Crypto Debanking in 2026: When AML Costs You a Bank Account
Debanking is the sharp end of anti-money-laundering policy: lawful crypto firms lose their accounts for risk they never posed. Here is how AML creates it, and how 2026's new US rules fight back.
You Can Do Everything Right and Still Lose Your Bank
The most unsettling thing about being debanked is that it usually has nothing to do with wrongdoing. You verify your identity, you clear the sanctions screen, your transactions are legal and dull, and then a letter arrives giving you 30 or 60 days to take your money elsewhere. There is rarely a reason attached, and almost never one you can appeal. For a growing number of crypto founders, exchanges, and ordinary holders, that letter is the sharp end of anti-money-laundering policy: a system designed to stop criminals that keeps closing the accounts of people who are not criminals.
This is the debanking problem, and in 2026 it sits at the center of a fight between two goals that pull in opposite directions. On one side is the anti-money-laundering (AML) machine, the largest financial-surveillance apparatus ever built, which asks banks to know their customers and to walk away from any risk they cannot manage. On the other is a political promise, now written into a US executive order and into federal banking rules, that no lawful business should lose access to the payment system because a regulator finds it distasteful.
The backdrop is a jittery market. Bitcoin was changing hands just under $78,000 as this went to press, down about 3% on the week after Fed governor Kevin Warsh’s hawkish turn cooled the rally and lifted rate-hike odds (spot price via CoinGecko). But the more durable story of the week was not the price chart. It was a rule the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) finalized on 27 August 2026, an attempt to make the kind of quiet account closure described above much harder to justify. To understand why that rule exists, you have to understand how anti-money-laundering law manufactures the very risk that banks then run away from.
Debanking Versus De-risking: Two Words, One Outcome
The two terms get used interchangeably, but they describe different things. Debanking is what happens to a single customer: a bank closes or refuses an account, often citing risk, compliance cost, or reputation, and the customer is left scrambling for a new provider. De-risking is the wholesale version: a bank decides an entire category of customer, all crypto firms, all money-services businesses, all clients from a given country, is more trouble than it is worth, and exits the lot without weighing each relationship on its own merits.
The distinction matters because regulators have been clear that one of these is not supposed to happen. The Financial Action Task Force (FATF), the global standard-setter for AML rules, has said since 2014 that de-risking of whole customer classes is not the risk-based approach it asks banks to follow. That approach requires a bank to assess each customer individually and apply controls in proportion to the actual risk. Cutting off everyone who fits a category is, in FATF’s own framing, a failure of risk management, not an example of it. Yet de-risking is exactly what tends to happen when the cost of getting a single customer wrong is measured in billions.
For crypto, the line between the two blurs. A firm can be debanked as an individual decision, or swept up in de-risking as a category. Either way the outcome is identical: no account, no payroll rail, no way to move dollars in and out, and often no explanation. The rest of this piece follows that outcome back to its source, and forward to the rules now trying to stop it.
The AML Machine That Manufactures the Risk
To see why banks flinch, start with what they are being asked to do. Anti-money-laundering is the umbrella: a body of law and a set of controls meant to stop the financial system from being used to hide the proceeds of crime. Know Your Customer (KYC) is the piece most people meet at signup, the identity-verification step, but it is only one component. Beneath it sit customer due diligence, ongoing transaction monitoring, sanctions screening, and the duty to report anything that looks suspicious.
A common mistake, especially in crypto coverage, is to file all of this under the Securities and Exchange Commission. It does not live there. In the United States, AML authority runs through the Treasury’s Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC), under the Bank Secrecy Act of 1970. Banks are supervised on their AML programs by their prudential regulators, the OCC, the FDIC, and the Federal Reserve. The SEC handles the securities dimension of crypto, not the money-laundering rules. Crypto exchanges themselves are treated as money services businesses and must register with FinCEN, typically within 180 days of launch.
The reporting duties are specific. A bank files a Currency Transaction Report for cash movements above $10,000, and a Suspicious Activity Report (SAR) when it spots activity that looks like laundering; at a money services business the SAR threshold is $2,000, and records are kept for five years. Tipping off a customer that a SAR has been filed is itself a crime. Layered on top is the risk-based approach and the five compliance pillars: a designated officer, internal controls, staff training, independent audit, and customer due diligence. Running this machinery is expensive, a cost we have documented in detail in our look at what DeFi compliance actually costs, and the expense is the first thing that nudges a bank toward the exit.
The Risk-Based Approach, and How It Curdles Into De-risking
On paper, the risk-based approach is elegant. A bank sizes up each customer, decides how much money-laundering risk they carry, and applies controls to match: a light touch for a payroll account, enhanced due diligence for a client with complex offshore structures. Done well, it concentrates scrutiny where the danger actually is, and leaves everyone else alone.
In practice, the math often points one way. Consider a mid-size bank weighing whether to keep a crypto exchange as a client. The compliance burden is heavy: blockchain analytics, extra staff, constant monitoring, and the standing risk that an examiner later decides the program was not good enough. Set that against the revenue from one account, and for many banks the rational move is not to build a better program. It is to close the account. De-risking is what the risk-based approach becomes when the penalty for a single mistake dwarfs the profit from getting it right.
Crypto executives sometimes argue the fear is overblown. The enforcement record says otherwise. In November 2023, Binance, the world’s largest exchange, agreed to a $4.3 billion resolution with US authorities, including a $3.4 billion FinCEN penalty that was the largest in the agency’s history at the time, after admitting it had never filed a single suspicious activity report despite processing transactions tied to sanctioned groups (Department of Justice). Announcing the case, then Attorney General Merrick Garland put the message plainly: “Using new technology to break the law does not make you a disruptor. It makes you a criminal.” In early 2025 the exchanges OKX and KuCoin both pleaded guilty to related money-transmission failures and paid substantial penalties of their own. A bank that onboards a crypto client and gets its monitoring wrong is not imagining the downside; it has watched it play out at nine and ten figures.
Why Crypto Sits at the Top of the De-risking List
Not every industry gets de-risked equally. Crypto attracts more of it than almost any other lawful sector, for reasons that stack on top of one another. Regulators have flagged the space as higher risk, the assets move across borders in minutes, and the reputational sting of a bad headline lands harder here than it would for, say, a chain of dry cleaners. The table below breaks down the four forces that most often push a bank to hang up on a crypto client.
| Driver | What it means | How it hits crypto |
|---|---|---|
| Reputational risk | Fear that association with a client damages the bank’s standing | Crypto is tied in headlines to fraud, hacks, and volatility, even when a given client is clean |
| Regulatory risk | Fear of supervisory criticism, fines, or enforcement | After Binance, examiners scrutinize crypto exposure; a weak AML program can trigger action |
| Operational cost | The expense of monitoring, screening, and reporting | Analytics, specialist staff, and constant SAR review can outweigh a single account’s revenue |
| Uncertain provenance | Doubt about where a client’s funds came from | Chain-analytics scores are probabilistic, not proof, so a compliance officer is never fully certain |
Note what is missing from that list: evidence that the specific customer did anything wrong. A crypto payroll account for a licensed, audited company can be closed on reputational grounds alone. That is the core grievance behind the debanking fight, and it is why the argument moved from private complaints to a very public political battle.
Operation Chokepoint 2.0: The Allegation
The crypto industry has a name for what it believes happened between 2022 and 2024: Operation Chokepoint 2.0. The venture capitalist Nic Carter popularized the term in early 2023, borrowing it from Operation Choke Point, a 2013 Justice Department initiative that pressured banks to drop legal but disfavored businesses such as payday lenders and firearms dealers. The 2.0 theory holds that US regulators, rather than banning crypto outright, quietly squeezed it out of the banking system by treating the whole sector as radioactive.
The claim broke into the mainstream in late November 2024, when Andreessen Horowitz co-founder Marc Andreessen told Joe Rogan’s podcast that roughly 30 technology founders had been debanked, describing what he framed as a coordinated effort by regulators to cut politically disfavored industries off from banking (Fortune). The account was contested; critics noted that some cases had ordinary explanations and that a single smoking gun was hard to produce. But it put a number and a narrative on a frustration that had been building for two years.
That frustration had a concrete trigger. In March 2023, the two banks that had built the plumbing connecting crypto to the dollar collapsed within days of each other. Silvergate, whose Silvergate Exchange Network let crypto firms move dollars around the clock, announced a voluntary wind-down in early March 2023. Silicon Valley Bank failed days later, and that weekend New York regulators seized Signature Bank, shutting its Signet payment rail. Whatever the mix of causes, the effect on crypto was immediate: the industry’s main on and off ramps to the banking system vanished at once, and the survivors found new banks much harder to come by.
The Pause Letters: What the FOIA Fight Revealed
For a long time the debanking story was anecdote against denial. That changed when documents started coming out. Under pressure from a Freedom of Information Act lawsuit brought by History Associates, a research firm acting at Coinbase’s direction, the FDIC was forced to release a set of “pause letters” it had sent to banks. The letters showed the agency asking at least 23 institutions about their crypto activities and, in several cases, telling them to pause or refrain from expanding crypto-related products (CoinDesk).
The disclosure did not come easily. US District Judge Ana Reyes ordered the FDIC to produce the letters and later faulted the agency’s heavy redactions, forcing several more rounds of disclosure before the records finally came out. To the industry, the letters were the closest thing yet to proof that debanking was not just banks acting on their own, but banks acting on a nudge from Washington.
None of this settled the underlying question of how much genuine risk crypto actually carries. Analysts who trace stolen funds, whose work we followed in our investigation of where bridge-hack money goes, will tell you the flows are real, even if they are a small share of the total. But the pause-letter fight reframed the debate: the issue was no longer only whether crypto is risky, but whether regulators had used AML supervision to make a policy choice they could not defend in public. The timeline below tracks how the fight escalated.
| Date | Event | Why it mattered |
|---|---|---|
| March 2023 | Silvergate winds down; Signature is seized | Crypto loses its main banking rails |
| Early 2023 | Operation Chokepoint 2.0 enters the lexicon | Gives the grievance a name |
| Late 2024 | FDIC pause letters surface via FOIA | Documentary evidence of supervisory pressure |
| Aug 2025 | Trump signs the fair-banking executive order | Reputation risk targeted from the top |
| April 2026 | OCC and FDIC drop reputation risk as a category | Removes a key debanking lever |
| 27 Aug 2026 | Agencies define unsafe or unsound practice | Narrows the grounds for supervisory pressure |
Custodia and the Master Account: A Six-Year Fight Reaches the Supreme Court
The purest test of the debanking question is not a closed checking account. It is a bank that cannot get into the payment system at all. That is the Custodia case. Custodia Bank, founded by the former Wall Street executive Caitlin Long and chartered in Wyoming as a special-purpose depository institution, applied to the Federal Reserve for a master account, the credential that lets a bank plug directly into the US payment rails, in October 2020. The Fed formally denied the application in January 2023, citing safety and soundness concerns tied to Custodia’s crypto focus.
Custodia sued, arguing that the Monetary Control Act of 1980, which says the Fed “shall” provide services to eligible institutions, does not leave room for a discretionary refusal. The courts have so far disagreed. A divided panel of the Tenth Circuit ruled 2 to 1 in October 2025 that Reserve Banks retain discretion over master accounts, and the full court declined to rehear the case 7 to 3 in March 2026 (CoinDesk). In August 2026 Custodia petitioned the Supreme Court, and the Blockchain Association filed a brief backing the appeal, arguing the case has broad consequences for any regulated institution a Reserve Bank decides it does not like (Crowdfund Insider).
Long has been blunt about what operating without a master account is like for a bank that has to rent access through an intermediary rather than hold it directly. She told Banking Dive that Custodia has been “operating with two hands tied behind our back,” and that the workaround is “anything but durable” (Banking Dive). The case cuts to the heart of the debanking debate: if a solvent, fully chartered bank can be kept out of the payment system indefinitely, then access to banking is a privilege regulators grant, not a right the law guarantees.
The 2026 Reversal: Deleting Reputation Risk From the Rulebook
The political response arrived from the top. On 7 August 2025, President Trump signed an executive order titled “Guaranteeing Fair Banking for All Americans,” directing federal banking regulators to strip reputation risk and equivalent concepts out of their guidance and examination manuals, to identify institutions that had engaged in what the order called politicized or unlawful debanking, and to consider remedial action including fines (The White House). Regulators were given until early December 2025 to review their records.
The agencies followed through in stages. In April 2026, the OCC and FDIC formally removed reputation risk as a stand-alone supervisory category, on the reasoning that a bank’s reputation is rarely the true driver of an unsafe condition. Then, on 27 August 2026, they finalized a rule giving the phrase unsafe or unsound practice a hard definition for the first time: a practice contrary to generally accepted standards of prudent operation that, if continued, is likely to materially harm a bank’s financial condition or the FDIC’s Deposit Insurance Fund (American Banker). The point of the definition is to raise the bar. A supervisor can no longer lean on a vague sense that a client is bad for the bank’s image; the concern has to trace back to financial safety.
Taken together, the executive order and the two rules are an attempt to disarm the specific mechanism behind Operation Chokepoint 2.0. If reputation risk can no longer be cited, and if supervisory pressure has to point at real financial harm, then the quiet nudge that allegedly emptied crypto’s bank accounts loses its legal cover. That is the theory. Whether it survives contact with the other half of the rulebook is another matter.
The Collision: Fair Banking Versus AML Law
Here is the tension the 2026 rules cannot fully resolve. The same government that now tells banks they may not debank lawful customers also tells them, under the Bank Secrecy Act, that they must know their customers, monitor them, walk away from risk they cannot manage, and file reports when something looks wrong. Push too hard on fair access and you weaken the second duty; push too hard on AML and you recreate the first problem.
Critics of the fair-banking push made this point as soon as the executive order landed. Forcing banks to serve everyone, they argue, sits awkwardly with a legal regime built on the premise that some customers are too risky to serve, and that treating a genuinely dangerous client the same as a safe one is itself a compliance failure. A bank told it cannot use judgment about reputation may still be told, at the next examination, that it should have caught a laundering typology it now feels pressured to ignore.
The honest description is that the two mandates were never reconciled; they were stacked. Banks are left to find the seam between a duty to include and a duty to exclude, with enforcement risk on both sides. For crypto, that is not an abstraction. It means the same firm can be simultaneously protected by a fair-banking rule and flagged by an AML examiner, and that the resolution of the debanking fight depends less on any single rule than on which of the two mandates a given regulator, in a given year, decides to weight more heavily.
Does the Surveillance Even Work?
Underneath the debanking argument is a harder question the industry keeps trying to force into the open: how much crime does all this catch? The most cited answer comes from the blockchain-analytics firm Chainalysis, whose 2026 crime report estimated that illicit addresses received at least $154 billion in 2025, a 162% jump driven mostly by sanctions evasion, while still amounting to less than 1% of all on-chain transaction volume (Chainalysis). Stablecoins carried about 84% of that illicit value, and value flowing to sanctioned entities rose 694%. The numbers are large in absolute terms and small in relative ones, which is exactly why both sides claim them.
For critics of the current regime, the mismatch is the whole point. Peter Van Valkenburgh of the research group Coin Center argued in a widely-read report that the existing AML and KYC system “does remarkably little to prevent illicit finance,” imposing heavy costs and privacy burdens for what he called negligible benefit, with US compliance spending running to tens of billions of dollars a year (Coin Center). If the system catches little and de-risks much, the debanking of lawful users starts to look less like a side effect and more like the main output.
There is a market response to all of this. Every time the banking system pushes a lawful crypto user out, it pushes them toward self-custody, holding assets in a wallet they control rather than an account a bank can close, an option we compared across the leading software wallets. That shift solves the access problem and creates a new one: self-custody removes the intermediary that files SARs and freezes stolen funds, which is precisely what AML supervisors worry about. Debanking, in other words, can quietly undercut the very surveillance it is meant to serve.
Europe’s Quieter Version: Unwarranted De-risking and the EBA
The debanking fight is loudest in the United States, but Europe has its own version, argued in a lower key. The European Banking Authority (EBA) has spent years warning banks against what it calls unwarranted de-risking. In guidelines issued on 31 March 2023, and an earlier opinion, the EBA drew a sharp line: ending a relationship because a specific customer is genuinely high risk can be legitimate, but cutting off an entire category without weighing individual profiles is a sign of poor risk management, not good compliance (European Banking Authority).
The incoming EU rulebook tries to bake that principle in. The Anti-Money-Laundering Regulation (AMLR), which takes full effect in 2027, tightens crypto AML sharply, banning anonymous crypto accounts and privacy-preserving services, but it also states that where a firm cannot complete due diligence and has to decline a customer, that refusal shall not prohibit the receipt of funds. A new EU authority, AMLA, based in Frankfurt, will directly supervise the highest-risk firms from 2028. The design intent is a system that de-risks genuine threats without sweeping up everyone who looks merely inconvenient.
Europe also exposes a gap that maps directly onto the US Custodia problem. A crypto firm can hold a full license to operate as a crypto-asset service provider under the EU’s MiCA regime and still struggle to open a bank account, because a MiCA authorization is not a banking license and does not oblige any bank to serve the holder. Passing the regulator’s front door, in other words, does not guarantee a seat at the payment table, on either side of the Atlantic.
US Versus EU, and What It Means for You
For anyone actually caught in this, the practical picture depends on where you are and who you are. The table below sets the two regimes side by side.
| Dimension | United States | European Union |
|---|---|---|
| Main lever against debanking | Executive order plus OCC and FDIC rules removing reputation risk | EBA guidelines on unwarranted de-risking |
| Who is protected | Any lawful customer; strong political focus on crypto | Emphasis on vulnerable customers and legitimate businesses |
| Right to an account | No general right; the Custodia case tests Fed master-account access | No general business right; consumer basic-account rules exist in member states |
| AML authority | FinCEN and OFAC, with OCC, FDIC, and Fed supervision | AMLR and AMLA from 2028; national regulators today |
| Open question | Can fair-banking rules coexist with Bank Secrecy Act duties? | Will the AMLR carve-outs actually stop category-wide de-risking? |
If you run a crypto business, the durable defenses are unglamorous. In practice they come down to a short checklist:
- Keep more than one banking relationship, so a single closure never strands payroll.
- Run a real AML program and keep clean documentation of where funds come from.
- Get any account closure in writing, since the 2026 US rules may make an unjustified one easier to challenge.
- Hold a portion of treasury in self-custody as a backstop against losing access entirely.
Three things will decide where this goes. The first is the Supreme Court’s handling of Custodia, which could settle whether the Fed’s master-account discretion is reviewable at all. The second is enforcement of the new US rules: a definition of unsafe or unsound practice only matters if examiners actually change how they behave. The third is Europe’s 2027 AMLR switch-on and the arrival of AMLA in 2028, which will test whether a rulebook can be written to catch real risk without debanking the merely inconvenient. Underneath all of it sits the question Van Valkenburgh keeps pressing: whether a surveillance system that catches so little is worth the accounts it closes.
Frequently Asked Questions
What is the difference between debanking and de-risking?
Debanking is when a single customer loses or is denied a bank account. De-risking is the broader practice of a bank exiting an entire category of customers, for example all crypto firms, without assessing each one individually. FATF has said since 2014 that blanket de-risking is not the risk-based approach regulators expect banks to follow.
Is crypto debanking legal in the United States?
There is no general legal right to a bank account in the US, so a bank can usually decline or close accounts at its discretion. What changed in 2026 is that regulators removed reputation risk as a supervisory category and defined unsafe or unsound practice narrowly, making it harder for supervisors to pressure banks into dropping lawful crypto clients. The Custodia case, now at the Supreme Court, tests whether the Federal Reserve must grant payment-system access to eligible institutions.
Does the SEC handle anti-money-laundering rules for crypto?
No. In the US, AML authority runs through FinCEN and OFAC under the Bank Secrecy Act, and banks’ AML programs are supervised by the OCC, FDIC, and Federal Reserve. The SEC deals with the securities dimension of crypto, not the money-laundering rules. Crypto exchanges are treated as money services businesses and register with FinCEN.
What was Operation Chokepoint 2.0?
It is the crypto industry’s name for what it alleges was a coordinated effort by US regulators between roughly 2022 and 2024 to cut crypto firms off from the banking system, echoing a 2013 initiative aimed at payday lenders and gun dealers. FDIC pause letters released under a Freedom of Information Act suit showed the agency telling banks to pause crypto activity, which the industry treated as supporting evidence.
What can a crypto business do if it gets debanked?
Keep more than one banking relationship, maintain a strong AML compliance program and clean records of where funds come from, and document any account closure that lacks a stated reason, since the 2026 US rules may make unjustified closures easier to challenge. Many firms and individuals also hold assets in self-custody so that no single account closure can cut off access to their crypto.
By Anneke de Vries, Regulation and Policy Desk, HOGE Wire.