00 · SUMMARY

Transaction Monitoring Analyst, Bitfinex

Homework for the role: what the group actually is, which flows its product surface creates, and a working alert console built on live chain data and the real OFAC list.

SDN crypto addresses
1,059
loaded into the console, OFAC publication 18 Sep 2026
Detection scenarios
11
TM-00 to TM-10, written from scratch
Benchmark
4 / 4
listed seed subjects caught, zero alerts on the legitimate ones
Bitfinex licences, El Salvador
3
securities 2023, derivatives Jan 2025, spot May 2026
THE READ

Bitfinex is licensed where it chose to be licensed and closed where it chose not to be. That puts more weight on what the monitoring desk catches, because there is no supervisor's checklist standing in for judgement.

THE ANGLE

The product surface writes the typologies. A peer-to-peer funding book, tokenised securities and a stablecoin issuer in the same group each create flows a generic exchange rule set does not look at. Section ★.

THE PROOF

A working triage console: live Ethereum transfers, 1,059 real SDN addresses, live issuer-blacklist reads, eleven scenarios, a tuning panel that shows what each control removes. Try it ↗

01

Bitfinex in context

Three facts shape the monitoring job here: the group owns a stablecoin issuer, the platform is licensed in one jurisdiction and restricted in others, and the enforcement record is old rather than open.

LayerWhat it isWhy the TM desk cares
iFinex Inc.Parent of the Bitfinex Group. The platform is operated by iFinex and its subsidiaries BFXNA Inc. and BFXWW Inc.The operating entity decides which rulebook a file is built against.
TetherTether Limited sits under Tether Holdings El Salvador S.A. de C.V. Tether and the Bitfinex Group share management, personnel and a number of common shareholders.The largest asset on the platform is issued by a related party that can freeze it on chain. That is a control most exchanges do not have and a conflict most exchanges do not have to manage.
Bitfinex SecuritiesFirst international platform licensed under El Salvador's Digital Assets Issuance Law, April 2023. Tokenised bonds and equity.Securities flows carry investor eligibility and transfer restrictions on top of AML.
Bitfinex DerivativesDigital Asset Service Provider licence, January 2025.Perpetuals and leverage change what a normal deposit-to-trade ratio looks like.
Bitfinex (spot)DASP licence from El Salvador's CNAD, May 2026, completing coverage across spot, derivatives and securities.Supervision now exists in one place, with reporting obligations attached.
Market accessUS persons are blocked from opening or funding accounts. No MiCA authorisation in the EEA. Availability claimed across 180+ countries.Geography controls and IP or KYC mismatch handling are a live control.
ENFORCEMENT RECORD
  • Feb 2021, NYAG. $18.5M settlement with Bitfinex and Tether over the disclosure of the $850M held at a payment processor, plus quarterly reserve reporting for two years.
  • Oct 2021, CFTC. $42.5M across Tether and iFinex, $1.5M of it Bitfinex, partly for violating a prior 2016 order.
  • Read. Both are disclosure and reserve matters from the 2016 to 2018 period. Neither is an open AML monitorship of the kind OKX and Binance are currently carrying.
THE 2016 HACK, STILL RUNNING
  • 119,754 BTC taken in August 2016. About 95,000 BTC recovered by the DOJ in February 2022.
  • Lichtenstein and Morgan pleaded guilty and were sentenced in November 2024. Prosecutors moved in January 2025 for in-kind return of the recovered coin to Bitfinex.
  • Lichtenstein was released early in January 2026 under the First Step Act.
  • Read. The laundering attempt in that case is the syllabus for this job: chain hopping, darknet market deposits, structured cash-outs through accounts opened with fake identity documents.
THE GROUP'S OWN FINANCIAL-CRIME CAPABILITY

Bitfinex has run Chainalysis KYT for real-time transaction screening since December 2019. Alongside it, Tether co-founded the T3 Financial Crime Unit with TRON and TRM Labs in 2024. T3 passed $450M frozen by May 2026 across 23 jurisdictions, including roughly $344.2M in USDt linked to the Central Bank of Iran in April 2026, coordinated with OFAC. A monitoring analyst here sits next to a freeze capability that most exchange analysts can only refer out to.

02

The compliance map

Every large venue now runs transaction monitoring. What differs is who the desk answers to, and that changes how an alert is worked.

VenueRegulatory anchorWhat the TM desk answers toGap against Bitfinex
BitfinexEl Salvador CNAD across spot, derivatives and securities. US persons blocked. No MiCA authorisation.Internal policy and the CNAD regime, with a related-party stablecoin issuer able to freeze on chain.Reference point.
CoinbaseUS public company, state money transmitter licences, NYDFS BitLicense, MiCA through Ireland.A named supervisor with examination powers and a published expectation of the programme.Far heavier reporting load. Far less freedom over which markets to leave.
KrakenMiCA authorisation in Ireland, US state licences, a settled SEC history.EU and US supervisors in parallel.Same dual-supervision load. Similar product breadth including derivatives.
BinanceNov 2023 DOJ and FinCEN resolution, $4.3B, with monitorships attached. The FinCEN monitor was still in place through 2026 and its status is being questioned in Congress.An external monitor sampling the files.Alerts are worked to a third party's standard, not the desk's own. Bitfinex does not carry that.
OKXFeb 2025 SDNY guilty plea by Aux Cayes FinTech, roughly $505M, external compliance consultant retained through Feb 2027.The consultant's sampling universe.Same shape as Binance. A remediation programme rather than a steady-state one.
BybitMiCA authorisation via Austria, plus EEA passporting.An EU supervisor, following the Feb 2025 theft of about $1.46B by DPRK-linked actors.That theft became everyone's monitoring problem. The proceeds reached other venues, which is what one-hop screening is for.

What it means for the role. Where a monitor or a consultant is in place, the standard is set outside the desk and the incentive is to document to that standard. Bitfinex sets its own standard against the CNAD regime. Both need the same thing from an analyst: a file that survives someone else pulling it a year later. The difference is that here nobody else is enforcing that habit, so it has to come from the desk.

The flows Bitfinex actually has

The JD asks for scenarios covering fiat wire and non-wire, and crypto on-chain and off-chain, across trades, deposits and withdrawals. Bitfinex's product surface is wider than a spot exchange, so the scenario set has to be wider too. Each row is a flow the platform really offers and the typology it invites.

Product surfaceThe flowTypology it invitesWhat the rule has to look at
P2P margin fundingUsers at Intermediate verification and above lend into a peer-to-peer funding book that borrowers draw on.Value moves between two customers with no trade print and no chain transaction. Funding at a rate nobody would accept is a transfer wearing a loan's clothes.Pair the lender and borrower over time. Rate against the book. Repeat pairings between the same two accounts. Funding taken and immediately withdrawn.
Spot and margin tradingDeposit, trade, withdraw, with leverage available.Deposit-to-withdrawal with minimal trading is the classic exchange pass-through. Wash trading between controlled accounts moves value and manufactures a record.Trade-to-deposit ratio. Self-crossing. Round-trip time. Withdrawal asset differing from the deposit asset.
DerivativesPerpetuals and leverage under a separate licensed entity.Mirror positions across two accounts transfer value with a market print on both sides.Offsetting positions opened and closed together. Loss transfers that repeat.
Tokenised securitiesBonds and equity issued under El Salvador's regime, traded on Bitfinex Securities.Securities bring eligibility rules and transfer restrictions. Subscription and redemption is a different flow from trading.Source of funds at subscription. Secondary transfers between accounts. Eligibility re-checked at the point of the trade as well as at onboarding.
Fiat railsUSD, EUR, GBP and JPY. Manual bank wires from 10,000 up, a third-party provider below that.The wire minimum is a visible line, so sub-threshold activity concentrates below it. Third-party processors introduce nested payments and a payer who is not the account holder.Payer name against account name. Repeated amounts under the wire floor. Processor-side counterparties that recur across unrelated accounts.
USDt on Tron and EthereumThe dominant deposit and withdrawal asset.Tron carries most of the sanctioned USDt address space. The issuer can freeze, which changes what a stale alert costs.Chain-specific counterparty screening. Re-screen held balances as well as movements. Reconcile against issuer blacklist state.
Sub-accounts and API tradingInstitutional structures with programmatic access.Sub-account topology can hide the same beneficial owner behind several alert streams.Aggregate at the owner level before thresholds are applied. Never alert per sub-account in isolation.
THE ROW THAT MATTERS MOST

The funding book. Every exchange has deposits, trades and withdrawals, so every vendor rule set covers them. A peer-to-peer lending market inside the platform is a Bitfinex signature, it is off-chain, and a generic scenario library has nothing pointed at it. That is where I would expect to find an uncovered typology.

THE ASYMMETRY TO USE

Issuer freeze power inside the group means a confirmed case can end with the funds immobilised rather than merely reported. It also means a wrong call has a harder edge. That argues for a high evidentiary bar on the escalation path and a written rationale on every file, which is the habit this console is built around.

03

JD duties, my method

Each duty in the posting, the method I would bring to it, and where it is demonstrated on this page.

JD dutyMethodShown inStatus
Develop and implement transaction monitoring algorithms for ML, TF and sanctions risk on a risk-based approachEleven scenarios written from scratch, each with a stated hypothesis, a threshold set, and a severity that reflects how often the shape is innocent. Screening rules are absolute. Behavioural rules are graded.§04built
Analyse alerts from fiat (wire and non-wire) and crypto (on-chain and off-chain) trades, deposits and withdrawalsThe console runs the on-chain half end to end. The off-chain half is covered by design in the flow table: funding-book pairings, derivative mirrors, sub-account aggregation, payer-name mismatch on fiat.§★designed
Escalate real-time urgent alerts according to risk appetiteSeverity decides the path, not the score. Any sanctions or issuer-freeze hit is critical and leaves the queue immediately. Behavioural alerts are scored and worked in order.§06built
Assist in periodic reports identifying ML, TF and sanctions anomalies for the CCO and product managersEvery alert generates a narrative with trigger, evidence, assessment and recommended action. Roll those up by scenario and disposition and the periodic report writes itself from the case files.§04built
Adjust risk parameters to keep exposure inside the platform's risk appetiteThresholds are controls on a panel, and moving one recomputes the queue live. A benchmark across labelled subjects shows what the change bought and what it cost.§05built
Initial assessment of referrals of unusual transaction activityA fixed triage order: subject-level screening, then counterparty screening, then one-hop exposure, then behaviour. Cheap and decisive checks first.§06built
Liaise with AML analysts and users for the information needed to verify ML or TF concernsThe narrative names the gap it needs closed, so the request for information is specific enough to answer in one round.§06built
Experience with a blockchain analytics or transaction monitoring tool such as Chainalysis, Elliptic or TRMI have not held a licensed seat on one. I built the equivalent primitives instead: address screening, entity labelling, counterparty typing, one-hop expansion, exposure scoring. Vendor fluency is a fortnight. The judgement underneath is the part that takes longer.§04honest
Source and understand documentation in various languages, types and formsNative English, Mandarin and Bahasa Malaysia. Chinese-language corporate documents and Malaysian filings read without a translation step, which matters on APAC files.resumehave
04

A working console

Built for this application. It pulls a real address's transfer history from a public block explorer, screens every counterparty against the OFAC SDN digital-currency address list, reads the USDt and USDC contract blacklists live on chain, runs eleven scenarios and produces a case file you can dispose of.

Open the TM Console ↗ tx.web3wagmi.com
CodeScenarioSeverityHypothesis it tests
TM-00Subject-level screening hitcriticalThe account address is itself listed, blacklisted by an issuer, or labelled as sanctioned or an exploit. Nothing to adjudicate, so it is handled before any behavioural rule runs.
TM-01Direct sanctions exposurecriticalA counterparty is on the SDN list. Address-level matching, so there is no fuzzy-name problem and no false match to argue about.
TM-02Issuer freeze exposurecriticalA counterparty is blacklisted on the USDt or USDC contract. An independent signal from a party that has seen law-enforcement process.
TM-03One-hop sanctions proximityhighNo direct hit, but a material counterparty has its own listed exposure. The console pulls the top five counterparties and screens them too.
TM-04Rapid pass-throughhighValue arrives and leaves inside the window with little retained. Bounded above as well as below, because a busy address is not a layering leg.
TM-05Structuring below thresholdhighRepeated moves under the reporting threshold that aggregate above it.
TM-06Fan-in consolidationmediumMany distinct senders funding one address in a short window.
TM-07Fan-out dispersionmediumOne address paying many distinct recipients quickly.
TM-08Round-amount repetitionlowWeak on its own. It earns its place only as a corroborator on a subject another rule has already touched.
TM-09Dormancy then burstmediumLong inactivity followed by material volume that the account profile did not anticipate.
TM-10Flagged counterparty labelmediumAn external mixer, scam or exploit label. A lead that still needs the flow read underneath it.
WHERE THE DATA COMES FROM

1,059 digital-currency addresses parsed straight from the OFAC SDN XML, publication date 18 September 2026, across 20 asset types. 133 of them are EVM addresses the console can match on chain. Transfers come from the public Blockscout API. Issuer blacklists are an eth_call to the token contracts at screening time.

WHAT LEAVES THE DESK

Each case file carries the trigger, the evidence rows with transaction links, an assessment that names the benign explanation as well as the suspicious one, and a recommended action. The whole queue exports as one case pack with the tuning in force printed at the top, and every case has a shareable link, which is how a reviewer gets handed a file.

THE BUG WORTH SHOWING

The venue-wallet exemption first swallowed SUEX OTC, a sanctioned desk carrying a deposit-address tag naming the exchange it paid into. A control meant to remove noise had silenced the one subject the desk most needs to see. The exemption now yields to any sanctions or risk label on the subject, which is the general rule: a suppression must never outrank a screening hit.

HONESTY

Mine, built for this application, and not connected to Bitfinex. It runs on Ethereum only, samples the most recent transfers rather than paging full history, and has no access to the off-chain side of an exchange. Those limits are stated on the page itself.

05

Cutting false positives

The application form asks what actually works. Here is my answer, with the console as the working demonstration rather than the claim.

1. Type the entity before you run the rule. Most alert volume on an exchange is a legitimate counterparty behaving legitimately at scale. Label the counterparty first: venue, contract, wallet, flagged. A deposit from a labelled exchange and a swap through a router are relationships the rule should never have been pointed at.
2. Never run behavioural rules on your own wallets. An institution's hot wallet is not a monitored customer. In the console, the Bitfinex hot wallet produces four behavioural alerts with that control off and none with it on, while catching exactly the same zero listed counterparties either way. That is a pure removal with no detection cost.
3. Price the leg, then floor it. Unpriced airdrop and spam tokens are the single largest source of noise on any high-profile address. On the retail wallet in the seed set, 149 of 150 sampled transfers are dust or unpriced spam. Without a floor, fan-in fires forever.
4. Age the list out in both directions. Tornado Cash was designated in August 2022 and delisted on 21 March 2025 after Van Loon v. Treasury. A screening list that was never re-pulled still fires a sanctions alert on it today. Every one of those is a false positive that looks like the most serious alert in the queue. Removals need the same handling as additions.
5. Bound a rule on both sides. The first version of the pass-through rule reported outflows at 156,000% of the inbound leg, because it summed every outbound transfer in the window. A pass-through moves out roughly what came in. Adding an upper bound removed the noise without losing a single real case.
6. Tune against labelled outcomes, not against alert counts. Alert volume alone cannot tell you whether a change was good. The console ships a benchmark over seven labelled subjects, four listed and two legitimate, with one delisted subject held out of both counts. At the shipped defaults it catches 4 of 4 listed subjects with zero alerts on the legitimate ones. Move a threshold and the cost shows up immediately.
7. Escalate on severity, score everything else. A sanctions hit belongs in a different category from a high score. Mixing them makes tuning dangerous, because a threshold change that helps behavioural precision can quietly move a screening hit down the queue.
8. Write the closure reason. The false positives that hurt are the ones closed twice by two analysts who never saw each other's reasoning. A closed alert with a written rationale is a control. A closed alert with a dropdown value is a gap waiting for an audit.

What I would not do. Raise thresholds to make the queue smaller. That reduces alerts and reduces detection by the same mechanism, and it is invisible in the metrics the queue reports. Every suppression in the console names itself and counts itself, so the trade-off stays on the page.

06

Working the queue

The triage order is fixed, so two analysts reach the same disposition on the same file. Cheap and decisive checks run first.

1. Subject screening
listed, frozen, labelled
2. Counterparty screening
SDN and issuer blacklists
3. One hop out
material counterparties only
4. Behaviour
shape of the flow
5. Profile
does onboarding explain it
6. Disposition
written, with a reason
DispositionWhenWhat leaves the desk
EscalateAny sanctions or issuer-freeze hit, at any value. Also any behavioural case where the account profile cannot explain the flow and the counterparty set is adverse.Straight to the Manager, Transaction Monitoring, with the record preserved and no tipping off. Prepared for the CCO report.
InvestigateScore above the investigation line, or two scenarios on the same subject inside 30 days.Full history pulled rather than the sampled window, a specific request for information, and a review date.
Close with reasonSingle low or medium scenario the profile explains.A written rationale on the file. Closure is a decision that has to survive being read back.
07

First 90 days

DAYS 1 TO 30 · LEARN THE QUEUE
  • Work the live queue daily and hit SLA before trying to improve anything.
  • Read the existing scenario inventory against the flow table in §★. Find which product surfaces have no rule pointed at them.
  • Learn the escalation boundary between this desk, AML investigations and the reporting seat.
  • Start CAMS. I do not hold it and I would rather close that on the company's calendar than mine.
DAYS 31 TO 60 · MEASURE
  • Sample 90 days of closed alerts by scenario and disposition. Find the scenarios that close at near 100%, which are candidates for tuning rather than removal.
  • Check list hygiene: when was the screening list last pulled, and are removals handled as carefully as additions.
  • Propose one tuning change, with the expected effect on both detection and volume stated before it goes in.
DAYS 61 TO 90 · ADD COVER
  • Draft one new scenario for an uncovered flow, most likely the funding book, with a hypothesis and a backtest.
  • Take a section of the periodic CCO report and standardise how it is produced from case files.
  • Write the closure-rationale standard down, so the next analyst inherits it rather than rediscovering it.
08

Method & sources

Everything here is from public sources, read and checked rather than summarised from memory. The console recomputes its numbers from live data on every load.

METHOD
  • The JD came from a public job posting, 2026. The role duties in §03 are quoted from it.
  • The sanctions list was parsed directly from the OFAC SDN XML, not from a third-party mirror, so the publication date and record count are verifiable.
  • Chain data is read from the public Blockscout API and a public Ethereum RPC at page load.
  • Numbers in §05 come from running the console over its own seed set.
LIMITS, STATED
  • Ethereum only. Most sanctioned USDt address space is on Tron, which needs a keyed API.
  • The sample is the most recent transfers per address, not full history.
  • No access to the off-chain half of an exchange: fiat rails, the funding book, sub-account topology. Those are designed in §★ and not demonstrated.
  • I have not held a seat on Chainalysis, Elliptic or TRM. Said plainly in §03.
ClaimSource
Bitfinex spot DASP licence, El Salvador, May 2026, completing spot, derivatives and securities coverageblog.bitfinex.com
iFinex operates Bitfinex through BFXNA and BFXWW; Tether Limited under Tether Holdings El Salvador; shared management and common shareholdersBitfinex, Tether Limited
NYAG settlement, February 2021, $18.5M plus quarterly reserve reportingCoinDesk
CFTC order, October 2021, $42.5M across Tether and iFinexCoinDesk
2016 hack of 119,754 BTC, about 95,000 BTC recovered, in-kind return moved for in January 2025, Lichtenstein released early January 20262016 Bitfinex hack, CoinDesk
Chainalysis KYT deployed at Bitfinex, December 2019PR Newswire
T3 Financial Crime Unit past $450M frozen, 23 jurisdictions, and the $344.2M Iran-linked freeze in April 2026Tether, The Block
US persons blocked, fiat in USD, EUR, GBP and JPY, manual wires from 10,000, P2P margin funding at Intermediate verificationBitfinex support
OKX guilty plea, roughly $505M, external consultant through February 2027enforcement summary
Binance $4.3B resolution and the monitorship status questions raised in April 2026US Treasury, The Block
Tornado Cash delisted 21 March 2025 following Van Loon v. TreasurySteptoe
MiCA authorisations: Coinbase and Kraken via Ireland, OKX via Malta, Bybit via AustriaCASP tracker
OFAC SDN digital-currency addresses, 1,059 records, publication 18 September 2026OFAC SDN.XML, parsed for this page

Independent work by Edward Tay for a job application. Not affiliated with Bitfinex. The console is a prototype built for this application and is not Bitfinex software.