Stablecoin Regulation: FDIC Announces New Proposed AML Rules For Issuers

bitcoinistPublicado a 2026-05-24Actualizado a 2026-05-24

Resumen

The FDIC has proposed new rules to extend Bank Secrecy Act (BSA) and economic sanctions compliance standards to FDIC-supervised Permitted Payment Stablecoin Issuers (PPSIs). This would formally classify PPSIs as financial institutions, requiring them to implement full Anti-Money Laundering/Countering the Financing of Terrorism (AML/CFT) programs, OFAC-aligned sanctions compliance structures, and related reporting obligations. The proposal follows earlier prudential standards for PPSIs. Supervision would involve FDIC coordination with FinCEN, with enforcement shielded for entities with effective programs unless significant failures occur. The public comment period lasts until June 9, 2026, with a final rule expected later that year. The FDIC estimates 5-30 PPSIs may seek approval initially, with compliance costs likely modest due to leveraging parent companies' existing infrastructure.

As crypto regulations continue to take shape in the US, the Federal Deposit Insurance Corporation (FDIC) has issued a notice of proposed rulemaking to extend Bank Secrecy Act (BSA) and economic sanctions compliance standards to FDIC-supervised Permitted Payment Stablecoin Issuers (PPSIs). The move aims to bring digital asset issuers further within the compliance architecture that has long governed traditional banking.

Major Highlights Of New FDIC Proposed Framework

According to a press release on Friday, the proposed rule by the FDIC mainly mandates PPSIs to comply with applicable Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) program requirements, economic sanctions programs, and reporting obligations, including those issued by the Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC).

This latest rulemaking follows an earlier FDIC proposal from April 2026, which established prudential standards for PPSIs covering reserve assets, redemption, capital, and risk management. Under the new parallel FinCEN-OFAC proposed rule, PPSIs would formally be classified as financial institutions under the BSA, requiring them to adopt full AML programs and OFAC-aligned sanctions compliance structures, including internal controls, a designated compliance officer, staff training, independent testing, customer identification, suspicious activity reporting, and on-chain transaction screening capabilities.

In terms of supervision and enforcement, the proposed rule would require the FDIC to notify the FinCEN director at least 30 days before initiating any formal enforcement action or significant supervisory determination related to a PPSI’s AML/CFT program. However, the FDIC signals that PPSIs with demonstrably effective AML/CFT programs would be shielded from enforcement action in most circumstances, except where there is a “significant or systemic failure” to implement required programs.

For context, PPSI refers to all entities authorized under the Guiding and Establishing National Innovation for US Stablecoins Act (GENIUS Act) to issue payment stablecoins as subsidiaries of insured State nonmember banks and State savings associations.

Looking Ahead

The public comment period on this proposed rule is expected to last until June 9, 2026, which would mark 60 days after its publication in the Federal Register. The final rule will be announced later in 2026, along with implementation details and deadlines. The FDIC estimates that between five and 30 FDIC-supervised PPSIs could seek approval in the first few years following enactment, and that most would leverage existing AML infrastructure from their parent institutions, keeping incremental compliance costs modest.

Total crypto market cap valued at $2.5 trillion on the daily chart | Source: TOTAL chart on Tradingview.com

Preguntas relacionadas

QWhat is the main purpose of the FDIC's new proposed rule for Permitted Payment Stablecoin Issuers (PPSIs)?

AThe main purpose of the proposed rule is to extend Bank Secrecy Act (BSA) and economic sanctions compliance standards to FDIC-supervised PPSIs, bringing digital asset issuers into the compliance framework that governs traditional banking.

QWhich two key regulatory bodies' requirements are PPSIs mandated to comply with under the FDIC's proposal?

AUnder the proposed rule, PPSIs are mandated to comply with requirements issued by the Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC).

QWhat specific AML/CFT program requirements would PPSIs need to adopt if classified as financial institutions under the BSA?

APPSIs would need to adopt full AML programs and OFAC-aligned sanctions compliance structures, including internal controls, a designated compliance officer, staff training, independent testing, customer identification, suspicious activity reporting, and on-chain transaction screening capabilities.

QIn what circumstance would a PPSI with an effective AML/CFT program still face enforcement action?

AA PPSI with a demonstrably effective AML/CFT program would still face enforcement action if there is a "significant or systemic failure" to implement the required programs.

QWhat is the deadline for the public to submit comments on this proposed rule, and by when is the final rule expected?

AThe public comment period is expected to last until June 9, 2026, and the final rule will be announced later in 2026, along with implementation details and deadlines.

Lecturas Relacionadas

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ruHace 28 min(s)

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ruHace 28 min(s)

Trading

Spot
活动图片