The U.S. Treasury has removed two of the most controversial unfinished crypto-surveillance proposals of the past several years.
On October 5, the Financial Crimes Enforcement Network announced that it is withdrawing:
- a 2020 proposal that would have imposed recordkeeping, verification and reporting requirements on certain transactions involving convertible virtual currency and unhosted wallets; and
- a 2023 proposal for a special measure involving convertible virtual currency mixing.
- the same customer;
- a merchant;
- a friend;
- a DAO;
- a smart contract;
- a privacy tool.
- self-custody;
- privacy;
- theft laundering;
- sanctions evasion;
- ordinary commercial activity.
- self-hosted-wallet transfers;
- mixers;
- privacy protocols;
- cross-chain bridges;
- stablecoin issuers.
The withdrawals are significant.
They are also easy to overstate.
Neither proposal had become a final rule.
FinCEN is not eliminating the Bank Secrecy Act.
Crypto exchanges and money services businesses still have anti-money-laundering, customer-identification, suspicious-activity and sanctions-related obligations under existing law.
The change is narrower and more important:
FinCEN has decided not to finalize these two broad, crypto-specific reporting frameworks.
The Unhosted-Wallet Proposal Targeted the Boundary Between Exchanges and Self-Custody
The 2020 proposal focused on transfers between regulated institutions and wallets not hosted by another financial institution.
Under the proposed framework, banks and money services businesses would have faced additional information-collection and reporting obligations for certain transactions involving unhosted wallets.
Contemporary descriptions of the proposal highlighted thresholds including recordkeeping above $3,000 in covered circumstances and reporting for certain transactions above $10,000.
The policy question was fundamental.
When a customer withdraws crypto from an exchange to a wallet they control, how much information should the exchange be required to collect about the destination?
Self-custody makes the answer difficult because the external address may belong to:
An address is not automatically a legal identity.
The proposed rule tried to extend more traditional financial-reporting concepts into that environment.
FinCEN has now withdrawn that approach.
The Mixer Proposal Was Even Broader
In 2023, FinCEN proposed using Section 311 of the USA PATRIOT Act to treat certain international convertible-virtual-currency mixing activity as a class of transactions of primary money laundering concern.
The proposal would have required covered financial institutions to collect and report information associated with mixing-related activity.
Critics argued that the definition could sweep too broadly and discourage legitimate privacy technologies.
FinCEN says it considered the comments and is withdrawing the proposal as part of an effort to make digital-asset rules more fit for purpose.
That removes one broad proposed reporting regime.
It does not turn every mixer into a legally protected service.
Targeted sanctions, criminal enforcement and other AML tools remain available.
Withdrawal Is Not the Same as a Safe Harbor
The cleanest way to understand the change is to separate a proposed reporting rule from underlying legal risk.
FinCEN is withdrawing the proposal.
It is not promising never to regulate self-hosted-wallet transfers.
It is not saying privacy tools cannot be used for money laundering.
It is not eliminating suspicious-activity reporting.
It is not preventing OFAC from sanctioning entities or addresses.
And it is not stopping law-enforcement investigations.
This distinction matters because headlines such as “Treasury ends crypto wallet surveillance” go too far.
Existing compliance frameworks still operate.
The removed rules would have added new crypto-specific obligations on top.
Why Self-Custody Is Becoming a Regulatory Principle
The timing is notable because the CFTC on the same day proposed treating delivery to an external non-custodial wallet as a strong example of “actual delivery” for retail commodity transactions.
Two agencies are approaching self-custody from different legal frameworks.
FinCEN is stepping away from a proposed special reporting regime at the exchange-to-wallet boundary.
The CFTC is considering self-custody as evidence that the user truly received the commodity.
Together, those actions suggest a broader shift:
control of private keys is increasingly being treated as a meaningful legal fact, not merely a technical preference.
That does not mean every regulator will treat self-custody favorably.
It does mean wallet architecture now matters directly to policy.
Privacy and Compliance Are Still in Tension
Crypto privacy has legitimate uses.
Companies do not want payroll, supplier payments and treasury balances exposed publicly.
Individuals may not want every purchase permanently linked to one public address.
At the same time, mixers can be used to obscure stolen or sanctioned funds.
The policy problem is designing rules that target illicit behavior without automatically treating privacy as suspicious.
FinCENs withdrawal suggests the previous approach was not the final answer.
A future framework may focus more narrowly on risk-based indicators, specific entities or transaction patterns rather than broad categories of tools.
Why It Matters
The decision reduces regulatory uncertainty around two proposals that had remained unfinished for years.
For exchanges, it avoids the immediate prospect of building large new reporting systems around self-hosted-wallet counterparties under those proposals.
For wallet developers, it removes a policy overhang that critics feared could make private wallets harder to use.
For privacy protocols, it signals that broad category-level regulation can be reconsidered.
But the deeper lesson is not deregulation.
It is regulatory targeting.
A durable AML framework needs to distinguish:
Those categories overlap, but they are not identical.
Risks and Counterarguments
The withdrawal can be reversed in spirit by future rulemaking.
Congress can legislate new requirements.
Agencies still have broad authorities under the Bank Secrecy Act and sanctions law.
Financial institutions may continue to apply their own risk-based controls to self-hosted-wallet transfers.
And privacy services connected to criminal activity can still face enforcement.
The market should not treat the announcement as an end to crypto AML regulation.
What to Watch Next
Watch whether FinCEN develops narrower, risk-based guidance for:
Also monitor how exchanges adjust their withdrawal-risk controls.
The key policy signal will be whether U.S. regulation moves from broad transaction-category rules toward behavior- and risk-specific compliance.
FAQ
What did FinCEN withdraw?
A 2020 proposal on certain unhosted-wallet transactions and a 2023 proposal involving CVC mixing.
Were those rules already in force?
No. They were proposals, not final effective rules.
Does this end AML requirements for crypto exchanges?
No. Existing Bank Secrecy Act, suspicious-activity and related obligations remain.
Does this make crypto mixers legal?
The withdrawal does not create a blanket safe harbor for mixers.
Why does it matter for self-custody?
It removes a proposed federal reporting framework that would have imposed additional requirements on certain transfers involving unhosted wallets.


