The non-profit research and advocacy group Coin Center has issued a comprehensive response to the Department of the Treasury regarding proposed regulations for stablecoin issuers, warning that the current trajectory of rulemaking could lead to an unprecedented expansion of financial surveillance. In a formal filing addressed to the Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC), the advocacy group argued that the implementation of the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act stands at a critical juncture. The organization posits that while stablecoins offer the potential for a more efficient and open digital economy, poorly designed regulatory requirements could transform these assets into the foundation of a pervasive, identity-linked surveillance system that surpasses the intrusive nature of traditional banking.
The Regulatory Landscape of the GENIUS Act
The GENIUS Act represents a significant legislative effort to provide a federal framework for "Permitted Payment Stablecoin Issuers" (PPSIs). As the digital asset market matures, U.S. regulators have sought to bring stablecoins—digital assets pegged to the value of the U.S. dollar—under a standardized oversight regime. The primary goal of the act is to ensure that issuers maintain adequate reserves and adhere to Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT) protocols.
However, the specific rulemaking process overseen by FinCEN and OFAC has raised alarms within the cryptocurrency industry. Coin Center’s response emphasizes that while regulated financial intermediaries should maintain lawful compliance programs and screen their direct customers, the mandate should not extend to the generalized monitoring of peer-to-peer (P2P) activity on public blockchains. The filing argues that forcing issuers to build databases that link static identity records to permanent, public blockchain histories creates profound security and privacy risks.
The Operational Risk of Data Overcollection
A central pillar of Coin Center’s argument is that the overcollection of sensitive customer information is not merely a privacy concern but a direct operational and AML/CFT risk. The organization contends that the traditional "Know Your Customer" (KYC) model—which relies on the collection of driver’s licenses, passport scans, and Social Security numbers—is increasingly obsolete in the face of sophisticated cybercrime.
According to the filing, the current reliance on static identifiers creates "honeypots" for hackers. When financial institutions aggregate massive amounts of personally identifiable information (PII), they become primary targets for malicious actors. Once stolen, this data is weaponized to commit further identity fraud, creating a self-perpetuating cycle of illicit finance. Coin Center cites data from the Identity Theft Resource Center’s (ITRC) 2025 annual report, which found that data compromises in the U.S. have transitioned from mass identity theft to pervasive identity fraud where stolen credentials are used with surgical precision.
Supporting this claim, a 2024 study from the University of Brasília analyzed 506 breaches across 274 publicly traded U.S. companies and concluded that financial institutions are the most frequently breached entities. This is largely because the information held by these institutions—such as the data used to pass identity checks—is the most valuable for bypassing AML/CFT controls in other sectors.
Quantifying the Scale of Identity-Related Fraud
The scale of identity-related crime highlights the failure of legacy compliance rituals to deter sophisticated criminals. FinCEN’s own data suggests a growing crisis; in 2021, approximately 1.6 million Bank Secrecy Act (BSA) reports—representing 42% of the total 3.8 million reports—involved identity-related suspicious activity. By 2023, the figure linked to identity-related suspicious activity reached an estimated $394 billion.
The Federal Trade Commission’s (FTC) Consumer Sentinel Network Data Book further illustrates this upward trend. In 2004, the number of fraud and identity theft reports stood at approximately 860,000. By 2014, that number had risen to 2.6 million, and by 2024, it surged to over 6.4 million. Similarly, the FBI’s 2025 Internet Crime Report documented over 67,000 complaints involving personal data breaches and over 31,000 complaints involving identity theft.
Coin Center argues that these statistics prove that the current regulatory obsession with data volume does not equate to effective security. Instead, a system that forces legitimate users to overshare sensitive data while failing to stop criminals is "outdated and backwards." The organization suggests that FinCEN should measure the success of AML programs by the actual reduction in illicit finance and fraud, rather than the volume of data collected.
The Unique Vulnerabilities of Blockchain-Linked Identities
The intersection of static identity records and public blockchain data creates a unique set of risks that do not exist in the traditional banking sector. In a standard bank, transaction records are private and siloed within the institution. Conversely, stablecoins operate on public ledgers like Ethereum or Bitcoin, where every transaction is visible to the world.
If a PPSI is forced to link a customer’s real-world identity to their blockchain address, a data breach would expose much more than just a Social Security number. It would reveal a "persistent financial graph" of every payment, counterparty, and donation the user has ever made. Coin Center warns that this linkage could be exploited by foreign adversaries to target dissidents or journalists, and by domestic criminals to identify wealthy individuals for "wrench attacks"—physical violence aimed at coercing the transfer of digital assets.
From a constitutional perspective, Coin Center argues that this level of surveillance may violate the Fourth Amendment. Referencing the Supreme Court’s decision in Carpenter v. United States, which held that cell-phone users do not waive their privacy rights to their physical movements simply by using a phone, the filing suggests that stablecoin users should not be treated as having voluntarily exposed their entire financial history simply by transacting on a public network.
Recommendations for a Privacy-Preserving Framework
To mitigate these risks, Coin Center proposed five specific courses of action for FinCEN and OFAC:
- Recognize Overcollection as a Risk: Regulators should explicitly state that collecting too much information is a security vulnerability that can facilitate money laundering and fraud.
- Permit Privacy-Preserving Tools: PPSIs should be allowed to use innovative technologies such as zero-knowledge proofs (ZKPs), portable credentials, and attribute-based proofs. These tools allow an institution to verify a user’s eligibility (e.g., "this person is a U.S. citizen over 18") without needing to store the underlying sensitive data.
- Establish Data-Minimized Onboarding Pilots: The government should create "safe harbors" for institutions that experiment with onboarding methods that minimize data retention.
- Clarify Secondary Market Obligations: The final rules should clarify that stablecoin issuers are not responsible for monitoring every secondary market transfer between third parties, provided those parties are not direct customers of the issuer.
- Require Lawful Process for Freezes: Before a PPSI is ordered to freeze the property of a U.S. person on the secondary market, there should be a requirement for a warrant or similar lawful process to ensure procedural safeguards.
NIST Guidelines and the Future of Digital Identity
The filing draws heavily on the National Institute of Standards and Technology (NIST) and its Digital Identity Guidelines (Special Publication 800-63). NIST has increasingly recognized the need for "secure, usable, and privacy-preserving identity solutions" in response to emerging threats.
FinCEN’s 2024 Financial Trend Analysis identifies three critical points in the identity process: validation (ensuring the evidence is genuine), verification (confirming the evidence belongs to the person presenting it), and authentication (ensuring the person accessing the account is the same person who was verified). Coin Center argues that modern technology can satisfy these three requirements more effectively than the current "manual JPG upload" system. By utilizing dynamic risk-scoring and cryptographically secure credentials, PPSIs can achieve higher levels of assurance while simultaneously reducing the risk of identity theft for their customers.
Implications for the Global Digital Economy
The outcome of the GENIUS Act rulemaking will likely set a global precedent. If the U.S. adopts a "surveillance-first" approach, it may drive innovation offshore to jurisdictions with more balanced privacy protections. Conversely, if FinCEN and OFAC embrace the privacy-preserving models suggested by Coin Center, the U.S. could lead the way in creating a digital dollar infrastructure that is both secure and compatible with democratic values.
The advocacy group concluded its filing by urging regulators to draw a clear line between regulated relationships and generalized monitoring. By encouraging data-minimized compliance and targeted technical capabilities, the government can fulfill its mandate to combat illicit finance without compromising the fundamental privacy and security of the American public. The debate now moves to the Treasury Department, which must weigh these security concerns against the traditional mandates of the Bank Secrecy Act.
