AMLConsensus · course
Programme · Lesson 7.2
Section 7 · Lesson 7.2

Fragmentation (smurfing / structuring)

Fragmentation is the breaking-up of one large operation into many small ones, each of which stays below the threshold at which enhanced scrutiny or mandatory reporting to the regulator kicks in. In English-language practice a distinction is drawn between structuring (structuring amounts to fit under a threshold) and smurfing (distributing the flow across a multitude of "smurf" people/mules and accounts). In crypto both techniques have merged and work at once. Let us take apart the mechanics, learn to recognize the characteristic "fan" and synchronicity on the graph, and see how it looks in real-world P2P.

The logic: hide an elephant in a herd of mice

Every compliance system has thresholds. Historically in fiat these are, for example, requirements to report transactions above a certain amount; in crypto they are exchanges' internal thresholds for requesting enhanced KYC, withdrawal limits without verification, and amounts above which a transaction is automatically routed to an officer for manual review. Fragmentation exploits the very idea of a threshold: if 1 operation × 100,000 raises an alarm, then 100 operations × 1,000 look like routine when taken individually. The elephant is hidden by cutting it into a herd of mice, each too small to be noticed on its own.

The second layer is distribution not only across amounts but across subjects. Classic "smurfing" enlists an army of "smurfs": front persons, mules, bought or rented accounts on exchanges and at banks. Each smurf pushes their small portion through their own account, so the load is smeared across dozens of identities, IPs, devices, and jurisdictions as well. This sharply complicates both technical filtering and the subsequent investigation.

Smurfing / structuring typology

The classic fragmentation "fan": a single source is dispersed into a multitude of small transfers through a network of intermediate addresses and mules.

1 source
100,000 USDT
Sprayer
splits into portions
mule 1 · 950
mule 2 · 980
… ×100 · ~1000

Step-by-step mechanics in crypto

  1. Accumulation and preparation of mules. The organizer assembles a pool of addresses and verified accounts in advance: self-registered, bought "turnkey," or rented from real people for a cut.Often this is the same market as the "warming up" of accounts to bypass anti-fraud.
  2. Spraying (fan-out). From one or several central addresses the funds spread out in a fan to dozens or hundreds of addresses in equal or nearly equal shares.On the graph this is a "star"/"fan" — one center, many rays.
  3. Running through small operations. Each portion travels its own path: P2P deals, buying gift cards, small withdrawals, coin swaps — all within "unremarkable" amounts.Here fragmentation is often combined with peel chains and chain-hopping from the neighboring lessons.
  4. Reconsolidation (fan-in). The cleaned portions flow back together — now at another center, another exchange, another network, where they are gathered into a large sum "with a clean history."A "fan outward" followed by a mirror "fan inward" is the strongest composite signature.
Why exactly this way. Fragmentation strikes at two pillars of control at once. It moves amounts below the thresholds of automatic rule-based monitoring, and distribution across identities breaks the "one flow — one subject" link on which classic risk scoring rests. On top of this is a psychological calculation: investigating a hundred small episodes involving a hundred people is more expensive and slower than one large case, so some cases simply "don't pay off" for law enforcement.

How to recognize fragmentation on the graph

Topologically, fragmentation is almost the opposite of a peel chain. There it was a "comb" in a single line; here it is a star-shaped structure: a wide fan outward and/or inward. The specific markers:

Fragmentation in real P2P: how it looks

On P2P platforms fragmentation is an everyday thing. An organizer who needs to "whiten" a large sum or, conversely, to disperse stolen rubles places or accepts a multitude of small orders instead of one deal. The signs that an attentive counterparty and analyst can see:

Personal risk. By accepting rubles from a mule in such a scheme, you risk having your account blocked under 115-FZ, even if you personally broke nothing: the money will turn out to be part of someone else's fraudulent chain, and the "arbiter" will be your bank.

How to tell it apart from normal activity

To summarize: fragmentation hides a large sum by cutting it into a multitude of small portions and distributing it across dozens of addresses and identities in order to slip under thresholds and blur the tie to any subject. On the graph it is recognized by its star-shaped "fan" outward and inward, the uniformity of amounts under a threshold, synchronicity in time, and transit empty recipients. In P2P this is the daily reality of cash-out through mules — and a direct source of blocks for honest counterparties. Next we move to a technique that tries to break the link not by topology but by cryptography — laundering through mixers and privacy coins.

This material is for educational purposes.