Skip to content
POST /v1/eventsRequest access
Detection

Crypto & cross-border

For remittance companies, stablecoin payment firms, exchanges and on/off-ramps: every amount compared in one currency, every corridor known, every wallet screened.

One currency for the rules

Send each amount in the currency it moved in. Sieve converts it to your workspace currency before any rule runs, so a USD 1,000 transfer and a KES or NGN 1,000 top-up are never confused, and thresholds such as CBK’s KES 1M line in Kenya or the NFIU’s NGN 5M line in Nigeria apply across currencies. The original amount, the rate and its source are stored with the event and returned in the response.

A USD remittance on a KES workspace
// A USD remittance from Nairobi to Kampala, on a KES workspace.
const d = await sieve.events.create({
  type: 'transaction',
  customer_id: 'cus_2044',
  direction: 'out',
  amount: 800,
  currency: 'USD',            // converted to KES for the rules; the original is kept
  method: 'bank',
  counterparty: { name: 'Grace Nakato', account: 'UG-STANBIC-00419', country: 'UG' },
})
// d.amount → { value: 103728.68, currency: 'KES', original: { value: 800, currency: 'USD' }, fx_rate: 129.66, fx_source: 'open.er-api.com' }

Rates come from your own entries in Settings → Currencies first, then a daily feed, then a bundled table so a new workspace works immediately. If a currency has no rate, the event is still scored and the response carries a warnings entry saying so.

Crypto transfers

Crypto withdrawal and deposit
// A customer withdraws 350.25 USDT on Tron to an exchange-hosted wallet.
const d = await sieve.events.create({
  type: 'payout.requested',
  customer_id: 'cus_1001',
  // The fiat value: every rule scores this (converted to your workspace currency if needed).
  amount: 350.25,
  currency: 'USD',
  method: 'crypto',
  // The on-chain amount, at full precision.
  asset: { code: 'USDT', amount: 350.25, network: 'tron' },
  destination: { type: 'crypto_wallet', account: 'TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t', network: 'tron', country: 'AE' },
  balance: 360,
  // FATF Travel Rule data (stored encrypted). Required above the threshold.
  travel_rule: {
    originator: { name: 'Wanjiru Kamau', account: 'cus_1001', country: 'KE' },
    beneficiary: { name: 'Wanjiru Kamau', address: 'TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t' },
    beneficiary_vasp: 'Example Exchange FZE',
  },
})
// d.wallet → { chain: 'tron', valid: true, network_matches: true, sanctioned: false, … }

// Deposits are transactions with the same shape; the source wallet goes in counterparty.wallet.
await sieve.events.create({
  type: 'transaction',
  customer_id: 'cus_1001',
  direction: 'in',
  amount: 128000,
  currency: 'KES',
  method: 'crypto',
  asset: { code: 'BTC', amount: 0.0153421, network: 'bitcoin' },
  counterparty: { wallet: 'bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq' },
})
  • Address checks. Bitcoin, Ethereum and EVM chains, Tron, Solana, XRP, Litecoin, Dogecoin, Bitcoin Cash and more are recognised, with checksums verified where the format has one.
  • Sanctioned wallets. OFAC and OpenSanctions name crypto addresses alongside people. Sieve indexes every listed address when the lists sync (over a thousand on the OFAC list alone) and blocks any transfer to or from one. This rule can’t be switched off.
  • On-chain risk (optional). Connect Chainalysis’ free sanctions API, or TRM, Elliptic or your own analytics through a small adapter, and wallets exposed to mixers, scams, hacks or darknet markets are flagged. Verdicts are cached for a day, and a slow provider never delays a decision.

The Travel Rule

FATF Recommendation 16 expects originator and beneficiary information to travel with crypto transfers above a threshold (USD 1,000 equivalent by default; editable on the rule). In Kenya the VASP Act applies to crypto businesses; in Nigeria, virtual asset service providers are regulated by SEC Nigeria. Check the exact obligations and threshold with your regulator. Send it in travel_rule; it is stored encrypted. Transfers above the threshold without it, or with gaps, are flagged with exactly what is missing. Set self_hosted: true when the other side is an unhosted wallet, so no counterparty VASP is expected.

Rules

Sanctioned crypto walletBlocks transfers to or from a listed address.
High-risk wallet exposureYour analytics provider rates the wallet medium or high risk.
Cash in, crypto straight outMost of the money paid in by mobile money (M-Pesa, OPay…), card or bank leaves as crypto within hours.
Many new wallets in a short timeFunds split across fresh wallets, the start of a peel chain.
Wallet address doesn’t fit the networkA Tron address on an Ethereum withdrawal, or a failed checksum: lost funds or clipboard malware.
Travel Rule information missingAbove the threshold without originator and beneficiary details.
Country under comprehensive sanctionsCuba, Iran, North Korea, Syria: blocked for review by default.
High-risk countryFATF call-for-action and increased-monitoring lists, plus your own. Your home country is never flagged against itself.
Large first transfer to a new countryA customer who always sends to Uganda suddenly sends a large sum to a new country.
Money spread across many countriesSeveral corridors in a day: layering.

Two preset patterns combine them: Crypto cash-out (new money leaving as crypto to a fresh wallet on a new account) and Cross-border layering (funds gathered from many senders and pushed out across borders). The FATF lists are dated in Settings; review them after each FATF plenary.