Why you should know this
A restriction can interrupt a payment or trading plan. It can also attract scammers who promise an instant unlock for a fee. Knowing the difference between review, restriction and legal freeze helps us respond through the correct channel.
An account review does not by itself prove wrongdoing. It means the provider needs to evaluate information, risk, authorization or a legal obligation.
Review is risk management, not a public verdict
Financial providers make decisions with incomplete information. A login from a new country might be legitimate travel or an account takeover. A first large transfer might be normal savings activity or inconsistent with the customer profile. A name match might involve the wrong person.
Controls create alerts so facts can be checked. Some alerts clear quickly; others require customer documents, internal investigation or a competent authority. The existence of a review should not be treated as proof of guilt, but neither should it be bypassed as mere inconvenience.
Providers also need to protect the details of their monitoring. A customer can reasonably ask what information or complaint route is required, while the provider may be unable to reveal thresholds or methods that would help someone evade detection.
Three different states

Review: The provider examines identity, activity, documents or a security event. Some features may remain available.
Restriction or hold: Selected actions—such as login, withdrawal, deposit credit or trading—may be limited while checks continue.
Freeze: Access or movement may be blocked under provider controls, a legal process or competent-authority direction. The legal meaning varies by jurisdiction and case.
Only the provider or relevant authority can describe the actual status. Social-media speculation cannot.
There can also be more than one layer at once. Login may be restored while withdrawals remain restricted, or a blockchain transaction may be final while the provider’s internal credit is under review. Ask which function is affected, which legal entity operates it and whether the notice concerns security, customer information, a transaction or a legal direction.
Why a provider may review activity

Possible reasons include:
- incomplete, outdated or inconsistent customer information;
- a new device, password reset, SIM change or suspicious login;
- a fraud complaint or potentially unauthorized transaction;
- unusual activity requiring customer due diligence or source information;
- a sanctions, name or transaction-monitoring alert needing resolution;
- missing Travel Rule or beneficiary information;
- a legal request, provider policy, technical incident or risk limit.
An alert is a reason to examine facts, not automatically a conclusion. Providers should not disclose controls in a way that enables evasion.
These reasons fit several practical groups:
- Authentication and fraud: new device, reset, SIM swap, impossible travel, malware indicators or a customer report.
- Identity and eligibility: expired documents, changed address, inconsistent name or country restrictions.
- Transaction compliance: source or destination information, Travel Rule data, sanctions screening or unusual patterns needing due diligence.
- Legal or policy action: court, regulator, law-enforcement or provider terms applied to the case.
- Technical and operational: maintenance, wallet incident, network congestion, reconciliation error or provider risk limit.
The category changes the response. A password reset is not solved by a payslip, and a source-of-funds question is not solved by changing the password.
Philippine context
BSP Circular 1108 requires VASPs to conduct customer due diligence in defined circumstances, maintain fraud-risk controls and comply with applicable AML and wire-transfer rules. FATF red-flag guidance explains why patterns may require examination.
Exact authority, process, timing and customer rights depend on the provider, facts and current law. A regulated status does not promise that every withdrawal will be immediate.
“Source of funds” normally asks where the money for a transaction came from; “source of wealth” is a broader question about how overall assets were accumulated. The provider should state what it needs. Give accurate, relevant records—not a dramatic life archive and not a fabricated shortcut.
Useful records may include payslips, bank or remittance statements, invoices, sale documents, transaction hashes and the purpose and relationship of a transfer. Availability depends on the genuine facts. Redact only as the provider permits; an unreadable or selectively altered document can delay the review.
A calm response sequence

- Open the provider through its official app or bookmarked domain.
- Read the exact notice and identify which feature is affected.
- Secure the email, device and account if compromise is possible.
- Use the official case or complaint channel and record its reference number.
- Provide truthful, relevant documents through the authenticated process.
- Organize transaction hashes, dates, amounts, counterparties and purpose.
- Ask what remains outstanding and which escalation route applies.
- Preserve responses and follow the published complaint process.
Do not split, reroute, disguise or fabricate activity to avoid checks. That can create additional legal and account risk.
Upload documents only inside the authenticated portal or another route independently confirmed by the provider. A scammer can copy the wording of a compliance request. No legitimate review requires a seed phrase, private key, account password, remote-control access or transfer to a “verification wallet.”
Ask precise questions: What feature is affected? What document or explanation is outstanding? Which date range and transaction does it concern? Has the case been escalated? What is the provider’s complaint process? A support agent may not promise an outcome or time, but clear questions improve the record.
OFW scenario

Ken sends funds from Japan and later converts part into crypto. His Philippine account requests information about the source and intended beneficiary.
Instead of opening a second account or inventing a description, Ken collects the relevant payslip or transfer record, recipient details and transaction hashes. He uploads only through the authenticated provider flow and asks for the case reference.
The review outcome and timing remain uncertain, but clear records give the real process something to evaluate.
Ken keeps originals and submits copies through the portal. His case note lists the date, reference number, documents supplied and the exact question answered. If support later asks for a different item, he can respond without guessing what was already sent.
He also leaves enough money outside one provider for ordinary living and remittance needs. That is not an evasion plan; it is liquidity planning. Concentrating every obligation in one account makes a legitimate review more damaging.
Beware the “unlock fee” scam
A stranger says they know a compliance officer and can release the account if you send crypto to a “verification wallet.” That is not a normal complaint or due-diligence process. Verify any fee or document request inside the official account or published support channel.
Recovery scammers may contact people who complain publicly. They can quote the provider name and case details copied from the post. Keep case numbers, balances and identity documents out of public threads. Genuine escalation begins with the provider’s official complaint channel.
For a BSP-supervised financial institution, the BSP consumer-assistance process may be available after the provider’s own complaint channel is used, subject to current rules and scope. The BSP cannot be replaced by a social-media “agent,” and regulatory escalation does not guarantee a particular account outcome.
What not to do

Do not open replacement accounts under another person’s name, fragment transactions to avoid attention, edit documents, invent counterparties or coach someone to give a false explanation. Besides legal and contractual risk, these actions destroy the clean factual record needed to resolve a legitimate misunderstanding.
Do not threaten support staff or flood the case with duplicate tickets. Keep one organized timeline, follow stated intervals and escalate through the published path. Firm and factual works better than frantic and scattered.
Plan for access risk before the review
Operational resilience means not depending on one provider for every urgent obligation. Keep essential expenses and near-term remittance needs in appropriate accessible forms, and understand the withdrawal rules before a deadline. This is diversification of access, not an instruction to avoid due diligence.
Maintain lawful records as activity occurs: payslips, invoices, bank transfers, counterparty purpose and transaction hashes. Creating a truthful file at transaction time is easier than reconstructing months of activity during a review.
For business accounts, align legal name, authorized users, beneficial-owner information and transaction purpose with the provider’s current requirements. Personal and company funds should not be mixed merely for convenience. Good records do not guarantee uninterrupted access, but they improve decision quality and complaint handling.
Review this access plan whenever transaction purpose, country, authorized user, funding source or near-term obligation materially changes.
How this connects to market mastery
Market participants manage operational liquidity, not just price. A balance that cannot move on schedule is a different risk from a falling price. Mature planning therefore includes provider rules, documentation, settlement windows and backup—not evasion.
Key takeaways and check
- Review, restriction and legal freeze are not interchangeable.
- Monitoring alerts require examination; they do not automatically prove guilt.
- Respond through the authenticated channel with truthful, relevant records.
- Never pay an unofficial “unlock” address or hide activity to bypass controls.
Explorer check: Build a case folder with identity records, transaction hashes, dates, amounts, counterparties, purpose and provider references—without adding irrelevant sensitive data.
This lesson introduces identity, fraud, sanctions, source-of-funds and unusual-activity controls without predicting outcomes.
*Cryptocurrency and virtual asset transactions are highly volatile and irreversible, may result in significant losses, and do not guarantee returns; customers should trade only after understanding the risks involved.