CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

FinCEN Drops $10,000 Unhosted Wallet and Mixer Reporting Rules

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING FinCEN Drops $10,000 Unhosted Walletand Mixer Reporting Rules

The Financial Crimes Enforcement Network has formally withdrawn two proposals that had shaped AML compliance planning across the US crypto industry for years. The first, originally floated in December 2020, would have required banks and money-service businesses to file currency-transaction-style reports whenever a customer transferred more than $10,000 in crypto to or from an unhosted wallet. The second, published in 2023, would have classified crypto mixing as a primary money-laundering concern, giving regulators broad authority to impose extra reporting burdens on any financial institution touching mixer-linked transactions. FinCEN pulled both on the same day and cited the Trump administration's deregulatory agenda and its goal of building "fit-for-purpose" digital-asset rules. For accounting firms, auditors, and CFOs running treasury desks with digital assets, the withdrawals change the near-term compliance landscape in concrete ways, but they do not eliminate the underlying AML risk management work.

FinCEN Drops $10,000 Unhosted Wallet and Mixer Reporting Rules

What the Two Withdrawn Proposals Actually Said

The 2020 unhosted wallet rule

The December 2020 proposal would have extended existing Bank Secrecy Act reporting logic to crypto transfers involving self-custodied wallets. Under the draft, any bank or money-service business, including a crypto exchange registered as an MSB, would have been required to file a report when a customer sent more than $10,000 in cryptocurrency to a wallet where the customer, not the exchange, controlled the private keys. The threshold was cumulative over a 24-hour window, meaning multiple smaller transfers that aggregated above $10,000 in a day would have triggered the obligation. Firms would also have had to collect identifying information about the counterparty wallet and, where possible, about the person controlling it. Critics argued the rule was technically unworkable because exchanges typically have no reliable way to verify who controls an unhosted address. The proposal never advanced to a final rule, but it remained on the books as a pending item and influenced how compliance teams designed their self-custody due diligence procedures.

The 2023 mixer designation proposal

The 2023 proposal took a different approach. Rather than setting a transaction threshold, it sought to designate crypto mixing as a category of primary money-laundering concern under Section 311 of the USA PATRIOT Act. A Section 311 designation is a powerful tool: once a category or jurisdiction is designated, Treasury can require financial institutions to apply special measures to any transactions connected to it, including record-keeping, reporting, and in extreme cases a complete prohibition on correspondent relationships. The mixer proposal would have given regulators a legal basis to demand enhanced scrutiny of any transaction that touched a mixing protocol or similar privacy service, regardless of transaction size. Like the wallet rule, it never crossed the finish line. FinCEN has now formally rescinded it.

Why FinCEN Withdrew Both Rules Now

The agency was direct in its stated rationale: the withdrawals are part of the current administration's broader deregulatory push and its intent to replace legacy proposals with rules that are better matched to how digital-asset markets actually operate. The phrase "fit-for-purpose" used in FinCEN's announcement is notable. It implies the agency does not regard these withdrawals as a permanent retreat from oversight of self-custody transfers or privacy tools, but rather as a clearing of the decks before new, more workable standards are drafted. Firms should read that signal carefully. The underlying policy concern, that large, opaque transfers to anonymous wallets can facilitate sanctions evasion and other financial crime, has not disappeared. What has changed is the regulatory instrument chosen to address it.

The deregulatory context

These two withdrawals sit within a wider pattern. The current administration has taken a generally permissive stance toward crypto at the federal level, pausing or reversing a number of prior-administration rulemakings. For compliance officers, that pattern creates a specific planning challenge: the regulatory floor has moved, but international standards from the Financial Action Task Force, including the Travel Rule and guidance on virtual asset service providers, remain in place. US firms that operate internationally, or that have counterparties in FATF-member jurisdictions with stricter domestic implementations, still face significant AML obligations even as certain domestic proposals are withdrawn.

Accounting and Audit Implications

Revising AML risk assessments

Accounting firms that service crypto exchanges, OTC desks, or any entity registered as a money-service business need to revisit the AML risk assessment language in their audit files. Many firms documented a heightened risk item tied specifically to the pending unhosted wallet rule: the possibility that a client's existing CTR and SAR processes were not calibrated for self-custody transfers. Now that the proposal is withdrawn, that specific risk item may no longer apply in the same form. However, it would be a mistake to simply delete the line. The underlying transaction type, large transfers to pseudonymous addresses, still carries inherent AML risk and should be assessed on its merits under the Bank Secrecy Act obligations that remain in force.

Engagement letters and compliance scope

Some firms will have written AML consulting or gap-analysis engagements that explicitly referenced the 2020 wallet rule or the 2023 mixer proposal as the regulatory driver for the work. Those engagement letters may need to be updated or supplemented. If a client asks whether the withdrawal means they can scale back a compliance programme that was built in anticipation of the rule, the honest answer is nuanced: the legal obligation to file that specific report is gone, but the BSA duty to maintain effective AML controls and to file SARs on suspicious activity is not. Crypto accounting software used for transaction monitoring should still flag unusual self-custody transfer patterns for human review.

CFO and treasury considerations

For corporate treasury teams holding digital assets, the immediate operational impact is limited because neither rule had taken effect. But CFOs should note two things. First, any internal policy that referenced the pending rules as the basis for restricting or flagging self-custody transfers may need to be rewritten to reference the underlying BSA obligation rather than a specific forthcoming regulation. Second, if the company uses a third-party custodian or exchange, it is worth confirming with that counterparty how they are adjusting their own policies, since the exchange's AML controls directly affect the firm's exposure in a SAR or examination context.

What Has Not Changed

Existing BSA obligations remain intact

The Bank Secrecy Act itself is untouched. Money-service businesses still file SARs on transactions they know, suspect, or have reason to suspect involve funds derived from illegal activity or are designed to evade reporting requirements. The $10,000 CTR threshold for cash transactions at banks still applies in its existing form. What is gone is only the proposed extension of CTR-style logic to crypto self-custody transfers, which had not yet been law. Firms that built their AML programmes around the actual existing rules are in a sound position. Those that deferred AML investment because they were waiting to see how the proposed rules shook out should use this withdrawal as a prompt to assess their current baseline, not as a green light to defer further.

FATF Travel Rule compliance

The FATF Travel Rule requires virtual asset service providers to pass identifying information about originators and beneficiaries along with transfers above a threshold (currently $3,000 in US implementation guidance). That rule is separate from the withdrawn proposals and is still operative. Firms using digital asset accounting software to reconcile inter-exchange transfers need to ensure their workflows still capture Travel Rule data correctly. The withdrawal of the unhosted wallet proposal does not affect Travel Rule obligations for transfers between two VASPs.

SAR obligations on mixer-related activity

The withdrawal of the Section 311 mixer designation proposal means Treasury cannot yet impose special measures on financial institutions handling mixer-linked transactions through that specific legal mechanism. It does not mean a SAR obligation disappears if a firm detects a transaction that has passed through a known mixing protocol and the surrounding facts suggest potential money laundering. The existing SAR standard, based on reasonable suspicion, still applies. Compliance teams should maintain their screening controls for mixer-linked addresses and document their reasoning when they decide not to file.

FinCEN Drops $10,000 Unhosted Wallet and Mixer Reporting Rules

Practical Steps for Firms and Auditors

Short-term actions

There are several concrete steps worth taking in the next 30 to 60 days. First, review any client-facing AML gap analyses that cited the two withdrawn proposals as the primary regulatory driver and update the framing to reflect existing obligations. Second, confirm with exchange and custodian counterparties how they are adjusting their self-custody transfer policies so that any changes to their data-sharing practices are captured in your own records. Third, if your crypto bookkeeping software or transaction monitoring system had rules specifically calibrated to the proposed $10,000 self-custody threshold, assess whether those rules should be retained, adjusted, or replaced with risk-based triggers aligned to your SAR obligations. Fourth, document the withdrawal in your audit workpapers as a change in the regulatory environment and note that no retrospective restatement is needed because the rule never took effect.

Longer-term planning

The "fit-for-purpose" language in FinCEN's announcement suggests new proposals in this space are likely, even if the timeline is uncertain. Firms should watch for FinCEN advance notices of proposed rulemaking on self-custody and privacy protocols. Building flexible AML infrastructure now, whether through digital asset accounting software with configurable rule sets or through documented risk-based frameworks that do not hard-code a single regulatory threshold, will reduce the cost of adapting when the next version of these rules arrives. You can also keep an eye on what the ICBA vs OCC crypto trust charter dispute means for AML obligations as a further indicator of how federal regulators are redefining the perimeter of crypto oversight, and consider reviewing how on-chain risk screening fits your AML workflow to ensure your transaction monitoring remains credible regardless of which specific rules are in force.

The Bigger Picture for Crypto Compliance

The withdrawal of these two proposals removes a specific, long-anticipated compliance burden from the US crypto industry. But it also removes a degree of regulatory clarity: firms at least knew what they were preparing for. In its place, there is a stated intention to build better rules, without a published timeline or a draft to analyse. For accounting firms advising crypto clients, that ambiguity is itself a risk item. Clients may interpret the withdrawal as a broader regulatory retreat and reduce their compliance investment accordingly. The professional duty of an adviser in this environment is to explain clearly what has changed, what has not, and where residual obligations still sit regardless of the political direction of rulemaking. That is a conversation worth having now, before a client makes a decision they may need to reverse.

Source: CoinDesk Policy

Frequently Asked Questions

Does the withdrawal mean firms no longer need to monitor transfers to unhosted wallets?

No. The withdrawal removes the specific proposed reporting obligation, but existing BSA duties, including the requirement to file SARs on suspicious activity, still apply. Transfers to unhosted wallets that present red flags should still be reviewed and documented.

Does the FATF Travel Rule still apply to self-custody transfers?

The Travel Rule applies to transfers between two virtual asset service providers. Where a transfer goes from a VASP to an unhosted wallet, FATF guidance recommends enhanced due diligence, and US implementation guidance still requires originator information to be collected. The withdrawn proposal was separate from and additional to Travel Rule obligations.

Should AML software rules tied to the $10,000 self-custody threshold be deleted?

Not necessarily deleted, but reviewed. A risk-based monitoring rule at or around that threshold may still be justified on SAR-filing grounds. The key is to ensure the rule is documented as a risk-based control rather than as compliance with a regulation that no longer exists as a pending requirement.

What does the mixer proposal withdrawal mean for firms that screen transactions against known mixer addresses?

Screening for mixer-linked addresses remains good practice and is consistent with existing SAR obligations. The withdrawal means Treasury cannot yet impose formal special measures under Section 311, but it does not affect the reasonable-suspicion standard that triggers a SAR filing when mixer activity is detected in a suspicious context.

How should auditors treat these withdrawals in audit workpapers?

Document the change in the regulatory environment clearly, note that neither rule had taken effect and therefore no prior-period compliance position is affected, and update any risk assessment language that referenced the proposals as pending obligations. The residual AML risk from self-custody transfers and mixing activity should be assessed on its substantive merits rather than by reference to a withdrawn rulemaking.

USGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Treasury Sanctions Hamas Crypto Fundraising Network Spanning Europe and Gaza
AML/KYC & Licensing
ZachXBT Infiltrates Lazarus Laundering Network: AML Lessons for Firms
AML/KYC & Licensing
Treasury Withdraws Crypto Unhosted Wallet and Mixer Surveillance Rules
AML/KYC & Licensing
FinCEN Withdraws Crypto Mixing Rule and Self-Hosted Wallet Proposal