Coinbase’s €176 Billion AML Blind Spot: Irish Fine Raises Questions About the MiCA Handover to Luxembourg

Spread financial intelligence

The Central Bank of Ireland found that more than 30 million Coinbase Europe transactions escaped parts of its high-risk monitoring system. The case exposes not only coding defects, but failures in outsourcing oversight, escalation, regulatory disclosure and group-level compliance governance.

The Central Bank of Ireland’s €21.46 million sanction against Coinbase Europe Limited is one of the most significant European crypto enforcement cases to date. It is also considerably more complex than the frequently repeated narrative of a few technical coding errors.

The Irish regulator found that faults affecting five high-risk transaction-monitoring scenarios caused more than 30.4 million transactions worth approximately €176 billion to escape full and proper monitoring. These transactions represented around 31% of Coinbase Europe’s activity during the period in which the faults existed.

The sanction was agreed in November 2025 and confirmed by the Irish High Court on 12 January 2026. It was the Central Bank of Ireland’s first enforcement outcome involving the crypto sector.

However, the most important regulatory lesson extends beyond Ireland. While the enforcement investigation was underway, Coinbase secured a MiCA authorisation in Luxembourg and transferred its European crypto services from Coinbase Europe Limited to Coinbase Luxembourg S.A. The case therefore raises a broader post-MiCA question:

When a major crypto group migrates its European business from one regulated entity and jurisdiction to another, how effectively do historical control failures, supervisory findings and group-level governance risks travel with it?

Key Facts

IssueFinding
Sanctioned entityCoinbase Europe Limited, Ireland, company number 675475
Final fine€21,464,734
Pre-discount penalty€30,663,906
Monitoring failure30,442,437 transactions
Transaction valueApproximately €176 billion
Share of relevant activityApproximately 31%
Affected monitoring scenariosFive of 21 high-risk scenarios
Transactions requiring further review184,790, valued at approximately €3.6 billion
Suspicious transaction reports2,708 STRs covering more than €13 million
Current EEA crypto entityCoinbase Luxembourg S.A., MiCA authorisation N00000004
Current EEA e-money entityCoinbase Ireland Limited

The figures above are based on the Central Bank’s settlement notice, its enforcement announcement and Coinbase’s current European contractual documentation.

Important Entity Clarification

The recent Investigations.org report carries the headline “CB Payments Limited Fined €21.4m by Central Bank of Ireland.” Its own substantive reporting, however, correctly identifies Coinbase Europe Limited as the sanctioned entity. The official Irish enforcement documents leave no ambiguity: the respondent was Coinbase Europe Limited.

This distinction matters.

CB Payments Limited is a separate UK Coinbase entity. It was fined £3.5 million by the Financial Conduct Authority in 2024 for repeatedly breaching restrictions that prevented it from serving new high-risk customers. The Irish and UK actions involve different companies, regulators, legal provisions and facts.

What Failed Inside Coinbase’s Monitoring System

Coinbase Europe used a proprietary transaction-monitoring system operated by the US-based Coinbase Inc. under an intra-group outsourcing arrangement.

The system applied 21 monitoring scenarios to identify transactions potentially connected to high-risk activity. Five of those scenarios compared blockchain addresses against lists associated with high-risk or very-high-risk activity.

Three configuration problems prevented these five scenarios from correctly matching some customer transactions with relevant high-risk blockchain addresses. Coinbase has explained that, in one example, crypto addresses separated by special characters were overlooked.

Coinbase said it identified and corrected the coding problems within two to three weeks. The Central Bank acknowledged that the affected system operated correctly from 29 April 2022 onward.

That, however, did not resolve the regulatory breach.

The system defects had already allowed 30.4 million transactions to avoid the affected screening rules between April 2021 and April 2022. Retrospective screening subsequently produced:

  • 255,125 alerts requiring additional analysis;
  • 184,790 transactions requiring further review, worth approximately €3.6 billion; and
  • 2,708 suspicious transaction reports covering transactions worth more than €13 million.

The retrospective review was not completed until March 2025. Some suspicious transaction reports were therefore submitted months or even years after the relevant transactions occurred.

The €176 Billion Figure Requires Careful Interpretation

The €176 billion did not represent proven criminal proceeds or even transactions that were all considered suspicious. It represented the total value of transactions that had not been fully screened against the five affected high-risk monitoring scenarios. Following rescreening, approximately €3.6 billion of transactions required further review. The 2,708 STRs ultimately submitted had a combined value of more than €13 million.

The reported suspicions included potential connections to darknet activity, controlled substances, scams, theft, malware, ransomware, money laundering, illegal media services, child sexual abuse material and addresses connected with US sanctions controls.

The Central Bank expressly stated that it could not determine whether any of the reported transactions actually resulted in a criminal offence. An STR is a report of suspicion, not proof of criminality.

Why This Was More Than a Coding Error

Coinbase’s public response presents the matter primarily as three technical errors affecting five scenarios within a broader monitoring system.

The Central Bank’s settlement notice reveals a substantially wider governance problem.

Outsourcing did not remove local responsibility

Coinbase Europe outsourced significant parts of its transaction monitoring to Coinbase Inc. in the United States. The Irish entity nevertheless remained legally responsible for supervising that outsourced activity and complying with Irish AML legislation.

The Central Bank found that Coinbase Europe’s systems and controls were ineffective in overseeing the work performed by its US sister company. As a result, the Irish entity remained unaware of the full monitoring failure for an extended period.

The board and regulator were not promptly informed

Coinbase Europe received information in February 2023 that should have alerted it to the monitoring problem and the unfinished retrospective review.

Despite that information, the issue was not escalated to the Coinbase Europe board in May 2023, nor was the Central Bank informed at that stage. Senior management later became aware of the potential regulatory significance, but the board was not formally notified until 27 October 2023. The Central Bank was informed on 21 November 2023.

The regulator treated this delay as an aggravating factor.

The regulator had previously been told about a different backlog

During Coinbase Europe’s Irish VASP registration process, the company disclosed an alert backlog caused by rapid customer and transaction growth. It provided remediation plans and assurances concerning future compliance investment. The Central Bank granted the VASP registration in December 2022 partly on the basis of those assurances.

The high-risk screening failure was not disclosed during the registration process because Coinbase Europe said it was unaware of it at the time.

The regulator stressed that an operational backlog caused by growth was materially different from a monitoring system that failed to identify transactions involving addresses already classified as high or very high risk.

The Penalty Mechanics

The Central Bank classified the seriousness of the violations at seven on a scale of one to ten. Using average annual revenues of approximately €417.2 million, it calculated a base penalty of €29.2 million. The delayed regulatory notification produced a further 5% aggravating adjustment, increasing the amount to €30.66 million.

The regulator found no mitigating factors warranting a reduction at that stage. Coinbase then received the maximum 30% discount available under the undisputed-facts settlement process, resulting in the final €21.46 million sanction.

The Central Bank characterised the underlying conduct as negligent and said the breaches continued from April 2021 until completion of the remediation in March 2025.

A Transatlantic Coinbase Compliance Pattern

The Irish settlement notice expressly places the European failure in the context of earlier regulatory problems at Coinbase Inc. in the United States. In January 2023, the New York Department of Financial Services reached a $100 million settlement with Coinbase Inc., consisting of a $50 million penalty and a commitment to invest another $50 million in compliance improvements.

NYDFS found serious deficiencies in KYC, customer due diligence, transaction monitoring, suspicious activity reporting and sanctions controls. By late 2021, Coinbase had accumulated more than 100,000 unreviewed transaction-monitoring alerts and more than 14,000 customers awaiting enhanced due diligence. The Irish regulator stated that the Coinbase Inc. issues examined by NYDFS were at the root of the transaction-monitoring failures affecting Coinbase Europe.

A further enforcement action followed in the United Kingdom.

In July 2024, the FCA fined CB Payments Limited £3.5 million for serving 13,416 high-risk customers despite a regulatory restriction. Approximately 31% of these customers deposited around $24.9 million and subsequently executed crypto transactions through other Coinbase entities totalling approximately $226 million.

These are legally separate cases. They should not be conflated. Nevertheless, viewed together, they indicate recurring group-level themes:

  • compliance capabilities failing to keep pace with business growth;
  • weaknesses in the design and testing of automated controls;
  • insufficient oversight of group systems;
  • delayed identification or escalation of failures; and
  • regulated gateway entities depending on systems operated by other group companies.

From Ireland to Luxembourg

Coinbase obtained its MiCA authorisation from Luxembourg’s Commission de Surveillance du Secteur Financier in June 2025. Coinbase described Luxembourg as its new European crypto hub, allowing it to offer crypto services across all 27 EU Member States.

European customers were migrated in phases from Coinbase Europe Limited to Coinbase Luxembourg S.A. between August and October 2025. Austrian customers moved under the new structure on 22 September 2025, while Irish and German customers followed on 23 October 2025.

Under the current structure:

  • Coinbase Luxembourg S.A. provides crypto-asset services under MiCA authorisation N00000004;
  • Coinbase Ireland Limited continues providing e-money services under Irish supervision;
  • Coinbase Inc. operates the US-based Coinbase Exchange; and
  • Coinbase Europe Limited’s Irish VASP registration lapsed at the end of 2025 and the entity ceased conducting the relevant Irish business.

The Luxembourg authorisation was granted while the Irish enforcement investigation, opened in August 2024, was still in progress.

There is no evidence in the reviewed public material that the CSSF ignored the Irish matter or that Coinbase failed to disclose it during the Luxembourg authorisation process. Equally, the public materials do not explain how the Irish findings, the NYDFS action, the UK enforcement history and the group’s outsourcing architecture were assessed during the MiCA authorisation.

That is a legitimate supervisory-transparency question.

MiCA requires CASP applicants to provide detailed information about governance, internal controls and procedures for identifying and managing money-laundering and terrorist-financing risks. It also requires authorised CASPs to continue meeting their authorisation conditions.

FinTelegram Assessment

Compliance Radar: AMBER — Enhanced Monitoring

Coinbase is not an unregulated offshore crypto exchange. Its European crypto operations are now conducted through a MiCA-authorised Luxembourg entity, and the company says it has corrected the affected coding defects and significantly enhanced its monitoring and testing.

There is also no regulatory finding that the €176 billion of affected transactions represented criminal proceeds. However, the Irish enforcement action cannot reasonably be reduced to an isolated software defect. It exposed failures across several layers:

  1. transaction-monitoring configuration and validation;
  2. supervision of outsourced group systems;
  3. local management awareness;
  4. board escalation;
  5. communication with the regulator; and
  6. retrospective remediation capacity.

The connections drawn by the Central Bank between the Irish failure and Coinbase Inc.’s NYDFS compliance problems make this a group-governance case, not merely an Irish subsidiary case.

The migration to Luxembourg under MiCA does not erase that history. It places responsibility on the CSSF and Coinbase Luxembourg to demonstrate that the group systems supporting the new European hub are now independently validated, adequately supervised and capable of scaling without repeating earlier failures.

Open Regulatory Questions

FinTelegram considers the following questions relevant for Coinbase and the CSSF:

  • What information concerning the Irish enforcement investigation was provided to the CSSF before the June 2025 MiCA authorisation?
  • Did the CSSF independently test the transaction-monitoring scenarios and group systems used by Coinbase Luxembourg?
  • Which monitoring and compliance functions remain outsourced to Coinbase Inc. or other non-Luxembourg group companies?
  • What local oversight, audit and escalation rights does Coinbase Luxembourg exercise over those systems?
  • Has the NYDFS independent monitorship been formally concluded?
  • How are supervisory findings involving Coinbase entities in the US, UK and Ireland reflected in the ongoing supervision of the Luxembourg MiCA hub?
  • Were the Irish enforcement findings shared with other EEA regulators before customer migrations commenced?

Conclusion

The Coinbase case illustrates a central problem for crypto regulation under MiCA: sophisticated financial-crime controls are increasingly embedded in code and operated through cross-border group structures.

A regulated entity may possess extensive policies, compliance teams and monitoring systems while significant parts of those systems silently fail in production. For regulators, banks and counterparties, the lesson is straightforward:

The presence of a transaction-monitoring system is not evidence that transactions are actually being monitored.

The next phase of European crypto supervision must therefore focus less on whether controls exist on paper and more on whether they operate effectively, are continuously tested and remain visible to the locally responsible management body.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

9,906FansLike
48FollowersFollow
2,130FollowersFollow
- Advertisement -spot_img

Latest Articles