Exchange Froze My Account: KYC vs AML vs Law-Enforcement Hold Taxonomy
Sort KYC refresh vs AML source-of-funds vs LE holds before you upload documents. Issuer blacklist checks answer a different plane.

When an exchange freezes your account or locks withdrawals, the first job is taxonomy - not rage-tweeting support. Most venue holds fall into three buckets: KYC refresh, AML / source-of-funds (SoF) review, and law-enforcement / legal-process hold. The documents that unblock a KYC refresh will not lift a sealed LE freeze, and an issuer isBlackListed read on your deposit address answers a different question entirely. Brand-agnostic desks that sort the bucket first waste fewer cycles and avoid coaching customers into evasion stories.
Educational only. Not legal advice. FreezeRadar does not unfreeze exchange accounts and does not help evade AML or LE process.

Check a wallet before you act
Run a FreezeRadar scan for issuer-freeze signals, sanctions exposure, counterparty risk, and freezeable asset sensitivity before moving funds.
Direct answer
Exchange account frozen for KYC/AML is usually a custodial compliance hold on your user record - not a Tether/Circle blacklist on a self-custody address. Ask support (in writing) which bucket applies, supply the matching document pack, and involve counsel when the venue cites legal process it cannot describe. Separate that path from exchange hold vs issuer USDT blacklist and from deposit-attribution guides like why exchange froze my deposit. This post owns the account-level three-bucket matrix.
Three-bucket taxonomy
| Bucket | Typical triggers | What support can often do | What support usually cannot do |
|---|---|---|---|
| KYC refresh | Expired ID, address change, enhanced due diligence, login from new country | Accept new ID / selfie / proof of address; reopen after automated checks | Rewrite your nationality; accept obviously altered docs |
| AML / SoF / wealth | Large unexplained inflows, high-risk corridor patterns, adverse media, structured deposits | Request bank statements, SoF letters, tx rationale; escalate to compliance | Tell you whether a SAR was filed; promise timelines that ignore investigation |
| LE / legal-process hold | Subpoena, freeze order, MLA/MLAT, court directive | Acknowledge restriction; point to legal channel | Disclose sealed process details; unilaterally release against a live order |
Related plane separation: issuer blacklist vs exchange hold. Pre-deposit hygiene: before CEX deposit wallet screen. Document packs for wallet reviews (different but overlapping artifacts): documents for frozen stablecoin wallet review.
Document packs by bucket
KYC refresh pack
- Government photo ID within validity window the venue accepts
- Liveness / selfie per app flow
- Proof of address (utility/bank letter) if requested
- Updated occupation / expected activity questionnaire
Reject recovery DMs offering “KYC boosters.”
AML / SoF pack
- Bank statements covering the fiat on-ramp window
- Salary / business / sale-of-asset evidence matching the story
- On-chain provenance for large crypto deposits (tx list - not seed)
- Counterparty invoices for OTC legs
- Plain-language memo: who, what, why, amounts, dates (UTC labeled)
Inconsistencies across tickets destroy credibility. One memo, reused.
LE / legal-process pack
- Retain counsel experienced in digital-asset freezes
- Ask counsel to contact the venue’s legal intake; do not invent exigent flags
- Preserve your own records; do not destroy devices
- If you receive a forfeiture notice in your jurisdiction, calendar claim deadlines - civil forfeiture clocks are unforgiving
Support agents often cannot confirm an LE hold even when one exists. Silence after document upload is not proof of malice; it may be a gag / SAR constraint.
Misfiles that burn weeks
- Treating a KYC lock as an issuer blacklist and writing Tether.
- Sending SoF bank statements into a ticket that only asked for a new passport photo.
- Paying a Telegram “Binance unfreeze specialist” (second scam).
- Opening multiple contradictory narratives across email aliases.
- Withdrawing to mixers “so compliance stops asking” - that escalates risk and is not advice we give; document and cooperate lawfully instead.
Competitor playbooks that market Binance-only click paths go stale when UI changes. Keep this matrix brand-agnostic; use each venue’s official help center for button labels.
How to ask support the classifying question
Template language: “Please confirm whether this restriction is (a) identity verification refresh, (b) compliance / source-of-funds review, or (c) a legal-process hold you cannot detail. I will upload documents matching the bucket.”
If they answer (a) or (b), upload the matching pack once. If they answer (c) or refuse to classify, talk to counsel before flooding the ticket with unrelated PDFs.
Worked composite
Corporate treasurer finds withdrawals disabled after a 2M USDT OTC receive. Support replies with a SoF questionnaire - not an LE letter. Desk uploads bank wires, OTC invoices, and a one-page memo; blacklist reads on the deposit address are false (issuer plane clean). Account reopens after compliance review. Parallel mistake avoided: filing a stolen-funds LERS as if they were the victim of theft.
Contrast: same UI freeze, but support says it cannot discuss and legal will contact counsel - bucket (c). Uploading more selfies does nothing useful.
Limitations
Venues differ by license, entity, and product (spot vs fiat). This taxonomy is educational, not a map of any single Terms of Use. FreezeRadar does not see inside CEX account flags. SAR / sealed process existence cannot be proven from the public blog.
Key takeaway
Sort KYC vs AML/SoF vs LE before you upload anything. Match the document pack to the bucket, keep one narrative, separate issuer blacklist checks from account holds, and bring counsel when legal process is in play.
Next: exchange hold vs issuer blacklist, why deposit froze, issuer vs exchange hold guide, documents guide, pre-CEX screen.
Deep dive: KYC refresh vs “permanent ban” folklore
Most KYC locks are reversible when documents match. “Permanent” language in community forums often conflates:
- Failed liveness / sanctions hits on the identity
- Terms-of-use violations (abuse, chargebacks)
- LE holds misreported as KYC
Ask for the bucket in writing. If the venue cites ToS breach, that is a fourth path (account enforcement) adjacent to AML - still not an issuer blacklist. Keep appeals factual; threats and bribery attempts end accounts.
Deep dive: AML SoF narratives that work
Compliance reviewers read for coherence:
- Timing: do fiat bank credits align with on-platform deposits?
- Magnitude: does stated income support the volume?
- Counterparties: are OTC desks named with invoices or only “a guy on Telegram”?
- Chain hops: are you explaining privacy tooling that you actually used? Honesty beat creative writing.
If you cannot explain a hop, say so. Invented stories collapse under follow-up questions.
Deep dive: LE holds and counsel
When legal process is involved:
- Do not cold-call random “exchange lawyers” from search ads.
- Corporate victims should route through retained counsel to the venue’s published legal email / portal.
- Individuals should still file local police reports when theft is alleged; an account hold is not itself proof of theft.
- SIM-swap / account-takeover emergencies are a different playbook - self-freeze first, then taxonomy (sim-swap self-freeze vs issuer once live).
Coordination with on-chain screening
Before the next large deposit after a hold lifts:
- Screen originating wallets (before CEX deposit workflow).
- Separate receiving / treasury / investigation wallets per academy compliance guidance.
- Do not treat a cleared KYC ticket as a blessing to skip blacklist checks on OTC counterparties.
Extended worked example (AML bucket)
A market-maker’s sub-account pauses withdrawals after receiving USDT from a new OTC counterparty. Support requests SoF for the last 90 days. Desk provides: banking letters for fiat margin, OTC trade blotter, tx hashes into the deposit address, and FreezeRadar screenshots showing counterparty clear of issuer blacklist at credit time. Support clears. Separately, the desk adds the counterparty to an enhanced watchlist because the pause itself was a signal - process improvement without assuming guilt.
Training quiz (answer key for leads)
- Expired passport lock → KYC.
- “Source of wealth questionnaire” → AML/SoF.
- “We cannot discuss; contact your attorney” → LE/legal.
isBlackListed=trueon a self-custody address with no CEX login issues → issuer plane, not this taxonomy.- Telegram unfreeze quote → scam.
Escalation timers (internal policy example)
These are desk SLAs for yourselves, not venue promises:
- KYC docs uploaded → internal follow-up if no ack in 3 business days
- SoF pack uploaded → weekly status check
- Suspected LE hold → counsel engaged within 1 business day
- Recovery-scam contact attempt → block + note in IR same day
Publishing invented venue SLAs in customer emails creates false expectations. Keep timers internal.
References
- Binance Support - Account / security help center hub - https://www.binance.com/en/support/faq/list/7-27
- Binance - Law Enforcement Guidelines (process holds context) - https://www.binance.com/en/support/law-enforcement/guidelines
- FATF - Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs - https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html
- FreezeRadar - Exchange hold vs issuer USDT blacklist - https://freezeradar.com/blog/exchange-hold-vs-issuer-usdt-blacklist
- FBI IC3 - https://www.ic3.gov/
Sources (5)
Binance Support — Security FAQ hub
Binance
Account security article index.
Binance — Law Enforcement Guidelines
Binance
LE process context for holds.
FATF — Guidance for VASPs (RBA)
FATF
AML/CFT expectations for VASPs.
FreezeRadar — Exchange hold vs issuer blacklist
FreezeRadar
Plane separation.
FBI IC3
FBI IC3
When theft is alleged alongside holds.
Related reading
Continue exploring FreezeRadar knowledge content.
On this page
Get posts like this by email
A daily or weekly digest of FreezeRadar freeze activity.
By FreezeRadar Team
Wallet risk intelligence and stablecoin compliance analysis from FreezeRadar.


