DeFi Protocols Under the Bank Secrecy Act: The Compliance Reckoning
By the Legal Cyber Academy editorial team ·
The Rule That Changed the Conversation
On October 19, 2023, the Financial Crimes Enforcement Network (FinCEN) issued a Notice of Proposed Rulemaking that would designate international convertible virtual currency mixing as a class of transactions of primary money laundering concern under Section 311 of the USA PATRIOT Act. Although the proposal targeted mixing services specifically, the legal reasoning it advanced — that software-based intermediaries can constitute "financial institutions" under the Bank Secrecy Act (BSA), 31 U.S.C. § 5312 — has direct implications for decentralized finance (DeFi) protocols operating in the United States.
As of 2026-09-03, that rulemaking has not been finalized, but FinCEN has not withdrawn it either. Compliance teams and general counsel at firms that interact with DeFi — whether as investors, liquidity providers, or platform operators — should treat the underlying legal theory as live.
What the BSA Actually Requires
The BSA and its implementing regulations at 31 C.F.R. Chapter X impose a layered set of obligations on "money services businesses" (MSBs), including money transmitters. FinCEN's longstanding guidance, most recently synthesized in its May 2019 guidance on convertible virtual currencies, makes clear that the economic function of a business — not its technical architecture — determines whether it is an MSB.
The core obligations for a registered MSB include:
- Registration with FinCEN under 31 C.F.R. § 1022.380
- Anti-money laundering (AML) program requirements under 31 C.F.R. § 1022.210
- Suspicious Activity Reports (SARs) under 31 C.F.R. § 1022.320
- Currency Transaction Reports (CTRs) for transactions over $10,000
- Customer identification consistent with applicable Customer Due Diligence (CDD) rules
The unresolved question for DeFi is whether a protocol — a set of smart contracts running autonomously on a blockchain, with no central operator — can be a "money transmitter" at all, and if so, who bears the obligation.
The Operator vs. Protocol Distinction
FinCEN's 2019 guidance distinguishes between software developers who create tools and those who use or deploy them to transmit value on behalf of others. Under that framing, a developer who merely writes and publishes code is less likely to be an MSB than an entity that operates infrastructure and exercises control over how value moves.
This distinction is harder to apply in practice than it sounds. DeFi protocols are not always fully autonomous. Many involve:
- Administrative keys that can pause contracts, upgrade logic, or set fee parameters
- Governance token holders who vote on protocol changes
- Frontend operators who control the website or application through which users actually interact with the underlying contracts
- Liquidity providers who deposit assets and earn fees
FinCEN has not issued guidance that maps these roles cleanly onto BSA definitions as of 2026-09-03. But the Department of Justice's prosecution of Tornado Cash developers — Roman Storm was indicted in the Southern District of New York in August 2023 on charges including conspiracy to commit money laundering and operation of an unlicensed money transmitting business — demonstrates that federal prosecutors are willing to reach the human beings behind ostensibly decentralized software.
The charges against Storm are pending as of 2026-09-03; no conviction has been entered. The indictment is not legal precedent. But it is a clear signal about prosecutorial theory.
Where OFAC Fits In
The Office of Foreign Assets Control (OFAC) added Tornado Cash smart contract addresses to the Specially Designated Nationals (SDN) list in August 2022 under 31 C.F.R. Parts 500–598. The U.S. Court of Appeals for the Fifth Circuit, in Van Loon v. Department of the Treasury, No. 23-50669 (5th Cir. 2024), held that OFAC exceeded its statutory authority under the International Emergency Economic Powers Act (IEEPA) by sanctioning immutable smart contracts that the court characterized as property rather than persons. The Sixth Circuit reached a different result on related facts.
The circuit split matters because it leaves the law unsettled as of 2026-09-03. Compliance professionals cannot simply point to Van Loon and conclude that sanctioning immutable code is categorically off the table. OFAC retains authority over persons, and mutable contracts or protocol operators may face different analysis.
Practical Pressure Points for Compliance Leaders
Know Your Touchpoints
Before assessing BSA exposure, map every point at which your organization touches a DeFi protocol. This includes direct investment, custody of LP tokens, treasury management through automated market makers, and any platform function that routes user funds through protocol contracts. Each touchpoint carries a different risk profile.
Governance Rights Are Not Passive
Holding governance tokens and voting on proposals is not the same as holding a passive equity stake. If a governance vote sets parameters that affect how the protocol processes user funds, counsel should analyze whether that level of control could support a theory of operational involvement under the BSA's "control or direction" language.
Frontend Operators Bear Real Risk
If your organization runs a website that serves as the primary user interface for a DeFi protocol, you are not merely a software company. You decide what wallets to geoblock, whether to display compliance warnings, and which pools to surface. FinCEN and DOJ have focused on frontend operators precisely because they exercise discretion that fully autonomous code would not.
Document Your Legal Analysis Now
In an enforcement action, a well-documented, contemporaneous legal memorandum analyzing BSA applicability — even one that concludes no registration is required — is materially different from the absence of any analysis. Document the reasoning, date it, and revisit it when FinCEN guidance or case law changes.
For compliance and legal teams building that analytical foundation, the Risky Business: Cryptocurrency, Money Laundering, and Smart Contracts course at Legal Cyber Academy covers the BSA, AML obligations, and smart contract mechanics in plain terms built for legal and compliance professionals.
If your team is also assessing how token issuance interacts with these questions, Introduction to Utility Tokens and Initial Coin Offerings provides grounding in the regulatory classifications that affect whether a token triggers securities or MSB analysis — or both.
The Questions That Do Not Have Clean Answers Yet
As of 2026-09-03, three questions remain genuinely open:
- Can a DAO itself be an MSB? FinCEN has not addressed DAOs directly in formal guidance.
- Does holding governance tokens without voting trigger any obligation? No agency or court has said.
- How will the Fifth and Sixth Circuit split on OFAC's smart-contract authority be resolved? No cert petition outcome has been issued as of this writing.
The absence of clear answers is not comfort. Enforcement — both criminal and civil — has moved faster than rulemaking. Organizations that wait for final rules before building AML controls around DeFi activity are making a deliberate risk choice, not a legally safe one.
Go deeper — courses on this
Blockchain LawPremiumRisky Business: Cryptocurrency, Money Laundering, and Smart Contracts
This two-part course covers how cryptocurrency is used for money laundering, including its three stages…
Blockchain LawIntroduction to Utility Tokens and Initial Coin Offerings
This seminar provides business, legal, and technical professionals with a practical overview of utility…
Blockchain LawOn the Money: Central Bank Digital Currency Explained
This seminar introduces central bank digital currencies (CBDCs) to a broad professional audience…
Daniel B. Garrie · 1h 4m
Keep reading
- SEC Cybersecurity Disclosure Rules: What You Need to KnowThe SEC's cybersecurity disclosure rules create new legal obligations for public companies. Here's what practicing lawyers need to understan…
- Stablecoin Regulation in 2026: The Compliance Fault LinesThe GENIUS Act signed in 2026 created the first federal stablecoin framework. Here is what compliance officers and counsel need to act on no…
- GDPR Fines for AI Training Data: The Enforcement Gap Closing FastEuropean regulators are targeting how companies collect and use personal data to train AI models. Here is what that means for your complianc…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.