FinCEN Crypto Rule Withdrawals Would Leave Core AML Duties Intact
FinCEN’s reported retreat from two proposed crypto rules may sound like a regulatory reprieve. It is not a clean slate. One proposal targeted transfers involving self-custody wallets; another focused on crypto mixing. Existing anti-money-laundering, reporting and sanctions duties remain. Here’s what compliance teams should—and shouldn’t—change while the announcement awaits confirmation.

Washington, D.C.
Oct 5, 2026
Two proposed cryptocurrency rules targeted different gaps in the government’s visibility into digital-asset transactions: transfers involving self-custody wallets and the use of services or techniques that obscure transaction trails. Withdrawing them would remove those proposed reporting regimes—not the underlying obligation of regulated financial institutions to detect and report suspicious activity.
An announcement attributed to the Financial Crimes Enforcement Network, dated October 5, 2026, says the agency has withdrawn both proposals after reviewing public comments. It describes the decisions as part of an effort to keep the digital-asset regulatory framework “fit for purpose.” The announcement’s publication and the withdrawals’ legal status have not been independently verified.
The substantive distinction is nevertheless important: ending a proposed rulemaking is not the same as dismantling the Bank Secrecy Act framework. Neither proposal was an operative rule merely because FinCEN had published it. Their withdrawal would prevent the additional requirements from taking effect through those proceedings, while leaving existing obligations in place.
Two proposals, two approaches to financial surveillance
The December 2020 proposal would have imposed additional reporting, recordkeeping and customer-verification requirements on banks and money services businesses handling certain transactions involving convertible virtual currency or legal-tender digital assets.
Its reach extended beyond unhosted wallets—commonly called self-custody wallets, whose private keys are controlled by users rather than a custodial intermediary. It also covered certain transactions involving wallets hosted by financial institutions in specified foreign jurisdictions.
The proposal contemplated recordkeeping and customer-identity verification for covered transactions exceeding $3,000, and reporting for covered transactions exceeding $10,000, with aggregation provisions. It also would have required institutions to collect information about counterparties, including names and physical addresses.
That last requirement went to the heart of the dispute. A regulated exchange can identify its own customer. Establishing reliable information about someone on the other side of a blockchain transfer is a different task, particularly when no intermediary holds that person’s wallet. A blockchain address is not, by itself, proof of the identity of its controller.
The proposal thus raised both a policy question—how much information should accompany transfers out of regulated custody—and an implementation question: what information could institutions reliably obtain? Withdrawing it would end that particular attempt to prescribe an answer. It would not establish that self-custody is inherently suspicious, or that transfers involving self-custody no longer warrant scrutiny.
The October 2023 proposal used a different statutory mechanism. Under Section 311 of the USA PATRIOT Act, FinCEN proposed identifying international convertible virtual currency mixing as a class of transactions of primary money laundering concern.
The agency sought to apply the first of Section 311’s special measures: additional recordkeeping and reporting. The proposal would have required covered domestic financial institutions to report certain transactions they knew, suspected or had reason to suspect involved mixing within or involving a jurisdiction outside the United States.
That was not simply a proposed ban on named mixing services. Its definition reached services and techniques used to obscure the source, destination or amount of virtual-currency transactions, subject to specified exceptions. Nor was it equivalent to a sanctions designation, which operates under a separate legal framework.
The government’s concern was the loss of visibility into financial flows. The competing concern was breadth: techniques that make transactions harder to trace can serve legitimate privacy interests as well as conceal illicit proceeds. A transaction’s association with mixing does not, standing alone, establish criminal conduct.
The compliance floor remains
FinCEN’s longstanding position is that digital assets do not create a general exemption from financial regulation. Its 2019 guidance on convertible virtual currency business models explains how existing rules apply according to what a business does, rather than the terminology it uses.
Certain virtual-currency administrators and exchangers qualify as money transmitters and therefore money services businesses. Depending on their activities and applicable exceptions, they can face registration, anti-money-laundering program, recordkeeping and suspicious activity reporting requirements. Banks remain subject to their own applicable obligations.
Those duties should not be confused with the additional thresholds and procedures in the 2020 proposal. Existing funds-transfer recordkeeping and information-transmission requirements have a separate legal basis; withdrawing a proposed rule does not repeal them.
Likewise, withdrawal of the mixing proposal would not eliminate suspicious activity reporting obligations. A covered institution must still assess transactions under the rules that apply to it. Mixing exposure can be relevant to that assessment, but so can the customer’s profile, the transaction’s purpose, its geographic connections and other evidence. Neither automatic suspicion nor automatic clearance substitutes for that analysis.
Sanctions are another distinct layer. Applicable restrictions administered by the Treasury Department’s Office of Foreign Assets Control do not depend on whether either FinCEN proposal becomes final. Ending these rulemakings would not authorize transactions otherwise prohibited by sanctions law.
Less proposed regulation, not a clean slate
For compliance departments, the practical issue is separating controls developed solely in anticipation of the proposals from controls supported by existing law or an institution’s documented risk assessment.
A proposed reporting form, data field or transaction threshold does not become mandatory simply because it appeared in a notice of proposed rulemaking. But a control does not become unnecessary simply because an overlapping proposal is withdrawn. Its justification may lie elsewhere—in an existing reporting duty, sanctions exposure or a pattern of suspicious transactions.
The larger policy consequence would be narrower but meaningful. FinCEN would be abandoning two specific approaches to obtaining more transaction-level information, without resolving the underlying tension between financial privacy and the government’s ability to follow illicit funds. Withdrawal would leave room for different approaches; it would not establish what, if anything, the agency will propose next.
The dividing line remains the one institutions cannot afford to blur: proposed obligations can disappear, while obligations already in force continue to govern.
Verification note: The supplied withdrawal announcement is dated October 5, 2026. Its publication and any corresponding official withdrawal notices require confirmation before the withdrawals are reported as established events. The descriptions of the proposals and existing compliance framework above are grounded in the linked regulatory materials.