Free guide: How to use AI in compliance
← Back

FinCEN withdraws the unhosted wallet rule and its crypto mixing proposal

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published October 6, 2026Reviewed by Charlene Wang
Editorial illustration for the article "FinCEN withdraws the unhosted wallet rule and its crypto mixing proposal".

FinCEN is withdrawing its 2020 unhosted wallet rule and 2023 mixing proposal, effective 6 October 2026. What still applies to MSBs and banks, and the EU view.

Table of contents

FinCEN announced on 5 October 2026 that it is withdrawing the unhosted wallet rule and its crypto mixing proposal, effective on Federal Register publication on 6 October 2026. The 2020 proposal covered bank and MSB transfers to or from self-custodied wallets. The 2023 proposal targeted transactions involving international mixing. Existing Bank Secrecy Act duties are unchanged.

  • FinCEN announced on 5 October 2026 that it is withdrawing two proposed digital asset rules; both withdrawal notices are dated for Federal Register publication on 6 October 2026.
  • The unhosted wallet rule, proposed in December 2020, would have required reports above 10,000 dollars and identity records above 3,000 dollars for transfers involving unhosted wallets.
  • The mixing proposal of October 2023 used section 311 of the USA PATRIOT Act to treat international mixing as a class of transactions of primary money laundering concern.
  • FinCEN cited commenters' concern that its mixing definition "could have a chilling effect on legitimate activity".
  • MSB registration, the 3,000 dollar funds travel rule and SAR filing still apply to crypto firms. EU crypto firms already check self-hosted addresses above EUR 1,000.

What did FinCEN withdraw on 5 October 2026?

FinCEN is withdrawing two proposals that never became final rules, with effect from Federal Register publication on 6 October 2026. The first is the December 2020 unhosted wallet rule for banks and money services businesses (MSBs). The second is the October 2023 finding and proposed special measure on international convertible virtual currency (CVC) mixing.

The FinCEN press release says the agency considered the comments it received and is withdrawing the proposals "as part of the Trump Administration's deregulatory agenda". Both notices are signed by FinCEN Deputy Director Jimmy L. Kirby and point to the July 2025 report of the President's Working Group on Digital Asset Markets, set up under Executive Order 14178.

The two notices differ in tone. The unhosted wallet withdrawal is final: FinCEN "will take no further action on this NPRM". The mixing withdrawal keeps a door open. FinCEN says illicit actors still use mixers. It will keep monitoring mixer activity and "may take appropriate steps in the future".

ItemUnhosted wallet proposalMixing proposal
Published23 December 2020, 85 FR 8384023 October 2023, 88 FR 72701
Legal basisBSA recordkeeping and reporting rulesSection 311, special measure one
Who was coveredBanks and MSBsAll covered financial institutions
Main triggerCounterparty uses an unhosted or otherwise covered walletTransaction involves CVC mixing outside the US
ThresholdsReport above 10,000 dollars, records above 3,000 dollarsNo dollar threshold
Status on 6 October 2026Withdrawn, no further actionWithdrawn, monitoring continues

The figures come from the withdrawal notices and the original Federal Register documents for the 2020 proposal and the 2023 proposal.

What would the two proposals have required?

The unhosted wallet rule would have made banks and MSBs collect data on the person at the other end of a transfer. Above 10,000 dollars, alone or aggregated within 24 hours, they would have filed a report with FinCEN and verified their own customer's identity. Above 3,000 dollars, they would have kept records of the transaction and the counterparty.

The proposal defined an unhosted wallet by reference to the financial institution: a wallet where no institution is required to conduct the transactions. It also covered "otherwise covered" wallets, meaning wallets held at a foreign institution outside the Bank Secrecy Act (BSA) in a jurisdiction FinCEN would name. Assets in scope were CVC and digital assets with legal tender status.

The first comment window closed on 4 January 2021, 12 days after publication. FinCEN reopened it on 15 January 2021 and later set one deadline of 29 March 2021. The rule then stayed a proposal for more than five years.

What would the mixing proposal have required?

The 2023 mixing proposal would have required far more data than the unhosted wallet rule. A report would have listed the amount, the asset type, the mixer used, wallet addresses, transaction hashes, IP addresses and a narrative. According to the withdrawal notice, institutions would also have kept records of each customer's full identity, date of birth, address and email address.

The mixing definition was broad. It covered pooling funds from several persons, splitting transfers into a series of independent transactions, single-use addresses, swaps between asset types and user-initiated delays. In its withdrawal notice FinCEN acknowledged commenters' warning that it could chill legitimate activity and place a large reporting burden on covered financial institutions.

What still applies to crypto MSBs and banks?

Withdrawing the unhosted wallet rule and the mixing proposal changes no existing obligation. A business that accepts and transmits CVC is still a money transmitter under FinCEN's 2019 guidance. It still needs an AML programme, travel rule compliance at 3,000 dollars, suspicious activity reporting and sanctions screening. Teams should keep those controls and drop any project built only for the proposals.

Start with registration and programme duties. An MSB registers with FinCEN within 180 days of being established and renews every two years under 31 CFR 1022.380. FinCEN's 2019 CVC guidance, FIN-2019-G001, treats hosted wallet providers as account-based money transmitters, which makes them money services businesses under the Bank Secrecy Act. The same guidance says a person using an unhosted wallet to buy goods or services on their own behalf is not a money transmitter.

Next, the travel rule. Under 31 CFR 1010.410(e) and (f), nonbank financial institutions keep records of, and pass on information with, transmittals of 3,000 dollars or more. The 2019 guidance applies this rule to hosted wallet providers. A transfer to an unhosted wallet has no receiving institution to send the data to, so the transmittor's records carry the evidence. A practical guide is our FATF travel rule explainer.

Suspicious activity reporting is unchanged. MSBs file a suspicious activity report at 2,000 dollars and banks at 5,000 dollars when the regulatory tests are met. Exposure to a mixer can still support a SAR. FinCEN's notice says it continues to watch mixer activity for "indicia of money laundering".

Sanctions screening is unchanged too. OFAC liability is strict, and blockchain analytics stay relevant for designated addresses. OFAC removed Tornado Cash from the SDN List on 21 March 2025, but OFAC can still list a named mixer or address.

Customer due diligence for counterparties is now a risk-based question. With the unhosted wallet rule gone, no federal rule requires a US firm to identify the person behind a self-custodied address. The travel rule records still capture what the customer provides about the recipient, and the firm decides when to ask for more.

What is still uncertain after the withdrawal?

The withdrawal settles federal rulemaking for now, not supervisory expectations. Examiners still judge whether a programme's monitoring is reasonable for its risk. Firms also operating in the EU must meet stricter rules on self-hosted addresses.

The first open question is the mixing notice's reservation. FinCEN says it "may take appropriate steps in the future". Section 311 still lets FinCEN act against a named foreign institution or a class of transactions. Any new measure would need a fresh finding, and measures one to four imposed by order without a rule last no more than 120 days. A firm that sees heavy mixer exposure should not read the withdrawal as clearance.

The second open question is examination practice. Supervisors judge suspicious activity monitoring against the institution's own risk assessment, so the test is whether the controls fit the risks the firm has documented. A programme that removes mixer or unhosted wallet indicators because a proposal died could struggle to justify that choice to an examiner.

The third is cross-border inconsistency. A US platform with European customers still runs EU rules, and the gap is widening (see the next section). Two policies for one wallet population add engineering cost and audit complexity.

The fourth is data. The 2020 proposal would have pushed counterparty names and addresses into the systems of every bank and MSB in scope. Its withdrawal reduces the volume of collected personal data. It does not reduce the duty to protect what firms already hold.

How does the US approach now compare with the EU?

The US and the EU now point in opposite directions on self-custodied wallets. Under the EU Transfer of Funds Regulation, applicable since 30 December 2024, a crypto-asset service provider must assess whether a self-hosted address is owned or controlled by its own customer for transfers above EUR 1,000. From 10 July 2027 the EU AML Regulation also bars CASPs from keeping accounts that allow anonymisation, including through anonymity-enhancing coins.

TopicUnited States after 6 October 2026European Union
Self-hosted transfersNo specific federal rule beyond travel rule records at 3,000 dollarsOwnership or control assessment above EUR 1,000
Counterparty dataRecipient details kept at 3,000 dollars, beyond that risk-basedOriginator and beneficiary information collected for every transfer
Mixing and privacy toolsProposal withdrawn, monitoring continuesAccounts allowing obfuscation banned from 10 July 2027
Future measuresFinCEN may act later on mixersCommission review of self-hosted address risks, possibly with restrictions

Article 14(5) and Article 16(2) of Regulation (EU) 2023/1113 set the EUR 1,000 test, and Article 37(2) required the Commission to report by 1 July 2026 on self-hosted address risks and on whether specific measures are needed. Article 79 of the AML Regulation (EU) 2024/1624 prohibits crypto-asset accounts that allow anonymisation "including through anonymity-enhancing coins".

How should compliance teams respond?

Compliance teams should treat the withdrawal as the end of two proposals, not a reason to relax controls. Retire any build work tied only to the 2020 reporting format. Keep travel rule records, mixer indicators and sanctions screening. Write the new risk-based position on unhosted wallets into the programme, so an examiner can see why it was chosen.

First, update the BSA/AML risk assessment. Record that the federal proposals are withdrawn, and set out how the firm scores unhosted wallet and mixer exposure instead.

Second, check monitoring rules. Keep mixer and privacy-tool typologies in transaction monitoring and SAR decision logic. Document thresholds and the reason for each.

Third, split policy by jurisdiction where needed. EU-facing flows still need the EUR 1,000 ownership assessment. The EBA travel rule guidelines list methods such as a small predefined transfer from the address or a message signed with its key. A signed message needs wallet software that supports signing, while a test transfer works with any wallet but waits for on-chain confirmation. A US programme can keep the same methods as an optional, risk-triggered step. Identity checks for crypto customers are covered in our crypto KYC compliance guide.

Fourth, minimise what you store. Collect counterparty data only where a rule or a risk decision requires it, and set retention limits that match the five-year BSA record period.

Zyphe runs KYC and AML screening with a reusable credential, so a customer verified once can re-present the result, and their documents stay encrypted in their own vault rather than in a central store of customer PII. To see how it fits a crypto onboarding flow, book a demo.

The bottom line

The withdrawal of the unhosted wallet rule and the mixing proposal ends nearly six years of uncertainty for US crypto firms, but it removes proposals, not obligations. Money transmitter status, travel rule records, SAR filing and sanctions screening all stand. The practical work is to document a risk-based stance on self-custodied wallets and mixers, and to keep a separate, stricter path for EU customers.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

It was a December 2020 proposal requiring banks and money services businesses to report crypto transfers above 10,000 dollars involving unhosted or otherwise covered wallets, and to keep records above 3,000 dollars. It never became final. FinCEN announced its withdrawal on 5 October 2026, effective 6 October, and says it will take no further action on it.

No. Crypto firms that accept and transmit value remain money services businesses under FinCEN's 2019 guidance. They still need an AML programme that verifies customer identity, travel rule records at 3,000 dollars, suspicious activity reporting and sanctions screening. Only the two proposed additional duties are gone.

FinCEN cited the Administration's deregulatory agenda and the July 2025 report of the President's Working Group on Digital Asset Markets. It also said commenters warned the broad definition of mixing could chill legitimate activity and impose a large reporting burden. FinCEN said it will keep monitoring mixers and may act in future.

Yes, when the suspicious activity tests are met. MSBs file at 2,000 dollars and banks at 5,000 dollars. The withdrawal removes a proposed special report, not the existing SAR duty, and FinCEN's notice says it still sees illicit actors using mixers to hinder investigations.

The EU Transfer of Funds Regulation has applied since 30 December 2024. Crypto-asset service providers collect originator and beneficiary information for transfers to or from self-hosted addresses and, above EUR 1,000, assess whether the customer owns or controls the address. From 10 July 2027 the AML Regulation bars CASPs from keeping accounts that allow anonymisation, including through anonymity-enhancing coins.

See privacy-first KYC in action

Verify identity without a central store of documents. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo