This post was originally published on June 06, 2019, and sent to Messari Pro subscribers.
One of theonly risks that still scares me in bitcoin is that a stupid regulator will concoct a half-baked and overly burdensome crypto transaction reporting standard - almost certainly in the name of “security” - that makes compliance all but impossible. Something dumber than the New York State BitLicense, but that crypto exchanges and users can’t really opt out of or route around. The Financial Action Task Force’s imposition of the “travel rule” on crypto businesses could present one such macro risk. What is FATF? What is the travel rule? And why does this present crypto’s biggest challenge to date?
The range of government regulators aiming to get their hands on crypto is vast. The SEC, CFTC, and FinCEN may make all the headlines in the crypto world these days, but the acronym you really want to get up to speed on is FATF, the Financial Action Task Force (FATF). The FATF is an intergovernmental organization, comprised of members from 38 countries, who share a mandate to combat money laundering and terrorist financing. Their recommendations have become the global standard for financial surveillance. The force is tasked with continuously monitoring compliance at global financial institutions. Unlike other regulators, though, the FATF is a policy-making body that operates by pressuring governments to enact legislative and regulatory reforms. The FATF may have no investigative authority, but they can name and shame jurisdictions that fail to push FATF standards, which can have fairly serious ramifications. The FATF’s “greylisting” ability can ward off foreign investment, disrupt cross-border capital flows, and raise trading costs to countries in the grey.
A few months ago, the FATF published a statement titled “Mitigating Risks from Virtual Assets.” Among other things, the draft called for every Virtual Asset Service Provider (VASP) to be licensed or registered in their local jurisdiction as well as anywhere their products or services to customers were sold. VASPs would also become subject to the “Travel Rule,” an onerous piece of financial regulation which requires parties to hold information on every virtual transfer between originator and recipient, and then provide that info to the beneficiary VASP (if applicable) and make it available upon request to authorities.
This last piece is critical and has some profound implications. If every VASP (which includes any exchange, custody, wallet provider, etc.) were required to follow this, it would mean they could only facilitate transactions between two addresses with known identities. This would be….ugh…difficult since addresses can be generated on-demand, and very little meta-data aside from an address is currently required for a p2p transaction. Not every crypto transfer must occur between two VASPs. But it’s tougher to “be your own bank” and conduct truly private commerce when your private wallet transfers also require a compliance team. It’s not even technically possible from a protocol level perspective to blacklist or whitelist addresses. There’s no registry of white or blacklisted addresses in crypto, nor a very logical way to build one. The travel rule’s imposition on the industry, then, would eliminate any semblance of financial privacy you could otherwise hope for in the future. It’s downright dystopian.