In April 2025, Binance changed the way it accepts foreign law enforcement requests. The exchange stopped responding to most of them directly. Requests now flow through the United Arab Emirates government or through Mutual Legal Assistance Treaties — the formal state-to-state channel for criminal evidence. The New York Times reported Tuesday that police officials from five European countries described the same experience at a conference in the Netherlands last month: requests for account data and asset freezes enter a diplomatic queue, and most receive no direct answer.
The carve-out reveals the design intent. Child sexual abuse material, terrorism, and imminent threats to life still get direct attention. Everything else — fraud, theft, ransomware payments, investment scams — is redirected to Abu Dhabi, where Binance's regulated entities sit under the Abu Dhabi Global Market, or routed into the MLAT pipeline.
The detail that matters most is not legal. It is temporal. Crypto investigations are decided in the first hours after a transfer. Illicit funds move across bridges, through swaps, and into mixers within seconds. A response that arrives in seven days is equivalent to no response at all. The ledger remembers what the narrative forgets: latency is not a compliance detail. It is the enforcement mechanism itself.
Context: This did not happen in a vacuum. In November 2023, Binance agreed to a $4.3 billion penalty to resolve U.S. Department of Justice money laundering and sanctions charges. Founder Changpeng Zhao pleaded guilty to a Bank Secrecy Act violation. The company accepted years of independent monitoring. The industry read that settlement as maturation: the exchange paying its fine, building its compliance program, joining the regulated world.
The structure changed. The behavior did not.
In May, The Information reported that the Treasury Department had privately pressed Binance to comply with the monitoring program after reports of roughly $1 billion in Iran-linked flows. The Wall Street Journal and Fortune reported earlier this year that Binance had dismissed compliance staff who investigated transactions allegedly tied to Iran. The exchange denied the allegations. This month, The Information published a Justice Department memo warning federal prosecutors in crypto cases to expect less help from Binance on freezing and seizing assets. The NYT report is the operational confirmation.
There is historical precedent for this kind of routing. For decades, Swiss banking secrecy functioned as a latency layer — not a refusal to cooperate, but a channel so slow and so discretionary that most requests expired before they produced results. The United States broke that system not through MLATs but through direct threat: the 2008 UBS case, FATCA, and the leverage of access to the dollar. The lesson was that diplomatic channels favor the party with time. In crypto, time belongs to the mover of funds, not to the state.
Reconstructing the protocol from first principles. Before April, a foreign investigator had a direct interface with Binance's compliance function. The exchange maintained a law enforcement portal. Requests carried timestamps. Responses came in hours or days. The interface was imperfect — but it existed.
After the policy change, the request path becomes:
Investigator → national central authority → UAE government channel → ADGM competent authority → Binance's Abu Dhabi entity → compliance team.
Each hop is a queue. Each queue operates on diplomatic time, measured in weeks. MLATs are not built for asset recovery; they are built for evidentiary exchange between sovereigns, and their default processing unit is the month. For a scam that drains an account in minutes, a month is an eternity. By the time the request reaches the entity that controls the funds, the funds have completed three bridge transfers and passed through a mixer. The database row still exists. The balance is gone.
This is a routing table with a misconfigured priority classifier. The urgency threshold recognizes "imminent threat to life." It does not recognize "imminent threat to assets." In crypto crime, those categories rarely coincide. An investment scam victim loses life savings. A ransomware victim loses data and money. But unless a human is in immediate physical danger, the request enters the slow lane. The system encodes a theory of harm that predates digital assets — financial crime as a paperwork category, not a destruction event.
I have seen this class of bug before. During the 2020 Curve Finance audit, my team found a rounding error in the stableswap invariant's virtual price calculation that could produce small arbitrage losses for liquidity providers under volatility. The bug was subtle: the code checked the right condition at the wrong precision. The Binance policy is structurally similar. It honors the right legal condition — sovereign channel integrity — at the wrong timescale. The request is valid. The classification passes. The funds still escape. The invariant breaks silently.
The 2022 Terra collapse taught the same lesson at a larger scale. I spent six weeks reverse-engineering the algorithmic stabilization mechanism, tracing recursive debt accumulation through smart contract calls. The peg relied on infinite liquidity assumptions; the consequence was a feedback loop that compounded into negative equity. Time arbitrage is the most reliable exploit in this industry, and it does not care whether the victim is a stablecoin, an investor, or a law enforcement agency. When the response interval exceeds the bridge-and-mix interval, enforcement becomes structurally lossy.
Consider the freeze request itself. It is not a read operation. It is a write operation on a custodial database, and it requires a keyholder to act. Routing that write through three sovereign layers converts a database transaction into a diplomatic negotiation. The parties that lose are rarely Binance's customers in the UAE. They are victims in Europe, Asia, and Africa — jurisdictions with no direct leverage over Abu Dhabi. The harm concentrates exactly where the exchange has the least incentive to see it.
There is also the question of which sovereigns get the fast lane. A European police unit has no contractual relationship with an Abu Dhabi entity. Its only channel is the MLAT, which requires a domestic competent authority to endorse, translate, and prioritize the request. Each requirement adds a queue. Meanwhile, the jurisdictions with direct regulatory power over the exchange — the United States and the UAE — retain the strongest channels. Those are precisely the places where this year's scam victims are least likely to find their way into the news. The routing policy is not neutral. It is a power map, drawn in a language regulators outside its borders are still learning to read.
My 2017 deconstruction of the Ethereum whitepaper established a habit I have kept: map the theoretical claim to the earliest implementation and check whether the behavior matches the promise. The promise here was that a $4.3 billion settlement and a monitoring regime would produce a mature compliance architecture. The implementation routes the most common category of harm into a months-long diplomatic pipe. Paper and behavior diverged.
The uncomfortable conclusion is that this policy is the logical endpoint of the industry's statelessness narrative. For years, the ecosystem celebrated Binance as a company without a country — operating everywhere, accountable nowhere. That design was marketed as freedom when the industry wanted to avoid regulators. The same design now functions as a shield against legitimate freezing of criminal funds. The cost is externalized to the most exposed and least sophisticated users. Protecting the user means protecting the victim of the scam, not the founding ideology of the exchange.
Privacy advocates may read friction in law enforcement channels as a victory. It is not privacy; it is asymmetry. Privacy-by-design protects users from surveillance. Friction-by-default protects one party from accountability while exposing everyone else to theft. They look similar in a diagram and behave entirely differently in practice. Conflating them is a category error this industry keeps repeating.
The monitoring program was supposed to be the corrective mechanism. It is not. Monitors review policies and audit internal controls; they do not force response-time obligations on foreign requests. A $4.3 billion penalty changes the balance sheet. It does not change the routing table. Stability is not a feature; it is a discipline, and discipline cannot be purchased — it must be enforced continuously.
The bull market context sharpens the stakes. When prices rise, inflows rise, and scam volume rises with them. The prevailing narrative treats settled penalties as evidence of maturity. A settlement is a transaction, not a transformation. Euphoria obscures structural details like this one — not a white-hat vulnerability, but a deliberate redesign of the compliance interface that slows the entire enforcement system relative to the criminals it is meant to catch.
The wider regulatory cost matters too. The industry's case for ETFs, bank access, and mainstream adoption rests on a simple claim: crypto can be regulated, and exchanges can cooperate with authorities. A policy that funnels routine requests into sovereign dead-letter queues undermines that claim. Regulators do not need a conspiracy theory; they need to read the NYT report and the DOJ memo. The cooperation surface shrinks, and the licensing penalty grows.
What comes next? Expect jurisdictions to write direct-response obligations into licensing conditions. The EU, the United States, and the Gulf states will impose measurable service levels — not out of compassion for victims, but because their own investigators are being routed into diplomatic queues. Expect a technical counter-proposal as well: cryptographic proof of compliance. An exchange could issue a signed, timestamped freeze receipt, verifiable by investigators without exposing user data, proving a request was received and acted on. The same principle as a Merkle proof, applied to a compliance obligation. The infrastructure does not exist yet.
While it is built, the queue grows. In the next bull leg, victims will watch their funds settle into a mixer while a treaty request sits on a desk in Abu Dhabi. The ledger remembers what the narrative forgets: speed is not a nicety in enforcement. It is the entire mechanism. The open question is whether the industry treats this as a design flaw to be patched, or as a settled feature. The pattern suggests the latter — until a jurisdiction makes that pattern cost more than the compliance.

