New: Hypersign is now eIDAS 2.0 ready verifiable credentials and EUDI Wallet compliance built in. See case studies →
← Back to Resources Crypto Casino KYC and AML: What Changes When a Gambling Operator Accepts Crypto
ComplianceCryptoiGaming

Crypto Casino KYC and AML: What Changes When a Gambling Operator Accepts Crypto

An online casino that accepts crypto deposits keeps every gambling-regulator obligation it already had and adds a second, activity-based layer on top: wallet screening, Travel Rule data, and a possible CASP threshold. What UKGC, MGA, and Curaçao's new LOK regime actually require once crypto enters the picture, and where the two compliance layers meet.

Hypersign Compliance Team·September 1, 2026·8 min read

An online casino that starts accepting crypto deposits does not swap one compliance regime for another. It keeps every obligation its gambling licence already imposed and adds a second set of obligations on top, the ones that attach to any business exchanging, transferring, or safekeeping virtual assets on behalf of a customer. Most vendor content treats "gambling KYC" and "crypto KYC" as separate categories, each with its own guide, because most vendors only sell into one of them. An operator that takes crypto deposits does not get to pick one.

That stacking is the actual compliance problem, not a hypothetical one. A licensee under the UK Gambling Commission or the Malta Gaming Authority has to verify identity and screen for risk before a customer gambles at all. A business handling virtual assets for a customer has to do that too, plus screen the wallet addresses the funds move through and, above certain thresholds, exchange originator and beneficiary data with the counterparty on the other end of the transfer. A crypto casino owes both sets of checks at once, on the same customer, in the same session.

What Gambling Regulators Require Before Crypto Enters the Picture

The baseline exists independent of payment method. Under LCCP Condition 17.1.1, a UK Gambling Commission licensee must obtain and verify a customer's identity, at minimum name, address, and date of birth, before that customer is permitted to gamble, not merely before a first withdrawal. The condition also bars an operator from demanding new identity information at withdrawal time if it could reasonably have asked for it earlier, and requires ongoing steps to keep the identity data it holds accurate.

The Malta Gaming Authority runs on a risk-based structure instead of a single fixed rule. Under joint MGA/FIAU customer due diligence guidance, every licensee has to assign each player a risk-based profile, apply enhanced due diligence automatically once a player's risk crosses a defined threshold, and run ongoing monitoring rather than a single check at registration. Neither regulator treats the payment rail as relevant to any of this. A crypto deposit does not lower the bar; it just adds a second bar next to it.

What a Crypto-Accepting Operator Adds on Top

The second layer follows a customer's crypto wallet, not their identity document. It runs on activity, the same test the Financial Action Task Force uses everywhere else in crypto, covered in more depth in what actually makes a business a VASP.

Sanctioned-wallet screening
Deposit and withdrawal addresses get screened against sanctioned-wallet lists as their own check, separate from identity verification. A player can pass every gambling-side KYC check and still route funds through a flagged address. See Crypto On-Ramp KYC + KYT for how buyer identity and wallet risk get screened together rather than as two disconnected steps.
Travel Rule data on qualifying transfers
Above the applicable jurisdictional threshold, a crypto-handling operator has to collect and be ready to exchange originator and beneficiary information under FATF Recommendation 16, the same requirement covered for VASPs generally in Crypto Travel Rule.
Possible CASP authorization in the EU
Accepting crypto as a deposit method does not by itself make an operator a crypto-asset service provider under MiCA. It becomes relevant only if the operator's own crypto-handling function meets the CASP activity test, running its own exchange or custody infrastructure rather than passing transactions through a third-party processor. See MiCA Crypto User Verification for what applies once that threshold is crossed.

None of these three replace the gambling-side identity and risk checks already in place. They run alongside them, against the same customer, often inside the same session.

Curaçao's New Regime Names Crypto Specifically

Curaçao replaced its old master-license system with the National Ordinance for Games of Chance, known as the LOK, enacted December 20, 2024 and regulated by the Curaçao Gaming Authority. The regulator's own site returns an access error to automated requests at the time of writing, so the detail below comes from licensing-consultancy summaries of the ordinance, not the CGA's own published text, and should be confirmed directly with the regulator before an operator relies on it for a filing.

Per that secondary reporting, the LOK requires risk-based customer due diligence at onboarding and at defined risk triggers, sanctions and PEP screening with ongoing rescreening, and mandatory disclosure of ultimate beneficial owners and key persons through a Personal History Disclosure Form. Crypto-accepting operators face an additional layer on top of that baseline: wallet-disclosure requirements and transaction monitoring specific to virtual-asset activity, named separately from the ordinary customer due diligence obligation rather than folded into it.

Where Sequencing Failures Actually Get Punished

Enforcement in this sector is not hypothetical, and it does not require a crypto angle to bite. Lithuania's Gaming Control Authority fined Olympic Casino Group Baltija close to €8.4 million in March 2025 after a former private equity fund manager, suspected of embezzling around €42 million from funds he managed, lost roughly €6.4 million gambling at the operator between 2016 and 2021. The regulator's finding was that Olympic Casino never adequately investigated the source of those funds, failed to file a suspicious activity report, and at one point offered the customer an incentive package worth €1.3 million to keep him gambling rather than escalate the account.

The case involved no crypto at all. It is included here because it shows what a gambling regulator actually inspects for: whether source-of-funds questions got asked when the pattern called for them, and whether a lucrative customer got a pass a smaller one would not have. A crypto-accepting operator inherits that exact same scrutiny on the gambling side, on top of the wallet-level and Travel Rule scrutiny that applies to the crypto side. Getting one layer right does not cover the other.

Where This Leaves an Operator Accepting Crypto Deposits

An operator already running a mature UKGC or MGA compliance program has most of the gambling-side baseline in place and needs to add the wallet-screening and Travel Rule layer, not rebuild identity verification from zero. An operator building both layers at once should treat them as one connected decision rather than two separate vendor searches, since a customer who fails wallet screening after passing gambling KYC is still a customer the operator has to act on, and a fragmented stack is where that handoff gets missed. Whether CASP authorization applies at all depends entirely on whether the operator's own crypto-handling function meets that activity test, not on the mere fact of accepting crypto as a payment method, and that determination is jurisdiction-specific enough that it is worth confirming with counsel before assuming either answer.

Questions About Crypto Casino Compliance

Does accepting crypto deposits change a casino's KYC requirements?

Yes, it adds requirements rather than replacing them. The gambling regulator's identity-verification and risk-profiling rules still apply exactly as before, and the operator now also owes wallet-address sanctions screening and, above certain thresholds, Travel Rule data exchange on the crypto side of the same transaction.

Is a crypto-accepting casino automatically a VASP or CASP?

Not automatically. The FATF and MiCA both test by activity, not by payment method: a casino that merely accepts crypto through a third-party processor is not conducting VASP-qualifying activity itself. It becomes relevant only if the operator runs its own exchange or custody function for the crypto it handles.

What does Curaçao's LOK require for crypto-accepting operators?

Per licensing-consultancy summaries of the ordinance, not the regulator's own published text, the LOK requires the standard risk-based CDD and PEP screening every licensee owes, plus added wallet-disclosure and transaction-monitoring obligations specific to virtual-asset activity. Confirm current detail with the Curaçao Gaming Authority before relying on it for a filing.

Does the Travel Rule apply to casino crypto withdrawals?

It can, above the applicable jurisdictional threshold, on the same basis it applies to any virtual asset transfer between service providers under FATF Recommendation 16. A casino processing a crypto withdrawal to a customer's external wallet is transferring a virtual asset, the activity the Travel Rule attaches to, not the identity of the business doing it.

References

About Hypersign

Hypersign is identity infrastructure that runs gambling-side identity verification, self-exclusion and risk-based screening, and crypto-side wallet risk scoring and Travel Rule data capture on one platform, through iGaming & Casino KYC Compliance and Crypto On-Ramp KYC + KYT. It is not a gambling licence, does not determine whether an operator's crypto-handling function meets the CASP activity test in a given jurisdiction, and does not replace counsel for that determination; it is the verification layer underneath whichever combination of gambling and crypto obligations an operator's specific setup requires.

Ready to add identity verification to your platform?

See how Hypersign's enterprise identity verification and reusable credential infrastructure works book a 30-minute demo.

Book a Demo →