AMLConsensus · course
Programme · Lesson 3.6
Section 3 · Lesson 3.6

CFT: financing of terrorism and extremism in crypto

The abbreviation AML almost always comes as a pair — "AML/CFT". The second element, CFT (Combating the Financing of Terrorism), is often perceived as an appendix to money laundering. That is a mistake. CFT is a separate discipline with a different logic, different amounts and different consequences. For any crypto service, terrorist financing is not "just another risk category" but a red line, the crossing of which means criminal liability and the instant loss of the business. Let's examine how CFT differs from AML, what real typologies exist, and why it is an absolute priority.

AML and CFT: mirror images, but different

At first glance they look similar — both are about "dirty" money and chains of transactions. But the direction of the flow and the nature of the money are opposite:

This is a fundamental distinction. Laundering always begins with a crime that generated the money. Terrorist financing can begin with a perfectly legitimate euro donated "to help refugees". That is why CFT cannot be caught by analysing origin alone — you need to analyse destination and the recipient's connections.

FeatureAML (laundering)CFT (terrorist financing)
Source of moneyAlways criminalOften legitimate
AmountsUsually largeOften small, fractional
PurposeConceal origin, legitimiseDeliver funds for violence
Key questionWhere from?Where to and why?

Why small amounts are a special challenge

Laundering operates in large flows: the criminal needs to legitimise millions. Terrorist financing is the opposite: preparing an attack may cost a few thousand dollars. This changes the entire logic of detection. The classic AML trigger "a large, unusual amount" does not fire here. A thousand dollars of cryptocurrency to the right wallet does not stand out against ordinary transfers — which is precisely why CFT relies so heavily not on amounts, but on the recipient's connections to known terrorist entities and sanctions lists.

Takeaway for scoring. In CFT the main signal is not an anomaly in the amount, but the identity of the counterparty. If an address has surfaced in a fundraising campaign of a proscribed organisation or on a sanctions list (OFAC SDN, UN lists), any transfer to it is dangerous, even one of $50. That is why high-quality sanctions and terrorist address databases are the heart of a CFT module.

Real typologies of fundraising in crypto

Terrorist and extremist structures use crypto according to specific, documented scenarios. Let's look at the main ones — they have appeared repeatedly in reports by FATF and Chainalysis and in criminal cases.

Typology 1: public donation campaigns

An organisation or sympathisers publish a crypto address on social media, Telegram channels or websites under the guise of "humanitarian aid" or a direct appeal. Supporters around the world send small amounts.

Typology 2: abuse of charity

A legitimate-looking "charitable fund" collects donations for a genuine humanitarian cause, but part of the funds is redirected to a structure recognised as terrorist. The money is clean on the way in — the donors are sincere — which makes the scheme especially insidious.

Here AML analysis of origin is useless: the source is legitimate. It is caught only by the final recipient's connections and by the reputation of the "fund" itself.

Typology 3: P2P and intermediaries in high-risk zones

Funds are collected in crypto, then converted to cash near a conflict zone through P2P swappers or hawala-like networks. Crypto here is a way to move value across borders, bypassing banking controls.

Typology 4: stablecoins and privacy coins

Increasingly, instead of volatile BTC, stablecoins are used (USDT on the TRON network) for their stability and low fees, while privacy coins (Monero) and mixers are used for concealment. Stablecoin transfers on cheap networks have become the dominant instrument of illicit financing in general.

Mini-diagram of a typical campaign.
An appeal on Telegram → publication of the address → hundreds of small donations from around the world → consolidation into one wallet → conversion to USDT (TRON) → P2P cash-out at a border.
Note: at no step is there any "dirty origin". The danger is solely in the destination and in the identity of the organiser.

Why CFT is a red line for any service

For a crypto business, terrorist financing stands apart from all other risks. The reasons are extremely harsh.

  1. Strict liability. In most jurisdictions, breaching sanctions and aiding terrorism is strict liability: ignorance is no defence. Even accidentally processing such a payment is a criminal offence, not merely a regulatory fine. There is no "we didn't know" here.
  2. Personal liability of executives. For CFT violations it is not only companies that are held responsible, but specific compliance officers and directors — up to prison terms. The stakes are personal.
  3. Instant loss of banking and licences. A single confirmed episode collapses relationships with partner banks, payment systems and licences. The business dies within days. Reputational death.
  4. Zero regulatory tolerance. While there is room to reason about a risk-based approach for laundering, for terror the principle is "zero". No appetite for risk is justified here. This is not about percentages, but about the absolute.
Practical rule. A match of an address or counterparty against a terrorist/sanctions list is not "elevated risk that needs to be weighed" but an immediate halt of the operation, a freeze and notification of the competent authority (in Russia — Rosfinmonitoring; for sanctions matches — the relevant procedures). A CFT match always outweighs any commercial consideration.
Lesson summary. AML asks "where did the money come from", CFT asks "where and why is it going". Terrorist financing often uses funds that are legitimate in origin and small in size, so it is caught not by anomalies in amounts but by the recipient's connections to terrorist and sanctions lists. Typical schemes are public crypto donation campaigns, abuse of charity, P2P cash-out near conflict zones, stablecoins and privacy coins. For any service this is a red line with criminal and personal liability and zero tolerance. That is why in AMLConsensus the checking of sanctions and terrorist databases takes absolute priority over commercial interest.

This material is for educational purposes only.