India Blocks 15 Crypto Exchanges for AML Violations

Logo of india flag with bitcoin icon on the bottom right and exclaimation icon on bottom left | complycube

India’s Financial Intelligence Unit (FIU) has issued non-compliance notices to 15 crypto exchanges, specifically, Virtual Digital Asset Service Providers (VDASPs) under the country’s Anti-Money Laundering (AML) law. The notice includes shutting down their apps and URLs from public access in India.

The Origin Story

In India, VDASPs must comply with the Prevention of Money Laundering Act, 2002 (PMLA) regulations. Businesses offering services such as crypto-to-fiat exchanges, virtual-asset transfers, or digital asset administration typically fall within the PMLA reporting-entity framework.

The case centers on Section 13 of the PMLA, which allows India’s FIU Director to impose fines. It can also enforce disciplinary action on companies that fail to meet full AML obligations. Notably, the 15 companies involved in the case do not all necessarily have physical offices in India. Most operate across several jurisdictions and serve global customer bases.

As such, crypto firms face a clear warning. India’s AML and Counter-Terrorism Financing (CTF) rules apply, regardless of any physical presence. Any crypto exchange that provides services to customers in India must comply with local laws or could face potential enforcement action.

Details on the 15 Crypto Exchanges Involved

The notice covers 15 different exchanges and how their existing compliance framework satisfied India’s PMLA. However, the authorities did not explicitly state the exact violations. The companies involved spanned derivatives platforms, centralized exchanges, and other virtual-asset services..

Image header reads 15 crypto exchanges targeted by indian authorities followed by the names and logos of 15 crypto exchanges | complycube

The range of businesses the FIU targets tells a compelling story. Authorities are focusing not only on the label a company uses to describe its operations, but also on the actual activities or services it offers. You can learn more here: Cryptocurrency Regulation in India.

India’s Stringent Stance Around Crypto

India’s latest crackdown on 15 crypto platforms is easier to understand when viewed as part of a broader regulatory campaign. Indian authorities have progressively broadened the AML perimeter around Virtual Digital Assets (VDAs). 

However, the government takes an unusually clear position on one point: a crypto company’s AML obligations depend on its activity, not its jurisdiction. That matters to international compliance teams. Over the last 20 months, India has shown that this stance is not just theory.

In 2025, India’s FIU updated its VDA-registration framework twice. First on 20 January and the next on 15 September. This happened before it targeted 25 more offshore crypto providers on 1 October 2025 and issued notices to take down their apps and URLs.

On January 8, 2026, the regulator took another step by issuing updated AML guidelines for businesses providing VDA-related services. The framework is not just telling an exchange to register. It covers key regulatory mandates on governance, Kunden-Due-Diligence (CDD), ongoing monitoring, the crypto Travel Rule, and higher-risk areas such as unhosted wallets and anonymity-enhancing products.

Was geschieht als Nächstes?

The 15 platforms named by the FIU will likely prioritize regulatory engagement and remediation. India’s previous reaction to offshore VDASP suggests the way ahead may be to respond to FIU notices, assess whether registration as a reporting entity is necessary, correct flaws in AML-Kontrollen, and pay financial penalties if violations are proven.

The commercial risk is immediate market access. If takedown notices are implemented, affected platforms could find it harder for Indian users to access their websites or apps while proceedings continue.

Avoiding Scrutiny from India’s Financial Intelligence Unit

The importance for compliance teams at international crypto businesses extends far beyond these 15 companies. The first question should be: Are we serving Indian customers even if we don’t have a legal entity, office, or staff in India? Here are the three key takeaways all AML teams must learn from this case:

1. Localize AML controls for every jurisdiction: Regulations can evolve quickly and vary drastically from country to country. Businesses must tailor every workflow, policy, and monitoring process to each jurisdiction’s requirements. Combining ongoing monitoring and policy assurance solutions equips firms to identify regulatory changes early and assess whether existing controls still meet local laws.

2. Technology only works when backed by strong governance: Sophisticated AML and monitoring tools cannot compensate for weak oversight or poor compliance culture. Companies need clear ownership, effective escalation processes, regular testing, and evidence that controls are working. Additionally, firms should test compliance controls continuously against evolving risks.

3. Regulators look at what you do, not simply where you are based: The FIU’s action reinforces that regulatory exposure can be driven by the services a company provides and the customers it serves. For crypto firms operating across borders, this means assessing obligations market by market rather than assuming that a lack of physical presence removes local compliance responsibilities.

Stärken Sie Ihre Lösungen zur Betrugsprävention und Identitätsprüfung mit complycube | complycube

Weitere Neuigkeiten zum Thema Geldwäschebekämpfung finden Sie in ComplyCubes Newsletter „Trust Edition“. Wir beleuchten die neuesten Entwicklungen im Bereich der Identitätsprüfung und der Bekämpfung von Geldwäsche weltweit. 

Inhaltsverzeichnis

Weitere Beiträge

Lesen Sie, wie der ukrainische Krypto-Betrug gestoppt wurde, nachdem er Opfer in über 20 Ländern mit gefälschten KYC-Wallet-Drainern und gestohlenen Identitätsdaten ins Visier genommen hatte | complycube

Ukrainisches Kryptobetrugsnetzwerk von Behörden zerschlagen

Ukrainische Strafverfolgungsbehörden zerschlugen einen Kryptobetrug, der sich über mehr als 20 Länder erstreckte, und deckten auf, wie gefälschte KYC-Prüfungen, Wallet-Draining, gestohlene Identitätsdaten und fragmentierte Betrugskontrollen zusammenwirken können, um das Vertrauen entlang der gesamten Customer Journey auszunutzen.
Zertifikat mit blauem Band und der Aufschrift „Qualifizierte elektronische Signatur (QES)“ sowie dem Label „Qualifiziertes Zertifikat“ | complycube

Was ist eine qualifizierte elektronische Signatur (QES)?

Eine QES-Signatur bietet höchste Sicherheit gemäß der EU-eIDAS-Verordnung. Sie verbessert die sichere Fernregistrierung, die Nichtabstreitbarkeit, die Interoperabilität zwischen den EU-Mitgliedstaaten und kann rechtsgültig als handschriftliche Unterschrift gelten.
Das Siegel des US-Finanzministeriums neben einem Stapel Goldmünzen und einer amerikanischen Flagge als Symbol für die Bundesfinanzen | complycube

FinCEN deckt Betrugsnetzwerk bei Investitionen in digitale Vermögenswerte auf

FinCEN hat schätzungsweise 1,7 Billionen US-Dollar mit Anlagebetrug im Bereich digitaler Vermögenswerte in Verbindung gebracht, der über ausländische Betrugszentren abgewickelt wurde. Erfahren Sie, wie diese Netzwerke illegale Gelder transferieren und welche Auswirkungen die Ergebnisse auf KYC, AML und die laufende Überwachung haben.