
Weekly Digital Assets Regulatory Brief: Week 26-2026
MiCA's transition ends 1 July as the Bank of England publishes its systemic-stablecoin rulebook, FATF reshuffles the grey list, and Treasury, VARA and Korea escalate enforcement.
Issue #26-26

Researched from primary regulatory sources with human editorial oversight. As AI-assisted analysis, occasional errors can occur — please verify against the original source before relying on it.
TL;DR
- •MiCA's transitional regime ends 1 July 2026: ESMA has ordered unauthorised CASPs to wind down, while a late licensing wave (Ripple in Luxembourg, NAGA, OpenPayd) races the deadline.
- •The Bank of England published its draft rulebook for systemic sterling stablecoins, replacing per-holder caps with a temporary 40 billion pound aggregate issuance guardrail and a 70% gilts / 30% central-bank-deposit reserve split.
- •US Treasury escalated against crypto-enabled scam networks: FinCEN moved to sever Huione successor H-Pay under Section 311 as the DOJ seized backend infrastructure tied to Cambodia's Prince Group.
- •The FATF June plenary approved its seventh virtual-asset implementation update and reshuffled the grey list (Iraq and Bosnia added; Algeria and Namibia removed), with Vietnam and Kenya racing to show VASP oversight.
- •Enforcement broadened on three continents: Dubai's VARA fined MEXC and KuCoin for unlicensed activity, Korea's PIPC fined Bithumb over cross-border data transfers, and the SEC and CFTC opened a portfolio-margining review.
Executive Summary
Week 26, 2026 • Published June 28, 2026
The single most consequential date on the calendar arrived this week: 1 July 2026, when the European Union's Markets in Crypto-AssetsThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States Regulation (MiCA) transitional regime ends and any firm serving EU clients without a Crypto-Asset Service ProviderEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance (CASP) authorisation is operating illegally rather than merely out of compliance. ESMAEU agency coordinating securities regulation and supervising credit rating agencies and trade repositories used the closing days to order unauthorised firms into orderly wind-down, while a cluster of last-minute authorisations (Ripple via Luxembourg, NAGA, OpenPayd) showed the licensing machinery still grinding right up to the cut-off. The practical message for institutions is unchanged but now urgent: verify every EU counterparty against the ESMA and national registers before the weekend.
Alongside the MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States endgame, two structural regimes moved forward. The Bank of England published its policy statement and draft Code of Practice for systemic sterling stablecoins, abandoning the unpopular per-holder caps in favour of a temporary 40 billion pound aggregate issuance guardrail per coin, with reserves split 70% short-term gilts and 30% non-interest-bearing central-bank deposits, par redemption within 24 hours, and a ban on paying interest. The FATFGlobal standard-setter for combating money laundering and terrorist financing June plenary approved its seventh virtual-asset implementation update, announced a forthcoming report on DeFiFinancial systems built on blockchain that operate without intermediaries like banks money-laundering exposure, and updated the grey list, keeping AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities/CFT pressure on jurisdictions that host virtual-asset activity.
Enforcement was the week's connective tissue. US Treasury escalated a coordinated action against the Cambodia-based Prince Group, with FinCEN moving to sever Huione successor H-Pay under Section 311 and the DOJ seizing backend laundering infrastructure. Dubai's VARA fined MEXC and KuCoin for unlicensed activity and CoinMENA for AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities failings; Korea's PIPC fined Bithumb over unlawful cross-border data transfers; and Vietnam and Kenya both advanced AML reforms aimed at exiting FATFGlobal standard-setter for combating money laundering and terrorist financing monitoring. The throughline for compliance teams: licensing perimeters and AML expectations are hardening simultaneously across the EU, GCC, and Asia-Pacific.
This Week's Signals
Jump to Risk MatrixEuropean Union
United Kingdom
United States
Asia-Pacific
Signal Analysis
What Changed: ESMA orders unauthorised CASPs to wind down as MiCA transition ends 1 July
CRITICALRisk: Licensing / market access | Affected: CASPsEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance, exchanges, custodians, EU-facing institutions | Horizon: Immediate (1 July 2026) | Confidence: High
Facts: With MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States's transitional period ending 1 July 2026, ESMAEU agency coordinating securities regulation and supervising credit rating agencies and trade repositories reiterated that firms serving EU clients without a CASPEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance authorisation will be in breach of EU law and must stop onboarding new clients, cease marketing, limit activity to facilitating orderly client exits, and maintain full AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities/CFT controls throughout wind-down. ESMA stressed that non-EU firms and outsourcing arrangements cannot be used to bypass the authorisation requirement, and national authorities (such as Spain's CNMV) have echoed the hard cut-off.
Implications: After 1 July, using an unauthorised platform is a legal exposure, not just an operational one. Institutions must verify every EU counterparty against ESMAEU agency coordinating securities regulation and supervising credit rating agencies and trade repositories and national registers before the deadline and migrate custody or trading relationships away from firms still relying on national registration. The deadline accelerates consolidation around authorised CASPsEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance and raises the value of EU-passportable infrastructure.
What Changed: Bank of England publishes systemic stablecoin policy statement and draft Code
CRITICALRisk: Prudential / market structure | Affected: StablecoinA cryptocurrency pegged to a stable asset, such as USD or gold issuers, banks, PSPs | Horizon: Consultation to 22 Sep 2026; rules from 2027 | Confidence: High
Facts: On 22 June 2026 the Bank of England published a policy statement and draft Code of Practice for sterling-denominated systemic stablecoins. The Bank dropped its earlier proposal for per-holder caps (20,000 pounds individual / 10 million pounds business) in favour of a temporary aggregate issuance guardrail set initially at 40 billion pounds per systemic stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold. Reserves must be held 70% in short-term UK government debt (residual maturity up to six months) and 30% in non-interest-bearing central-bank deposits, with par redemption within 24 hours, statutory-trust segregation, and a prohibition on paying interest to coinholders. The consultation runs to 22 September 2026, with final rules targeted by end-2026 and implementation from 2027.
Implications: The UK is converging with the US GENIUS ActUS law (July 2025) requiring payment stablecoin issuers to be regulated entities with 1:1 reserve backing on the core design (high-quality liquid reserves, strict redemption, no yield) but pairs it with a hard issuance ceiling that constrains scale until credit-provision risks are addressed. Prospective issuers (including non-UK firms) will need a UK subsidiary, bank-grade risk management, capital to absorb the largest plausible loss event, and dual statutory trusts. Treasury and product teams should model the 40 billion pound guardrail and the gilts/deposit split into business cases now.
What Changed: Pre-deadline MiCA CASP licensing wave (Ripple-Luxembourg, NAGA, OpenPayd)
HIGHRisk: Market structure / competition | Affected: CASPsEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance, banks, payment institutions | Horizon: Immediate | Confidence: High
Facts: In the final week before the MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States deadline, several firms secured authorisation. On 23 June 2026 Ripple received preliminary CASPEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance approval (a CSSF "Green Light Letter") in Luxembourg which, combined with its existing EU Electronic Money Institution licence, enables regulated cryptoasset and stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold payment services across the 30-country EEA through a single integration. NAGA Group's entity NAGA X and payments firm OpenPayd both announced MiCA authorisations on 24 June covering trading, custody and stablecoin services, while Italy's Conio (Consob / Bank of Italy) had cleared its CASP licence days earlier.
Implications: A MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States CASPEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance licence plus passportingRight to offer crypto services across EU member states with home state authorization is becoming the baseline for institutional access to EU crypto rails. For banks and corporates, authorised providers like Ripple (CASP + EMI) simplify vendor risk analysis and offer a compliant route for cross-border tokenised payments and stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold settlement. The wave also illustrates the documentation and governance bar national regulators are applying, and the jurisdiction-shopping dynamics as firms pick their home-state authority.
What Changed: European Parliament committee adopts the digital euro framework
HIGHRisk: CBDCDigital form of a nation's fiat currency issued and guaranteed by the central bank / payments market structure | Affected: Banks, PSPs, payment networks | Horizon: Pilot from mid-2027; issuance possibly 2029 | Confidence: High
Facts: On 23 June 2026 the European Parliament's Economic and Monetary Affairs (ECON) committee adopted its position on the single-currency package, backing the digital euroProposed CBDC issued by European Central Bank to complement cash and private payments framework by 43 votes to 14 with one abstention. The texts provide for online and offline versions of an ECB-issued digital euro, with cash-like privacy offline, ECB-set holding limits to protect bank deposits, free basic services, and a 12-month pilot from mid-2027 ahead of a possible first issuance in 2029. Negotiating mandates head to the July plenary before trilogue with the Council, which agreed its position in December 2025.
Implications: The digital euroProposed CBDC issued by European Central Bank to complement cash and private payments is moving from study to legislation. Banks and payment service providers should plan now for holding limits, mandatory distribution obligations, and offline-payment infrastructureInfrastructure and networks that enable money transfer between parties, and watch the trilogue for the final calibration of limits and intermediary compensation. The EU frames the project as reducing dependence on US card networks and dollar stablecoins, a strategic-autonomy driver that will shape European payments for the rest of the decade and sits in direct contrast to the US move to bar a Federal Reserve retail CBDCDigital form of a nation's fiat currency issued and guaranteed by the central bank.
What Changed: FinCEN severs Huione successor H-Pay under Section 311 as DOJ seizes infrastructure
HIGHRisk: AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities / sanctions | Affected: Banks, payment processors, VASPs | Horizon: Immediate (NPRM open) | Confidence: High
Facts: On 23 June 2026, as part of a coordinated US action against Cambodia's Prince Group, FinCEN issued a notice of proposed rulemaking to amend its October 2025 Huione Group designation to add H-Pay Service PLC (a rebrand of the sanctioned Huione Pay) and any successor entities as a "primary money laundering concern," severing them from the US financial system. The same day, the DOJ announced the seizure of cloud backend infrastructure used by Huione subsidiaries to launder billions in crypto investment-fraud and scam proceeds, and OFAC added related designations.
Implications: US financial institutions and VASPs must treat H-Pay and any Huione successors as blocked, high-risk counterparties and update sanctions/AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities screening, walletA tool for storing, sending, and receiving cryptocurrencies attribution, and on/off-rampA service that converts cryptocurrency back into fiat money monitoring to capture indirect flows through mixers and high-risk exchanges. The rebrand-and-continue pattern shows that designations must reach "successor entities," and Section 311 is now an established tool against crypto-enabled scam ecosystems that foreign FIUs are likely to mirror.
What Changed: Dubai VARA fines MEXC and KuCoin (unlicensed) and CoinMENA (AML)
HIGHRisk: Licensing / AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities enforcement | Affected: Offshore exchanges, licensed VASPs, treasuries | Horizon: Immediate | Confidence: High
Facts: Dubai's Virtual Assets Regulatory AuthorityDubai's independent regulator for virtual assets and crypto activities in the emirate (VARA) issued enforcement measures and financial penalties against MX Global (operating as MEXC) and KuCoin for providing broker-dealer and exchangeA platform where users can buy, sell, or trade cryptocurrencies services to customers in Dubai without a VARA licence (MEXC's breach spanning 2022 to April 2026, with KYCA process where exchanges and financial institutions verify user identity failures), directing them to cease and desist. Separately, VARA penalised already-licensed CoinMENA for AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities programme compliance failures found during inspection. VARA did not publicly disclose the fine amounts.
Implications: VARA has shifted from licensing build-out to active enforcement on two fronts at once: unlicensed "fly-in" platforms serving Dubai residents, and post-licensing governance at authorised firms. Treasuries and institutions using offshore exchanges for liquidityThe ease with which an asset can be bought or sold without affecting its price must verify VARA status before dealing with platforms that have material UAE user bases, and licensed firms should expect inspection-driven scrutiny of AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities systems, sanctions screeningChecking customers and transactions against government sanctions lists, and STR processes.
What Changed: Vietnam adopts AML/CFT action plan with virtual-asset regulation mandate
HIGHRisk: AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities / licensing | Affected: VASPs, banks, fintechs in Vietnam | Horizon: Phased through grey-list review | Confidence: High
Facts: On 26 June 2026 Vietnam's government adopted a national action plan to combat money laundering, terrorism financing and proliferation financing, with the explicit objective of exiting the FATFGlobal standard-setter for combating money laundering and terrorist financing's increased-monitoring list. The plan instructs authorities to implement risk-based supervision for financial institutions and designated non-financial businesses and to "take action to regulate virtual assetsFATF term for digital value representation tradable or transferable electronically and virtual asset service providers."
Implications: VASPs operating in or targeting Vietnam should anticipate formal licensing, registration and reporting obligations as the regime is built out, and banks will need to fold virtual-asset risk into AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities assessments. Vietnam is one of the world's highest crypto-adoption markets, so a move from informal tolerance to FATFGlobal standard-setter for combating money laundering and terrorist financing-aligned supervision is a material shift for cross-border flows and exchangeA platform where users can buy, sell, or trade cryptocurrencies access.
What Changed: FATF June plenary updates grey list and approves seventh virtual-asset implementation report
HIGHRisk: AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities / cross-border | Affected: VASPs, banks, custodians | Horizon: Flows into national guidance | Confidence: High
Facts: At its 17-19 June 2026 plenary, the FATFGlobal standard-setter for combating money laundering and terrorist financing approved a seventh targeted update on implementation of its virtual-asset standards and announced a new targeted report on DeFiFinancial systems built on blockchain that operate without intermediaries like banks money-laundering exposure. The grey list was reshuffled: Iraq and Bosnia and Herzegovina were added, while Algeria and Namibia were removed, leaving 22 jurisdictions under increased monitoring. The plenary reinforced the supervisory expectations set out in the FATF's Best Practices on Travel RuleRequirement to share sender and recipient information for crypto transactions above a threshold Supervision (first published June 2025), and the incoming UK Presidency flagged scam compounds and fraud as priorities.
Implications: Supervisors will use the Travel RuleRequirement to share sender and recipient information for crypto transactions above a threshold best practices to benchmark local regimes, increasing pressure on lagging jurisdictions and on VASPs to demonstrate effective originatorPerson or entity sending a virtual asset transfer under Travel Rule requirements/beneficiaryPerson or entity receiving a virtual asset transfer under Travel Rule requirements data collection and screening across on- and off-chainA decentralized, digital ledger of transactions maintained across multiple computers transfers. Firms dealing with counterparties in newly listed jurisdictions (Iraq, Bosnia) should refresh enhanced due diligenceProcess of verifying customer identity and assessing risk; the forthcoming DeFiFinancial systems built on blockchain that operate without intermediaries like banks report signals where the next supervisory frontier lies.
What Changed: Delaware passes GENIUS-aligned banking and stablecoin laws (SB 16/18/19)
HIGHRisk: Licensing / market structure | Affected: StablecoinA cryptocurrency pegged to a stable asset, such as USD or gold issuers, trust banks, MSBs | Horizon: Phased on signature | Confidence: High
Facts: Delaware's General Assembly passed a three-bill package now on the governor's desk. SB 16 (Banking Modernization Act) defines "digital asset" and "virtual currency" and authorises Delaware banks and trust companies to holdA misspelling of 'hold,' used to mean holding onto cryptocurrency for long-term gains and manage digital assets. SB 19 (Payment StablecoinA cryptocurrency pegged to a stable asset, such as USD or gold Act) creates a licensing regime for stablecoin issuers under the State Bank Commissioner with 1:1 reserve requirements modelled on the federal GENIUS ActUS law (July 2025) requiring payment stablecoin issuers to be regulated entities with 1:1 reserve backing. SB 18 (Money Transmission and Virtual Currency Modernization Act) adopts the CSBS model framework already enacted in 30+ states. Parts of SB 16 take effect immediately; SB 19 phases in with GENIUS directives; SB 18 after one year.
Implications: Delaware, the US corporate-domicile hub, is positioning itself as a licensed on-rampA service that converts fiat money into cryptocurrency for stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold issuers and a registration venue for digital-asset service providers under GENIUS. Expect increased use of Delaware trust and bank charters for institutional custody and tokenisation structures, and watch whether other states accelerate GENIUS-aligned licensing to compete.
What Changed: Korea's PIPC fines Bithumb over cross-border data transfers and issues blockchain privacy rules
MEDIUMRisk: Data protection / AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities overlap | Affected: Exchanges serving Korean users | Horizon: Immediate (corrective order) | Confidence: High
Facts: At its 24 June 2026 plenary session, Korea's Personal Information Protection Commission (PIPC) fined Bithumb 210 million won (about 136,000 US dollars) and issued a corrective order. The PIPC found Bithumb shared its TetherThe largest stablecoin by market cap, pegged 1:1 to the US Dollar and issued by Tether Limited (USDT) order-book data with overseas exchanges from September to November 2025: users had consented to a transfer involving one exchangeA platform where users can buy, sell, or trade cryptocurrencies (Stellar), but member numbers and order data were routed to another (BingX). It also flagged the sharing of names, walletA tool for storing, sending, and receiving cryptocurrencies addresses and, in one case, dates of birth with 13 overseas exchanges for AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities checks. The PIPC simultaneously released blockchainA decentralized, digital ledger of transactions maintained across multiple computers-service privacy guidelines warning against placing identifying data on-chain.
Implications: The case puts data-protection compliance, especially cross-border transfers, on par with AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities as a first-order risk for exchanges. Firms serving Korean users need accurate disclosure of foreign data recipients, robust consent, and architectures that avoid recording personal identifiers on public chains. The tension between Travel RuleRequirement to share sender and recipient information for crypto transactions above a threshold data-sharing and privacy law is now an enforcement reality, not a theoretical conflict.
What Changed: SEC and CFTC seek comment on harmonising portfolio margining
MEDIUMRisk: Market structure | Affected: Broker-dealers, FCMs, clearing agencies | Horizon: 60-day comment period | Confidence: High
Facts: On 26 June 2026 the SECU.S. federal agency regulating securities markets and protecting investors and CFTCU.S. federal agency regulating derivatives markets including crypto commodity futures issued a joint request for public comment on harmonising portfolio-margining frameworks across securities, security-based swaps, futures, swaps and related positions, with a 60-day comment window. The request builds on the agencies' 11 March 2026 memorandum of understanding and comes ahead of US Treasury clearing mandates expected by end-2026. Regulators asked for input on cross-margining, collateral eligibility, risk-management standards and customer protections.
Implications: Firms supporting crypto derivatives cleared alongside traditional products should expect eventual changes to how cross-product margin is calculated, offset and documented, with knock-on effects for capital usage and the segregation treatment of crypto collateral. This is the regulatory plumbing that determines how efficiently crypto futures and options can sit in a unified book; comment letters now will shape the calculus.
What Changed: EBA consults on MiCA penalty methodology for significant tokens
MEDIUMRisk: Enforcement / prudential | Affected: Issuers of significant ARTsCrypto token under MiCA that maintains stable value by referencing multiple assets and EMTsCrypto token under MiCA that maintains stable value by referencing a single fiat currency | Horizon: Consultation open | Confidence: High
Facts: On 26 June 2026 the European Banking AuthorityEU agency supervising banking and stablecoin regulation across member states opened a consultation on a methodology for calculating fines in its role as supervisor of significant asset-referenced tokens (s-ARTsCrypto token under MiCA that maintains stable value by referencing multiple assets) and significant e-money tokens (s-EMTsCrypto token under MiCA that maintains stable value by referencing a single fiat currency) under MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States Article 131. The two-step approach sets a basic amount and then adjusts for aggravating and mitigating factors, with fines of at least 5 million euros or 3% to 12.5% of total annual turnover depending on the infringement.
Implications: Large stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold issuers under direct EBAEU agency supervising banking and stablecoin regulation across member states supervision face a structured, turnover-linked penalty regime that makes breach exposure quantifiable. Compliance teams should map which MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States obligations (governance, reserve management, disclosure, conduct) most drive penalty exposure and feed that into risk assessments and internal audit plans. Non-EU issuers passportingRight to offer crypto services across EU member states with home state authorization into the EU should assume harmonised administrative fines rather than lighter national-level sanctions.
What Changed: ASIC extends crypto licensing no-action relief to 30 September 2026
MEDIUMRisk: Licensing / transition | Affected: Australian-facing digital-asset firms | Horizon: Relief ends 30 Sep 2026; framework ~April 2027 | Confidence: High
Facts: On 27 June 2026 ASICSpecialized hardware designed for mining cryptocurrencies efficiently extended its sector-wide no-action position for digital-asset businesses providing financial services to 30 September 2026 (from 30 June), giving firms three more months to apply for or vary an Australian Financial Services (AFS) licence, and broadened it to cover authorised-representative and intermediary arrangements. ASIC has received roughly 30 licence applications since updating Information Sheet 225 in October 2025, and the Corporations Amendment (Digital Assets Framework) Act 2026 is expected to take effect around April 2027.
Implications: This is transitional relief, not a softening. ASICSpecialized hardware designed for mining cryptocurrencies efficiently has confirmed that many digital-asset products are financial products requiring an AFS licence, and the compliance runway is now firmly dated. Australian-facing digital-asset firms should use the window to lodge or vary applications and map the incoming Digital Assets Framework, because enforcement forbearance ends on 30 September 2026.
What Changed: Kenya tightens crypto rules in push to exit the FATF grey list
MEDIUMRisk: AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities / licensing | Affected: VASPs, banks, mobile-money operators | Horizon: Ongoing FATFGlobal standard-setter for combating money laundering and terrorist financing review | Confidence: Medium
Facts: Kenya, grey-listed by the FATFGlobal standard-setter for combating money laundering and terrorist financing in February 2024, is accelerating AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities/CFT reforms to exit increased monitoring, with virtual-asset risk a named focus. Building on the Virtual AssetFATF term for digital value representation tradable or transferable electronically Service Providers Act 2025, authorities are tightening crypto oversight and beneficial-ownership frameworks as part of the action plan reviewed by the FATF through 2026.
Implications: Expect clearer VASPEntity providing services related to virtual assets, subject to AML regulations registration requirements and stronger enforcement against unlicensed platforms in one of Africa's largest crypto markets. Banks, payment firms and mobile-money operators must ensure AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities programmes capture fiatTraditional government-issued currency, such as USD, EUR, or NIS-to-crypto gateways and peer-to-peer transfers, and cross-border institutions dealing with Kenyan counterparties should expect more detailed due-diligence inquiries on virtual-asset exposure.
What Changed: Yellow Card obtains Swiss supervised financial-intermediary status
LOWRisk: Licensing / AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities | Affected: StablecoinA cryptocurrency pegged to a stable asset, such as USD or gold payment providers, EM corridors | Horizon: Immediate | Confidence: Medium
Facts: StablecoinA cryptocurrency pegged to a stable asset, such as USD or gold infrastructure and payments firm Yellow Card announced it has obtained AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities affiliation in Switzerland as a supervised financial intermediary, operating from Lugano. The status brings it under Swiss AML/CFT obligations and provides a regulated baseCoinbase's Ethereum Layer 2 network using Optimism's OP Stack, designed for low-cost, high-speed transactions with Coinbase ecosystem integration to offer stablecoin-based cross-border capital flows into emerging markets alongside Swiss and other banking partners.
Implications: For institutions routing payments into African and other high-growth markets via stablecoins, a Swiss-supervised intermediary is a more palatable counterparty than an unsupervised offshore provider. Yellow Card must maintain Swiss-grade AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities controls, monitoring and reporting, aligning emerging-market stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold rails with FATFGlobal standard-setter for combating money laundering and terrorist financing expectations. (Source: company announcement; treat as a licensing-status data point.)
What Changed: MAS adds Hyperliquid to its Investor Alert List
LOWRisk: Consumer protection / licensing | Affected: Singapore users, DeFiFinancial systems built on blockchain that operate without intermediaries like banks platforms | Horizon: Immediate | Confidence: High
Facts: On 26 June 2026 the Monetary Authority of SingaporeSingapore's central bank and integrated financial regulator overseeing banking, insurance, and securities added the decentralised exchangeA platform where users can buy, sell, or trade cryptocurrencies Hyperliquid to its Investor Alert List, flagging that it is neither licensed nor authorised in Singapore. The addition follows Bybit, KuCoin and Bitget on the same list. Hyperliquid responded that, as permissionless infrastructure with user self-custody, it has never claimed to be MAS-licensed; MAS clarified the listing is not an outright ban.
Implications: Hyperliquid is among the first major DeFiFinancial systems built on blockchain that operate without intermediaries like banks protocols flagged this way, signalling MAS's willingness to apply its alert mechanism to decentralised venues, not just centralised exchanges. Regulated firms must treat listed entities as high-risk counterparties in onboarding and marketing controls, and the move sharpens the question of how permissionless protocols sit within a licensing perimeter.
What Changed: Texas fines Ramad Pay for AML failures; FBI flags OneCoin remission deadline
LOWRisk: AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities enforcement / investor restitution | Affected: MSBs, crypto money-services firms | Horizon: Immediate; claims by 30 Jun 2026 | Confidence: Medium
Facts: The Texas Department of Banking announced an enforcement action against Ramad Pay, Inc. for AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities/CFT violations tied to its money-services business. Separately, the FBI reminded victims of the OneCoin fraud (2014-2019) to file for compensation under a DOJ remission program covering more than 40 million US dollars in forfeited assets before the 30 June 2026 deadline.
Implications: State banking regulators are actively using AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities/CFT enforcement against crypto-linked money-services businesses, so firms must harmonise state-level licensing and BSAU.S. anti-money laundering law applied to crypto businesses by FinCEN/AML compliance with federal GENIUS/FinCEN obligations across their US footprint. The OneCoin remission process underscores continued DOJ appetite for investor restitution in legacy crypto-fraud cases.
Risk Impact Matrix
| Jur. | Development | Risk Category | Severity | Affected | Timeline |
|---|---|---|---|---|---|
| EU | MiCA transition ends; ESMA wind-down order | Licensing / market access | Critical | CASPs, EU-facing institutions | 1 July 2026 |
| UK | BoE systemic stablecoin policy + draft Code | Prudential / market structure | Critical | Stablecoin issuers, banks, PSPs | Consult to 22 Sep 2026 |
| US | FinCEN H-Pay Section 311 + DOJ seizure | AML / sanctions | High | Banks, processors, VASPs | NPRM open |
| EU | MiCA CASP licensing wave (Ripple, NAGA, OpenPayd) | Market structure / competition | High | CASPs, banks, PSPs | Immediate |
| EU | EU Parliament committee adopts digital euro framework | CBDC / payments market structure | High | Banks, PSPs, payment networks | Pilot mid-2027 |
| AE | VARA fines MEXC, KuCoin, CoinMENA | Licensing / AML enforcement | High | Offshore exchanges, licensed VASPs | Immediate |
| VN | Vietnam AML/CFT action plan + VA mandate | AML / licensing | High | VASPs, banks, fintechs | Phased |
| US | Delaware GENIUS-aligned banking/stablecoin laws | Licensing / market structure | High | Issuers, trust banks, MSBs | Phased on signature |
| GLOBAL | FATF plenary: grey-list changes + 7th VA update | AML / cross-border | High | VASPs, banks, custodians | Flows to national guidance |
| KR | PIPC fines Bithumb; blockchain privacy rules | Data protection / AML overlap | Medium | Exchanges serving Korea | Immediate |
| US | SEC-CFTC portfolio-margining harmonisation review | Market structure | Medium | Broker-dealers, FCMs, clearing | 60-day comment |
| EU | EBA MiCA penalty methodology consultation | Enforcement / prudential | Medium | Significant ART/EMT issuers | Consultation open |
| KE | Kenya crypto-rule tightening for grey-list exit | AML / licensing | Medium | VASPs, banks, mobile money | Ongoing review |
| AU | ASIC extends crypto licensing no-action relief | Licensing / transition | Medium | Australian-facing digital-asset firms | Relief ends 30 Sep 2026 |
| CH | Yellow Card Swiss supervised-intermediary status | Licensing / AML | Low | Stablecoin payment providers | Immediate |
| SG | MAS adds Hyperliquid to Investor Alert List | Consumer protection / licensing | Low | Singapore users, DeFi platforms | Immediate |
| US | Texas Ramad Pay AML action; OneCoin remission | AML enforcement / restitution | Low | MSBs, crypto money-services firms | Claims by 30 Jun 2026 |
Regulations move faster than headlines.
One weekly brief. Every development that matters. No noise.
Read by compliance and legal teams at Standard Chartered, Lloyds, Freshfields, and Loyens & Loeff.
Free. No spam. Unsubscribe anytime.
Cross-Signal Patterns
Pattern: The stablecoin rulebook converges across jurisdictions
Linked Signals: BoE systemic stablecoin, Delaware GENIUS laws, EBA penalty methodology
What it means: The UK, the US (federal GENIUS plus Delaware state implementation) and the EU are settling on the same stablecoin design: high-quality liquid reserves, strict par redemption, no yield to holders, and licensed issuers. The remaining divergence is on scale (the UK's 40 billion pound guardrail) and enforcement calibration (the EBA's turnover-linked fines). Multinational issuers should design one global compliance framework to the strictest common denominator rather than per-jurisdiction patchwork.
Confidence: High
Pattern: Enforcement shifts from licensing to supervision and successor-chasing
Linked Signals: VARA enforcement, FinCEN H-Pay, PIPC Bithumb, MAS Hyperliquid
What it means: Regulators that spent two years building licensing regimes are now exercising them. VARA is penalising both unlicensed entrants and AML failings at licensed firms; FinCEN is chasing rebranded successor entities; Korea is enforcing data-protection law against an exchange; MAS is flagging DeFi protocols. The common thread: being unlicensed, or being licensed but non-compliant, now carries concrete monetary and access consequences.
Confidence: High
Pattern: FATF pressure pulls emerging markets into VASP supervision
Linked Signals: FATF June plenary, Vietnam AML plan, Kenya grey-list push
What it means: The grey-list mechanism is doing exactly what it is designed to do: high-adoption emerging markets (Vietnam, Kenya) are building VASP supervision and Travel Rule capacity to avoid or exit increased monitoring. For global institutions, this is a leading indicator of where new licensing perimeters and counterparty due-diligence requirements will appear next, and of where correspondent-banking risk is being actively managed down.
Confidence: Medium
Strategic Implications
1. Close the MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States counterparty gap before the weekend
Treat 1 July as a hard control date. Run every EU-facing crypto counterparty against the ESMAEU agency coordinating securities regulation and supervising credit rating agencies and trade repositories and national CASPEntity providing crypto services under EU MiCA requiring authorization and regulatory compliance registers, document the check, and freeze or migrate any relationship with a firm relying on lapsing national registration. Reverse-solicitation is a narrow exception, not a strategy. [Traced to: ESMA wind-down order, MiCAThe EU's comprehensive regulatory framework for crypto-assets, establishing harmonized rules for issuers and service providers across all 27 Member States CASP licensing wave]
2. Build stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold compliance to the converging global standard
The UK, US and EU now share a recognisable stablecoinA cryptocurrency pegged to a stable asset, such as USD or gold template. Issuers and institutional users should design reserve, redemption, segregation and no-yield controls to satisfy all three at once, while planning for jurisdiction-specific limits such as the BoE's 40 billion pound guardrail and the EBAEU agency supervising banking and stablecoin regulation across member states's turnover-linked fines. [Traced to: BoE systemic stablecoin, Delaware GENIUS laws, EBA penalty methodology]
3. Refresh sanctions and successor-entity screening for scam networks
The H-Pay action shows designations now explicitly reach "successor entities." Update screening, walletA tool for storing, sending, and receiving cryptocurrencies attribution and on/off-rampA service that converts cryptocurrency back into fiat money monitoring to capture rebrands and indirect flows through mixers and high-risk exchanges, and expect foreign FIUs to mirror Section 311-style measures against crypto-enabled scam ecosystems. [Traced to: FinCEN H-Pay, FATFGlobal standard-setter for combating money laundering and terrorist financing June plenary]
4. Reconcile Travel RuleRequirement to share sender and recipient information for crypto transactions above a threshold data-sharing with privacy law
The PIPC fine against Bithumb makes the tension between AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities data transfers and data-protection law a live enforcement risk. Firms must obtain accurate cross-border transfer consent, disclose foreign recipients precisely, and avoid putting personal identifiers on-chainA decentralized, digital ledger of transactions maintained across multiple computers, even when sharing originatorPerson or entity sending a virtual asset transfer under Travel Rule requirements/beneficiaryPerson or entity receiving a virtual asset transfer under Travel Rule requirements data for Travel RuleRequirement to share sender and recipient information for crypto transactions above a threshold compliance. [Traced to: PIPC Bithumb, FATFGlobal standard-setter for combating money laundering and terrorist financing June plenary]
5. Track emerging-market VASPEntity providing services related to virtual assets, subject to AML regulations regimes as forward licensing indicators
Vietnam and Kenya advancing AMLRegulatory framework requiring financial institutions to detect and prevent money laundering, terrorist financing, and other illicit financial activities reforms under FATFGlobal standard-setter for combating money laundering and terrorist financing pressure preview where new VASPEntity providing services related to virtual assets, subject to AML regulations licensing and due-diligence obligations will land. Institutions with exposure to high-adoption markets should monitor implementing rules (registration, Travel RuleRequirement to share sender and recipient information for crypto transactions above a threshold timing, beneficial ownershipIdentification of natural persons who ultimately own or control legal entity customers) and build them into onboarding and correspondent-banking risk now. [Traced to: Vietnam AML plan, Kenya grey-list push, FATF June plenary]
Sources
- ESMA - Markets in Crypto-Assets Regulation (MiCA)
- Bank of England - Policy statement and draft rules on regulating systemic stablecoins
- Ripple - Ripple secures preliminary MiCA CASP licence
- FinCEN - Proposes to sever H-Pay Service PLC and other Huione Group successors
- DOJ - Seizes backend infrastructure used by the Huione Group
- VARA - Regulatory notices
- Government of Vietnam - New action plan for combatting money laundering and terrorism financing
- FATF - Outcomes of the June 2026 Plenary
- Delaware General Assembly - Senate Bill 19
- PIPC - Personal Information Protection Commission (English)
- SEC - SEC, CFTC Seek Public Comment on the Harmonization of Portfolio Margining Frameworks
- EBA - Publications and media
- FATF - Kenya country page
- MAS - Investor Alert List
- Texas Department of Banking
- Bank of England - Draft Code of Practice for sterling-denominated systemic stablecoin issuers (PDF)
- FATF - Best Practices on Travel Rule Supervision, 2025 (PDF)
- European Parliament - Digital euro: MEPs want to ensure sovereignty, privacy and financial stability
- ASIC - Media releases
If you found this useful, please share it.
Questions or feedback? Contact us
MCMS Brief • Classification: Public • Sector: Digital Assets • Region: Global
Disclaimer: This content is for educational and informational purposes only. It is NOT financial, investment, or legal advice. Cryptocurrency investments carry significant risk. Always consult qualified professionals before making any investment decisions. Make Crypto Make Sense assumes no liability for any financial losses resulting from the use of this information. Full Terms