The intersection of cryptocurrency policy and federal oversight has reached a critical juncture as the Financial Crimes Enforcement Network (FinCEN) and other federal agencies, including the Office of the Comptroller of the Currency (OCC), the Federal Reserve, the FDIC, and the National Credit Union Administration (NCUA), evaluate the implementation of the GENIUS Act. This legislation mandates that Permitted Payment Stablecoin Issuers (PPSIs) maintain effective Customer Identification Programs (CIP). In a formal comment letter to these agencies, the nonprofit advocacy group Coin Center has proposed a significant departure from traditional "know-your-customer" (KYC) protocols, arguing that current methods of data collection are not only antiquated but pose systemic risks to both financial institutions and the public.
Background and Legislative Context
The GENIUS Act represents a comprehensive attempt by U.S. regulators to establish a formal framework for stablecoin issuers. As the digital asset market matures, the integration of stablecoins—cryptocurrencies pegged to the value of a fiat currency like the U.S. dollar—into the broader financial system has necessitated clearer compliance guidelines. Traditionally, financial institutions have operated under a "collect and retain" model, where they gather extensive personally identifiable information (PII) to satisfy Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT) requirements.
Coin Center’s intervention comes at a time when the frequency and scale of data breaches involving sensitive financial information are at an all-time high. The organization contends that the federal government’s reliance on centralized databases creates "honeypots" for malicious actors, foreign adversaries, and cybercriminals. By mandating that PPSIs follow the same rigid identification standards as legacy banks, regulators risk replicating the vulnerabilities of the traditional financial sector within the burgeoning blockchain ecosystem.
The Case for User-Controlled Digital Identity (UCDI)
Coin Center’s proposal advocates for the adoption of User-Controlled Digital Identity (UCDI) solutions. This framework relies on four primary technological pillars: Verifiable Digital Credentials (VDCs), Zero-Knowledge Proofs (ZKPs), Multi-Party Computation (MPC), and open, decentralized blockchain networks.
The shift proposed by the organization is fundamentally structural. Rather than requiring an issuer to hold a static dossier of a customer’s life, UCDI allows a user to present cryptographically signed documents—such as a proof of age, citizenship, or account status—without revealing the underlying personal information. ZKPs enable a user to mathematically prove they meet a regulatory requirement (such as "not appearing on a sanctions list") without disclosing the sensitive data that would otherwise be stored in a centralized database.
This approach addresses a long-standing inefficiency in the current regulatory environment. Research indicates that U.S. financial institutions spend approximately $26 billion annually on AML and sanctions compliance, yet global law enforcement agencies struggle to intercept more than 0.2 percent of criminal proceeds. Coin Center argues that this low success rate, combined with the high cost and high risk of data exposure, justifies a pivot toward privacy-preserving technology.
Chronology of Regulatory Engagement
The current debate is the result of a multi-year dialogue between the cryptocurrency sector and federal regulators.
- October 2025: Coin Center submitted a response to the Treasury Department’s request for comment on innovative methods to detect illicit activity involving digital assets. This document introduced the "John Hancock Project," outlining the initial vision for portable, user-controlled credentials.
- June 2026: In response to a formal request from FinCEN and OFAC regarding AML/CFT programs for PPSIs, Coin Center expanded its argument to emphasize how traditional KYC requirements can be exploited by illicit actors through identity theft and credential compromise.
- September 2026: The current comment period regarding the GENIUS Act’s CIP requirements serves as the most recent formal step, where the organization has synthesized its previous research into actionable recommendations for the final rule.
Addressing the Secondary Market and Contractual Relationships
A central point of contention in the proposed rulemaking is the definition of an "account" and the scope of CIP requirements. The agencies have debated whether these obligations should extend to secondary market transactions—interactions where the PPSI is not a direct participant.
Coin Center strongly opposes the application of CIP requirements to the secondary market. The organization argues that forcing issuers to monitor every downstream transaction would lead to unprecedented levels of blockchain surveillance. From a legal standpoint, they cite the Supreme Court’s decision in Carpenter v. United States, which cautioned against the over-collection of digital records that could reveal an individual’s private associations, political beliefs, and daily habits.
To mitigate this, Coin Center proposes replacing the term "formal relationship" with "contractual relationship" in the definition of an account. By legally defining the scope of an account through clear, enforceable contract law—requiring mutual assent, consideration, and capacity—the agencies could create a definitive boundary between direct customers and secondary market participants. This distinction would protect users from unnecessary surveillance while ensuring that the primary issuer remains responsible for vetting its direct clients.
Redemption-Only Transactions
Another critical area identified by Coin Center is the "redemption-only" scenario. In many cases, a user may interact with a PPSI solely to redeem a stablecoin for fiat currency. The organization argues that requiring a full identity onboarding process for a single, isolated transaction is excessive and risky. Instead, they suggest that regulators should allow PPSIs to utilize privacy-preserving proofs to verify only the necessary facts—such as whether the user is on a sanctions list—without requiring the collection of a full identity dossier.
Broader Implications and Economic Analysis
The implications of this regulatory shift extend beyond privacy; they touch on the competitive landscape of the U.S. financial sector. If the United States adopts a regulatory framework that encourages privacy-preserving, decentralized identification, it could position American firms at the forefront of global financial technology. Conversely, if the final rule mandates the mass collection of sensitive data, it may incentivize innovation to migrate to jurisdictions with more flexible or privacy-centric regulatory environments.
Furthermore, the "honeypot" risk remains a significant concern for national security. As state-sponsored actors become increasingly sophisticated, the centralization of identity data poses a risk not just to the privacy of individual stablecoin holders, but to the integrity of the broader financial system. The use of VDCs and MPC could potentially de-risk this environment by eliminating the need for institutions to store massive, immutable datasets of PII.
Conclusion and Official Stance
The comment letter, authored by Coin Center Research Director Lizandro Pieper, concludes with a warning: maintaining the status quo in a new technological medium will not result in greater security, but rather a digital version of the same failures currently plaguing the traditional banking sector. The organization urges the agencies to view privacy-preserving technologies not as a supplement to traditional CIP, but as a superior, more secure foundation for the future of digital finance.
As the comment period concludes, the federal agencies are faced with a fundamental policy choice. They must decide whether the mandate to curb illicit finance requires the total surveillance of stablecoin users, or if the same goal can be achieved through technological innovation that upholds the American values of individual agency and data privacy. The final ruling on the GENIUS Act’s CIP requirements will likely serve as a benchmark for how the U.S. government intends to treat the evolution of blockchain-based financial services for years to come.
