Blog
7 min readPublished November 9, 2026

Exchange Froze My Account: KYC vs AML vs Law-Enforcement Hold Taxonomy

Sort KYC refresh vs AML source-of-funds vs LE holds before you upload documents. Issuer blacklist checks answer a different plane.

Wallet Operations
Sanctions & Wallet Screening
#wallet-screening
#law-enforcement
#freeze-risk
#compliance
Exchange Froze My Account: KYC vs AML vs Law-Enforcement Hold Taxonomy

When an exchange freezes your account or locks withdrawals, the first job is taxonomy - not rage-tweeting support. Most venue holds fall into three buckets: KYC refresh, AML / source-of-funds (SoF) review, and law-enforcement / legal-process hold. The documents that unblock a KYC refresh will not lift a sealed LE freeze, and an issuer isBlackListed read on your deposit address answers a different question entirely. Brand-agnostic desks that sort the bucket first waste fewer cycles and avoid coaching customers into evasion stories.

Educational only. Not legal advice. FreezeRadar does not unfreeze exchange accounts and does not help evade AML or LE process.

Financial documents / calculator metaphor for exchange KYC vs AML vs LE freeze taxonomy.

Check a wallet before you act

Run a FreezeRadar scan for issuer-freeze signals, sanctions exposure, counterparty risk, and freezeable asset sensitivity before moving funds.

Scan a wallet

Direct answer

Exchange account frozen for KYC/AML is usually a custodial compliance hold on your user record - not a Tether/Circle blacklist on a self-custody address. Ask support (in writing) which bucket applies, supply the matching document pack, and involve counsel when the venue cites legal process it cannot describe. Separate that path from exchange hold vs issuer USDT blacklist and from deposit-attribution guides like why exchange froze my deposit. This post owns the account-level three-bucket matrix.

Three-bucket taxonomy

BucketTypical triggersWhat support can often doWhat support usually cannot do
KYC refreshExpired ID, address change, enhanced due diligence, login from new countryAccept new ID / selfie / proof of address; reopen after automated checksRewrite your nationality; accept obviously altered docs
AML / SoF / wealthLarge unexplained inflows, high-risk corridor patterns, adverse media, structured depositsRequest bank statements, SoF letters, tx rationale; escalate to complianceTell you whether a SAR was filed; promise timelines that ignore investigation
LE / legal-process holdSubpoena, freeze order, MLA/MLAT, court directiveAcknowledge restriction; point to legal channelDisclose sealed process details; unilaterally release against a live order

Related plane separation: issuer blacklist vs exchange hold. Pre-deposit hygiene: before CEX deposit wallet screen. Document packs for wallet reviews (different but overlapping artifacts): documents for frozen stablecoin wallet review.

Document packs by bucket

KYC refresh pack

  • Government photo ID within validity window the venue accepts
  • Liveness / selfie per app flow
  • Proof of address (utility/bank letter) if requested
  • Updated occupation / expected activity questionnaire

Reject recovery DMs offering “KYC boosters.”

AML / SoF pack

  • Bank statements covering the fiat on-ramp window
  • Salary / business / sale-of-asset evidence matching the story
  • On-chain provenance for large crypto deposits (tx list - not seed)
  • Counterparty invoices for OTC legs
  • Plain-language memo: who, what, why, amounts, dates (UTC labeled)

Inconsistencies across tickets destroy credibility. One memo, reused.

  • Retain counsel experienced in digital-asset freezes
  • Ask counsel to contact the venue’s legal intake; do not invent exigent flags
  • Preserve your own records; do not destroy devices
  • If you receive a forfeiture notice in your jurisdiction, calendar claim deadlines - civil forfeiture clocks are unforgiving

Support agents often cannot confirm an LE hold even when one exists. Silence after document upload is not proof of malice; it may be a gag / SAR constraint.

Misfiles that burn weeks

  1. Treating a KYC lock as an issuer blacklist and writing Tether.
  2. Sending SoF bank statements into a ticket that only asked for a new passport photo.
  3. Paying a Telegram “Binance unfreeze specialist” (second scam).
  4. Opening multiple contradictory narratives across email aliases.
  5. Withdrawing to mixers “so compliance stops asking” - that escalates risk and is not advice we give; document and cooperate lawfully instead.

Competitor playbooks that market Binance-only click paths go stale when UI changes. Keep this matrix brand-agnostic; use each venue’s official help center for button labels.

How to ask support the classifying question

Template language: “Please confirm whether this restriction is (a) identity verification refresh, (b) compliance / source-of-funds review, or (c) a legal-process hold you cannot detail. I will upload documents matching the bucket.”

If they answer (a) or (b), upload the matching pack once. If they answer (c) or refuse to classify, talk to counsel before flooding the ticket with unrelated PDFs.

Worked composite

Corporate treasurer finds withdrawals disabled after a 2M USDT OTC receive. Support replies with a SoF questionnaire - not an LE letter. Desk uploads bank wires, OTC invoices, and a one-page memo; blacklist reads on the deposit address are false (issuer plane clean). Account reopens after compliance review. Parallel mistake avoided: filing a stolen-funds LERS as if they were the victim of theft.

Contrast: same UI freeze, but support says it cannot discuss and legal will contact counsel - bucket (c). Uploading more selfies does nothing useful.

Limitations

Venues differ by license, entity, and product (spot vs fiat). This taxonomy is educational, not a map of any single Terms of Use. FreezeRadar does not see inside CEX account flags. SAR / sealed process existence cannot be proven from the public blog.

Key takeaway

Sort KYC vs AML/SoF vs LE before you upload anything. Match the document pack to the bucket, keep one narrative, separate issuer blacklist checks from account holds, and bring counsel when legal process is in play.

Next: exchange hold vs issuer blacklist, why deposit froze, issuer vs exchange hold guide, documents guide, pre-CEX screen.

Deep dive: KYC refresh vs “permanent ban” folklore

Most KYC locks are reversible when documents match. “Permanent” language in community forums often conflates:

  • Failed liveness / sanctions hits on the identity
  • Terms-of-use violations (abuse, chargebacks)
  • LE holds misreported as KYC

Ask for the bucket in writing. If the venue cites ToS breach, that is a fourth path (account enforcement) adjacent to AML - still not an issuer blacklist. Keep appeals factual; threats and bribery attempts end accounts.

Deep dive: AML SoF narratives that work

Compliance reviewers read for coherence:

  • Timing: do fiat bank credits align with on-platform deposits?
  • Magnitude: does stated income support the volume?
  • Counterparties: are OTC desks named with invoices or only “a guy on Telegram”?
  • Chain hops: are you explaining privacy tooling that you actually used? Honesty beat creative writing.

If you cannot explain a hop, say so. Invented stories collapse under follow-up questions.

Deep dive: LE holds and counsel

When legal process is involved:

  • Do not cold-call random “exchange lawyers” from search ads.
  • Corporate victims should route through retained counsel to the venue’s published legal email / portal.
  • Individuals should still file local police reports when theft is alleged; an account hold is not itself proof of theft.
  • SIM-swap / account-takeover emergencies are a different playbook - self-freeze first, then taxonomy (sim-swap self-freeze vs issuer once live).

Coordination with on-chain screening

Before the next large deposit after a hold lifts:

  • Screen originating wallets (before CEX deposit workflow).
  • Separate receiving / treasury / investigation wallets per academy compliance guidance.
  • Do not treat a cleared KYC ticket as a blessing to skip blacklist checks on OTC counterparties.

Extended worked example (AML bucket)

A market-maker’s sub-account pauses withdrawals after receiving USDT from a new OTC counterparty. Support requests SoF for the last 90 days. Desk provides: banking letters for fiat margin, OTC trade blotter, tx hashes into the deposit address, and FreezeRadar screenshots showing counterparty clear of issuer blacklist at credit time. Support clears. Separately, the desk adds the counterparty to an enhanced watchlist because the pause itself was a signal - process improvement without assuming guilt.

Training quiz (answer key for leads)

  1. Expired passport lock → KYC.
  2. “Source of wealth questionnaire” → AML/SoF.
  3. “We cannot discuss; contact your attorney” → LE/legal.
  4. isBlackListed=true on a self-custody address with no CEX login issues → issuer plane, not this taxonomy.
  5. Telegram unfreeze quote → scam.

Escalation timers (internal policy example)

These are desk SLAs for yourselves, not venue promises:

  • KYC docs uploaded → internal follow-up if no ack in 3 business days
  • SoF pack uploaded → weekly status check
  • Suspected LE hold → counsel engaged within 1 business day
  • Recovery-scam contact attempt → block + note in IR same day

Publishing invented venue SLAs in customer emails creates false expectations. Keep timers internal.

References

  1. Binance Support - Account / security help center hub - https://www.binance.com/en/support/faq/list/7-27
  2. Binance - Law Enforcement Guidelines (process holds context) - https://www.binance.com/en/support/law-enforcement/guidelines
  3. FATF - Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs - https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html
  4. FreezeRadar - Exchange hold vs issuer USDT blacklist - https://freezeradar.com/blog/exchange-hold-vs-issuer-usdt-blacklist
  5. FBI IC3 - https://www.ic3.gov/
Sources (5)

Continue exploring FreezeRadar knowledge content.