Go back to Blog
Jennifer Edidiong
Marketing
11 min read
Share to
Wallet Fraud vs Account Fraud: What Crypto Platforms Must Monitor Post-Onboarding

Crypto fraud on African platforms rarely looks the same twice. One incident starts with a compromised login. Another involves a wallet address that has touched sanctioned funds across three chains. A third involves an account that passed every KYC check but has quietly accumulated and dispersed funds in patterns no single transaction would flag.
The common thread is the point of failure: monitoring that stops at onboarding.
87.5% of Nigerian fintechs already deploy AI for fraud detection, according to the CBN Fintech Report 2025. That signals how serious the fraud environment has become. For platforms operating as licensed VASPs under SEC Nigeria's ARIP framework, this is not just a fraud prevention best practice. Continuous monitoring is part of what SEC's ongoing compliance assessment looks at, and platforms that stop at onboarding verification carry a gap that regulators can and do scrutinise.
While onboarding confirms identity, it cannot confirm intent, and it cannot track what happens after an account goes live. That is where the real fraud exposure sits, and where most platforms are underbuilt.
This article breaks down the two distinct fraud surfaces crypto platforms need to monitor, how they differ, and what a complete detection approach actually looks like.
Account Fraud in Crypto: When the Identity Layer Is the Target

Account fraud targets the verified identity behind a crypto account. The goal is to compromise an existing account, or create one with fraudulent credentials, then use it to move funds, access liquidity, or build a reputation that enables further fraud.
The four patterns that appear most frequently on African crypto platforms:
Account takeover via credential theft or SIM swap: A legitimate user's account is accessed by someone else, either through phishing, credential stuffing, or a SIM swap that reroutes OTP delivery. The attacker gains access to a verified account and can act on it immediately. The account itself passes every identity check because it did, once, belong to a real, verified person.
Synthetic identity creation: A fraudster creates a plausible identity using a combination of real and fabricated data, then passes KYC at onboarding. The synthetic identity may look indistinguishable from a genuine one at the point of verification. Detection requires monitoring behaviour after the account is active, since synthetic accounts often show patterns that genuine users do not.
Mule account recruitment: A real person, fully verified, is recruited or coerced into opening an account that will be used to receive and pass through stolen funds. The KYC check confirms the mule's identity accurately. The fraud is in how the account is used, not who opened it.
Coordinated account farms: Multiple accounts are created, often across different platforms, using a shared pool of identity data or low-cost farmed credentials. Each account individually may look legitimate. The fraud pattern only becomes visible when accounts are viewed in relation to each other, through shared device signals, coordinated transaction timing, or overlapping beneficiary networks.
Also see:Â How African fintechs can prevent account takeover fraud in 2026
Wallet Fraud in Crypto: When the On-Chain Layer Is the Target

Wallet fraud operates at the transaction and asset layer, targeting the movement of funds rather than the identity behind the account. Because blockchain transactions are public and traceable, wallet fraud often involves deliberate obfuscation, mixing, or layering designed to break the connection between funds and their origin.
The four patterns that appear most frequently on African crypto platforms:
Sanctioned wallet interaction: A user transacts with a wallet address that appears on OFAC or other sanctions lists, either directly or through intermediate hops. The user may not know the counterparty is sanctioned, or may be doing it intentionally. Either way, the platform is exposed if it processes the transaction without screening.
Mixing and layering through unhosted wallets: Funds move through a series of unhosted wallets or mixing services designed to obscure their origin before arriving at a platform. By the time funds reach a custodied account, the on-chain trail connecting them to a flagged source may be several hops removed from anything immediately visible.
Wash trading and artificial volume: A user or coordinated group of users trades between their own wallets to generate artificial transaction volume, inflate perceived liquidity, or manipulate price signals. The trades are real on-chain, but the economic activity is circular and does not represent genuine market participation.
Rug pull and exit scheme deposits: Funds originating from fraudulent schemes, rug pulls, exit scams, or other on-chain fraud are deposited into a platform account before the fraud is publicly identified. The platform becomes the off-ramp for illicit funds without any single transaction appearing anomalous at the time.
Related:Â How to implement automated transaction monitoring for crypto platforms
Where Account and Wallet Fraud Overlap (The Highest-Risk Scenario)?

The most dangerous fraud scenario your platform will face isn’t just a stolen password or a flagged wallet. It’s the double-threat overlap, when a verified identity is used to move illicit funds. You’re not just dealing with a bad actor, but a coordinated operation using a trusted account to bypass your controls.
Here are three practical ways this shows up on African exchanges today:
- The SIM Swap and Flagged Wallet Combo
A long-time user suddenly changes their phone number. Shortly after, a large crypto deposit arrives from a flagged source and is quickly withdrawn. If you only track the identity change, you miss the wallet risk. By the time it’s flagged, the funds are gone. - Mule Accounts with Real Identities
A real user passes KYC with a valid ID but is working with a fraud ring. They use their verified account to move illicit funds at scale. Because the identity is legitimate, static checks won’t catch this. Behavioral shifts are often the only signal. - Dormant Verified Accounts as Routing Hubs
Fraudsters target inactive but verified accounts. Instead of immediate withdrawals, they use these accounts to route funds across wallets. These accounts are rarely monitored closely after onboarding, which makes them ideal for abuse.
Monitoring only the who (account) or only the what (wallet) leaves gaps. To scale safely, platforms need a unified view of identity and fund movement together.
Post-Onboarding Fraud Detection: What You Should Actually Monitor

To build a resilient platform, you have to move away from the "set it and forget it" mindset of onboarding. Effective post-onboarding fraud detection for crypto requires a dual-track monitoring system that watches both the person and the assets they move.
Account-Level Fraud Signals to Monitor
These signals focus on the user’s digital footprint and access points. A change here usually suggests that the account is no longer in the hands of the original owner.
| Signal | What it Indicates | Risk Level |
| Device or Session Change | Login from an unrecognized device ID, browser, or a high-risk IP range (e.g., a known VPN). | Medium |
| Login Velocity | A sudden spike in failed login attempts followed by a successful one, or logins from two different geographic locations within minutes. | High |
| Dormancy to High Activity | A verified account that has been silent for months suddenly attempts a maximum-limit transaction. | High |
| Profile Updates | Changes to sensitive data (email, phone, or password) immediately followed by a withdrawal request. | Critical |
| SIM Swap Events | Real-time telco signals indicating that the user's SIM card was recently replaced or ported. | Critical |
Wallet & Transaction-Level Fraud Signals
These signals focus on the flow of money. Even if the login seems legitimate, these patterns suggest the funds themselves are tied to illicit activity.
| Signal | What it indicates | Risk Level |
| Flagged Source Wallet | Funds entering your platform from addresses associated with hacks, scams, or sanctioned entities. | Critical |
| Structuring Patterns | Multiple small deposits or withdrawals specifically designed to stay beneath reporting or manual review thresholds. | Medium |
| Rapid Off-Platform Movement | Funds are withdrawn to a private, unhosted wallet almost immediately after arriving, leaving no time for review. | High |
| Chain-Hopping | Repeated, rapid swapping between different blockchains (e.g., BTC to SOL to XMR) to break the audit trail. | High |
| Withdrawal/Deposit Anomalies | A sudden, massive spike in volume that does not match the user's historical transaction behavior or tier. | Medium |
Â
The Strategic Takeaway: You shouldn't block an account based on one Medium signal, but you should absolutely trigger a manual review or a step-up verification when two or more signals overlap.Â
When to Trigger a Fraud Response
Detecting a signal is only half the battle; the real test is how your platform responds.
Here is a practical framework for deciding when to intervene:
1. Low-Confidence Alerts: Trigger Step-Up Verification
When you see a single, isolated signal, like a login from a new device or an IP address in a different city, don't jump to a block. Instead, apply friction through step-up authentication.
- The Action: Require a biometric liveness check or a face match against their original KYC document.
- The Goal: Confirm the real account owner is still in control without locking them out of their funds.
2. Combined Signals: Place a Transaction Hold
If you see two or more signals overlapping—for example, a device change followed by a sudden attempt to move funds to a new beneficiary—the risk level moves from suspicious to likely.
- The Action: Place a temporary 24-hour hold on the transaction. Notify the user via an out-of-band channel (like email) that the move is under review.
- The Goal: Buy your fraud team time to investigate. Most account takeovers happen within minutes of a compromise; a 24-hour delay is often enough to stop the theft.
3. High-Confidence Threats: Immediate Suspension and Review
When you hit a critical signal, such as a confirmed SIM swap or funds arriving directly from a sanctioned wallet address, you cannot afford to wait.
- The Action: Suspend the account immediately and restrict all outbound transfers. Flag the account for a full compliance and SAR (Suspicious Activity Report) review.
- The Goal: Protect the platform’s regulatory standing and prevent the further movement of illicit assets.
The goal of a response framework isn't to stop every transaction. It's to ensure that as the risk increases, the proof of identity required to complete the move also increases.
Dojah: Continuous Fraud Intelligence Across the Lifecycle

Most verification partners stop at onboarding. Dojah is built as an identity and risk infrastructure that continues working after the user is verified, when most fraud actually happens.
Instead of treating verification as a one-time check, Dojah helps you monitor identity, behavior, and fund movement across the entire user lifecycle.
- On the Account Side: We provide behavioral monitoring, SIM intelligence (to detect swaps), and session anomaly detection.
- On the Wallet Side: Our transaction monitoring and wallet screening tools detect patterns of illicit movement as they happen.
- Unified Visibility: Instead of 5 different tools, Dojah gives your fraud team a single view of the user’s identity and their fund movement.
Dojah helps you move from onboarding compliance to continuous fraud protection.
If you’re scaling your crypto platform and need better visibility into user risk, reach out to the Dojah team or book a demo today.Â
FAQs on Crypto Fraud Monitoring in Africa
1. What is the difference between account fraud and wallet fraud in crypto?
Account fraud involves unauthorized access to a legitimate user's account. Wallet fraud involves illicit fund movement, regardless of whether the account holder is the actual verified user. Both can occur independently or together.
2. Why is post-onboarding fraud a bigger risk than onboarding fraud?
KYC controls verify identity at a single point in time. Post-onboarding fraud exploits the monitoring gap that follows, when credentials are stolen, accounts are taken over, or illicit funds are moved through verified accounts.
3. What makes African crypto platforms particularly vulnerable?
Weak telecom verification in key markets, heavy reliance on SMS OTPs, rapid user growth, and uneven regulatory enforcement create multiple entry points for both account and wallet fraud.
4. How does wallet screening work in practice?
Wallet screening checks deposit and withdrawal addresses against databases of flagged wallets linked to scams, darknet activity, sanctioned entities, and mixers. Platforms running screening in real time can block illicit funds before they enter or leave the platform.
5. Can one platform handle both account and wallet fraud monitoring?
Yes. Platforms like Dojah combine behavioral monitoring for account-level anomalies with transaction monitoring and wallet screening, providing unified fraud visibility across both layers simultaneously.
Â
This article was originally published in April 2026 and updated in September 2026 to add SEC regulatory context for licensed VASPs.
Start using Dojah for all your business needs