SardineCon SF/2026

Learn More
Crypto & blockchain crime4 分で読めます

Nested exchangeとは?

SUBSCRIBE

A nested exchange is a business that offers trading to its own customers by operating through accounts it holds at a larger host exchange, so its clients' activity hides behind the host's onboarding. These services often run weak or no KYC of their own, creating a laundering channel inside an otherwise compliant venue.

What is a nested exchange, in plain English?

A nested exchange is a small crypto business that does not connect to the blockchain on its own. Instead, it opens one or more accounts at a bigger host exchange and runs its own trading service through them. Its customers deposit and withdraw, but on the host's books all of that activity appears to belong to the nested service's accounts, not to the individual clients behind them.

The problem is that the nested service often does weak or no KYC on its own customers. So people who could never pass the host's checks get access to the host's liquidity anyway, with their identities hidden one layer down. The nested exchange effectively becomes a laundering channel operating inside a compliant venue, borrowing the host's legitimacy while stripping out the controls.

Crucially, the host sees the accounts, not the end customers, so the host has to detect the nesting itself. From the outside it can look like one very busy customer. The way to spot it is behavior: a single account that acts like a mini-exchange, with many counterparties and high pass-through volume that makes no sense for one individual.

How a nested exchange operates

  1. Open — Account at a host. The nested service opens accounts at a larger, compliant host exchange.
  2. Onboard — Take its own customers. It signs up clients with weak or no KYC, whom the host never sees.
  3. Route — Funnel activity through. Client deposits and trades flow through the nested service's host accounts as if they were its own.
  4. Hide — Identities stay masked. The host records the service's accounts, not the individuals, so the real clients stay hidden.

Who is involved?

Who

Their role

The nested service

Runs a mini-exchange through host accounts, often with weak or no KYC of its own.

The host exchange

Holds the accounts and must detect the nesting, since it never sees the end clients.

The hidden customers

Trade through the nested service, shielded from the host's onboarding checks.

The analyst

Looks for accounts behaving like exchanges: many counterparties, high pass-through volume.

What it looks like in practice

In practice

A compliance team at a host exchange reviews one customer account and notices it behaves nothing like an individual. It sends to and receives from hundreds of unrelated counterparties, moves large volumes straight through with little sitting balance, and shows deposit and withdrawal patterns that look like a business serving many users.

Digging in, they conclude the account is a nested exchange: a separate service running its own thinly checked customers through the host's rails. Because the host only ever saw one account, the nesting was invisible until its exchange-like behavior gave it away. The team offboards it and reviews the flows it carried.

Why it matters to operators

Nested exchanges defeat the assumption that a compliant venue means clean accounts inside it. The host may have strong KYC, but a nested service quietly pipes in customers who never faced those checks, so the host ends up carrying laundering risk it cannot see at onboarding. The exposure hides behind the host's own good name, which is exactly what makes it dangerous.

The operator takeaway is that hosts must actively hunt for nesting rather than trust their front-door checks. Since the end clients are invisible, detection has to come from behavior: accounts that act like mini-exchanges, with many counterparties and high pass-through volume that make no sense for a single person. Never assume a compliant host means every account inside it is clean.

What to watch in the data

  • Exchange-like account behavior. A single account with many counterparties and high pass-through volume behaves like a business, not an individual.
  • Low resting balance. Funds moving straight through with little sitting balance suggests a service routing others' money.
  • Broad, unrelated counterparties. Sending to and receiving from hundreds of unconnected addresses is a mini-exchange signature.
  • Weak downstream attribution. Flows that trace to low-KYC or illicit sources arriving through one host account.
  • Patterns inconsistent with the stated customer. Activity far beyond what the onboarded identity should plausibly generate.

Quick questions

How is a nested exchange different from a high-risk exchange?

A high-risk exchange is a standalone venue with weak controls. A nested exchange operates inside a larger host by holding accounts there, hiding its clients behind the host's onboarding. Nesting is a structure; high-risk is a broader risk label that a nested service usually also carries.

Why can't the host just KYC the real customers?

Because it never sees them. The host only knows the nested service's accounts, not the individuals trading through them. That is the whole point of the arrangement, and it is why the host must detect the nesting from account behavior instead.

What behavior gives a nested exchange away?

Acting like a mini-exchange: many unrelated counterparties, high pass-through volume, low resting balance, and deposit and withdrawal patterns that fit a business serving many users rather than one person.

Is running a nested service always illegal?

Not automatically, but doing so with weak or no KYC while riding a compliant host's rails creates serious laundering risk and often breaches the host's terms and AML expectations. The missing controls are the core problem.

How does it relate to a parasite exchange?

The ideas overlap: both live off a host's infrastructure while running their own weak controls. Nested specifically means operating through accounts held at the host. Parasite is a related label for venues that similarly depend on a host to function.

What should a host do when it finds one?

Investigate the account's flows, offboard the nested service, and review the activity it carried for illicit exposure and reporting obligations. Then tune monitoring to catch exchange-like behavior earlier in other accounts.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • OFAC, US Treasury ↗ — Administers US sanctions programs, the SDN list, and licensing.

Nested exchangeと併せて知っておきたい用語