The compliance regime has become the breach surface
Cryptomus, Sumsub, IDMerit, the alleged Kraken admin leak, the Zcash Orchard bug. Five 2026 incidents that share one structural lesson: centralized vendor architectures fail catastrophically and were predicted to do so.
The Editors
Editorial desk
The compliance regime has become the breach surface
In 2026, the regulated, audited, fully licensed path through which a crypto user proves they are a person now routinely produces datasets the criminal market could not have assembled on its own, at any price, through any amount of phishing or insider recruitment. That is the structural fact this essay is built around. The Know Your Customer apparatus, sold to legislators and to the public as a fraud-prevention regime, has in its current architecture become the largest single contributor to identity-theft inventory in the history of the consumer internet, and the reason is not malice on the part of any specific vendor but the simple geometry of concentration: a small number of specialized providers now sit in front of the verified identity records of an enormous fraction of the world's crypto users, and when any one of them is breached, the loss is denominated in hundreds of millions of records at a time. The argument here is not that anti-money-laundering rules are wrong in principle. The argument is that the specific institutional form those rules have taken, the form that funnels every onboarding flow through a handful of vendors, has produced a foreseeable, predicted, and now realized single point of failure, and that 2026 is the year the bill came due.
Five incidents, in order
- Cryptomus, October 16, 2025. FINTRAC, the Canadian financial intelligence regulator, levied a $176 million penalty against Xeltox Enterprises, operator of the Cryptomus payment processor, for what Krebs on Security reported as a sweeping failure to file suspicious activity reports on transactions that researchers had repeatedly tied to ransomware affiliates and stolen-credential markets. The vector here is not a data breach in the technical sense. It is the inverse: a regulated chokepoint that failed to chokepoint anything. Same structural problem, opposite symptom. We covered the fine in detail in [our Cryptomus piece](/articles/cryptomus-vancouver-shell).
- Sumsub, early 2026. The compliance vendor whose client list reportedly includes Bitget, Bitpanda, Bybit, Huobi, and Wirex was the subject of a breach disclosure that, depending on which exchange's user base estimate you trust, touched the verified identity records of somewhere between fifteen and forty million traders. The damage is hard to scope precisely because each downstream exchange has incentives to minimize, and Sumsub itself has incentives to scope-narrow, but the central fact is that a single vendor compromise cascaded across five major venues at once.
- IDMerit, disclosed February 18, 2026. One billion records, twenty-six countries, full legal names cross-referenced against national identity numbers, telecom metadata, and the AML decision logs that record why each customer was approved or flagged. Bright Defense's incident report and the Cybernews follow-up established that the exposed corpus included not only the personally identifying inputs but the structured AML scores that downstream institutions had relied on, which means the leak is doubly weaponizable: criminals get the identity, and they also get the compliance answer the identity will produce. Our [IDMerit deep dive](/articles/idmerit-billion-kyc-sim-swap) walks through the records schema.
- Alleged Kraken administrative leak, March 2026. TorNews reported that a dark-web seller was offering read-only administrative access to user profiles, full transaction history, support ticket archives, and uploaded KYC documents from a major exchange identified in the listing as Kraken. The exchange has not confirmed the report and we treat it as alleged. We include it here because, confirmed or not, the listing is consistent with the pattern: the highest-value criminal market product of 2026 is no longer credit-card dumps, it is exchange-grade verified identity bundles.
- Zcash Orchard consensus bug, May 29, 2026. A different domain, a different failure mode, and arguably a different essay, but the lesson rhymes. The Orchard pool, a privacy primitive depended on by a non-trivial fraction of the privacy-coin economy, shipped with a bug that survived multiple audits because the population of cryptographers qualified to review zk-SNARK circuit code is small and the audit market for that population is thin. Critical primitives that depend on a small number of qualified eyes fail in the same structural way that critical compliance infrastructure depending on a small number of qualified vendors fails. We discussed the Orchard incident in our [primitive-audit piece](/articles/zcash-orchard-4-years-undetected).
Why specialization compounds the risk
The standard defense of the current architecture runs as follows: specialized vendors do compliance better than each exchange could do it in-house, therefore consolidating onboarding through specialists improves average outcome quality. This is, in the narrow technical sense of false-positive rates and decision latency, probably true. It is also irrelevant to the question that actually matters, which is the tail risk of a single vendor compromise. Specialization improves the mean and degrades the tail simultaneously, and a regulator looking only at mean compliance quality will reward exactly the consolidation that produces the worst tail outcomes. The FATF's 2025 update on virtual asset service providers, in its guidance language around "consistent application" of customer due diligence, actively recommends the kind of vendor-led standardization that produces this concentration. MiCA in the European Union, the Transfer of Funds Regulation, and the United States' GENIUS Act all push, by design and by exemption structure, toward a small number of approved compliance counterparties. The regime is not accidentally centralized. It is centralized because the cheapest path to demonstrable regulatory compliance is to outsource to a vendor the regulator has already implicitly blessed.
The historical record was already on the wall
The etheralpha/kycisbad repository has, since 2019, maintained a public ledger of KYC-related leaks and breaches. The pre-2025 entries alone document well over a dozen incidents at exchanges, custodians, and dedicated identity vendors, ranging from the BitMEX email leak in 2019 through the Celsius creditor list in 2022 and the Gemini support-vendor incident in 2024. The pattern visible across those years is not that any one provider was uniquely careless. It is that the surface area defined by "places where a verified identity record is at rest" grows monotonically every quarter, and the probability that none of those places is compromised in any given twelve-month window is now effectively zero. The 2026 incidents are not a novel category of failure. They are the predicted continuation of a multi-year trend that the regulatory architecture has steadily made worse.
What the compliance theatre actually costs
Run the accounting honestly. The IDMerit corpus alone, priced at the going dark-web rate for verified-identity records with associated AML metadata, is worth more on the criminal market than any single ransomware operation grossed in all of 2025. That is one breach. Set against that loss the marginal AML benefit, measured as the incremental volume of illicit funds detected at the KYC-vendor layer rather than at the exchange transaction-monitoring layer, and the trade looks, in plain numbers, catastrophic. The honest framing is that the regime imposes a near-certain industrial-scale identity-theft uplift on the user base in exchange for a marginal improvement in AML signal that the same exchanges could have produced from on-chain analytics without ever assembling the off-chain identity corpus at all.
What this changes for the Directory
We are taking three editorial steps in response. First, we are publishing, as an ongoing project, the KYC-provider-by-exchange listing map, so that a user evaluating an exchange can see which compliance vendor will end up holding their documents and can make the obvious risk decision for themselves. Second, we are elevating in our ranking system those venues that route identity through user-held keys, proof-of-personhood schemes, or zero-knowledge attestations, on the explicit grounds that decentralizing the storage layer of identity is now a first-order safety property and not a niche cryptographic preference. Third, and this is the editorial position the Directory will hold in print until the evidence changes, we argue that the policy answer is not the abandonment of AML obligations but the dismantling of the centralized vendor architecture those obligations have produced. The regulator's question should stop being "did the exchange verify the user" and start being "did the exchange verify the user without producing a copy of the user's identity that an attacker can steal." Those are different questions, and only one of them has a defensible answer in 2026.
Sources
- Krebs on Security, Canada Fines Cybercrime-Friendly Cryptomus $176M (October 2025)
- Cybernews, Global data leak exposes billion records (February 2026)
- Bright Defense, IDMerit data breach analysis
- TorNews, Kraken admin internal access leaked on dark web
- etheralpha/kycisbad, historical record of KYC leaks
- FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs, 2025 revision.
- NoKYC Directory, [Cryptomus FINTRAC sanctions](/articles/cryptomus-vancouver-shell)
- NoKYC Directory, [IDMerit: one billion records and what they actually contained](/articles/idmerit-billion-kyc-sim-swap)
Edit log
- 2026-04-22 : Pulled the etheralpha/kycisbad repository, took notes on the pre-2025 incidents to establish the long pattern.
- 2026-05-04 : Cross-referenced the Sumsub client list against the Bitget, Bybit, and Huobi user count estimates from CoinGecko to scope the cascade size.
- 2026-05-17 : Read the FATF 2025 update on virtual asset service providers, took notes on the centralization recommendation language for the structural mechanism section.
- 2026-05-28 : Drafted the "compliance theatre" section, cut three paragraphs that veered into polemic and rewrote with strict sourcing against the IDMerit and Cryptomus filings.
- 2026-06-04 : Final pass, removed em-dashes throughout, added internal cross-links to articles #2 and #3, tightened the verdict paragraph into a three-step editorial commitment.
Browse the directory
Find a no-KYC service for what you need.
More articles
Investigation
A wallet that does not collect identity, paired with a Swiss IBAN that legally cannot exist without it
OffChain just announced a Swiss IBAN linked to its no-KYC mesh wallet, EUR/CHF/USD conversion on demand, a debit card, and SEPA/SWIFT in both directions, all of it "fully offline". We walk through the four ways this can actually work, and the one Swiss law makes hardest.
Read article
Regulation
The comment window closes at midnight, and every US-licensed stablecoin issuer is now on the clock
FinCEN and OFAC's joint proposed rule on Permitted Payment Stablecoin Issuers under the GENIUS Act closes its public comment docket today, June 9 2026. Five obligations, USDC and PYUSD in scope, and what it means for self-custody on-ramps.
Read article
Profile
The story that changed when the honeypots leaked
A 2026 working threat model for an investigative reporter covering crypto cybercrime, after the IDMerit, Sumsub, and Chen Zhi cases reshaped what an organized criminal adversary can buy. Tools, walkthrough, twenty-four hours over her shoulder.
Read article