Payment stablecoins now occupy a distinct position in United States federal law because Congress enacted a product-specific statute for them before completing wider digital-asset market legislation. The question is whether the quoted proposition accurately describes the GENIUS Act compliance duties, the FDIC proposal, the Senate’s stablecoin reward limits, its decentralized-finance provisions, and its insolvency safe harbor as of August 2, 2026. This analysis assumes that “stablecoin issuer” means a permitted payment stablecoin issuer under 12 U.S.C. § 5901, unless stated otherwise. It addresses federal law and does not assess a particular issuer, product, protocol, or insolvency.
Summary
- Payment stablecoins have an enacted federal statute and active agency rulemakings. H.R. 3633 remains pending. Guiding and Establishing National Innovation for U.S. Stablecoins Act, Pub. L. No. 119-27, 139 Stat. 419 (2025); H.R. 3633, 119th Cong. (reported in Senate June 1, 2026).
- The FDIC proposal does not regulate every stablecoin issuer. It applies to permitted payment stablecoin issuers for which the FDIC is the primary federal payment stablecoin regulator. Bank Secrecy Act and Sanctions Compliance Standards for FDIC-Supervised Permitted Payment Stablecoin Issuers, 91 Fed. Reg. 34,171, 34,172, 34,177–78 (June 5, 2026) (proposed rule).
- Treasury’s FinCEN and OFAC proposal supplies most substantive BSA, AML/CFT, sanctions, monitoring, reporting, and technical requirements. The FDIC proposal adds examination, supervision, and enforcement for its supervised issuers. 91 Fed. Reg. 18,582, 18,598–600, 18,610, 18,615–16, 18,649–68 (Apr. 10, 2026) (proposed rule); 91 Fed. Reg. at 34,177–78.
- The compliance program is extensive but risk-based. It requires written controls, a documented risk assessment, independent testing, training, a qualified United States-based officer, suspicious activity reporting, sanctions controls, customer identification, and lawful-order capabilities. It does not impose strict liability for every misuse. 12 U.S.C. § 5903(a)(5)–(6); 91 Fed. Reg. at 18,598–600, 18,615–16, 18,649–68.
- These proposed rules are not final. The GENIUS Act generally takes effect on January 18, 2027, unless final regulations trigger the earlier statutory date. 12 U.S.C. § 5901 note; Pub. L. No. 119-27, § 20, 139 Stat. at 466.
- The enacted issuer rule already bars interest or yield paid solely for holding, using, or retaining a payment stablecoin. The pending Senate text addresses payments by digital asset service providers and affiliates. 12 U.S.C. § 5903(a)(11); H.R. 3633, EHF26374 MSS S.L.C. § 404(c), at 207–10 (May 20, 2026 committee substitute).
- “Idle balance” is useful shorthand, not the proposed statutory test. The May 20 substitute bars deposit-equivalent returns and permits bona fide activity-based or transaction-based rewards that are not economically or functionally equivalent to bank-deposit interest. H.R. 3633, EHF26374 MSS S.L.C. § 404(c)(1)–(3), at 207–10 (May 20, 2026 committee substitute).
- The Senate DeFi text does not create one universal license. It allocates duties by control and function among controlling persons, United States web front ends, regulated intermediaries, and non-controlling developers. H.R. 3633, EHF26374 MSS S.L.C. §§ 301–308, 601, 604, at 151–85, 255–72 (May 20, 2026 committee substitute).
- The insolvency safe harbor first appeared in the May 20 substitute, not the May 8 discussion draft. It protects specified digital-commodity contracts and counterparties across federal insolvency statutes. It does not replace the GENIUS Act’s separate priority and reserve rules for payment stablecoin holders. H.R. 3633, EHF26374 MSS S.L.C. §§ 701–702, at 275–80 (May 20, 2026 committee substitute); 12 U.S.C. § 5910.
Payment stablecoins are the enacted anchor
The thesis is accurate only when “stablecoins” means payment stablecoins covered by the GENIUS Act. The Act does not govern every asset marketed as stable. It covers a digital asset designed for payment or settlement whose issuer undertakes fixed-value redemption and creates a reasonable expectation of stable value. 12 U.S.C. § 5901(22). It excludes national currency, deposits, and securities from that definition. Id.
Congress enacted the GENIUS Act on July 18, 2025. Pub. L. No. 119-27, 139 Stat. 419. The Act creates the issuer perimeter, reserve rules, redemption duties, supervisory allocation, illicit-finance duties, an issuer yield ban, and special insolvency treatment. 12 U.S.C. §§ 5901–5916. That enacted structure contrasts with H.R. 3633, which remains proposed legislation.
This sequencing gives payment stablecoins the clearest enacted, product-specific federal structure among the categories addressed by H.R. 3633. It does not mean every operative detail is settled. The statute delegates material implementation work to Treasury and the primary federal payment stablecoin regulators. Several proposed rules remain unfinished.
Three legal layers must remain separate. The GENIUS Act is enacted law, subject to its delayed effective date. Treasury’s and the FDIC’s notices are proposed rules. H.R. 3633 is pending legislation whose text changed during May, June, and July 2026. A compliance determination must identify the relevant layer and version.
The FDIC proposal and the actual compliance stack
The statement that “the FDIC has proposed rules requiring stablecoin issuers” is too broad. The FDIC proposal covers an issuer only when the FDIC is that issuer’s primary federal payment stablecoin regulator. Its principal target is a payment-stablecoin-issuing subsidiary of an FDIC-supervised insured state nonmember bank or state savings association. 91 Fed. Reg. at 34,172.
The proposal does not create the entire substantive program. Section 4(a)(5) of the GENIUS Act directs Treasury to issue tailored rules for all permitted payment stablecoin issuers. 12 U.S.C. § 5903(a)(5)(B). FinCEN and OFAC responded with a joint proposal on April 10, 2026. 91 Fed. Reg. 18,582. A separate June 22 proposal addresses customer identification. Permitted Payment Stablecoin Issuer Customer Identification Program, 91 Fed. Reg. 37,234 (June 22, 2026) (proposed rule).
The FDIC’s June 5 proposal adds the bank-supervisory layer. Proposed 12 C.F.R. § 350.6(d) would require an FDIC-supervised issuer to comply with 12 U.S.C. § 5903(a)(5) and (6)(B), 31 C.F.R. chapters V and X, and applicable program and reporting requirements. 91 Fed. Reg. at 34,177. Proposed subpart C would authorize examination, supervision, and enforcement. Id. at 34,177–78.
The precise statement is therefore narrower. Congress imposed the core duties. Treasury proposed the principal BSA, AML/CFT, sanctions, and customer-identification rules. The FDIC proposed to supervise and enforce those duties for the issuers within its assigned jurisdiction.
Program content and accountability
The statutory baseline is broad. A permitted payment stablecoin issuer must be treated as a financial institution under the Bank Secrecy Act. It becomes subject to federal laws concerning sanctions, money laundering prevention, customer identification, and due diligence. 12 U.S.C. § 5903(a)(5)(A).
The statute names six required areas. They are an effective AML program, records, suspicious transaction monitoring and reporting, transaction blocking and rejection capabilities, an effective customer identification program, and an effective sanctions program. Id. § 5903(a)(5)(A)(i)–(vi). Treasury must tailor its rules to issuer size and complexity. Id. § 5903(a)(5)(B).
FinCEN’s proposal converts that mandate into a written operational program. The issuer would need risk-based policies, procedures, and controls. It would need a documented assessment of products, services, distribution channels, customers, and geographic exposure. The assessment would require prompt updates after material risk changes. 91 Fed. Reg. at 18,649–50.
The proposed program also requires independent testing, continuing training, and a designated compliance officer located in the United States. The officer must oversee day-to-day compliance and remain accessible to FinCEN. The board, an equivalent body, or appropriate senior management must approve the written program. Id. at 18,650–51.
The proposed rule treats program effectiveness as a risk-based standard. An issuer would direct more attention and resources to higher-risk customers and activity. Id. at 18,649–50. A minor or isolated misuse would not automatically prove that the program is ineffective. The legal inquiry would examine design, implementation, risk responsiveness, and correction.
Monitoring, reporting, and records
A permitted payment stablecoin issuer would have suspicious activity reporting duties under proposed 31 C.F.R. part 1033. The proposal includes filing deadlines, immediate law-enforcement notification for urgent cases, confidentiality rules, and five-year retention. 91 Fed. Reg. at 18,661–64.
The statutory language reaches suspicious transactions relevant to a possible legal violation. 12 U.S.C. § 5903(a)(5)(A)(iii). FinCEN’s proposal supplies transaction thresholds, reporting mechanics, aggregation rules, and supporting-document requirements. 91 Fed. Reg. at 18,661–64.
As a practical inference from the proposed risk-assessment and monitoring duties, relevant inputs can include wallet exposure, bridge use, mixer contact, chain-hopping, transaction velocity, counterparty risk, geography, and redemption behavior. The proposed rule does not prescribe one vendor or model. An issuer must select controls that fit its products and verified risks.
The issuer’s monitoring perimeter is not identical to the public ledger. FinCEN did not propose a free-standing duty to monitor every secondary-market transfer of the stablecoin. The issuer must monitor activity within its legal duties and operational visibility. It must also respond when secondary-market data bears on an issuer transaction, account, redemption, freeze, or report.
Customer identification does not mean universal identification of every token holder. The June proposal ties CIP duties to an “account” and a “customer.” A person whose only relationship is token ownership, without a formal issuer relationship, would generally fall outside the proposed account concept. Interaction with a smart contract alone would not create a covered account. 91 Fed. Reg. at 37,270–72.
Direct relationships remain different. An issuer may have CIP duties when a person opens an issuer account, obtains direct services, or enters a covered relationship. The proposed procedures would require collection, verification, recordkeeping, list checks, notice, and handling of failed verification. Id.
Sanctions controls and lawful-order capability
The GENIUS Act requires technical capabilities, policies, and procedures to block, freeze, and reject specified impermissible transactions. 12 U.S.C. § 5903(a)(5)(A)(iv). It separately provides that an issuer may issue only if it can comply, and will comply, with lawful orders. Id. § 5903(a)(6)(B).
OFAC’s proposal would require an effective sanctions compliance program. Its elements are management commitment, risk assessment, internal controls, testing or audit, and training. 91 Fed. Reg. at 18,615–16, 18,666–68. The design must reflect the issuer’s products, technologies, customers, counterparties, and geographic exposure.
These duties have architectural consequences. A prospective issuer must identify how it will block issuance, reject redemption, freeze controlled value, update sanctions data, investigate alerts, document decisions, and execute lawful orders. The statute does not require one token-control design. A design that cannot perform legally required actions creates an approval and operating problem.
The analysis changes for activity outside issuer control. The issuer is not automatically responsible for stopping every transfer on an open network. It remains responsible for the functions it controls and for capabilities required by law. Its risk assessment must describe technical limits rather than assume nonexistent control.
Certification, supervision, and enforcement
The GENIUS Act adds an annual certification mechanism. Within 180 days after approval, and annually afterward, each issuer must certify implementation of AML and sanctions programs reasonably designed to prevent specified illicit finance. 12 U.S.C. § 5904(i)(1).
Failure to submit can support revocation of approval. Knowingly false certification can trigger 18 U.S.C. § 1001. 12 U.S.C. § 5904(i)(3). This elevates program documentation, issue escalation, remediation tracking, and executive review.
The FDIC proposal would place its covered issuers within ordinary supervisory processes adapted to the GENIUS Act. Examiners could review program design, implementation, reports, testing, training, transaction controls, and correction of deficiencies. 91 Fed. Reg. at 34,177–78.
The primary regulators face a statutory limit. They may issue rules necessary to regulate payment stablecoin issuance, but may not impose requirements beyond section 4. 12 U.S.C. § 5904(g). Treasury retains its separate statutory authority over the BSA and sanctions. Id. § 5903(a)(5)(C). The division matters when assessing any final rule’s legal basis.
Current legal effect
The April, June 5, and June 22 notices are proposed rules. They do not yet impose final regulatory duties. Their text can still change after comments, interagency review, and publication of final rules.
The GENIUS Act’s default effective date is January 18, 2027. It can take effect sooner, 120 days after the primary federal payment stablecoin regulators issue any final regulations implementing the Act. Pub. L. No. 119-27, § 20, 139 Stat. at 466; 12 U.S.C. § 5901 note.
No final rule identified in the reviewed official sources had triggered that acceleration by August 2, 2026. Issuers therefore face a preparation period, not a basis for treating the proposed regulatory text as final law.
Transaction controls, on-chain analytics, data lineage, case management, independent testing, and lawful-order execution may require material redesign before the effective date. Firms should distinguish statutory necessities from proposed implementation choices.
Stablecoin interest, yield, and rewards
The enacted GENIUS Act already governs issuer-paid returns. A permitted payment stablecoin issuer or foreign payment stablecoin issuer may not pay interest or yield solely in connection with holding, using, or retaining a payment stablecoin. 12 U.S.C. § 5903(a)(11).
That provision leaves an important perimeter question. It names issuers, not every exchange, wallet provider, broker, affiliate, merchant, or protocol. Congress used H.R. 3633 to address rewards paid by digital asset service providers and their affiliates.
Version control is decisive. The May 8 Senate Banking discussion draft used section 404, “Preserving Rewards for Stablecoin Holders.” It broadly preserved payments tied to transactions, platform use, loyalty programs, merchant acceptance, liquidity, collateral, protocol participation, validation, staking, and related activity. H.R. 3633, EHF26031 MKR S.L.C. § 404, at 188–94 (May 8, 2026 discussion draft).
The May 20 committee substitute changed the rule and title. Section 404 became “Prohibiting Interest and Yield on Payment Stablecoins.” H.R. 3633, EHF26374 MSS S.L.C. § 404, at 205–19. The Senate reported that substitute on June 1, 2026.
The later text bars a covered party from directly or indirectly paying interest or yield solely for holding payment stablecoins. It also bars payments economically or functionally equivalent to interest on a bank deposit. Id. § 404(c)(1), at 207–08. The covered-party definition reaches digital asset service providers and affiliates, subject to stated exclusions. Id. § 404(a), at 205–06.
Bona fide activity-based and transaction-based rewards remain possible. They qualify only when they are not deposit-equivalent. Id. § 404(c)(2), at 208–09. The SEC, CFTC, and Treasury would jointly issue implementing rules. Id. § 404(c)(3), at 209–10.
The listed activities include payments, transfers, conversions, remittances, settlement, merchant acceptance, account or wallet use, platform participation, liquidity, collateral, validation, and staking. Id. A category label does not control. A purported “loyalty” reward can still violate the prohibition when its economics replicate deposit interest.
“Idle balance” captures the principal target but understates the legal test. The proposal does not ask only whether the customer performed an activity. It asks whether the compensation is economically or functionally equivalent to bank-deposit interest.
A reward may reference balance, duration, or customer tenure without obtaining an automatic safe harbor. Id. § 404(c)(3)–(4), at 209–10. Those variables remain evidence in the equivalence inquiry. A fixed annual percentage applied to average balance will face greater risk than a rebate linked to an identifiable transaction cost.
The later text also contains anti-evasion authority. The agencies could address circumvention by labels, affiliates, intermediaries, or payment design. Id. § 404(c)(4), at 210–11. Good-faith reliance receives a limited 90-day cure after an adverse rule or adjudication, absent a substantially similar prior violation. Id. § 404(c)(5), at 211.
Marketing carries separate risk. Covered parties could not characterize payment stablecoins as deposits, deposit-equivalents, or insured products. Required disclosures would distinguish rewards from interest and explain the absence of federal deposit insurance. Id. § 404(d)–(e), at 211–15.
A knowing and willful violation can support a Treasury civil monetary penalty up to $5 million per violation. Related acts with a common cause or statement can count as one violation under the aggregation rule. Id. § 404(f), at 214–15.
The proposal limits attribution for unaffiliated third parties. A covered party is not deemed to violate section 404 merely because an independent third party pays consideration. Attribution can return when the covered party directs or exercises significant influence over the offering. Id. § 404(i), at 218.
The legal classification of a reward therefore turns on facts. The payer, affiliate links, customer location, required activity, formula, duration, balance sensitivity, marketing, funding source, and third-party influence all matter. No single product label resolves the issue.
The DeFi control-and-function structure
The Senate text does not treat all decentralized finance alike. It assigns different consequences based on control, interface operation, intermediary status, and custody or transaction power. H.R. 3633, EHF26374 MSS S.L.C. §§ 301–308, 601, 604.
Section 301 defines a decentralized-finance trading protocol by automated, predetermined, non-discretionary execution without reliance on another person for custody. Id. § 301(a)(1), at 151–52. The text then identifies circumstances that make a protocol “non-decentralized.”
Control is central. A protocol can become non-decentralized when a person or coordinated group can materially alter functionality, operation, or consensus rules. The same result can follow from unilateral censorship or from operations not governed solely by transparent pre-established code. Id. § 301(a)(2), at 152–53.
Decentralized decision procedures alone do not establish coordinated control. The text also excludes specified node, oracle, validation, and incident-response functions. Id. § 301(a)(2)(B)–(C), at 153–54. The exclusions are fact-dependent.
The SEC would clarify how existing Exchange Act duties apply to persons controlling non-decentralized protocols. Id. § 301(b)–(c), at 154–58. Registration under that rule could carry existing BSA consequences where current law makes them applicable. The section does not independently classify every controller as a financial institution.
The text protects code and open systems from automatic entity treatment. It would not require software code or a distributed ledger system to register in its own capacity. It would not prohibit launching or operating a distributed ledger. Id. § 301(d)(1), at 158.
The same section disclaims an expansion of existing statutory authority. It creates no presumption that a person or activity is, or is not, subject to the Exchange Act. Id. § 301(d)(2)–(3), at 158–60. The practical dispute will therefore center on control evidence and existing registration law.
Emergency powers receive tailored treatment. Predefined, temporary, incident-specific powers can avoid a control finding when their limits are disclosed and they do not support unrelated upgrades or economic changes. Id. § 301(e), at 160–61. Permanent or discretionary powers present greater classification risk.
United States web front ends form a second category. Section 302 defines a “distributed ledger messaging system” as a web-hosted application through which a user submits a transaction instruction to a protocol or application. It excludes the protocol, nodes, validators, infrastructure, and self-custody wallets. Id. § 302(a), at 161–62.
Treasury would issue guidance for systems owned or operated by United States persons. The guidance may address analytics, sanctions screening, transaction blocking or rejection, ransomware indicators, and risk-based controls. Id. § 302(b), at 162–64.
A savings clause preserves existing sanctions, AML, and illicit-finance law. It also rejects automatic financial-institution status for non-controlling developers. Id. § 302(c), at 164–65. Section 302 is therefore a guidance mandate bounded by existing authority, not a new universal front-end license.
Regulated intermediaries form a third category. Before routing orders or executing trades through a DeFi protocol, a digital asset intermediary would need specified risk controls. Id. § 308(a), at 183.
The intermediary would assess money-laundering and sanctions risk, fraud, manipulation, operations, cybersecurity, and settlement. It would provide customer disclosures, monitor activity, and maintain procedures to execute, reject, or suspend transactions. Id. § 308(b), at 183–85. Treasury, the SEC, and the CFTC would divide implementing duties. Id. § 308(c), at 185.
Non-controlling developers form a fourth category. Section 604 protects a provider that lacks the legal right or unilateral independent ability to control, initiate, or effect user transactions. Id. § 604(b)(3), at 270.
Such a provider would not be treated as a federal money transmitting business solely for publishing or maintaining software, supplying self-custody hardware or software, or providing ledger infrastructure. Id. § 604(c), at 270–71.
The protection is not absolute. It does not alter 18 U.S.C. § 1960(b)(1)(C) when a person specifically intends to transfer known criminal proceeds or funds intended to support unlawful activity. Id. § 604(d), at 271–72. Conduct outside the protected functions remains subject to federal and state law. Id. § 604(e), at 272–74.
A project cannot classify itself from its marketing. Relevant evidence includes administrator keys, upgrade authority, censorship rights, fee control, treasury control, coordinated voting, front-end ownership, emergency powers, custody, routing, and transaction execution. Those facts determine the likely statutory bucket.
The insolvency safe harbor and stablecoin insolvency
The quoted chronology needs correction. The May 8 discussion draft did not contain the digital-commodity contract safe harbor. The May 20 committee substitute added Title VII and section 702. The Senate reported that text on June 1.
Section 702 would treat a transaction involving a unit of digital commodity as a commodity contract for specified federal insolvency laws when the counterparty is a commodity broker, stockbroker, financial institution, financial participant, or securities clearing agency. H.R. 3633, EHF26374 MSS S.L.C. § 702, at 279–80.
The cross-references reach the Bankruptcy Code’s commodity-contract protections, Federal Deposit Insurance Act resolution, Dodd-Frank orderly liquidation, and SIPA liquidation. Id. The provision also treats related margin as a margin payment for 11 U.S.C. § 548(d)(2)(B).
The practical effect is close-out protection for covered market contracts. Qualifying counterparties could receive protections for termination, liquidation, acceleration, setoff, netting, and related margin transfers under the referenced statutes. Exact rights would still depend on the transaction, counterparty, contract, and governing insolvency regime.
The safe harbor is not a general shield for every digital asset. It requires a transaction involving a “digital commodity” and a listed counterparty. It does not automatically protect a retail holder, an unlisted counterparty, an ordinary spot transfer, or every token-related agreement.
The July 22 sponsor draft retained the provision as section 10702. H.R. 3633, EHF26654 FYM S.L.C. § 10702, at 317–18 (July 22, 2026 sponsor draft). That merged draft expressly excludes payment stablecoins issued by permitted payment stablecoin issuers from its digital-commodity definition. Id. § 20101, at 394–96.
The exclusion separates market-contract protections from issuer insolvency. A payment stablecoin holder’s principal federal protection comes from the enacted GENIUS Act, not proposed section 702 or 10702.
Section 11 of the GENIUS Act gives direct holders ratable priority against required reserves. 12 U.S.C. § 5910(a). Required reserves are excluded from the bankruptcy estate. Id. § 5910(e). The automatic stay applies to redemption, subject to a court process that can permit distributions. Id. § 5910(c).
If required reserves are deficient, a remaining direct holder claim receives first priority to the extent section 4 required additional reserves. Id. § 5910(d). Claims not arising directly from holding payment stablecoins do not receive the same statutory priority. Id. § 5910(a)(3).
The two regimes serve different functions. The GENIUS Act protects redemption claims and required reserves in issuer failure. H.R. 3633’s safe harbor protects specified market contracts in covered insolvencies. Treating them as one stablecoin insolvency rule would misstate both.
Practical consequences
An issuer workstream should begin with charter and regulator classification. The answer determines whether the FDIC, OCC, Federal Reserve, NCUA, a state regulator, or more than one authority will examine the business.
The compliance build should map each section 4 duty to an owner, policy, control, system, record, test, and certification artifact. It should document which ledger functions the issuer controls. It should also document actions that remain technically unavailable.
Reward programs require a separate payer-and-economics review. Firms should identify every issuer, affiliate, exchange, wallet, protocol, merchant, and independent payer. They should model returns by balance, time, transactions, fees, liquidity, and customer behavior.
DeFi projects should maintain a control register. It should identify upgrade keys, censorship powers, emergency rights, fee settings, front-end operators, routing functions, custody, coordinated voting, and change procedures. Legal determinations should track changes in those facts.
Insolvency analysis should separate issuer redemption claims from market-contract closeouts. Counsel must identify the debtor, claimant, asset classification, counterparty status, contract type, reserve location, custody chain, and applicable insolvency statute.
