‹ BackNewsCrypto Compliance

Crypto Compliance

U.S. State Department offers up to $15 million for information on IRGC financial network
SEC
2026-09-28 06:00:58

SEC FAQ narrows the reading on token buybacks and network upgrades

A new FAQ issued by the U.S. Securities and Exchange Commission’s Division of Corporation Finance on Sept. 25 has been widely read as a green light for token buybacks and continued post-launch development. The source article argues that reading goes too far. The FAQ is staff guidance, not a Commission rule, statement, or regulation, and it does not carry independent legal force. Instead, it gives more specific answers within the lifecycle framework the SEC Commission described in March 2026. The key question, the article says, is no longer whether a token is abstractly a security. The focus is whether the asset remains tied to promises made by an issuer in a contract, transaction, or arrangement, and whether buyers still reasonably expect profits from the issuer’s essential managerial efforts. Under the FAQ, a buyback announcement by itself does not automatically create an investment contract if the asset is a non-security crypto asset and the system is already functional. That does not mean all buybacks are outside securities law. The piece also reviews the SEC’s limited clarification on post-launch development, the importance of evidence showing when promised functionality has actually been delivered, and a separate CFTC FAQ update touching tokenized forms of permitted investments and recordkeeping. Its conclusion is narrow: projects received more detailed analytical guidance, not a blanket regulatory pass.

290
SEC FAQ narrows the reading on token buybacks and network upgrades
SEC Staff Says Token Buybacks Usually Don’t Make a Token a Security if the Network Is Already Functional
Hong Kong reg
2026-09-22 08:10:46

Hong Kong’s Crypto Rulebook Takes Shape Across Exchanges, Stablecoins and New Licensing Plans

Hong Kong’s crypto regime is being built through multiple statutes rather than a single all-in-one code, with different rules applying to securities tokens, non-security virtual asset trading platforms and fiat-referenced stablecoins. The framework now links issuance, trading, client onboarding and custody more closely after the Hong Kong Monetary Authority issued the first two stablecoin issuer licenses on April 10, 2026, followed by a Securities and Futures Commission circular on May 27 setting out how licensed virtual asset trading platforms and licensed corporations may offer those licensed stablecoins to clients. The article maps out how the system works in practice. Securities tokens remain under the Securities and Futures Ordinance, while centralized spot crypto platforms fall under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. Stablecoin issuance is handled separately under the Stablecoins Ordinance, which took effect in August 2025. It also details licensing thresholds for trading platforms, including capital and liquidity requirements, token admission rules for retail access, and custody standards such as the 98% cold-storage requirement. Beyond current law, Hong Kong is still moving to add new licensing regimes for custody, trading intermediation, advisory and asset management. The piece also covers the role of banks and licensed corporations, the treatment of tokenized securities, and the city’s settlement infrastructure work through the HKMA’s Ensemble project.

440
Hong Kong’s Crypto Rulebook Takes Shape Across Exchanges, Stablecoins and New Licensing Plans
CFTC
2026-09-18 02:45:26

CFTC’s Letter 26-25 Does Not Ease Crypto Rules and Bars Software Firms From Handling Client Assets

The U.S. Commodity Futures Trading Commission’s Sept. 17 no-action letter, known as Letter 26-25, has been framed in some coverage as a green light for crypto firms. The text says otherwise. Rather than loosening oversight, the letter limits the circumstances in which a passive software provider can avoid broker registration and ties that relief to the same custody structure used in existing exchange-traded derivatives markets. The letter says covered activity applies only when users trade on a designated contract market, either as members or as customers of a futures commission merchant or introducing broker that is a member. User collateral must stay with the market’s clearing organization or a member futures commission merchant. The software provider cannot hold, control, or custody user assets at any point, cannot generate explicit buy or sell signals, and cannot exercise discretion over order routing or execution. The relief also comes with 10 conditions. The most consequential one requires the software provider and its partner registered entity to sign a written undertaking accepting joint and several liability for legal violations tied to covered activity, while also submitting to CFTC investigative and enforcement jurisdiction. The letter states that it reflects staff views only, does not bind the Commission, and remains in effect only until the Commission adopts effective rulemaking or guidance on how introducing broker registration requirements apply to software developers.

400
CFTC’s Letter 26-25 Does Not Ease Crypto Rules and Bars Software Firms From Handling Client Assets
Brazil central bank rules raise compliance bar for virtual asset service providers
Policy Regula
2026-09-11 09:40:27

Fake AML screening sites lure crypto users into wallet approvals that drain funds

A report carried by Foresight and written by Zero Hour Technology warns that a new phishing playbook is exploiting crypto users’ compliance anxiety by posing as anti-money laundering, or AML, screening tools. According to the article, Malwarebytes disclosed on Aug. 19, 2026, that numerous fake AML check sites were actively operating, tricking users into connecting wallets and approving malicious transactions that later emptied their balances. Some pages reportedly impersonated AMLBot, while others used generic branding such as "AML Check," though the report said they were built from the same malicious template. The piece says a legitimate AML screening process is a read-only query that only needs a public wallet address to review on-chain history for links to sanctions, hacks, theft, or suspicious activity. It does not require a wallet connection, a signature, a token approval, or any payment. By contrast, the fake sites simulate a professional workflow with scan progress bars, compliance messages, fake errors, and small "verification fee" prompts before returning a reassuring "Clean, Low Risk" result. The key risk comes after the wallet is connected and the user clicks approve, granting token access that attackers can later use to move funds. The article’s advice is direct: do not connect a wallet for an AML check, do not pay any fee for such a check, and regularly review and revoke unknown token approvals.

880
Fake AML screening sites lure crypto users into wallet approvals that drain funds
Bitget Wallet joins Japan’s BCCC to take part in self-custody wallet compliance talks