Privacy coin regulation after FinCEN drops its mixing rule
FinCEN withdrew its crypto mixing and unhosted wallet proposals on 6 October 2026. What still binds firms in the US, EU, Canada, India and Dubai, and what to do before AMLR Article 79 applies in July 2027.
By Alberto RosasCo-founder & CEO, DiditUpdated 
In short
Privacy coin regulation moved in opposite directions this week. On 6 October 2026 the US Financial Crimes Enforcement Network (FinCEN) withdrew its 2023 proposal to make banks and exchanges report crypto mixing, and its 2020 proposal on unhosted wallets.[1][2][3] The European Union, India and Dubai keep their restrictions, and the EU adds a new one on 10 July 2027.[6][7][9][10]
- The withdrawn US rules never applied. FinCEN's 2019 guidance still treats a service that anonymises transfers for others as a money transmitter, and FinCEN says it may still act on mixers.[2][5]
- From 10 July 2027, EU credit institutions, financial institutions and crypto-asset service providers may not keep accounts that allow anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.[6]
- Each rule has its own scope: money transmitters in the US, service providers in the EU and India, and issuance plus all related virtual asset activities in Dubai.[5][6][9][10]
A privacy coin is a crypto-asset built to hide who sent what to whom. A mixer does the same for coins on a public ledger. A no-KYC swap service trades crypto without know your customer (KYC) checks.
What happened: FinCEN withdrew two crypto proposals
On 5 October 2026 FinCEN announced that it was withdrawing two proposed rules on convertible virtual currency (CVC): one on mixing and one on unhosted wallets.[1] CVC is the term FinCEN's guidance uses for virtual currency that substitutes for currency.[5] Both withdrawals were published in the Federal Register and took effect on 6 October 2026.[2][3]
The mixing proposal rested on section 311 of the USA PATRIOT Act, which lets the Treasury name a class of transactions "of primary money laundering concern" and attach special measures.[2] Covered financial institutions would have reported any transaction they knew, suspected or had reason to suspect involved mixing within or involving a jurisdiction outside the United States, within 30 calendar days of detecting it.[2][4]
In the withdrawal notice FinCEN maintains that illicit actors continue to use mixers. It wrote that the withdrawal "is informed by the concerns from commentors that the expansive definition of CVC mixing in the proposed rule could have a chilling effect on legitimate activity and place a large reporting burden on covered financial institutions."[2]
| Withdrawn proposal | Published | What it would have required | Withdrawal |
|---|---|---|---|
| CVC mixing special measure | 23 October 2023, 88 FR 72701[4] | Reports on suspected foreign mixing, with wallet addresses, transaction hashes and IP addresses[2] | 6 October 2026, 91 FR 63513[2] |
| Unhosted wallet rule | 23 December 2020, 85 FR 83840[3] | Banks and money services businesses to report, keep records and verify customers on unhosted wallet transactions[3] | 6 October 2026, 91 FR 63514[3] |
Watch out
A withdrawn proposal removes no duty that exists today. FinCEN wrote that it "will continue to monitor activity involving CVC mixers for indicia of money laundering, terrorist financing, or other illicit finance activity, and may take appropriate steps in the future to mitigate any such activity."[2]
The rules behind it: what still binds firms
In the United States, the working text is FinCEN guidance FIN-2019-G001 of 9 May 2019. A provider of anonymizing services is a money transmitter under the Bank Secrecy Act, the core US anti-money laundering law. A provider of anonymizing software is not: suppliers of tools "are engaged in trade and not money transmission."[5]
The guidance also covers the firm that receives anonymised value. A money transmitter "cannot avoid its regulatory obligations because it chooses to provide money transmission services using anonymity-enhanced CVC." When it knowingly accepts such value in a transfer subject to the Funds Travel Rule, it must track the value and have procedures to obtain the identity of the sender or recipient.[5]
The EU writes the asset category into the law. The EU Anti-Money Laundering Regulation (AMLR) defines anonymity-enhancing coins as crypto-assets with built-in features designed to make transfer information anonymous, "either systematically or optionally".[6] Article 79 then prohibits regulated firms from keeping a class of accounts.[6]
Article 79(1)Regulation (EU) 2024/1624
"Credit institutions, financial institutions and crypto-asset service providers shall be prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts as well as any account otherwise allowing for the anonymisation of the customer account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins."
Source: EUR-Lex, Regulation (EU) 2024/1624[6]
Article 79 applies from 10 July 2027.[6] Under Article 76(3) of the Markets in Crypto-Assets Regulation (MiCA), a trading platform's operating rules must prevent the admission to trading of crypto-assets with an inbuilt anonymisation function, unless the platform can identify the holders and their transaction history. MiCA has applied since 30 December 2024.[7]
So regulators use two tests: one names the asset, the other asks whether the firm can still identify who holds it.
Test 1
The asset category is named
- EU: AMLR Article 79, from 10 July 2027[6]
- India: FIU-IND guidelines, section 7.4[9]
Test 2
Traceability decides
- EU: MiCA Article 76(3), since 30 December 2024[7]
- Dubai: VARA definition of Anonymity-Enhanced Cryptocurrencies[10]
- US: track and obtain identity when accepting anonymised value[5]
An EU trading platform faces both tests.
Who it affects, by jurisdiction
Each rule has its own addressee. The EU, US and Indian texts bind firms that provide services, not a person who holds a privacy coin in their own wallet.[5][6][9] Recital 160 of the AMLR says the Article 79 prohibition does not apply to providers of hardware, software or self-hosted wallets, as long as they have no access to or control over those wallets.[6]
| Jurisdiction | Instrument | Who it binds | What it says | Status on 6 October 2026 |
|---|---|---|---|---|
| EU | AMLR Article 79[6] | Credit institutions, financial institutions, crypto-asset service providers | No account allowing anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins | Applies from 10 July 2027 |
| EU | MiCA Article 76(3)[7] | Operators of crypto trading platforms | No admission to trading for anonymising assets unless holders and history can be identified | Applies since 30 December 2024 |
| EU | Regulation (EU) 2023/1113, Article 16(2)[8] | The crypto-asset service provider of the beneficiary | Obtain and hold originator and beneficiary information on a transfer from a self-hosted address; above EUR 1,000, take adequate measures to assess whether the beneficiary owns or controls that address | Applies since 30 December 2024 |
| US | FIN-2019-G001, section 4.5[5] | Money transmitters, by role performed | Anonymizing service providers are money transmitters; software providers are not | Guidance in place since 9 May 2019 |
| India | FIU-IND guidelines, sections 7.3 to 7.5[9] | Virtual digital asset service providers, wherever registered | No deposits or withdrawals of anonymity-enhancing crypto tokens; same for mixers | Guidelines updated 8 January 2026 |
| Dubai | VARA Virtual Assets and Related Activities Regulations 2023[10] | Issuance and virtual asset activities in the Emirate | The issuance of Anonymity-Enhanced Cryptocurrencies and all virtual asset activities related to them are prohibited in the Emirate | Version dated 19 May 2025 |
In India, reporting entities "shall refrain from permitting deposits or withdrawals of Anonymity-Enhancing Crypto Tokens (AECs)", and every entity engaged in the notified activities must register with the Financial Intelligence Unit, India (FIU-IND), whatever its registered location.[9] Dubai's Virtual Assets Regulatory Authority (VARA) defines the prohibited category by traceability: a virtual asset that prevents the tracing of transactions or ownership and for which the provider "has no mitigating technologies or mechanisms to allow traceability or identification of ownership."[10]
For no-KYC services, enforcement turns on registration and identification. The Royal Canadian Mounted Police said on 18 September 2025 that it had recovered an estimated sum of over 56 million dollars from the platform TradeOgre, which "failed to register with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a money services business and did not identify its clients." The release said charges may follow.[11] In the US, the two co-founders of Samourai Wallet were sentenced in November 2025 to five and four years in prison. The US Attorney's Office said they "participated in a conspiracy to operate a money transmitting business in which they knowingly transmitted criminal proceeds."[14]
Timeline: from the first rules to July 2027
- 9 May 2019US guidanceFinCEN: anonymizing services are money transmitters.[5]
- 30 December 2024EU appliesMiCA and the transfer of funds regulation apply.[7][8]
- 8 January 2026India updatesFIU-IND guidelines bar anonymity-enhancing token transfers.[9]
- 6 October 2026US withdrawsFinCEN drops the mixing and unhosted wallet proposals.[2][3]
- 10 July 2027AMLR appliesArticle 79 and the Article 40 risk duty start.[6]
What compliance teams should do now
The EU deadline is nine months away.[6] The work is the same in the US and the EU: know which assets you support and what you do with a transfer from a wallet nobody hosts.
- List every supported asset with an inbuilt or optional anonymisation feature.[6][7]
- Decide before 10 July 2027 which accounts and assets you stop offering in the EU.[6]
- As an EU beneficiary's provider, collect originator and beneficiary information on every transfer from a self-hosted address; above EUR 1,000, assess whether the beneficiary owns or controls it.[8]
- Write the risk assessment for self-hosted transfers that Article 40 AMLR requires.[6]
- Screen inbound wallets and set a rule for mixer exposure, as India's guidelines expect.[9]
- Keep the 2019 FinCEN guidance in your US policy.[2][5]
- Check your registration in each country you serve.[9][11]
1An inbound transfer reaches an EU provider
Check that originator and beneficiary information came with it.[8]
The sending address is self-hosted
Obtain the information from your customer
Above EUR 1,000, assess whether the customer owns or controls the address.[8]
Check the information the other provider sent
Follow up on anything missing.[8]
2Screen the wallet and apply your risk rules
From 10 July 2027, add mitigating measures such as enhanced ongoing monitoring.[6]
3Verify the beneficiary, then release the funds
Decide and record the reason.[8]
Simplified from Articles 16(1) to 16(3) of Regulation (EU) 2023/1113 and Article 40 of the AMLR.
What is still open on 6 October 2026
The largest open question sits in a US court: where writing privacy software ends and running a money transmitting business begins.
| Open item | Where it stands |
|---|---|
| The Tornado Cash prosecution | A jury in the Southern District of New York convicted a co-founder of Tornado Cash on 6 August 2025 of conspiracy to operate an unlicensed money transmitting business and reached no verdict on two other counts.[12][13] The retrial is set for 26 April 2027. On 10 September 2026 the court declined to dismiss the two counts on Speedy Trial Act grounds.[12] |
| US charging policy | A Justice Department memorandum of 7 April 2025 says it will no longer target exchanges, mixing services and offline wallets for the acts of their end users, with exceptions.[15] Remarks by the Criminal Division on 21 August 2025 set cumulative conditions: "where the evidence shows that software is truly decentralized and solely automates peer-to-peer transactions, and where a third party does not have custody and control over user assets, new 1960(b)(1)(C) charges against the third-party will not be approved. Though, if criminal intent is present, other charges may be appropriate."[16] The provision is 18 U.S.C. 1960(b)(1)(C), on transmitting funds known to derive from crime or to be intended for unlawful activity.[16] This is policy, not law. |
| Optional privacy in the EU | The AMLR definition covers coins whose privacy features work "optionally".[6] The text does not say how Article 79 treats an account that uses such a coin only in its transparent mode. |
| EU guidance | The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) must issue guidelines on self-hosted address measures by 10 July 2027.[6] The Commission was due to report on self-hosted address risks by 1 July 2026; I could not find a published report.[8] |
The Financial Action Task Force (FATF), the global standard setter, said on 16 July 2026 that jurisdictions adopting prohibition frameworks "continue to face challenges in identifying and sanctioning illicit VASP activity", VASP meaning virtual asset service provider. It added that prohibition is permitted under its Standards and that its effectiveness depends on strong supervision and enforcement.[17]
How Didit helps with wallet screening and customer checks
First, the limit. Didit does not trace privacy coins and does not de-anonymise any transaction. Article 79 is about which accounts a firm keeps. Software can support the controls around that decision, and the choice stays with the firm.
Didit works next to that decision. Wallet screening runs inside transaction monitoring, which applies real-time rules to fiat and crypto transfers and raises alerts. Its pricing is on the pricing page.
Customer checks are separate products. A full KYC check costs $0.33 and an anti-money laundering (AML) screening check costs $0.20. Questionnaires collect source of funds.
Didit provides
- Wallet screening inside transaction monitoring rules
- Real-time rules, alerts and case management
- Identity verification and AML screening of the customer
- Report preparation for the financial intelligence unit, which you file
Stays with you
- Which assets and accounts you offer
- The risk assessment for self-hosted transfers
- The decision to accept, hold or reject a transfer
- Every report, and the liability for it
Put wallet checks and customer checks in one workflow
Screen the wallet, verify the person and keep the evidence of each decision.
Key takeaways
- FinCEN withdrew its mixing and unhosted wallet proposals on 6 October 2026. Neither had ever applied.[2][3]
- FinCEN's 2019 guidance still makes a service that anonymises transfers for others a money transmitter.[5]
- From 10 July 2027, AMLR Article 79 bars the EU firms it names from keeping accounts that allow anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.[6]
- India and Dubai restrict the asset category today, each with its own scope.[9][10]
Frequently asked questions
Did FinCEN legalise crypto mixers?
No. FinCEN withdrew a proposed reporting rule that had never applied. Its 2019 guidance still treats a provider of anonymizing services as a money transmitter with Bank Secrecy Act duties.[2][5]
Why did FinCEN withdraw the mixing rule?
FinCEN said commenters were concerned that the expansive definition of CVC mixing could chill legitimate activity and place a large reporting burden on covered financial institutions. It also said it will keep monitoring mixers and may take appropriate steps in the future.[2]
Does the EU ban privacy coins?
Not for holders. From 10 July 2027, Article 79 of the AMLR bars credit institutions, financial institutions and crypto-asset service providers from keeping accounts that allow anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.[6]
Is a no-KYC exchange legal?
It depends on the country and on what the service does. Canadian police said in September 2025 that TradeOgre failed to register as a money services business and did not identify its clients.[11]
What must an EU provider do with a transfer from a self-hosted wallet?
Under Article 16(2) of Regulation (EU) 2023/1113, the crypto-asset service provider of the beneficiary must obtain and hold the information on the originator and the beneficiary. Above EUR 1,000 it must take adequate measures to assess whether the beneficiary owns or controls the address.[8]
Does India ban privacy coins?
The guidelines name no coin. Section 7.4 tells reporting entities to refrain from permitting deposits or withdrawals of anonymity-enhancing crypto tokens. The instruction is addressed to service providers, not to holders.[9]
What does Dubai prohibit?
VARA prohibits the issuance of Anonymity-Enhanced Cryptocurrencies and all virtual asset activities related to them in the Emirate. The definition covers assets that prevent tracing and for which the provider has no mechanism to allow traceability.[10]
Are developers of privacy software money transmitters in the US?
FinCEN's 2019 guidance says a provider of anonymizing software is not a money transmitter. The question is still before a US court in the Tornado Cash prosecution, where a retrial on two counts is set for 26 April 2027.[5][12]
Sources
- FinCEN Announces Withdrawals of Proposed Digital Asset Related Rules, FinCEN, 5 October 2026.
- Proposal of Special Measure Regarding Convertible Virtual Currency Mixing; Withdrawal, Federal Register, 91 FR 63513, 6 October 2026.
- Requirements for Certain Transactions Involving Convertible Virtual Currency or Digital Assets; Withdrawal, Federal Register, 91 FR 63514, 6 October 2026.
- Proposal of Special Measure Regarding Convertible Virtual Currency Mixing, FinCEN, Federal Register, 88 FR 72701, 23 October 2023.
- FIN-2019-G001, Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies, FinCEN, 9 May 2019, section 4.5.
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, recital 160 and Articles 2(1)(25), 40, 79 and 90.
- Regulation (EU) 2023/1114 (MiCA), EUR-Lex, Articles 76(3), 143(3) and 149.
- Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, EUR-Lex, Articles 3(20), 14, 16 and 37.
- AML and CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets, Financial Intelligence Unit, India, updated 8 January 2026, sections 7.2 to 7.5 (scanned document).
- Virtual Assets and Related Activities Regulations 2023, Virtual Assets Regulatory Authority, Dubai, version dated 19 May 2025.
- RCMP executes record seizure of more than 56 million dollars in cryptocurrency, Royal Canadian Mounted Police, 18 September 2025.
- Order, United States v. Storm, 23 Cr. 430 (KPF), US District Court for the Southern District of New York, 10 September 2026 (copy on CourtListener).
- Founder Of Tornado Cash Crypto Mixing Service Convicted Of Knowingly Transmitting Criminal Proceeds, US Attorney's Office, Southern District of New York, 6 August 2025.
- Founders Of Samourai Wallet Cryptocurrency Mixing Service Sentenced To Five And Four Years In Prison, US Attorney's Office, Southern District of New York, 19 November 2025.
- Memorandum: Ending Regulation By Prosecution, US Department of Justice, Office of the Deputy Attorney General, 7 April 2025.
- Remarks at the American Innovation Project Summit, US Department of Justice, Criminal Division, 21 August 2025.
- FATF calls for closing of regulatory gaps as virtual asset illicit finance risks become more complex, Financial Action Task Force, 16 July 2026.
The United States stepped back from a new reporting rule this week, and the EU prohibition is nine months away. If you are building controls for both, start with wallet screening and the customer checks beside it.
Build your crypto controls before July
Set up transaction rules, wallet checks and identity verification.
Related articles
- Companies House identity verification: Insolvency Service convictions
- OSC Argosy decisions: KYC risk tolerance and a suspended UDP
- FinCEN verifiable digital credentials: mDLs under the CIP Rule
- Revolut data breach: the reported fake government request
- CIMA AML Rule: Cayman's audit filing duty explained
- e-Devlet for businesses: identity verification in Turkey