Transaction Monitoring Analyst, Bitfinex
Homework for the role: what the group actually is, which flows its product surface creates, and a working alert console built on live chain data and the real OFAC list.
Bitfinex is licensed where it chose to be licensed and closed where it chose not to be. That puts more weight on what the monitoring desk catches, because there is no supervisor's checklist standing in for judgement.
The product surface writes the typologies. A peer-to-peer funding book, tokenised securities and a stablecoin issuer in the same group each create flows a generic exchange rule set does not look at. Section ★.
A working triage console: live Ethereum transfers, 1,059 real SDN addresses, live issuer-blacklist reads, eleven scenarios, a tuning panel that shows what each control removes. Try it ↗
Bitfinex in context
Three facts shape the monitoring job here: the group owns a stablecoin issuer, the platform is licensed in one jurisdiction and restricted in others, and the enforcement record is old rather than open.
| Layer | What it is | Why the TM desk cares |
|---|---|---|
| iFinex Inc. | Parent of the Bitfinex Group. The platform is operated by iFinex and its subsidiaries BFXNA Inc. and BFXWW Inc. | The operating entity decides which rulebook a file is built against. |
| Tether | Tether Limited sits under Tether Holdings El Salvador S.A. de C.V. Tether and the Bitfinex Group share management, personnel and a number of common shareholders. | The largest asset on the platform is issued by a related party that can freeze it on chain. That is a control most exchanges do not have and a conflict most exchanges do not have to manage. |
| Bitfinex Securities | First international platform licensed under El Salvador's Digital Assets Issuance Law, April 2023. Tokenised bonds and equity. | Securities flows carry investor eligibility and transfer restrictions on top of AML. |
| Bitfinex Derivatives | Digital Asset Service Provider licence, January 2025. | Perpetuals and leverage change what a normal deposit-to-trade ratio looks like. |
| Bitfinex (spot) | DASP licence from El Salvador's CNAD, May 2026, completing coverage across spot, derivatives and securities. | Supervision now exists in one place, with reporting obligations attached. |
| Market access | US persons are blocked from opening or funding accounts. No MiCA authorisation in the EEA. Availability claimed across 180+ countries. | Geography controls and IP or KYC mismatch handling are a live control. |
- Feb 2021, NYAG. $18.5M settlement with Bitfinex and Tether over the disclosure of the $850M held at a payment processor, plus quarterly reserve reporting for two years.
- Oct 2021, CFTC. $42.5M across Tether and iFinex, $1.5M of it Bitfinex, partly for violating a prior 2016 order.
- Read. Both are disclosure and reserve matters from the 2016 to 2018 period. Neither is an open AML monitorship of the kind OKX and Binance are currently carrying.
- 119,754 BTC taken in August 2016. About 95,000 BTC recovered by the DOJ in February 2022.
- Lichtenstein and Morgan pleaded guilty and were sentenced in November 2024. Prosecutors moved in January 2025 for in-kind return of the recovered coin to Bitfinex.
- Lichtenstein was released early in January 2026 under the First Step Act.
- Read. The laundering attempt in that case is the syllabus for this job: chain hopping, darknet market deposits, structured cash-outs through accounts opened with fake identity documents.
Bitfinex has run Chainalysis KYT for real-time transaction screening since December 2019. Alongside it, Tether co-founded the T3 Financial Crime Unit with TRON and TRM Labs in 2024. T3 passed $450M frozen by May 2026 across 23 jurisdictions, including roughly $344.2M in USDt linked to the Central Bank of Iran in April 2026, coordinated with OFAC. A monitoring analyst here sits next to a freeze capability that most exchange analysts can only refer out to.
The compliance map
Every large venue now runs transaction monitoring. What differs is who the desk answers to, and that changes how an alert is worked.
| Venue | Regulatory anchor | What the TM desk answers to | Gap against Bitfinex |
|---|---|---|---|
| Bitfinex | El Salvador CNAD across spot, derivatives and securities. US persons blocked. No MiCA authorisation. | Internal policy and the CNAD regime, with a related-party stablecoin issuer able to freeze on chain. | Reference point. |
| Coinbase | US public company, state money transmitter licences, NYDFS BitLicense, MiCA through Ireland. | A named supervisor with examination powers and a published expectation of the programme. | Far heavier reporting load. Far less freedom over which markets to leave. |
| Kraken | MiCA authorisation in Ireland, US state licences, a settled SEC history. | EU and US supervisors in parallel. | Same dual-supervision load. Similar product breadth including derivatives. |
| Binance | Nov 2023 DOJ and FinCEN resolution, $4.3B, with monitorships attached. The FinCEN monitor was still in place through 2026 and its status is being questioned in Congress. | An external monitor sampling the files. | Alerts are worked to a third party's standard, not the desk's own. Bitfinex does not carry that. |
| OKX | Feb 2025 SDNY guilty plea by Aux Cayes FinTech, roughly $505M, external compliance consultant retained through Feb 2027. | The consultant's sampling universe. | Same shape as Binance. A remediation programme rather than a steady-state one. |
| Bybit | MiCA authorisation via Austria, plus EEA passporting. | An EU supervisor, following the Feb 2025 theft of about $1.46B by DPRK-linked actors. | That theft became everyone's monitoring problem. The proceeds reached other venues, which is what one-hop screening is for. |
What it means for the role. Where a monitor or a consultant is in place, the standard is set outside the desk and the incentive is to document to that standard. Bitfinex sets its own standard against the CNAD regime. Both need the same thing from an analyst: a file that survives someone else pulling it a year later. The difference is that here nobody else is enforcing that habit, so it has to come from the desk.
The flows Bitfinex actually has
The JD asks for scenarios covering fiat wire and non-wire, and crypto on-chain and off-chain, across trades, deposits and withdrawals. Bitfinex's product surface is wider than a spot exchange, so the scenario set has to be wider too. Each row is a flow the platform really offers and the typology it invites.
| Product surface | The flow | Typology it invites | What the rule has to look at |
|---|---|---|---|
| P2P margin funding | Users at Intermediate verification and above lend into a peer-to-peer funding book that borrowers draw on. | Value moves between two customers with no trade print and no chain transaction. Funding at a rate nobody would accept is a transfer wearing a loan's clothes. | Pair the lender and borrower over time. Rate against the book. Repeat pairings between the same two accounts. Funding taken and immediately withdrawn. |
| Spot and margin trading | Deposit, trade, withdraw, with leverage available. | Deposit-to-withdrawal with minimal trading is the classic exchange pass-through. Wash trading between controlled accounts moves value and manufactures a record. | Trade-to-deposit ratio. Self-crossing. Round-trip time. Withdrawal asset differing from the deposit asset. |
| Derivatives | Perpetuals and leverage under a separate licensed entity. | Mirror positions across two accounts transfer value with a market print on both sides. | Offsetting positions opened and closed together. Loss transfers that repeat. |
| Tokenised securities | Bonds and equity issued under El Salvador's regime, traded on Bitfinex Securities. | Securities bring eligibility rules and transfer restrictions. Subscription and redemption is a different flow from trading. | Source of funds at subscription. Secondary transfers between accounts. Eligibility re-checked at the point of the trade as well as at onboarding. |
| Fiat rails | USD, EUR, GBP and JPY. Manual bank wires from 10,000 up, a third-party provider below that. | The wire minimum is a visible line, so sub-threshold activity concentrates below it. Third-party processors introduce nested payments and a payer who is not the account holder. | Payer name against account name. Repeated amounts under the wire floor. Processor-side counterparties that recur across unrelated accounts. |
| USDt on Tron and Ethereum | The dominant deposit and withdrawal asset. | Tron carries most of the sanctioned USDt address space. The issuer can freeze, which changes what a stale alert costs. | Chain-specific counterparty screening. Re-screen held balances as well as movements. Reconcile against issuer blacklist state. |
| Sub-accounts and API trading | Institutional structures with programmatic access. | Sub-account topology can hide the same beneficial owner behind several alert streams. | Aggregate at the owner level before thresholds are applied. Never alert per sub-account in isolation. |
The funding book. Every exchange has deposits, trades and withdrawals, so every vendor rule set covers them. A peer-to-peer lending market inside the platform is a Bitfinex signature, it is off-chain, and a generic scenario library has nothing pointed at it. That is where I would expect to find an uncovered typology.
Issuer freeze power inside the group means a confirmed case can end with the funds immobilised rather than merely reported. It also means a wrong call has a harder edge. That argues for a high evidentiary bar on the escalation path and a written rationale on every file, which is the habit this console is built around.
JD duties, my method
Each duty in the posting, the method I would bring to it, and where it is demonstrated on this page.
| JD duty | Method | Shown in | Status |
|---|---|---|---|
| Develop and implement transaction monitoring algorithms for ML, TF and sanctions risk on a risk-based approach | Eleven scenarios written from scratch, each with a stated hypothesis, a threshold set, and a severity that reflects how often the shape is innocent. Screening rules are absolute. Behavioural rules are graded. | §04 | built |
| Analyse alerts from fiat (wire and non-wire) and crypto (on-chain and off-chain) trades, deposits and withdrawals | The console runs the on-chain half end to end. The off-chain half is covered by design in the flow table: funding-book pairings, derivative mirrors, sub-account aggregation, payer-name mismatch on fiat. | §★ | designed |
| Escalate real-time urgent alerts according to risk appetite | Severity decides the path, not the score. Any sanctions or issuer-freeze hit is critical and leaves the queue immediately. Behavioural alerts are scored and worked in order. | §06 | built |
| Assist in periodic reports identifying ML, TF and sanctions anomalies for the CCO and product managers | Every alert generates a narrative with trigger, evidence, assessment and recommended action. Roll those up by scenario and disposition and the periodic report writes itself from the case files. | §04 | built |
| Adjust risk parameters to keep exposure inside the platform's risk appetite | Thresholds are controls on a panel, and moving one recomputes the queue live. A benchmark across labelled subjects shows what the change bought and what it cost. | §05 | built |
| Initial assessment of referrals of unusual transaction activity | A fixed triage order: subject-level screening, then counterparty screening, then one-hop exposure, then behaviour. Cheap and decisive checks first. | §06 | built |
| Liaise with AML analysts and users for the information needed to verify ML or TF concerns | The narrative names the gap it needs closed, so the request for information is specific enough to answer in one round. | §06 | built |
| Experience with a blockchain analytics or transaction monitoring tool such as Chainalysis, Elliptic or TRM | I have not held a licensed seat on one. I built the equivalent primitives instead: address screening, entity labelling, counterparty typing, one-hop expansion, exposure scoring. Vendor fluency is a fortnight. The judgement underneath is the part that takes longer. | §04 | honest |
| Source and understand documentation in various languages, types and forms | Native English, Mandarin and Bahasa Malaysia. Chinese-language corporate documents and Malaysian filings read without a translation step, which matters on APAC files. | resume | have |
A working console
Built for this application. It pulls a real address's transfer history from a public block explorer, screens every counterparty against the OFAC SDN digital-currency address list, reads the USDt and USDC contract blacklists live on chain, runs eleven scenarios and produces a case file you can dispose of.
| Code | Scenario | Severity | Hypothesis it tests |
|---|---|---|---|
| TM-00 | Subject-level screening hit | critical | The account address is itself listed, blacklisted by an issuer, or labelled as sanctioned or an exploit. Nothing to adjudicate, so it is handled before any behavioural rule runs. |
| TM-01 | Direct sanctions exposure | critical | A counterparty is on the SDN list. Address-level matching, so there is no fuzzy-name problem and no false match to argue about. |
| TM-02 | Issuer freeze exposure | critical | A counterparty is blacklisted on the USDt or USDC contract. An independent signal from a party that has seen law-enforcement process. |
| TM-03 | One-hop sanctions proximity | high | No direct hit, but a material counterparty has its own listed exposure. The console pulls the top five counterparties and screens them too. |
| TM-04 | Rapid pass-through | high | Value arrives and leaves inside the window with little retained. Bounded above as well as below, because a busy address is not a layering leg. |
| TM-05 | Structuring below threshold | high | Repeated moves under the reporting threshold that aggregate above it. |
| TM-06 | Fan-in consolidation | medium | Many distinct senders funding one address in a short window. |
| TM-07 | Fan-out dispersion | medium | One address paying many distinct recipients quickly. |
| TM-08 | Round-amount repetition | low | Weak on its own. It earns its place only as a corroborator on a subject another rule has already touched. |
| TM-09 | Dormancy then burst | medium | Long inactivity followed by material volume that the account profile did not anticipate. |
| TM-10 | Flagged counterparty label | medium | An external mixer, scam or exploit label. A lead that still needs the flow read underneath it. |
1,059 digital-currency addresses parsed straight from the OFAC SDN XML, publication date 18 September 2026, across 20 asset types. 133 of them are EVM addresses the console can match on chain. Transfers come from the public Blockscout API. Issuer blacklists are an eth_call to the token contracts at screening time.
Each case file carries the trigger, the evidence rows with transaction links, an assessment that names the benign explanation as well as the suspicious one, and a recommended action. The whole queue exports as one case pack with the tuning in force printed at the top, and every case has a shareable link, which is how a reviewer gets handed a file.
The venue-wallet exemption first swallowed SUEX OTC, a sanctioned desk carrying a deposit-address tag naming the exchange it paid into. A control meant to remove noise had silenced the one subject the desk most needs to see. The exemption now yields to any sanctions or risk label on the subject, which is the general rule: a suppression must never outrank a screening hit.
Mine, built for this application, and not connected to Bitfinex. It runs on Ethereum only, samples the most recent transfers rather than paging full history, and has no access to the off-chain side of an exchange. Those limits are stated on the page itself.
Cutting false positives
The application form asks what actually works. Here is my answer, with the console as the working demonstration rather than the claim.
What I would not do. Raise thresholds to make the queue smaller. That reduces alerts and reduces detection by the same mechanism, and it is invisible in the metrics the queue reports. Every suppression in the console names itself and counts itself, so the trade-off stays on the page.
Working the queue
The triage order is fixed, so two analysts reach the same disposition on the same file. Cheap and decisive checks run first.
listed, frozen, labelled
SDN and issuer blacklists
material counterparties only
shape of the flow
does onboarding explain it
written, with a reason
| Disposition | When | What leaves the desk |
|---|---|---|
| Escalate | Any sanctions or issuer-freeze hit, at any value. Also any behavioural case where the account profile cannot explain the flow and the counterparty set is adverse. | Straight to the Manager, Transaction Monitoring, with the record preserved and no tipping off. Prepared for the CCO report. |
| Investigate | Score above the investigation line, or two scenarios on the same subject inside 30 days. | Full history pulled rather than the sampled window, a specific request for information, and a review date. |
| Close with reason | Single low or medium scenario the profile explains. | A written rationale on the file. Closure is a decision that has to survive being read back. |
First 90 days
- Work the live queue daily and hit SLA before trying to improve anything.
- Read the existing scenario inventory against the flow table in §★. Find which product surfaces have no rule pointed at them.
- Learn the escalation boundary between this desk, AML investigations and the reporting seat.
- Start CAMS. I do not hold it and I would rather close that on the company's calendar than mine.
- Sample 90 days of closed alerts by scenario and disposition. Find the scenarios that close at near 100%, which are candidates for tuning rather than removal.
- Check list hygiene: when was the screening list last pulled, and are removals handled as carefully as additions.
- Propose one tuning change, with the expected effect on both detection and volume stated before it goes in.
- Draft one new scenario for an uncovered flow, most likely the funding book, with a hypothesis and a backtest.
- Take a section of the periodic CCO report and standardise how it is produced from case files.
- Write the closure-rationale standard down, so the next analyst inherits it rather than rediscovering it.
Method & sources
Everything here is from public sources, read and checked rather than summarised from memory. The console recomputes its numbers from live data on every load.
- The JD came from a public job posting, 2026. The role duties in §03 are quoted from it.
- The sanctions list was parsed directly from the OFAC SDN XML, not from a third-party mirror, so the publication date and record count are verifiable.
- Chain data is read from the public Blockscout API and a public Ethereum RPC at page load.
- Numbers in §05 come from running the console over its own seed set.
- Ethereum only. Most sanctioned USDt address space is on Tron, which needs a keyed API.
- The sample is the most recent transfers per address, not full history.
- No access to the off-chain half of an exchange: fiat rails, the funding book, sub-account topology. Those are designed in §★ and not demonstrated.
- I have not held a seat on Chainalysis, Elliptic or TRM. Said plainly in §03.
| Claim | Source |
|---|---|
| Bitfinex spot DASP licence, El Salvador, May 2026, completing spot, derivatives and securities coverage | blog.bitfinex.com |
| iFinex operates Bitfinex through BFXNA and BFXWW; Tether Limited under Tether Holdings El Salvador; shared management and common shareholders | Bitfinex, Tether Limited |
| NYAG settlement, February 2021, $18.5M plus quarterly reserve reporting | CoinDesk |
| CFTC order, October 2021, $42.5M across Tether and iFinex | CoinDesk |
| 2016 hack of 119,754 BTC, about 95,000 BTC recovered, in-kind return moved for in January 2025, Lichtenstein released early January 2026 | 2016 Bitfinex hack, CoinDesk |
| Chainalysis KYT deployed at Bitfinex, December 2019 | PR Newswire |
| T3 Financial Crime Unit past $450M frozen, 23 jurisdictions, and the $344.2M Iran-linked freeze in April 2026 | Tether, The Block |
| US persons blocked, fiat in USD, EUR, GBP and JPY, manual wires from 10,000, P2P margin funding at Intermediate verification | Bitfinex support |
| OKX guilty plea, roughly $505M, external consultant through February 2027 | enforcement summary |
| Binance $4.3B resolution and the monitorship status questions raised in April 2026 | US Treasury, The Block |
| Tornado Cash delisted 21 March 2025 following Van Loon v. Treasury | Steptoe |
| MiCA authorisations: Coinbase and Kraken via Ireland, OKX via Malta, Bybit via Austria | CASP tracker |
| OFAC SDN digital-currency addresses, 1,059 records, publication 18 September 2026 | OFAC SDN.XML, parsed for this page |
Independent work by Edward Tay for a job application. Not affiliated with Bitfinex. The console is a prototype built for this application and is not Bitfinex software.