Stablecoins Have Become Crime’s Favorite Rail: Inside FATF’s Seventh Virtual-Asset Review

On July 16, the Financial Action Task Force published its Seventh Targeted Update on the implementation of its standards for virtual assets and virtual asset service providers — and the headline is blunt: organised crime groups are moving billions of dollars in illicit proceeds through the crypto sector by exploiting the gaps between jurisdictions that regulate on paper and those that supervise in practice. For compliance officers at exchanges, custodians, payment firms and money service businesses, this report is not background reading. It is a preview of the questions your regulators, banking partners and auditors will be asking over the next twelve months.

More Laws, Not Yet More Supervision

The implementation scoreboard is improving. Eighty-three percent of surveyed jurisdictions have now passed Travel Rule legislation, up from 73 percent a year ago, and eleven more report that implementation is under way. But FATF’s message is that legislation is the easy part. Many jurisdictions still struggle to identify who is actually conducting VASP activity in their markets, licensing and registration regimes remain incomplete, and enforcement of Travel Rule obligations lags well behind the statutes. The result is a two-speed world: compliant firms absorb rising regulatory cost while illicit actors simply route around them through weakly supervised corridors and offshore platforms.

Stablecoins Now Dominate On-Chain Illicit Activity

The most consequential finding is the shift in criminal preference. FATF reports that the majority of identified on-chain illicit activity now involves stablecoins — a decisive move away from volatile assets toward tokens that behave like dollars and settle in seconds. Misuse by DPRK-linked actors and terrorist financiers has increased since the 2025 update. Most striking of all, some criminal networks have begun developing proprietary stablecoins engineered specifically to resist the freezing and seizure powers that make regulated issuers a hard target. When criminals start building their own settlement instruments to escape your controls, it is confirmation that the controls on regulated rails are starting to work — and that risk is migrating, not disappearing.

The US Context: GENIUS Act Rules Are Landing Now

The FATF findings land in the middle of an active US rulemaking cycle. FinCEN and OFAC have proposed AML and sanctions rules for permitted payment stablecoin issuers under the GENIUS Act, treating them as financial institutions under the Bank Secrecy Act, and the OCC’s comment window on parallel proposals closes this week, on July 24. Add FinCEN’s broader AML/CFT program reform proposal and the Federal Reserve’s July push to streamline and align bank AML rules, and US firms face a simple reality: the supervisory perimeter around stablecoins and crypto payments is being drawn right now, and FATF’s data will be cited to justify a firmer line.

What Examiners and Banking Partners Will Ask Next

Expect the report’s priority actions to translate quickly into examination themes and counterparty due-diligence questionnaires:

  • Stablecoin exposure. Can you quantify what share of your flows touches stablecoins, which issuers, and on which chains — and does your transaction monitoring treat those flows with risk-appropriate scrutiny?
  • Travel Rule performance, not paperwork. Regulators are moving from “do you have a solution” to “show me your match rates, your handling of non-responsive counterparties, and your controls for deposits from non-compliant VASPs.”
  • Offshore VASP counterparties. FATF again flags offshore platforms licensed nowhere or in light-touch havens. Counterparty VASP due diligence — licensing status, supervision quality, ownership — is becoming a standing expectation.
  • Unhosted wallets and DeFi. Firms need documented, risk-based policies for self-hosted wallet interactions and DeFi touchpoints, not blanket allowances or blanket bans adopted by default.
  • Sanctions resilience. With DPRK misuse rising, screening must reach beyond names to behavioral and typology-based detection — chain-hopping, peel chains, mixer proximity and rapid stablecoin swaps.

FinCheck’s Perspective & Way Forward

Our read: the era in which a crypto or MSB compliance program could be judged by the documents on its shelf is closing. FATF has effectively told supervisors where to press — stablecoin flows, Travel Rule execution and offshore counterparty exposure — and US agencies are writing those expectations into rules in real time. Firms that get ahead of this will treat the Seventh Targeted Update as a free examination blueprint: refresh the enterprise-wide risk assessment to explicitly address stablecoins and counterparty VASP risk; test Travel Rule performance with real data rather than vendor attestations; and commission an independent review before an examiner, bank partner or state regulator does it for you. The window between report and enforcement is where reputations — and banking relationships — are won or lost.

FinCheck LLC supports crypto and digital-asset firms, MSBs, fintechs and gaming platforms with BSA/AML risk assessments, independent AML audits, Travel Rule and sanctions program design, policy development and fractional compliance officer services. If your program has not yet been stress-tested against FATF’s 2026 findings, now is the time.

Payroll Fraud Meets AML: What FinCEN’s New Advisory (FIN-2026-A002) Means for MSBs, Payroll Firms, and FinTechs

Payroll Fraud Meets AML: What FinCEN’s New…

On June 5, 2026, FinCEN — jointly with the FDIC, OCC, and NCUA and in…

The Post-MiCA Era Begins: What the July 1 CASP Deadline and AMLA’s Ramp-Up Mean for Global Crypto Compliance

The Post-MiCA Era Begins: What the July…

On July 1, 2026, the era of transitional tolerance for crypto-asset service providers (CASPs) in…

Whose Compliance Program Is It, Anyway? Sponsor Banks, FinTechs, and the New AML Accountability in BaaS

Whose Compliance Program Is It, Anyway? Sponsor…

For a decade, Banking-as-a-Service ran on a comfortable fiction: the sponsor bank “owned” BSA/AML compliance,…