Why do crypto off-ramps ask for source of funds? Documents, triggers, and on-chain proof

Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.

Crypto off-ramps ask for source of funds to confirm that the stablecoins you convert came from a lawful activity that matches your business. It's part of enhanced due diligence under AML rules, triggered by risk: high volumes, unusual transactions, high-risk countries, or funds with a crypto-only history. Good evidence links a document, like an invoice, to the on-chain transfer that paid it.

It isn't personal. The off-ramp is the point where a blockchain balance becomes a bank deposit (how off-ramps work), and someone has to vouch for it.

Key takeaways

  • Source of funds is where this money came from. Source of wealth is how the business or its owners got rich overall. Different questions, different documents.
  • Off-ramps ask when risk goes up: onboarding into enhanced checks, limit increases, flagged transactions, and changes in your activity.
  • Crypto-origin funds need a trail: transaction hashes, wallet addresses, exchange statements, and proof you control the wallet.
  • Documents must be in the business's name, legible, unredacted, and consistent with what you said your business does.

What is source of funds, and how is it different from source of wealth?

FATF, the global standard-setter for anti-money-laundering rules, draws the line in its guidance on politically exposed persons (paragraphs 86 to 88). "Wealth" and "funds" are two different concepts. Source of funds is the origin of the particular funds in the business relationship. Source of wealth is the origin of the customer's entire body of wealth.

Source of fundsSource of wealth
Question it answersWhere did this money come from?How did this business or person accumulate its assets?
ScopeOne transaction, or the money moving through the accountTotal assets over time
Typical evidenceInvoices, contracts, bank or exchange statements, on-chain historyFinancial statements, tax returns, records of a company sale or investments
When off-ramps askHigher-risk customers, large or unusual transactions, limit increasesEnhanced due diligence, complex ownership, high-risk profiles

FATF also makes a point that matters for crypto: knowing which institution the money came from isn't enough. You have to know the activity behind it.

Why do crypto off-ramps ask for it?

Because their regulators and their banks require it, and stablecoins make the question both easier and harder to answer.

The rules are risk-based almost everywhere:

  • FATF. The virtual asset guidance points virtual asset service providers to enhanced due diligence for higher-risk situations, including obtaining information on the customer's source of funds.
  • EU. The EBA's ML/TF risk factor guidelines, applying since December 2024, tell crypto-asset service providers to get evidence of the source of funds, the source of wealth, or the source of crypto-assets for higher-risk transactions. They also name self-hosted addresses that use mixers as a risk factor.
  • US. FinCEN's customer due diligence rule doesn't require source of funds for every customer. It requires a risk profile and ongoing monitoring, and source of funds comes in through enhanced checks on higher-risk accounts.

The crypto-specific part: every stablecoin has a public history. Blockchain analytics can show whether a deposit passed through a mixer, a sanctioned address, or a hacked exchange before it reached you. That's why an off-ramp can ask about money you received from a legitimate client. The client's wallet history comes along with the payment. Most of that screening is automated now, which is what compliance agents do, but the questions it raises still go to a person.

Regulation by country is in the stablecoin regulation tracker.

When does an off-ramp ask for source of funds?

At predictable moments. Here are the usual triggers, in the order most businesses meet them:

  1. Onboarding into enhanced checks. Individuals from high-risk countries go through enhanced KYC, which at BlindPay requires a source of funds document and a stated purpose of transactions (KYC requirements, country tiers).
  2. Limit increases. Asking for higher per-transaction, daily, or monthly caps means showing the money behind the volume: bank statements, financial statements, or tax returns.
  3. Volume or structure that needs validation. High transaction volumes, or funding that runs through several entities or wallets.
  4. A change in your profile. New ownership, a new business model, or activity that no longer matches what you declared.
  5. A flagged transaction. Monitoring holds a payout and compliance asks what it is: who the sender is to you, why the money moved, and what it's for. Some providers review every dollar payout as a standard step, as the US off-ramp guide explains.

BlindPay's source of funds guide lists the same triggers for businesses.

What documents prove source of funds?

Two families: documents for money that came through banks, and documents for money that lives on-chain. These are the categories BlindPay accepts, and most regulated off-ramps ask for the same.

Funds came fromDocuments that prove it
Operating revenueInvoices, customer contracts, settlement statements, receipts
A bank accountBank statements or account summaries from a regulated institution
Investors or foundersSubscription agreements, capital injection or founder contribution records
BorrowingExecuted loan agreements or credit facilities
Selling assetsRecords of a sale of business assets, securities, or property
A crypto walletProof the business or its principals control the wallet
On-chain activityTransaction history with transaction hashes and wallet addresses
A crypto exchangeStatements from a regulated exchange showing deposits, withdrawals, or trades
Minting or redeemingStablecoin issuance or redemption records
Trading or market makingTrade history, P&L summaries, liquidity provision records
A token saleAllocation summaries, private placement records, use-of-funds explanations

How do you prove funds that came from crypto?

Tell the story of the money, then attach the receipts. A worked example:

A Mexican software company invoices a US client for 25,000 USDC. The client pays from its own wallet on Base. Three months later, the company's off-ramp asks about the deposit.

  1. The commercial reason. The signed services contract and invoice number INV-2026-0412 for 25,000 USDC.
  2. The payment itself. The transaction hash, the client's sending address, the company's receiving address, the amount, and the date. A block explorer link lets the reviewer check it in seconds.
  3. The link between the two. The invoice names the client's company, and the client's wallet was shared in writing before payment, for example in the contract or an email.
  4. Proof you control the receiving wallet. On EVM networks, signing a message with the wallet proves control without moving funds. BlindPay offers this signed-message option when you register a blockchain wallet.
  5. Where the money went next. If part of it was swapped or bridged before the off-ramp, include those transaction hashes too, so the trail has no gaps.

The common failure is a gap in step 5. Stablecoins that hop through three wallets with no explanation look like layering, even when they're just a messy treasury.

What makes a source of funds review fail?

Usually the paperwork, not the money. BlindPay's document standards are typical: documents issued in the name of the business, showing the source and flow of funds, legible and complete with no material redactions, in PDF, JPG, or PNG.

Red flags that trigger follow-up questions or rejection:

  • Funds that don't match the declared business activity. A consultancy receiving trading-desk volumes.
  • Third-party wallets paying with no contract or explanation.
  • Heavy redactions on statements.
  • On-chain exposure to mixers, sanctioned addresses, or known scam clusters.
  • Round-tripping: the same money leaving and coming back to make volume look larger.
  • An owner or controller who doesn't appear in the documents.

What happens if you don't respond?

The money stops until you do.

At BlindPay, a request for information moves the customer to compliance_request. While it's open the customer can't send or receive funds, and BlindPay emails your team on days 0, 7, and 17. With no submission by day 27, the customer is rejected automatically. For a single held transaction, the on-hold process is faster: if the request goes unanswered for 24 hours, the transaction may be refunded to the sender.

Who collects the documents, you or the provider?

Responsibility is shared, and it's worth writing down before the first request arrives.

TaskUsually the providerUsually youEvidence to ask the provider for
Verify your customers (KYC, KYB)Runs the checks and decidesCollects data and documents from your customerRequired fields per tier, review times
Source of fundsReviews and decidesCollects documents from your customer and uploads themAccepted documents and standards
Sanctions and wallet screeningRuns on every customer and transferNothing, beyond accurate dataWhat gets screened and when
Transaction monitoringFlags and holdsAnswers requests for informationResponse deadlines
RecordsKeeps its ownKeeps contracts and invoices behind each paymentRetention periods

At BlindPay, requests go to your team, not straight to your customer, because collecting and uploading the documents is the platform's job. If you sit between BlindPay and your own users, build the upload path into your product before you need it.

How does BlindPay handle source of funds?

Compliance runs inside the payment flow. BlindPay verifies customers, screens transactions, and reviews source of funds and source of wealth when an account or transaction needs enhanced due diligence. Requests arrive by email and in the dashboard, and you answer them in one submission. Read the source of funds guide for the full document list before you onboard a high-volume customer.

This article is educational content, not legal advice. Requirements vary by jurisdiction and provider; confirm your obligations with counsel.

FAQ