Cointime

Download App
iOS & Android

KYC'd Wallet Sales on Dark Net Markets

Validated Project

The sale of cryptocurrency exchange accounts that have passed Know Your Customer (KYC) verification happens across a multitude of platforms, including Telegram and Discord. While one might expect a similar volume of sales to occur on dark web markets, our examination of KYC'd account sales shows this is likely not the case. Our analysis of fraudulent sales of KYC'd accounts across 300 dark web markets shows that just 4% of markets host ads for crypto related KYC services.

Background

Know Your Customer rules are one of the legal requirements that financial services providers must adhere to when selling financial services products to new customers. These regulations require customers to prove their identities – using identification documents and other personal records – so that financial institutions can better assess risk and monitor for all types of financial crimes, including fraud, money laundering, terrorism financing, and identity theft. Depending on the nature of the financial services provided, these rules can require institutions in the US and their international affiliates to:

  • Collect the identities of their customers;
  • Monitor their customers through periodic identity documentation updates;
  • Screen customer transactions;
  • Closely monitor Politically Exposed Persons (PEPs); and
  • Screen their customers against sanctioned entities lists

Those who have used centralized exchanges are most likely familiar with some of these practices. However, the semi-anonymous nature and relative newness of the Web3 ecosystem have made the industry a particularly difficult one for traditional financial regulators to enforce KYC rules on. There are multiple reasons for this, including the fact that many major exchanges operate in jurisdictions with looser financial regulations than the US and the lack of international coordination around regulating these platforms.

The current regulatory environment creates opportunities for bad actors to take advantage of centralized exchanges (CEX) to launder and move funds. One method used to launder funds involves obtaining a fraudulently KYC'd account. You can read more about CertiK’s investigation into over-the-counter KYC sales here. This particular investigation focuses on the sale of fraudulent KYC sales primarily on Telegram, Discord, and other social media sites. However, we also wanted to take a deeper dive into how much of this activity takes place dark web markets.

Dark web markets are often associated with criminal services, including the sale of stolen data, credit card information, malware, hackers-for-hire, drugs, and weapons.

Analyzing KYC Sales on Dark Web Markets

It is important to note here the difficult nature of conducting research on the dark web. Research must be conducted using a special browser known as the Tor browser, or by configuring another web browser like Firefox to access the Tor network. The browser allows one to access website URLs ending with the extension .onion. These URLs change frequently and often are often left inactive when domain owners move a market’s online location for security purposes. This makes finding and maintaining access to dark web markets much complex than on the surface web. A market URL can be working today, and replaced with a scam or non-functional URL tomorrow.

We started with a database of over 300 links to dark web markets and assessed them for sales of KYC’ed accounts. Of the original 300 URLs only 182 were transcribed correctly, meaning they contained the correct number of characters in a .onion address. Of the 182 full addresses, 102 were dead links and 80 were working. Of the remaining working links, only 12 markets had advertisements related to KYC account sales or fraudulent KYC services for other money transfer platforms, such as PayPal.

Graph: Shows the number of links from our dark web market database both live and inactive.

Only 27% percent of the links in this database were live. The number of links that worked for markets where KYC’d accounts or KYC services were being sold were only 4% percent of the total.

Not only were the number of markets hosting KYC'd CEX account advertisements quite small, but the total number of ads on each platform were also minimal. The chart below shows the distribution across all markets where we found vendors selling KYC services.

Graph: The total number of KYC service ads on each market examined in this sample

A Closer Look at KYC Ads

We looked at the ads and vendors on the three most active markets by total number of ads currently listed. This includes Nemesis Market, MGM Grand Market, and the Ares Market, each of which had 10 ads or more. It should be noted that even though these markets had the highest number ads around half of the ads had broken links and appeared to be reposts from the same vendors.

Markets that contained KYC ads vary in their structure but all provide the following basic pieces of information about the vendors providing these services:

  • Vendor Usernames
  • Total Vendor Sales
  • Total Vendor Reviews
  • Vendor Ratings
  • Product Price
  • Product Descriptions
Image: Example advertisement for a Paxful.com KYC’ed account. Source: Ares Market

What also becomes clear when examining these ads is that the vast majority are cross-posts from the same vendors. In our examination of the big three markets mentioned above we identified six vendors with unique usernames, however, the content of these ads suggests there are only four unique actors, two of which use different usernames on different markets. We based this conclusion on the content of these ads being word-for-word exactly the same. Below is is list of these actors and their associated vendor stats for the Nemesis, MGM, and Ares markets.

Image: Actors across dark web markets with live KYC ads do not have many metrics by which to judge their activity

The vendor data we have on these actors does not provide much information for identifying or assessing the efficacy of these vendors' sales. While most vendor scores are ranked quite high out of five, there are not enough sales or reviews to truly assess the impact or overall activity of the vendors. The one exception is vendor mikedoesittoo who has over 100 sales and 37 reviews on Nemesis market. Multiple of these reviews include positive five star ratings specifically for his KYC'ed account sales, making them the most active and effective actor selling KYC’ed accounts.

Conclusion

Overall, the KYC'd CEX account market on the dark web appears to be small and likely statistically irrelevant in terms of its overall contribution to fraud in the cryptocurrency industry.

It it likely that we continue to see this activity predominate on Telegram and Discord, as these channels are already used heavily by individuals and projects in the crypto space. These social platforms are not only more readily accessible than dark web markets, but cryptocurrency enthusiasts as a whole are almost certainly more familiar with navigating these platforms from doing research on projects or connecting with project communities. While this is not to say that finding these types of markets on social media platforms is simple, their ease of use without a doubt creates greater accessibility to both fraud peddlers and enablers in these circumstances.

Read more: https://www.certik.com/resources/blog/3bUwDt2r8azcC7cqddl6rZ-kycd-wallet-sales-on-dark-net-markets

Comments

All Comments

Recommended for you

  • BlackRock BUIDL reaches $375 million, surpassing Franklin Templeton to become the largest tokenized Treasury fund

    CoinDesk, on-chain data shows that BlackRock's BUIDL fund grew by $70 million last week, bringing its total size to $375 million, surpassing Franklin Templeton to become the largest tokenized government bond fund.

  • Backed raises $9.5 million in funding round led by Gnosis for tokenization of real-world assets

    Backed, a Switzerland-based tokenized asset issuer, has raised $9.5 million in a funding round led by Gnosis. The company aims to speed up its private tokenization offering and onboard asset managers to blockchain rails with the investment. Tokenization of real-world assets is becoming increasingly popular, with the market for RWAs predicted to reach $10 trillion by the end of the decade. Backed has already issued over $50 million worth of tokenized RWAs, including ERC-20 compatible token versions of exchange-traded funds and individual stocks like Coinbase and Tesla.

  • London-based X10 raises $6.5M to expand hybrid crypto exchange operations

    London-based hybrid crypto exchange company X10 has raised $6.5m in funding from investors including Tioga Capital, Semantic Ventures, Cherry Ventures, Starkware, and Cyber fund, as well as executives from Revolut and the founder of Lido, Konstantin Lomashuk. The funds will be used to expand operations and development efforts. X10 offers a hybrid model that combines the centralized exchange experience with the benefits of DeFi, including on-chain trade settlement, validation, and self-custody. The exchange also provides a customizable web interface, advanced market and portfolio analytics, and premier on- and off-ramping options provided through trusted global partners.

  • Hong Kong Monetary Authority: Crypto assets (especially stablecoins) are one of the key work priorities in 2024

    Hong Kong Monetary Authority (HKMA) official website released the "2023 Annual Report", which includes the financial statements of foreign exchange funds and its "2023 Sustainable Development Report". The 2024 work focus and outlook section of the annual report includes encrypted assets (especially stablecoins), and the HKMA pointed out that public consultations on regulating stablecoin issuers will be conducted from December 2023 to February 2024. The HKMA will work with the government to promote relevant legislative work and will continue to communicate with different stakeholders in formulating and implementing relevant regulatory regimes, as well as paying attention to market developments and relevant international discussions. At the same time, the HKMA will implement a stablecoin "sandbox" arrangement to promote exchanges of views with the industry on proposed regulatory regimes and requirements, and to enhance the stability, cryptographic assets, and financial innovation of non-bank financial intermediaries. The HKMA will focus on virtual asset-related products and will refer to the latest market developments and revisions to international standards in the relevant processes. To promote sustainable and responsible development of the virtual asset industry, the HKMA will continue to work with the government and other regulatory agencies to ensure the establishment of a robust, comprehensive, and balanced regulatory framework for the virtual asset industry.

  • BONKKILLER is a Pixiu scam, and has withdrawn more than 3,000 SOL liquidity

    SolanaFloor disclosed on X platform that Meme coin BONKKILLER on Solana chain is a honeypot scam, and after freezing the token sales of users, the project party has withdrawn liquidity of over 3000 SOL.

  • Crypto accounting firm H&T completes $10 million in financing

    Harris and Trotter Digital Assets (H&T), a crypto accounting firm that provides comprehensive services to approximately 500 native cryptocurrency clients, has completed a $10 million financing round with Orbs leading and Re7 Capital and Kingsway Capital participating.

  • Liquid staking protocol MilkyWay raises $5 million in funding

    The mobile pledge agreement MilkyWay raised $5 million in seed round financing led by Binance Labs and Polychain Capital. Other investors in this round of financing include Hack VC, Crypto.com Capital, and LongHash Ventures.

  • The Goldilocks consensus problem

    Imagine that you wanted to build a sufficiently decentralized Twitter — a social network in which no single person or company is in control. How would you build something like that?

  • LayerZero Ecosystem Full-Chain NFT Protocol Holograph Completes $3 Million New Round of Financing

    LayerZero's full-chain NFT protocol Holograph has announced the completion of a new strategic financing round of $3 million, led by Mechanism Capital and Selini Capital, with participation from Northrock Capital, Arca, Courtside Ventures, and Hartmann Capital from Hal Press. The total amount of financing for the project has reached $11 million. Holograph's full-chain technology allows for the creation of NFT assets that can be used on multiple Ethereum-compatible blockchains. The new funds aim to accelerate its expansion into the growing blockchain gaming market, with a focus on supporting Ethereum-compatible network tokens, including Optimism, Arbitrum, Avalanche, BNB Chain, Base, Mantle, Zora, and Linea.