Stolen-Funds Payment
Pronunciation: STOH-luhn fuhndz PAY-muhnt
Also known as: Payment Involving Stolen Crypto
Definition
A stolen-funds payment is a cryptocurrency payment that contains assets reasonably linked to theft, account compromise, fraud, ransomware, an exploit, or another unauthorized taking. The classification concerns the suspected origin or control history of the assets, not whether the blockchain transfer itself was technically valid. It differs from tainted funds, a broader and less precise label for assets associated with risky activity. It also differs from a fraudulent payment, where the payer may be deceiving the merchant even if the funds are not known to be stolen.
Overview
A stolen-funds payment is a cryptocurrency payment that contains assets reasonably linked to theft, account compromise, fraud, ransomware, an exploit, or another unauthorized taking. The classification concerns the suspected origin or control history of the assets, not whether the blockchain transfer itself was technically valid.
It differs from tainted funds, a broader and less precise label for assets associated with risky activity. It also differs from a fraudulent payment, where the payer may be deceiving the merchant even if the funds are not known to be stolen. Related operational concepts include Tainted-Funds Payment, Suspicious Crypto Payment, and Crypto Payment Wallet Screening. They should remain connected through identifiers and evidence without being treated as the same payment state, control, or financial result.
A merchant should document the data source, exposure path, timing, confidence, and applicable policy before deciding to hold, reject, report, or refund. The label should be produced by a documented risk process rather than by intuition or a single vendor score. The authoritative record for Stolen-Funds Payment should also show the rule version, responsible system, permitted state transition, and any downstream action such as fulfillment, settlement, refund, or manual review.
The label should be produced by a documented risk process rather than by intuition or a single vendor score. A match is a reason for proportionate review, not automatic proof of criminal ownership, and decisions should follow applicable law and the merchant’s risk policy. Testing should cover duplicated and out-of-order events, incorrect asset or network data, late transactions, provider outages, retries after uncertain responses, and manual intervention after one subsystem has already changed state. Specific scope: a cryptocurrency payment that contains assets reasonably linked to theft, or another unauthorized taking.
Governance should connect Stolen-Funds Payment to the original obligation, payment instructions, observed transaction, internal state, financial posting, and any fulfillment or refund. The decisive principle remains that a stolen-funds payment is a cryptocurrency payment that contains assets reasonably linked to theft, account compromise, fraud, ransomware, an exploit, or another unauthorized taking.
Key Takeaway
A stolen-funds payment is a cryptocurrency payment that contains assets reasonably linked to theft, account compromise, fraud, ransomware, an exploit, or another unauthorized taking.
Sources
- Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing — Financial Action Task Force (2026-08-02)
- Sanctions Compliance Guidance for the Virtual Currency Industry — U.S. Department of the Treasury, OFAC (2026-08-02)
- Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs — Financial Action Task Force (2026-08-02)