2026-06-03

Older

United States Web3 Security Tools & Vulnerabilities

The United States has no single federal crypto regulatory framework, but multiple agencies (SEC, CFTC, FinCEN) assert jurisdiction over digital assets. Licensing for crypto businesses is state-level,…

RESEARCH: United States Web3 Security Tools & Vulnerabilities

Executive Summary

The United States has no single federal crypto regulatory framework, but multiple agencies (SEC, CFTC, FinCEN) assert jurisdiction over digital assets. Licensing for crypto businesses is state-level, requiring Money Transmitter Licenses (MTLs) in 40+ states, with no federal license available. Practical reality is fragmented: some firms obtain state licenses (e.g., Coinbase, Gemini), while others operate offshore or face SEC enforcement. The regulatory landscape is dominated by enforcement actions rather than clear rules, creating high compliance risk for web3 firms.

Regulatory Framework

  • Regulatory bodies: SEC (Securities and Exchange Commission, sec.gov), CFTC (Commodity Futures Trading Commission, cftc.gov), FinCEN (Financial Crimes Enforcement Network, fincen.gov), IRS (Internal Revenue Service, irs.gov)
  • Primary laws: Bank Secrecy Act (BSA, 1970, amended 2021 for digital assets), Securities Act of 1933 (applied to ICOs via SEC v. Telegram), Commodity Exchange Act (CEA, applied to crypto derivatives)
  • International standing: FATF member (United States implements FATF Recommendations through FinCEN); Moneyval not applicable (U.S. is not a Council of Europe member)
  • State-level: New York BitLicense (23 NYCRR Part 200, effective 2015), California Digital Financial Assets Law (effective 2025)

Licensing Requirements

  • Who needs a license: Any business engaged in "money transmission" (including crypto exchanges, custodians, kiosk operators) under state MTL laws; New York requires BitLicense for virtual currency business activity
  • Activities requiring licensing: Custody, exchange, transfer, issuance of virtual currencies; trading platforms, DeFi front-ends (if they control funds), and OTC desks
  • Capital requirements: Varies by state — typically $25,000–$500,000 USD; New York BitLicense requires $100,000–$500,000 USD minimum capital depending on activity
  • Application process: Submit to state financial regulator (e.g., NYDFS for BitLicense), including business plan, AML program, cybersecurity policies, background checks, audited financials
  • Timeline: 12–24 months for multi-state MTL licensing; BitLicense averages 18–24 months
  • Structural requirements: Must be registered with FinCEN as MSB, maintain surety bond (varies by state), appoint registered agent in each state
  • Reality: Zero federal crypto license exists. Over 40 entities hold BitLicenses (including Coinbase, Gemini, BitPay, Ripple). Many small firms cannot obtain licenses due to cost/complexity.

AML/KYC Requirements

  • CDD & EDD: FinCEN requires crypto exchanges (MSBs) to implement Customer Due Diligence (CDD) for all accounts; Enhanced Due Diligence (EDD) for high-risk customers, including PEPs and high-volume traders (31 CFR § 1022.210)
  • STR reporting: Suspicious Activity Reports (SARs) required for transactions over $2,000 if suspicious; Currency Transaction Reports (CTRs) for cash transactions over $10,000 (31 CFR § 1010.311)
  • Record retention: Maintain records for 5 years (31 CFR § 1010.430), including transaction logs, identification records, and SAR filings
  • Beneficial ownership: Required for legal entity customers (identity of any individual owning 25%+ or controlling the entity) under CDD Rule (31 CFR § 1010.230)
  • PEP screening: Not explicitly mandated by U.S. federal law, but FinCEN guidance and OCC advisories recommend screening Politically Exposed Persons as part of risk-based AML program
  • Travel Rule: FinCEN requires transmission of originator and beneficiary information (name, address, account number) for transactions over $3,000 (31 CFR § 1010.410(f))

Enforcement Actions

  • SEC v. Coinbase (2023): SEC sued Coinbase for operating as unregistered exchange, broker, and clearing agency; case pending (SDNY)
  • CFTC v. Binance (2023): CFTC charged Binance and CEO Changpeng Zhao with willful evasion of U.S. law, including failure to register; settled for $2.85 billion penalty (2024)
  • FinCEN v. BitMEX (2021): FinCEN fined BitMEX $100 million for willful violation of BSA/AML requirements (no crypto license, no AML program)
  • SEC v. Ripple (2020–2023): SEC alleged XRP was unregistered security; partial win for Ripple (programmatic sales not securities), $125 million penalty (August 2024)
  • NYDFS v. Robinhood Crypto (2024): NYDFS fined Robinhood Crypto $30 million for violations of BSA/AML and cybersecurity rules (August 2024)

Tax Treatment

  • General guidance: IRS treats cryptocurrency as property (IRS Notice 2014-21); gains taxed under capital gains rules (short-term >1 year = ordinary income rates; long-term = 0–20%)
  • Income tax: Mining income, staking rewards, airdrops, and payment received in crypto are taxable as ordinary income at fair market value upon receipt (IRS Revenue Ruling 2019-24)
  • Capital gains: Disposal of crypto (sale, trade, payment) triggers capital gains tax on difference between cost basis and fair market value at disposition
  • VAT: No federal VAT; state sales tax treatment varies (some states exempt crypto transfers, others treat as taxable property)
  • Reporting: Form 8949 and Schedule D required for capital transactions; Form 1040 includes checkbox for crypto activity (since 2020); Foreign Account Tax Compliance Act (FATCA) may apply for overseas holdings >$10,000
  • No tax guidance: Has not issued specific guidance for DeFi lending, NFT royalties, or DAO token distributions (guidance expected under IRS Virtual Currency Guidance initiative)

Key Gaps & Risks

  • No federal statute: No comprehensive federal law governing crypto; SEC vs. CFTC jurisdiction dispute unresolved; DeFi and DAOs operate in regulatory gray zone
  • State-by-state licensing: Businesses must obtain MTLs in 40+ states individually, costing $500k+ annually in legal/compliance fees; impossible for smaller startups
  • Enforcement-first regulation: Agencies rely on enforcement actions (SEC issued 30+ crypto enforcement actions in 2024) rather than rulemaking, creating retroactive liability risk
  • Travel Rule compliance gap: FinCEN Travel Rule requires originator/beneficiary data for crypto transactions, but technical solutions (e.g., TRISA, OpenVASP) not widely adopted; many transactions non-compliant
  • DeFi/DAOs unregulated: No clear regulatory framework for decentralized exchanges, lending protocols, or DAOs; SEC has sued Uniswap Labs and others for operating unregistered exchanges
  • Stablecoin regulation incomplete: No federal stablecoin law passed yet (Lummis-Gillibrand Payment Stablecoin Act and Clarity for Payment Stablecoins Act introduced in 2023, both stalled)

Sources