The proposed BRCA changes are a tough pill to swallow
The revised language stops short of resolving the essential criminal law issue; Lewellen’s lawsuit becomes that much more important.
The revised language stops short of resolving the essential criminal law issue; Lewellen’s lawsuit becomes that much more important.
The Senate is scheduled for a pivotal vote on the Clarity Act tomorrow, and in an effort to secure the 60 votes needed for passage, the drafters have made last-minute revisions to the Blockchain Regulatory Certainty Act (BRCA). The revised language would still provide important protections for non-controlling blockchain developers under the Bank Secrecy Act (BSA), but it removes the BRCA’s explicit protection against criminal liability under 18 U.S.C. § 1960.
That is an important change to a provision Coin Center has championed for years and that has now, incredibly, reached the point of potential passage into law.
As a reminder, the BRCA would proactively protect developers and service providers like validators against being treated as “money transmitters” when they do not take control of user funds. This is critical to defining the line between what is at the core of this ecosystem: developers who create software that anyone can use to conduct peer-to-peer transactions and those who operate centralized businesses that play a trusted intermediary role and are generally subject to traditional financial regulation and liability for their customers’ activities.
We have seen the consequences when that line is blurry. Developers have faced uncertainty about their potential liability and have been dissuaded from publishing and operating software that allows users to transact without an intermediary. More concerning, we have seen aggressive prosecutors bring criminal cases premised in significant part on the fact that a developer distributed software that was ultimately used by bad actors for criminal purposes.
We have pushed hard for BRCA because Clarity should not just clarify the rules for centralized exchanges and other intermediaries. It should also clarify the legal environment for the developers building and operating the infrastructure on which this entire ecosystem depends.
The revised BRCA makes substantial progress on the regulatory side. Section 10604(c) provides that a qualifying “non-controlling blockchain developer or provider” shall not be treated as (1) a “money transmitting business” under 31 U.S.C. § 5330, (2) a “money transmitter” under regulations from the Financial Crimes Enforcement Network (FinCEN), or (3) a specified “financial institution” under Title 31. It also protects covered software development, self-custody, and infrastructure activities against substantially similar registration requirements.
This would essentially codify the control-based approach FinCEN articulated in its 2019 guidance and provide an important statutory protection against future regulatory overreach. Developers who cannot control users’ funds should not be saddled with AML obligations that they often have no technical ability to perform.
But the revised language stops short of resolving the essential criminal-law question that has led to the indictment of software developers and made the BRCA a vital provision.
Earlier BRCA language expressly protected qualifying non-controlling developers from being treated as engaged in “money transmitting” under 18 U.S.C. § 1960—the criminal statute prohibiting certain unlicensed money transmitting businesses. The revised BRCA removes that explicit protection.
But because the revised BRCA still establishes that qualifying non-controlling developers are not money transmitters subject to federal registration requirements, it should significantly strengthen the argument against prosecutions under Section 1960(b)(1)(A) and (B). Those provisions target money transmitting businesses that operate without a required state license or fail to comply with federal registration requirements under 31 U.S.C. § 5330. If Congress expressly provides that a non-controlling developer is not subject to those money-transmitter requirements in the first place, it becomes much harder to argue that the developer committed a crime by failing to comply with them.
The developers of Tornado Cash and Samourai Wallet were both charged under Section 1960(b)(1)(B) before then-Deputy Attorney General Todd Blanche directed the Department of Justice (DOJ) not to pursue digital-asset cases premised on unwitting regulatory violations.
Unfortunately, Section 1960(b)(1)(C) remains unresolved. Unlike subsections (A) and (B), the language of subsection (C) is not explicitly premised on the failure to obtain a license or register with FinCEN. It is a broader and more ambiguous criminal statute but still entails a charge for unlicensed money transmission. The DOJ explicitly chose to continue pursuing these cases in the Blanche memo, and the developers of Tornado Cash and Samourai Wallet were both charged with subsection (C) charges as well.
That is deeply disappointing. Section 1960(b)(1)(C) has been central to criminal cases against open-source developers. We believe that the concept of money transmission under all laws, both regulatory and criminal, should be subject to the same basic principle: whether a person actually takes control of another person’s funds.
Ultimately, all three subsections of Section 1960(b)(1) turn on whether a criminal defendant is operating an “unlicensed money transmitting business.” We believe there’s a genuine due process concern with holding someone criminally liable for being unlicensed when the regulator says they don’t need a license in the first place. Still, the DOJ has ignored this requirement and gone ahead with prosecutions without first proving that criminal defendants were operating unlicensed money transmitters. We also find strong arguments that liability for publishing code chills protected speech and is unconstitutional under the First Amendment.
The revised BRCA would therefore establish an important rule for federal registration and regulatory obligations: a non-controlling developer is not a money transmitter merely because they build or provide software and infrastructure. But it would leave unresolved whether prosecutors may nevertheless argue that the same developer is engaged in “money transmitting” under 18 U.S.C. § 1960.
Should Clarity pass with this language, that question will remain for the courts to decide. Coin Center fellow Michael Lewellen is suing the DOJ seeking declarative judgement to get clarity that persons developing and maintaining non-custodial software is not criminal conduct. That case becomes even more important in a world where the BRCA does not address the criminal law implications of such conduct, and developers remain fearful of wrongful criminal prosecution. Coin Center will continue pushing for clear protection against criminal liability for people who merely develop blockchain software, publish code, or run non-controlling infrastructure.
The revised BRCA would still represent meaningful progress. Congress would, for the first time, put into statute the principle that developers who do not control user funds should not be regulated as money transmitters simply because they build the tools that allow people to transact. That is worth recognizing. But it is not the full protection Coin Center has advocated for, and it does not end the debate over criminal liability for non-controlling developers. If enacted, there will still be important work left to do.