Much of the compliance burden on American crypto businesses comes from rules written decades before the technology existed. Money transmission law is the framework doing most of the work.

The definition is about function

Money transmission is broadly the business of accepting value from one person and making it available to another, which is deliberately written to be technology neutral.

An exchange holding customer balances and processing withdrawals fits that description regardless of what the value being moved is called.

This is why the framework applied without needing new legislation, and why arguments about whether a token is a security do not exempt a firm from these duties.

Federal registration and reporting

Businesses meeting the federal definition must register as money services businesses and build a compliance program with policies, training and an appointed officer.

Reporting obligations follow, including filings on transactions above certain thresholds and reports on activity that appears designed to evade those thresholds.

Records must be kept for defined periods and produced on request, which is why exchanges retain detailed histories long after an account has closed.

Identity collection follows from this

Customer identification requirements are the source of the documents every American exchange asks for at signup, which users often attribute to the exchange's own preference.

Ongoing monitoring is required as well, so an account whose pattern of activity changes materially can be reviewed or restricted without any accusation being made.

The obligation to report certain activity comes with a prohibition on telling the customer, which is why explanations for account freezes are frequently unavailable.

How custody changes the analysis

The rules generally attach where a business takes control of customer value, so holding keys is the pivotal fact rather than the software's capabilities.

Wallet software that never holds funds and merely helps a user sign their own transactions sits differently, and this distinction has been argued repeatedly.

Where responsibility falls for peer-to-peer protocols with no operator remains genuinely unresolved, and positions on it have shifted over time.

Why the framework fits imperfectly

Rules built for wire transfers assume identifiable senders, recipients and intermediaries, and public blockchains supply pseudonymous addresses instead.

Adapting the requirements has produced awkward results, including rules about transmitting customer information alongside transfers that have no natural place to sit.

Requirements continue to evolve through guidance and enforcement rather than through comprehensive legislation, so specifics change and vary by jurisdiction.