FinCEN Withdraws Crypto Surveillance Rules Shifting Compliance to Internal Controls
On October 5, 2026, the U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN) withdrew two contentious surveillance proposals targeting unhosted wallets and mixers. The rules, first proposed in late 2020, would have required banks and money service businesses (MSBs) to collect detailed information on transactions involving non-custodial wallets and report any use of mixers. The withdrawal came after significant industry pushback, with FinCEN stating the rules no longer aligned with current enforcement priorities.
The proposed unhosted wallet rule would have mandated reporting for transactions exceeding $10,000 in 24 hours or $3,000 for high-risk wallets. The mixer rule would have required reporting within 15 days of any interaction, regardless of the amount. The withdrawal of these rules provides immediate relief for crypto treasury managers, who no longer face the burden of per-transaction reporting. However, existing anti-money laundering (AML) and Bank Secrecy Act (BSA) requirements still apply, emphasizing the need for robust internal controls.
For crypto treasury management, the absence of these rules shifts the compliance burden to internal policies. Teams must now reassess their wallet and mixer policies, update internal playbooks, and strengthen governance around multi-signature wallets. DAOs and Web3 treasuries, which rely heavily on multi-sig wallets, also benefit from the withdrawal, as they no longer face the impractical task of identifying every signer’s counterparty wallet. However, they must still adhere to state money-transmission laws and BSA expectations.
Looking ahead, treasury teams should monitor potential legislative actions at the congressional or state level, as well as global regulatory trends like the EU’s MiCA framework. The withdrawal of these rules does not make mixers safe, as FinCEN’s guidance still flags them as high-risk. Unhosted wallets remain a legitimate tool when governed by internal policy and documented controls, but disciplined recordkeeping is essential to maintain compliance and security.