Crypto & MiCA Licensing

Enter password to access the presentation

Incorrect password
Crypto Basics & MiCA framework
1 / 46
Crypto Basics
& MiCA Framework
by Arturas B.
Agenda
Part 1 · Slides 4-27

Crypto Basics

  • Blockchain & cryptocurrency fundamentals
  • Transactions, mining & consensus - UTXO vs EVM, PoW vs PoS, 51% attack
  • Wallets, keys, custodial vs non-custodial (SHW)
  • Multisig & MPC
  • Smart contracts, NFTs, bridges, DeFi & DAO
  • Coins, tokens, wrapped assets, asset types
  • Blockchain architectures, forks, Layer 1/2, speed & scalability
  • Dark side: scams, mixers - plus CEX vs DEX
Part 2 · Slides 29-44

MiCA Framework

  • MiCA Regulation overview & scope
  • Merchant Payments & TFR compliance
  • CASP Authorisation - process & capital
  • Passporting & Reverse Solicitation
  • Client Disclosures & pre-contractual
  • Conflict of Interest - Chinese Wall
  • Sustainability Disclosure
  • Asset Protection & Segregation
  • Sanctions Screening (EBA 3-layer)
  • Travel Rule (TFR)
  • Market Abuse & Insider Trading
  • FNTT reporting - Lithuania
  • DAC8 tax reporting (VMI)
  • BoL reporting
  • Resilience (DORA)
  • Enforcement & Penalties
Part 3 · Slides 46-57

MiCA in Practice

  • Asset classification & stablecoins
  • Simplified deposit schema
  • KYC onboarding - retail
  • KYB onboarding
  • Transaction flows: deposit → exchange → withdrawal
  • Blockchain analytics & screening
  • Service providers & revenue model
Part 4 · Slide 59

Homework

  • MetaMask setup & self-custody
  • CEX onboarding & withdrawal
  • On-chain exploration
  • DEX trade & cross-chain bridge
  • Multi-chain balance check
Part 1
Crypto Basics
Blockchain · Wallets · Assets · Consensus · Ecosystem
What is Cryptocurrency & Blockchain

Cryptocurrency

  • Digital asset secured by cryptography - exists purely as code
  • Ownership = controlling a private key. No key = no asset
  • No physical form - no serial number, no vault

Blockchain

  • A digital database distributed across a peer-to-peer network. Records in sequential blocks - each linked to the previous, forming a linear, append-only chain
  • Not just finance - can store contracts, medical records, supply chain logs
How blocks link: Each block holds its data + the hash of the previous block. Change one block → its hash changes → chain breaks. Tamper-evident.
Blockchain structure

Decentralisation

  • No central authority, no single server - no bank or government controls the network
  • Every node holds a full copy of the ledger
Decentralisation

Immutability

  • Once confirmed and buried under subsequent blocks, a transaction cannot be altered or deleted
  • No "undo", no chargebacks - ever
Think: Google Docs shared with 10,000 people - no one owns the master copy

Block Explorers

  • Public tools to browse any transaction, block, or address on-chain
  • blockchain.com - Bitcoin
  • etherscan.io - Ethereum
  • bscscan.com - BNB Chain

EVM & Layers

  • EVM - Ethereum's smart contract runtime, BSC, Polygon, Avalanche all share the same address format and tooling
  • Layer 1 - base blockchain (Bitcoin, Ethereum), secure but slower and more expensive
  • Layer 2 - built on top of L1, faster & cheaper (Arbitrum, Optimism, Polygon)
  • Lightning Network - Bitcoin L2, payment channels for near-instant, near-free BTC transfers
How a Transaction Gets Into the Blockchain
Transaction flow with mempool Transaction example
1
User Signs Transaction
You initiate a send. Wallet signs the tx with your private key - cryptographic proof you authorised it.
2
Tx Broadcasted to Network
Signed tx is sent out to the P2P network and lands in the mempool on every node.
3
Pending Transactions Pool (Mempool)
Tx waits in the mempool. Miners pick txs from here, prioritising by fee. Low fee = wait longer or never get picked during congestion.
4
Block is Formed
Miner selects txs from mempool, assembles a candidate block, and races to solve the PoW cryptographic puzzle.
Every miner builds their own candidate block independently (highest-fee txs first). All race simultaneously - whoever finds a valid nonce first broadcasts it. All others immediately drop their candidate and start fresh on top of the new block.
5
Block Broadcasted Over Network
Winning miner broadcasts the solved block to all nodes simultaneously.
6
Validated by Majority - Consensus
Each node independently validates. Majority consensus is enough - one rejection doesn't block it.
Orphan blocks: Sometimes two miners solve the puzzle at nearly the same time - two valid blocks exist briefly. Nodes eventually pick one (longest chain wins). The other is discarded - an orphan block. In Bitcoin the orphan miner gets no reward. In Ethereum these are called uncle blocks and the miner receives a small partial reward.
7
Block Added to Blockchain
Block permanently appended. All nodes update their copy. Tx confirmed and immutable. Every block on top makes reversal harder.
Bitcoin Block Hashing (Proof of Work)

How mining works

  • A block header has 6 fields: Version, Previous Block Hash, Merkle Root, Timestamp, Bits (difficulty) - and a Nonce
  • 5 fields are fixed or change rarely. Miners only brute-force the nonce: try 0, 1, 2… billions of times per second
  • A guess is correct when SHA-256 of the full header produces a hash with enough leading zeros
  • SHA-256 is one-way - you can't reverse-calculate the nonce. Only brute force works
What a valid hash looks like:
00000000000000000004b3f2c8e1a7d9…
Always 64 hex chars. Zeros stored as "Previous Block Hash" in the next block. Bitcoin requires ~19-20 leading zeros. One in ~2⁷⁶ qualifies - hard to produce, easy to verify.

Difficulty adjustment

  • Every 2,016 blocks (~2 weeks) the protocol auto-adjusts the required number of leading zeros
  • More miners join → difficulty rises → block time stays ~10 min
  • When all 2³² nonce values are exhausted, miners tweak the timestamp or swap transactions (changing the Merkle Root) to get a fresh nonce space
ASIC-only. Top 2026: Antminer S21 XP - 270 TH/s. Network: 800 EH/s. GPUs/CPUs obsolete.
  • BTC block size varies between 1-4 MB and houses 2,000-5,000 txs/each
  • Transaction fee is entirely based on the weight of inputs, not their value
  • Current BTC blockchain size is about 748 GB
  • Current network reward to miners - 3.125 BTC (±171,000 EUR) or about 24.7M EUR/day
  • Last block is expected to be mined in 2140
Bitcoin Block Hashing diagram
Bitcoin hashing 2
Bitcoin mining
BTC Transaction Example (UTXO)

How Bitcoin UTXOs Work

  • Bitcoin has no "balance" - your wallet holds UTXOs (Unspent Transaction Outputs) - discrete chunks like cheques. No accounts, just unspent outputs that can be filtered via public addresses
  • To send BTC, wallet selects UTXOs that cover amount + fee. UTXOs are fully consumed - cannot be partially spent
  • Tx has inputs (UTXOs spent) and outputs (recipient + change back to you)
  • Change address - surplus returns to a fresh address in your own wallet
  • Fee - implied: difference between total inputs and total outputs. Never stated explicitly.
  • Advanced wallets (Electrum, Sparrow) let you pick UTXOs manually - matters for privacy and AML taint

Real Transaction Breakdown

AmountNote
Input0.00042275 BTCOne UTXO from sender
Output 10.00037439 BTCPayment - recipient
Output 20.00003396 BTCChange - back to sender
Fee0.00001440 BTCImplied remainder
UTXO concept BTC transaction example
Change address depends on the wallet - good wallets (Ledger, Electrum) send change to a fresh address. Simpler wallets may return it to the same input address.
51% Attack

Condition

  • Attacker must control >50% of the network's total hashrate
  • This lets them mine blocks faster than the rest of the network combined
  • Nodes always follow the chain with the most accumulated proof-of-work - this is the attack vector

How it works - double spend

  • Step 1: Send a valid payment to a merchant - confirmed on public chain
  • Step 2: Secretly mine an alternative chain - same coins sent back to yourself instead
  • Step 3: Being faster, private chain eventually overtakes the honest chain
  • Step 4: Publish it - nodes switch to the longer chain
  • Result: Merchant's payment disappears. Attacker keeps goods + coins.
Honest:   A→B→C(payment)→D→E
Secret:   A→B→C'(self)→D'→E'→F' ← wins

Top Bitcoin Mining Pools

  • Foundry USA - largest, US-based
  • AntPool - Bitmain, Chinese origins
  • F2Pool, ViaBTC, Binance Pool
⚠️ Top 3-4 pools control 50%+ combined hashrate - theoretically could coordinate. No evidence of this, but the incentive structure allows it.

✅ Can do

  • Double-spend own coins
  • Reorganize recent blocks (not deep history - too much PoW to redo)
  • Censor transactions - refuse to include them
  • Delay confirmations

❌ Cannot do

  • Create coins out of thin air
  • Spend someone else's coins - no private key
  • Change consensus rules accepted by nodes
  • Make invalid transactions valid

Small chains - very real threat

  • Ethereum Classic (ETC) - attacked multiple times
  • Bitcoin Gold - attacked
  • Vertcoin - attacked
  • Any low-hashrate PoW chain is vulnerable
  • Rental attack services exist - rent hashrate per hour
51% attack animation
Bitcoin Hashrate Distribution (2026)
Bitcoin-specific - not overall crypto hashrate
Hashrate = hashes per second - measures mining power. Top 2026 hardware: Antminer S21 XP = 270 TH/s. Network total: ~800 EH/s. Higher hashrate = harder + costlier to attack.

Global Distribution (2026)

  • 🇺🇸 USA ~40%+ - dominant post-China ban. Texas & Kentucky hubs, cheap energy.
  • 🇷🇺 Russia ~10-15%
  • 🇰🇿 Kazakhstan ~10%
  • 🇨🇦 Canada ~5-7%
  • 🇨🇳 China - was 65%+ → banned mining 2021 → near zero now

Solo vs Pool Mining

  • Solo: keep full reward (3.125 BTC). Probability near zero. Economically unviable.
  • Pools: combine hashrate, split reward proportionally. 1-3% fee. Dominant today.

Largest National BTC Treasury Reserves

Source: bitcointreasuries.net · June 2026 · BTC ~$66,339
#CountryBTCUSD% of 21M
1🇺🇸 USA328,372$21.8B1.564%
2🇨🇳 China190,000$12.6B0.905%
3🇬🇧 UK61,245$4.1B0.292%
4🇺🇦 Ukraine46,351$3.1B0.221%
5🇸🇻 El Salvador7,670$509M0.037%
6🇦🇪 UAE6,420$426M0.031%
7🇧🇹 Bhutan4,973$330M0.024%
8🇰🇿 Kazakhstan3,544$235M0.017%
9🇰🇵 North Korea803$53M0.004%
10🇻🇪 Venezuela240$16M0.001%
Notable seizures:
🇺🇸 Silk Road ~174k BTC · Bitfinex hack ~94k BTC (2022) · James Zhong 50k BTC
🇨🇳 PlusToken Ponzi ~190k BTC - held, never sold
🇬🇧 Jian Wen fraud 60k+ BTC (2024)
🇩🇪 Movie2k piracy 50k BTC - sold mid-2024, briefly crashed market
🇧🇹 Bhutan: sovereign mining via Himalayan hydropower since ~2020
Ethereum Block Hashing (Proof of Stake)

From PoW to PoS

  • Ethereum ran on Proof of Work until September 15, 2022 - "The Merge"
  • Mining eliminated overnight - energy consumption dropped ~99.95%

How PoS works

  • Validators replace miners - stake 32 ETH as collateral to participate (post-2025 Pectra upgrade: up to 2,048 ETH per validator)
  • Algorithm pseudo-randomly selects the next validator to propose a block
  • Other validators verify and approve the block
  • Block added to chain - proposing validator earns transaction fees
  • Misbehave or go offline → stake gets slashed (partially or fully destroyed)
  • Today: ~897,000 active validators, ~38.9M ETH staked (~32% of total supply)
PoW = trust through energy spent. PoS = trust through economic stake at risk.
Proof of Stake flow

What validators actually do

  • No nonce guessing, no leading zeros, no puzzle to solve
  • Selected validator builds the block and signs it with their private key
  • Block validity = a staked, accountable validator signed it - not computational work
  • The nonce field still exists in Ethereum blocks for legacy reasons - set to zero, ignored
What validators earn: (1) Staking issuance - new ETH from the network (~3-4% APY), (2) Priority fee (tip) - portion of user tx fees paid to the block proposer, (3) MEV - extra profit from strategically ordering txs. The base fee from every tx is burned (EIP-1559) - making ETH sometimes net deflationary when activity is high.
Validator selection analogy
EVM Transaction Example (USDC on BSC)

How EVM Transactions Differ from BTC

  • EVM uses an account model - no UTXOs. Your address has a balance, like a bank account
  • No change address - exact amount is sent, nothing returns to sender
  • Token transfers (USDC) are smart contract calls - value field is 0. The actual amount lives in the contract input data
  • Fee is always paid in the native chain token (BNB on BSC) - even when sending USDC
  • Same address works across all EVM chains - ETH, BSC, Polygon, Avalanche
  • Gas = fee for computation. Gas used × Gas price = total fee

Real Transaction Breakdown

ValueNote
From0x1827…d901Sender wallet
To (contract)0x8ac7…580dUSDC contract on BSC
Recipient0x5c18…f5f2Token recipient
Amount1.6139 USDCERC-20 transfer
BNB value0No native BNB moved
Gas used41,771Of 62,901 limit
Gas price3 GweiBSC standard
Fee0.000125 BNB~$0.08 - paid by sender
  • ETH has inflationary issuance and a deflationary burn mechanism: net supply can be inflationary or deflationary depending on network activity
  • Block size is limited by gas, not tx count. Block gas limit = 30 million gas
  • Typical ETH block contains roughly 20-200 transactions, but a single smart contract can also send up to 1,400 transactions per contract in one block
USDC BSC transaction
Public & Private Keys / Wallets

Private Key - proof of ownership

  • A mathematically generated number - derived from your seed
  • Signs transactions to prove you own the input/amount being spent
  • Never share. Lost = that address's funds gone permanently
Each address has its own private key. For Bitcoin: the key unlocks a specific input (UTXO). For Ethereum: the key authorises spending from that address's balance. Same mechanism, different models underneath.

Public Key / Address - where to receive

  • Derived from the private key. Safe to share publicly
  • Bitcoin: new address generated per transaction - your balance = sum of all UTXOs across all addresses
  • Ethereum: one address reused for everything (true account model)
Like an IBAN - share it freely, people send to it, but only you can move what's inside

Seed Phrase - master recovery

  • Your wallet derives all private keys from one seed phrase - one per address, deterministically
  • Same seed → always same keys → same addresses, on any wallet, anywhere
  • Never share. Anyone with it controls everything your seed has ever received
  • Write on paper, store offline, never photograph
Like the master password to a password manager - one phrase unlocks all your accounts. Anyone who gets it owns everything inside.
All valid words come from a public list of exactly 2,048 words. Yet a 12-word phrase has 2,048¹² ≈ 5 × 10³⁹ combinations - longer than the age of the universe to brute-force.

HD Wallets

  • One seed phrase → master key → infinite child addresses
  • Each tx can use a fresh address (UTXO chains)
  • xpub - share with auditor to see all addresses (no spending rights)
  • xpub hidden in MetaMask/Trust Wallet - only in Electrum, Ledger, Sparrow

Hot vs Cold Wallets

  • Hot - internet-connected. Convenient, higher risk. MetaMask, Trust Wallet.
  • Cold - air-gapped, offline. Hardware device (Ledger, Trezor). For long-term storage.
Irony: Bitcoin is hardest to verify ownership despite being the oldest - fresh address per tx, xpub hidden in most wallets
Multisig & MPC - Multi-Party Authorisation

Bitcoin Multisig

  • Native protocol level - P2SH, P2WSH scripts
  • No smart contract (Bitcoin doesn't have them)
  • Logic lives in UTXO locking script
  • M-of-N: 2-of-3 keys must sign to spend

Ethereum/EVM Multisig - Gnosis Safe

  • IS a smart contract - Gnosis Safe
  • Contract holds funds + enforces M-of-N logic
  • Every approval on-chain - fully auditable
  • Example: 2-of-3 (CEO + CFO + Security, any 2)
Multisig diagram

MPC - Multi-Party Computation (Fireblocks, BitGo)

  • No smart contract, no on-chain script
  • Private key never created as a whole - mathematically split into shards at creation
  • Shards never combine - signing via secure multi-party computation
  • Looks like normal single-sig tx on-chain - nothing reveals multi-party control
  • Policy engine: low-risk txs auto-signed, high-risk triggers human approval workflow
  • Full audit trail, granular controls per tx type
  • Preferred by institutional CASPs - no single point of failure, works across all chains
MPC diagram
Custodial vs Non-Custodial (SHW)
"Not your keys, not your coins"
SHW - Self-Hosted Wallet (Non-Custodial)CASP - Exchange (Custodial)
Key holderYouCASP holds keys on your behalf
KYCNone requiredRequired
On-chain ownershipYes - verifiable on blockchainLedger entry only - not on-chain
RiskLose key = funds gone permanentlyCASP failure = your problem
ExamplesMetaMask, Ledger, Trust WalletCoinbase, Kraken, Binance
FTX 2022: CASP failed → client funds gone. Alameda used client deposits for proprietary trading. MiCA Art. 70 (Safekeeping of clients' crypto-assets and funds) exists exactly to prevent this.

Deposit Addresses - Deterministic (CREATE2) vs Simple

  • EVM smart contract deposit address (CREATE2) - computed before deployment, unique per client. Contract deployed on first deposit. Gas cost per deployment (~$0.50-$5 depending on network congestion). Millions of clients = significant cost.
  • Simple address - free to generate, no on-chain cost. But management is hard: harder to attribute incoming deposits to specific clients without off-chain tracking logic.
  • Simple addresses also accumulate dust - tiny leftover amounts after txs, too small to sweep (gas > value). Multiplied across millions of addresses this becomes a real reconciliation headache.
  • Most CASPs use a hybrid: deterministic addresses for EVM chains (auto-forward to hot wallet), simple addresses for BTC/Solana with strong off-chain attribution.
Use term "deterministic address" - not "ghost" or "counterfactual"

Third-Party Access to Your SHW

  • "Connect Wallet" doesn't move custody - it triggers two different signatures with very different stakes
  • Login signature - off-chain, no gas, proves you control the address. Nothing moves.
  • Approval transaction - on-chain, costs gas. You authorize a specific contract (e.g. OpenSea) to move specific tokens on your behalf, within a scope you set.
  • Risk shifts from "who holds my keys" to "what did I approve, and to whom" - broad approvals to a malicious contract are the most common drain vector, not a hacked key
Smart Contracts

What are they?

  • A simple BTC or ETH transfer is not a smart contract - it's just a state change
  • A smart contract is a program deployed on-chain - it has its own address, holds state, and runs code automatically when triggered
  • No intermediary - trustless execution enforced by the network
  • Cannot be stopped once deployed (unless a kill switch was built in)
  • Ethereum = dominant platform. Others: Solana, BNB Chain, Avalanche
Smart contract interactions: swapping tokens on Uniswap · minting an NFT · sending USDC (every ERC-20 transfer calls the token's contract) · DeFi deposit, borrow, or liquidation
→ Live example: BNB Chain smart contract on BscScan

Powers

  • DeFi - lending, borrowing, trading without banks
  • NFTs - ownership and transfer logic
  • DAOs - governance and treasury management
  • Token issuance - ERC-20, ERC-721
Smart contract diagram

Risk - bugs are permanent vulnerabilities

  • No bank to call. No customer support. No undo.
  • Audits reduce risk but cannot eliminate it
  • Complexity = larger attack surface

Famous hacks

  • DAO 2016 - $60M. Led to Ethereum hard fork.
  • Ronin Bridge 2022 - $625M. North Korean hackers.
  • Wormhole 2022 - $320M
  • Nomad 2022 - $190M
Smart contract audit ≠ guarantee. It's a peer review of code at a point in time. Protocol can be upgraded, conditions can change.
Vending machine analogy
The idea:
  • A vending machine is a simple machine that follows predefined rules.
  • You insert €2.
  • You press a button.
  • If the conditions are met, it automatically gives you an item.
  • No cashier, manager, lawyer, or third party needs to approve the transaction.
Transaction & NFT Examples
Coin Transaction Coin transaction
Token Transaction Token transaction
NFT Transaction NFT transaction
NFT NFT
Bridges - Cross-Chain Asset Movement

How it works (lock & mint)

  • Lock 1 BTC on Bitcoin chain → smart contract holds it
  • Mint 1 WBTC on Ethereum - 1:1 representation
  • Use WBTC in Ethereum DeFi
  • Burn WBTC → unlock original BTC
  • Examples: Stargate, Polygon Bridge, Arbitrum Bridge
Regulatory angle: bridges used for chain-jumping to evade AML. Under increasing regulatory scrutiny. Cross-chain analytics = known weakness in Elliptic/Chainalysis.
CEX as unintentional bridge: A user can deposit BTC to a CEX, swap to ETH, and withdraw to an Ethereum wallet - effectively moving value across chains without touching any bridge protocol. The CEX becomes the bridge against its will. This is a known AML typology called chain hopping via CEX. Detection requires the CEX to flag cross-asset deposit/withdrawal patterns - most don't.
Bridge diagram

⚠️ Bridges are extremely high risk

  • Smart contract complexity = large attack surface
  • Hold enormous locked value - prime targets

Famous bridge hacks

  • Ronin Bridge 2022 - $625M stolen. Axie Infinity. North Korean hackers.
  • Wormhole 2022 - $320M stolen
  • Nomad 2022 - $190M. Copy-paste exploit.
  • Multichain 2023 - $130M. CEO arrested in China.
DeFi, CeDeFi & DAO

DeFi - Decentralised Finance

Financial services without banks - via smart contracts; current TVL ±$75B. No KYC. Permissionless.

  • DEX trading - Uniswap, Curve, PancakeSwap · token swaps, liquidity pools · Slippage: difference between the price when you place an order and the price when it executes - caused by market volatility and execution delay. Controllable: set a slippage tolerance when opening an order to cap how much price movement you accept.
  • Lending / borrowing - Aave, Compound, Morpho · earn interest, borrow against collateral, flash loans
  • Liquid staking - Lido, Rocket Pool · stake ETH, receive tradable receipt (stETH, rETH)
  • Restaking - EigenLayer, Symbiotic · reuse staked assets to secure other networks
  • Derivatives / perpetuals - Hyperliquid, GMX, dYdX · leverage, futures, hedging
  • Yield aggregation - Yearn, Beefy · auto-compound across protocols
  • Prediction markets - Polymarket · elections, economic forecasts

Risks: smart contract bugs, no recourse, no deposit protection. Impermanent loss - liquidity providers in AMM pools lose value when asset prices diverge, "impermanent" only if prices recover - often they don't.

CeDeFi - Centralised DeFi

Centralised entity offering DeFi-like products. Examples: Binance Earn, old Nexo, BlockFi (collapsed).

Regulatory grey area under MiCA. Often involves rehypothecation risk.

⚠️ The CeDeFi Paradox: Regulatory Arbitrage

A MiCA-licensed CASP can technically route client funds through DeFi protocols while presenting a compliant face to regulators. MiCA licences the wrapper - not what's underneath. This is a regulatory loophole, not a legal safe harbour. MiCA has no mechanism to reach DeFi infrastructure. But AMLD6 does - it requires knowing your counterparty on every transaction. DeFi has no counterparty. Full compliance while interacting with DeFi is structurally impossible: Travel Rule has no target, AML has no data. Nexo, BlockFi, Celsius all ran this model - all collapsed, sanctioned, or under criminal investigation. EBA and ESMA have flagged CeDeFi as priority scrutiny. It will get caught.

DAO - Decentralised Autonomous Org

Governed by token holders via on-chain smart contracts. No CEO, no board - votes executed automatically.

Top active DAOs: Uniswap DAO, MakerDAO/Sky, Aave DAO, Arbitrum DAO, Compound DAO

Legal status undefined under MiCA.

CASPs cannot participate in DeFi protocols on behalf of clients without specific MiCA authorisation. Staking via centralised validators is ok, DeFi protocol staking (Lido, Rocket Pool) is a grey area most CASPs avoid early stage.
Money Legos: The idea is that smart contracts are like Lego blocks that can be combined together. E.g.: Borrow USDC from Protocol A >>> Swap it on DEX B >>> Deposit the received tokens into Lending Protocol C >>> Stake the resulting LP token in Farm D. This can also happen all in an all-or-nothing mode.
Asset Types

Stablecoins

Fiat-backed: USDC, USDT - backed by real cash/treasuries
Algorithmic: UST/Luna - backed by nothing, collapsed 2022, $40B wiped. Effectively banned under MiCA.
Commodity-backed: gold-pegged tokens

NFTs - Non-Fungible Tokens

Unique, not interchangeable. Ownership on-chain. Examples: digital art, event tickets, gaming items.

Outside MiCA scope entirely.

Governance Tokens

Voting rights over protocol decisions.
Examples: UNI (Uniswap), AAVE, MKR (MakerDAO)

Utility Tokens

Access to a specific service or platform.
Example: Filecoin (FIL) for decentralised storage

Inflationary vs Deflationary

Bitcoin: fixed 21M supply → deflationary
Ethereum post-Merge: semi-deflationary (burn mechanism)
Most altcoins: unlimited supply → inflationary

MiCA Classification Preview

ART: non-fiat pegs (gold)
EMT: single fiat pegs (USDC, EURC)
Other: BTC, ETH, SOL, UNI…

→ Covered in depth in Part 2

Coin vs Token + Wrapped Assets + NFTs
CoinToken
BlockchainOwn native chainBuilt on existing chain
PurposeNative currency, gas feesUtility, governance, ownership
ExamplesBTC, ETH, SOLUSDC, UNI, LINK, AAVE
Standard-ERC-20 (ETH), BEP-20 (BNB), SPL (SOL)

Fungible vs Non-Fungible

  • Fungible - every unit is identical and interchangeable. 1 BTC = any other 1 BTC. Same with USDC, ETH, ERC-20 tokens.
  • Non-Fungible (NFT) - each token is unique. Token ID #1 ≠ Token ID #2, even from the same contract.

NFTs - Non-Fungible Tokens (ERC-721)

  • Each token has a unique on-chain ID - ownership is verifiable and transferable
  • Use cases: digital art, event tickets, game items, domain names, real-world asset tokenisation
  • ERC-721 = one unique token. ERC-1155 = semi-fungible: multiple copies of same item ID (e.g. 1,000 identical swords in a game) - fungible within the same ID, non-fungible across IDs. Also supports fractional ownership of a single asset.
  • The NFT points to metadata (image, file) - usually stored off-chain (IPFS). The blockchain records ownership, not the file itself.
  • Outside MiCA scope entirely - no white paper or reserve requirements
Analogy: Coin = country's official currency. Token = loyalty points issued by a business in that country.

Fractional Tokens

  • ERC-20 tokens support up to 18 decimal places - you can hold 0.000000000000000001 ETH (1 Wei). All fungible tokens are inherently fractional.
  • Fractional NFTs - lock an ERC-721 into a vault contract, issue ERC-20 shares representing % ownership. E.g. a $1M art NFT split into 1,000,000 shares at $1 each. Allows collective ownership of high-value assets.
  • ERC-1155 semi-fungible tokens also serve this purpose within game/platform ecosystems - multiple identical copies of the same asset ID.
  • Regulatory note: fractional NFTs with profit expectations may be classified as securities under MiCA or national law - grey area.
Risk: trust the custodian. If hacked/insolvent → WBTC worthless.

Wrapped Tokens

  • Lock 1 BTC → mint 1 WBTC on Ethereum (1:1)
  • Use Bitcoin value inside Ethereum DeFi
  • Burn WBTC → unlock original BTC
  • Examples: WBTC, WETH, wBNB
Risk: trust the custodian. If hacked/insolvent → WBTC worthless.
Top Blockchains
ChainConsensusKey Feature
BitcoinPoWMost secure, 21M supply, digital gold
EthereumPoSDominant DeFi/NFT, smart contracts
SolanaPoH + PoSHigh speed, low cost
BNB ChainPoSABinance-controlled, EVM-compatible
AvalanchePoSFast finality, subnets
PolygonPoSETH L2/sidechain, low fees
CardanoPoSAcademic, peer-reviewed
XRPFederatedPayments focus, fast settlement

Most Bitcoin is not actively trading

CategoryBTCShare
Lost forever3-4 million15-20%
Satoshi's coins (mostly unmoved)~1.1 million~5%
Long-term holders (1+ year inactive)~13-15 million65-75%
Actively circulating/trading~3-6 million15-30%
Top Cryptocurrencies by CMC (06.03)
#NamePrice24h%7d%Market Cap24h VolumeCirc. Supply
1BTC$65,867−0.12%+2.08%$1.32T$50.1B20.03M
2ETH$1,825−0.10%+4.60%$220B$25.2B120.68M
3USDT$0.9990.00%+0.02%$188B$106.9B188.1B
4BNB$627−0.15%+4.98%$85B$2.1B134.78M
5USDC$1.000.00%0.00%$76B$16.9B75.94B
6XRP$1.21−0.25%+0.35%$75B$2.8B61.97B
7SOL$72.75−0.44%+4.28%$42B$4.5B578.44M
8TRX$0.334−0.34%+0.70%$32B$723M94.81B
9HYPE$73.88−0.74%+4.17%$19B$1.4B253.62M
10DOGE$0.093−0.21%+1.79%$14B$1.1B170.22B
Soft Fork vs Hard Fork

Soft Fork - backward compatible

  • Old nodes still work, just don't enforce new rules
  • No chain split if majority adopts
  • Example: Bitcoin SegWit 2017 - changed how tx data is stored, increased effective block capacity

Hard Fork - non-backward compatible

  • Old and new nodes become incompatible
  • Community split → two separate chains
  • Both chains share history up to the fork block
  • Holders of original coin receive both
PoW vs PoS comparison

Famous Hard Forks

  • Bitcoin → Bitcoin Cash (BCH) 2017
    Block size disagreement: BTC kept 1MB, BCH increased to 8MB. Both exist independently today.
  • Ethereum → Ethereum Classic (ETC) 2016
    DAO hack rollback. Purists: "code is law" → kept original chain = ETC. Others followed rollback = ETH.
  • Ethereum Merge 2022
    PoW → PoS. Near-unanimous agreement, no split. Biggest protocol change in crypto history. Energy use dropped ~99.95%.
Speed & Scalability
NetworkTPSTxs per BlockConfirmation TimeSafe Confirmations
Bitcoin~72,000-5,000~10 min / block6 blocks (~60 min) for large amounts, 1-3 for small
Ethereum L1~3020-200 (1,400 as tokens)~12 sec / block12-30 blocks (~2-6 min)
BNB Chain~300200-500~3 sec / block15-30 blocks (~45-90 sec)
Solana3,000-5,000N/A (slots)~400 ms / slot32 slots (~13 sec) for finality
Ethereum + L24,000-100,000+VariesSeconds on L2Depends on L2 - optimistic rollups: 7-day challenge period
Visa (avg / peak)~24,000 / ~65,000N/A~2-3 sec (auth)N/A - centralised, final settlement takes days
Blockchain Trilemma - pick 2 of 3: Security · Decentralisation · Speed. Bitcoin chose security + decentralisation → slow. Solana chose speed → trade-offs on decentralisation.

Lightning Network (Bitcoin L2)

  • Payment channels opened off-chain with one on-chain tx
  • Unlimited txs between parties - instant, near-free
  • Channel closed with one on-chain settlement
  • Theoretically millions TPS. Used in El Salvador.
  • Limitations: capital locked in channels, routing can fail, designed for micropayments
Blockchain Architectures

Transaction model

  • UTXO (Bitcoin, Litecoin, Cardano) - no accounts. Your balance is a pile of unspent outputs locked to your addresses. Every spend consumes old UTXOs and creates new ones
  • Account (Ethereum, Solana, BNB Chain) - one address, one balance. Tx = subtract from sender, add to receiver

Consensus - who validates

  • Proof of Work - PoW (Bitcoin) - miners compete with computing power to solve a cryptographic puzzle
  • Proof of Stake - PoS (Ethereum, Cardano) - validators lock collateral, pseudo-randomly selected to propose blocks. Cheat = stake slashed
  • Delegated PoS - DPoS (TRON, EOS) - token holders vote for a fixed set of delegates who validate. Faster but more centralised
  • Federated / PBFT (XRP, Stellar) - pre-agreed trusted validator set reach consensus by voting. No mining, no staking
  • Proof of Staked Authority - PoSA (BNB Chain) - 21 pre-selected validators chosen by Binance. Fast, centralised by design
  • Proof of History - PoH (Solana) - not a standalone consensus but a cryptographic clock. Creates a verifiable time sequence so validators don't need to constantly communicate to agree on ordering. Combined with PoS for block validation - PoH sequences, PoS secures
PoW vs PoS comparison

Privacy model

  • Transparent (Bitcoin, Ethereum) - everything public forever. Full chain analytics possible
  • Private by default (Monero) - sender, receiver, amount all hidden via ring signatures. Auditability opt-in via view keys. Most exchanges delisted - incompatible with AML
  • Optional privacy (Zcash) - choose shielded or transparent per transaction

Architecture

  • Standard linear chain (Bitcoin, Ethereum) - blocks, miners/validators, mempool
  • DAG - Directed Acyclic Graph (IOTA, Nano, Aidos Kuneen) - no blocks, no miners. Each tx confirms 2 previous txs. The network is a web, not a chain. Zero fees, near-instant. IOTA = Internet of Things Application - designed for machine-to-machine micropayments
  • Permissioned / private (Hyperledger, R3 Corda) - enterprise chains with known validators, not public
Layer 1 vs Layer 2
L1 - Base BlockchainL2 - Built on Top
SecurityOwn consensusInherits L1 security
SpeedSlowerFaster
CostHigher gas feesLower fees
ExamplesBitcoin, Ethereum, SolanaArbitrum, Optimism, Lightning
Lightning Network Hotel (L2 analogy)
Lightning Network stats (2026):
  • ~12,600 public nodes, ~44,000 channels
  • ~4,000-5,600 BTC locked in capacity (~$400M-$560M)
  • ~$1.17B monthly tx volume, ~5.2M transactions/month
  • Average tx size ~$220 - shifted from micropayments toward larger transfers
  • Volume grew 266% YoY in 2025

Why L2 matters for CASPs

  • Lower gas = cheaper client withdrawals
  • Faster settlement = better UX
  • Same Ethereum security guarantees
  • EVM-compatible = same tooling, same contract addresses
  • Polygon, Arbitrum, Optimism all have Elliptic/Chainalysis coverage
Polygon is technically a sidechain (own validators) - not a pure L2. But functionally: EVM-compatible, low fees, USDC supported.

L2 Types

  • State channels - Lightning Network (BTC). Two parties lock funds on-chain, transact off-chain freely, settle final balance on-chain. Fast, cheap, but limited to direct participants.
  • Optimistic rollups - Arbitrum, Optimism. Bundle txs, post to ETH L1 every few minutes. 7-day challenge window to dispute fraud. Withdrawing to L1 takes up to 7 days.
  • ZK rollups - zkSync, StarkNet. Post cryptographic proof of validity to L1. No challenge period - mathematically guaranteed. Withdrawals in minutes to hours.
  • Sidechains - Polygon PoS. Own validators, own consensus. Checkpoints to Ethereum but doesn't fully inherit its security.
Dark Side - Risks, Scams & Obfuscation

Mixers / Tumblers

Pool crypto from multiple users, return equivalent from different addresses - breaks transaction trail.
Tornado Cash (ETH): OFAC sanctioned 2022. Any touch = auto-reject at regulated CASPs.

Privacy Coins

XMR (Monero) - fully private by default. ZEC (Zcash) - shielded txs untraceable. Also: DASH, GRIN, BEAM.

Elliptic/Chainalysis cannot screen what they cannot see. AML incompatible.

Chain Jumping

BTC → XMR (untraceable) → ETH on fresh address. Via non-KYC DEXs or cross-chain bridges. Cross-chain analytics = known weakness.

Rug Pulls & Honeypots

Rug pull: hidden drain function, team disappears with funds.
Honeypot: can buy but contract blocks selling.
Rule: contract address = identity. Name/ticker means nothing.

Fake Tokens

Same name "USDC", worthless contract. USDC has different verified address on every chain. Only official contract address matters. CASPs: hardcoded whitelist required.

CASP Response

Mixer-linked funds → hard reject.
Privacy coin deposit → reject.
Suspicious pattern → EDD + STR.
Serious cases → relationship exited.

CEX vs DEX

CEX - Centralised Exchange

  • Company operates the exchange
  • KYC required
  • Custodial - they hold your keys
  • Regulated - MiCA, AML obligations
  • Examples: Coinbase, Kraken, Binance

DEX - Decentralised Exchange

  • Smart contracts - no company operating it
  • No KYC - permissionless, pseudonymous
  • Non-custodial - you keep your keys
  • Not regulated under MiCA (no operator)
  • Examples: Uniswap, PancakeSwap, dYdX
CEX vs DEX diagram
⚠️ DEX routing = not viable for regulated CASPs. No counterparty identity. Travel Rule collapses - cannot collect sender/beneficiary info. Unknown liquidity providers. AML model breaks entirely. Never route client funds through DEX as a licensed CASP.
Part 2
MiCA Framework
Authorisation · Client Protection · Asset Protection · Transaction Controls · Market Integrity · Enforcement
Markets in Crypto-Assets (MiCA) Framework

I · Authorisation

  • Post-MiCA: primary supervisor - Bank of Lithuania (BoL)
  • AML/CTF & Sanctions - FNTT (FCIS)
  • Minimum capital requirements
  • Fit & proper management body

II · Client Protection

  • Client information, risk warnings & pre-contractual disclosures
  • Conflict of interest policy & disclosures (Art. 72 + RTS)
  • Complaint handling procedure, templates & client communication rules
  • KYC / KYB onboarding

III · Asset Protection

  • Segregation of clients' crypto-assets & funds (Art. 70)
  • Reconciliation of client assets - regular internal records & daily operational controls
  • Safeguarding - custody architecture
  • Insolvency ring-fencing

IV · Transaction Controls

  • Sanctions screening - client, counterparty & transaction-level controls
  • Blockchain analytics - AML, sanctions & illicit exposure screening
  • Travel Rule / TFR - originator/beneficiary info, CASP-to-CASP exchange, SHW controls
  • Outsourcing, reliance & whitelabel responsibility - CASP remains accountable

V · Market Integrity

  • Market abuse regime (Arts. 86-92)
  • Insider dealing prohibition
  • Market manipulation prohibition
  • FNTT reporting: STOR (market abuse), SAR/STR, CTR (mandatory ≥€15,000 transfers)

VI · Resilience

  • DORA - ICT risk management
  • Major ICT incident reporting under DORA timelines
  • Annual resilience testing
  • Third-party ICT provider oversight

VII · Enforcement

  • Administrative sanctions - up to €15M or 10% turnover
  • Criminal liability for market abuse
  • Public naming by FNTT
  • Licence suspension or revocation

MiCA Scope

✅ IN scope: CASPs (exchanges, custodians, brokers, advisors), asset issuers launching tokens publicly, stablecoins (ARTs and EMTs), crypto trading platforms, portfolio managers & crypto advisors.

❌ OUT of scope: DeFi protocols (no identifiable operator), NFTs (unless features re-qualify them), DAOs (legal status undefined), CBDCs (central bank issued), security tokens (covered by MiFID II).

Abbreviations
CASP - Crypto-Asset Service Provider NCA - National Competent Authority STOR - Suspicious Transaction & Order Report FNTT - Financial Crime Investigation Service (LT) KYC - Know Your Customer SAR/STR - Suspicious Activity / Transaction Report KYB - Know Your Business EBA - European Banking Authority CTR - Currency Transaction Report (≥€15,000 transfers) AML - Anti-Money Laundering TFR - Transfer of Funds Regulation DORA - Digital Operational Resilience Act ICT - Information & Communications Technology Arts. - Articles (of MiCA regulation)
TFR & Crypto Payments - What We Know
Hard Claims
  • TFR applies to all crypto transfers (BTC, ETH, any asset) where a CASP is involved - no goods/services exemption for standard on-chain transfers
  • CASP-to-CASP: full TFR data required from €0, no de minimis threshold
  • SHW transfers: TFR data required at all amounts. €1,000 only triggers enhanced SHW ownership verification on top
  • USDC is MiCA-compliant for use in the EU. Circle obtained MiCA authorization through its EU-regulated entity, allowing both USDC (USD-pegged) and EURC (EUR-pegged) to be issued as MiCA-compliant e-money tokens (EMTs). USDT (Tether) is not compliant and major EU CASPs delisted it back in 2024
  • Outgoing payment: screen beneficiary vs sanctions lists + wallet address (Elliptic/Chainalysis). If receiver is CASP - transmit TFR data via Travel Rule protocol. If receiver is SHW - record internally, nothing to transmit
  • Outgoing to SHW: CASP records TFR data internally, verifies SHW belongs to client for ≥€1,000, screens address. Data stays on record - SHW cannot receive it
  • EMI + CASP license: EMI handles SEPA, e-money, fiat settlement; CASP adds crypto services. No third-party payment institution needed
  • Crypto transfers are irreversible. A refund is a new outbound transaction with its own TFR obligations - not a rollback
  • Safeguarding rules apply to all received funds - flagged or unclaimed crypto cannot be appropriated, reused, or freely disposed of
Grey Areas - regulation pending
  • How to collect pre-transaction TFR data from an anonymous third-party shopper with no contract with the CASP - no binding guidance exists
  • SHW ownership verification was written for first-party client flows. For merchant payments, the shopper is a stranger - do you verify ownership? Whose? Regulation does not answer this
  • Mandatory originator data has three valid readings: conservative (address + doc number + personal code mandatory, date/birth as last resort), flexible (both options equal alternatives), literal (doc number optional)
  • Unclaimed flagged funds: no disposal path, no statute of limitations, no reporting obligation defined in EU law
  • Refunding to a flagged SHW address may create money laundering exposure - funds arrived suspicious, refund sends back equivalent value
  • Sunrise asymmetry: no supervisory guidance on transfers to non-TFR-compliant CASPs - block, flag, or proceed? Each CASP decides alone
  • Sub-€1,000 SHW transfers: risk-based approach is a business-friendly workaround. If a transfer later proves to be laundering, documented risk logic is the only defense - whether regulators accept it is untested
I - CASP Authorisation - Process & Capital Requirements
1
Prepare 3-6 months
Business plan & programme of operations, governance and internal control framework, AML/CTF and sanctions framework (including EWRA & AML/CTF audit reports), suitability documents for management body members, key function holders and qualifying shareholders, source of funds & wealth for shareholders and UBOs, prudential safeguards evidence, conflicts of interest policy, complaints-handling procedure, outsourcing arrangements, BCP/DR and DORA documentation
2
Submit to Bank of Lithuania
Two regulators: Bank of Lithuania (prudential supervisor) + FNTT (AML supervisor). Lithuanian or English accepted.
3
Completeness Check 25 working days
BoL checks whether all required information has been submitted. Missing information requests may stop the clock. This is mainly a completeness check, not yet the full quality assessment.
4
Full Assessment up to 40 working days
Assessment of MiCA Title V compliance, including governance, suitability, AML/CTF risk exposure, prudential safeguards, safeguarding arrangements, outsourcing, ICT security and DORA readiness.
5
Decision
Authorisation granted → EU passport activated. Can operate in all 27 member states. Bank of Lithuania requirements →
!
EMT / Payment Services Overlap
Where the business model includes EMT-related services that qualify as payment services, MiCA CASP authorisation alone is not sufficient. From 2 March 2026, CASPs carrying out certain EMT transactions must also hold an additional payment services authorisation, limited Payment Institution licence, or provide those services through an authorised PSP. This is especially relevant for EMT transfers performed on behalf of clients and custodial EMT wallets allowing third-party send/receive functionality.

Capital Requirements by Class

ClassServicesMin. Capital
1Order execution, advice, portfolio management, RTO€50,000
2Custody, crypto↔fiat exchange, crypto↔crypto exchange€125,000
3Operation of a trading platform€150,000
Own funds must also cover ¼ of previous year's fixed overheads - whichever is higher. Capital must be maintained at all times, not just at application.

Lithuania Reality Check

  • Pre-MiCA: 370+ FNTT-registered firms, minimal capital, weeks to complete → attracted shell companies
  • MiCA transition: ~30 applied, only 3 received the licence (Robinhood, CoinGate, Nuvei)
  • Minimum 3 local staff required for substance
  • Bank of Lithuania = prudential supervisor · FNTT = AML supervisor
  • Rumours suggest Bank of Lithuania is reluctant to issue new CASP licences - thorough preparation is key
I - Passporting and Reverse Solicitation

How Passporting Works (Art. 83)

  • CASP notifies Bank of Lithuania (the MiCA licensing NCA - not FNTT) of intent to passport into a specific member state - one notification per country, not per client
  • Bank of Lithuania forwards the notification to the host NCA (e.g. BaFin) within 10 working days
  • CASP may begin services after transmission - no waiting for host NCA approval, all 26 member state notifications can be sent in one batch
  • Host NCA receives a copy but cannot block or delay the passport - only Bank of Lithuania can suspend or revoke the licence
  • Notification must specify: member states, services offered, start date

Reverse Solicitation (Art. 61)

  • MiCA allows a non-EU CASP to serve an EU client without a MiCA licence - but only if the EU client approached the CASP entirely on their own initiative
  • Logic: MiCA protects EU clients from being targeted, it cannot stop a client from seeking out a foreign provider themselves
⚠️ Common misconception: "We'll run without a licence and claim reverse solicitation." ESMA has made clear this does not work if you have any EU-facing digital presence. FNTT can and will act on unlicensed providers serving Lithuanian clients.
II - Client Disclosures & Pre-contractual Obligations

What MiCA Requires (Arts. 81-82)

  • General risk warning - crypto-assets are not covered by deposit guarantee schemes (DGS) or investor compensation schemes (ICS). Must be prominent, not buried in T&Cs
  • Custody arrangement description - clients must be told: (a) pooled vs segregated - whether their assets sit in a shared wallet with other clients or in a dedicated address, (b) direct vs sub-custodian - whether the CASP holds assets itself or delegates to a qualified custodian (BitGo, Fireblocks, Copper), (c) proof of reserves - MiCA encourages, and market practice increasingly requires, a public transparency page showing on-chain verifiable proof that client liabilities match held assets. Binance, Kraken, and others publish real-time reserve dashboards. Post-FTX, clients expect this - absence is a red flag
  • Fee schedule - all fees, charges, and spreads disclosed before service begins
  • Conflict of interest policy - structural separation (Chinese wall between prop desk and client flow), pre-approval for unavoidable conflicts (e.g. listing fees), personal account dealing rules for all staff with market access. Client notified in writing before CASP acts on any flagged conflict
  • Complaint handling procedure - how to file, timelines, escalation to FNTT
  • White paper reference - for each crypto-asset offered, the relevant issuer white paper must be accessible
  • Service-specific risk warnings - staking, lending, exchange each carry distinct risk disclosures

Why This Matters Operationally

  • Disclosures must be provided before the client agreement is signed - not after
  • Client must actively acknowledge risk warnings - passive scroll-through is insufficient under MiCA
  • Must be in the client's language or a language they accepted
  • Disclosures are updated whenever material changes occur (fees, custody arrangements, services)
  • Compliant crypto finance service makes UI/UX a somewhat challenging task

Common FNTT Audit Question

Show us the client's signed acknowledgement of the risk warning, the fee schedule they accepted, and the version of your conflict of interest disclosure they saw at onboarding.

If you cannot produce these per client - you have a compliance gap.
II - Conflict of Interest (Arts. 72-76)

What Counts as a Conflict

  • CASP vs client - CASP takes the other side of a client trade (proprietary trading against client flow)
  • Client vs client - CASP has information advantage allowing it to favour one client over another
  • Staff vs client - employee front-runs a client order using knowledge of pending transactions
  • Issuer relationships - CASP lists a token it has a financial stake in without disclosure
  • Group / shareholder links - conflicts involving shareholders, group entities, management body members, employees, outsourcees or connected persons
  • Issuer / token relationships - CASP promotes, lists, places or supports a token where it has a financial or commercial interest
  • Remuneration and incentives - fees, bonuses, rebates or non-monetary benefits that may influence objective client treatment

What MiCA Requires

  • Written conflicts of interest policy - maintained, proportionate to the business model and reviewed at least annually
  • Conflict mapping - across services, clients, staff, shareholders, group entities, outsourcees, issuers and commercial partners
  • Prevention and management first - disclosure alone is not enough where the conflict can be prevented or controlled
  • Website disclosure - general nature, sources of conflicts and mitigation steps published clearly for clients and prospective clients
  • Information barriers and segregation - own account activity, client order flow, custody, listing, pricing and execution functions must be properly separated where relevant
  • Staff dealing and remuneration controls - personal transactions, incentives and bonuses must not undermine fair treatment of clients
⚠️ Conflict of interest policy is one of the first documents FNTT requests in a licence application. Not having a written, mapped, approved policy = application stalled.
💡 Practical rule: if your CASP also trades its own book - you need a "Chinese wall" between the trading desk and the client services team. Same person cannot manage both.
II - Sustainability Disclosure - Art. 66(3)

What CASPs Must Disclose

  • Crypto-asset white papers must include sustainability information, but CASPs also have their own website disclosure obligation for crypto-assets they provide services on
  • CASPs must publish, in a prominent place on their website, information on the principal adverse impacts on climate and other environment-related impacts for each crypto-asset they service
  • For each supported asset: disclose energy consumption data, methodology, source of information and, where required, additional indicators such as renewable energy use, GHG emissions and energy intensity
💡 Practical implication: if a CASP offers BTC, ETH, SOL, USDT, USDC or other crypto-assets, it needs a documented sustainability disclosure process, including data source, methodology, update frequency and website publication. This is not usually a licensing blocker by itself, but it is an ongoing MiCA disclosure obligation that the Bank of Lithuania may review.

Consensus Mechanism Comparison

AssetMechanismDisclosure burden
BTCProof of WorkHigh - energy use must be quantified
ETHProof of StakeLow - post-Merge energy use ~99.95% lower
SOLPoS + PoHLow
ADA, DOTProof of StakeLow
III - Asset Protection - Three Linked Obligations
Safekeeping of Clients' Crypto-Assets and Funds - Arts. 70 & 75 MiCA
These controls work together: where client assets are held, how they are protected, and how the CASP proves through records and reconciliation that segregation works in practice.

1 · Segregation of Client Assets (Arts. 70 & 75)

  • Client assets held separately from CASP own assets - at all times
  • Cannot be used for CASP operations, lending, or investment
  • Separate own/client wallets, or clearly segregated omnibus wallets, supported by client-level ledger records
  • Hard prohibition - no exceptions, no "temporary" commingling
MiCA does not require a separate blockchain wallet per client - omnibus custody can work, but ledger segregation must be very strong. The CASP's own assets must still sit in separate, dedicated wallets from any client omnibus wallet.

Only Exception: Staking

  • Explicit client opt-in required, full risk disclosure, rewards passed to client
  • CASP takes transparent fee only
  • Centralised validator = clean. DeFi staking = grey area.

2 · Safeguarding

  • Cold / hot wallet split - majority of assets in cold storage, only operational float in hot wallet
  • Third-party custody / wallet infrastructure - where used, outsourcing must be controlled, and the CASP remains responsible. If another CASP performs the custody service, it must be MiCA-authorised, and clients must be informed (Art. 75)
  • Insolvency ring-fencing - client assets must be unreachable by CASP creditors in insolvency
  • Insurance / capital buffer - must cover potential losses from operational failures
BitGo, Fireblocks, Copper are typically wallet infrastructure, not a qualified custodian in the legal sense - the distinction depends on the actual setup and contract.
Pooled (Omnibus), standard model: all client funds in shared hot/cold wallets, CASP ledger tracks per-client share, client pool never mixed with CASP own funds (Art. 70).
Segregated, premium/institutional: dedicated on-chain address per client, CASP manages keys only, client can verify balance on-chain. Rare and expensive - Coinbase Custody, BitGo, Anchorage.

3 · Recordkeeping and Reconciliation

  • Daily operational reconciliation - client ledger vs on-chain wallets, custody provider records and bank / safeguarding account balances
  • Any unexplained discrepancy triggers investigation, escalation and remediation
  • Reconciliation records kept for minimum 5 years
  • Result: proof that segregation and safeguarding are actually working - not just policy on paper
Unresolved reconciliation breaks are a red flag in Bank of Lithuania supervision and internal/external audit - and may also create AML/CTF or sanctions concerns depending on the cause.
Reconciliation discrepancy
Causes: fat finger errors, gas fee accounting errors, hot/cold transfer timing differences, hack or theft, or - worst case - unauthorised use of client assets.
Dust: tiny fractional amounts left after txs, too small to spend (gas > value). Managed via EVM forwarding at deposit, reassigning dusty addresses, automated sweeps and UTXO consolidation during low-fee windows, or written off below a minimum threshold.
IV - Sanctions Screening - EBA 3-Layer Framework
EBA guidelines mandate three independent screening layers. One does not substitute for another - all three are required simultaneously. Lists covered: UN Security Council, OFAC (only if USDC is operated), HM Treasury, EU asset-freeze measures.
EBA guidelines require PSPs and CASPs to maintain effective policies, procedures and controls for Union and national restrictive measures. For CASPs, this means screening relevant client, transfer and wallet information before making crypto-assets available, with blockchain analytics used where appropriate based on the business model, volume and risk exposure. Internal policies may also include non-EU lists, such as OFAC or UK sanctions, where required by the company's risk appetite, partners or global exposure.

Layer 1 · Customer-Level

  • All customers screened at onboarding
  • All authorised representatives screened
  • All UBOs (25%+ ownership) screened
  • Continuous - re-screening triggered by list updates, not just at sign-up
  • Tools: ComplyAdvantage, Refinitiv, Dow Jones
Confirmed sanctions match = stop / reject / freeze as legally required, escalate immediately and report to FNTT or other competent authority where required. Risk scoring cannot override an asset-freeze obligation.

Layer 2 · Transaction-Level

  • All crypto-asset transfers screened before crypto-assets are made available to the beneficiary
  • Originator and beneficiary information from TFR / Travel Rule used in sanctions screening
  • Transfer purpose, free-text fields and supporting information screened where available and relevant
  • Counterparty CASP / PSP, intermediary institution and wallet data checked where available
  • Applies to inbound and outbound transfers, including one-off transfers
Wallet addresses screened against official EU / national restrictive measures lists and internal sanctions intelligence, OFAC / UK lists may also be screened where included in the company's global sanctions policy.

Layer 3 · Blockchain Analytics

  • Explicitly mandated by EBA - not optional
  • Used to detect direct and indirect exposure to sanctioned wallets, sanctioned services and circumvention typologies, including mixers, bridges, nested services and chain-hopping
  • Dual-use control: supports both AML/CTF transaction monitoring and sanctions exposure assessment
  • Must have dedicated sanctions hard-block module (automatic process) - risk score alone is insufficient
  • Tools: Elliptic, Chainalysis, TRM Labs
Abbreviations
EBA - European Banking Authority CASP - Crypto-Asset Service Provider VASP - Virtual Asset Service Provider UBO - Ultimate Beneficial Owner OFAC - Office of Foreign Assets Control (US) SDN - Specially Designated Nationals list (OFAC) FNTT - Financial Crime Investigation Service (LT) AML - Anti-Money Laundering KYC - Know Your Customer TFR - Transfer of Funds Regulation PSP - Payment Service Provider HMT - HM Treasury (UK)
IV - Travel Rule (TFR) for CASPs. EBA Standards. Whitelabel Trap.

TFR Basics (Regulation EU 2023/1113)

  • CASP-to-CASP transfers: no threshold - all transfers require full originator + beneficiary TFR data regardless of amount
  • Self-hosted wallet (SHW) transfers: different rule - below €1,000 a risk-based approach applies, at €1,000+ the CASP must verify the client actually owns/controls the unhosted wallet (ownership proof: signature, micro-deposit, etc.)
  • Originator and beneficiary information must travel with every transfer

TFR → EBA Travel Rule Guidelines (EBA/GL/2024/11)

  • EBA guidelines define: exact data fields required, what to do when counterparty VASP data is incomplete, acceptable VASP discovery methods, record-keeping requirements
  • EBA guidelines are binding on all EU CASPs - not soft guidance
  • Tools: Notabene, Sygna, Chainalysis KYT for VASP discovery
TFR services

⚠️ Whitelabel Compliance Trap

  • If your CASP provides infrastructure to another brand (whitelabel / hosted service), you remain the regulated entity - you, the licensed CASP, own compliance
  • NCAs like FNTT will hold the licence holder responsible for TFR breaches on any transaction processed through their infrastructure
Whitelabel contracts must explicitly define data flows and confirm TFR data collection happens at the licensed CASP layer.

VASP Discovery Problem

  • Wallet address alone tells you nothing - CASP or SHW?
  • Option 1: Travel Rule network (Notabene, Sygna, TRP, VerifyVASP) - only if both CASPs on same/interoperable network
  • Option 2: Elliptic/Chainalysis address-to-entity mapping
  • Option 3: Bilateral agreements - doesn't scale
  • If discovery fails → treat as SHW
Choose Travel Rule provider by coverage of high-volume exchanges - not by number of registered CASPs. Notabene and Sygna cover most realistic transaction volume.

VASP Discovery Problem

  • Wallet address alone tells you nothing - CASP or SHW?
  • Option 1: Travel Rule network (Notabene, Sygna, TRP, VerifyVASP) - only if both CASPs on same/interoperable network
  • Option 2: Elliptic/Chainalysis address-to-entity mapping
  • Option 3: Bilateral agreements - doesn't scale
  • If discovery fails → treat as SHW
Choose Travel Rule provider by coverage of high-volume exchanges - not by number of registered CASPs. Notabene and Sygna cover most realistic transaction volume.
💡 Operational reality: inbound crypto may arrive before or without complete Travel Rule data. The CASP must have controls to hold, reject, return, suspend or request missing information, and to assess whether an STR/FIU report is required.

⚠️ Pre-Transaction TR is Largely Theoretical

  • Blockchain doesn't require permission
  • Funds arrive whether CASP likes it or not
  • In practice: funds land → CASP freezes pending TR data
  • Post-transaction is the real world

If TR data never arrives

  • Risk-based decision by compliance officer
  • Document decision thoroughly
  • Consider: amount, counterparty risk, history with that CASP
  • Repeated failures from same CASP → escalate / exit relationship
Abbreviations
TFR - Transfer of Funds Regulation (EU 2023/1113) CASP - Crypto-Asset Service Provider EBA - European Banking Authority VASP - Virtual Asset Service Provider RTS - Regulatory Technical Standards ITS - Implementing Technical Standards FNTT - Financial Crime Investigation Service (LT) AML - Anti-Money Laundering KYT - Know Your Transaction STR - Suspicious Transaction/Transfer Report FIU - Financial Intelligence Unit
V - Market Abuse - MiCA Title VI (Arts. 86-92)
MiCA introduces a market abuse regime for crypto-assets - mirroring MAR (Market Abuse Regulation) from traditional finance. CASPs are both subject to these rules and obligated to enforce them on their platforms.

Inside Information & Insider Dealing (Arts. 87, 89-90)

  • Inside information - precise, non-public information likely to significantly affect the price of a crypto-asset
  • Insider dealing - using inside information to buy, sell, cancel or amend orders, or recommending another person to trade
  • Unlawful disclosure - sharing inside information outside normal duties
  • Example: employee buys a token before a listing, partnership, delisting or major incident announcement
  • Staff with market access need personal account dealing and information-access controls

Market Manipulation (Art. 91)

  • Wash trading - trading with yourself or related accounts to create artificial volume
  • Spoofing / layering - placing orders without genuine execution intent to move the price or order book
  • Pump-and-dump - coordinated promotion and buying to inflate price, then selling
  • False or misleading signals - transactions, orders or public statements that distort supply, demand or price
  • Crypto-specific patterns - coordinated wallets, cross-platform activity, thin liquidity abuse, token promotion campaigns

CASP Obligations (Art. 92)

  • Surveillance arrangements - systems and procedures to prevent and detect suspected market abuse
  • Monitoring scope - orders, transactions, client behaviour and relevant DLT / wallet indicators where applicable
  • STOR filing - suspicious transaction and order report to the competent authority / official STOR channel without delay
  • STOR is not STR - market abuse reporting is separate from AML suspicious activity reporting, unless AML suspicion also exists
  • Confidentiality - client or staff member must not be informed that a STOR was filed or is being considered
  • Record keeping - orders, transactions, alerts and investigation rationale kept for supervisory inspection (8 years from the end of business relationship)
V - FNTT Reporting Obligations - Lithuania
1
STR - Suspicious Transaction Report
3-hour clock starts from human compliance review determining reasonable suspicion - not from alert generation. Alert alone does not trigger the clock.
(a) Tx can be stopped: suspend first → file via goAML within 3 working hours of suspension. (b) Tx already executed / cannot be stopped: file within 3 working hours of suspicion determination - which may be days after the actual transaction. Suspension period: up to 10 working days from the day after filing. No tipping off the client - ever. ⚠️ A 10-day freeze is a direct customer satisfaction and Trustpilot risk - MLRO must be reachable fast.
2
CTR - Cash Transaction Report
Cash transactions €15,000+. Crypto equivalent: large fiat on-ramp/off-ramp. Filed within standard reporting window.
3
Sanctions Freeze
Immediate freeze - no delay. Hard block before any investigation. Report to FNTT. Do not unfreeze without explicit FNTT approval.
4
Periodic Transaction Volume Statistics
Regular aggregate reporting of transaction volumes, asset types, jurisdiction breakdown.
5
Ownership / Management Changes
Any change in UBO, directors, or key management must be reported to Bank of Lithuania. New fit & proper assessment may be required.
Records kept: 10 years. Lithuania: minimum 3 local staff for CASP substance.
V - DAC8 - EU Crypto Tax Reporting (VMI)
1
What DAC8 Is
EU directive (8th amendment to the Directive on Administrative Cooperation), aligned with the OECD's Crypto-Asset Reporting Framework (CARF). Separate legal basis from MiCA - this is tax reporting, not AML/sanctions reporting. Different recipient too: VMI (State Tax Inspectorate), not FNTT.
2
Who Must Register / Report
Any Reporting CASP, including ones not yet MiCA-licensed. One registration in one member state covers all 27 - but the reporting itself still goes to the local tax authority (VMI for Lithuania-based CASPs).
3
Data to Collect at Onboarding
Valid TIN (tax identification number) and self-certification from every EU-resident client. For legal-entity clients, this extends to UBOs - not just the account holder. New onboarding field - coordinate with KYC/KYB.
4
What Gets Reported per Transaction
Transaction type (exchange / transfer / payment), crypto-asset type, amount in native units and fiat equivalent at time of transaction, transaction date.
5
Timeline
In force from 1 January 2026. First reports cover the 2026 calendar year, due to VMI between January and September 2027.
TIN implementation involves real calculation work - valuing and aggregating transactions per client/asset isn't trivial. VMI's systems have had recurring issues with CRS/FATCA reporting for EMIs and payment institutions in prior years, and this is the first year crypto is included - how smoothly the data actually flows through remains an open question.
V - BoL Reporting

Quarterly reports for CASP

  • Finansinės būklės ataskaita
  • Nebalansinė ataskaita
  • Pelno (nuostolių) ataskaita
  • Paslaugų ir komisinių pajamų ataskaita
  • Nuosavybė, gautinos sumos ir įsipareigojimai
  • Nuosavų lėšų ataskaitos
  • Nuosavų lėšų reikalavimų
  • Pastoviųjų netiesioginių išlaidų ataskaitos
  • Informacijos apie kriptoturto paslaugų teikėjo klientus ir valdomus klientų kriptoturto portfeliu
  • Kriptoturto paslaugų teikėjo sandorių
  • Kitų kriptoturto paslaugų teikėjo paslaugų
  • Investicijos
  • Kriptoturto paslaugų teikėjo viešai platinamų kitoje valstybėje narėje ar trečiojoje šalyje su turtu susietų žetonų vertės ir dalyvių skaičiaus
  • Kriptoturto paslaugų teikėjo Lietuvoje viešai platinamų kitoje valstybėje narėje ar trečiojoje šalyje įsteigtų su turtu susietų žetonų išpirkimo (išplatinimo) ataskaitos

Questionnaires

  • Klientų skaičius
  • Klientų tapatybės nust.
  • Klientų rūšys
  • Visų klientų geografija
  • Aktyv. klientų geografija
  • Naudos gavėjai
  • Produktai, paslaugos
  • Operacijos
  • Op. koridoriai
  • Kontrolės priemonės
  • Travel rule
  • Vidiniai tyrimai
  • Pranešimai FNTT
  • Nutraukti santykiai
  • Valstybių sąrašas
This is fine
VI - Resilience (DORA)
Digital Operational Resilience Act - in force for CASPs since 17 January 2025
DORA is a separate EU regulation, not part of MiCA itself - but CASPs are in scope as financial entities. Proportionality applies: requirements scale with size and risk profile, smaller CASPs are not expected to build bank-grade ICT functions.

ICT Risk Management Framework

  • Governance and risk framework approved and overseen by the management body
  • Identification, protection, detection, response and recovery functions for ICT systems
  • Business continuity and disaster recovery plans, reviewed regularly
  • Mapped to the same governance structure already required under MiCA Title V

Major Incident Reporting

  • Initial notification - no later than 4h after classification, and 24h after detection
  • Intermediate report - within 72h of the initial notification
  • Final report - within 1 month of the intermediate report
  • Reported to Bank of Lithuania, separate channel from FNTT AML/sanctions reporting
Not simply "4h to NCA" - it is a staged timeline (4h / 24h → 72h → 1 month), and only major incidents trigger it.

Testing & Third-Party Oversight

  • Annual basic resilience testing - vulnerability scans, scenario-based testing
  • Threat-led penetration testing (TLPT) for significant entities, roughly every 3 years
  • Register of all ICT third-party providers, with contractual risk and exit terms
  • Critical ICT providers (e.g. major cloud vendors) can face direct EU-level oversight
Not simply "4h to NCA" - it is a staged timeline (4h / 24h → 72h → 1 month), and only major incidents trigger it.
VII - Enforcement & Penalties - Title VII

Administrative Sanctions

Breach typeMax penalty
Operating without CASP authorisation / breach of operating conditions€700k (individual) · €5M or 5% turnover (entity)
Authorisation / disclosure violations€700k (individual) · €15M or 10% turnover (entity)
Market abuse (insider dealing, manipulation)€2.5M (individual) · €15M or 15% turnover (entity)
Sanctions screening breachCriminal referral possible in addition to admin fine
Higher of the fixed amount, turnover-based amount, or profit/loss-based amount may apply, depending on the breach. Member States may also set stricter penalties.

Bank of Lithuania Powers under MiCA

  • Suspend or withdraw CASP authorisation
  • Issue public statements / warnings naming the responsible person or entity
  • Order the person to cease the breach and prevent recurrence
  • Require disgorgement of profits gained or losses avoided
  • Temporarily ban responsible individuals from management functions
  • Refer suspected criminal conduct to law enforcement, where applicable

ESMA & EBA Role

  • ESMA - sets binding technical standards, monitors supervisory convergence across NCAs, maintains public CASP register
  • EBA - sets standards for ART/EMT issuers and sanctions screening. Supervises significant token issuers directly
  • National competent authority - supervises individual CASPs. In Lithuania: Bank of Lithuania for MiCA, FNTT for AML/CTF, sanctions and FIU matters
⚠️ MiCA penalty decisions are generally published by the competent authority, unless publication is deferred, anonymised or not published for specific legal reasons. Public enforcement is a major reputational risk for a CASP, especially where client trust, safeguarding and regulatory reliability are the core product.
"Individual" in this context means a natural person, not the company itself - but it's broader than just the CEO. Under MiCA's enforcement provisions, this typically covers members of the management body (the board), key function holders (e.g. compliance officer, MLRO), or any natural person who is found personally responsible for causing or permitting the breach.
Part 3
MiCA in Practice
KYC · KYB · Custody · Transaction Flows · AML · Analytics · Lithuania
MiCA Asset Classification & Stablecoins
CategoryDefinitionExamplesTrad. finance eq.
ART
Asset-Referenced Token
Any non-fiat peg - basket of currencies or single commodityGold-backed token, multi-currency basketETF / ETP
EMT
E-Money Token
1:1 single fiat currency pegUSDC, EURC, EURIFiat money
OtherNo peg, no ART/EMT classificationBTC, ETH, SOL, ADA, UNI, AAVEAsset

MiCA Authorised EMTs

  • USDC - Circle, French ACPR July 2024, USD-pegged
  • EURC - Circle, EUR-pegged
  • EURI - Banking Circle, EUR-pegged
  • EURCV - Société Générale Forge, EUR-pegged
  • Various smaller EUR EMTs (Membrane Finance, Quantoz)
List is short and EUR-dominated. USDC is the only major USD stablecoin with MiCA status.

USDT (Tether) - NOT MiCA compliant

  • BVI-based, no EMT authorisation
  • Reserves historically questioned
  • Delisted: Binance EU, Coinbase EU, Kraken EU - Q1 2026
  • EU clients cannot use USDT

No ARTs authorised (yet)

  • Requirements too stringent
  • Demand low - market hasn't developed
💡 ART note: single commodity peg (e.g. gold) = ART, not EMT. EMT = single fiat only. NFTs outside MiCA scope. CASP licence is separate from asset classification.
Important exclusions / separate regimes: MiCA does not apply to crypto-assets that qualify as financial instruments under MiFID II, such as security tokens, or to products already regulated under other EU financial services laws, such as deposits, structured deposits, securitisation positions, insurance or pension products. A CASP licence does not authorise investment services, deposit-taking, e-money issuance or payment services where a separate EMI / PI / credit institution licence is required.
Algorithmic stablecoins: effectively banned under MiCA. UST/Luna 2022 = $40B wiped in 72 hours. Exactly what MiCA was designed to prevent.
Simplified Deposit Schema
Simplified deposit schema
KYC Onboarding - Retail (Private Person)
1
Identity Verification
ID document (passport, national ID) + liveness check (selfie/video). Tools: Sumsub, Jumio, Onfido.
2
Address Verification
Utility bill or bank statement < 3 months old. Name + address must match ID.
3
Sanctions + PEP Screening
Screen against OFAC, EU, UN, and FATF lists. PEPs can be clients - but require enhanced due diligence and closer monitoring. ⚠️ One sanctions miss = potential licence revocation. Tools: ComplyAdvantage, Refinitiv, Dow Jones.
4
Source of Funds
Declaration above thresholds. Higher risk = more documentation (payslips, tax returns).
5
Ongoing Monitoring
Periodic re-screening + transaction monitoring throughout relationship.

⚡ Smart re-screening policy

  • Don't auto re-screen all clients periodically - wasteful
  • Re-screen when triggered: new tx after inactivity, client update, risk profile change
  • Inactive clients (1-2yr no tx) = do nothing until they return
  • Tx-level screening (Elliptic) covers ongoing risk anyway
  • Consider forced offboarding for long-term inactive clients
Risk-based approach. Low-risk = lighter touch. High-risk = enhanced due diligence (EDD): video call, additional documents, senior approval.
KYB Onboarding
1
Company Documents
Certificate of incorporation, articles of association, proof of registered address, board resolution authorising account opening.
2
UBO Mapping - 25%+ threshold
Anyone owning 25%+ must be individually verified. Trace through holding companies to actual humans. For UBOs: ID document + photo is sufficient - no liveness check required (liveness only for high-risk UBOs or if also a director).
3
Directors & Signatories
Full liveness check - same as retail KYC. Fit & proper assessment for key persons.
4
Sanctions + PEP - All Persons
ComplyAdvantage screening on all identified UBOs, directors, and authorised signatories.
5
Source of Wealth / Funds
How was the business established? Source of operating capital? Audited accounts if available.
!
High Risk → Enhanced
Video call with UBOs, notarised/apostilled docs, AML policy reviewed, senior approval required.
Takes days/weeks vs minutes for retail. Larger revenue opportunity but significantly higher compliance burden.

Typical corporate KYC timeline

  • Simple company, clean UBOs: 2-5 days
  • Complex structure (holding co, multiple UBOs): 1-3 weeks
  • High risk / sanctions-adjacent jurisdiction: weeks + EDD

Onboarding fee

  • Typical: €500-€2,000+ for corporate onboarding
  • Reflects real compliance cost
  • Non-refundable in most frameworks
Transaction Flow - Deposit from SHW
1
User Broadcasts Tx
User sends from SHW to CASP deposit address. Tx broadcast to network, pending in mempool. Status: Detected
2
Confirmations + Screening Begins
Confirmations reached → Elliptic/Chainalysis risk score on source address + UTXO contamination (BTC) + Sanctions hard check + KYC cross-ref + STR threshold check. Status: Processing
3a
Clean → Auto-Approve
Ledger credited, funds swept to hot/cold wallet. Status: Completed
3b
Medium Risk → Manual Review
Compliance officer reviews. May request additional documentation from client. Status: Action Required
3c
High Risk / STR → Freeze
High risk: reject, return to source (screen return address). STR: freeze if possible, file via goAML within 3 working hours of suspicion determination (clock starts from human review, not alert). Up to 10-day suspension. No tipping off. Status stays Processing. Rejected: return tx to source address.
Edge
Unregistered Address
Ownership proof required first: cryptographic signature (EVM) or micro-deposit (BTC) or self-declaration. UTXO chains: fresh proof per new address.
Transaction Flow - Deposit from CASP
1
VASP Discovery + TR Data
Sending CASP attempts VASP discovery via Notabene/Sygna/Chainalysis. Prepares Travel Rule data package: sender + beneficiary info. ⚠️ Pre-tx TR theoretical - funds may arrive before data.
2
CASP Detects Tx → Screening
Confirmations reached → Elliptic risk score + Sanctions hard check + VASP identity verification + TR data completeness check. Status: Processing
3a
TR Received + Clean → Approve
All checks passed. Ledger credited, swept to hot/cold. Status: Completed
3b
TR Missing / Incomplete
Freeze funds. Contact sending CASP. If never arrives → risk-based compliance decision, document thoroughly.
3c
Sanctions / STR
Sanctions: hard block, freeze, FNTT immediately. STR: freeze if possible, file via goAML within 3 working hours of suspicion determination (clock from human review, not alert). Up to 10-day suspension. No tipping off.
Edge
VASP Undetected → Fallback SHW
If sending CASP not identified → treat as SHW flow. Client proves ownership via screenshots/signature. Status: Action Required → Completed
Transaction Flow - Internal Exchange
1
Order Submitted
Client requests swap (e.g. 1 BTC → ETH). CASP validates sufficient ledger balance. Order type: market (instant) or limit (target price).
2
Liquidity Sourcing
Option A: Internal order matching - pure ledger swap, cheapest. Option B: CASP own inventory - needs MiCA "dealing on own account" authorisation. Option C: External LP/market maker API (B2C2, Cumberland, Wintermute).
3
Best Execution + Rate Markup
MiCA best execution obligation applies. Exchange rate markup applied - this is the main retail margin. Rate locked, client notified.
4
AML Monitoring
Ongoing monitoring: layering, structuring, rapid cycling, large trades vs risk profile. No on-chain tx - pure ledger update.
5
Ledger Updated
Pure internal ledger update - nothing happens on-chain. Fast, no gas fees. Status: Completed
⚠️ DEX routing = not viable. AML collapses - no counterparty identity, Travel Rule impossible, unknown LPs. Never route through DEX as regulated CASP.
Transaction Flow - Withdrawal to SHW
1
Request + Whitelist Check
Client requests withdrawal. Is destination address pre-registered/whitelisted? If yes → proceed. If no → ownership proof required first. Status: Action Required (if new address)
1a
Ownership Proof (new address)
EVM: cryptographic signature via MetaMask - one-time. Bitcoin (UTXO): fresh proof required for each new address - xpub hidden, HD wallets complicate verification.
2
Screening
Elliptic risk score on destination address + Sanctions hard check + KYC cross-reference + STR amount threshold. Status: Processing
3a
Clean → Approve + Broadcast
Ledger debited. Hot wallet broadcasts on-chain tx. If hot wallet below threshold → admin alert + M-of-N multisig rebalance request. Status: Completed once confirmed on-chain.
3b
Mixer-Linked Address → Hard Reject
Hard reject. Enhanced due diligence. Possible client offboarding. STR if warranted. Funds stay on ledger.
Note, that withdrawal (self) is not payment (other beneficiary).
Transaction Flow - Withdrawal to CASP
1
VASP Discovery
Attempt to identify if destination is a known CASP: Notabene/Sygna directory, Chainalysis address mapping, bilateral agreement. If unidentified → treat as SHW flow.
2
Travel Rule Data Prepared + Transmitted
If CASP identified → prepare TR package: sender name + account + wallet, beneficiary name + wallet, amount. Transmit via Notabene/Sygna. Await acknowledgment.
3
Screening
Elliptic risk on destination + Sanctions hard check + KYC cross-ref + STR threshold. Status: Processing
4a
TR Sent + Clean → Approve
Ledger debited. Hot wallet broadcasts. Status: Completed. Hot wallet alert if below threshold.
4b
Receiving CASP Returns Funds
Screen returning funds same as inbound deposit. Re-credit ledger. Document reason for return.
4c
Sanctions / STR
Sanctions: hard block, freeze, FNTT. STR: freeze if possible, file via goAML within 3 working hours of suspicion determination (clock from human review, not alert). Up to 10-day suspension. No tipping off.
Blockchain Analytics & Transaction Screening

Main Providers

  • Elliptic - CASP-focused, tx risk scoring, address screening
  • Chainalysis - tx tracing, government-grade intelligence
  • TRM Labs - real-time blockchain risk monitoring

Two separate checks

  • Sanctions - OFAC/EU published specific wallet addresses. Hard block - separate from risk score. No discretion. Freeze immediately.
  • Risk score - 0-100 based on exposure to darknet, mixers, ransomware, stolen funds, high-risk exchanges

Typical Thresholds (CASP defines own)

  • 70%+ → block automatically
  • 40-70% → manual review
  • Below 40% → pass

UTXO Contamination Ratio (Bitcoin)

  • BTC tx composed of UTXOs, each with own history
  • Some UTXOs may be partially tainted
  • 0-5% indirect exposure → proceed
  • 5-15% → manual review
  • 15%+ → reject/freeze
  • Direct exposure (any %) → hard block always
Address laundering problem: User proves ownership of one clean address. Has 50 HD wallet addresses. Dirty funds routed through unregistered addresses → clean address → deposit. Partially mitigated by multi-hop analytics.
Key Service Providers Reference
CategoryProviderKey Service
KYC / LivenessSumsubAutomated ID + liveness, global coverage, most popular
KYC / LivenessJumioDocument verification + biometric check
KYC / LivenessOnfidoAI-powered ID verification
Sanctions + PEPComplyAdvantageReal-time sanctions, PEP, adverse media screening
Sanctions + PEPRefinitiv (LSEG)Institutional-grade screening database
Blockchain AnalyticsEllipticTx risk scoring, address screening, CASP-focused
Blockchain AnalyticsChainalysisTx tracing, government-grade intelligence
Travel RuleNotabeneVASP discovery + Travel Rule messaging (recommended)
Travel RuleSygna BridgeTravel Rule protocol
Custody / MPCFireblocksMPC wallet infrastructure + policy engine
Custody / MPCBitGoInstitutional multisig + MPC
Multisig (EVM)Gnosis SafeSmart contract multisig, DAO standard
Travel Rule: choose by coverage of high-volume exchanges, not number of registered CASPs. Notabene + Sygna cover most realistic transaction volume.
CASP Revenue & Cost Model (provocation)
Revenue sources
Revenue TypeSources
Transaction-basedExchange rate markup (biggest retail margin) · Trading/exchange fee % · Deposit/withdrawal fees · Gas fee markup
Account-basedCorporate onboarding fee €500-€2,000 · Monthly maintenance · API access · Inactivity fee
Custody-basedAnnual custody fee % of AUM · Segregated custody premium · Staking cut % of rewards (MiCA compliant, opt-in)
Minimum team costs - Lithuania
RoleMinEMI overlapGross salary/mo (EUR)Notes
CEO + Co-Director2✅ Yes€5,000 - €10,000 eachFour eyes principle. Both fit & proper. At least one Lithuania-based. Clean criminal record, relevant experience.
MLRO1🟡 Maybe€4,200 - €7,500Mandatory. Independent. AML expertise. FNTT relationship. Files STRs. Cannot be combined with CEO in small CASPs.
Compliance Officer1⚠️ Hardly€2,900 - €5,000MiCA/BoL obligations. Separate from MLRO ideally. Can be combined in early stage with strong justification.
Crypto Developer1-4❌ No€4,600 - €9,200/eachCritical - cannot fully outsource. Deposit contracts, sweep logic, node integration, Fireblocks/Elliptic APIs. Regulator will question technical competence.
KYC Analyst1✅ Yes€1,700 - €2,900Can be part-time or outsourced at early stage
IT / Security1⚠️ Hardly€2,100 - €3,750Can be outsourced to qualified firm
Accountant1✅ Yes€1,500 - €2,500Can be outsourced to licensed firm
Total team cost-~€38,900/mo gross
⚠️ Reality check - team cost alone: At 1% revenue on transacted volume, you need ~€3.9M/month (€47M/year) in transactions just to cover gross salaries. This excludes tech stack, office, Fireblocks, Elliptic, legal, and banking fees. CASP is a high-volume business or high-risk business to justify high fees - plan accordingly.
Part 4
Homework
Homework

Objective: learn the complete lifecycle of a crypto asset - centralized exchange (CEX), self-custody wallet, blockchain explorers, DEX trading, cross-chain bridging, gas fees, and multi-chain asset management. Work through the 7 steps below in order, on your own wallet, with small real amounts.

01 - MetaMask Setup

  • Install MetaMask extension
  • Create new wallet
  • Save seed phrase offline (paper, never email/cloud/password manager/chat)
  • Note public address (0x...)
  • Add BNB Smart Chain + Polygon
Observe
  • Address vs seed phrase
  • Self-custody responsibility
Questions
  • What can be shared publicly?
  • What gives full control?
MetaMask

02 - CEX Onboarding (Kraken)

  • Open account at kraken.com
  • Complete full KYC
  • Deposit €20 via SEPA
  • Buy €12 of USDC, €5 of BNB, €3 of POL
Observe
  • KYC requirements
  • Fiat→crypto conversion
  • Trading fees
Questions
  • Why is KYC required?
  • Why monitor transactions?
Kraken

03 - Withdraw to Metamask - SHW

  • USDC → BNB Chain (BEP-20)
  • BNB → BNB Chain (BEP-20)
  • POL → Polygon
Expected
  • BSC: ~12 USDC, ~0.01-0.02 BNB
  • Polygon: small POL
Questions
  • Wrong network selected?
  • Why BNB on BNB Chain?
  • Why POL on Polygon?

04 - Explore On-Chain Activity

  • Open bscscan.com + polygonscan.com
  • Search your wallet address
  • Locate Kraken withdrawals (USDC/BNB/POL)
Observe
  • Tx hashes, block numbers
  • Timestamps, public balances
Questions
  • Is chain activity private?
  • What can investigators see?
Token transaction

05 - DEX Trade (PancakeSwap)

  • pancakeswap.finance, connect MetaMask
  • Swap 2 USDC → CAKE
  • Tx1: approval. Tx2: swap
Observe
  • No platform KYC, liquidity pools
  • Gas paid in BNB, slippage
DEX does no KYC - wallet-to-wallet via smart contracts, not a regulated intermediary.
PancakeSwap

06 - Cross-Chain Bridge

  • app.debridge.finance, connect MetaMask
  • Bridge 8-10 USDC, BNB Chain → Polygon
Observe
  • Approval, source tx, execution
  • Destination receipt, wait time, fees
AML: chain hopping, cross-chain movement, sanctions screening gaps, beneficial ownership tracing.
deBridge

07 - Verify Multi-Chain Balances

Expected
  • BSC: BNB, USDC, CAKE
  • Polygon: bridged USDC, POL
Observe
  • Same address, different assets per chain
Questions
  • Same address on multiple chains?
  • Same blockchain or not?
MetaMask