Hook
Two documents landed in the same news cycle, and almost nobody read them side by side. The first was a terse withdrawal notice signed by FinCEN Deputy Director Jimmy L. Kirby, retiring a proposed rule on unhosted wallets that had sat unresolved for roughly 1,700 days β and, alongside it, a 2023 rule that would have designated international crypto mixing a "primary money laundering concern" under Section 311 of the USA PATRIOT Act. The second was a sentencing order. Keonne Rodriguez, co-founder of Samourai Wallet, received five years. His co-founder, William Lonergan Hill, received four. The underlying allegations covered roughly $2 billion in transactions.
One document said the government would stop writing rules for privacy tools. The other said it would keep sending their builders to prison. Both are true, and the distance between them is where every self-custody product now lives.
Context
To understand why the withdrawal means less than it appears, you have to understand what the original rules were actually doing.
The Bank Secrecy Act does not regulate users. It regulates intermediaries β banks, money services businesses, money transmitters β by attaching reporting and recordkeeping duties to the moment value crosses their ledger. A self-custodied wallet has no such moment. The private key sits with the user, no institution executes the transfer, and no BSA-defined entity exists at the point of settlement. This is what redefining what ownership means in the digital age looks like at the statutory level: the owner and the institution are no longer the same entity, and the reporting duty has nowhere to attach. That is not a loophole. It is an architectural fact the law was never written to reach.
FinCEN's December 2020 proposal tried to reach it anyway. Banks and money services businesses would have been required to file reports on transactions involving unhosted wallets above $10,000, and to keep records β including counterparty identity verification β above a $3,000 threshold. In effect, every regulated institution touching a self-custodied counterparty would have become a surveillance relay, because the institution, not the user, was the entity FinCEN could compel.
The 2023 mixing rule used a different instrument. Section 311 lets Treasury impose special measures on a jurisdiction or transaction class deemed a primary money laundering concern. The proposed reporting fields were unusually granular: transaction amounts, wallet addresses, transaction hashes, IP addresses, and full customer identity. The Crypto Council for Innovation filed comments warning that the definition was broad enough to catch legitimate activity. When the withdrawal arrived, CCI described the outcome as the rulemaking process working as intended β public comment, then a change of course. That is accurate, as far as it goes.

The stated basis for reversal was the Trump administration's deregulatory agenda, anchored in the July 2025 White House President's Working Group report on digital asset markets. Five years of limbo ended not because the technical questions were answered, but because the political ones changed hands.
Core
Here is the part worth dwelling on: the data FinCEN asked for in 2023 is not data a compliant intermediary reliably possesses. That is not a policy objection. It is a data-model objection, and it explains a great deal about how the rule would have behaved in practice.

Start with IP addresses. An IP address is a routing artifact, not an identity. It is shared behind carrier-grade NAT, reassigned on lease expiry, spoofable at the packet level, and trivially obscured by a VPN. Requiring its collection does not produce attribution. It produces a filled-in field β populated with whatever the reporting institution can observe at its own edge, which is a proxy for network position, not for a person.
Transaction hashes are stranger still: they are already public. Any hash on a public chain is retrievable by anyone running an indexer. Mandating their submission adds no information the regulator could not obtain independently.
So the interesting question is what the rule would actually have yielded. Strip out the fields that are public and the fields that are unreliable, and what remains is identity collection β names, addresses, verified records β attached to transactions the intermediary was never party to. The mixer rule was framed as a tracing requirement; its practical effect was KYC by proxy.
Tracing the hidden vulnerabilities in the code has taught me to recognize this shape. In 2018, working through the MakerDAO contracts during the post-ICO lull, the findings that mattered were never the dramatic ones. They were the specifications that asked a component to enforce a guarantee its data model could not represent β a liquidation engine asked to price collateral it could not observe within the same block. The code did not fail loudly. It silently accepted a value it should have rejected. Regulation behaves the same way. A rule that asks an intermediary for an IP address will receive an IP address. It will not receive the truth.
Consider where the burden would have landed. A requirement that a bank verify the identity of a counterparty it never sees does not produce verification. It produces a decision by the bank to decline the transaction or price the relationship higher. The user-facing cost of the 2020 proposal was always going to be de-risking β self-custodied users quietly pushed off banking rails, not individually investigated.
What the withdrawal removes, then, is prospective obligation: no new reporting duty, no new recordkeeping threshold, no new KYC trigger for self-custodied counterparties. For a user, self-custody does not acquire a compliance tax. For a wallet operator, a liability that would have been passed downstream as friction β longer onboarding, more retention, more surface area to breach β simply disappears.

What it does not remove matters more. Section 311 remains on the books; the authority to designate a transaction class a primary money laundering concern was never repealed, only one proposed use of it withdrawn. The BSA's core obligations to regulated intermediaries are untouched. And the criminal statutes behind the Samourai sentences β operating an unlicensed money transmitting business, money laundering β are wholly independent of whether FinCEN has a pending rulemaking.
The withdrawal governs rulemaking. The convictions were built on existing law. The two tracks never intersected, which is exactly why they can move in opposite directions without contradiction.
The Department of Justice's April 2025 memo is sometimes read as softening. It narrowed the practice of pursuing cases on regulatory technicalities β prosecution as a substitute for rulemaking. That is a real constraint on one theory of liability. It is not a statute, it does not bind a future department, and it plainly did not shield the Samourai founders, whose case proceeded on theories the memo never foreclosed. A policy memo is a statement of priorities. Priorities are the most reversible thing in government.
Contrarian
The consensus reading is straightforward: deregulation, therefore privacy tools are safer. I think that reading inverts the actual risk profile.
When a rule exists, it is legible. You can read the threshold, model the reporting burden, hire counsel to interpret the definition, and build against a known constraint. When the rule is withdrawn but enforcement discretion remains, you have traded a bad but predictable constraint for an unpredictable one. Builders can engineer around a rule. They cannot engineer around a docket.
There is another, less comfortable observation. The defense offered for the Samourai founders β that the platform was built for anonymity, not for concealing wrongdoing β is a defense about intent. The court did not evaluate the cryptography; it evaluated the operator. The judge's formulation was that the founders had used their talents to further fraud. Whatever one thinks of that outcome, the structural lesson is unambiguous: legal exposure in privacy infrastructure concentrates at the operator, not at the protocol.
That creates a perverse incentive. The rational response is to eliminate the operator β to migrate from a service someone runs to a protocol no one runs. Architecturally sound. Legally, the risk does not vanish; it redistributes to users, who are harder to indict and harder to advise. It also makes the regulator's job harder, which is precisely the outcome a withdrawal is supposed to prevent.
I would flag the narrative layer too. Privacy is being repackaged right now as a policy catalyst, and sentiment in the sector will warm. Warm sentiment is not a durable fundamental, and in a market where survival is the only metric that compounds, the distinction is not academic. What changed is the cost of building, not the demand for what gets built.
Takeaway
The signals worth tracking are concrete: whether FinCEN reopens a docket on unhosted wallets; whether DOJ brings a new privacy-tool case under a theory the April memo did not address; whether the PWG report produces binding guidance or stays advisory; and, above all, the election calendar, because a five-year limbo ended on a change of government and can restart on the next one.
Quietly securing the layers beneath the hype has never meant assuming the layers above will hold still. Building trust through rigorous, unseen diligence remains the only durable strategy in this sector. The question for anyone building privacy infrastructure today is not whether the rule is gone. It is whether the discretion that replaced it is something you can design around β or only something you can survive.