is finished before a monthly update lands.
Third, know in advance what to do when you get a hit: who can pause a withdrawal, who you call, and who supplies the case context so you can justify the hold.
The platforms that become ‘accidental gateways’ are rarely the ones without tools — they are the ones without a decision procedure.
Сообщение From AML Screening to Lazarus Investigations: Interview with AMLBot CEO Viacheslav Demchuk появились сначала на INCRYPTED.
Source: Incrypted


