CRYPTO POLICY
1. POLICY STATEMENT
Code Harbor N.V. (“the Company”) is committed to maintaining robust and effective controls over the acceptance, holding, and payment of crypto-assets in connection with its remote gambling operations. This policy is based on the Curaçao Gaming Authority (CGA) Crypto Policy Guideline for Online Gaming Operators, the National Ordinance on Games of Chance (LOK 2024), and applicable AML/CFT legislation, and incorporates guidance from the CGA and international best practice, including the FATF Recommendations.
This policy applies to all crypto-asset workflows operated by the Company, including deposits, wagering, withdrawals, and treasury activities, and to all group entities supporting the CGA-licensed operation. It does not replace or limit any other legal, regulatory, or licensing obligation, including VASP-related laws and regulations applicable in Curaçao. The Company remains independently responsible for ensuring full compliance with all applicable registration, licensing, reporting, and other regulatory requirements in this respect.
This policy is to be read together with, and does not replace, the Company’s Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) Policy. Where cryptocurrency transactions are accepted, the applicable crypto-specific controls are expressly detailed in both this policy and the Company’s submitted AML/CFT policy on the CGA portal.
This document defines the operational procedures and responsibilities that support crypto-asset compliance and risk management. It is signed off by the Compliance Officer, approved by the Board of Directors, and reviewed at least annually, or earlier where material regulatory changes, incidents, or new asset/VASP additions occur.
2. PURPOSE
The purpose of this policy is to set the minimum internal controls for accepting, holding, and paying out crypto-assets in remote gambling operations, and to ensure that the risks associated with money laundering, terrorist financing, proliferation financing, fraud, and player harm arising from the use of crypto-assets are identified, assessed, and mitigated to the same standard applied to fiat currency. It establishes the framework for asset-specific risk assessment, VASP due diligence, wallet governance, transaction monitoring, blockchain analytics, incident reporting, and staff training.
3. SCOPE AND APPLICABILITY
This policy applies to the Company with regard to all crypto-asset activities regulated and licensed by the CGA. It is binding on all directors, officers, employees, contractors, agents, and assignees involved in crypto-asset workflows, including but not limited to the Compliance Department, the payments team, risk and fraud teams, customer support, and any third-party VASP or payment provider engaged by the Company.
4. DEFINITIONS AND FRAMEWORK
For the purpose of this policy, the following definitions apply:
- VASP – Virtual Asset Service Provider. A legal or natural person that conducts one or more of the following activities on behalf of another person: exchange between virtual assets and fiat currencies; exchange between virtual assets; transfer of virtual assets; safekeeping or administration of virtual assets or instruments enabling control over them. Aligned with FATF Recommendation 15.
- Compliant VASP – A VASP that demonstrates appropriate standards of AML/CFT compliance, Travel Rule capability, sanctions screening, operational resilience, and transparency — assessed by the Company on a risk basis, not determined by jurisdiction label alone.
- Unhosted Wallet – A wallet not managed by a VASP and controlled directly by a user through private keys. The unhosted status of a wallet affects risk treatment and Travel Rule applicability.
- Wallet Ownership Verification – The process of confirming that a customer controls a specific wallet address, through methods such as test transactions (e.g. Satoshi test), signed messages, or equivalent mechanisms.
- Blockchain Analytics Tools – Systems capable of tracing, analysing, and risk-assessing virtual asset transactions, including identification of exposure to high-risk or prohibited sources.
- FATF Travel Rule – The requirement under FATF Recommendation 16 that originator and beneficiary information must accompany virtual asset transfers between VASPs and be made available to competent authorities upon request.
- Whitelisting – A control whereby only pre-verified and approved wallet addresses may receive outbound withdrawals from the Company’s platform.
- Hot / Warm / Cold Wallet – Wallets classified by connectivity and purpose: hot wallets are online and used for day-to-day player transactions; warm wallets support liquidity management under enhanced controls; cold wallets are offline and used for treasury and reserve safekeeping.
- Stablecoin – A crypto-asset designed to maintain a stable value, typically pegged to a fiat currency. The Company distinguishes between fiat-backed regulated stablecoins (preferred) and unregulated or algorithmic stablecoins (subject to heightened review).
- CGA – Curaçao Gaming Authority. The regulatory body responsible for overseeing, licensing, and supervising the gaming and gambling industry in Curaçao, including AML/CFT supervision in the gaming sector.
- LOK – The National Ordinance on Games of Chance, the primary legal framework governing games of chance in Curaçao.
5. GOVERNANCE AND ACCOUNTABILITY
The Company’s Board of Directors retains ultimate accountability for this policy and for the Company’s crypto-asset risk exposure. Day-to-day implementation is delegated to the Chief Compliance Officer (CCO) and the payments team, including responsibility for on-chain risk screening.
This policy is signed off by the CCO and approved by the Board, and states its effective date. It is reviewed at least annually, and an unscheduled review is triggered by material regulatory change (including updates to the CGA Crypto Policy Guideline), a material crypto-related incident, the addition or removal of an accepted crypto-asset or VASP, or a change to an applicable risk threshold.
Any addition or removal of an accepted crypto-asset, VASP (including exchange or wallet provider), or risk threshold requires a documented risk assessment and appropriate sign-off by the CCO prior to implementation, together with notification to the CGA where applicable.
The Company must:
- Undertake the blockchain analytics and transaction monitoring tools necessary to identify prohibited assets and transaction patterns. The Company is not required to employ in-house blockchain analysts, but must not operate blind to the crypto transactions relating to its licensed operations. Risk assessment functions may be outsourced; visibility and accountability may not be.
- Reject, freeze, or return funds where prohibited activity is detected.
- Report relevant incidents in accordance with Section 6.11 (Incident Reporting).
- Maintain documented procedures for identifying and handling prohibited assets.
- Ensure that relevant personnel are trained in digital asset risk identification and assessment, in accordance with Section 6.13 (Training and Awareness).
The Company shall notify the CGA without undue delay of any material crypto-related compliance breach or systemic deficiency that may affect the safe, responsible, transparent, and reliable offering of games of chance, in accordance with LOK requirements and consistent with Section 5 of the Company’s AML/CFT Policy.
6. POLICY IMPLEMENTATION
6.1 Not a Financial Institution
The Company does not itself function as an exchange, payment services provider, or VASP. It accepts crypto-assets solely as a means of payment for gambling services and makes it explicitly clear to players that the Company is not responsible for the services of any third-party exchange used by the player to buy or sell crypto-assets.
The Company must not:
- Convert crypto-to-crypto or crypto-to-fiat on behalf of players.
- Offer trading, swapping, or exchange services.
- Offer custody, transfer, or wallet services outside gambling-related transactions.
- Operate its own crypto exchange; where a link to an exchange is provided for player convenience, it must direct to a separate, regulated third-party website.
The Company's own crypto-asset holdings are maintained either with regulated custodial VASPs or in wallets owned and controlled by the licensed entity, in each case in accordance with the wallet ownership, segregation, and control requirements set out in Sections 6.9 and 6.10. Where holdings are maintained with a custodial VASP, the Company ensures on a contractual basis the segregation of player funds and a level of control and auditability sufficient to meet those requirements.
6.2 AML/KYC in a Crypto Context
The use of crypto-assets is not a carve-out from AML/CFT or Responsible Gaming obligations. The Company’s AML/CFT Policy applies equally to fiat and crypto-currency, and the applicable crypto-specific controls are expressly detailed within the Company’s AML/CFT policy submitted on the CGA portal. Given the elevated risk associated with crypto-assets, the Company applies a heightened approach, including but not limited to the following.
- KYC: Customer identity and beneficial ownership are verified in accordance with the Company’s AML/CFT Policy. Where on-chain indicators suggest elevated risk, Enhanced Due Diligence (EDD) is applied.
- Wallet ownership and origin checks: the Company obtains appropriate evidence of wallet control (e.g. a Satoshi test/return transaction, a signed message, or Travel Rule payloads where the counterparty is a VASP) and conducts on-chain tracing to assess exposure to high-risk sources such as darknet markets, mixers, sanctioned entities, or wallets linked to fraud.
- FATF Travel Rule: where applicable, required originator and beneficiary information accompanies crypto transfers to and from VASPs, in line with Section 6.5.
- Monitoring and reporting: the Company establishes monitoring thresholds appropriate to crypto-related activity, including player verification triggers, suspicious activity escalation, and reporting to the FIU Curaçao via the goAML portal, consistent with Section 6.6 of the AML/CFT Policy. The Company maintains updated typology libraries relevant to crypto use, including self-transfer chip-dumping, high-velocity deposit/withdrawal patterns, and mixer adjacency.
- Responsible Gaming in a crypto context: equivalent Responsible Gaming controls apply irrespective of the tender used, including markers of harm, affordability checks, time-outs, self-exclusion, and bonus restrictions. The Company monitors behavioural signals of problem gambling that may be masked by high-velocity, on-chain micro-deposits.
- Incident, fraud, and cyber response: the Company defines and maintains procedures for crypto-specific issues such as compromised keys, suspicious deposit rings, smart-contract failures, blockchain forks, or exchange outages, in accordance with Section 6.11 (Incident Reporting).
6.3 Blockchain Analytics Capability
The Company deploys blockchain analytics solutions (such as Chainalysis, Elliptic, or TRM Labs, or an equivalent combination of internal systems and external providers) as an integrated means of meeting its crypto-related AML/CFT obligations. The CGA does not mandate a specific provider; the Company must ensure the following functionality is achieved, whether through a single solution or a combination of tools:
- Trace the origin and destination of funds.
- Identify exposure to high-risk or prohibited sources (e.g. mixers, sanctions, fraud-linked wallets).
- Assess and risk-score wallets and transactions.
- Investigate and evidence suspicious activity for reporting purposes.
- Screen wallet addresses at the point of deposit and risk-score/flag exposure to darknet markets, scams, or mixers.
- Conduct ongoing transaction monitoring to detect new risk exposure and suspicious patterns over time.
- Verify source of funds by tracing fund origins, and document for KYC/EDD and audit purposes.
- Screen destination wallets before outbound transfers (withdrawal screening).
6.4 Digital Assets and Transaction Sources
Crypto-currencies are considered by the CGA to be high risk and are subject to asset-specific risk assessment. It is the Company’s preference to transact in fiat-backed regulated stablecoins. A separate and heightened review applies before accepting any unregulated or algorithmic stablecoin, or any other crypto-asset type.
- Privacy-Enhancing Cryptocurrencies. The Company does not accept crypto-assets that obscure transaction data and prevent effective monitoring, blockchain analysis, or source-of-funds verification, including but not limited to Monero (XMR), Zcash (ZEC, including shielded transactions), Dash (where privacy features are utilised), and Litecoin’s MWEB where privacy is enabled.
- Pooled / Omnibus Wallet Structures. Pooled or omnibus wallets operated by VASPs are permitted only where the Company can obtain sufficient data to attribute transactions to individual customers, assess source of funds, and perform monitoring and reporting. Structures that specifically prevent effective attribution or auditability are not permitted.
- Meme or Highly Speculative Tokens. Highly speculative or so-called “meme coins” (e.g. DOGE, SHIB, PEPE) are not accepted by default. Any consideration of such assets is categorised and assessed against objective criteria: liquidity and volatility profile; governance and ecosystem maturity; and financial-crime risk features (e.g. anonymity-enhancing functionality).
- Wrapped Tokens and Bridged Assets of Unverified Origin. The Company does not accept deposits or facilitate transactions involving wrapped tokens (e.g. wrapped Bitcoin) or bridged assets where the custody, backing, or transactional history of the underlying asset cannot be independently verified.
- Expressly Prohibited. The Company does not accept crypto-assets that: originate from, pass through, or are associated with sanctioned mixers or tumblers (e.g. Tornado Cash, Blender.io, Sinbad.io); are linked to wallet addresses appearing on any applicable sanctions list or flagged by a recognised blockchain analytics provider; or are otherwise designated as prohibited by the CGA as presenting equivalent risks to transparency, traceability, or regulatory oversight.
6.5 FATF Travel Rule Compliance
The Company recognises the requirements of the Financial Action Task Force (FATF), including Recommendation 16 (the “Travel Rule”). Where crypto-assets are transferred between regulated entities, including exchanges, custodial wallet providers, and VASPs, the required originator and beneficiary information accompanies the transaction and is made available to competent authorities upon request.
6.6 Use of Third-Party VASPs and Payment Providers
Crypto transactions involving a third-party service provider must be routed through licensed crypto exchanges or registered VASPs. Deposits from unhosted (self-hosted / non-custodial) wallets and DeFi protocols are accepted only in accordance with the risk-based controls set out in Section 6.7.
The use of a third-party provider does not transfer, reduce, or dilute the Company’s obligations in respect of AML/CFT, transaction monitoring, player protection, or incident reporting; the Company remains fully responsible for AML/CTF breaches even where it relies on third-party services.
The Company must ensure that any third-party VASP (exchange, custodian, or payment provider) is regulated, registered, or otherwise subject to reputable oversight in its home jurisdiction, and demonstrates:
- Robust AML/CFT controls.
- FATF Travel Rule compliance capability.
- Sanctions screening.
- Transaction monitoring capability.
- Operational resilience and transparency.
The Company documents its due diligence and risk assessment of each VASP prior to onboarding and on an ongoing basis. Access security controls applied to VASP and wallet integrations must include Multi-Factor Authentication (MFA) and/or Hardware Security Modules (HSMs), withdrawal whitelisting to restrict outbound transfers, and multi-signature protocols for treasury wallet operations.
6.7 Unhosted (Self-Hosted / Non-Custodial) Wallets
The Company may accept crypto-assets from unhosted wallets or DeFi protocols, subject to the following risk-based controls:
- Wallet ownership or control is verified prior to acceptance.
- Blockchain analytics are applied to assess transaction risk.
- Enhanced Due Diligence is required where elevated risk is identified.
- Transactions must not impair the Company’s AML/CFT, monitoring, and reporting obligations.
6.8 Transaction Management
The default rule is that withdrawal requests are processed to the same wallet, and in the same crypto-asset, from which the deposit was received (source-of-funds verification). Players cannot transfer amounts to each other on the platform.
The Company recognises that a strict same-wallet, same-asset rule is not always operationally possible and may create material volatility exposure. Where equivalent controls can be demonstrated and documented, the following alternatives are permitted:
- Withdrawal to a different wallet address, where that wallet is whitelisted, pre-screened, and verified as belonging to the same customer, and has passed KYC/AML and whitelisting controls.
- Withdrawal in a different crypto-asset or stablecoin, where the full transaction flow remains transparent and auditable, conversion is conducted via a regulated VASP, and records are maintained.
The Company sets asset-specific deposit and withdrawal velocity limits, cooling-off, and hold periods proportionate to on-chain risk, and discloses network fees, gas fees, and any conversion or slippage handling rules to players.
Delisted Tokens, Blockchain Forks and Sanctioned Wallet Addresses. Where a crypto-asset has been delisted from the exchanges or VASPs used by the Company, where the relevant blockchain has undergone a fork, or where a player’s wallet address is or becomes sanctioned, blocked, or otherwise unavailable, the standard same-wallet, same-asset withdrawal rule set out above cannot be applied. Such events are treated as reportable incidents under Section 6.11 (Incident Reporting). In these cases, the Company will agree an alternative remittance method with the player — which may include remittance in an equivalent regulated stablecoin, remittance to a different verified and whitelisted wallet, or remittance to a fiat account following conversion through a regulated VASP — subject to the Company’s AML/CFT and KYC obligations, and will inform the player of the process to be followed. This paragraph, together with Section 6.11, is the basis for the crypto-specific remittance provisions referenced in the Company’s Terms and Conditions.
6.9 Operator Wallets and Segregation
All wallets used in connection with the licensed operation must be owned or controlled by the licensed legal entity or an approved group/payment entity. Personal wallets, UBO-linked wallets, employee wallets, or informal wallet arrangements are strictly prohibited.
Wallet architecture must clearly segregate: operational wallets, used for day-to-day transactional flows; treasury wallets, used for strategic reserves and capital management; and player-flow wallets, used for customer-facing deposits and withdrawals. Player funds must be held in segregated wallets to prevent commingling of player funds and Company funds.
6.10 Hot, Warm and Cold Wallet Controls
The Company may use a combination of hot, warm, and cold wallets, provided that the wallet architecture is documented, risk-assessed, and subject to appropriate controls:
- Hot wallets may be used for day-to-day player deposits and withdrawals, with balances limited to operationally necessary amounts.
- Warm wallets may be used for liquidity management, subject to enhanced access controls and transaction approval procedures.
- Cold wallets may be used for treasury, reserves, or longer-term safeguarding of funds, provided that access, key management, reconciliation, and auditability are maintained.
- Multi-signature controls, withdrawal whitelisting, MFA, HSMs, or equivalent security measures are applied proportionate to the value and risk of the wallet.
The Company maintains records sufficient to evidence ownership/control, transaction history, reconciliations, access rights, approvals, and any movement of funds between wallets.
6.11 Incident Reporting
In line with the Incident Reporting requirements established under the LOK (Article 5.10), the Company ensures that all crypto-related incidents are identified, assessed, and reported without undue delay to the CCO and, where required, to the CGA. Reportable incidents include:
- Security breaches, including compromised private keys, wallet access, or unauthorised transactions.
- System failures impacting crypto processing (e.g. exchange outages, blockchain congestion, or failed transactions).
- Detection of fraud schemes involving crypto (e.g. coordinated deposit/withdrawal patterns, chip-dumping, or collusion).
- Material discrepancies in wallet balances or transaction records.
- Any event that may impact the integrity, security, or traceability of crypto transactions.
- Exposure to sanctioned wallets, mixers, or prohibited sources.
- Smart contract failures.
- Blockchain forks or chain-level disruptions.
6.12 Recordkeeping and Audit Trail
The Company retains Travel Rule payloads, on-chain risk reports, KYC documentation, and transaction logs for the statutory retention period, consistent with Section 6.10 of the AML/CFT Policy (a minimum of five (5) years after the termination of the business relationship or completion of the transaction, or longer where required by law or instructed by the CGA or FIU Curaçao).
The Company ensures reconciliation between blockchain explorers, exchange statements, and internal ledgers, and maintains records in a manner that enables independent audit reproduction. Records are stored securely and made available to the CGA on request.
6.13 Training and Awareness
Relevant personnel, including the Compliance Department, payments team, risk and fraud teams, and customer support, receive training in digital asset risk identification and assessment upon hiring and annually thereafter. Training covers crypto-specific ML/TF typologies, wallet and VASP risk indicators, the use of blockchain analytics tools, and crypto-specific incident response procedures. Training records are maintained and made available to the CGA on request.
7. IMPLEMENTATION TIMELINE
In accordance with the CGA Crypto Policy Guideline, this policy and its underlying controls are implemented on the following phased basis:
- Immediate effect: prohibitions on sanctioned wallets and mixers, prohibited crypto-assets, personal or UBO-linked wallets, and the Company acting as an exchange, payment provider, or VASP, apply from the effective date of this policy.
- By September 2026: the Company uploads this Crypto Policy to the CGA Portal, together with a clear timeline of adoption and compliance with the requirements set out herein, prioritising the development — internally or through hiring — of the crypto compliance knowledge and experience needed to reflect the Company’s crypto business.
- By December 2026: the Company completes documented crypto risk assessments, VASP due diligence, wallet ownership controls, transaction monitoring procedures, and staff training.
- By June 2027: the Company fully implements wallet segregation, blockchain analytics capability, reconciliation processes, withdrawal whitelisting (or equivalent controls), and audit-ready recordkeeping.
The CGA may require earlier implementation of any of the above where material risks are identified. The status of implementation against this timeline is reported to the Board as part of the CCO’s periodic compliance reporting.
8. COMPLIANCE AND CONSEQUENCES OF NON-COMPLIANCE
Failure to comply with this policy may result in serious consequences for both the individual and the Company:
- Internal disciplinary action, up to and including termination of employment, for employees.
- Regulatory penalties, fines, or suspension or revocation of the Company’s licence by the CGA, for the Company.
- Criminal prosecution and legal sanctions under applicable laws (including LOK and AML/CFT legislation), for customers involved in illicit activity.
Where serious or repeated non-compliance with this policy is identified, the Company may take immediate remedial action, including suspension of duties, restriction of system access, or termination of employment or contractual relationships, in accordance with applicable labour and contractual law. In the case of players, the Company may suspend or terminate the business relationship, freeze or return funds, refuse transactions, and report the matter to the FIU Curaçao or other competent authorities, where required or deemed appropriate. All such decisions are documented, justified, and approved by senior management or the Board, as applicable.
9. RELATED INFORMATION
This policy is based on the following legislation and regulatory instruments:
- Curaçao Gaming Authority – Crypto Policy Guideline for Online Gaming Operators
- National Ordinance on Games of Chance (LOK 2024)
- CGA AML/CFT Regulations (January 2025)
- FATF Recommendations, including Recommendation 15 (VASPs) and Recommendation 16 (Travel Rule)
- Code Harbor N.V. Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) Policy, V1.6
- Code Harbor N.V. Responsible Gaming Policy, V1.2
10. CONTACT INFORMATION
Compliance Department – Code Harbor N.V.
Email: [email protected]
11. POLICY HISTORY
Version 1.0 – initial Crypto Policy prepared in response to the CGA Crypto Policy Guideline for Online Gaming Operators
12. POLICY URL
https://wildwinz.com/crypto-policy