The landscape of digital finance in the United States stands at a pivotal juncture as federal regulators move to establish the first comprehensive framework for stablecoin oversight. In a detailed filing submitted to the Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC), Coin Center, a leading non-profit research and advocacy group, has warned that the implementation of the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act could either foster a new era of financial freedom or create an unprecedented system of total surveillance.
The filing serves as a formal response to the proposed rulemaking regarding Anti-Money Laundering (AML), Countering the Financing of Terrorism (CFT), and sanctions compliance for Permitted Payment Stablecoin Issuers (PPSIs). Coin Center’s central thesis argues that while regulated financial intermediaries must maintain lawful compliance programs, the unique nature of public blockchains requires a departure from legacy data collection methods that have increasingly become liabilities rather than assets for national security.
The Evolution of the GENIUS Act and Regulatory Context
The GENIUS Act represents the culmination of several years of legislative debate regarding the role of private dollar-pegged tokens in the American economy. Since the 2021 President’s Working Group Report on Stablecoins, policymakers have sought to bring issuers into the federal regulatory perimeter. The current rulemaking by FinCEN and OFAC is the practical application of these legislative goals, aiming to ensure that stablecoin issuers—entities that bridge the gap between traditional fiat and digital assets—do not become conduits for illicit finance.
However, the transition from traditional banking to blockchain-based payments introduces technical nuances that the current Bank Secrecy Act (BSA) framework was not designed to handle. Traditional banks maintain private ledgers where customer data is siloed. In contrast, stablecoins often move on public, permissionless networks like Ethereum or Bitcoin. This transparency, while beneficial for auditing, creates a "privacy-security paradox" where the collection of identity data by an issuer could inadvertently expose a user’s entire financial history to hackers, foreign adversaries, or government overreach.
The Risks of Data Overcollection and the "Honeypot" Effect
A significant portion of the Coin Center filing focuses on the operational risks inherent in current identity verification rituals. The advocacy group argues that the standard practice of collecting "static identifiers"—such as Social Security numbers, driver’s license scans, and biometric templates—has become an invitation for cybercrime.
Citing data from the Identity Theft Resource Center’s (ITRC) 2025 annual report, the filing notes a shift from mass identity theft to "pervasive identity fraud and scams." Criminals are increasingly prioritizing static identifiers because, unlike credit card numbers, they cannot be easily replaced. A 2024 study from the University of Brasília corroborated these findings, identifying financial institutions as the most frequently breached entities among publicly traded U.S. companies.
FinCEN’s own data supports the gravity of the situation. In 2021, the agency linked approximately $212 billion to identity-related suspicious activity. By 2023, that figure surged to $394 billion. Coin Center contends that the current system "mistakes examiner comfort for public safety," forcing institutions to build massive databases of sensitive information that become "honeypots" for malicious actors. When these databases are breached, the stolen information is used to bypass the very AML/CFT controls they were intended to satisfy, creating a self-perpetuating cycle of fraud and money laundering.
The Unique Vulnerability of Public Blockchains
For PPSIs, the risk of data breaches is compounded by the nature of blockchain technology. In the traditional financial system, a data breach might expose a customer’s name and account number. In the stablecoin context, a breach that links a real-world identity to a blockchain address creates a "bridge" to a persistent, public transaction graph.
This linkage can reveal intimate details about an individual’s life, including:
- Political and Religious Affiliations: Donations to specific causes or memberships in decentralized organizations.
- Counterparty History: A complete map of every person or business the individual has ever transacted with.
- Wealth and Balance: Real-time visibility into the user’s total holdings, which can lead to targeted physical threats, such as "wrench attacks" where criminals use violence to extort private keys.
Coin Center emphasizes that the federal government’s access to these identity-linked dossiers raises serious Fourth Amendment concerns. Drawing a parallel to the Supreme Court’s decision in Carpenter v. United States, which restricted warrantless access to cell-site location information, the filing argues that stablecoin users should not be deemed to have "voluntarily" exposed their entire financial life to the state simply by using a modern payment technology.
Recommendations for a Modern Compliance Framework
To mitigate these risks while maintaining the integrity of the financial system, Coin Center proposed five high-level courses of action for FinCEN and OFAC:
1. Recognize Overcollection as a Risk
Regulators should formally acknowledge that collecting too much information is as dangerous as collecting too little. AML/CFT programs should be evaluated not just on the volume of data they hold, but on their ability to minimize the risk of hacking and identity theft.
2. Permit Privacy-Preserving Digital Identity (PPDI)
The filing urges regulators to allow PPSIs to use innovative technologies such as zero-knowledge proofs, attribute-based proofs, and portable credentials. These tools allow a user to prove they meet a certain criteria (e.g., "I am over 18" or "I am not on a sanctions list") without revealing their underlying sensitive data to the issuer.
3. Create a Data-Minimized Onboarding Pilot
Coin Center suggests a "safe harbor" or pilot program for PPSIs that implement data-minimized onboarding. This would encourage the industry to move away from the "JPEG of a driver’s license" model toward more secure, cryptographically verified identity signals.
4. Clarify Secondary Market Obligations
A critical point of contention is whether stablecoin issuers should be responsible for monitoring peer-to-peer (P2P) transfers that occur on the secondary market. Coin Center argues that a PPSI should not have recordkeeping or "Travel Rule" obligations for transactions where they are not a direct intermediary. Imposing such a mandate would effectively turn private companies into "surveillance deputies" for the state.
5. Require Lawful Process for Asset Freezes
The filing calls for strong procedural safeguards before an issuer is compelled to freeze the assets of a U.S. person on the secondary market. Without a requirement for warrants or subpoenas, the power to freeze stablecoins could be used as a tool for political discrimination or extrajudicial punishment.
Chronology of Stablecoin Regulation in the United States
The current rulemaking is the latest chapter in a multi-year effort to define the legal status of digital dollars:
- June 2019: Facebook announces the Libra project, sparking global regulatory scrutiny of "global stablecoins."
- November 2021: The President’s Working Group on Financial Markets issues a report recommending that stablecoin issuers be limited to insured depository institutions.
- 2022-2023: Multiple legislative proposals, including the Lummis-Gillibrand Responsible Financial Innovation Act and the McHenry-Waters stablecoin bill, are introduced in Congress.
- 2024: The GENIUS Act is introduced, providing a framework for "Permitted Payment Stablecoin Issuers" and directing FinCEN/OFAC to establish AML/CFT rules.
- June 2025: FinCEN and OFAC release the Notice of Proposed Rulemaking (NPRM) for PPSI compliance, leading to the current public comment period.
Analysis of Broader Implications
The outcome of this rulemaking will likely set a global precedent. If the U.S. adopts a "surveillance-first" approach, it may drive innovation to jurisdictions with more robust privacy protections or push users toward non-compliant, decentralized alternatives that are harder for law enforcement to track. Conversely, if FinCEN and OFAC embrace privacy-preserving technologies, they could establish a new gold standard for digital identity that reduces fraud and enhances national security.
Industry reactions have been mixed. While major issuers like Circle and Paxos have generally supported clear regulatory guidelines to gain institutional trust, they have also voiced concerns regarding the technical feasibility of monitoring every P2P transaction. Privacy advocates and civil liberties groups have echoed Coin Center’s warnings, suggesting that the "identity-to-blockchain" map could be used by future administrations to target dissidents or marginalized communities.
Conclusion
The Coin Center filing concludes by emphasizing that the goal of AML/CFT policy should be the reduction of illicit finance, not the maximization of data collection. By distinguishing between "regulated relationships" and "generalized monitoring," FinCEN and OFAC have the opportunity to build a financial system that is both secure and compatible with American values of privacy and due process. As the comment period closes, the financial world awaits a final ruling that will determine whether the future of the digital dollar is one of empowerment or intrusion.



