§307 and the Self-Hosted Wallet Question

July 1, 2026

The FinCEN proposal that became Notice 2020-CVC-2 was published on December 23, 2020, three weeks after the Mnuchin Treasury Department announced the end-of-term initiative to subject self-hosted wallet transactions to reporting and recordkeeping requirements equivalent to those for traditional financial-institution wires. The proposed rule would have required money services businesses to collect, record, and report transactions with self-hosted wallets above defined thresholds, including the identity of the counterparty controlling the self-hosted wallet. Coin Center filed comments characterizing the proposal as unconstitutional under the Fourth Amendment, the First Amendment, and the Administrative Procedure Act. The Biden administration withdrew the proposed rule in early 2021 but the underlying policy concern (illicit-finance flows through self-hosted wallets that bypass regulated financial intermediaries) persisted across two administrations. The OFAC designation of Tornado Cash smart-contract addresses on August 8, 2022, then Coin Center v. Yellen, 5:22-cv-00149 (E.D. Ky.), then Van Loon v. Department of the Treasury, 122 F.4th 549 (5th Cir. 2024), then the OFAC withdrawal of the designations in March 2025, made clear that the regulatory authority over self-hosted wallets was both constitutionally constrained and politically contested.

§307 of CLARITY answers the self-hosted wallet question structurally. §307(b) amends 31 U.S.C. § 5312(a)(3)(D) to expressly include digital assets within “monetary instruments,” which has cascading BSA implications. §307(c) requires Treasury to conduct a national-strategy risk assessment that explicitly weighs both illicit-finance risks and civil-liberties benefits of self-hosted wallets. §307(d) is the operational constraint: any Treasury guidance “shall not require a regulated entity to collect… personally identifiable information about the controller of a self-hosted wallet when the controller is not both the customer of the regulated entity and a party to such transaction, except as required by Federal law, including United States sanctions laws and regulations or lawful process.” The 2020 FinCEN NPRM in the form it took would be foreclosed.

§307(b) and the Monetary-Instrument Amendment

§307(b) is short but has cascading consequences. The amendment to 31 U.S.C. § 5312(a)(3)(D) inserts “including digital assets (as defined in section 2 of the GENIUS Act (12 U.S.C. 5901)), as may be applicable,” after “value” in the existing statutory text. The pre-amendment text included “any other instrument or evidence of value, including stored value.” The post-amendment text includes digital assets within that residual category, with an “as may be applicable” qualifier that preserves Treasury’s interpretive flexibility on which digital-asset transactions fall within the BSA monetary-instrument framework.

The structural significance of the §5312(a)(3)(D) amendment runs through the BSA. The monetary-instrument definition is the threshold definition that triggers the BSA’s reporting and recordkeeping framework. Form 8300 reporting (cash transactions over $10,000), suspicious activity reporting (SAR), currency transaction reporting (CTR), and the various record-retention requirements operate against a monetary-instrument predicate. Inclusion of digital assets within the monetary-instrument definition extends the BSA framework to digital-asset transactions, at least in principle.

The “as may be applicable” qualifier is the operational constraint. Not every digital-asset transaction is subject to BSA reporting. Treasury retains authority to specify which digital-asset transactions fall within the BSA framework through rulemaking, guidance, and interpretive positions. The qualifier preserves Treasury’s flexibility to draw lines that reflect the operational realities of digital-asset transactions: peer-to-peer transactions on permissionless networks, smart-contract interactions, decentralized-exchange transactions, and self-hosted-wallet transactions raise different policy considerations than custodial-intermediary transactions.

The §307(b) amendment also has cross-references throughout the BSA framework. The §5318 customer due diligence and SAR-filing requirements operate against monetary-instrument transactions. The §5331 reporting of nonfinancial trades or businesses operates against monetary-instrument transactions. The §5332 bulk-cash-smuggling provisions operate against monetary instruments. Each of these provisions would reach digital-asset transactions to the extent Treasury implements them. The §307(d) operational constraint then layers on top, limiting how Treasury may implement these provisions with respect to self-hosted wallets specifically.

§307(c) the Treasury Risk Assessment

§307(c) directs Treasury, as part of the national strategy for combating terrorist and other illicit financing required under §§ 261 and 262 of the Countering America’s Adversaries Through Sanctions Act, to consider eight enumerated factors. The list is structurally important because it builds civil-liberties analysis into the regulatory baseline.

  • (1) illicit activity, such as money laundering and sanctions evasion, involving self-hosted wallets. This is the conventional illicit-finance framing. Treasury is required to assess and quantify the illicit-finance flows through self-hosted wallets, which is what FinCEN had attempted to do as the justification for the 2020 NPRM.
  • (2) the effectiveness of, and gaps in, existing methods, techniques, and strategies used by regulated financial institutions in detecting illicit activity involving self-hosted wallets. This is a regulatory-effectiveness assessment that asks whether existing tools (blockchain analytics, transaction monitoring at on-ramps and off-ramps, sanctions screening at custodial intermediaries) are adequate or whether additional tools are needed. The structural choice is to require Treasury to demonstrate the inadequacy of existing tools before proposing new ones.
  • (3) any illicit actors, including nation-state actors, that pose a high risk of facilitating illicit activity through the use of self-hosted wallets. This is the threat-actor assessment. North Korean state-sponsored cyber actors (the Lazarus Group and similar operations) have used self-hosted wallets to launder proceeds from cryptocurrency exchange hacks. Russian sanctioned entities have used self-hosted wallets to attempt sanctions evasion. The threat assessment is required, but it is structured to focus on specific actors rather than on self-hosted wallets generally.
  • (4) is the civil-liberties counter-balance. Treasury is required to consider “the benefits of the use of self-hosted wallets to (A) enhance user privacy and civil liberties through direct asset custody; and (B) expand financial inclusion and access for communities underserved by traditional financial institutions.” This is the structurally important provision. The 2020 FinCEN NPRM did not engage seriously with the civil-liberties and financial-inclusion benefits of self-hosted wallets. The §307(c)(4) directive requires Treasury to do so in the current risk-assessment cycle.
  • (5) end-user and counterparty risks associated with self-hosted wallets, including consumer fraud, cybersecurity, and identity verification. This is the consumer-protection assessment. Self-hosted wallets impose user-protection costs (lost keys, phishing, fraud) that custodial intermediaries internalize. The assessment is required to quantify these costs.
  • (6) the use of hardware self-hosted wallets to smuggle digital assets for financing cross-border illicit activity. This is the bulk-cash-smuggling analog. The pre-CLARITY policy debate on this issue centered on whether physical hardware wallets carrying private keys to substantial digital-asset balances are functionally equivalent to bulk-cash transportation across borders. The assessment is required to address the question empirically.
  • (7) the use of hardware self-hosted wallets for tax evasion and asset concealment. The IRS and Treasury’s tax-enforcement assessment of self-hosted wallet usage. The cross-reference to the §6045 broker-reporting framework and the Coin Center v. Treasury litigation is implicit.
  • (8) other considerations the Secretary may determine appropriate. The residual clause allowing Treasury flexibility on the assessment scope.

The cumulative structure of §307(c) is to require a balanced risk assessment that internalizes civil-liberties and financial-inclusion analysis alongside the conventional illicit-finance analysis. The pre-CLARITY assessment posture, which produced the 2020 FinCEN NPRM, focused predominantly on illicit-finance concerns without serious engagement with the civil-liberties counter-weights. §307(c)(4) and the requirement for assessment under the national-strategy framework would structurally constrain Treasury to do better in the next cycle.

§307(d) the Operational Constraint

§307(d) is where the rubber meets the road. The Secretary of the Treasury “may issue guidance for financial institutions that transact with self-hosted wallets based on the results of the research on benefits and risks required under subsection (c), which shall not (1) require a regulated entity to collect, with respect to any transaction, personally identifiable information about the controller of a self-hosted wallet when the controller is not both the customer of the regulated entity and a party to such transaction, except as required by Federal law, including United States sanctions laws and regulations or lawful process; or (2) be construed to hinder, restrict, or otherwise impair the authority of any Federal agency to investigate, detect, counteract, or prevent illegal activity.”

The §307(d)(1) constraint would foreclose the central element of the 2020 FinCEN NPRM. Treasury could not require a regulated financial institution to collect PII about the controller of a self-hosted wallet who is not both a customer of the institution and a party to the specific transaction. The structural carve-outs are (i) other federal law that requires the collection (including U.S. sanctions law), and (ii) lawful process (subpoenas, court orders, search warrants).

The 2020 FinCEN NPRM would have required institutions to collect PII about counterparties to self-hosted wallet transactions even when those counterparties were not the institution’s customers. §307(d)(1) prohibits exactly that requirement, with the exceptions narrowly drawn. A regulated institution can collect PII about its own customer (because the customer is both the controller of the self-hosted wallet and a party to the transaction; the parenthetical conjunction matters). A regulated institution cannot be required by Treasury to collect PII about the other end of a self-hosted-wallet transaction when that party is not its customer.

The sanctions-law carve-out is important. Treasury can require institutions to screen self-hosted wallet counterparties against the OFAC SDN list, and to refuse transactions with sanctioned addresses. The §307(d)(1) framework does not affect sanctions compliance. What it affects is the affirmative collection of PII about non-customer counterparties for AML/CFT purposes outside the sanctions framework.

The lawful-process carve-out preserves law-enforcement access. A subpoena, court order, or search warrant can compel an institution to disclose information about a self-hosted wallet counterparty regardless of the §307(d)(1) limit on routine collection. The §307(d)(1) framework constrains regulatory authority over data collection; it does not constrain criminal-procedure authority over evidence gathering.

§307(d)(2) preserves federal-agency authority over illegal activity investigation, detection, counteraction, and prevention. The §307(d)(1) constraint does not impair these authorities. The structural choice is to preserve enforcement authority while constraining regulatory authority over routine data collection.

Why the 2020 NPRM Could Not Come Back

The principal substantive consequence of §307(d) is that the 2020 FinCEN NPRM, in the form it took, could not be reissued. The proposed rule would have required money services businesses to collect, record, and report PII about counterparties to self-hosted wallet transactions above $3,000 (for recordkeeping) and $10,000 (for reporting), even when those counterparties were not customers of the reporting institution. The collection requirement is exactly the activity §307(d)(1) prohibits.

Treasury would retain authority to require other aspects of the 2020 NPRM. The recordkeeping requirements for the institution’s own customers (where the customer is the controller of a self-hosted wallet and a party to the transaction) are not foreclosed. The reporting of suspicious activity involving self-hosted wallets remains within Treasury’s existing SAR-filing framework. The sanctions-compliance screening of self-hosted wallet counterparties is not foreclosed. What §307(d)(1) eliminates is the centerpiece of the 2020 proposal: the affirmative-collection requirement for non-customer counterparty PII.

The structural effect is that self-hosted wallets would remain a viable financial-privacy infrastructure under U.S. law. Users who hold their own keys can transact with regulated institutions without those institutions being compelled to collect PII about the user’s counterparties. The institution can still satisfy its own customer-identification, customer-due-diligence, and beneficial-owner-identification obligations with respect to its customers. It just cannot be required to extend those obligations to non-customer self-hosted-wallet counterparties.

§307(a)(1) and the Self-Hosted Wallet Definition

§307(a)(1) defines self-hosted wallet as “a digital interface (A) that is used to secure and transfer digital assets; and (B) under which the owner of digital assets secured and transferred under subparagraph (A) retains independent control over those digital assets.” The definition is parallel to §605(b)(2) (the Keep Your Coins Act). The two definitions track each other.

The structural element is the “independent control” requirement. A wallet under which the user can independently move funds without the consent or participation of any third party is self-hosted. A wallet under which the user must obtain the consent or participation of a custodian to move funds is not. The MetaMask, Phantom, Rabby, and similar non-custodial wallets are self-hosted. Coinbase Wallet (in its non-custodial mode) is self-hosted. The custodial Coinbase exchange account is not. Hardware wallets (Ledger, Trezor) are self-hosted. Multisig wallets where the user holds enough keys to move funds independently are self-hosted; multisig wallets where the user does not hold enough keys are not.

The “independent control” formulation is the same one used in FinCEN’s 2019 guidance (FIN-2019-G001) to distinguish money-transmitter wallet providers from non-money-transmitter software providers. The structural consistency between FinCEN’s interpretive framework and the §307 statutory framework simplifies the operational analysis: a wallet that satisfies the §307(a)(1) self-hosted definition is also not within FinCEN’s money-transmitter framework under the 2019 guidance, and a wallet provider that creates the wallet without controlling user funds is a non-controlling developer or provider under §604.

Cross-References to §305 and §303

§307 cross-references §305 (temporary hold) and §303 (special measures expansion). The §305 framework, covered in Post #15 of this series, creates a hybrid private-actor freeze mechanism that permits covered persons to delay execution of transactions on reasonable belief of law violation or qualified written request from a covered agency. The §305 framework operates against transactions involving covered persons (permitted payment stablecoin issuers, registered foreign issuers, digital-asset service providers), which means the §305 freeze authority is broader than self-hosted-wallet transactions. But §305(c) preserves §307(d)(1) by stating that the section does not require compelled freezes beyond existing law.

§303 expands FinCEN’s special-measures authority under 31 U.S.C. § 5318A. The special-measures framework permits Treasury to impose targeted reporting, prohibition, or other requirements on specific jurisdictions, institutions, or transactions identified as primary money-laundering concerns. The §303 expansion incorporates digital-asset transactions within the special-measures authority. §303 is structurally distinct from §307: the special-measures authority is targeted (specific entities or transactions identified as primary concerns), while §307(d)(1) addresses routine institution-wide data collection. The two operate at different levels of the regulatory framework.

Comparison to EU AMLR

The EU’s Anti-Money Laundering Regulation, AMLR, adopted in 2024 and entering into force in mid-2027, takes a structurally different approach to self-hosted wallets. The AMLR imposes verification requirements on crypto-asset service providers when transacting with self-hosted wallets above €1,000, with specific identification and counterparty-verification obligations. The EU framework is closer to the 2020 FinCEN NPRM than to the §307 framework.

The divergence between the EU and U.S. frameworks has cross-border implications. A U.S.-domiciled exchange transacting with a self-hosted wallet from an EU user faces the §307(d)(1) constraint on data collection in the United States and the AMLR requirements in the EU. The structural conflict requires either dual compliance (collecting data for EU purposes that the §307(d)(1) constraint does not require for U.S. purposes) or jurisdictional limitations (the exchange does not transact with EU-based self-hosted wallets above the AMLR threshold). The cross-border policy reconciliation is ongoing and is the subject of §507 of CLARITY (international coordination on digital-asset illicit-finance combatting).

§6045 and Tax-Reporting Cross-Issues

The Treasury 2024 Final Regulations on Broker Reporting under §6045, T.D. 10000, extended broker-reporting requirements to certain digital-asset intermediaries. The regulations were challenged in Coin Center v. Treasury and related litigation, with the principal legal claim that the §6045 broker definition could not constitutionally reach non-controlling parties to digital-asset transactions. The §307 framework does not directly address §6045 broker reporting (which is a tax-reporting framework rather than a BSA framework), but the structural commitments in §307(d)(1) and §605 are relevant to the §6045 analysis.

A regulated entity that is a §6045 broker continues to face its broker-reporting obligations. The §307(d)(1) constraint applies to BSA collection, not to tax-reporting collection. But the structural commitment to limiting routine collection of self-hosted wallet counterparty PII implicit in §307(d)(1) provides interpretive support for narrowing constructions of the §6045 broker definition. The Coin Center litigation and its progeny will play out on tax-law grounds, but the §307 framework, if enacted, would stand as an authoritative congressional signal that self-hosted wallets occupy a privileged position in the U.S. financial-regulatory architecture.

The Compliance Consequences

Four compliance consequences follow.

  • First, enactment kills the 2020 FinCEN NPRM in the form it took. Treasury could not reissue the proposal as written. The §307(d)(1) constraint forecloses the affirmative-collection requirement for non-customer self-hosted wallet counterparty PII.
  • Second, customer-side compliance is unchanged. An institution’s obligations with respect to its own customers (KYC, CDD, beneficial-owner identification, SAR-filing) are not affected by §307. The §307(d)(1) constraint runs against affirmative-collection requirements for non-customer counterparties, not against customer-side compliance.
  • Third, sanctions compliance is preserved. The §307(d)(1) sanctions-law carve-out preserves OFAC compliance. Institutions can be required to screen self-hosted wallet counterparties against the SDN list and to refuse transactions with sanctioned addresses. The Tornado Cash designation arc (and the subsequent withdrawal) is an artifact of the IEEPA framework, not of §307. Sanctions compliance continues to operate on its own terms.
  • Fourth, cross-border friction is real. The EU AMLR framework imposes obligations that the U.S. §307 framework does not. Institutions operating across both jurisdictions face structural compliance tensions. The §507 international-coordination framework provides a path to resolution, but the timing is uncertain and continued divergence is the near-term planning assumption.

The §307 framework is, in the aggregate, a substantial accommodation of the self-hosted-wallet privacy and financial-inclusion case. It forecloses the 2020 FinCEN proposal, builds the civil-liberties analysis into the regulatory baseline, and makes the constraint on routine collection of non-customer PII statutory. The remaining questions are how Treasury implements the §307(c) risk assessment, how the resulting guidance is drafted, and how cross-border friction with the EU AMLR is managed. The architectural commitment to self-hosted wallets as legitimate financial infrastructure is now in the bill text, one signature away from statutory law, and enactment would end the policy debate over the 2020 NPRM.

Written by David Lopez Kurtz