
The industry group wants KYC rules limited to primary market activity, with zero-knowledge proofs accepted as a verification method for stablecoin issuers under the GENIUS Act.
The Blockchain Association told federal regulators on August 21 that proposed know-your-customer rules for stablecoin issuers sweep too broadly. The industry group wants identification requirements limited to direct issuer-customer relationships, with zero-knowledge proofs accepted as a verification method.
The comment letter targets a joint proposed rule from FinCEN, the Federal Reserve, and other agencies. It would establish customer identification program requirements for permitted payment stablecoin issuers under the GENIUS Act, signed July 18. That legislation created the first federal framework for payment stablecoins in the US.
The Association endorsed the broad concept of KYC for stablecoin issuers. It draws the line at how far those obligations extend.
Under the proposal, CIP requirements mirror existing bank rules. Issuers would collect a customer's name, date of birth, address, and identification number. Records would be retained for five years after account closure.
The Association's position: these requirements should only apply where an explicit contractual relationship exists between issuer and customer. That means primary market activity, the direct minting and redemption of stablecoins where the two parties are actually transacting.
Secondary market transactions work differently. When someone swaps stablecoins on a decentralized protocol, the issuer has no direct relationship with the buyer. The Association argues this would be impractical and misaligned with how blockchain infrastructure actually operates.
The group also wants flexibility in identity verification. It advocates for allowing zero-knowledge proof technologies as an acceptable CIP method. Zero-knowledge proofs let one party prove something, say that they're over 18 or that their identity has been verified, without revealing the underlying data. The cryptographic math confirms the claim without exposing the personal information behind it.
The five-year recordkeeping requirement makes this tension acute. Holding personal data for half a decade post-account closure creates a target on servers. Privacy-preserving verification could let issuers comply without accumulating large stores of names, addresses, and ID numbers.
The letter flags a coordination problem. The GENIUS Act created a new regulatory category, the implementing agencies are working on different timelines. The Association wants regulators to synchronize their deadlines to prevent conflicting or overlapping compliance windows.
The comment submission aligns with August 2026 deadlines set by the rulemaking process.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.