h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

FATF Crypto Guidance in 2026: The Offshore and DeFi Blind Spots

The FATF wrote the rulebook that shapes crypto money-laundering controls worldwide. In 2026 the real story is the parts of crypto its rules still cannot reach.

Every time you open an account on a crypto exchange and upload a photo of your passport, you are following a decision made in Paris by an organisation most crypto users have never heard of. The Financial Action Task Force, the FATF, does not write laws and cannot fine anyone. Yet its recommendations set the anti-money-laundering standard that more than two hundred jurisdictions translate into their own rules, and by 2026 those rules touch almost every regulated corner of the crypto market.

The headline numbers explain why regulators care. Chainalysis found that illicit crypto addresses received at least 154 billion dollars in 2025, a 162 percent jump on the year before, even though that flow is still under 1 percent of all on-chain activity. Stablecoins now carry roughly 84 percent of that illicit value, having overtaken Bitcoin as the criminal rail of choice. The stablecoin market itself is worth close to 290 billion dollars, led by Tether at about 183 billion dollars and USDC near 74 billion dollars. Bitcoin, for context, traded around 77,300 dollars as this piece went out.

Two earlier HOGE Wire explainers covered how the FATF’s rulebook works and why the rules on paper have outrun enforcement in practice. This piece is about the third act: the parts of crypto the rulebook was built to catch and still cannot reach. Offshore shell providers, DeFi front-ends with no obvious operator, wallets that answer to no company, and a new generation of stablecoins engineered to resist freezing all sit at the edge of the perimeter, or just beyond it. In 2026 the FATF spent more words on those blind spots than on anything else, and its new leadership has made closing them the priority for the next two years.

What the FATF is, and why your exchange answers to Paris

The FATF was created in 1989 by the G7, housed at the OECD in Paris, to coordinate a response to drug-money laundering. Its core product is a set of 40 Recommendations, a template that member countries and a wider Global Network of more than 200 jurisdictions agree to implement. The body has around 40 members and no direct power over any private firm. Its influence runs through national governments, which pass the laws, and through the peer-review process that grades how well each country follows the template.

That grading is the teeth. Countries that fall short land on one of two lists. The black list, formally the high-risk jurisdictions subject to a call for action, sits at three names in 2026: Iran, North Korea, and Myanmar. The grey list, or jurisdictions under increased monitoring, held 22 countries after the June 2026 plenary, which added Bosnia and Herzegovina and Iraq while removing Algeria and Namibia. Being listed is expensive: correspondent banks pull back, cross-border payments slow, and capital turns cautious, so governments treat delisting as a serious economic goal.

Crypto entered this machinery in October 2018, when the FATF amended Recommendation 15, the one covering new technologies, to add two terms to its glossary: the virtual asset and the virtual asset service provider. In June 2019 it published an interpretive note and its first risk-based guidance, and extended the Travel Rule to crypto. Updated guidance followed in October 2021, reaching into DeFi, NFTs, stablecoins, and peer-to-peer transfers. Since then the FATF has issued an annual targeted update on how implementation is going, the seventh of which landed in July 2026. None of this is law by itself. It becomes law when your country’s legislature copies it across, which is why an exchange in New York, Lisbon, or Singapore all end up asking for the same passport photo.

Two words that pull crypto in: the VA and the VASP

The whole framework hangs on two definitions. A virtual asset is a digital representation of value that can be traded or transferred and used for payment or investment. That definition deliberately excludes central bank digital currencies, which are treated as fiat, and any asset already captured as a security or a traditional financial instrument. Bitcoin, Ether, most tokens, and stablecoins are virtual assets.

The more consequential term is the virtual asset service provider, the VASP. A VASP is any person or business that, for or on behalf of someone else, does at least one of five things. Miss the definition and you sit outside the rules; meet it and the full anti-money-laundering rulebook applies, from customer identification to suspicious-activity reporting to the Travel Rule. The five activities are worth spelling out, because the blind spots later in this piece are all arguments about whether a given actor is doing one of them.

ActivityWhat it coversTypical example
Exchange between virtual assets and fiatSwapping crypto for dollars, euros, or other national currencyA centralised exchange buy and sell desk
Exchange between one virtual asset and anotherTrading one token for anotherA spot trading pair on an exchange
Transfer of virtual assetsMoving crypto from one person or address to another on their behalfA custodial wallet send function
Safekeeping or administrationHolding or controlling assets for a customerA custodian or hosted wallet
Financial services for a token issuanceParticipating in and providing services for an issuer’s offer or saleAn exchange running a token launch

The pattern that matters: every activity in the table involves acting for someone else. A business that holds your keys, executes your trades, or moves your coins on your instruction is a VASP. Software that lets you do those things yourself, with no one in control of your assets, is where the definition starts to fray, and that fraying is the whole story of 2026.

The Travel Rule in one paragraph, and the caveat that matters

The single rule crypto firms complain about most is the Travel Rule. In traditional finance it is Recommendation 16, the requirement that banks attach originator and beneficiary information to wire transfers so money cannot move anonymously between institutions. The FATF extended it to VASPs. When one provider sends crypto to another above a de minimis threshold of USD or EUR 1,000, it must transmit the sender and receiver identifying details alongside the transaction, using a shared data standard known as IVMS 101. The receiving VASP is supposed to screen that data and hold it.

The caveat is the reason the rule struggles, and it is the hinge of this whole article. The Travel Rule assumes there is a regulated VASP on both ends of the transfer. When both ends are licensed exchanges, it works reasonably well. The problem the industry calls the sunrise issue is that jurisdictions switched the rule on at different times, so a compliant exchange in one country often has to send data to a counterparty in a country that never built the pipes to receive it. The deeper problem is that a growing share of crypto activity has no VASP on the other end at all: a self-hosted wallet, a DeFi contract, an offshore shell posing as a private individual. The rule was designed for a two-VASP world, and the money increasingly moves through the gaps between VASPs.

The seventh update: rules almost everywhere, enforcement almost nowhere

The FATF’s seventh targeted update, published in July 2026 with data running through April, is the clearest snapshot of where implementation stands. The topline reads like success. Travel Rule legislation is now in force in 83 percent of surveyed jurisdictions, 91 of 109, up from 73 percent a year earlier, and it is in force or in progress in 93 percent. Among the 69 jurisdictions that handle roughly 97 percent of global virtual-asset volume, 94 percent have rules enacted or pending. On paper, the rulebook has almost won.

Look one layer down and the picture inverts. Of the 91 jurisdictions with Travel Rule laws in force, 60 percent, that is 55 countries, have taken no supervisory or enforcement action at all. Technical compliance with Recommendation 15 is largely met in only 34 percent of jurisdictions, up from 29 percent but still leaving nearly two-thirds partially compliant or worse. Chainalysis flagged the sharpest gap: only 13 of 139 jurisdictions, under 10 percent, fully meet the FATF’s preventive-measures standard. Licensing is required in 73 percent of places but actually issued in only 58 percent. As the FATF itself put it, organised crime groups are taking advantage of the gap between rule and reality.

Measure2026 figureReading
Travel Rule in force83% (91 of 109)Almost universal on paper
Took no enforcement action60% of those with lawsThe gap between rule and reality
R.15 largely compliant34%Up from 29%, still a minority
Fully meet preventive standards~10% (13 of 139)The weakest link
Assessed DeFi risk18%Most jurisdictions have not looked
Rate P2P via unhosted wallets high-risk88%Widely feared, rarely measured

Those last two rows are where the blind spots start. The rest of this piece walks through the four biggest ones, in roughly the order the FATF itself now ranks them.

Blind spot one: the offshore VASP

In March 2026 the FATF did something it rarely does for a single risk: it published a dedicated report, “Understanding and Mitigating the Risks of Offshore VASPs”. An offshore VASP, in the report’s shorthand, an oVASP, is a provider that incorporates in one place, often a jurisdiction with weak or absent supervision, while serving customers everywhere else. The report found that fewer than half of jurisdictions, 46 percent, apply their rules on an activity basis, meaning they regulate a provider based on what it does in their market rather than where its paperwork is filed. The rest leave a provider free to serve their citizens as long as it planted its flag somewhere lax.

Elisa de Anda Madrazo, who chaired the FATF through June 2026, did not soften the finding. The report, she said, “exposes how oVASPs create blind spots that criminals are clearly exploiting, to scam vulnerable people through fraud or fuel terror around the world”. The mechanics she was describing are specific. The report details how offshore, unlicensed providers reach into the regulated system through what it calls nested relationships: the oVASP opens an account at a licensed exchange while posing as an ordinary retail customer, then runs its own users’ flows through that single account, invisible to the licensed firm’s monitoring. Victim funds from scam compounds get dispersed across many addresses, routed through layers of intermediary wallets, and bridged across chains to break the trail.

The July update put a number on how few jurisdictions have closed this door: only 39 of 114 with licensing frameworks, about a third, extend those frameworks to offshore providers on an activity anchor. For a user, the lesson is uncomfortable. An exchange with a slick interface and a support desk can be an oVASP with no meaningful supervisor, and the fact that it accepted your passport photo does not mean anyone is checking its work. HOGE Wire’s own bank test comparison of the largest venues exists partly because licensing status, not user experience, is what separates a supervised firm from a blind spot.

Blind spot two: DeFi and the control test

The second blind spot is philosophical before it is practical. The FATF’s rulebook regulates people and businesses, not software. Decentralised finance is software: a set of smart contracts that swap, lend, and trade without any obvious company in the middle. If there is no operator acting on your behalf, there may be no VASP, and if there is no VASP, most of the rulebook does not apply.

The FATF’s 2021 guidance tried to close this with what practitioners call the control test. The guidance argued that a DeFi arrangement may still have owners or operators who maintain control or sufficient influence, for example through an administrative key, a fee switch, or ongoing governance, and that those people can be VASPs even if the front-end looks decentralised. The label DeFi, the FATF warned, does not by itself put an arrangement outside the rules. In principle, the perimeter follows control wherever it hides.

In practice, almost no one has drawn that line. The July update found that only 18 percent of jurisdictions have even assessed DeFi risk, and 93 percent report they have not identified a single DeFi arrangement that qualifies as a VASP. Chainalysis counted four jurisdictions that have imposed licensing on a DeFi arrangement and exactly one that has enforced it. The gap is not that regulators think DeFi is safe; it is that the control test is hard to apply to a governance token held by thousands of anonymous wallets, and harder still to enforce across borders. The question of when interacting with a DeFi protocol becomes a crime, rather than a compliance failure, is being fought out in courtrooms rather than rulebooks, as HOGE Wire covered when an oracle-manipulation conviction went to appeal on exactly that boundary. Until those cases settle, DeFi remains the largest structurally unregulated slice of the market.

Blind spot three: unhosted wallets and the peer-to-peer edge

The third blind spot is the one closest to crypto’s founding idea. An unhosted wallet, sometimes called a self-hosted wallet, is software you control directly, with no company holding your keys. MetaMask, a Ledger device, a paper seed phrase: none of them is a VASP, because none of them acts on anyone else’s behalf. When two people transfer crypto wallet-to-wallet, peer-to-peer, there is no intermediary to run a Travel Rule check, file a report, or freeze anything.

The FATF knows this is where the framework thins out. In the July update, 88 percent of jurisdictions rated peer-to-peer transfers via unhosted wallets as high-risk, yet only 23 percent collect any metrics to measure that flow. Regulators fear it and cannot see it. The compromise most rulebooks have settled on is to regulate the point where an unhosted wallet touches a hosted one. When you withdraw from an exchange to your own wallet, or deposit from it, the exchange is a VASP and can be told to verify that the wallet is really yours, screen the address against sanctions lists, and apply extra checks above a threshold.

Europe drew that line hardest. The EU Transfer of Funds Regulation, the bloc’s version of the Travel Rule, carries no minimum threshold at all, and it requires enhanced checks when funds move between a custodial platform and a self-hosted wallet above 1,000 euros. The United States relies on exchange-level obligations under the Bank Secrecy Act rather than a rule aimed at the wallets themselves. Either way, the wallet stays free; the on-ramp and off-ramp get watched. The moment value leaves the regulated venue and stays peer-to-peer, it is beyond the rule’s reach by design.

Blind spot four: the stablecoin that will not freeze

The fourth blind spot is the newest and, by the numbers, the most alarming. Stablecoins were supposed to be the compliant part of crypto: dollar-backed, issued by identifiable companies, easy to freeze. Most are. When Tether or Circle blacklists an address, the tokens there become unusable, which is exactly the choke point regulators want. That is why the FATF and national supervisors have leaned so hard on the issuer as the point of control.

The alarming part is what happens when an issuer refuses to play, or is the criminal. Chainalysis attributes 84 percent of all illicit transaction value in 2025 to stablecoins, up from 63 percent a year earlier. The starkest example is A7A5, a ruble-backed token that Chainalysis says processed more than 93 billion dollars in sanctions-evasion flows in under a year. The FATF’s July update warned about a proprietary stablecoin engineered to resist freezing and seizure, and its new president was blunt about the pattern: criminal networks, Giles Thomson said, “continue to abuse virtual assets for illicit purposes and exploit their borderless nature to commit fraud and scams, evade sanctions and launder the proceeds of crime”. A stablecoin whose issuer will not freeze, or cannot be reached, turns the industry’s favourite compliance lever into dead weight.

The response has been to regulate the issuer directly. In the United States the GENIUS Act, enacted in July 2025, created the first federal framework for payment stablecoins, and in April 2026 FinCEN and OFAC jointly proposed a rule treating permitted stablecoin issuers as financial institutions under the Bank Secrecy Act, with full anti-money-laundering and sanctions-compliance programs. HOGE Wire traced how that rulebook is designed to reach offshore issuers who serve Americans from abroad. The bet is that if the coin cannot be frozen at the address, the issuer can be regulated at the source. It only works when there is an issuer willing to answer a subpoena, which A7A5 pointedly is not.

Why the US answer is FinCEN, not the SEC

A persistent confusion is worth clearing up, because it changes who you watch. In the United States, crypto anti-money-laundering authority does not sit with the Securities and Exchange Commission. It sits with the Financial Crimes Enforcement Network, FinCEN, part of the Treasury, backed by the Office of Foreign Assets Control for sanctions. FinCEN’s 2019 guidance treats crypto money transmitters as money services businesses, which must register, run an AML program, verify customers, and file suspicious-activity reports. The US Travel Rule recordkeeping threshold is 3,000 dollars. The SEC enters only when a token is also a security, a separate question about investor protection, not money laundering. When people say the SEC polices crypto laundering, they are naming the wrong agency.

The distinction matters because FinCEN holds the single sharpest tool for reaching a blind spot from the outside: Section 311 of the USA PATRIOT Act. Section 311 lets the Treasury declare a foreign financial institution a primary money-laundering concern and cut it off from the US financial system, without ever proving a case in court. In 2025 it used that power on Huione Group, a Cambodian conglomerate that FinCEN found had laundered at least 4 billion dollars between August 2021 and January 2025, serving as a hub for North Korean cyber-heist proceeds and Southeast Asian pig-butchering scams, the same social-engineering machine HOGE Wire examined in its look at crypto phishing. Treasury Secretary Scott Bessent said Huione “has established itself as the marketplace of choice for malicious cyber actors like the DPRK and criminal syndicates, who have stolen billions of dollars from everyday Americans”. After a proposed rule in May, the final rule in October 2025 barred US banks from maintaining correspondent accounts for the group.

Huione is the template for how the perimeter gets enforced against the unreachable. FinCEN could not audit a Cambodian scam bank, so it did the next best thing: it made the dollar system refuse to touch it. That is a chokepoint strategy, and it is the same logic behind the pressure on stablecoin issuers and behind the grey list. When you cannot regulate the actor, you regulate everyone who has to deal with the actor.

Europe’s sharper edge: TFR, AMLR, and AMLA

If the FATF sets the standard, the European Union has implemented it more aggressively than almost anyone. Three instruments do the work. The Transfer of Funds Regulation, in force since December 2024, is the EU Travel Rule, and unlike the FATF’s version it carries no minimum threshold: every crypto transfer between providers must carry identifying data, whatever the size. The Anti-Money-Laundering Regulation, the AMLR, which takes full effect in July 2027, goes further than any FATF recommendation by banning anonymous crypto accounts outright and prohibiting providers from handling privacy coins such as Monero. And the Anti-Money-Laundering Authority, AMLA, headquartered in Frankfurt, will directly supervise up to 40 of the highest-risk financial firms across the bloc, crypto platforms included, from 2028.

The contrast with the FATF’s own scorecard is the point. Where the seventh update shows most jurisdictions writing rules and never enforcing them, the EU is building an enforcement body with its own staff and its own list of firms to police. It is the clearest attempt yet to convert the FATF’s template from paper into practice.

Blind spotWhy the rule misses itThe main patch in 2026
Offshore VASPsRegulated by where they incorporate, not who they serveActivity-based licensing; Section 311 cut-offs
DeFiNo operator to name as a VASPThe control test, largely unenforced
Unhosted wallets and P2PNo intermediary to run the checkOn-ramp and off-ramp screening; EU TFR
Freeze-resistant stablecoinsIssuer will not or cannot freezeGENIUS Act, FinCEN and OFAC issuer rules

None of these patches closes its blind spot completely. Each moves the enforcement point to wherever control still exists: the licensed counterparty, the correspondent bank, the stablecoin issuer, the on-ramp. The rulebook cannot reach the software, so it reaches the people who touch the software.

The grey list: where the FATF actually bites

Strip away the guidance documents and the FATF’s real power is a list. A country that fails its mutual evaluation and does not commit to a credible action plan gets placed under increased monitoring, the grey list, or in the worst cases the black list. The consequences are financial, not legal. Global banks reprice or sever ties with institutions in listed countries, remittances get more expensive, foreign investment hesitates, and study after study has tied grey-listing to measurable drops in capital inflows.

For crypto specifically, listing has a compounding effect. A jurisdiction that tolerates offshore VASPs or refuses to implement the Travel Rule risks the grey list, and once listed, its exchanges find correspondent banking harder to keep, which pushes legitimate users toward better-supervised venues. The June 2026 plenary, the last under Mexico’s presidency, kept the black list at Iran, North Korea, and Myanmar, and reshaped a grey list of 22 by adding Bosnia and Herzegovina and Iraq while congratulating Algeria and Namibia out of it. Each change is a signal to the global banking system about where to apply extra caution.

This is why the FATF matters even though it cannot fine your exchange. Its recommendations become national law because no government wants to be on the list, and no bank wants to clear money for a country that is. The blind spots discussed here are, in the end, jurisdictions and activities where that pressure has not yet been brought to bear. The grey list is the lever that eventually brings it.

What this means for a crypto business, and for you

For a crypto business, the 2026 rulebook turns counterparty risk into a first-order compliance problem. It is no longer enough to identify your own customers; you have to know something about the VASPs you transact with, because an oVASP nesting inside your platform is your exposure, not just theirs. In practice that means real due diligence on counterparties, a Travel Rule solution that can exchange IVMS 101 data with the venues you actually deal with, address screening against sanctions lists before funds move, and enhanced checks when value crosses between hosted and self-hosted wallets. The identity layer underneath all of this is under its own pressure, as HOGE Wire documented in the arms race between deepfake onboarding fraud and the checks meant to stop it.

For a user, the practical effects are quieter but real. Onboarding asks for more, and asks earlier. Withdrawals to a self-hosted wallet may trigger an ownership check or a short delay. Deposits from certain addresses may be declined outright. And the single most useful habit is the one the offshore blind spot argues for: check whether the venue holding your money is actually licensed and supervised somewhere serious, rather than incorporated in a jurisdiction chosen precisely because no one is watching. A polished app is not a regulator. The whole thrust of the FATF’s 2026 work is that the gap between looking compliant and being supervised is exactly where the money goes missing.

The road to 2028: Thomson’s fraud roadmap

On 1 July 2026 the FATF presidency passed from Mexico’s de Anda Madrazo to the United Kingdom’s Giles Thomson, director for economic crime and sanctions at HM Treasury, for a two-year term. On day one the FATF launched a 2026 to 2028 Roadmap on Combatting Fraud, naming fraud as the fastest-growing source of illicit finance and noting that it was a proceeds-generating offence in nearly 90 percent of the last round of mutual evaluations. Virtual assets sit at the centre of that roadmap, because scam compounds, investment fraud, and sanctions evasion increasingly run on crypto rails, a concern the agenda spells out in detail.

The direction for the next two years is set. Expect more pressure on the enforcement gap, since writing a Travel Rule that no one supervises now counts as a failure rather than progress. Expect the offshore and DeFi blind spots to stay near the top of the agenda, since they are where the FATF’s own reports say the money concentrates. Expect the stablecoin issuer to become the favoured chokepoint, in Washington through the GENIUS rulebook and in Brussels through the AMLR. And expect the grey list to keep doing the quiet work of turning recommendations into law. The FATF has spent two decades proving it can write rules the world adopts. The 2026 story, and the job Thomson inherited, is whether it can make those rules reach the places crypto was designed to keep them out.

Frequently Asked Questions

What is a VASP under FATF rules?

A virtual asset service provider is any business that, on behalf of a customer, exchanges crypto for fiat or for other crypto, transfers virtual assets, holds or administers them, or provides financial services for a token issuance. Meeting any one of those five activities pulls a firm into the full anti-money-laundering rulebook, including customer identification and the Travel Rule. Software you control yourself, with no one holding your assets, generally falls outside the definition.

What is the FATF Travel Rule for crypto?

The Travel Rule requires a crypto provider sending assets to another provider above a threshold of about USD or EUR 1,000 to transmit identifying information about both the sender and the recipient, using a shared data standard called IVMS 101. It mirrors the rule banks follow for wire transfers, and it works only when there is a regulated provider on both ends, which is why self-hosted wallets and offshore shells are so hard to cover.

Does the FATF regulate DeFi?

FATF guidance says a decentralised-finance arrangement can still have owners or operators who keep control or influence, through an admin key, a fee switch, or governance, and that those people can be treated as VASPs. In practice almost no jurisdiction has applied this: in the July 2026 update, 93 percent reported finding no DeFi arrangement that qualified as a VASP, and only a handful have licensed one. DeFi remains the largest structurally unregulated part of the market.

Is the SEC responsible for crypto anti-money-laundering rules in the US?

No. In the United States, crypto anti-money-laundering authority sits with FinCEN, part of the Treasury, supported by OFAC for sanctions, under the Bank Secrecy Act. Crypto money transmitters register as money services businesses and file suspicious-activity reports. The SEC is involved only when a token is also a security, which is a separate investor-protection question, not a money-laundering one.

What happens when a country is put on the FATF grey list?

Grey-listing, formally being placed under increased monitoring, signals to the global banking system that a jurisdiction has strategic anti-money-laundering weaknesses. It is not a legal penalty, but the financial consequences are real: correspondent banks pull back, cross-border payments get slower and costlier, and foreign investment tends to fall. Governments treat getting off the list as a serious economic priority, which is a major reason FATF recommendations become national law.

Anneke de Vries covers financial regulation and crypto compliance for HOGE Wire.

Share 𝕏 Post Telegram