Cryptocurrency exchange OKX faces scrutiny as investigative journalist Joseph Cox reveals alarming flaws in its identity verification process. Cox managed to create a verified account using false identification and passports, raising questions about the platform's lax know-your-customer (KYC) and anti-money laundering (AML) procedures.
No Verification, No Problem?
The ability to establish and verify a fake identity across multiple platforms highlights a systemic failure in the regulations governing digital financial institutions. Despite the commonality of fake IDs, OKX's vulnerability to such manipulation suggests a significant lapse in KYC/AML protocols.
Supporting a Dubious System
Protos, following Cox's revelation, engaged with OKX's customer support on Telegram. Rather than addressing the serious concerns raised, the support dismissed Cox's findings as "fake news" and shockingly admitted that no real KYC/AML checks occur during account creation or fund deposits.
In traditional financial institutions, rigorous identity verification processes precede any fund deposits, a measure to prevent money laundering and the entry of illicit funds. OKX's failure to implement such measures contradicts industry standards.
Withdrawal Woes and Crypto Exchanges' Common Practices
According to OKX's customer support, KYC/AML checks only come into play when users attempt to withdraw funds. This revelation aligns with a prevailing theory on Twitter and Reddit, suggesting that many crypto exchanges prioritise KYC/AML only during withdrawal attempts, hindering users from moving or withdrawing their funds easily.
Unveiling Industry Practices or Exposing a Widespread Issue?
Contrary to the support's attempt to downplay the situation, it appears to shed light not only on OKX's deficiencies but also on a potential industry-wide disregard for effective KYC/AML implementation. The support's argument that "every exchange all over the world does KYC/AML" in a similar manner does not absolve OKX of its responsibilities.
Binance Assisting Users in Circumventing KYC Procedures
As reported by Coinlive last year, within Binance's official Chinese chatrooms, Binance employees and Binance Angels have been sharing techniques with users to circumvent Binance's Know Your Customer (KYC) and verification systems. These methods include forging bank documents and providing false addresses.
Screenshot of a Binance Angel guiding a Chinese user on how to sign up for an account while in China on Binance’s Discord channel. (Source: ABMedia)
Binance Angels, who are Binance-trained volunteers, seem to frequently assist Chinese users in the registration process, even suggesting the use of a VPN to bypass restrictions and register with an overseas email as a "Taiwan resident" before switching nationality back to Chinese. It's important to note that such activities go against standard KYC and regulatory procedures, raising concerns about the integrity of Binance's user verification processes.
How Chinese Users Circumvent Crypto Exchange Regulations
In the domain of cryptocurrency exchanges, several platforms founded by Chinese nationals, such as Huobi, Binance, and OKX (collectively referred to as HBO), have exited China due to regulatory challenges. They have been prohibiting mainland Chinese users from accessing and registering for their services.
Over the past two years, Bybit and Bitget have also withdrawn from China due to regulatory issues. So, what happened to the user base these platforms had built up?
Users were forced to withdraw their funds and leave, however, some sought ways to continue trading by passing the KYC verifications.
Creative Solutions Amidst Restrictions
Alan Zhang, a senior crypto trader in Guangdong, has assisted numerous Chinese users in completing KYC verifications on various platforms after certain exchanges blocked mainland Chinese users.
According to Zhang, the most legitimate method involves registering an offshore BVI company and using its documents for KYC verification to trade successfully. He explained,
"The registration fee for a BVI company can be as high as $1,000 USD. Registering a UK company is cheaper, around $200 USD, but it's more troublesome due to annual audits and credit record entries. I've helped many people register foreign companies. For some big players, this is an essential need."
He also further shared that,
"But what I'm most grateful for is Taobao. Once, I successfully organised a group purchase of hundreds of driving licences from a Southeast Asian country, at a very affordable price of $100 USD per licence. And all I needed was to spend 20 RMB on Taobao to Photoshop one. These driving licences can pass the KYC on some exchange platforms."
Insider Collusion and Quick Approvals
Zhang revealed to Coinlive, "There have always been rumours that KYC verification teams at several Chinese-founded exchanges like Binance and OKX are colluding with external parties to make money. They not only accept fake documents but also pass the verification on the same day."
A former head of KYC at one exchange, who wishes to remain anonymous, told Coinlive, "Many clients provided genuine documents, but it would still take at least a week. I'm certain of this because I submitted my compliant BVI company's documents following the official process and waited two weeks for the verification."
"I didn't want my company and colleagues to know it was my personal account, but I checked the KYC verification backend many times a day, and I saw many accounts being verified on the same day," he said. "I don't want to blame anyone because I don't know which officer from the upper management, or boss, personally clicked the approval button."
The Rise of Neural Network-Generated Fake IDs
In addition to enlisting traders like Zhang to aid in the KYC process, the creation of fake IDs has undergone a significant transformation with the advent of OnlyFake, an underground website harnessing advanced technologies such as neural networks and generators. The traditional method of manually crafting fake IDs with tools like Photoshop is now being replaced by a more efficient and accessible approach with just $15.
Instant Fake ID Generator: Customise details, upload a photo, and hit generate for a personalised ID in minutes. (Source: X.com @josephfcox)
1. Neural Networks Technology:
- OnlyFake leverages neural networks to generate highly realistic-looking photos for fake IDs. Neural networks are a type of artificial intelligence that can learn patterns and create content resembling genuine documents.
- These networks analyse various features like facial expressions, background settings, and lighting to produce authentic-looking images that mimic the appearance of legitimate identification cards.
2. Generators:
- The service employs generators capable of producing up to 20,000 documents per day. These generators work based on algorithms and data inputs to create a wide variety of identification cards quickly and efficiently.
- According to OnlyFake's claims, these generators can extract data from sources like Excel tables, enabling the simultaneous creation of hundreds of fake documents.
3. Customisation Options:
- OnlyFake provides users with the ability to customise every detail of the fake ID, including names, biographical information, addresses, expiration dates, and even signatures. This level of customisation makes it easier for users to generate IDs tailored to specific needs.
4. Realism in Design:
- The generated IDs go beyond simple information by incorporating realistic details. For instance, the inclusion of background elements, such as a fluffy carpet beneath the ID, adds an extra layer of authenticity. This feature is particularly relevant for websites that require users to verify their identity by placing their ID on a surface and taking a photo.
Example of a fake ID. (Source: 404 MEDIA)
5. Instant Availability:
- Unlike traditional methods that may involve a lengthy crafting process or waiting for a physical ID to arrive by mail, OnlyFake allows users to generate fake IDs almost instantly. This quick turnaround time reduces the barrier to entry for individuals seeking fraudulent identification.
6. Potential Misuse:
- The ease and speed at which fake IDs can be created through OnlyFake raise concerns about their potential misuse in various illegal activities. The website's claims of successfully bypassing identity verification processes on platforms like OKX, a cryptocurrency exchange, highlight the risks associated with the widespread availability of such technology.
Threat to Online Security
OnlyFake represents a significant advancement in the realm of fake IDs, moving away from manual craftsmanship towards automated generation using neural networks and sophisticated algorithms. This shift in technology poses challenges for online security and identity verification systems, potentially facilitating criminal activities such as bank fraud and money laundering.
A Wake-Up Call for Crypto Regulation
The lax KYC/AML practices revealed at OKX underscore the urgent need for regulatory authorities to strengthen oversight of cryptocurrency exchanges. This incident raises concerns not only about OKX but also about the broader industry's commitment to preventing illicit financial activities. It's a call to action for regulators to ensure the robust implementation of KYC/AML protocols, safeguarding the integrity of the entire cryptocurrency ecosystem.