Two of the most controversial U.S. proposals around crypto privacy and self-custody are no longer moving toward final rules.
On October 5, the Financial Crimes Enforcement Network withdrew a proposed rule targeting certain transactions involving unhosted wallets and a separate proposal that would have imposed a special measure on convertible virtual currency mixing.
FinCEN says it considered the public comments and withdrew both proposals as part of the administration’s deregulatory agenda and an effort to make digital-asset regulation fit for purpose.
The immediate result is straightforward. The specific reporting architecture proposed for unhosted-wallet transactions is not being finalized, and the specific special measure aimed at mixing as a class of transactions is also being withdrawn.
The legal conclusion is less dramatic than some crypto headlines will make it sound.
Two Different Proposals Died on the Same Day
The unhosted-wallet proposal would have imposed additional recordkeeping, verification and reporting duties on financial institutions for certain convertible virtual currency transactions involving wallets not hosted by a regulated intermediary.
The mixing proposal took a different route. It sought to treat convertible virtual currency mixing as a class of transactions of primary money-laundering concern and impose a special measure under the Bank Secrecy Act framework.
Both approaches attempted to regulate by identifying a transaction type that regulators considered unusually risky and adding rules around the category.
FinCEN has now withdrawn both rather than carrying them into the final-rule stage.
Withdrawal Is Not a Legal Safe Harbor for Mixers
This is the most important distinction.
FinCEN did not announce that mixing services are exempt from anti-money-laundering law, sanctions law or criminal enforcement. It withdrew two proposed rules.
Existing Bank Secrecy Act obligations still apply to covered financial institutions. Sanctions administered by the Treasury Department remain separate. Suspicious-activity reporting, customer due diligence and other obligations do not vanish because one proposed special measure is gone.
A service can therefore face legal risk because of what it does, who it serves or how it handles funds even without a rule declaring the entire transaction class subject to an extra measure.
Self-Custody No Longer Gets This Particular Reporting Layer
The unhosted-wallet withdrawal matters for a different reason. Self-custody has always created a difficult boundary for financial regulation because the wallet is software controlled by the user rather than an account held by an intermediary.
The withdrawn proposal would have placed additional obligations on regulated institutions interacting with certain self-hosted wallets. Without it, the government is not adding that specific architecture as originally drafted.
That does not make a self-hosted wallet invisible. Blockchain analytics, sanctions screening, existing transaction-monitoring duties and subpoenas can still connect activity to regulated endpoints.
Optimisus recently made the same distinction when zk.money relaunched private payments while leaving the Ethereum deposit itself publicly visible. Privacy is rarely one switch. It is a set of boundaries between what the system reveals, what an intermediary knows and what law requires the intermediary to do.
This May Signal a More Targeted Enforcement Philosophy
The withdrawal can reasonably be read as a move away from adding broad transaction-class rules, but it should not be confused with the end of enforcement against illicit finance.
There is a policy difference between saying “mixing as a category gets a special rule” and saying “transactions tied to sanctions evasion, theft or laundering will be investigated under existing authorities.”
The former regulates a technological behavior at category level. The latter focuses more heavily on conduct, counterparties and specific legal obligations.
Whether that is the durable direction will depend on future Treasury and FinCEN actions. One withdrawal notice cannot answer every privacy-policy question.
Privacy Tools Still Need an Operating Model, Not Just Cryptography
For wallet builders and exchanges, the practical lesson is not that compliance became optional.
A self-custodial wallet may not itself be a regulated financial institution, while an exchange, broker, money-services business or other intermediary may have extensive obligations when funds enter or leave it. Privacy protocols can reduce public visibility without changing that legal perimeter.
Optimisus has also covered the European version of this distinction, where rules restricting licensed providers from custodying privacy coins still preserve a separate role for self-hosted software.
The emerging question is less “is privacy allowed?” and more specific: who controls the funds, who intermediates the transaction, what information exists at the boundary and which legal duty applies to that participant.
FinCEN’s October 5 decision removes two proposed answers. It does not remove the question.
This is not financial advice.
Sources
- FinCEN — Withdrawals of proposed digital-asset-related rules — Primary announcement confirming withdrawal of both proposals.
- Federal Register — Unhosted-wallet proposal withdrawal — Official public-inspection document.
- Federal Register — Mixing special-measure proposal withdrawal — Official public-inspection document.

