Treasury’s GENIUS Act Report Backs Mixers, But Wants a New ‘Hold Law’ For Crypto

bitcoinistОпубликовано 2026-03-09Обновлено 2026-03-09

Введение

The U.S. Treasury's GENIUS Act report acknowledges the legitimate privacy benefits of cryptocurrency mixers for lawful users, such as protecting personal or business transactions. However, it highlights the misuse of these tools by illicit actors like North Korean cyber units and ransomware groups to launder funds. To address this, the report proposes a new "digital-asset-specific hold law" that would allow regulated platforms to temporarily freeze suspicious transactions, giving law enforcement time to act without disrupting legitimate privacy-focused usage. The report is part of a broader effort to balance financial innovation and security under the GENIUS Act framework.

Treasury sent Congress its GENIUS‐Act‐mandated report on “innovative tools” to fight crypto‐enabled illicit finance.

A Crypto’s “Hold Law” And A Privacy Paradox

In a 32-page report submitted to the US Congress this March, the U.S. Treasury Department has endorsed lawful uses of crypto mixers (a service that takes in cryptocurrency from many different users, mixes all those coins together, and then sends each user back an equivalent amount from the pool, but from different addresses than the ones they used to deposit) in favor of privacy.

However, it has also urged lawmakers to create a new “digital‐asset‐specific hold law” so platforms can freeze suspicious funds.

Mixers, Privacy And DPRK

The report notes favorably that mixing and similar tools “can be used by lawful users seeking to enhance financial privacy on public blockchains,” including for “protecting sensitive information about personal wealth, business transactions, or charitable donations from public view. It adds that Treasury “recognizes that privacy‐enhancing technologies, including mixers and other obfuscation tools, may serve legitimate purposes when used by compliant actors in line with applicable AML/CFT requirements.”

On the other side, the same report also stresses that North Korea’s cyber units and major ransomware crews rely on mixers, cross‐chain bridges, and rapid swaps as core infrastructure to launder massive hauls from hacks and fraud. The report cites billions of dollars in stolen digital assets tied to DPRK actors and details how those funds are pushed through mixers and into stablecoins before being bridged and cashed out, using the same tools that ordinary users might pick for privacy.

What The “Hold Law” Would Do

Therefore, to tackle this paradox, the report proposes a “hold law” that would ensure that legitimate, clean, users keep their privacy while unlawful or suspicious activity can be addressed. Under the proposal, crypto exchanges and other regulated platforms would gain a clear and legal “pause button” for suspicious funds. The report recommends that “Congress establish a digital‐asset‐specific statutory ‘hold’ authority” that would allow platforms “to temporarily retain or delay the movement of digital assets associated with suspected illicit activity while appropriate legal process is pursued.” Firms could temporarily hold or delay those assets when strong red flags appear, with statutory cover for doing so.

The idea would be to give law enforcement time to act against ransomware crews, large fraud schemes, or state‐sponsored hackers, while limiting the tool to narrowly defined, high‐risk cases so routine customer flows are not frozen by default.

TradFi and Legacy media have often linked mixers to money laundering, with Tornado Cash as the obvious cautionary tale. Ethereum co‐founder Vitalik Buterin has repeatedly argued that mixers are neutral tools, even saying he used Tornado Cash to make a private donation to Ukraine, and is now backing ‘compliant’ designs like Privacy Pools that aim to protect on‐chain privacy without commingling with known dirty funds.

Another Piece On The GENIUS Act Puzzle

The report is part of the broader GENIUS Act framework, the law Trump signed to create a federal regime for payment stablecoins and push “innovative” tools against illicit finance. It fulfills a mandate for Treasury to spell out how AI, digital identity, and blockchain analytics should be used under a risk‐based AML approach.

The report also proposes a preferred tech stack (AI, digital ID, blockchain analytics, APIs) that regulated platforms should deploy under a risk‐based AML approach.

BTC's price trends to the downside on the daily chart. Source: BTCUSD on Tradingview

Cover image from ChatGPT, BTCUSD chart from Tradingview

Связанные с этим вопросы

QWhat is the main purpose of the GENIUS Act report submitted by the U.S. Treasury Department?

AThe GENIUS Act report outlines 'innovative tools' to fight crypto-enabled illicit finance, endorsing lawful uses of crypto mixers for privacy while proposing a new 'hold law' to freeze suspicious funds.

QHow does the report view the use of crypto mixers by lawful users?

AThe report recognizes that mixers and other privacy-enhancing technologies can serve legitimate purposes for lawful users seeking financial privacy, such as protecting sensitive information about personal wealth or business transactions, when used in compliance with AML/CFT requirements.

QWhat specific legislative measure does the Treasury Department recommend to address suspicious crypto transactions?

AThe Treasury Department recommends that Congress establish a digital-asset-specific statutory 'hold' authority, allowing platforms to temporarily retain or delay the movement of digital assets associated with suspected illicit activity while legal process is pursued.

QAccording to the report, how do malicious actors like North Korea's cyber units utilize crypto mixers?

ANorth Korea's cyber units and ransomware crews use mixers, cross-chain bridges, and rapid swaps as core infrastructure to launder massive amounts of stolen digital assets, often pushing funds through mixers into stablecoins before cashing out.

QWhat broader framework is this report a part of, and what additional tools does it propose for regulated platforms?

AThe report is part of the GENIUS Act framework, which aims to create a federal regime for payment stablecoins and combat illicit finance. It proposes a tech stack including AI, digital identity, blockchain analytics, and APIs for regulated platforms under a risk-based AML approach.

Похожее

Claude Opus 4.8 Finds a $4.5 Billion Bug: The AI Era is Mass-Producing Hackers

A researcher discovered a critical "infinite mint" vulnerability in the Zcash cryptocurrency's Orchard protocol using Claude Opus 4.8, leading to a swift fix but also a 50% market drop, erasing billions in value. This incident highlights a new era where powerful, accessible AI models are dramatically lowering the barrier to finding software vulnerabilities. Previously, the security community feared specialized models like Claude Mythos Preview, capable of finding decades-old zero-day exploits. The Zcash case, however, involved a publicly available, general-purpose model. This shift makes advanced security auditing—and attack capabilities—accessible to far more people, not just experts. The mass democratization of vulnerability discovery brings a dual challenge: a flood of low-quality, AI-generated false reports that overwhelm maintainers, and the real, rapid uncovering of deep, dangerous bugs. Open-source projects, often understaffed and unfunded, are particularly vulnerable to this "attention DDoS." The article cites examples like curl shutting down its bug bounty program due to the unsustainable workload. Our perceived digital safety has often been luck, relying on the high cost and effort required to find deeply hidden flaws in complex systems, as seen with historical vulnerabilities like Heartbleed or Baron Samedit. AI changes this cost structure, effectively "mass-producing flashlights" to illuminate every corner of our codebase. While large companies operate extensive security chains involving external white-hat hackers and massive defensive operations, the global cybersecurity workforce faces a severe shortage, especially of experienced personnel capable of analyzing complex threats and coordinating fixes. The core dilemma emerges: AI makes *finding* bugs cheap and scalable, but *fixing* them remains a slow, expensive, and human-intensive process. The article concludes that AI won't destroy the internet but acts as a bright light, revealing that our digital existence is not inherently secure but is precariously maintained by ongoing human effort. The true cost in the AI era may not be discovery, but whether there will be enough people left willing and able to do the hard work of repair.

marsbit5 мин. назад

Claude Opus 4.8 Finds a $4.5 Billion Bug: The AI Era is Mass-Producing Hackers

marsbit5 мин. назад

Codex Goal Mode Usage Guide: How to Make AI Continuously Pursue a Specific Objective

"Codex Goal Mode: How to Make AI Work Continuously Toward a Specific Goal" OpenAI's Codex "goal mode" (/goal) transforms the AI from a reactive code assistant into a proactive execution agent capable of working autonomously for hours or even days to achieve a defined objective. To maximize its effectiveness, follow these key principles: 1. **Define Clear, Verifiable Exit Criteria:** The goal prompt should be a concise, measurable success condition, not a lengthy specification. Use quantifiable metrics like "reduce build time by 30%" or "achieve 100% test parity." 2. **Provide Initial Guidance and Tools:** Direct Codex toward likely problem areas and specify available tools (e.g., browsers, testing environments) to prevent it from exploring unproductive paths. 3. **Enable Progress Measurement:** Equip Codex with ways to track advancement, such as creating comparison tools for visual tasks or evaluation sets, ensuring it can gauge its own progress. 4. **Use a Realistic Execution Environment:** For tasks like performance optimization, provide access to environments that closely mimic production (e.g., similar configs, databases) to yield valid results. 5. **Be Cautious with Visual Goals:** Avoid vague "pixel-perfect" instructions. Instead, supplement visual references with functional checklists or design system specifications to prevent Codex from obsessing over minor details. 6. **Implement Progress Tracking:** For long-running tasks, have Codex commit code to draft PRs, update progress documents, or send Slack updates to maintain visibility into its work. 7. **Review and Consolidate Results:** Once the goal is met, instruct Codex to review its work, clean up ineffective experimental code, and reflect on what strategies succeeded or failed. Ultimately, using goal mode shifts the developer's role from writing prompts to managing a persistent engineering agent—defining objectives, establishing metrics, configuring environments, and conducting final reviews.

marsbit1 ч. назад

Codex Goal Mode Usage Guide: How to Make AI Continuously Pursue a Specific Objective

marsbit1 ч. назад

From Ethereum to AI's 'CROPS': What Exactly Is This 'Slow Variable' That Vitalik Has Repeatedly Emphasized?

Recently, Vitalik Buterin has frequently emphasized the concept of "CROPS," first outlined in the Ethereum Foundation's March mandate as core principles guiding its focus: Censorship Resistance, Capture Resistance, Open Source, Privacy, and Security. CROPS represents Ethereum's commitment to providing foundational capabilities for user sovereignty—enabling asset ownership, identity expression, and coordination without reliance on centralized platforms or surrendering ultimate control. This framework is gaining new urgency with the rise of AI, particularly AI agents managing digital assets and automating transactions. While AI offers convenience, it risks centralizing user data, intent, and control if dependent on opaque, centralized services. Vitalik argues for "CROPS AI"—AI that is open, privacy-preserving, secure, and capable of local execution to maintain user agency. He highlights convergence between "CROPS Ethereum access layers" and "CROPS AI," such as using zero-knowledge proofs for private remote LLM calls and Ethereum RPC reads, ensuring users can access services without exposing sensitive information. Ultimately, CROPS is not just an abstract ideal but a practical guide for Ethereum's development and AI integration. It addresses the critical long-term question: as digital systems grow more powerful, how can users retain control over their privacy, assets, and autonomy? In an AI-driven era, these principles may define Ethereum's enduring value—prioritizing verifiable, secure, and user-centric design over short-term optimizations like speed and cost alone.

marsbit1 ч. назад

From Ethereum to AI's 'CROPS': What Exactly Is This 'Slow Variable' That Vitalik Has Repeatedly Emphasized?

marsbit1 ч. назад

Торговля

Спот
Фьючерсы
活动图片