Section 6 · Lesson 6.5
Case: a P2P deal on Bybit / Binance P2P
P2P is a marketplace where you sell crypto directly to another person and receive rubles to your card from them (or the other way around). The exchange only holds the crypto in escrow and guarantees that, on payment, the seller releases the coins. It sounds simple — but this is exactly where a beginner most often falls into the most dangerous AML trap: dirty rubles to a card. Let's work through a scenario that is realistic in type — selling USDT for rubles — and build a protocol that protects both your money and your freedom.
The starting situation
- RoleYou are the seller. You're selling 1000 USDT for rubles at the marketplace rate.
- MarketplaceBybit P2P / Binance P2P. The crypto is frozen by the exchange in escrow; the buyer is obliged to transfer rubles to your card.
- BuyerA new account, few deals, rushing you: "I've paid, release it quickly."
- RiskThe rubles may come from a card flagged in a fraud scheme. Then, on the victim's report, the bank will block your card (Federal Law 115-FZ), and you'll be left with neither crypto nor money.
The insidious part of P2P. In an ordinary AML check we look at a crypto address. In P2P the danger shifts into fiat: the "dirt" arrives not on the blockchain but onto a bank card. Meanwhile you hand over perfectly clean crypto — and still become a link in the chain of laundering stolen money. You have to check both sides.
What to check on the buyer — before you release the crypto
- Name match. The name of the cardholder the payment came from must match the verified name of the account on the exchange. Payment from "someone else's" card (a third party) is red flag no. 1. Never accept a payment from a third party.
- Account age and reputation. A fresh account, zero-to-two completed orders, a low completion rate — grounds to be wary and not to hurry.
- Payment method. A transfer in one sum from a card with the same name — normal. Splitting into several small payments from different senders — a sign of smurfing/cash-out. Stop.
- Payment purpose. A note on the transfer like "debt repayment," "for goods," "child support" is alarming: the buyer is disguising the transfer. A P2P transfer should carry no "cover story."
- The actual fact of crediting. Release the crypto only after the money has actually arrived and shows in the bank balance, not on a "paid" screenshot. A screenshot is faked in a minute.
Fraud victim
transfer "as instructed"
→
Your card
"dirty" rubles
→
115-FZ block
victim's report to the bank
Red flags where it's better to cancel the deal
- Payment from another person's cardCash-out classic: the victim is made to transfer money to the "seller's card." The name doesn't match — cancel.
- A request to move the conversation out of the exchange chat"Let's go to Telegram, we'll agree on a better rate there." Leaving escrow and moderation is almost always fraud.
- Pressure and rush"Release it faster, I'm in a hurry." Rush is a tool to keep you from checking the crediting in time.
- Payment split upIt arrived in three payments from three different cards — a chain of mules. Stop and contact the exchange's support.
- A rate that's "too good"The buyer is willing to heavily overpay — often a sign that offloading dirty money matters to them more than saving.
Why it's more dangerous than it seems. Even if you're an honest seller and handed over clean crypto, once stolen money lands on your card you are, to the bank and the investigation, a mule — that is, a cash-out link. The card is blocked under 115-FZ, and unblocking will require explanations and time. Criminal risk arises if awareness is proven. That's why checking the buyer protects not only your money but your freedom.
What to record for every deal
Your only defence in a dispute or a block is proof of good faith. Build a file for every P2P sale.
- A screenshot of the order from the marketplace: amount, rate, the counterparty's nickname and rating, time.
- Confirmation of crediting from the banking app: the sender's full name, amount, date.
- The full exchange-chat correspondence — it is stored on the marketplace and confirms the terms.
- The full-name match: a screenshot showing that the payer's name = the account name.
- The hash of the crypto transaction paying USDT to the buyer — in case you need to show that you handed over exactly what and where.
The "one deal — one folder" rule. Get into the habit of putting these five artifacts into a separate folder/note for each sale and keeping them for at least a year. When a request from the bank arrives three months later, you'll pull up the evidence in a minute rather than trying to remember "who that was."
The case conclusion
Decision. Release the crypto only when three conditions are met: (1) the money is actually in the bank balance, (2) the payer's full name = the account's full name, (3) the payment is a single one with no "cover story" in the purpose. Any red flag — cancel the deal through the exchange's support, not "at your own risk."
What the case teaches. In P2P, the AML centre of gravity shifts into fiat. Clean crypto is no salvation if the rubles are dirty. The seller must check the buyer as thoroughly as an exchanger checks an incoming address — and record everything in writing.
- P2P risk is dirty rubles to a card and a subsequent block under 115-FZ.
- Check the full-name match, the account age, the payment method and purpose, and the fact of crediting.
- Payment from a third party, splitting, rush, moving to private chat — stop signals.
- Record a five-artifact file for every deal and keep it for a year.
The example is instructional, assembled from typical features of real incidents. It is not legal advice.