Claudia Hui is Head of Compliance Advisory, APAC at TRM Labs, where she advises financial institutions, crypto businesses, and regulators on anti-money laundering and financial crime risks in digital assets. She previously served as Head of Compliance for Singapore at Revolut and held a regional compliance leadership role at Qashier. Earlier in her career, Hui was an Assistant Director in the Payments Department at the Monetary Authority of Singapore, where she played a pivotal role in implementing the Payment Services Act.
In this interview with CryptoMegaphone, Hui discusses the growing role of blockchain intelligence in digital asset regulation and institutional compliance, the evolution of illicit finance risks, and the challenges created by regulatory fragmentation. She also examines compliance expectations for financial institutions entering digital asset markets, the implications of stablecoins and tokenized real-world assets, and the regulatory and technological developments likely to shape financial integrity over the next five years.
Blockchain intelligence has evolved from a specialized investigative capability into essential infrastructure for regulators, financial institutions, and virtual asset service providers. From TRM Labs’ perspective, what developments have driven this transformation, and what role do you see blockchain intelligence playing in the next phase of digital asset market regulation?
A few things drove this shift. Adoption crossed a threshold. Stablecoins, tokenization, and digital asset custody are now moving into mainstream banking and payments, so the exposure is no longer niche. Regulation also matured, from Singapore’s Payment Services Act to the expansion of the travel rule and MiCA, and supervisors now expect firms to show they have control and robust oversight over all crypto exposure. And because public blockchains are transparent, risk can be measured directly to an extent that is unprecedented in the financial industry.
At TRM, we see blockchain intelligence moving from a forensic tool used as a complementary good-to-have option to being part of the foundation that compliance programs are built on. When you can screen a wallet, trace its exposure, and map its risk to specific threats in real time, much better risk decisions can be made with these extensive data points than if you only relied on traditional methods of reviewing and monitoring customers and transactions.
In the next phase, I expect intelligence to underpin supervision and regulation itself. Regulators are building supervisory capacity, and shared, verifiable on-chain data lets industry and regulators work from the same set of facts. That common ground allows regulators to set clearer expectations and firms to better articulate how they are meeting regulatory standards, which will enable this ecosystem to scale responsibly.
As digital asset adoption continues to accelerate globally, illicit activity is evolving alongside legitimate use cases. Which trends concern TRM Labs the most today, and where should regulators and industry participants focus their efforts to remain effective while preserving innovation and the benefits of blockchain technology?
What concerns us most is the industrialization of fraud. Pig-butchering scams, AI-enabled social engineering, and deepfakes are now run at scale, and they can convert a victim’s losses into crypto within minutes. We have also watched laundering become more professional, with cross-chain bridges, mixers, and instant swaps that move value faster than older controls can react. Stablecoins play a growing role in illicit flows for the same reason they are useful — because they are fast and liquid.
The mistake would be to treat any of this as a reason to slow innovation. Transparency is our biggest advantage — on-chain activity is traceable in ways cash never was. My advice is to leverage existing strengths and focus on where blockchain offers us a technological advantage to build stronger controls.
Regulators should continue to invest in supervisory capacity and intelligence sharing across borders, given the increasingly international nature of such illicit activity networks, and build faster channels for collaboration and communication to match the increasing speed of these networks.
Industry should build more real-time controls to keep up with the pace of blockchain activity and ensure that they are risk-based and intelligence-led rather than box-ticking, so legitimate users are not unfairly impacted by the actions of bad actors. Done well, strong compliance and innovation support each other rather than compete.
Finally, public-private partnerships should continue to be strengthened, as this is not a battle that can be won in isolation — sharing typologies and threat data quickly keeps defenders ahead, and decisive, coordinated action across all parties will be crucial to keeping the ecosystem safe.
Governments around the world are introducing increasingly comprehensive digital asset frameworks while strengthening anti-money laundering and sanctions requirements. Do you see meaningful convergence emerging among major regulatory regimes, or will regulatory fragmentation remain one of the defining challenges for global crypto businesses in the years ahead?
I am seeing convergence at the level of principles and divergence at the level of implementation, and that gap is where much of the compliance uplift effort lies. FATF’s standards — adopting a risk-based approach, travel rule obligations, and licensing for virtual asset service providers — are common reference points almost everywhere. But shared principles haven’t always produced interoperable rules. A pertinent example is the different thresholds and wallet verification requirements set by each jurisdiction for the travel rule.
So I would frame it less as “convergence versus fragmentation” and more as convergence in what regulators are trying to achieve in principle, alongside differences in how they require firms to prove meaningful compliance and tailor their approach to the specific risks of the jurisdiction. For global businesses, that means the operational answer isn’t to wait for harmonization of requirements, as each jurisdiction inherently has different risks and will require different controls. It’s about building compliance infrastructure flexible enough to satisfy the applicable standard and effectively manage risks in every market you touch.
As banks and other financial institutions continue integrating digital asset services, what compliance capabilities do you believe have shifted from being competitive advantages to becoming baseline expectations for institutional participation, and what role does blockchain intelligence play in meeting those expectations?
Three key capabilities have moved from “nice-to-have” to “must-have.” The first is wallet and counterparty risk scoring at the point of transaction, not after the fact. Firms are expected to know the risk profile of an origination or destination address before the transaction is completed, the same way they’d screen a wire originator or beneficiary.
The second is source-of-funds and source-of-wealth tracing across chains, given how easily value now moves between Bitcoin, Ethereum, and dozens of other networks, plus bridges and mixers. The third is sanctions screening that actually understands on-chain typologies, not just static address lists, because regulators are now designating addresses and entire darknet or laundering infrastructures, not just individuals. None of these are differentiators anymore; they are table stakes for any institution that wants to custodize digital assets, process stablecoin payments, or serve crypto-native clients.
Under the “same risk, same regulation” approach that most regulators take, the anti-money laundering and sanctions rigor applied to traditional financial services is expected to apply equally to digital asset services, and firms will need to demonstrate that the measures they are taking in this space are at least as effective at mitigating such risks as the controls they have in place for other services offered.
Blockchain intelligence is what makes these baseline expectations achievable at institutional scale. It turns a public ledger that offers little actionable information on its own into an investigable record — with attribution, transaction graphing, and exposure scoring — that a compliance team can review and act on in real time. The wealth of information and customisability of such tools allows firms to monitor their customers and transactions against their risk appetite in real time, which is necessary given the fast pace of blockchain activity and the ever-evolving ecosystem.
As stablecoins, tokenized real-world assets, and increasingly interconnected blockchain ecosystems continue to develop, what new compliance and investigative challenges do you believe regulators and financial institutions may still be underestimating, and how should the industry prepare for them?
First, stablecoins have quietly become the dominant rail for the most consequential illicit activity, not the most visible activity. Monthly stablecoin volumes topped USD 1 trillion multiple times in 2025, and in that same year illicit entities received roughly USD 141 billion via stablecoin wallets. What’s underappreciated is how concentrated that risk is: stablecoins accounted for 86% of all illicit crypto flows in 2025. Scams and ransomware still favor volatile assets at the point of offense before converting to stablecoins downstream.
That distinction matters because it means point-of-off-ramp screening — checking a wallet when it cashes out — misses the risk entirely. We’re seeing sanctioned networks split funds across many short-lived “funnel” addresses and route them through cross-chain swaps specifically designed to defeat freeze-and-seize capabilities before re-entering stablecoins near the exit. Institutions have to trace backward through the full transaction chain, not just screen the deposit.
This is further complicated by the fact that stablecoins are becoming settlement infrastructure, not just a trading instrument, raising the stakes for ensuring that the right flows are identified as illicit while the majority of legitimate transactions continue to be processed efficiently.
Second, tokenized real-world assets shift the compliance problem from the chain itself to the wrapper around it. Tokenization doesn’t change the underlying asset; it changes how ownership is recorded and transferred. That means identity and wallet attribution, entry-point screening, continuous behavioral monitoring for things like wash trading and circular funding, and jurisdictional controls embedded at the smart-contract level all have to work together. This introduces a novel combination of considerations that goes beyond just KYC and requires live behavioral monitoring layered on top of controls to mitigate custody and legal-wrapper risk.
Reviewing the comprehensiveness of blockchain intelligence and its meaningful integration with controls for related risks must become a key component of every institution’s risk assessment framework. Blockchain intelligence must be able to trace the full transaction chain rather than screening at the edges, include secondary-market monitoring capabilities, and enable continuous behavioral monitoring. Given that digital assets often cut across many domains, it is also critical to unify risk functions across AML, fraud, sanctions, cyber, legal, and other areas so they can sit on top of on-chain products, provide a full picture of risk, and efficiently address any issues that may arise.
Looking ahead over the next five years, which regulatory, technological, or market developments do you believe will have the greatest impact on digital asset compliance and financial integrity, and what should policymakers, financial institutions, and the digital asset industry begin preparing for today?
Five years out, I would point to three forces converging. From a regulatory perspective, we are moving globally from framework-building to supervision and enforcement — the regulatory frameworks that were theoretical two years ago are now the standards institutions are being examined against, and enforcement gaps between jurisdictions will narrow as they are tested in real cases.
This clarity on regulatory expectations that comes with ongoing supervision and enforcement will, in turn, impact the market’s openness to expand into various types of digital asset products and services, depending on the perceived risk and regulatory standards that apply. It is clear, however, that digital assets can and will continue to unlock value in the financial industry, bringing benefits through innovation and furthering the interconnectedness of digital and real-world assets.
Market developments in digital assets must ultimately be rooted in robust technological fundamentals. New cybersecurity challenges are emerging in the form of artificial intelligence and quantum computing that will need to be managed carefully to ensure the continued viability and growth of the digital asset ecosystem.
The growth of tokenized real-world assets and the deepening of stablecoin settlement rails mean far more value will sit on public or permissioned ledgers, which is a genuine opportunity for transparency, but only if investigative capabilities keep pace. And the interconnectedness of blockchain ecosystems — more chains, more bridges, more cross-chain DeFi — means illicit finance will keep migrating toward whatever seam has the least visibility.
Financial institutions should be prepared to treat blockchain intelligence and investigative capabilities as core infrastructure investments, as exposure to digital assets will likely become the default rather than the exception in the years to come. More focus will need to be placed on the intersection between real-world and digital assets as the line blurs, while associated risks such as cybersecurity and custodial risk will become increasingly important.