Thank you. We have your message and will reply within one business day.

Our client is OVEX, a South African cryptocurrency exchange with a large retail and institutional customer base. Among the financial services offered on the exchange are cross-border payments, wholesale FX, and over-the-counter crypto and fiat trading. As with any exchange, OVEX's services can be misused. Its compliance team has handled roughly 1,400 confirmed fraud cases since 2023, most of them in the last year.
At the start of the engagement, around 15% of retail accounts on the platform had been linked to fraud. The goal was to replace hard-coded detection rules with a model that learns how fraudsters and honest customers behave, and to flag only the former.
The existing rules identified roughly 75% of confirmed fraud cases, at a false-alarm rate of 93.6%: of every 100 accounts the rules flagged, about 94 were honest. It is always possible to catch every fraudster by flagging every customer. The work lies in catching more while flagging fewer.
A full investigation of one customer can take hours. At a 93.6% false-alarm rate, the rules would raise on the order of 10,000 alarms a year, which amounts to tens of thousands of hours spent investigating honest customers. So the first requirement was to cut false alarms as far as possible.
South African banks issue return requests when they suspect a fraudulent deposit into an exchange. If the request arrives before the money is withdrawn, the deposit is reversed. If it arrives after, recovery is much harder. Stopping funds from leaving the exchange is critical.
Fraud is invisible until discovered, so some accounts assumed honest in fact belong to criminals. The not-fraud labels cannot be fully trusted, while confirmed fraud labels can. We used several methods during training to limit the effect of these wrong labels.
When the timing between logins and transactions, and the order of activities, is what separates honest from criminal behaviour, summarising an account's history into one vector loses the signal. A sequence model reads the events in order and produces a behaviour score for each account.
The notion of time is built into the model's architecture. The training data is a sequence of events, not a summary of them.
Some information is not sequential. KYC data (identity documents, proof of address, contact details) rarely changes between transactions, and once confirmed it supports a stable risk profile. A separate risk model trained on this static data, combined with each customer's behaviour score, was a crucial part of the system.
| Model | Fraud caught | False-alarm rate |
|---|---|---|
| Existing detection rules | 75% | 93.6% |
| Risk model (static KYC data) | 88% | 2% |
| Behaviour model (sequence) | 99.3% | 15% |
| Ensemble | 98% | 5% |
“We partnered with DataProphet for their deep machine-learning expertise and they've built a system tailored to our platform, giving us a far more sophisticated way to identify fraud as it evolves.”