Coding Errors Left €176 Billion in Transactions Unmonitored
Coinbase, one of the world’s largest cryptocurrency exchanges, has agreed to pay nearly €21.5 million ($24.8 million) to the Central Bank of Ireland (CBI) to settle allegations that its Dublin-based subsidiary failed to properly monitor transactions under anti-money laundering (AML) and counterterrorism financing (CTF) regulations.
The fine—the largest ever imposed on a crypto firm by the Irish regulator—centers on compliance lapses between April 2021 and March 2023, during which more than 30 million transactions worth over €176 billion were insufficiently screened for suspicious activity.
According to the CBI, Coinbase’s transaction monitoring system contained three coding errors that caused five of its 21 automated detection scenarios to malfunction, leaving certain transactions unchecked. One error involved overlooking crypto wallet addresses with special characters such as “&,” preventing them from being properly flagged.
AML Gaps and Regulatory Response
While Coinbase ultimately filed 2,708 suspicious transaction reports related to the affected period covering potential cases of money laundering, fraud, scams, cyberattacks, drug trafficking, and child exploitation the regulator said the system failures left the company vulnerable to illicit use.
“Crypto has particular technological features which, together with its anonymity-enhancing capabilities and cross-border nature, make it especially attractive to criminals,” said Colm Kincaid, the CBI’s Deputy Governor for Consumer and Investor Protection. “This is why it is especially important that firms engaged in crypto services have robust controls in place to identify and report suspicious transactions.”
While the CBI’s investigation did not establish whether the missed transactions resulted in actual criminal activity, the regulator emphasized the need for stronger internal oversight and real-time risk detection systems within crypto institutions.
Coinbase’s Response and Corrective Measures
Coinbase identified the coding flaws during routine compliance testing and fixed them within two to three weeks of discovery, the company said in a statement. The exchange enhanced its testing and monitoring procedures to prevent similar issues from recurring and cooperated fully with Irish regulators throughout the investigation.
As part of the settlement, the central bank reduced Coinbase’s initial penalty from €30.6 million to €21.4 million, citing the company’s prompt remedial actions and cooperation.
Coinbase also confirmed that its European operations will relocate from Ireland to Luxembourg by the end of 2025, a move that had already been in progress prior to the fine.
Regulatory Oversight Tightens Across Crypto Sector
The case underscores growing regulatory scrutiny of digital asset firms operating under European Union jurisdiction. The Central Bank of Ireland has increased oversight of virtual asset service providers amid the rollout of the EU’s Markets in Crypto-Assets (MiCA) framework, which requires stringent compliance with AML standards and transaction transparency.
Coinbase’s penalty adds to a series of enforcement actions globally as regulators tighten expectations around crypto compliance and consumer protection.
Closing Insight
The Irish fine serves as a stark reminder that regulatory expectations for crypto firms now match those of traditional banks. As digital assets become more mainstream, firms like Coinbase face increasing pressure to ensure their monitoring systems, compliance controls, and data integrity meet the highest standards of financial supervision.