Perspectives · Analysis
Southeast Asia Must Force Crypto Exchanges to Stop Enabling Scammers
With nearly $40 billion stolen annually through regional scam networks, baseline global standards are failing. The Philippines and Thailand show a better path forward through shared liability and proactive prevention.

KEY TAKEAWAYS
- ·Southeast Asian scam networks steal nearly $40 billion annually, using crypto exchanges as entry points for victim funds and exit ramps for criminals cashing out through money mule accounts.
- ·Current FATF baseline standards focus on anti-money laundering compliance but do not explicitly address fraud prevention, leaving exchanges liable only for procedural failures rather than scams occurring on their platforms.
- ·The Philippines' 2024 Anti-Financial Account Scamming Act and Thailand's 2025 Emergency Decree impose shared liability on exchanges for customer losses and mandate real-time fraud detection systems.
- ·Effective regional action requires three measures: explicit mandates for scam and mule prevention, shared liability frameworks that create financial consequences for exchanges, and cross-border blacklist infrastructure for flagged addresses.
The Gateway Problem
Crypto exchanges are the infrastructure that makes Southeast Asia's $40 billion annual scam economy possible. These platforms serve as both entry points where victims send money to fraudsters and exit ramps where criminals convert stolen digital assets into cash through networks of money mule accounts. Yet regulation across the region remains anchored to a global framework designed for a different problem.
The scale of enforcement in 2025 revealed the depth of the crisis. Former Philippine mayor Alice Guo faced 62 money laundering charges linked to major scam compounds. Cambodian-Chinese national Chen Zhi was indicted for running forced labor scam operations in Cambodia and allegedly laundering over $15 billion in Bitcoin. Thailand seized roughly $300 million in assets connected to scam networks. The UN Office on Drugs and Crime now estimates hundreds of thousands of people are trafficked to operate these criminal enterprises across Southeast Asia.
Indonesia's Indodax, Thailand's Bitkub, and similar platforms handle legitimate cryptocurrency trading. But their core function also enables users to move digital assets across blockchains without identity checks, creating the infrastructure scammers exploit. The regulatory gap is clear: exchanges face consequences for procedural compliance failures, but not for the fraud that happens on their platforms.
What the Current Rules Actually Do
Five major Southeast Asian economies have adopted the Financial Action Task Force recommendations for Virtual Asset Service Providers. The FATF framework focuses on preserving financial system integrity through anti-money laundering and counter-terrorism financing controls. Countries implement registration systems, conduct inspections, require customer due diligence and transaction monitoring, and mandate suspicious activity reports.
The framework uses a risk-based approach that gives exchanges flexibility to design their own compliance measures. This contrasts with rigid rule sets and theoretically allows platforms to allocate resources where risks are highest. FATF also requires the Travel Rule, which mandates that sending institutions transmit transaction details including sender and recipient information to receiving institutions, curtailing anonymous transfers.
Indonesia, Malaysia, the Philippines, Singapore, and Thailand have implemented nearly all baseline requirements. Thailand was the final holdout on the Travel Rule until Prime Minister Anutin Charnvirakul directed the Securities and Exchange Commission to enforce it in January 2026. The Thai SEC released implementation plans in March after public consultation.
Singapore and the Philippines exceed minimum standards in specific areas. Singapore explicitly requires exchanges to assess risks from anonymity-enhancing technologies like privacy coins and mixers, and mandates verification of customer ownership for self-hosted wallet transactions. The Philippines requires enhanced due diligence whenever customers transact with self-hosted wallets.
The problem is what these rules do not address. FATF recommendations do not explicitly target scams or the money mule accounts that allow criminals to cash out. National risk assessments across the region identify these as significant money laundering typologies, and exchanges are expected to adjust policies accordingly. But year-over-year growth in crypto scams demonstrates the framework is insufficient. Exchanges face liability for compliance failures like inadequate suspicious transaction reports, which occur after criminal activity has already happened. The mandate to preserve financial system integrity is not the same as preventing fraud or protecting victims.
The Philippine and Thai Models
Two countries have moved beyond the baseline with regulations directly targeting scam prevention and imposing consequences on exchanges for customer losses.
The Philippines' 2024 Anti-Financial Account Scamming Act requires regulated financial institutions, including crypto exchanges, to implement fraud risk management systems that identify and block suspicious or fraudulent transactions in real time. These systems must analyze transaction velocity and thresholds, account information changes, geolocation data, and behavioral anomalies. The law specifies continuous data analysis, risk assessments, adaptive rule adjustments, and proactive monitoring of fraud patterns.
Thailand's 2025 Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes explicitly regulates exchanges to prevent money mule activity. The Ministry of Digital Economy and Society estimates over one million mule accounts operate in Thailand. The decree established the Technology Crime Suppression Centre with expanded powers, replacing the former Anti-Online Scam Operation Centre. Exchanges must compare customer activity against a blacklist of blockchain addresses associated with cybercrimes, managed by the new agency.
The most significant provision in both frameworks is shared liability. The Philippine law holds exchanges jointly liable with account holders and third parties for customer losses from money mule and account takeover activity when losses are attributable to non-compliance with anti-scam regulations. Thailand's decree holds exchanges liable for customer losses from technological crimes including scams unless they prove compliance with prevention standards set by authorities.
This shifts the incentive structure fundamentally. Under FATF alone, exchanges optimize for procedural compliance and face regulatory penalties for violations. Under shared liability, exchanges face direct financial consequences for fraud that occurs on their platforms. The cost-benefit calculation changes: investing in sophisticated scam detection and prevention becomes economically rational rather than discretionary.
Three Priorities for Regional Action
First, governments should expand the risk-based approach to explicitly require scam and money mule prevention measures. Current FATF guidelines give exchanges flexibility to assess risks and design controls, but this flexibility has not produced adequate protection. Regulators should mandate specific capabilities: real-time transaction analysis using velocity patterns, geolocation data, and behavioral anomalies; continuous monitoring of account activity against known fraud patterns; and systems to detect and freeze suspected money mule accounts before funds exit the platform.
The data exists to enable this. Exchanges have access to both publicly available blockchain data and proprietary platform information showing customer behavior, transaction patterns, and network relationships. The challenge is not technical capability but regulatory mandate and enforcement priority. Making scam prevention an explicit compliance requirement removes ambiguity about what exchanges are expected to deliver.
Second, shared liability frameworks should be adopted across the region. The Philippines and Thailand have demonstrated the model. When exchanges face financial consequences for customer losses attributable to inadequate prevention, they allocate resources differently. The framework must include clear standards for what constitutes adequate prevention so exchanges understand their obligations and can defend compliance. But the principle of shared accountability is sound: platforms that profit from transaction volume should bear responsibility for ensuring those transactions are legitimate.
Third, Southeast Asian countries should build regional blacklist infrastructure for flagged blockchain addresses and known money mule accounts. Thailand's Technology Crime Suppression Centre maintains a domestic blacklist, but scam networks operate across borders. A regional system would allow exchanges in one country to screen transactions against addresses flagged by authorities in another. This requires data sharing agreements, common technical standards, and coordination mechanisms.
Singapore's position as a financial hub gives it convening power. The Monetary Authority of Singapore has demonstrated technical sophistication in digital asset regulation and could facilitate regional coordination. The ASEAN framework provides existing institutional channels for cooperation on financial crime. The question is political will and resource allocation.
The Enforcement Gap
Regulation only matters if enforced. Myanmar is on the FATF blacklist; Laos and Vietnam remain on the grey list subject to increased monitoring. These classifications create incentives to implement proper controls to participate in the global financial system. But implementation on paper and operational reality diverge.
Exchanges in countries with weaker enforcement can become preferred channels for illicit activity even if regulations exist. This creates competitive pressure: exchanges in jurisdictions with strict enforcement face higher compliance costs than those in jurisdictions where rules are not rigorously applied. Regional coordination on enforcement standards, not just regulatory text, is necessary to prevent regulatory arbitrage.
The 2025 enforcement wave demonstrates that authorities can act when political will exists. The challenge is sustaining that will and building institutional capacity for ongoing monitoring and intervention. Crypto scam networks are adaptive. They shift operations across borders, exploit new technologies, and adjust tactics in response to enforcement. Regulatory frameworks must be equally adaptive, with mechanisms for rapid updates as new typologies emerge.
What Success Requires
Effective regulation of crypto exchanges requires three elements working together: clear mandates for scam prevention and money mule detection, financial liability that aligns exchange incentives with customer protection, and regional coordination that prevents criminals from exploiting jurisdictional gaps.
The current FATF baseline was designed for a different set of risks. It addresses money laundering and terrorism financing through procedural controls and suspicious activity reporting. Those remain important, but they do not directly tackle the fraud infrastructure that enables Southeast Asia's $40 billion annual scam economy.
The Philippines and Thailand have shown what stronger regulation looks like. Other governments in the region should examine these models and adapt them to their own contexts. The data and technical capability to identify and prevent scam transactions exist. What is required is the regulatory mandate to compel exchanges to use that capability and the enforcement capacity to ensure compliance.
Crypto exchanges are not neutral infrastructure. They are gatekeepers that can either enable or obstruct criminal networks. Making them active participants in scam prevention rather than passive compliance checkboxes is the next necessary step in Southeast Asia's fight against digital fraud.
RELATED STORIES
Spot something wrong? Email editor@briefasia.com. We log every correction publicly.



