Ireland’s central bank announced on November 6, 2025, that Coinbase Europe Limited had accepted a reprimand and a €21,464,734 monetary penalty for failures in its anti-money-laundering and counter-terrorist-financing transaction monitoring.
The settlement was significant beyond its size. The Central Bank of Ireland described it as the regulator’s first enforcement outcome in the crypto sector, placing a major digital-asset intermediary under the same operational expectations applied to other regulated financial institutions. Coinbase Europe admitted the prescribed contraventions and agreed to the regulator’s undisputed facts.
The parties reached the settlement on November 5, 2025. As of the November 6 announcement, however, the sanctions still required confirmation by Ireland’s High Court before taking effect.
What the regulator found
The central bank said faults in Coinbase Europe’s transaction-monitoring system left 30,442,437 transactions without full and proper screening. Those transactions had an aggregate value exceeding €176 billion and represented approximately 31% of the company’s transactions during the affected 12-month period. That figure measured transaction value; it did not represent customer losses or proven criminal proceeds.
The underlying configuration problems affected monitoring during portions of 2021 and 2022. The broader contravention period ran from April 23, 2021, through March 19, 2025 because reviewing the backlog and completing required follow-up took substantially longer.
After the affected transactions were screened again, 184,790 required additional review. Coinbase Europe ultimately submitted 2,708 suspicious transaction reports to Ireland’s Financial Intelligence Unit. A suspicious transaction report records suspicion or reasonable grounds for suspicion; its filing does not establish that a crime occurred. The regulator said the reports included suspicions associated with fraud, drug trafficking, cyberattacks and other serious offenses.
The settlement also found that Coinbase Europe had not maintained sufficient internal policies, controls and procedures to prevent and detect money laundering and terrorist financing. The central bank characterized the conduct behind the contraventions as negligent. It treated delayed notification as an aggravating factor: the regulator was not informed of the full non-monitoring issue until November 21, 2023.
How the penalty was calculated
The central bank initially determined that a €30,663,906 penalty was warranted. A 30% discount under its settlement process reduced that amount to €21,464,734. The company accepted both the monetary penalty and a reprimand.
The regulator calculated the sanction against Coinbase Europe’s financial position and the duration and seriousness of the failures. Its settlement notice listed 2024 turnover of €486.565 million and said the maximum available monetary penalty in the case was €48.6565 million.
Coinbase’s account of the failure
In its November 6 response, Coinbase described three coding errors that prevented five of 21 monitoring scenarios from fully screening transactions. The company said other monitoring scenarios and complementary compliance controls continued operating, and that the coding errors were fixed within two to three weeks after discovery.
Coinbase also said the much longer process involved rerunning the affected transactions through the corrected scenarios and manually investigating the resulting alerts. It emphasized that the reports filed after this review reflected suspicions rather than confirmed criminal conduct. Those explanations were the company’s contemporaneous account, not independent findings that displaced the regulator’s settlement record.
Why the case mattered
The action showed that software configuration was a regulatory control, not merely an engineering concern. For a crypto platform operating across borders, incomplete rules, testing failures or delayed escalation could impair legally required monitoring at enormous transactional scale.
The timing also intersected with Europe’s transition to the Markets in Crypto-Assets framework. Coinbase Europe planned to transfer its crypto-services business to an affiliated Luxembourg entity authorized under MiCA as Irish virtual-asset-service-provider registrations approached expiration. The Irish case nevertheless concerned obligations under Ireland’s 2010 anti-money-laundering law; it was not a MiCA enforcement action.
Later context
The Central Bank of Ireland subsequently updated its record to state that the High Court confirmed the sanctions on January 12, 2026. That confirmation was not yet available on November 6, 2025 and does not alter the event-day distinction between an accepted settlement and an effective sanction.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

