Case

Restrictions on $280,000 at Binance lifted in 40 hours

BinanceDeFi / AML taint$280,00040 hours

After funds were withdrawn from Uniswap, Binance restricted the account. We first mapped the on-chain source of funds and then submitted a compliance package, after which access was restored.

An anonymized case. A similar situation does not mean the same timeline or outcome.

Situation

What the client reported

Client statement

The client reported closing a Uniswap V3 liquidity position, transferring ETH to a personal wallet, and depositing the funds at Binance. About three hours later, the account was restricted with a notice citing "suspicious activity" but providing no details.

About $280,000 remained in the account. The client described the transaction as a routine DeFi operation and denied any connection to the flagged address.

Available evidence

What was documented

Documented fact
  • Platform and amount

    A Binance account with about $280,000 restricted after a deposit originating from DeFi.

  • Sequence before the deposit

    Exit from a Uniswap V3 liquidity position → transfer of ETH to a personal wallet → deposit at Binance.

  • On-chain context of the deposit

    The pool's on-chain liquidity history showed adjacent transaction hops before the deposit. The case materials did not show a direct transfer from the client to a mixer.

  • Case materials

    The available materials included the on-chain history of the position and the context of the deposit transaction. Public TxIDs and the client's addresses are not disclosed here.

Work completed

Steps toward resolution

Our analysis
  1. 01

    Identified the on-chain trigger before contacting support

    We first examined what the AML system appeared to have detected: an address labeled as mixing-adjacent was about two hops away within the pool. The client's funds had entered AMM liquidity rather than moving directly through a mixer. We avoided opening multiple tier-one support tickets without a transaction map.

  2. 02

    Built a source-of-funds tree

    We mapped the sequence from entry into the pool through the AMM mechanics, the ETH withdrawal, and the exchange deposit so that the origin of the funds, not only the final transaction, was visible.

  3. 03

    Assembled a compliance package

    We prepared an annotated graph of the transaction hops, an explanation of why "AMM does not equal mixer," and a description of the indirect two-hop exposure using compliance terminology.

  4. 04

    Submitted the package through a specialist channel

    We sent a structured submission to the compliance team rather than the standard support queue.

  5. 05

    Awaited the exchange's decision

    The outcome then depended on Binance and the completeness of the materials. In this case, the period from the first submission to the decision was about 40 hours.

OutcomeDocumented fact

How the case concluded

After the forensic materials were submitted, the restriction was lifted. The client regained access to the funds and withdrew about $280,000. The period from submission to the decision was about 40 hours.

The account restrictions were lifted after the forensic materials were submitted.

Binance$280,00040 hours
What mattered

Factors that influenced the outcome

Our analysis
  • Identifying the specific on-chain trigger before communicating with the exchange instead of relying on a general assertion of legitimate activity.
  • Explaining DeFi in AML terms: AMM liquidity and an indirect hop, rather than suggesting that the client had used a mixer.
  • One complete package submitted through a specialist channel instead of multiple support tickets.

Important limitations

  • This outcome does not guarantee the same result or timeline in another case.
  • The exchange makes the decision. On-chain analysis and a report do not by themselves restore account access.
  • DeFi and AMM exposure is more complex than conventional Source of Funds evidence involving a bank or centralized exchange; the length of the transaction chain can affect the timeline.
  • The client, TxIDs, and addresses are not disclosed.
Free initial assessment

Describe what happened

Answer a few questions so we can assess the situation and suggest the next steps.

Do not send seed phrases, private keys, passwords, or 2FA codes. They are not needed for an initial assessment.

Do not send seed phrases, private keys, passwords, or 2FA codes.