In the past two days, Mankun Law Firm has received numerous inquiries from clients: In certain Web3 teams, where the company lacks a suitable exchange entity account, it requires employees to provide their identity cards, mobile phone numbers, and undergo facial recognition to complete exchange KYC procedures in their personal names. After the account is registered, passwords, verification codes, and API keys()and even withdrawal permissions are controlled by the company’s finance department or project managers. Several months after an employee resigns, the account may suddenly be subject to risk control measures, the source of assets may come under investigation, or public security organs may locate the employee based on the real-name information.
At this point, merely explaining that “the account actually belongs to the company, and I only assisted with the real-name registration” usually does not resolve the issue immediately.
While the exchange sees the employee’s real-name identity, determining who ultimately bears legal responsibility requires further investigation into who controls the account, who makes trading decisions, what the employee knew, and whether the employee continued to provide assistance after resignation.
Therefore, when a company makes such requests, employees must first recognize that this is not ordinary administrative cooperation, but rather involves using their personal identity to assume responsibility for a fund account that may operate over the long term.
After completing KYC, the account primarily points to the employee personally in external relations.
KYC()The basic function of KYC is for the platform to verify customer identity and establish a correspondence between the account and a specific natural person or entity.
If an employee uses their own identity document, mobile phone number, facial information, and email address to register an account, then regardless of how the company internally labels it, for the exchange, risk control institutions, and investigative authorities, the account is primarily linked to the employee through real-name identification.
The company’s internal characterization of the account as a “company account” does not automatically alter the following facts: the real-name registrant is the employee; facial authentication was performed by the employee; platform notifications may be sent to the employee’s mobile phone or email; when the platform produces data, the employee’s identity will be the primary information appearing; and if abnormal transactions occur, the employee may also be the first person questioned.
The fact that the employee is the real-name registrant does not mean that every transaction within the account was necessarily executed by the employee; likewise, the company’s actual control over the account does not mean that the employee necessarily bears no responsibility.
What truly needs to be determined is whether, beyond providing identity information, the employee participated in logging in, depositing funds, trading, withdrawing funds, conducting OTC payments and receipts, maintaining wallet addresses, or making decisions regarding fund flows.
The very reason why the company borrows an employee’s identity constitutes the first risk signal.
A company conducting business in the ordinary course should, in principle, open and use accounts in accordance with platform rules, under the identity of the genuine business entity or the actual user.
If a company repeatedly requires employees, interns, or outsourced personnel to register real-name accounts, it is usually necessary to further ascertain the reasons: Is it because the platform temporarily does not support institutional accounts for the region where the company is located, or because the company cannot pass entity verification? Is it to segregate different lines of business, or to circumvent regional restrictions, account limits, or the platform’s risk control measures? Are the accounts used for general asset management, or for over-the-counter (OTC) trading(), customer collections, fund pooling, and outbound payments?
The risks associated with different reasons vary significantly.
The 2026 Notice on Further Preventing and Disposing of Risks Related to Virtual Currencies and Other Matters continues to clarify that conducting businesses within the mainland of China involving the exchange between fiat currency and virtual currencies, the exchange between virtual currencies, acting as an intermediary for transaction information, and pricing-related services constitutes illegal financial activities that are strictly prohibited and subject to lawful ban; overseas entities and individuals are also prohibited from illegally providing related services to domestic entities.
Therefore, if employee personal accounts are in fact used for opening accounts for domestic customers, collecting funds, purchasing USDT, transferring and settling funds, or circumventing regional restrictions, the risk cannot be understood merely as “corporate asset management.”
The more reluctant a company is to explain the purpose of the accounts, the more it requires employees to conceal the actual users, or the more frequently it changes real-name accounts, the more cautious employees should be.
Does stating “I only provided my ID card” necessarily mean there is no liability?
Not necessarily; however, this alone does not directly establish that the employee bears criminal liability.
Common scenarios can be categorized into four tiers:
Providing identity information only
Common manifestations:Completed KYC once and did not log in again; did not control the password or know the purpose of the funds
Key factors for determination:Whether the individual knew the company’s actual purpose, and whether they proactively requested to cease use
Continued cooperation with verification
Common manifestations:Repeatedly providing verification codes and facial recognition authentication to help lift risk controls
Key factors for determination:Whether the individual had already detected account anomalies and yet continued to provide assistance
Participation in account operations
Common manifestations:Being responsible for buying crypto assets, selling crypto assets, transferring funds, withdrawing crypto assets, or maintaining addresses
Key factors for determination:Nature of funds handled, frequency of operations, instructions from superiors, and abnormal circumstances
Involvement in core business operations
Common manifestations:Determining the flow of funds, managing multiple real-name accounts, and receiving commissions based on transaction volumes
Key factors for determination:Whether there is participation in joint business operations and whether a stable coordination has been formed with upstream parties
If an employee merely completes a one-time real-name registration as required by the company, thereafter cannot log into the account, has no contact with the funds, and is unaware that the company uses the account for illegal or criminal activities, this scenario shall not be evaluated in the same manner as cases where an employee long-term provides facial recognition verification, handles abnormal cryptocurrency withdrawals, or executes fund transfers.
The 2025 Opinions issued by the Supreme People’s Court, the Supreme People’s Procuratorate, and the Ministry of Public Security regarding cases of aiding information network criminal activities emphasize that determining whether a perpetrator knowingly facilitates others in committing crimes via information networks shall be comprehensively assessed based on factors such as cognitive capacity, professional identity, prior experience, manner of assistance, frequency, profits gained, and whether regulatory measures were evaded, so as to avoid direct criminal liability based solely on objective acts.
Providing identity information constitutes a factual risk, but it does not constitute a complete conclusion of liability.
What criminal risks may arise when an account receives funds involved in fraud?
The legal evaluation differs significantly between scenarios where an employee’s real-name account is used for ordinary investments or corporate asset management, and scenarios where it is used to receive, convert, or transfer criminal proceeds.
If an employee, knowing that others are using information networks to commit crimes, still provides internet accounts, payment settlement services, or technical support, and the circumstances are serious, this may constitute the crime of aiding information network criminal activities. For those who acquire, organize, or recruit others to provide bank accounts, payment accounts, or internet accounts, and form a stable coordinated relationship with upstream crimes, they may also be evaluated as accomplices to the upstream crimes depending on the specific circumstances.
If, after the proceeds of crime have been generated, an employee uses an exchange account to purchase virtual assets and then transfers such virtual assets to a designated wallet, thereby helping to alter the form of the funds and sever the tracing chain, the employee may further be implicated in the crime of concealing or disguising the proceeds of crime and the gains derived therefrom.()。
However, the mere fact that an account has received funds involved in the case does not necessarily mean that the real-name employee was aware of it. Judicial authorities must conduct a comprehensive review of whether the transactions were abnormal, what information the employee had access to, the scale and frequency of the funds, the relationship between the employee and the company’s controlling persons, whether the employee received abnormal benefits, and whether the employee continued to cooperate after discovering the abnormalities.
If the account continues to be used by the company after the employee’s departure, what are the key factors for determining liability?
Departure is an important temporal node, but it does not automatically constitute a clear-cut line for severing liability.
Where an employee has departed but the account remains active in trading, five issues typically warrant focused scrutiny: first, whether the employee knew at the time of departure that the account was still operational; second, whether the employee had made a written request to the company to cease using the account and completed the handover or revocation of passwords, mobile phone numbers, email addresses, API keys, and withdrawal permissions; third, whether the employee continued to provide verification codes, facial recognition authentication, or assistance in lifting risk-control restrictions after departure; fourth, whether the employee continued to receive salary, commissions, revenue-sharing from transaction volumes, or other benefits after departure; and fifth, which devices, IP addresses, API keys, and wallet permissions were actually used to initiate the abnormal transactions.
A certificate of employment termination only proves the termination of the labor or cooperative relationship; it cannot, by itself, prove that control over the account and any aiding conduct ceased simultaneously.
Conversely, if the employee had expressly objected in writing to the continued use of the account, completed applications to freeze or close the account, and subsequent transactions were carried out by the company using other devices and permissions, these facts may also serve as important evidence for distinguishing liability.
Before departure, it is advisable to complete this “KYC Account Handover Checklist.”Identity Aspect
Content to be preserved or verified:Preserve the account registration time, KYC pages, the authenticated entity, and authentication materials; confirm whether control over the mobile phone number, email address, and facial verification permissions remains with the individual; retain chat records and approval information in which the company requested the provision of identity information.
Recommended actions:Confirm whether you will still be required to provide verification codes, facial recognition, or other forms of authentication going forward; if you no longer wish to participate, promptly notify the company in writing to cease using your real-name information.
Account Side
Content to Preserve or Verify:Export historical login devices, login IP addresses, transaction records, deposit and withdrawal records, API keys, sub-accounts, and cryptocurrency withdrawal whitelists; confirm which permissions are used by you personally and which have been handed over to other personnel within the company.
Recommended Actions:Depending on the specific circumstances, change passwords, unbind devices, revoke API access, remove withdrawal addresses, close sub-accounts, or apply for account freezing.
On-Chain Side
Content to Preserve or Verify:Preserve primary deposit addresses, withdrawal addresses, transaction hashes, and wallets designated by the company; correlate exchange records with on-chain transfer timestamps to avoid situations where only isolated wallet addresses remain without explanation in the future.
Recommended Actions:Strive to establish a one-to-one correspondence among "account transaction records—wallet addresses—on-chain transfers" to form a basic fund trail.
Workplace Side
Content requiring preservation or verification:Preserve employment contracts, job descriptions, work instructions, bank statements showing salary payments, commission rules, account handover documents, and certificates of employment termination; retain communication records from before and after termination.
Recommended actions:Clearly notify the company via email or enterprise chat tools to cease using personal real-name accounts, and preserve records of sending and delivery.
Special Reminder
•After preserving evidence, employees may take measures such as changing passwords, unbinding devices, revoking API access, removing cryptocurrency withdrawal addresses, applying for account freezes, or closing accounts, depending on the specific circumstances.
•However, do not unauthorizedly delete records, transfer account assets, or destroy devices after an investigation has commenced.
•Ceasing the company’s continued control over the account is entirely distinct from deleting evidence that may be used to establish facts.
If the account has been subject to risk control measures or contacted by public security authorities, the first step is not to align testimonies.
Once an account faces risks, some companies may require employees to uniformly claim that “this is a personal cryptocurrency trading account,” or conversely, require employees to explain it entirely as a “company account, unrelated to me.” Both approaches may be overly absolute.
More importantly, clarify based on objective materials: why the account is registered under the employee’s real name; who set and stored the password; who bound the mobile phone number and email address; who holds API and withdrawal permissions; from which device specific transactions were initiated; whether the employee had access to the source of funds; when the employee terminated employment; and whether assistance was still provided after termination.
The key to such cases often lies not in a single oral explanation, but in correlating real-name identity, account control, transaction operations, on-chain funds, and work instructions.
Employees should be particularly cautious against hastily signing statements that are inconsistent with the facts, such as admitting to "voluntarily lending their accounts to others for fund turnover" or assuming full responsibility for all account operations on behalf of the company. Once such explanations conflict with backend logs, chat records, or on-chain data, they become significantly more difficult to rectify.
When lawyers intervene, the focus is not merely on proving that "this is a company account."
In cases of this nature, simply emphasizing that the account was used by the company is insufficient.
Lawyers must first reconstruct the chain of account control by verifying real-name registration information, login devices, IP addresses, verification codes, API keys, withdrawal addresses, and transaction instructions, to determine who had actual control over the funds.
Secondly, it is necessary to reconstruct the evolution of the employee’s awareness: what purposes the employee was initially told the account would serve, when anomalies were discovered, whether the employee received notifications regarding frozen cards, fraud involvement, risk control measures, or complaints, and whether the employee continued to provide assistance thereafter.
Thirdly, a distinction must be drawn between the employee’s regular salary and any abnormal profits, avoiding the direct equating of normal labor compensation with illegal gains. It is also necessary to examine whether compensation was calculated based on transaction volumes, deposit and withdrawal amounts, or the number of accounts.
If the employee has already been summoned, detained, or if assets in the account have been seized, lawyers may prepare applications for release on bail pending trial,()arguments against approval of arrest, arguments for non-prosecution, or defenses for mitigated criminal liability, focusing respectively on actual control, subjective knowledge, duration of participation, amount involved, and the individual’s role.
Concluding Remarks
When a company requires employees to complete exchange KYC procedures using their own identities, it may appear to be merely a facial recognition verification. In reality, however, it may result in the employee’s identity being long-term linked to the company’s transactions, funds, and on-chain activities.
The name under which the account is registered determines who is likely to be identified first during an investigation; however, ultimate liability depends on who controlled the account, who operated the funds, whether the employee had actual knowledge, and whether assistance was continued after resignation.
For current employees, the most critical step is to clarify the purpose of the account as early as possible and not to treat ID cards, facial recognition data, verification codes, and transaction permissions as ordinary office materials to be handed over to the company. For those preparing to resign, it is essential to complete a separate handover of accounts, permissions, and evidence, rather than merely obtaining a certificate of employment termination.
If an account is already involved in fraud-related funds, subject to platform-assisted investigations, asset freezes, or contact by public security authorities, it is even more critical not to rush to delete records or coordinate a uniform narrative with the company. The sooner you clearly reconstruct your identity, accounts, devices, on-chain addresses, and work instructions, the more likely it is that the company’s overall risk will be distinguished from your individual specific liability.
/ END.
*This article is an original work of Mankun Law Firm. It reflects only the personal views of the author and does not constitute legal consultation or legal advice on any specific matter. For reprints and legal consultation, please add our customer service contact:mankunlawyer。

About Mankun



