Treasury Withdraws Crypto Unhosted Wallet and Mixer Surveillance Rules
The US Department of the Treasury has officially withdrawn two proposed Bank Secrecy Act rules that would have forced crypto businesses to collect, record, and report data on transactions involving unhosted wallets and cryptocurrency mixing services. The withdrawal, announced in October 2026, removes what many in the industry had flagged as among the most operationally demanding AML proposals ever put to the digital asset sector. For accounting firms, auditors, and CFOs with crypto exposure, the immediate question is not celebration but recalibration: what compliance work built in anticipation of these rules now needs to be revisited, and what underlying AML obligations remain unchanged?
What the Two Withdrawn Rules Would Have Required
Understanding what has been withdrawn matters as much as the withdrawal itself. Treasury had put forward two distinct proposals under the Bank Secrecy Act framework administered by the Financial Crimes Enforcement Network (FinCEN).
The Unhosted Wallet Rule
The first proposal targeted transactions between regulated financial institutions (including crypto exchanges registered as money services businesses) and unhosted wallets, which are wallets where the user holds their own private keys rather than relying on a custodian. Under the draft rule, covered institutions would have been required to collect counterparty identity information for transactions above a specified threshold, maintain records, and in some cases file reports with FinCEN. The proposal drew direct comparisons to the existing Travel Rule, but its reach into self-custodied wallets made it significantly broader in scope.
The Mixer Surveillance Rule
The second proposal would have designated cryptocurrency mixing as a category of "primary money laundering concern" under Section 311 of the USA PATRIOT Act. That designation would have given FinCEN authority to impose special measures on financial institutions that interact with mixing services, potentially including outright prohibition of certain transactions. Mixing services, which aggregate and redistribute cryptocurrency to obscure transaction trails, have been a persistent focus of enforcement actions, but the proposed rule would have created a formal standing obligation rather than relying on case-by-case enforcement.
Why Treasury Has Pulled the Proposals
Treasury has not published a detailed explanatory statement alongside the withdrawal, so the precise reasoning is a matter of official record rather than speculation. What is publicly known is that both proposals attracted substantial industry opposition during comment periods, with concerns centred on technical feasibility, privacy implications, and the risk of driving activity toward less transparent venues. The current administration has also signalled a broader preference for regulatory restraint in the digital asset space, consistent with executive-level guidance issued earlier in 2026 directing agencies to reduce regulatory friction for crypto businesses. The withdrawal fits within that broader posture.
It is equally important to note what the withdrawal does not do. It does not repeal the Bank Secrecy Act. It does not alter existing FinCEN guidance on virtual currency. It does not remove the Travel Rule obligations that already apply to money services businesses. And it does not affect OFAC sanctions screening requirements, which operate entirely independently of the withdrawn proposals. Firms that have built AML programmes on those existing foundations are not affected by this decision in any operational sense.
Accounting and Audit Implications
For accounting firms and auditors serving crypto clients, the withdrawal creates a specific set of tasks that belong in the next engagement cycle.
Reassess Provisions and Contingency Disclosures
Some firms may have advised clients to accrue costs or disclose contingent compliance burdens in financial statements prepared in anticipation of the rules. With the proposals formally withdrawn, those provisions and disclosures need to be revisited. Under US GAAP, a contingent liability accrual is appropriate only when an obligation is probable and estimable. A rule that no longer exists cannot sustain a probable obligation, so any accruals tied solely to the withdrawn proposals should be reversed and the reversal documented in the working papers.
Update AML Programme Documentation
Crypto businesses that had begun drafting policies, procedures, or technology specifications in response to the proposed rules will need to update their compliance documentation. Auditors conducting AML programme reviews should request updated policy inventories from clients and confirm that no active control references the withdrawn rules as their source of authority. Leaving phantom controls in place creates confusion and may mislead future examiners about the firm's actual regulatory basis.
Engagement Letters and Scope
If an engagement letter or a compliance gap assessment specifically scoped work around either of the withdrawn proposals, that scope should be revisited with the client. Depending on how the work was framed, there may be a case for a revised scope memo. Good digital asset accounting software and crypto bookkeeping software setups will have audit trails of which regulatory triggers drove which workflow configurations; those logs should be reviewed and updated accordingly.
What Changes for CFOs with Digital Asset Exposure
CFOs at companies that hold digital assets on their balance sheet, operate treasury functions using crypto, or have subsidiaries that interact with decentralised protocols should treat this withdrawal as an occasion to run a structured regulatory gap review rather than a signal to relax oversight.
Existing Obligations Are Unchanged
The core AML framework governing US businesses with crypto exposure has not changed. FinCEN's 2019 guidance on convertible virtual currency, the Travel Rule thresholds for money services businesses, OFAC's sanctions screening expectations, and state-level money transmission licensing requirements all remain in full force. A CFO who interprets the Treasury withdrawal as a broad relaxation of crypto compliance requirements is misreading the situation in a way that could create material risk.
Counterparty Due Diligence Still Matters
The withdrawal of the unhosted wallet rule does not mean that transacting with self-custodied wallets is now risk-free from a compliance perspective. Banks and exchanges that interact with corporate treasury operations still apply their own internal risk scoring, and a corporate wallet that regularly transacts with high-risk addresses can still trigger enhanced due diligence requests or account restrictions. CFOs running crypto treasury programmes should maintain their counterparty screening processes and ensure their digital asset accounting software captures the provenance data needed to respond to those requests promptly. For context on how on-chain risk providers approach this kind of screening, see our earlier coverage of the nine questions to ask every on-chain risk provider.
International Exposure Requires Separate Analysis
Firms with cross-border operations should note that the Treasury withdrawal has no bearing on AML obligations in other jurisdictions. The Financial Action Task Force's Recommendation 16 (the international Travel Rule standard) continues to apply in jurisdictions that have implemented it, and several of those jurisdictions have taken a stricter line on unhosted wallets than the now-withdrawn US proposal would have required. European firms operating under MiCA and its associated AML framework, for example, face different rules entirely. The withdrawal is a US domestic regulatory event, not a global reset.
Broader Regulatory Context
The withdrawal sits inside a period of significant regulatory repositioning in Washington. The current administration has used executive action to direct financial regulators toward less prescriptive approaches to digital assets, and FinCEN has been among the agencies navigating those signals while retaining its statutory mandate under the Bank Secrecy Act. The mixer proposal in particular had raised novel legal questions about the extent to which a decentralised protocol could be treated as a financial institution subject to BSA obligations, questions that federal courts had begun to address in related enforcement contexts.
The enforcement landscape has also shifted. Rather than broad surveillance rules, the current approach appears to favour targeted enforcement actions against specific bad actors, a pattern consistent with OFAC's continued use of sanctions designations and the Department of Justice's prosecution strategy. For firms advising clients on AML risk, that shift in approach matters: a rules-based compliance programme built around specific regulatory triggers may need to be supplemented with a more principles-based risk assessment framework that can absorb enforcement-by-action rather than enforcement-by-regulation.
For a sense of how international AML enforcement continues regardless of US domestic rule changes, the situation involving Japan's Garantex sanctions and what firms need to know is instructive: sanctions actions operate on a separate legal track and are unaffected by domestic rulemaking withdrawals.
Frequently Asked Questions
Does the withdrawal mean unhosted wallets are now unregulated in the US?
No. The withdrawal removes a proposed additional layer of reporting and recordkeeping. Existing Bank Secrecy Act obligations, OFAC sanctions screening, and the applicable rules for money services businesses all continue to apply. Exchanges and other covered entities still make their own risk-based decisions about how they treat unhosted wallet transactions.
Do businesses need to file anything with FinCEN to confirm they are not subject to the withdrawn rules?
No filing is required. Because the proposals never became final rules, no compliance action under those specific proposals was ever legally required. Businesses should update their internal compliance documentation to reflect that the anticipated obligations will not materialise, but there is no regulatory notification process tied to the withdrawal.
Should accruals made in anticipation of compliance costs be reversed immediately?
That depends on the specific basis for the accrual. If the provision was tied solely to costs expected from the withdrawn rules and there is no residual obligation, a reversal is appropriate under US GAAP once the withdrawal is confirmed. If the accrual also covered costs related to other regulatory requirements that remain in force, only the portion attributable to the withdrawn rules should be reversed. Document the analysis in the working papers either way.
How does this affect crypto businesses that were already building unhosted wallet tracking into their crypto accounting software?
Operationally, those firms now have more flexibility in how they configure their digital asset accounting software. However, retaining the capability to track wallet provenance is still commercially prudent, since exchanges and banking partners may request that data independently of any regulatory mandate. Firms should review whether the technical build can be repurposed for voluntary risk management rather than scrapped entirely.
Does the mixer rule withdrawal affect OFAC sanctions against specific mixing services?
No. OFAC sanctions against named entities, including any mixing services that have been designated, remain in full force. The withdrawn FinCEN proposal would have created a structural obligation covering mixing as a category. OFAC designations are individual enforcement actions under a different statutory authority and are not affected by this withdrawal.
Source: Decrypt
