In a comprehensive formal comment filed with the Financial Crimes Enforcement Network (FinCEN), Coin Center, the leading non-profit research and advocacy group for cryptocurrency policy, has called for a fundamental shift in how the United States approaches Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT) compliance. The filing, directed toward the Department of the Treasury’s ongoing efforts to modernize the Bank Secrecy Act (BSA), argues that the current regulatory insistence on the collection and retention of sensitive personal information has become a primary driver of cybercrime and financial fraud. Coin Center contends that the legacy "know your customer" (KYC) rituals, which rely on the transmission of unencrypted identity documents, have created massive "honeypots" of data that are increasingly weaponized by sophisticated criminal actors.
The Shift Toward Modernization and Its Current Failures
The Department of the Treasury and FinCEN have recently embarked on a mission to modernize the AML/CFT framework to better address the realities of a digital-first global economy. While Coin Center expressed support for FinCEN’s recognition that financial institutions are best positioned to assess their own risks, the advocacy group warned that the current definition of "risk" is dangerously narrow. Traditionally, regulators have viewed risk primarily through the lens of a financial institution failing to collect enough information. Coin Center argues that the "overcollection" of data now presents an equal, if not greater, threat to the integrity of the financial system.
Under the current regime, Americans are frequently required to submit high-resolution scans of driver’s licenses, passports, and "selfie" photographs to open even basic financial accounts. Coin Center’s filing describes these signals as "trivially forged" by modern criminals using artificial intelligence and sophisticated digital editing tools. Consequently, the process provides a false sense of security for regulators while imposing a massive security burden on the public. When financial institutions store these dossiers, they become prime targets for hackers. The stolen data is then used to facilitate the very crimes—identity theft, fraud, and money laundering—that the regulations were intended to prevent.
A Chronology of Regulatory Evolution and the Rise of Identity Fraud
To understand the urgency of Coin Center’s proposal, it is necessary to examine the timeline of U.S. financial surveillance laws. The Bank Secrecy Act of 1970 established the initial requirements for financial institutions to assist the government in detecting and preventing money laundering. Following the September 11 attacks, the USA PATRIOT Act of 2001 significantly expanded these requirements, introducing mandatory Customer Identification Programs (CIP) that codified the collection of names, dates of birth, and Social Security numbers.
By 2020, the Anti-Money Laundering Act (AMLA) was passed to modernize these aging statutes, leading to FinCEN’s current efforts to refine the rules for a digital age. However, during this same period, the nature of crime has shifted. The Identity Theft Resource Center’s (ITRC) 2025 annual report, cited in the filing, highlights a transition from mass identity theft to "pervasive identity fraud," where stolen credentials are weaponized with precision.
The ITRC data reveals a drastic increase in the compromise of "static identifiers"—data points that are difficult or impossible to change, such as Social Security numbers and driver’s license details. Between 2020 and 2025, the frequency of these compromises reached record highs, directly correlating with the increasing volume of data required by financial institutions under AML mandates.
Supporting Data: The Financial Cost of Insecure Identity Systems
Coin Center’s argument is supported by a growing body of empirical evidence suggesting that the current AML framework is failing to achieve its core objectives. According to a 2024 study from the University of Brasília, financial institutions are the most frequently breached entities among publicly traded U.S. companies. These breaches are uniquely damaging because they expose the specific credentials used to bypass AML/CFT controls.
The National Institute of Standards and Technology (NIST) has also flagged the emergence of new threats to identity-proofing systems. In its "Digital Identities—Mobile Driver’s License (mDL)" publication, NIST noted that financial institutions are primary targets for attackers seeking to drain accounts and open fraudulent lines of credit. FinCEN’s own data underscores the scale of the crisis. In 2021, identity-related suspicious activity was linked to approximately $212 billion in illicit funds. By 2023, that figure had ballooned to an estimated $394 billion.
Furthermore, FinCEN’s 2024 Financial Trend Analysis revealed that nearly 42% of all Bank Secrecy Act reports involved identity-related suspicious activity. The Federal Trade Commission (FTC) reported a staggering increase in fraud and identity theft complaints, rising from approximately 860,000 in 2004 to over 6.4 million in 2024. These figures suggest that the more data the government requires institutions to collect, the more tools criminals have at their disposal to commit financial crimes.
Proposed Technological Solutions: Privacy-Preserving Digital Identity
The central recommendation of Coin Center’s filing is for FinCEN to explicitly permit and encourage the use of alternative, privacy-preserving onboarding methods. Rather than retaining raw copies of sensitive documents, the group advocates for the adoption of modern cryptographic tools, including:
- Portable Credentials: Digital identities that users can carry across different platforms without needing to resubmit raw PII for every new service.
- Attribute-Based Proofs: Utilizing technologies like Zero-Knowledge Proofs (ZKP) to allow a user to prove a specific fact—such as "I am over 18" or "I am a U.S. citizen"—without revealing their birthdate, address, or full identity.
- Dynamic Risk-Scoring Mechanisms: Using real-time data and behavioral patterns to assess risk rather than relying on static, easily stolen identifiers.
Coin Center argues that success in an AML framework should not be measured by the volume of information stored in a database, but by the actual reduction in illicit finance and fraud. A modern framework should reward institutions that can verify relevant facts with "less data, fewer honeypots, and stronger privacy protections."
Broader Impact and Policy Implications
The implications of FinCEN’s eventual decision on these matters extend far beyond the cryptocurrency industry. If FinCEN adopts a risk-based approach that recognizes overcollection as a liability, it could set a global standard for financial privacy. Conversely, continuing the current trajectory may exacerbate the risks of warrantless financial surveillance and political abuse.
Coin Center’s filing highlights that financial transactions reveal intimate details of a person’s life, including their memberships, beliefs, and associations. In the hands of hostile administrations or foreign adversaries, centralized databases of financial activity can be used for discrimination, debanking, or the targeting of journalists and dissidents. By shifting toward a decentralized, privacy-preserving identity model, the U.S. could protect the "freedom, dignity, and security of everyday Americans" while simultaneously making the financial system more resilient to cyberattacks.
The organization concludes that the current compliance regime often mistakes "examiner comfort for public safety." Regulators are accustomed to seeing the same invasive data collection practices they have overseen for decades, even as those practices become counterproductive. Coin Center urges FinCEN to treat the good-faith deployment of privacy-preserving tools as an "innovative activity" capable of achieving superior AML/CFT outcomes.
Reaction from the Industry and Future Outlook
While FinCEN has not yet issued a final ruling on the proposed modernization of AML/CFT programs, the industry reaction to Coin Center’s filing has been largely positive among privacy advocates and fintech innovators. Many industry leaders have long argued that the "Travel Rule" and other data-sharing mandates are incompatible with the decentralized nature of blockchain technology and the heightened cybersecurity risks of the 21st century.
As FinCEN reviews the comments from Coin Center and other stakeholders, the focus will likely remain on whether the agency is willing to move away from "legacy expectations." The transition to a modern AML framework will require a significant cultural shift within regulatory bodies, moving from a "collect-everything" mindset to a "verify-and-minimize" philosophy.
The outcome of this regulatory process will determine the security of the American financial system for the next decade. As the FBI’s 2025 Internet Crime Report demonstrates, with tens of thousands of complaints regarding personal data breaches and identity theft filed annually, the status quo is increasingly untenable. Coin Center’s proposal offers a path toward a system where identity can be verified without being compromised, potentially ending the cycle of data-driven fraud that currently plagues the global economy.



