The UK Financial Conduct Authority announced on July 25, 2024 that it had fined CB Payments Limited £3,503,546 for repeatedly breaching a regulatory restriction on onboarding or serving high-risk customers. CB Payments was part of Coinbase Group and provided e-money and payment services that could fund cryptoasset transactions through other Coinbase entities.
The FCA called the case its first enforcement action against a firm enabling cryptoasset trading. It was also the regulator's first enforcement action under the Electronic Money Regulations 2011. That combination made the development more significant than the size of the penalty alone: it showed how the FCA could use its payments supervision where a regulated gateway connected customers to a crypto platform, even though the gateway did not itself execute their cryptoasset trades.
What the restriction required
After identifying weaknesses in CB Payments' financial-crime controls during a February 2020 visit, the FCA imposed a voluntary requirement, or VREQ, on October 30, 2020. Despite the name, the resulting restriction was mandatory. It barred the company from onboarding specified high-risk customers or providing them payment or e-money services while controls were remediated.
The FCA's final notice, dated July 23 and published on July 25, defined the relevant breach period as October 31, 2020 through October 1, 2023. During that window, CB Payments onboarded approximately 3.9 million customers. The regulator found that 13,416 customers classified as high-risk under the VREQ were nevertheless onboarded or served. Coinbase separately said those customers represented 0.34% of customers onboarded and characterized the breaches as unintentional.
The FCA attributed the breaches to failures in the design, testing, implementation and monitoring of compliance controls. Its notice described incomplete implementation instructions, inadequate testing, gaps across products and onboarding routes, and monitoring failures that allowed repeated material breaches to remain undiscovered for almost two years.
The transaction figures need careful reading
Approximately 31% of the 13,416 affected customers made 12,912 prohibited deposits totaling about $24.9 million, according to the final notice. Those customers then made withdrawals and executed multiple cryptoasset transactions through other Coinbase Group entities using the same funds; the FCA put the combined value of those withdrawals and transactions at approximately $226 million.
The $226 million figure was transaction value, not customer deposits, revenue earned by Coinbase, proven criminal proceeds or a loss calculation. Repeated use of the same funds can produce transaction value far above the original deposits. The notice did not provide a complete breakdown that would permit an independent turnover calculation.
CB Payments filed Suspicious Activity Reports concerning 62 customers, covering transactions valued at approximately $1.75 million. A suspicious-activity report alerts law enforcement to potential concerns; it is not itself a finding that a customer committed a crime. The FCA said the control breaches increased financial-crime risk, not that all affected accounts or transactions were illicit.
Why the penalty mattered
The FCA said the failures breached both its Principle 2 requirement for due skill, care and diligence and the VREQ. The authority applied a substantial deterrence increase in its penalty calculation. CB Payments resolved the case at the first settlement stage and received a 30% discount; without that discount, the FCA said the penalty would have been £5,003,646.
Coinbase said it took the findings seriously, had invested in improving its UK financial-crime framework and would continue enhancing controls. The company also stressed that the restriction applied to its UK payments business, not every Coinbase entity or customer.
The event-day record therefore supports a narrow conclusion: on July 25, 2024, UK enforcement reached a regulated fiat gateway into a major crypto group for failures to honor an agreed customer-risk restriction. It did not revoke Coinbase's global operations, determine that the cited transactions were criminal, or establish a new comprehensive UK licensing regime for cryptoassets.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

