Thoughts from Paul Hampson, CEO and Director at CEL Solicitors, on one of the most interesting emerging disputes in payment services law
Over the past 12 months, I have been dealing with an increasing number of fraud claims, often described by clients as Revolut scams, involving cryptocurrency transactions through Revolut.
What is becoming increasingly apparent is that these complaints are no longer simply about cryptocurrency.
Instead, they raise important questions about the scope of a payment service provider’s obligations when processing transactions through integrated crypto platforms.
From the cases I have reviewed, Revolut’s defence has become increasingly consistent. Whilst each case turns on its own facts, the principal arguments appear to be:
- the Financial Ombudsman Service, the free dispute resolution service for consumers dealing with financial firms, has no jurisdiction because cryptocurrency is largely unregulated;
- any intervention should occur only when cryptocurrency is withdrawn from the platform, rather than when fiat currency is exchanged;
- requiring intervention at the exchange stage improperly converts an execution-only service into an advisory service; and
- only a very small proportion of customers who purchase cryptocurrency ultimately become victims of fraud, making earlier intervention disproportionate.
They are well-constructed arguments.
However, I am not convinced they answer the real legal question.
This isn’t really a cryptocurrency complaint
One of the biggest misconceptions in these cases is the assumption that the complaint concerns cryptocurrency.
In my view, it rarely does.
Instead, the complaint concerns the conduct of an FCA-authorised Electronic Money Institution (an EMI, a firm authorised by the Financial Conduct Authority to issue e-money and process payments) whilst carrying out regulated activities.
Before any cryptocurrency exists, the firm has:
- received regulated electronic money;
- operated a regulated payment account;
- executed regulated payment instructions;
- monitored customer behaviour; and
- applied fraud detection systems.
Those are regulated activities.
The fact that the transaction ultimately results in the purchase of Crypto currency does not retrospectively alter the nature of the regulated conduct that preceded it.
That distinction, in my view, lies at the heart of the jurisdiction debate.
The payment journey should not be artificially divided
A recurring argument advanced by firms is that intervention should occur only when cryptocurrency is withdrawn.
At first sight that appears logical.
However, it assumes that each stage of the transaction should be viewed independently.
Modern fraud simply does not operate like that.
Fraud investigators rarely identify fraud from one transaction.
They identify it from patterns.
Repeated identical values.
Increasing transaction velocity.
Rapid account depletion.
Multiple exchange-to-withdrawal cycles.
Behavioural repetition.
The legal question is therefore not:
“Was this purchase of cryptocurrency suspicious?”
Instead it is:
“Had the customer’s overall transaction behaviour become sufficiently unusual that proportionate enquiries should reasonably have been undertaken?”
Those are fundamentally different questions.
Fraud does not begin when cryptocurrency leaves the platform
Another point that often appears to be overlooked is the nature of fraud itself.
Under the Fraud Act 2006, fraud by false representation is complete once the statutory ingredients exist, meaning the fraudster has committed the offence in law as soon as the false representation is made.
Actual financial loss is not required.
Cases of this kind, where cryptocurrency is bought using money obtained through deception, are often referred to as APP fraud, short for authorised push payment fraud, where the victim is persuaded to send money themselves.
The fraud therefore does not somehow begin only once cryptocurrency leaves the platform.
The withdrawal frequently represents the final implementation of an existing fraud rather than its commencement.
That distinction is important because fraud prevention is necessarily preventative.
If intervention is postponed until the final irreversible step, the opportunity to prevent the loss may already have passed.
Execution-only does not mean execution-without-question
Perhaps the most interesting argument is that asking questions at the exchange stage would somehow transform an execution-only platform (one that simply carries out a customer’s payment instructions, without advising on whether to make them) into an investment adviser.
I find that proposition difficult to accept.
Questions such as:
- Who asked you to make this payment?
- Are you sending money as part of a job?
- Have you downloaded software?
- Has somebody instructed you to move funds?
- Have you been told not to tell your bank why you are making these transactions?
are not investment advice.
They are fraud prevention.
The same questions would be appropriate whether the customer was:
- buying gold;
- transferring funds overseas;
- purchasing foreign currency; or
- sending money to another bank.
The questions concern the authenticity of the customer’s instructions, not the merits of the underlying asset.
Revolut’s own contractual terms raise an interesting point
One aspect of these cases which I think deserves greater attention is the firm’s own contractual documentation.
Revolut’s published cryptocurrency terms reserve broad powers allowing it to refuse or delay cryptocurrency transactions where it has reason to suspect fraud or where necessary to comply with regulatory obligations.
That is significant.
If those powers already exist contractually, then asking whether they ought reasonably to have been exercised is very different from suggesting the Financial Ombudsman Service is creating entirely new obligations.
In other words, the debate is not about creating new powers.
It is about whether existing powers should have been exercised differently in the circumstances of a particular case.
That strikes me as an important distinction.
Statistics rarely answer individual cases
Another common submission is that only a very small percentage of customers purchasing cryptocurrency become victims of fraud.
That may be true.
However, I am not convinced it answers the relevant question.
The comparison is not between fraud victims and every customer who has ever purchased cryptocurrency.
The comparison should be between customers exhibiting an objectively unusual transaction pattern.
Repeated identical exchanges.
Repeated withdrawals.
Rapidly increasing expenditure.
Clustered transactions occurring within minutes.
Without data relating to those specific behaviours, broad statistical comparisons are of limited assistance.
Consumer Duty and foreseeable harm
The introduction of Consumer Duty, the FCA rule requiring firms to act in the best interests of customers and prevent foreseeable harm, has shifted the regulatory focus towards preventing harm rather than simply responding after it has occurred.
Payment service providers possess information unavailable to individual consumers.
They can identify:
- unusual transaction velocity;
- changes in behaviour;
- cumulative spending;
- repeated payment patterns; and
- other indicators that a consumer cannot see.
That informational advantage is precisely why these cases are becoming so interesting from a regulatory perspective.
Where does this leave the Financial Ombudsman Service?
It is understood that the Financial Ombudsman Service is currently reviewing its wider approach to complaints involving integrated cryptocurrency services.
That is hardly surprising.
These cases raise genuinely difficult questions at the intersection of payment services regulation, consumer protection and emerging financial technology.
Whatever approach ultimately develops, I suspect the key issue will not be whether cryptocurrency itself is regulated.
Instead, the real question will be:
At what point does an objectively observable pattern of behaviour become sufficiently unusual that a regulated payment institution ought reasonably to intervene before further losses occur?
In my view, that is the debate practitioners should be having.
It is a considerably more interesting legal question than whether Ethereum is regulated. Firms that already hold the contractual power to intervene should not be permitted to leave it unused and then argue, after the fact, that intervention was never their responsibility.
Disclaimer: This article reflects my personal views on developing issues in payment services, APP fraud and cryptocurrency litigation. It is intended to encourage discussion amongst practitioners and should not be taken as legal advice.