Pix fraud: from October, the notification will state which layer a transaction sits in
The Brazilian Central Bank will add to each infraction notification the hop depth at which a transaction sits along the fraud trail. Layering stops being invisible to whoever receives the notification — and the first-hop problem finally gets a number.

▸In this article
Anyone who investigates the diversion of funds knows the point where nearly every inquiry dies: the second hop.
The money leaves the victim's account, lands in the recipient's account, and from there splits into smaller transfers to other accounts. Every new layer costs time, paperwork and coordination across different institutions. In practice, plenty of investigations stop at the first destination — not because the trail ran out, but because following it requires information no single party holds.
As of 26 October 2026, part of that information will circulate by default inside Pix.
What changes
The Banco Central do Brasil has published version 4.4 of the implementation guide for the Mecanismo Especial de Devolução (MED), with two effective dates. The second of them, 26 October, carries a discreet line in the revision history:
"Inclusion of information, in the infraction notification corresponding to the transaction under analysis, on the layer in the tracing graph."
In operational terms: the infraction notification will now carry an attribute called TransactionDepth. The guide spells out what it means.
"The notification for the root transaction has a value of 1, notifications for second-layer transactions have a value of 2, and so on."
It is a hop count. Whoever receives the notification will now know how far the transaction in front of them sits from the original fraud.
What already existed
It is worth separating what is new from what is already in force, because the distinction changes how you read it.
The tracing graph already exists. The current version of the guide defines it as the mapping of the path taken by the funds from the root transaction onward, and it is what allows value to be blocked in the accounts the money was diverted to — not only in the account that received the original transfer.
Recuperação de Valores, the process for opening a MED claim in fraud cases, already works the same way: it traces subsequent transactions and blocks funds along the path.
What did not exist was the layer showing up in the notification. Before, a participant received a blocking request; now it receives a blocking request together with that transaction's position along the trail.
Why the layer matters
Spreading money across successive layers is the oldest laundering technique there is, and it works for a simple reason: each hop raises the cost for whoever is chasing and dilutes the responsibility of whoever has to answer.
An institution that receives a blocking request with no context treats every request alike. With depth made explicit, three things become possible within the regulatory flow itself:
Prioritisation by proximity. A layer-2 transaction is more directly related to the fraud than a layer-5 one. That is not a presumption of guilt — it is an order of analysis.
Pattern reading. A graph that fans out quickly across many shallow layers describes different behaviour from one that runs deep through a handful of accounts. The topology of the diversion is information about the operation behind it.
A measure of reach. Knowing how far down the tracing got is knowing where it stopped. And where it stops tends to be where the money leaves the system.
None of this is conceptually new to anyone doing flow tracing. What is new is the data arriving standardised, via API, to every participant in the arrangement at the same time.
What got reported badly
The same version 4.4 brings a second change, effective 1 September, that drew a bigger headline than it deserves: the extension of the contestation window from 30 to 80 days.
The extended deadline applies to one specific case — contesting a refund transaction, where the recipient argues that MED was invoked against them improperly. It is the right of reply for someone who has been hit with a block, not the victim's general window.
The deadline that matters in most cases — the maximum age of the original transaction for opening a Recuperação de Valores claim — is 80 days and has not changed. It was already in the previous version of the guide.
The distinction is not pedantry. Anyone who reads "from 30 to 80 days" and concludes that the refund window tripled will give bad advice to the next person who turns up with a 100-day-old case.
What to do with it
For participating institutions, the 26 October change is an implementation matter: the attribute has to be read, recorded and factored into analysis criteria. Ignoring it means receiving the information and throwing it away.
For those running fraud prevention and response, the effect is different. Hop depth becomes historical data. After a few months, it becomes possible to answer questions that today get answered by gut feel: at which layer do blocks usually fail, how fast does a graph fan out, which topologies precede total loss.
And the direction is worth noting. The regulator is embedding into payment infrastructure the vocabulary of people who trace flows — graph, layer, depth, root. That is not an aesthetic choice: it is an acknowledgement that recovering money from fraud is a topology problem, not a matter of an isolated transaction.
The trail was always there. What changes is how many people can read it.
Sources
Guia de implementação dos procedimentos de devolução no Pix, com ênfase no Mecanismo Especial de Devolução — Banco Central do Brasil. The quoted line appears in the revision history of version 4.4, effective 26 October 2026; the definitions of the tracing graph and of Recuperação de Valores are in version 4.3, currently in force.
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/analysis/pix-fraud-from-october-the-notification-will-state-which-layer-a-transaction-sits-in
Retrieved on