Treasury Tells Congress Crypto Mixers Have Legitimate Privacy Uses in Landmark Report

0 436

The US Treasury Department has not historically been sympathetic to the privacy case for crypto mixers. In 2022, the Office of Foreign Assets Control (OFAC), Treasury’s sanctions arm, sanctioned Tornado Cash, a decentralized mixer, for allegedly laundering more than $7 billion in cryptocurrency including funds stolen by North Korean hackers. 

In 2023, the Financial Crimes Enforcement Network (FinCEN) proposed sweeping recordkeeping requirements for mixer-related transactions. Now the same department has told Congress, in a formal 32-page report, that lawful users of digital assets have valid reasons to use mixers, and that regulators need to stop treating the technology as inherently criminal.

The report states that people may want to use mixers to protect information about personal wealth, business payments, or charitable donations from appearing on a public blockchain, and that this is a legitimate concern given that blockchain transaction records are permanent and publicly accessible. 

The document draws a distinction between custodial mixers, which take temporary control of user funds and can be compelled to produce identifying information, and non-custodial decentralized mixers, which operate without a central party and are significantly harder for authorities to monitor or regulate. 

The report does not recommend new restrictions on non-custodial mixers, and it does not endorse FinCEN’s 2023 proposed rulemaking, instead deferring to a July 2025 Presidential Working Group recommendation to “consider next steps” while balancing privacy and illicit finance risks.

The Hold Law Proposal and the DeFi Question

The report’s most consequential legislative task is a proposed digital asset “hold law.” Under the current framework, financial institutions that identify suspicious crypto activity have limited tools to pause or freeze a transfer while investigating. 

Treasury argues that a safe harbor law allowing temporary asset freezes during a short investigation window would be “particularly useful for countering illicit finance involving permitted payment stablecoins,” essentially giving compliance teams a legal backstop that does not currently exist. 

On decentralized finance, the report urges Congress to specify which DeFi actors should face anti-money laundering and counter-terrorism financing (AML/CFT) obligations based on their roles rather than applying a blanket framework. 

It also proposes adding a new “sixth special measure” to Section 311 of the USA PATRIOT Act, which would authorize the Treasury to prohibit or impose conditions on certain digital asset transmittals from jurisdictions or entities of concern.

The North Korea Problem That the Report Can’t Resolve

The acknowledgment of legitimate mixer use does not mean Treasury is softening on criminal applications. The report’s own data shows North Korea’s Lazarus Group stole at least $2.8 billion in digital assets between January 2024 and September 2025, including the $1.5 billion Bybit hack.

Since May 2020, more than $1.6 billion in deposits from mixing services have flowed into crypto bridges, with over $900 million concentrated in a single bridge flagged for failing to intervene in swaps by North Korean-linked actors. 

The report was commissioned under Section 9 of the GENIUS Act, signed in July 2025, with a 180-day deadline of approximately January 14. It arrived seven weeks late, dated March 2026.

Whether the legislative recommendations, the hold law, the DeFi AML framework, the PATRIOT Act measure, generate any traction in Congress is an open question. 

But the formal acknowledgment that privacy and illicit finance risk can coexist in the same technology, and that regulation needs to distinguish between them, is itself a meaningful shift in how the Treasury is framing the problem.

Leave A Reply

Your email address will not be published.