← Back to Archive
Weekly Digital Assets Regulatory Brief: Week 26-2026

Weekly Digital Assets Regulatory Brief: Week 26-2026

MiCA's transition ends 1 July as the Bank of England publishes its systemic-stablecoin rulebook, FATF reshuffles the grey list, and Treasury, VARA and Korea escalate enforcement.

Issue #26-26

Sophie Valmont
by Sophie Valmont - AI Research Analyst | Under Human Supervision

Researched from primary regulatory sources with human editorial oversight. As AI-assisted analysis, occasional errors can occur — please verify against the original source before relying on it.

TL;DR

  • MiCA's transitional regime ends 1 July 2026: ESMA has ordered unauthorised CASPs to wind down, while a late licensing wave (Ripple in Luxembourg, NAGA, OpenPayd) races the deadline.
  • The Bank of England published its draft rulebook for systemic sterling stablecoins, replacing per-holder caps with a temporary 40 billion pound aggregate issuance guardrail and a 70% gilts / 30% central-bank-deposit reserve split.
  • US Treasury escalated against crypto-enabled scam networks: FinCEN moved to sever Huione successor H-Pay under Section 311 as the DOJ seized backend infrastructure tied to Cambodia's Prince Group.
  • The FATF June plenary approved its seventh virtual-asset implementation update and reshuffled the grey list (Iraq and Bosnia added; Algeria and Namibia removed), with Vietnam and Kenya racing to show VASP oversight.
  • Enforcement broadened on three continents: Dubai's VARA fined MEXC and KuCoin for unlicensed activity, Korea's PIPC fined Bithumb over cross-border data transfers, and the SEC and CFTC opened a portfolio-margining review.

Executive Summary

Week 26, 2026 • Published June 28, 2026

The single most consequential date on the calendar arrived this week: 1 July 2026, when the European Union's Markets in Crypto-Assets Regulation (MiCA) transitional regime ends and any firm serving EU clients without a Crypto-Asset Service Provider (CASP) authorisation is operating illegally rather than merely out of compliance. ESMA used the closing days to order unauthorised firms into orderly wind-down, while a cluster of last-minute authorisations (Ripple via Luxembourg, NAGA, OpenPayd) showed the licensing machinery still grinding right up to the cut-off. The practical message for institutions is unchanged but now urgent: verify every EU counterparty against the ESMA and national registers before the weekend.

Alongside the MiCA endgame, two structural regimes moved forward. The Bank of England published its policy statement and draft Code of Practice for systemic sterling stablecoins, abandoning the unpopular per-holder caps in favour of a temporary 40 billion pound aggregate issuance guardrail per coin, with reserves split 70% short-term gilts and 30% non-interest-bearing central-bank deposits, par redemption within 24 hours, and a ban on paying interest. The FATF June plenary approved its seventh virtual-asset implementation update, announced a forthcoming report on DeFi money-laundering exposure, and updated the grey list, keeping AML/CFT pressure on jurisdictions that host virtual-asset activity.

Enforcement was the week's connective tissue. US Treasury escalated a coordinated action against the Cambodia-based Prince Group, with FinCEN moving to sever Huione successor H-Pay under Section 311 and the DOJ seizing backend laundering infrastructure. Dubai's VARA fined MEXC and KuCoin for unlicensed activity and CoinMENA for AML failings; Korea's PIPC fined Bithumb over unlawful cross-border data transfers; and Vietnam and Kenya both advanced AML reforms aimed at exiting FATF monitoring. The throughline for compliance teams: licensing perimeters and AML expectations are hardening simultaneously across the EU, GCC, and Asia-Pacific.

Signal Analysis

What Changed: ESMA orders unauthorised CASPs to wind down as MiCA transition ends 1 July

CRITICAL

Risk: Licensing / market access | Affected: CASPs, exchanges, custodians, EU-facing institutions | Horizon: Immediate (1 July 2026) | Confidence: High

Facts: With MiCA's transitional period ending 1 July 2026, ESMA reiterated that firms serving EU clients without a CASP authorisation will be in breach of EU law and must stop onboarding new clients, cease marketing, limit activity to facilitating orderly client exits, and maintain full AML/CFT controls throughout wind-down. ESMA stressed that non-EU firms and outsourcing arrangements cannot be used to bypass the authorisation requirement, and national authorities (such as Spain's CNMV) have echoed the hard cut-off.

Implications: After 1 July, using an unauthorised platform is a legal exposure, not just an operational one. Institutions must verify every EU counterparty against ESMA and national registers before the deadline and migrate custody or trading relationships away from firms still relying on national registration. The deadline accelerates consolidation around authorised CASPs and raises the value of EU-passportable infrastructure.

What Changed: Bank of England publishes systemic stablecoin policy statement and draft Code

CRITICAL

Risk: Prudential / market structure | Affected: Stablecoin issuers, banks, PSPs | Horizon: Consultation to 22 Sep 2026; rules from 2027 | Confidence: High

Facts: On 22 June 2026 the Bank of England published a policy statement and draft Code of Practice for sterling-denominated systemic stablecoins. The Bank dropped its earlier proposal for per-holder caps (20,000 pounds individual / 10 million pounds business) in favour of a temporary aggregate issuance guardrail set initially at 40 billion pounds per systemic stablecoin. Reserves must be held 70% in short-term UK government debt (residual maturity up to six months) and 30% in non-interest-bearing central-bank deposits, with par redemption within 24 hours, statutory-trust segregation, and a prohibition on paying interest to coinholders. The consultation runs to 22 September 2026, with final rules targeted by end-2026 and implementation from 2027.

Implications: The UK is converging with the US GENIUS Act on the core design (high-quality liquid reserves, strict redemption, no yield) but pairs it with a hard issuance ceiling that constrains scale until credit-provision risks are addressed. Prospective issuers (including non-UK firms) will need a UK subsidiary, bank-grade risk management, capital to absorb the largest plausible loss event, and dual statutory trusts. Treasury and product teams should model the 40 billion pound guardrail and the gilts/deposit split into business cases now.

What Changed: Pre-deadline MiCA CASP licensing wave (Ripple-Luxembourg, NAGA, OpenPayd)

HIGH

Risk: Market structure / competition | Affected: CASPs, banks, payment institutions | Horizon: Immediate | Confidence: High

Facts: In the final week before the MiCA deadline, several firms secured authorisation. On 23 June 2026 Ripple received preliminary CASP approval (a CSSF "Green Light Letter") in Luxembourg which, combined with its existing EU Electronic Money Institution licence, enables regulated cryptoasset and stablecoin payment services across the 30-country EEA through a single integration. NAGA Group's entity NAGA X and payments firm OpenPayd both announced MiCA authorisations on 24 June covering trading, custody and stablecoin services, while Italy's Conio (Consob / Bank of Italy) had cleared its CASP licence days earlier.

Implications: A MiCA CASP licence plus passporting is becoming the baseline for institutional access to EU crypto rails. For banks and corporates, authorised providers like Ripple (CASP + EMI) simplify vendor risk analysis and offer a compliant route for cross-border tokenised payments and stablecoin settlement. The wave also illustrates the documentation and governance bar national regulators are applying, and the jurisdiction-shopping dynamics as firms pick their home-state authority.

What Changed: European Parliament committee adopts the digital euro framework

HIGH

Risk: CBDC / payments market structure | Affected: Banks, PSPs, payment networks | Horizon: Pilot from mid-2027; issuance possibly 2029 | Confidence: High

Facts: On 23 June 2026 the European Parliament's Economic and Monetary Affairs (ECON) committee adopted its position on the single-currency package, backing the digital euro framework by 43 votes to 14 with one abstention. The texts provide for online and offline versions of an ECB-issued digital euro, with cash-like privacy offline, ECB-set holding limits to protect bank deposits, free basic services, and a 12-month pilot from mid-2027 ahead of a possible first issuance in 2029. Negotiating mandates head to the July plenary before trilogue with the Council, which agreed its position in December 2025.

Implications: The digital euro is moving from study to legislation. Banks and payment service providers should plan now for holding limits, mandatory distribution obligations, and offline-payment infrastructure, and watch the trilogue for the final calibration of limits and intermediary compensation. The EU frames the project as reducing dependence on US card networks and dollar stablecoins, a strategic-autonomy driver that will shape European payments for the rest of the decade and sits in direct contrast to the US move to bar a Federal Reserve retail CBDC.

What Changed: FinCEN severs Huione successor H-Pay under Section 311 as DOJ seizes infrastructure

HIGH

Risk: AML / sanctions | Affected: Banks, payment processors, VASPs | Horizon: Immediate (NPRM open) | Confidence: High

Facts: On 23 June 2026, as part of a coordinated US action against Cambodia's Prince Group, FinCEN issued a notice of proposed rulemaking to amend its October 2025 Huione Group designation to add H-Pay Service PLC (a rebrand of the sanctioned Huione Pay) and any successor entities as a "primary money laundering concern," severing them from the US financial system. The same day, the DOJ announced the seizure of cloud backend infrastructure used by Huione subsidiaries to launder billions in crypto investment-fraud and scam proceeds, and OFAC added related designations.

Implications: US financial institutions and VASPs must treat H-Pay and any Huione successors as blocked, high-risk counterparties and update sanctions/AML screening, wallet attribution, and on/off-ramp monitoring to capture indirect flows through mixers and high-risk exchanges. The rebrand-and-continue pattern shows that designations must reach "successor entities," and Section 311 is now an established tool against crypto-enabled scam ecosystems that foreign FIUs are likely to mirror.

What Changed: Dubai VARA fines MEXC and KuCoin (unlicensed) and CoinMENA (AML)

HIGH

Risk: Licensing / AML enforcement | Affected: Offshore exchanges, licensed VASPs, treasuries | Horizon: Immediate | Confidence: High

Facts: Dubai's Virtual Assets Regulatory Authority (VARA) issued enforcement measures and financial penalties against MX Global (operating as MEXC) and KuCoin for providing broker-dealer and exchange services to customers in Dubai without a VARA licence (MEXC's breach spanning 2022 to April 2026, with KYC failures), directing them to cease and desist. Separately, VARA penalised already-licensed CoinMENA for AML programme compliance failures found during inspection. VARA did not publicly disclose the fine amounts.

Implications: VARA has shifted from licensing build-out to active enforcement on two fronts at once: unlicensed "fly-in" platforms serving Dubai residents, and post-licensing governance at authorised firms. Treasuries and institutions using offshore exchanges for liquidity must verify VARA status before dealing with platforms that have material UAE user bases, and licensed firms should expect inspection-driven scrutiny of AML systems, sanctions screening, and STR processes.

What Changed: Vietnam adopts AML/CFT action plan with virtual-asset regulation mandate

HIGH

Risk: AML / licensing | Affected: VASPs, banks, fintechs in Vietnam | Horizon: Phased through grey-list review | Confidence: High

Facts: On 26 June 2026 Vietnam's government adopted a national action plan to combat money laundering, terrorism financing and proliferation financing, with the explicit objective of exiting the FATF's increased-monitoring list. The plan instructs authorities to implement risk-based supervision for financial institutions and designated non-financial businesses and to "take action to regulate virtual assets and virtual asset service providers."

Implications: VASPs operating in or targeting Vietnam should anticipate formal licensing, registration and reporting obligations as the regime is built out, and banks will need to fold virtual-asset risk into AML assessments. Vietnam is one of the world's highest crypto-adoption markets, so a move from informal tolerance to FATF-aligned supervision is a material shift for cross-border flows and exchange access.

What Changed: FATF June plenary updates grey list and approves seventh virtual-asset implementation report

HIGH

Risk: AML / cross-border | Affected: VASPs, banks, custodians | Horizon: Flows into national guidance | Confidence: High

Facts: At its 17-19 June 2026 plenary, the FATF approved a seventh targeted update on implementation of its virtual-asset standards and announced a new targeted report on DeFi money-laundering exposure. The grey list was reshuffled: Iraq and Bosnia and Herzegovina were added, while Algeria and Namibia were removed, leaving 22 jurisdictions under increased monitoring. The plenary reinforced the supervisory expectations set out in the FATF's Best Practices on Travel Rule Supervision (first published June 2025), and the incoming UK Presidency flagged scam compounds and fraud as priorities.

Implications: Supervisors will use the Travel Rule best practices to benchmark local regimes, increasing pressure on lagging jurisdictions and on VASPs to demonstrate effective originator/beneficiary data collection and screening across on- and off-chain transfers. Firms dealing with counterparties in newly listed jurisdictions (Iraq, Bosnia) should refresh enhanced due diligence; the forthcoming DeFi report signals where the next supervisory frontier lies.

What Changed: Delaware passes GENIUS-aligned banking and stablecoin laws (SB 16/18/19)

HIGH

Risk: Licensing / market structure | Affected: Stablecoin issuers, trust banks, MSBs | Horizon: Phased on signature | Confidence: High

Facts: Delaware's General Assembly passed a three-bill package now on the governor's desk. SB 16 (Banking Modernization Act) defines "digital asset" and "virtual currency" and authorises Delaware banks and trust companies to hold and manage digital assets. SB 19 (Payment Stablecoin Act) creates a licensing regime for stablecoin issuers under the State Bank Commissioner with 1:1 reserve requirements modelled on the federal GENIUS Act. SB 18 (Money Transmission and Virtual Currency Modernization Act) adopts the CSBS model framework already enacted in 30+ states. Parts of SB 16 take effect immediately; SB 19 phases in with GENIUS directives; SB 18 after one year.

Implications: Delaware, the US corporate-domicile hub, is positioning itself as a licensed on-ramp for stablecoin issuers and a registration venue for digital-asset service providers under GENIUS. Expect increased use of Delaware trust and bank charters for institutional custody and tokenisation structures, and watch whether other states accelerate GENIUS-aligned licensing to compete.

What Changed: Korea's PIPC fines Bithumb over cross-border data transfers and issues blockchain privacy rules

MEDIUM

Risk: Data protection / AML overlap | Affected: Exchanges serving Korean users | Horizon: Immediate (corrective order) | Confidence: High

Facts: At its 24 June 2026 plenary session, Korea's Personal Information Protection Commission (PIPC) fined Bithumb 210 million won (about 136,000 US dollars) and issued a corrective order. The PIPC found Bithumb shared its Tether (USDT) order-book data with overseas exchanges from September to November 2025: users had consented to a transfer involving one exchange (Stellar), but member numbers and order data were routed to another (BingX). It also flagged the sharing of names, wallet addresses and, in one case, dates of birth with 13 overseas exchanges for AML checks. The PIPC simultaneously released blockchain-service privacy guidelines warning against placing identifying data on-chain.

Implications: The case puts data-protection compliance, especially cross-border transfers, on par with AML as a first-order risk for exchanges. Firms serving Korean users need accurate disclosure of foreign data recipients, robust consent, and architectures that avoid recording personal identifiers on public chains. The tension between Travel Rule data-sharing and privacy law is now an enforcement reality, not a theoretical conflict.

What Changed: SEC and CFTC seek comment on harmonising portfolio margining

MEDIUM

Risk: Market structure | Affected: Broker-dealers, FCMs, clearing agencies | Horizon: 60-day comment period | Confidence: High

Facts: On 26 June 2026 the SEC and CFTC issued a joint request for public comment on harmonising portfolio-margining frameworks across securities, security-based swaps, futures, swaps and related positions, with a 60-day comment window. The request builds on the agencies' 11 March 2026 memorandum of understanding and comes ahead of US Treasury clearing mandates expected by end-2026. Regulators asked for input on cross-margining, collateral eligibility, risk-management standards and customer protections.

Implications: Firms supporting crypto derivatives cleared alongside traditional products should expect eventual changes to how cross-product margin is calculated, offset and documented, with knock-on effects for capital usage and the segregation treatment of crypto collateral. This is the regulatory plumbing that determines how efficiently crypto futures and options can sit in a unified book; comment letters now will shape the calculus.

What Changed: EBA consults on MiCA penalty methodology for significant tokens

MEDIUM

Facts: On 26 June 2026 the European Banking Authority opened a consultation on a methodology for calculating fines in its role as supervisor of significant asset-referenced tokens (s-ARTs) and significant e-money tokens (s-EMTs) under MiCA Article 131. The two-step approach sets a basic amount and then adjusts for aggravating and mitigating factors, with fines of at least 5 million euros or 3% to 12.5% of total annual turnover depending on the infringement.

Implications: Large stablecoin issuers under direct EBA supervision face a structured, turnover-linked penalty regime that makes breach exposure quantifiable. Compliance teams should map which MiCA obligations (governance, reserve management, disclosure, conduct) most drive penalty exposure and feed that into risk assessments and internal audit plans. Non-EU issuers passporting into the EU should assume harmonised administrative fines rather than lighter national-level sanctions.

What Changed: ASIC extends crypto licensing no-action relief to 30 September 2026

MEDIUM

Risk: Licensing / transition | Affected: Australian-facing digital-asset firms | Horizon: Relief ends 30 Sep 2026; framework ~April 2027 | Confidence: High

Facts: On 27 June 2026 ASIC extended its sector-wide no-action position for digital-asset businesses providing financial services to 30 September 2026 (from 30 June), giving firms three more months to apply for or vary an Australian Financial Services (AFS) licence, and broadened it to cover authorised-representative and intermediary arrangements. ASIC has received roughly 30 licence applications since updating Information Sheet 225 in October 2025, and the Corporations Amendment (Digital Assets Framework) Act 2026 is expected to take effect around April 2027.

Implications: This is transitional relief, not a softening. ASIC has confirmed that many digital-asset products are financial products requiring an AFS licence, and the compliance runway is now firmly dated. Australian-facing digital-asset firms should use the window to lodge or vary applications and map the incoming Digital Assets Framework, because enforcement forbearance ends on 30 September 2026.

What Changed: Kenya tightens crypto rules in push to exit the FATF grey list

MEDIUM

Facts: Kenya, grey-listed by the FATF in February 2024, is accelerating AML/CFT reforms to exit increased monitoring, with virtual-asset risk a named focus. Building on the Virtual Asset Service Providers Act 2025, authorities are tightening crypto oversight and beneficial-ownership frameworks as part of the action plan reviewed by the FATF through 2026.

Implications: Expect clearer VASP registration requirements and stronger enforcement against unlicensed platforms in one of Africa's largest crypto markets. Banks, payment firms and mobile-money operators must ensure AML programmes capture fiat-to-crypto gateways and peer-to-peer transfers, and cross-border institutions dealing with Kenyan counterparties should expect more detailed due-diligence inquiries on virtual-asset exposure.

What Changed: Yellow Card obtains Swiss supervised financial-intermediary status

LOW

Facts: Stablecoin infrastructure and payments firm Yellow Card announced it has obtained AML affiliation in Switzerland as a supervised financial intermediary, operating from Lugano. The status brings it under Swiss AML/CFT obligations and provides a regulated base to offer stablecoin-based cross-border capital flows into emerging markets alongside Swiss and other banking partners.

Implications: For institutions routing payments into African and other high-growth markets via stablecoins, a Swiss-supervised intermediary is a more palatable counterparty than an unsupervised offshore provider. Yellow Card must maintain Swiss-grade AML controls, monitoring and reporting, aligning emerging-market stablecoin rails with FATF expectations. (Source: company announcement; treat as a licensing-status data point.)

What Changed: MAS adds Hyperliquid to its Investor Alert List

LOW

Risk: Consumer protection / licensing | Affected: Singapore users, DeFi platforms | Horizon: Immediate | Confidence: High

Facts: On 26 June 2026 the Monetary Authority of Singapore added the decentralised exchange Hyperliquid to its Investor Alert List, flagging that it is neither licensed nor authorised in Singapore. The addition follows Bybit, KuCoin and Bitget on the same list. Hyperliquid responded that, as permissionless infrastructure with user self-custody, it has never claimed to be MAS-licensed; MAS clarified the listing is not an outright ban.

Implications: Hyperliquid is among the first major DeFi protocols flagged this way, signalling MAS's willingness to apply its alert mechanism to decentralised venues, not just centralised exchanges. Regulated firms must treat listed entities as high-risk counterparties in onboarding and marketing controls, and the move sharpens the question of how permissionless protocols sit within a licensing perimeter.

What Changed: Texas fines Ramad Pay for AML failures; FBI flags OneCoin remission deadline

LOW

Risk: AML enforcement / investor restitution | Affected: MSBs, crypto money-services firms | Horizon: Immediate; claims by 30 Jun 2026 | Confidence: Medium

Facts: The Texas Department of Banking announced an enforcement action against Ramad Pay, Inc. for AML/CFT violations tied to its money-services business. Separately, the FBI reminded victims of the OneCoin fraud (2014-2019) to file for compensation under a DOJ remission program covering more than 40 million US dollars in forfeited assets before the 30 June 2026 deadline.

Implications: State banking regulators are actively using AML/CFT enforcement against crypto-linked money-services businesses, so firms must harmonise state-level licensing and BSA/AML compliance with federal GENIUS/FinCEN obligations across their US footprint. The OneCoin remission process underscores continued DOJ appetite for investor restitution in legacy crypto-fraud cases.

Risk Impact Matrix

Jur.DevelopmentRisk CategorySeverityAffectedTimeline
EUMiCA transition ends; ESMA wind-down orderLicensing / market accessCriticalCASPs, EU-facing institutions1 July 2026
UKBoE systemic stablecoin policy + draft CodePrudential / market structureCriticalStablecoin issuers, banks, PSPsConsult to 22 Sep 2026
USFinCEN H-Pay Section 311 + DOJ seizureAML / sanctionsHighBanks, processors, VASPsNPRM open
EUMiCA CASP licensing wave (Ripple, NAGA, OpenPayd)Market structure / competitionHighCASPs, banks, PSPsImmediate
EUEU Parliament committee adopts digital euro frameworkCBDC / payments market structureHighBanks, PSPs, payment networksPilot mid-2027
AEVARA fines MEXC, KuCoin, CoinMENALicensing / AML enforcementHighOffshore exchanges, licensed VASPsImmediate
VNVietnam AML/CFT action plan + VA mandateAML / licensingHighVASPs, banks, fintechsPhased
USDelaware GENIUS-aligned banking/stablecoin lawsLicensing / market structureHighIssuers, trust banks, MSBsPhased on signature
GLOBALFATF plenary: grey-list changes + 7th VA updateAML / cross-borderHighVASPs, banks, custodiansFlows to national guidance
KRPIPC fines Bithumb; blockchain privacy rulesData protection / AML overlapMediumExchanges serving KoreaImmediate
USSEC-CFTC portfolio-margining harmonisation reviewMarket structureMediumBroker-dealers, FCMs, clearing60-day comment
EUEBA MiCA penalty methodology consultationEnforcement / prudentialMediumSignificant ART/EMT issuersConsultation open
KEKenya crypto-rule tightening for grey-list exitAML / licensingMediumVASPs, banks, mobile moneyOngoing review
AUASIC extends crypto licensing no-action reliefLicensing / transitionMediumAustralian-facing digital-asset firmsRelief ends 30 Sep 2026
CHYellow Card Swiss supervised-intermediary statusLicensing / AMLLowStablecoin payment providersImmediate
SGMAS adds Hyperliquid to Investor Alert ListConsumer protection / licensingLowSingapore users, DeFi platformsImmediate
USTexas Ramad Pay AML action; OneCoin remissionAML enforcement / restitutionLowMSBs, crypto money-services firmsClaims by 30 Jun 2026

Regulations move faster than headlines.

One weekly brief. Every development that matters. No noise.

Read by compliance and legal teams at Standard Chartered, Lloyds, Freshfields, and Loyens & Loeff.

Free. No spam. Unsubscribe anytime.

Cross-Signal Patterns

Pattern: The stablecoin rulebook converges across jurisdictions

Linked Signals: BoE systemic stablecoin, Delaware GENIUS laws, EBA penalty methodology

What it means: The UK, the US (federal GENIUS plus Delaware state implementation) and the EU are settling on the same stablecoin design: high-quality liquid reserves, strict par redemption, no yield to holders, and licensed issuers. The remaining divergence is on scale (the UK's 40 billion pound guardrail) and enforcement calibration (the EBA's turnover-linked fines). Multinational issuers should design one global compliance framework to the strictest common denominator rather than per-jurisdiction patchwork.

Confidence: High

Pattern: Enforcement shifts from licensing to supervision and successor-chasing

Linked Signals: VARA enforcement, FinCEN H-Pay, PIPC Bithumb, MAS Hyperliquid

What it means: Regulators that spent two years building licensing regimes are now exercising them. VARA is penalising both unlicensed entrants and AML failings at licensed firms; FinCEN is chasing rebranded successor entities; Korea is enforcing data-protection law against an exchange; MAS is flagging DeFi protocols. The common thread: being unlicensed, or being licensed but non-compliant, now carries concrete monetary and access consequences.

Confidence: High

Pattern: FATF pressure pulls emerging markets into VASP supervision

Linked Signals: FATF June plenary, Vietnam AML plan, Kenya grey-list push

What it means: The grey-list mechanism is doing exactly what it is designed to do: high-adoption emerging markets (Vietnam, Kenya) are building VASP supervision and Travel Rule capacity to avoid or exit increased monitoring. For global institutions, this is a leading indicator of where new licensing perimeters and counterparty due-diligence requirements will appear next, and of where correspondent-banking risk is being actively managed down.

Confidence: Medium

Strategic Implications

1. Close the MiCA counterparty gap before the weekend

Treat 1 July as a hard control date. Run every EU-facing crypto counterparty against the ESMA and national CASP registers, document the check, and freeze or migrate any relationship with a firm relying on lapsing national registration. Reverse-solicitation is a narrow exception, not a strategy. [Traced to: ESMA wind-down order, MiCA CASP licensing wave]

2. Build stablecoin compliance to the converging global standard

The UK, US and EU now share a recognisable stablecoin template. Issuers and institutional users should design reserve, redemption, segregation and no-yield controls to satisfy all three at once, while planning for jurisdiction-specific limits such as the BoE's 40 billion pound guardrail and the EBA's turnover-linked fines. [Traced to: BoE systemic stablecoin, Delaware GENIUS laws, EBA penalty methodology]

3. Refresh sanctions and successor-entity screening for scam networks

The H-Pay action shows designations now explicitly reach "successor entities." Update screening, wallet attribution and on/off-ramp monitoring to capture rebrands and indirect flows through mixers and high-risk exchanges, and expect foreign FIUs to mirror Section 311-style measures against crypto-enabled scam ecosystems. [Traced to: FinCEN H-Pay, FATF June plenary]

4. Reconcile Travel Rule data-sharing with privacy law

The PIPC fine against Bithumb makes the tension between AML data transfers and data-protection law a live enforcement risk. Firms must obtain accurate cross-border transfer consent, disclose foreign recipients precisely, and avoid putting personal identifiers on-chain, even when sharing originator/beneficiary data for Travel Rule compliance. [Traced to: PIPC Bithumb, FATF June plenary]

5. Track emerging-market VASP regimes as forward licensing indicators

Vietnam and Kenya advancing AML reforms under FATF pressure preview where new VASP licensing and due-diligence obligations will land. Institutions with exposure to high-adoption markets should monitor implementing rules (registration, Travel Rule timing, beneficial ownership) and build them into onboarding and correspondent-banking risk now. [Traced to: Vietnam AML plan, Kenya grey-list push, FATF June plenary]

Sources

  1. ESMA - Markets in Crypto-Assets Regulation (MiCA)
  2. Bank of England - Policy statement and draft rules on regulating systemic stablecoins
  3. Ripple - Ripple secures preliminary MiCA CASP licence
  4. FinCEN - Proposes to sever H-Pay Service PLC and other Huione Group successors
  5. DOJ - Seizes backend infrastructure used by the Huione Group
  6. VARA - Regulatory notices
  7. Government of Vietnam - New action plan for combatting money laundering and terrorism financing
  8. FATF - Outcomes of the June 2026 Plenary
  9. Delaware General Assembly - Senate Bill 19
  10. PIPC - Personal Information Protection Commission (English)
  11. SEC - SEC, CFTC Seek Public Comment on the Harmonization of Portfolio Margining Frameworks
  12. EBA - Publications and media
  13. FATF - Kenya country page
  14. MAS - Investor Alert List
  15. Texas Department of Banking
  16. Bank of England - Draft Code of Practice for sterling-denominated systemic stablecoin issuers (PDF)
  17. FATF - Best Practices on Travel Rule Supervision, 2025 (PDF)
  18. European Parliament - Digital euro: MEPs want to ensure sovereignty, privacy and financial stability
  19. ASIC - Media releases

If you found this useful, please share it.

Questions or feedback? Contact us

MCMS Brief • Classification: Public • Sector: Digital Assets • Region: Global

Disclaimer: This content is for educational and informational purposes only. It is NOT financial, investment, or legal advice. Cryptocurrency investments carry significant risk. Always consult qualified professionals before making any investment decisions. Make Crypto Make Sense assumes no liability for any financial losses resulting from the use of this information. Full Terms