The Blockchain Association told five federal agencies in a 15-page comment letter that customer identification requirements for stablecoin issuers should remain confined to primary-market relationships, arguing that extending them to secondary-market transfers exceeds what the GENIUS Act authorizes.
What the Proposal Does
The joint rule, published at 91 Fed. Reg. 37,234 on June 22, implements the GENIUS Act’s requirement that permitted payment stablecoin issuers maintain a customer identification program. It was issued by FinCEN, the OCC, the Federal Reserve Board, the FDIC, and the NCUA and would take effect 12 months after a final rule is issued. The proposal arrived one month before the statutory rulemaking deadline, following the same compliance track as earlier illicit-finance rulemakings.
The letter, signed by Blockchain Association Chief Executive Summer K. Mersinger, was addressed to FinCEN Acting Director Jenna Casanova, Comptroller Jonathan V. Gould, and the chairmen of the three remaining agencies.
The Secondary-Market Question
The agencies asked commenters directly whether CIP obligations should extend to secondary-market activity. As proposed, they do not: obligations attach only where an issuer interacts directly with a customer through issuance, redemption, conversion, or custody.
The Blockchain Association’s argument runs on two tracks. On statute, it points to the GENIUS Act’s text at 12 U.S.C. § 5903(a)(5)(A)(v), which requires issuers to verify the identities of account holders with the issuer—language the group reads as foreclosing obligations over transfers of already-circulating stablecoins.
In practice, the letter describes what an issuer can observe during a peer-to-peer transfer: a sending wallet signs and broadcasts a transaction, validators confirm it, and settlement occurs without the issuer’s involvement or knowledge. The issuer’s smart contract executes non-discretionary code, does not identify the parties, and provides no pre-settlement approval function.
Paradigm and Hyperliquid raised the same objection in June, warning that treating smart contract interactions as issuer services would hold issuers responsible for transfers they cannot see clearly or realistically stop.
The group’s strongest support comes from the agencies themselves. The preamble states that smart contract interaction does not currently give an issuer the information needed to verify an identity and describes the resulting obligations as “nearly impossible” in scope.
Two Carve-Outs to the Definition of an Account
The proposal defines an account by reference to a formal relationship between issuer and customer, an approach borrowed from existing CIP rules for banks, broker-dealers, and futures intermediaries. The Blockchain Association supports that structure while asking for four exclusions, which fall into two pairs.
The first pair concerns relationships the group says should not count as accounts at all. One-off redemptions from non-account holders should not create an account, the letter argues, drawing an analogy to check-cashing and money-order purchases, which existing bank rules already exclude. Vendor and service-provider relationships—market data, Oracle services, blockchain infrastructure, analytics—should not qualify either, on the grounds that procurement is not financial intermediation.
Two Asks About Double Coverage
The second pair concerns customers who are already identified under some other regime.
Read literally, the proposal treats provision of digital asset services as creating an account while defining a digital asset service provider broadly enough to cover exchanging, transferring, or holding digital assets. Combined, that would make every exchange customer a CIP account holder of the issuer whenever a single legal entity does both jobs.
The letter notes that those customers already fall under whatever Bank Secrecy Act regime governs exchanges and that the reading produces an asymmetry: identical trading services would carry a general CIP obligation only where the provider also issues a stablecoin. It points to 12 U.S.C. § 5903(a)(7)(B), where Congress contemplated that an issuer might also be a service provider, as evidence the merger was not intended. FinCEN and OFAC’s April proposal already treats issuers as financial institutions under the Bank Secrecy Act.
The fourth ask concerns redemptions submitted through an exchange on a customer’s behalf. The proposal already excludes those who redeem by means other than directly to the issuer. The Blockchain Association wants the final rule to state explicitly that the exchange is the party involved and that this holds even where identifying information about the underlying customer reaches the issuer in the process.
The Bank Comparison
Under the 2003 CIP rule, a bank relying reasonably on another institution’s identity verification is not held responsible if that institution fails. The preamble to this proposal says an issuer remains responsible for its own compliance, which the Blockchain Association reads as leaving issuers exposed where banks are not. The letter says no rational justification exists for the difference and asks that the final rule extend the same protection.
Zero-Knowledge Proofs
The agencies declined to write regulatory text on verifiable credentials and digital identity, preferring to leave the method open, and asked for comment on the approach.
The Blockchain Association endorsed that flexibility and named zero-knowledge proofs specifically: a customer supplies cryptographic proof of satisfying identification predicates without transmitting underlying personal data to the issuer. The letter argues such proof can be mathematically sound and auditable and, in some cases, more reliable than checking a customer’s details against a public database.
It also asks that issuers be permitted to obtain taxpayer identification numbers from third-party sources rather than directly from customers, pointing to a July 2025 exemption order the Federal Reserve and FinCEN issued for banks.
State Issuers and Timing
Section 4(c) of the GENIUS Act lets issuers with no more than $10 billion outstanding opt into state regulation where the state regime is substantially similar to the federal framework. The proposal would not permit federally regulated issuers to rely on identity checks performed by state-qualified issuers, a disparity the agencies acknowledged. The letter asks them to revisit that once Treasury finalizes its substantially similar rulemaking.
On timing, the group asks that the compliance date match that of the separate FinCEN and OFAC rulemaking on AML and sanctions programs, published April 10. That proposal supplies definitions this rule depends on, including what constitutes a permitted payment stablecoin issuer. The structural complaint is not new: banking groups argued in April that the GENIUS rulemakings were inextricably tied to an unfinished OCC framework and asked for comment deadlines to be pushed accordingly.
Also Read: GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
