chainscore.net ScoreGuard
Re-run now VASP directory
32of 100

Know Your VASP report Severe risk

Kiosk Cash Exchange
High Risk Exchange · incorporated in Curacao · founded 2022 · attribution: synthetic
Desk review10
On-chain review50
Cluster volume 0

Kiosk Cash Exchange is a high risk exchange incorporated in Curacao, assessed at 32/100 (severe risk) from a desk review of 10/100 and an on-chain review of 50/100. Licence status is unlicensed with none evidence (no identified regulator), MiCA not authorised, KYC rigour weak, Travel Rule absent. The largest single deduction is 22 points for licence status: unlicensed — no identified regulator. No clustered wallet could be screened, so the on-chain half of the score falls back to a neutral 50. No identified licence; onboarding requires senior sign-off and ongoing monitoring.

Combined score weights the desk review at 45% and the on-chain review at 55%, because chain evidence is observed while the regulatory file is asserted.

What this assessment rests on

45% of the score is a desk review of the regulatory file. Licence status, controls and monitoring maturity are asserted in the directory record rather than observed on chain, and no attribution measurement grades them. This directory record is a demonstration entry, so the paperwork it describes belongs to no real business.

55% of the score is the on-chain review, and none of the 1 clustered address(es) could be screened, so that half falls back to a neutral 50 and rests on no observed evidence.

The attribution figure covers the on-chain review only. There is no single coverage percentage for this score, because the desk review half is not measured over counterparty value.

Regulatory file

Legal nameKiosk Cash Exchange
Trading nameKiosk Cash Exchange
Licence statusunlicensed (none evidence)
Regulatorno identified regulator
Licence reference
MiCA statusnot authorised
JurisdictionCuracao (CW), risk 4/10 · offshore secrecy
Operational hubsCW, KP, VG

Controls

KYC rigourweak · Verification only above a high threshold, or easily bypassed.
Withdrawal KYC threshold $10,000
Travel Ruleabsent · No Travel Rule capability identified.
Transaction monitoringabsent
Sanctions screening none identified
Source of funds checks not performed
Custody modelcustodial

Desk review deductions

90.5 points deducted from 100.

Licence status -22.0 pts
unlicensed — no identified regulator
KYC rigour -14.0 pts
Verification only above a high threshold, or easily bypassed.
Travel Rule -12.0 pts
No Travel Rule capability identified.
Transaction monitoring -10.0 pts
monitoring programme absent
MiCA status -9.0 pts
MiCA not authorised
Sanctions screening -9.0 pts
no sanctions screening programme identified
Licence evidence -8.0 pts
licence evidence is none
Jurisdiction -5.0 pts
Curacao is an offshore secrecy jurisdiction
Jurisdiction risk -1.5 pts
Curacao carries jurisdiction risk 4/10

On-chain review of the provider's clusters

Clustered addresses 1
Wallets screened 0
Inbound 0
Outbound 0
Illicit share 0.0%

Risk composition of managed wallets

No on-chain activity was returned for the clustered wallets.

Screened wallets

AddressChainScoreRisk InboundOutboundTransfersSource
3BdCD7dRZ8pJ3QNS4wiwjnZPT3D95dczGz Bitcoin provider error (ProviderError)

Compliance and provenance

Travel Rule counterparty not ready · No Travel Rule capability identified.
Data sourcenone · 0 of 1 clustered address(es) screened
Directory41 VASP profiles, 2463 labelled entities

Label sources

  • Sanctions: 943 designated addresses from the US Treasury OFAC SDN list, published 08/28/2026.
  • Token contracts: 927 identified from public token lists.
  • Cited public labels: 519 addresses from 34 source(s), each with a URL.
    • Aave address book: V3 Ethereum (98 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Ethereum.json
    • FBI/IC3 PSA: North Korea responsible for $1.5 billion Bybit hack (51 addresses) — https://www.ic3.gov/PSA/2025/PSA250226
    • Aave address book: AaveV3Polygon (45 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Polygon.json
    • Aave address book: V2 Ethereum (40 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Ethereum.json
    • Aave address book: AaveV3Arbitrum (39 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Arbitrum.json
    • Aave address book: AaveV3Optimism (31 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Optimism.json
    • Aave address book: AaveV3Base (25 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3Base.json
    • Tornado Cash smart contracts (24 addresses) — https://docs.tornado.cash/general/tornado-cash-smart-contracts
    • Bybit: wallet addresses ownership explained (21 addresses) — https://www.bybit.com/en/help-center/article/Bybit-Wallet-Addresses-Ownership-Explained
    • Circle CCTP EVM contract addresses (20 addresses) — https://developers.circle.com/cctp/evm-smart-contracts
    • Aave address book: AaveV3BNB (18 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3BNB.json
    • Bitfinex: published public wallets (16 addresses) — https://github.com/bitfinexcom/pub/blob/main/wallets.txt
    • Aave address book: AaveV2Polygon (16 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV2Polygon.json
    • Aave address book: AaveV3EthereumLido (12 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/AaveV3EthereumLido.json
    • Crypto.com: Transparency First cold-wallet list (10 addresses) — https://crypto.com/en/company-news/transparency-first
    • Uniswap v3 Arbitrum deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/arbitrum-deployments
    • Uniswap v3 Optimism deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/optimism-deployments
    • Uniswap v3 Polygon deployments (7 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/polygon-deployments
    • Lido deployed contracts (6 addresses) — https://docs.lido.fi/deployed-contracts/
    • Uniswap v3 Base deployments (6 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/base-deployments
    • Uniswap v3 Ethereum deployments (3 addresses) — https://docs.uniswap.org/contracts/v3/reference/deployments/ethereum-deployments
    • Chainalysis: Euler Finance flash loan attack (2 addresses) — https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/
    • Morpho deployed contracts (2 addresses) — https://docs.morpho.org/get-started/resources/addresses
    • Compound III USDC Ethereum roots (2 addresses) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdc/roots.json
    • Aave address book: GhoEthereum (2 addresses) — https://aave-dao.github.io/aave-address-book/api/v1/modules/GhoEthereum.json
    • Railgun privacy system contracts (1 address) — https://docs.railgun.org/wiki/learn/helpful-links
    • Linea network contracts (1 address) — https://docs.linea.build/network/build/contracts
    • Starknet L1-L2 messaging (1 address) — https://docs.starknet.io/documentation/architecture_and_concepts/Network_Architecture/l1-l2-messaging/
    • Chainalysis: Wormhole hack February 2022 (1 address) — https://www.chainalysis.com/blog/wormhole-hack-february-2022/
    • Compound III USDS Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usds/roots.json
    • Compound III USDT Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/usdt/roots.json
    • Compound III WBTC Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wbtc/roots.json
    • Compound III WETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/weth/roots.json
    • Compound III WSTETH Ethereum roots (1 address) — https://github.com/compound-finance/comet/blob/main/deployments/mainnet/wsteth/roots.json
  • Demonstration data: excluded — 118 synthetic entities were not scored.

Screen window

  • Up to 500 transfers across 3 indexer page(s) · default 3 hops · hop-2 budget 16 · hop-3 budget 12.

Artefact integrity

  • sha256+hmac · SHA-256 8161cb7fd2e4c42413c46106235d8142118732b39b73165d6f41b916039ec402 · sealed 2026-09-13T20:16:29+00:00 · HMAC present.

Frameworks covered

Informative

Notice / Disclaimer

Limits that apply to this artefact as a whole. Sources and hashes stay in provenance; this section is how to read them.