A normie’s guide to the fight over the Blockchain Regulatory Certainty Act
Why the struggle over the legal definition of “money transmitting” matters beyond crypto
Hello! Before we get to our latest edition, a reminder that we just announced the Third Annual DC Privacy Summit. The main event will take place on October 15. Check out dcprivacysummit.org for more info, and to grab your tickets (use this link or the code DCPS2026 for $100 off the ticket price). You can also check out our highlight video from last year’s event, below. Hope to see you in October.
Unpacking the confusing dispute over CLARITY’s protections for software developers
by Mike Orcutt
If you’ve ever spoken with me in person, there’s a good chance I told you something: I’m not “pro-crypto.” I’m a technology journalist who fell down the crypto rabbit hole a decade ago and haven’t climbed out. What I do advocate for, though, is better conversations about crypto, because I believe this would be good for privacy and freedom of expression online.
In that light, there’s a conversation around a specific piece of the Digital Asset CLARITY Act, the crypto market structure bill that has been moving through Congress this year, that could be much better.
The breakdown concerns language in the bill that originates from an older piece of proposed legislation known as the Blockchain Regulatory Certainty Act (BRCA). Proponents, who tend to be “pro-crypto,” say it protects software developers against prosecutorial overreach. Opponents of the language say it will make it harder to fight crypto-related crime. But the underlying conflict has implications that stretch beyond cryptocurrency.
The prosecution of Roman Storm illustrates why.
Nearly a year ago Storm, one of the developers of the Ethereum-based privacy tool Tornado Cash, was convicted in US federal court of “conspiracy to operate an unlicensed money transmitting business.” He faces five years in prison. (He’s also scheduled to face trial for two other charges—conspiracy to commit money laundering and conspiracy to violate US sanctions against North Korea—after the jury in his first trial was unable to reach a verdict on those.)
The case against Storm is bewildering, and next to impossible for folks who aren’t deep in the crypto rabbit hole to grasp. But I’m going to try to break it down here in a way that curious normies can follow, because it reflects a strategy by the government that could have implications for all kinds of non-crypto software.
When the government disagrees with itself
Under a US law known as the Bank Secrecy Act, money-transmitting businesses must obtain a license in order to operate legally. Those licenses are issued by the Financial Crimes Enforcement Network (FinCEN, part of the Treasury Department), and apply to traditional banks as well as newer entities like Venmo-style digital payment services and centralized crypto exchanges.
In 2019, in response to the rapid evolution of the cryptocurrency industry in the preceding few years, FinCEN published guidance stating that a person or entity is not a money transmitter if they do not take “total independent control” of customer funds. That means they don’t need a license. Storm and his co-developers did not take control of user funds. Even the prosecutors in Storm’s case don’t dispute this—and yet, he was convicted of operating an unlicensed money transmitting business. How?
The prosecutors and the jury that convicted Storm believe the language of a separate law, Section 1960 of the US criminal code, pertained. Section 1960 works alongside the BSA. The former requires that money transmitting businesses be licensed. The latter is what makes it a federal crime to operate without one.
In 2001, shortly after 9/11, Congress used the PATRIOT Act to broaden Section 1960, adding a new category of unlicensed money transmitting that doesn’t mention the word “license” at all. The PATRIOT Act addition states that the crime of unlicensed money transmitting can be defined as activity that “involves the transportation or transmission of funds that are known to the defendant to have been derived from a criminal offense or are intended to be used to promote or support unlawful activity.”
This is the language that the DOJ used to prosecute Storm. Prosecutors were able to convince a jury that he “transmitted” funds he knew to be criminal in nature. So the jury found him guilty of operating an unlicensed money transmitting business—even though the regulator who licenses money transmitting businesses said a license wasn’t necessary.
Storm’s case wasn’t a one-off. The DOJ prosecuted Keone Rodriguez and William Lonergan Hill, co-developers of a privacy-enhancing Bitcoin wallet called Samourai, using the same approach. Both men pleaded guilty last year, and, in the words of the judge in the case, admitted to aiding the “transportation and transmission of funds derived from criminal offenses.” Like Storm, they did not take control of user funds. As part of the deal, prosecutors agreed to drop an additional charge that they conspired to launder money.
Storm, Rodriguez, and Lonergan Hill built and deployed blockchain-based software tools that move money around automatically; others used those tools—which were free for anyone to use because that’s how a blockchain works—to commit crimes. The developers were not sending money on behalf of others, because they didn’t have any control over the funds flowing through the software.
The BRCA has a simple purpose: it establishes that “non-controlling” developers won’t be considered money transmitters by the BSA or Section 1960.
How free should software be?
That would resolve the contradiction that ensnared Storm and the Samourai developers. But opponents of the BRCA language say it would also make it harder to stop crimes.
“Existing investigative authorities and regulatory frameworks play a critical role in helping investigators and prosecutors identify bad actors, follow financial trails, recover assets for victims, and hold offenders accountable,” reads a June 23 letter to Senate leaders from the National Sheriffs Association, the National Association of US Attorneys, the National District Attorneys Association, and the International Association of Chiefs of Police. The BRCA language “risks creating gaps in oversight and accountability that could impede these efforts,” those groups wrote.
The Alliance to End Human Trafficking, a group of Catholic organizations, argued that the BRCA wording “could create broad carveouts and regulatory ambiguities that may make it more difficult to responsibly monitor illicit financial activity tied to trafficking, organized crime, child exploitation, sanctions evasion, and other forms of abuse,” in another letter to top senators sent on the same day.
The “pro-crypto” Trump administration’s own DOJ may not even be completely on board. Punchbowl News recently obtained an email dated July 7 from a “senior DOJ official” in the Criminal Division to the Treasury Department stating that CLARITY, as it stands, “would ‘impose a higher burden of proof for prosecutions’ for money laundering charges.”
Hold on a second, though. Why are we talking about money laundering? The BRCA language refers to money transmitting, not money laundering, which is a different crime that requires different evidence to prove. That could be Punchbowl’s wording and not the DOJ official’s; it’s not part of the quoted material. But in that case, the thing the DOJ official is ostensibly complaining about—imposing “a higher burden of proof for prosecutions” for unlicensed money transmitting—is the whole point of BRCA.
Peter Van Valkenburgh, the Executive Director at the crypto think tank Coin Center, said it wouldn’t be surprising if Justice Department officials weren’t happy with BRCA. After all, he tweeted, it asks prosecutors “to do more work finding actual evidence that someone intended to move criminal money rather than simply built software tools for anyone to move money.”
In Van Valkenburgh and Coin Center’s view, that’s what the US Constitution—and specifically the First Amendment—calls for. He argues that requiring a license to create and deploy software on a blockchain is a violation of the right to free speech. US courts have recognized software code as speech since around 1995, when mathematician Daniel Bernstein sued the government for requiring him to register as an arms dealer before he could publish the source code for an encryption algorithm he created. Crucially, however, the Supreme Court has never definitively established the Constitutional status of software code.
If CLARITY doesn’t pass, the fight to define “unlicensed money transmitting” will continue. But something else will also likely continue: the government will keep trying to enhance its power to control the development of and access to novel software systems it finds threatening. And as might already be obvious to anyone following the administration’s attempts to control access to advanced AI models, this won’t be limited to crypto.
In other words, the US seems on the precipice of a monumental legal conflict. The cases against Tornado Cash and Samourai were an opening volley. At stake is whether all software really is protected by the First Amendment, whether certain new software systems should be regulated, and, if so, how exactly we should do that.
In which we share news and happenings, and ponder what they portend…
AI & agents
Will cool cryptography make it safe to trust AI agents with your money? Moonpay thinks so. The company debuted its new agentic payment system PayBox last week to a decent amount of fanfare—the company claims 224,000 people signed up for the new service within a day of launch.
People, especially people in crypto, are excited about the prospect of AI agents paying for things. But the problem with giving an AI system the ability to spend money on your behalf is… how do you stop it from going rogue and buying stuff you didn’t ask it to? Or worse, what if someone convinces it to cough up your financial details? LLMs regularly behave in unexpected ways, and we haven’t yet figured out a foolproof way of preventing bad outcomes. That’s one big reason that frontier AI labs haven’t already released their own payment systems.
The team at Moonpay think they’ve solved this problem with PayBox, which is essentially a fancy cryptographic container that plugs into Claude or ChatGPT. It allows users to order up an item or service via a standard chatbot interface and specify how the agent should pay.
When someone sets up PayBox to use crypto, the private keys needed to make transactions using their crypto wallet are broken into fragments, which are then stored, in encrypted form, in several different locations using trusted hardware (this approach was developed by the Israeli cryptography firm Sodot, which Moonpay acquired earlier this year). You can also use a credit card, but that works a little differently; Moonpay says PayBox plugs into Visa’s agentic payment network, which handles the transaction from there. In both cases, the idea is that neither the AI agent nor PayBox itself ever takes full control of the ability to carry out a transaction.
Before a transaction can happen, a user must give permission. The transaction must either fit a series of parameters a user sets, such as how much to spend, or be individually approved (people can choose between “Autonomous” mode and “Always Ask” mode).
In theory, the combination of cryptographic and user-approval mechanisms will thwart an AI from running amok with your money, or attackers from draining your accounts. The company’s slick demo sure makes it look easy to connect up your agent and get started.
So, who’s ready to let a robot do their shopping?
Cops have a fever, and the solution is more AI. Police departments around the US and the world recently gathered at the annual meeting of the International Association of Chiefs of Police, a large conference and trade show for police tech that’s sometimes referred to as “Cop Con.” As the Verge points out, there is a huge commercial push to sell AI-powered tools to cops. The tools are sometimes billed as a way to turn the deluge of data that officers must contend with—streams of information from social media activity, arrest databases, networks of license plate readers, gunshot detection systems, facial recognition cameras, and so on—into useful insights into how to fight crime and protect communities. But by offloading human decision-making to automated tools, longstanding questions about the nature of modern policing become even more urgent: as surveillance capabilities continue to grow, are we all treated as suspects? Will police departments simply keep adopting more and more powerful technology into infinity? Where in the course of police work is there room to make complicated decisions about how much surveillance is too much?
Privacy & Identity
Whoever is behind a devastating bitcoin attack appears to have used blockchain data to zero in on high-value wallets. That’s according to Chainalysis, which posted evidence supporting their assessment on Twitter. The attackers exploited a vulnerability in a hardware wallet called Coldcard to steal upwards of $100 million thus far. They were able to net $30 million in just the first 10 minutes of the attack by prioritizing big wallets, Chainalysis said.
France has banned social media for kids younger than 15. First Australia, then the UK, and now France is aiming to age-gate certain parts of the internet. Opponents say the bill may violate France’s constitution, end anonymity online, and may not even work. It’s also not clear how it will work from a technical perspective.
Pornhub is speaking out against age-verification laws.
“It’s easy for a lawmaker to say, ‘I’ve signed this law that’s going to protect kids.’ Well, how many kids are actually protected? How many people have not looked at age-inappropriate content as a result of these laws?”
—Alex Kekesi, head of community and brand at Pornhub’s parent company Aylo, in an interview with Politico journalist Aaron Mak.
The UK’s new prime minister is scrapping Keir Starmer’s digital ID project. Meanwhile in the UK… Andy Burnham usurping Keir Starmer as prime minister has meant a volley of new policy pledges and a reset on some old promises. Starmer’s flagship digital ID plans are mothballed for now, a move that Burnham claims saves the country £1.8 billion ($2.4 billion). The question of a digital ID card in the UK has been in contention on and off since 2002, when Prime Minister Tony Blair’s administration first proposed it. At the time, Burnham was the junior minister responsible for bringing in digital ID at the Home Office, but he appears to have rethought his stance.
Burnham’s opposition should sit well with many civil liberties campaigners and those working in privacy tech, who argued that Starmer’s proposal to create centralized identity services could lead to a dystopian reality. It would “[normalise] ID checks across employment, age-restricted services, KYC and public services, while leaving personal data vulnerable to breaches and function creep,” Andre Omietanski, Aztec’s general counsel, wrote on Twitter. Among the recommendations Aztec made to the Starmer government during its consultation on digital ID cards in May were to make digital credentials optional and self-custodial, use zero knowledge proofs for age verification, and avoid centralized databases that could turn into honeypots for hackers.
The plans might be dead for now, but with a quarter-century of political football behind it, and an ongoing drive to verify age online, the debate over who controls your digital credentials may have more punts yet to come.
Some other Glitchy headlines 🐈⬛

