An exchange inside an exchange: how nested services moved $8 billion past the checks?

An exchange inside an exchange: how nested services moved $8 billion past the checks?

Over eight years, around $8 billion in transactions linked to nested services passed through 39 cryptocurrency exchanges, with 87.4% of that volume falling on a single platform.

Aug 21, 2026

A compliance program can pass all checks and audits and still contain a risk it is simply unable to see. This is exactly the conclusion the analysis of nested services leads to — third-party platforms that operate through accounts on regulated cryptocurrency exchanges, effectively using their reputation and regulatory compliance while serving their own clients, whom the exchange itself has never verified or onboarded.

Over the past eight years, around $8 billion in turnover linked to nested services has been identified. These transactions passed through a large number of different organizations: in total, 2,275,270 transactions and 39 exchanges on whose accounts such operations were carried out were recorded. Among these organizations there are perfectly legal instant crypto exchange services, but there are also sanctioned platforms as well as Iranian payment processors. From the point of view of the exchange where the accounts are held, their transactions can look almost identical. This is precisely the core problem for any virtual asset service provider: ordinary exchange-level monitoring was never designed to distinguish such flows.

What a nested service is and why ordinary monitoring doesn't see it

A nested service is a cryptocurrency exchange, broker, over-the-counter (OTC) exchange service or payment processor that operates on top of a larger exchange's infrastructure, using its accounts instead of creating its own blockchain infrastructure. Such an operator gains access to the large platform's liquidity, its payment rails and its regulatory infrastructure, and then uses them to serve its own clients. Meanwhile, the large exchange itself may not know who these clients are at all.

This is exactly where the transaction attribution problem arises, which lies at the heart of nested-service risk. On the blockchain, every transaction initiated by a nested operator is ultimately linked to the crypto wallet addresses belonging to the large exchange. Any tool that determines a transaction's source solely from the blockchain may therefore interpret such activity as the exchange's own. A transfer that looks like an ordinary deposit from a licensed exchange may in fact have started at an exchange point without KYC procedures in Lebanon, or at a broker in Iran that routes funds through the large platform's deposit addresses.

The result is a structural «blind spot». If a compliance team considers a transaction from a known licensed counterparty to be low-risk, it may have no mechanism to see that the real source of the funds was a nested operator from a higher-risk jurisdiction that has no regulated presence of its own. Under the requirements of the Travel Rule and European MiCA regulation, this gap can no longer be regarded as a purely theoretical problem. It becomes a regulatory obligation that cannot be fully met without looking one level deeper.

How concentrated is this risk?

The volume of nested-service operations is distributed extremely unevenly. A single large international exchange alone handled $6.97 billion, or 87.4% of the entire identified volume of such operations.

This picture is consistent with the assumption that nested operators choose platforms not simply because they are the largest by trading volume. They are drawn by deep liquidity, a wide selection of supported tokens, and client-onboarding procedures that are assumed to let their operations pass the checks. For any virtual asset service provider (VASP), the key takeaway here is this: the very characteristics that help an exchange grow and attract legitimate clients — scale and accessibility — simultaneously attract operators seeking to dissolve into the general flow of transactions.

Concentration is also observed at the level of individual organizations. Two nested services, designated NS-01 and NS-02, both of which are legal, together account for $5.48 billion, or 68.8% of the entire identified volume. Even this scale of legitimate nested-service activity means that the exchange must be able to distinguish their operations from those of its own clients. The same «blind spot» that allows a legal exchange service to go unnoticed can simultaneously conceal a sanctioned organization.

What is actually hidden inside nested-service flows?

The risks associated with nested services span the entire spectrum of possible scenarios, and three conclusions are especially important for any cryptocurrency exchange.

Second, operations from higher-risk jurisdictions can concentrate on a small number of receiving platforms. Nested services linked to Iran account for a combined volume of around $239M across 17 different organizations. The bulk of this flow passes through one exchange (which accounts for roughly $103M, or 43% of this entire cluster). The largest volume falls on NS-05 — $55.8M, followed by NS-06 with $39.1M. This exchange does not appear on the main lists of sanctioned exchanges, yet its role as a preferred platform for Iranian payment processors creates an obvious risk in terms of OFAC's requirements.

How do nested operators look on the blockchain?

The nature of the tokens used and wallet behavior give exchanges concrete signs by which such operations can be tracked. Bitcoin accounts for 39.2% of nested-operation volume — around $3.13 billion. This corresponds to high-value but relatively rare transfers typical of over-the-counter trading platforms and brokers working with large volumes.

USDT comes next by volume — 25.9%, or $2.06 billion. At the same time, the number of transactions with it is significantly higher. This picture is consistent with the use of USDT on the Tron network for low-cost, high-frequency cross-border payments.

This difference alone can serve as a signal for detecting a nested service. A nested OTC desk and a nested retail payment processor leave different characteristic traces on the blockchain: the former shows large amounts and a small number of transactions, the latter, conversely, more frequent operations of smaller size. The common behavioral sign linking these different types of operators is a large volume of funds passing through a single account, stable connections with certain counterparties, and sequences of intermediate wallets. These are exactly the characteristics that entity-level monitoring makes it possible to detect.

What should virtual asset service providers do?

The main conclusion of the analysis is fairly straightforward: checks at the exchange level itself cannot reliably detect nested operators, so receiving platforms need to implement detection mechanisms directly at the level of individual organizations. For VASPs that want to both protect their compliance status and continue growing their business, three areas are especially important.

First of all, a separate nested-service detection program needs to be created. For this, one should use blockchain analytics that can not only analyze blockchain transactions but also verify direct interactions with a potential operator and establish a link to the specific organization. Direct interaction means that analysts conduct a transaction with the suspected service and then track where the funds actually go. This is exactly the approach that makes it possible to confirm the existence of a nested link rather than merely assume it on the basis of indirect signs.

In addition, enhanced customer due diligence must be applied to accounts with signs of a nested service. Large operation volumes with a small number of transactions, stable connections with the same counterparties, and sequences of intermediate wallets are the signs around which it makes sense to automate alerts. Early detection of such patterns makes it possible to quickly assess potential risk without creating unnecessary friction for ordinary clients.

Finally, mandatory disclosure must be established. Accounts used as nested services are required to self-report the nature of their activity and provide information about the KYC procedures of their own clients. Otherwise, cooperation with them must be terminated. A formal rule of this kind turns invisible risk into risk that is controllable and manageable.

The problem becomes even more serious in the case of operators working through several platforms at once. Some organizations simultaneously use accounts on several cryptocurrency exchanges, so no single platform has the full picture of their activity. This is exactly why fully understanding a nested operator's activity requires visibility across different exchanges, provided by a single analytical layer.

#AML#KYC
$8 billion in the shadows: how nested services bypass crypto exchange compliance