Legal Cyber Academy
All insights

DeFi Protocols Under the Bank Secrecy Act: The Compliance Reckoning

By the Legal Cyber Academy editorial team ·

The Rule That Changed the Conversation

On October 19, 2023, the Financial Crimes Enforcement Network (FinCEN) issued a Notice of Proposed Rulemaking that would designate international convertible virtual currency mixing as a class of transactions of primary money laundering concern under Section 311 of the USA PATRIOT Act. Although the proposal targeted mixing services specifically, the legal reasoning it advanced — that software-based intermediaries can constitute "financial institutions" under the Bank Secrecy Act (BSA), 31 U.S.C. § 5312 — has direct implications for decentralized finance (DeFi) protocols operating in the United States.

As of 2026-09-03, that rulemaking has not been finalized, but FinCEN has not withdrawn it either. Compliance teams and general counsel at firms that interact with DeFi — whether as investors, liquidity providers, or platform operators — should treat the underlying legal theory as live.

What the BSA Actually Requires

The BSA and its implementing regulations at 31 C.F.R. Chapter X impose a layered set of obligations on "money services businesses" (MSBs), including money transmitters. FinCEN's longstanding guidance, most recently synthesized in its May 2019 guidance on convertible virtual currencies, makes clear that the economic function of a business — not its technical architecture — determines whether it is an MSB.

The core obligations for a registered MSB include:

  • Registration with FinCEN under 31 C.F.R. § 1022.380
  • Anti-money laundering (AML) program requirements under 31 C.F.R. § 1022.210
  • Suspicious Activity Reports (SARs) under 31 C.F.R. § 1022.320
  • Currency Transaction Reports (CTRs) for transactions over $10,000
  • Customer identification consistent with applicable Customer Due Diligence (CDD) rules

The unresolved question for DeFi is whether a protocol — a set of smart contracts running autonomously on a blockchain, with no central operator — can be a "money transmitter" at all, and if so, who bears the obligation.

The Operator vs. Protocol Distinction

FinCEN's 2019 guidance distinguishes between software developers who create tools and those who use or deploy them to transmit value on behalf of others. Under that framing, a developer who merely writes and publishes code is less likely to be an MSB than an entity that operates infrastructure and exercises control over how value moves.

This distinction is harder to apply in practice than it sounds. DeFi protocols are not always fully autonomous. Many involve:

  • Administrative keys that can pause contracts, upgrade logic, or set fee parameters
  • Governance token holders who vote on protocol changes
  • Frontend operators who control the website or application through which users actually interact with the underlying contracts
  • Liquidity providers who deposit assets and earn fees

FinCEN has not issued guidance that maps these roles cleanly onto BSA definitions as of 2026-09-03. But the Department of Justice's prosecution of Tornado Cash developers — Roman Storm was indicted in the Southern District of New York in August 2023 on charges including conspiracy to commit money laundering and operation of an unlicensed money transmitting business — demonstrates that federal prosecutors are willing to reach the human beings behind ostensibly decentralized software.

The charges against Storm are pending as of 2026-09-03; no conviction has been entered. The indictment is not legal precedent. But it is a clear signal about prosecutorial theory.

Where OFAC Fits In

The Office of Foreign Assets Control (OFAC) added Tornado Cash smart contract addresses to the Specially Designated Nationals (SDN) list in August 2022 under 31 C.F.R. Parts 500–598. The U.S. Court of Appeals for the Fifth Circuit, in Van Loon v. Department of the Treasury, No. 23-50669 (5th Cir. 2024), held that OFAC exceeded its statutory authority under the International Emergency Economic Powers Act (IEEPA) by sanctioning immutable smart contracts that the court characterized as property rather than persons. The Sixth Circuit reached a different result on related facts.

The circuit split matters because it leaves the law unsettled as of 2026-09-03. Compliance professionals cannot simply point to Van Loon and conclude that sanctioning immutable code is categorically off the table. OFAC retains authority over persons, and mutable contracts or protocol operators may face different analysis.

Practical Pressure Points for Compliance Leaders

Know Your Touchpoints

Before assessing BSA exposure, map every point at which your organization touches a DeFi protocol. This includes direct investment, custody of LP tokens, treasury management through automated market makers, and any platform function that routes user funds through protocol contracts. Each touchpoint carries a different risk profile.

Governance Rights Are Not Passive

Holding governance tokens and voting on proposals is not the same as holding a passive equity stake. If a governance vote sets parameters that affect how the protocol processes user funds, counsel should analyze whether that level of control could support a theory of operational involvement under the BSA's "control or direction" language.

Frontend Operators Bear Real Risk

If your organization runs a website that serves as the primary user interface for a DeFi protocol, you are not merely a software company. You decide what wallets to geoblock, whether to display compliance warnings, and which pools to surface. FinCEN and DOJ have focused on frontend operators precisely because they exercise discretion that fully autonomous code would not.

Document Your Legal Analysis Now

In an enforcement action, a well-documented, contemporaneous legal memorandum analyzing BSA applicability — even one that concludes no registration is required — is materially different from the absence of any analysis. Document the reasoning, date it, and revisit it when FinCEN guidance or case law changes.

For compliance and legal teams building that analytical foundation, the Risky Business: Cryptocurrency, Money Laundering, and Smart Contracts course at Legal Cyber Academy covers the BSA, AML obligations, and smart contract mechanics in plain terms built for legal and compliance professionals.

If your team is also assessing how token issuance interacts with these questions, Introduction to Utility Tokens and Initial Coin Offerings provides grounding in the regulatory classifications that affect whether a token triggers securities or MSB analysis — or both.

The Questions That Do Not Have Clean Answers Yet

As of 2026-09-03, three questions remain genuinely open:

  1. Can a DAO itself be an MSB? FinCEN has not addressed DAOs directly in formal guidance.
  2. Does holding governance tokens without voting trigger any obligation? No agency or court has said.
  3. How will the Fifth and Sixth Circuit split on OFAC's smart-contract authority be resolved? No cert petition outcome has been issued as of this writing.

The absence of clear answers is not comfort. Enforcement — both criminal and civil — has moved faster than rulemaking. Organizations that wait for final rules before building AML controls around DeFi activity are making a deliberate risk choice, not a legally safe one.

Go deeper — courses on this

Keep reading

Get the next one by email

Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.