As the United States Senate prepares for a decisive and closely watched vote on the Clarity Act, congressional drafters have introduced last-minute revisions to the accompanying Blockchain Regulatory Certainty Act (BRCA) in a strategic bid to secure the elusive 60 votes required to clear the chamber. While the updated legislative text preserves critical regulatory exemptions for non-controlling blockchain developers under the Bank Secrecy Act (BSA), it notably strips away explicit protections shielding developers from federal criminal liability under 18 U.S.C. § 1960.
This eleventh-hour compromise highlights the delicate legislative balancing act lawmakers are performing as they attempt to integrate decentralized technologies into the traditional financial regulatory framework. For advocacy groups like Coin Center, which has championed the BRCA’s comprehensive protections for years, the inclusion of statutory non-custodial exemptions marks a historic milestone, even as the omission of criminal liability safeguards leaves open-source software creators exposed to aggressive federal prosecution.
Legislative Background and the Core Debate
At the heart of the BRCA is a fundamental effort to establish a statutory boundary between centralized financial intermediaries and decentralized software developers. Traditional financial regulations—such as those enforced by the Financial Crimes Enforcement Network (FinCEN)—impose stringent anti-money laundering (AML) and know-your-customer (KYC) obligations on entities that act as money transmitters. These centralized businesses, including traditional cryptocurrency exchanges and custodial wallet providers, maintain operational control over customer funds and play a trusted intermediary role in moving assets.
In stark contrast, open-source blockchain developers and infrastructure operators, such as decentralized network validators and node operators, typically write and publish immutable software code that enables peer-to-peer transactions. These developers do not take custody or control of user funds, nor do they possess the technical capability to monitor or halt transactions executed on public, permissionless blockchains.
Without clear statutory distinctions, this operational ambiguity has left developers vulnerable to shifting regulatory interpretations. Over recent years, aggressive federal prosecutors have increasingly targeted software creators, arguing that the mere distribution of general-purpose privacy or transaction-mixing tools constitutes the operation of an unlicensed money-transmitting business when those tools are co-opted by bad actors for illicit financial activities. Proponents of the BRCA argue that treating code as a regulated financial service represents a severe regulatory overreach that threatens foundational technological innovation and chills protected speech under the First Amendment.
Evolution of the BRCA and the Revised Legislative Text
The newly revised text of the BRCA makes substantial headway on the civil regulatory front by attempting to codify a control-based regulatory approach. Section 10604(c) of the updated bill explicitly dictates that a qualifying "non-controlling blockchain developer or provider" shall not be classified as:
- A "money transmitting business" under 31 U.S.C. § 5330;
- A "money transmitter" under regulatory definitions promulgated by FinCEN; or
- A specified "financial institution" under Title 31 of the United States Code.
Furthermore, the revised legislation extends these protections to cover software development, self-custody infrastructure, and related network activities against analogous state and federal registration mandates. By embedding these protections into federal statute, Congress would essentially codify the foundational control-based framework first articulated in FinCEN’s guidance back in 2019, providing a much-needed federal baseline against arbitrary state-level regulatory enforcement actions.
However, the major point of contention centers on what the revised text leaves out. Earlier drafts of the BRCA explicitly shielded qualifying non-controlling developers from being prosecuted under 18 U.S.C. § 1960, the primary federal criminal statute used to penalize unlicensed money transmitting businesses. The removal of this explicit criminal safe harbor has alarmed digital asset advocates and legal scholars alike.
The Legal Shadow of Section 1960 and Past Prosecutions
The debate over Section 1960 is not merely theoretical; it is rooted in high-profile federal indictments that have rattled the cryptocurrency development community. Prominent developers behind privacy-enhancing tools and decentralized applications, such as Tornado Cash and Samourai Wallet, have faced severe criminal charges under Section 1960(b)(1)(B) and (C).
While federal prosecutorial guidelines have evolved—notably following a directive issued by former Deputy Attorney General Todd Blanche instructing the Department of Justice (DOJ) to exercise restraint in digital asset cases premised solely on unwitting regulatory violations—statutory ambiguities remain. Section 1960 is divided into multiple subsections with distinct legal thresholds:
- Subsections (A) and (B): These provisions explicitly target money transmitting businesses that operate without a required state license or fail to comply with federal registration mandates under 31 U.S.C. § 5330. Legal experts suggest that because the revised BRCA explicitly exempts non-controlling developers from these underlying registration requirements, defendants will possess a significantly strengthened defense against prosecutions brought under these specific subsections. It is logically inconsistent, legal analysts argue, to criminalize an entity for failing to obtain a license that federal regulators explicitly state they do not need.
- Subsection (C): Unlike its companion subsections, Section 1960(b)(1)(C) is broader, more ambiguous, and is not explicitly contingent upon a failure to register with FinCEN or obtain a state license. The DOJ has historically utilized this subsection to pursue criminal charges against open-source developers regardless of their custodial status. Because the revised BRCA fails to carve out a specific exemption for Section 1960(c), prosecutors retain the legal leeway to argue that the act of writing and publishing decentralized code constitutes unlicensed money transmission under this broader statutory umbrella.
Industry Reactions and Expert Analysis
The decision by congressional leaders to truncate the criminal liability protections in pursuit of the 60 Senate votes necessary to break potential filibusters has drawn mixed reactions from legal experts, policy advocates, and digital asset stakeholders.
Supporters of the compromise emphasize the pragmatic reality of the legislative process. Passing any coherent regulatory framework for digital assets in a divided Congress is a monumental task. Securing explicit civil and regulatory certainty under federal law for millions of developers represents an unprecedented leap forward. For the first time, federal statute would formally recognize that building underlying blockchain infrastructure does not automatically transform a software engineer into a regulated financial institution.
Conversely, civil liberties advocates and cryptocurrency defense organizations express deep disappointment over the unresolved criminal exposure. Critics point out that leaving the interpretation of Section 1960 up to the courts creates a chilling effect on open-source software development. Developers remain hesitant to publish code or contribute to decentralized toolsets out of fear that an overly aggressive prosecutor could interpret the downstream utility of their software as a criminal enterprise.
Furthermore, legal challenges are already underway to address these constitutional questions. Independent legal efforts—such as a declaratory judgment lawsuit filed by Coin Center fellow Michael Lewellen against the DOJ—seek judicial clarity to establish that the development and maintenance of non-custodial software code does not constitute criminal conduct. With the BRCA falling short of providing statutory immunity from criminal prosecution, these ongoing judicial proceedings assume even greater significance for the future of decentralized technology in the United States.
Broader Implications and Outlook
As the Senate prepares for tomorrow’s pivotal vote on the Clarity Act and its amended BRCA component, the legislative landscape surrounding digital assets stands at a critical juncture.
If enacted in its current form, the revised legislation will establish a robust, federally backed regulatory shield protecting non-custodial developers from burdensome and inappropriate anti-money laundering registration requirements. This achievement will provide foundational legal stability for the civil side of the ecosystem, reassuring institutional participants and independent developers alike that building open-source infrastructure is a legally protected endeavor.
At the same time, the persistence of the criminal liability loophole means the debate is far from over. If the bill passes, the legal battles over software developers’ rights will shift decisively from Capitol Hill to the federal court system. Lawmakers, prosecutors, and technologists will continue to grapple with the fundamental constitutional questions of how traditional criminal statutes apply to decentralized, immutable software. Whether Congress will eventually revisit the statute to close the Section 1960 gap will likely depend on how federal courts interpret the boundaries of code, commerce, and criminal culpability in the years ahead.



