The speculative hype around non-fungible tokens (NFTs) has cooled significantly, but this does not mean that their relevance for financial crime compliance has disappeared. The key question is not how popular NFTs remain, but how they can be used to transfer value, conceal the origin of funds or introduce criminal proceeds into the financial system.
This approach is consistent with the Illicit Finance Risk Assessment of Non-Fungible Tokens, published by the U.S. Department of the Treasury in 2024. The assessment primarily highlights risks relating to fraud, scams, theft and the laundering of criminal proceeds. The relevant AML question is therefore what role NFTs can play within a broader financial and on-chain transaction chain.
Why can NFTs create specific AML risks?

An NFT is a blockchain-based token that can represent a particular digital or physical asset, a right or an access entitlement. On public blockchains, transactions are generally visible. This creates a degree of transparency: investigators can, for example, see which wallet transferred a token, which wallet received it and which cryptocurrency was used for payment.
That transparency does not, however, automatically mean that the identities of the people involved are known. Blockchain addresses are generally pseudonymous. A single person can control multiple wallets, and a transaction may pass through different addresses, blockchains and services before the proceeds ultimately reach a regulated financial institution.
In addition, NFT valuations can be highly subjective. For listed securities or many other financial assets, there is usually an observable market price. For a unique digital collectible, it is far more difficult to determine objectively why it might be worth, for example, EUR 2,000 at one point and EUR 50,000 shortly afterwards.
This combination of pseudonymity and valuations that are difficult to assess objectively creates opportunities for abuse. A person could, for example, trade with themselves through different wallets, a practice generally referred to as wash trading. This can artificially create trading volume or give the impression that an NFT has a higher market value than it actually does.
From an AML perspective, a potential form of self-laundering is particularly relevant. A criminal could, for example, offer an NFT for sale through one wallet they control and then purchase it using illicitly obtained cryptocurrency through another wallet they also control. This can create an apparently legitimate sale transaction that is subsequently presented as an explanation for the cryptocurrency received. The illicit origin of the funds does not, of course, disappear, but the transaction can be used to construct an alternative economic explanation for the flow of funds.
Such a transaction does not automatically constitute money laundering. Nor does a high NFT price in itself amount to evidence of criminal activity. For compliance purposes, it is the combination of indicators that matters: connected wallets, unexplained price movements, an unclear source of the cryptocurrency used, the immediate onward transfer of proceeds, or subsequent transactions through privacy-enhancing services may together justify further investigation.
How can NFT fraud develop into money laundering?
NFTs may not only be used to move existing criminal proceeds; they can also form part of the fraud through which those proceeds are initially generated. A well-known example is a rug pull, where an NFT project is marketed on the basis of promised benefits or functionality before the organisers disappear with the cryptocurrency received.
U.S. criminal cases illustrate how such fraud can develop into money laundering. In the original 2022 Frosties indictment, authorities alleged that approximately USD 1.1 million in proceeds were moved across different wallets to conceal the source of the funds. In another U.S. case from 2024, proceeds from a fraudulent NFT project were, according to evidence presented at trial, moved from Solana to Ethereum, including through a crypto mixer, before ultimately being converted into U.S. dollars.
For financial institutions, this final stage is particularly relevant: they may only become involved at the end of the chain, even though the funds originated several wallets, blockchains and crypto services earlier from fraud.
Does an NFT automatically fall outside financial regulation?
The legal classification of NFTs also requires nuance.
The European Union’s Markets in Crypto-Assets Regulation (MiCA) does not, in principle, apply to crypto-assets that are genuinely unique and non-fungible. Digital art or a genuinely unique collectible may therefore fall outside the scope of MiCA.
This does not, however, mean that every digital asset marketed as an “NFT” is automatically excluded from MiCA.
MiCA emphasises that the underlying economic characteristics are decisive. Fractions of a unique NFT, for example, are not automatically regarded as unique and non-fungible. Likewise, issuing NFTs as part of a large series or collection may indicate that the tokens nevertheless display a degree of economic fungibility. Simply assigning a unique identifier to a token is therefore not sufficient to classify it legally as unique and non-fungible.
More importantly, falling outside the scope of MiCA does not mean falling outside all financial regulation. MiCA expressly states that the exclusion for unique and non-fungible crypto-assets is without prejudice to their possible classification as financial instruments. A token may therefore fall outside MiCA while still being subject to another financial regulatory framework, depending on the rights it represents and its economic characteristics.

The Financial Action Task Force (FATF) also takes a functional approach. The name given to a digital asset is not decisive. What matters is how it is used in practice and what activity a service provider carries out in relation to that asset. FATF has therefore explicitly addressed NFTs in its guidance on virtual assets and VASPs.
For compliance purposes, the right question is therefore not simply: “Is this an NFT?” The more relevant questions are: “What economic function does the token perform, what rights does it represent and what services are being offered around it?”
What do MiCA and the Belgian supervisory framework mean for financial institutions?
In Belgium, MiCA is supplemented by the Law of 11 December 2025. Supervision of crypto-related activities is divided, among others, between the FSMA and the National Bank of Belgium (NBB), depending on the institution and activity concerned.
For traditional financial institutions, indirect exposure is particularly important. A bank does not need to operate an NFT platform itself to encounter NFT-related risks. Clients may, for example, receive proceeds from NFT activities after cryptocurrency has moved through different wallets, exchanges, bridges or other crypto services.
This fits within the risk-based approach under the Belgian anti-money laundering framework. For AML purposes, institutions should therefore look beyond the final fiat payment and consider the origin of the funds, the transaction path and the underlying economic context.
When does the European Travel Rule apply to NFT transactions?
The European Travel Rule does not automatically apply to every NFT transaction. Regulation (EU) 2023/1113 is relevant where the crypto-asset concerned falls within its scope and a CASP is involved in the transfer.

Direct person-to-person transfers without the involvement of a CASP are, in principle, outside the scope of the Regulation. The legal classification of the NFT also matters: a genuinely unique and non-fungible NFT that falls outside MiCA does not automatically fall within the crypto Travel Rule. Where a CASP is involved, additional requirements may apply, including to transfers to or from self-hosted wallets. Their practical application is further clarified in the European Banking Authority guidelines.
Compliance therefore requires an assessment of the nature of the asset, the structure of the transfer and the service providers involved.
Which indicators are relevant for financial crime compliance?
For institutions that are directly or indirectly exposed to NFT-related financial flows, traditional client identification alone may not always be sufficient.
An effective approach combines KYC with an understanding of the client’s economic activity and, where justified by the level of risk, blockchain analysis and investigation into the source of funds.
A number of indicators may be relevant. These can include repeated purchase and sale transactions between wallets that appear technically or economically connected, extreme price changes without a clear explanation, high transaction volumes shortly after an NFT is created, cryptocurrency originating from wallets associated with hacks or fraud, or sales proceeds that are immediately transferred to bridges, mixers or other services that make the subsequent flow of funds more difficult to reconstruct.
Source of funds and, in higher-risk situations, source of wealth may also be important. Where a client suddenly receives a significant amount and explains it as the “sale of NFTs”, that explanation should not necessarily mark the end of the analysis. Depending on the level of risk, the institution should be able to understand what activity lies behind the proceeds and whether the explanation is consistent with the client’s known profile and normal transaction behaviour.
Blockchain technology does not only create risks. The public nature of many blockchains makes it possible to analyse financial flows and historical wallet interactions. In some cases, compliance teams can therefore reconstruct information that would be much more difficult to obtain in an entirely cash-based environment.
The main challenge lies in connecting this on-chain information to the natural or legal persons behind the addresses.
Has the AML risk disappeared now that the NFT hype has faded?
The decline in the popularity of NFTs does not mean that their AML relevance has disappeared. For compliance purposes, what matters is not the NFT in isolation, but the role it plays within a broader financial chain.
The practical challenge is therefore to look beyond the final transaction. Where did the funds originate, which wallets and services were used, and where was the value ultimately converted? It is this wider analysis that determines whether an NFT-related flow presents a relevant financial crime risk.






