From Prohibition to Prosecution: Nigeria's Evolving Cryptocurrency Regulatory and Enforcement Landscape
Nigeria has undergone one of the most dramatic regulatory reversals in the global digital asset space, shifting from an outright banking ban to a comprehensive statutory framework backed by active enforcement. Here is what compliance professionals need to understand.
The Situation at a Glance
Nigeria is today one of the most consequential jurisdictions in global cryptocurrency regulation. With peer-to-peer trading volumes consistently ranking among the highest in the world, Nigeria’s regulatory choices carry significant weight for the continent and for global virtual asset service providers. Between 2017 and 2026, the country’s approach has moved through three distinct phases: cautious warning, outright prohibition, and structured statutory enforcement.
That journey has not been smooth. A seven-year period of regulatory ambiguity pushed trading underground, created parallel market distortions, and enabled large-scale financial crime to flourish beyond regulatory reach. The current framework, anchored by the Investment and Securities Act 2025 and supported by the CBN’s VASP Guidelines and the MLPPA 2022, represents a serious and deliberate effort to bring Nigeria’s digital asset sector into alignment with global AML and CFT standards. The exit from the FATF grey list in October 2025, after 32 months, confirmed that the effort is being recognised internationally.
The Regulatory Timeline: From Warning to Prohibition to Structured Access
Phase 1: The CBN’s Initial Caution (2017)
Nigeria’s first formal engagement with virtual assets came in January 2017, when the Central Bank of Nigeria issued Circular FPR/DIR/GEN/CIR/06/010, directing all financial institutions to refrain from using, holding or transacting in virtual currencies. The circular also required institutions to enforce AML and CFT controls on existing exchange customers and to report suspicious transactions immediately. This was a warning, not a ban. It signalled discomfort but left the ecosystem largely intact.
Phase 2: The Banking Ban (February 2021)
The CBN escalated sharply on 5 February 2021, ordering all deposit money banks and non-bank financial institutions to close all accounts belonging to cryptocurrency exchanges or individuals engaged in cryptocurrency transactions. The effect was immediate and severe. Crypto platforms lost access to the formal banking system entirely, and trading migrated into peer-to-peer networks and over-the-counter channels that were far harder to monitor or regulate.
The SEC attempted to fill the regulatory vacuum during this period. In September 2020 it had asserted jurisdiction over digital assets under Section 13 of the Investment and Securities Act 2007, and in May 2022 it introduced licensing frameworks for VASPs, DAOPs, digital asset exchanges and digital asset custodians. These frameworks were largely inoperative in practice. Without access to bank accounts, commercial entities had no incentive to incur the cost and burden of SEC registration.
Phase 3: The Policy Reversal and VASP Guidelines (December 2023)
The CBN reversed course on 22 December 2023, issuing its Guidelines on Operations of Bank Accounts for Virtual Asset Service Providers. The guidelines systematically lifted the banking ban under a structured risk-based framework. The key conditions are:
- Only SEC-licensed VASPs may open designated corporate bank accounts. Unlicensed entities remain excluded from the formal banking system.
- Commercial and merchant banks remain strictly prohibited from holding, trading or transacting in virtual currencies on their own account.
- Cash withdrawals from VASP accounts and third-party cheque clearing are prohibited. Standard NUBAN account numbers may not be generated for VASPs.
- Account opening requires formal written approval from senior bank management, validated SEC licences, corporate documentation and robust AML policies.
The Legislative Framework
Nigeria’s digital asset regulation is now anchored in primary legislation rather than administrative circulars, giving it permanence and enforceability that earlier instruments lacked.
Money Laundering (Prevention and Prohibition) Act 2022
Section 30 of the MLPPA 2022 explicitly defines virtual assets as property and formally classifies VASPs as financial institutions. This statutory designation removes any remaining ambiguity about the compliance obligations that attach to crypto platforms. All VASPs are now bound by the same AML and CFT documentation, transaction monitoring and KYC obligations that apply to banks and other regulated financial entities.
Cybercrimes (Prohibition, Prevention, Etc.) Act 2015, as Amended 2024
The Cybercrimes Act is the EFCC’s primary prosecutorial instrument for cryptocurrency-related offences. Multi-count indictments covering cyberterrorism, identity theft, money laundering and unlawful computer access are routinely framed under this legislation. The 2024 amendment significantly modernised the Act’s provisions to capture sophisticated cryptographic and network-based financial fraud, responding directly to the types of offending seen in cases such as Operation Eagle Flush and the Genting International prosecution.
Investment and Securities Act 2025
The ISA 2025, signed on 25 March 2025 and in force from 31 March 2025, is the most significant legislative development for digital assets in sub-Saharan Africa. It repealed the ISA 2007 entirely and, under Section 357, explicitly codifies virtual and digital assets as securities. The consequences are far-reaching:
- Section 3 establishes the SEC as the apex regulator of the entire virtual asset ecosystem, legally mandating that all VASPs, DAOPs and exchanges register and operate under its rules. Section 357 also broadens the definition of a securities exchange to cover any organised facility bringing together buyers and sellers of virtual assets, distributed ledger technologies or native cryptographic tokens.
- Most notably, Section 3(4)(o) introduces a private key domestication requirement, compelling digital custodians to maintain localised security nodes for assets under management within Nigerian jurisdiction. This provision directly addresses one of the core weaknesses previously identified by FATF in its grey list assessment: the unmonitored flight of digital capital across borders.
Finance Act 2023
Amending the Capital Gains Tax Act, the Finance Act 2023 formally classified digital assets and cryptocurrencies as chargeable assets. All realised crypto profits are now subject to capital gains tax, bringing the sector into the national tax framework and creating a further incentive for transparent, compliant operation.
Enforcement Architecture: Who Regulates and Who Prosecutes
Economic and Financial Crimes Commission (EFCC)
The EFCC, led since October 2023 by Executive Chairman Ola Olukoyede, is the frontline enforcement body. The scale of its activity between October 2023 and September 2025 illustrates the intensity of enforcement: 19,318 petitions received, 29,240 detailed investigations initiated, 10,525 formal cases filed and 7,503 convictions secured. Financial recoveries in this period totalled N566.3 billion and US$411.6 million, alongside the judicial forfeiture of 1,502 real estate assets.
The agency deploys advanced blockchain analytics tools to trace illicit digital wallet activity, working in close coordination with international partners. Its enforcement record in the cryptocurrency space is substantial and growing.
SEC, CBN and Inter-Agency Coordination
The SEC and CBN operate as the primary licensing and supervisory bodies, with enforcement powers delegated to the EFCC for criminal matters. An active inter-agency alliance between the three bodies uses shared blockchain intelligence to identify and freeze illicit wallets before criminal proceeds can be moved offshore.
NFIU and SCUML
The Nigerian Financial Intelligence Unit (NFIU) manages the macro-level AML architecture. Its Project Exit programme, which coordinated the legislative and regulatory reforms needed to satisfy FATF’s deficiency findings, resulted in Nigeria’s removal from the FATF grey list in October 2025 after 32 months of intensive remediation. The Special Control Unit Against Money Laundering (SCUML), embedded within the EFCC, directly supervises AML compliance for Designated Non-Financial Businesses and Professions, including crypto-adjacent service providers.
Six Landmark Enforcement Cases: 2024 to 2026
The real-world application of Nigeria’s digital asset laws is best understood through the six enforcement actions that have shaped the regulatory landscape over the past two years.
Case 1: Binance Nigeria: Executive Detention and Currency Speculation (2024)
In February 2024, Nigerian authorities detained two senior Binance executives, Tigran Gambaryan and Nadeem Anjarwalla, on charges of money laundering (US$35.4 million), operating an unlicensed financial institution and unlawful foreign exchange negotiation. Anjarwalla escaped from custody in March 2024. Charges against Gambaryan were dropped in October 2024 on medical grounds. The corporate prosecution against Binance continues, with prosecutors alleging that Nigerian users transacted over US$21.6 billion on the platform without identity verification, directly fuelling parallel market naira speculation.
Case 2: Operation Eagle Flush: Mass Cybercrime and Token Forfeiture (December 2024)
On 10 December 2024, the EFCC conducted its largest single-day raid, arresting 792 syndicate members, including 148 Chinese nationals and 40 Filipinos, operating from four high-end properties in Victoria Island and Ikoyi, Lagos. The group ran a coordinated international cryptocurrency investment fraud and romance scam network. Law enforcement seized 1,596 mobile devices, 2,120 workstations, 194 enterprise routers and a network server. Advanced blockchain analytics traced funds through peer-to-peer nodes to wallets linked to the Conti.vip cyberterrorism network. A Federal High Court granted permanent forfeiture of US$222,729.86 in USDT in July 2025.
Case 3: Genting International Co. Ltd: Landmark Sentences for Cyberterrorism (February 2026)
A Lagos High Court sentenced two Chinese directors of Genting International, Huang Haoyu and An Hongxu, to 46 years’ imprisonment each for cyberterrorism, internet fraud and money laundering. The criminal operation routed N3.4 billion through a Union Bank account alongside US$2,562,203 held in Binance and Bybit corporate wallets. All properties and hardware from four operational hubs were permanently forfeited under Sections 18 and 27 of the Cybercrimes Act.
Case 4: CBEX Ponzi Collapse: The N1.3 Trillion Non-Custodial Challenge (2025)
Crypto Bridge Exchange imploded in April 2025, defrauding hundreds of thousands of retail investors of N1.3 trillion through promises of 100 per cent returns within 30 days. The EFCC confirmed that full victim restitution is practically impossible. The syndicate routed funds across four countries using non-custodial wallets entirely devoid of KYC protocols. Three domestic suspects are in custody; key foreign promoter Elie Bitar has been declared wanted internationally. The case exposed the limits of enforcement where assets are held in unhosted, non-custodial wallets.
Case 5: Taofeek Daniel Oriola: Individual Laundering Conviction (May 2026)
A Lagos court sentenced Taofeek Daniel Oriola to nine years’ imprisonment for operating illicit cryptocurrency laundering desks. The court ordered the forfeiture of a 2014 Range Rover Supercharged, a five-bedroom apartment in Ibeju-Lekki, a 653-square-metre land parcel and an iPhone 16. The case illustrates enforcement against individual actors, not only institutional platforms.
Case 6: N162 Billion Bank-Fintech Fraud: The KYC Compliance Failure (January 2026)
In January 2026, an EFCC investigation exposed systematic compliance failures within a new-generation commercial bank, six fintech platforms and multiple microfinance banks. A combined N162 billion in illicit cryptocurrency-linked transactions bypassed core customer due diligence protocols during the 2024/2025 financial period. In a striking illustration of the failure, a single fraudulent customer successfully maintained 960 separate accounts within one institution. Over 200,000 citizens were affected. The EFCC recovered and returned N33.62 million to victims.
International Cryptocurrency Recovery: Lessons for Nigerian Enforcement
Nigeria’s enforcement agencies are studying international precedents to strengthen domestic asset recovery capabilities. Three cases are particularly instructive.
The Wormhole Bridge Hack: US$400 Million Cross-Border Recovery (UK/US, 2024)
Following a US$400 million decentralised bridge exploit, Tai Mo Shan Limited obtained an urgent proprietary injunction from the English High Court compelling a third-party DeFi provider to modify its smart contract architecture, enabling the direct seizure of 90 per cent of the hacker’s wallet contents. A concurrent New York default judgment was recognised globally. Crucially, the courts validated the service of legal process via non-fungible tokens sent directly to public wallet addresses, establishing a novel legal mechanism for reaching anonymous blockchain actors.
UK Metropolitan Police: GBP 5 Billion Bitcoin Seizure (2025)
Chinese national Qian Zhimin was convicted in London after UK and Chinese law enforcement completed a seven-year joint investigation. The 61,000 bitcoins in her possession, derived from a wealth management fraud affecting 128,000 victims in mainland China, represented the largest cryptocurrency seizure in UK history. The case demonstrates both the value of long-term cross-border cooperation and the patience required in complex digital asset investigations.
Greece: First Cryptocurrency Seizure via Bybit Hack Trace (2025)
The Hellenic Anti-Money Laundering Authority executed Greece’s first cryptocurrency asset freeze by using Chainalysis Reactor software to trace funds from the US$1.5 billion Bybit exchange exploit carried out by North Korea’s Lazarus Group. Coordinated asset freezes were executed across Greece and Germany, with 12 global agencies participating. Germany seized EUR 34 million from the eXch platform. The case illustrates the technical and institutional infrastructure required for effective multi-jurisdictional crypto asset recovery.
Nigeria and FATF: The Global Compliance Context
The Financial Action Task Force’s Recommendation 15 requires all jurisdictions to treat virtual assets as property or funds, mandate registration for all VASPs and deploy risk-based supervisory frameworks. Recommendation 16, the Travel Rule, requires VASPs to obtain and transmit originator and beneficiary data for all token transfers exceeding US/EUR 1,000. Global implementation of the Travel Rule remains fragmented, with approximately 75 per cent of jurisdictions falling short as of 2024.
Nigeria’s regulatory overhaul, including the passage of the ISA 2025, the MLPPA 2022 and the CBN VASP Guidelines, was directly driven by its 32-month FATF grey listing from February 2023. The ISA 2025’s private key domestication requirement under Section 3(4)(o) was a specific legislative response to deficiencies identified under Recommendation 15. Nigeria’s October 2025 exit from the grey list under Project Exit confirmed international recognition of these reforms. The IMF-FSB Synthesis Paper of September 2023 had warned that the borderless nature of cryptocurrency renders isolated national frameworks weak, a lesson Nigeria’s legislative programme has clearly absorbed.
Key Compliance Takeaways
At JIN Legal and Regulatory Compliance Consultants, we draw the following practical lessons for regulated entities, compliance professionals and legal practitioners from Nigeria’s cryptocurrency enforcement landscape.
1. VASPs Must Secure SEC Licensing Before Opening Bank Accounts.
The December 2023 VASP Guidelines make SEC licensing the gateway to formal banking access. Any virtual asset service provider operating in Nigeria without a valid SEC licence is excluded from the banking system and exposed to prosecution. The licensing framework under the ISA 2025 provides the statutory foundation. There is no compliant path to operation without it.
2. Banks and Fintechs Face Serious Liability for KYC and CDD Failures.
The N162 billion bank-fintech investigation is the most important compliance warning in this body of case law. The primary financial crime risk in Nigeria’s digital asset sector is not sophisticated crypto fraud alone. It is the failure of basic customer due diligence within mainstream financial institutions. Banks and fintechs that process cryptocurrency-linked transactions without adequate KYC controls face EFCC investigation, regulatory sanction and reputational damage. The 960-account single-customer failure must not be treated as an outlier.
3. The ISA 2025 Removes Any Remaining Regulatory Ambiguity.
Virtual assets are now explicitly classified as securities under Nigerian law. VASPs, DAOPs and digital exchanges are legally required to register with the SEC and operate under its rules. The private key domestication requirement under Section 3(4)(o) imposes specific technical obligations on custodians. Compliance functions in institutions with Nigerian exposure should review their frameworks against the ISA 2025 without delay.
4. Non-Custodial Wallets Represent an Enforcement Blind Spot That Requires Policy Attention.
The CBEX collapse demonstrated that where criminal proceeds are held in non-custodial, KYC-free wallets and routed across multiple jurisdictions, full recovery is practically impossible under current frameworks. Institutions and regulators must assess their exposure to non-custodial wallet activity, and compliance frameworks should include specific risk indicators for transactions that route through non-custodial infrastructure, particularly where they originate from higher-risk jurisdictions.
5. Cross-Border Enforcement Infrastructure Is Now a Compliance Necessity.
The Wormhole, UK Bitcoin and Bybit seizure cases confirm that effective cryptocurrency asset recovery requires multi-jurisdictional legal strategies, advanced blockchain analytics and sustained interagency cooperation. Nigerian enforcement agencies are actively developing these capabilities. Institutions operating across borders should ensure they have clear protocols for responding to freezing orders, asset recovery requests and cross-border information-sharing demands from Nigerian and international enforcement bodies.
6. Nigeria’s FATF Exit Signals Rising Regulatory Expectations.
Nigeria’s removal from the FATF grey list in October 2025 is a marker of progress, not a signal to relax. The reforms that achieved the exit, including the ISA 2025, the MLPPA 2022 and the CBN VASP Guidelines, create a substantially higher compliance baseline than existed before. Institutions with Nigerian operations or Nigerian-linked customer bases should treat 2025 as the start of a new regulatory era, not the end of a remediation programme.
Prepared by JIN Legal & Regulatory Compliance Consultants
Expert Insight | Proactive Compliance | Strategic Governance
This alert is for informational purposes only and does not constitute legal advice.
