Crypto & cross-border
For remittance companies, stablecoin payment firms, exchanges and on/off-ramps: every amount compared in one currency, every corridor known, every wallet screened.
One currency for the rules
Send each amount in the currency it moved in. Sieve converts it to your workspace currency before any rule runs, so a USD 1,000 transfer and a KES or NGN 1,000 top-up are never confused, and thresholds such as CBK’s KES 1M line in Kenya or the NFIU’s NGN 5M line in Nigeria apply across currencies. The original amount, the rate and its source are stored with the event and returned in the response.
// A USD remittance from Nairobi to Kampala, on a KES workspace. const d = await sieve.events.create({ type: 'transaction', customer_id: 'cus_2044', direction: 'out', amount: 800, currency: 'USD', // converted to KES for the rules; the original is kept method: 'bank', counterparty: { name: 'Grace Nakato', account: 'UG-STANBIC-00419', country: 'UG' }, }) // d.amount → { value: 103728.68, currency: 'KES', original: { value: 800, currency: 'USD' }, fx_rate: 129.66, fx_source: 'open.er-api.com' }
Rates come from your own entries in Settings → Currencies first, then a daily feed, then a bundled table so a new workspace works immediately. If a currency has no rate, the event is still scored and the response carries a warnings entry saying so.
Crypto transfers
// A customer withdraws 350.25 USDT on Tron to an exchange-hosted wallet. const d = await sieve.events.create({ type: 'payout.requested', customer_id: 'cus_1001', // The fiat value: every rule scores this (converted to your workspace currency if needed). amount: 350.25, currency: 'USD', method: 'crypto', // The on-chain amount, at full precision. asset: { code: 'USDT', amount: 350.25, network: 'tron' }, destination: { type: 'crypto_wallet', account: 'TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t', network: 'tron', country: 'AE' }, balance: 360, // FATF Travel Rule data (stored encrypted). Required above the threshold. travel_rule: { originator: { name: 'Wanjiru Kamau', account: 'cus_1001', country: 'KE' }, beneficiary: { name: 'Wanjiru Kamau', address: 'TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t' }, beneficiary_vasp: 'Example Exchange FZE', }, }) // d.wallet → { chain: 'tron', valid: true, network_matches: true, sanctioned: false, … } // Deposits are transactions with the same shape; the source wallet goes in counterparty.wallet. await sieve.events.create({ type: 'transaction', customer_id: 'cus_1001', direction: 'in', amount: 128000, currency: 'KES', method: 'crypto', asset: { code: 'BTC', amount: 0.0153421, network: 'bitcoin' }, counterparty: { wallet: 'bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq' }, })
- Address checks. Bitcoin, Ethereum and EVM chains, Tron, Solana, XRP, Litecoin, Dogecoin, Bitcoin Cash and more are recognised, with checksums verified where the format has one.
- Sanctioned wallets. OFAC and OpenSanctions name crypto addresses alongside people. Sieve indexes every listed address when the lists sync (over a thousand on the OFAC list alone) and blocks any transfer to or from one. This rule can’t be switched off.
- On-chain risk (optional). Connect Chainalysis’ free sanctions API, or TRM, Elliptic or your own analytics through a small adapter, and wallets exposed to mixers, scams, hacks or darknet markets are flagged. Verdicts are cached for a day, and a slow provider never delays a decision.
The Travel Rule
FATF Recommendation 16 expects originator and beneficiary information to travel with crypto transfers above a threshold (USD 1,000 equivalent by default; editable on the rule). In Kenya the VASP Act applies to crypto businesses; in Nigeria, virtual asset service providers are regulated by SEC Nigeria. Check the exact obligations and threshold with your regulator. Send it in travel_rule; it is stored encrypted. Transfers above the threshold without it, or with gaps, are flagged with exactly what is missing. Set self_hosted: true when the other side is an unhosted wallet, so no counterparty VASP is expected.
Rules
| Sanctioned crypto wallet | Blocks transfers to or from a listed address. |
| High-risk wallet exposure | Your analytics provider rates the wallet medium or high risk. |
| Cash in, crypto straight out | Most of the money paid in by mobile money (M-Pesa, OPay…), card or bank leaves as crypto within hours. |
| Many new wallets in a short time | Funds split across fresh wallets, the start of a peel chain. |
| Wallet address doesn’t fit the network | A Tron address on an Ethereum withdrawal, or a failed checksum: lost funds or clipboard malware. |
| Travel Rule information missing | Above the threshold without originator and beneficiary details. |
| Country under comprehensive sanctions | Cuba, Iran, North Korea, Syria: blocked for review by default. |
| High-risk country | FATF call-for-action and increased-monitoring lists, plus your own. Your home country is never flagged against itself. |
| Large first transfer to a new country | A customer who always sends to Uganda suddenly sends a large sum to a new country. |
| Money spread across many countries | Several corridors in a day: layering. |
Two preset patterns combine them: Crypto cash-out (new money leaving as crypto to a fresh wallet on a new account) and Cross-border layering (funds gathered from many senders and pushed out across borders). The FATF lists are dated in Settings; review them after each FATF plenary.