Curaçao Gaming Authority Issues New Crypto Rules for Licensees – Full Compliance Required by Mid-2027
Key Takeaways
- The Curaçao Gaming Authority has introduced detailed crypto guidelines for B2C online gambling licensees, effective June 2026.
- Operators must restrict crypto use strictly to gambling activities and may not act as exchanges, custodians, or virtual asset service providers.
- Mandatory blockchain analytics, wallet screening, and transaction monitoring will apply to deposits and withdrawals.
- Full compliance, including wallet segregation and audit-ready records, is required by June 2027.
- Funds linked to sanctioned addresses, mixers, or tumblers are explicitly prohibited.
New Crypto Policy Applies to All B2C Licensees
The Curaçao Gaming Authority, or CGA, has issued a comprehensive crypto policy guideline targeting holders of its business-to-consumer online gambling licences. The framework takes effect in June 2026 and applies to all group entities involved in cryptocurrency transactions.
According to the regulator, the objective is to align the management of virtual assets with international anti-money laundering and countering the financing of terrorism standards. The rules cover the entire lifecycle of crypto use within licensed gambling operations, including deposits, wagering, withdrawals, and treasury management.
For operators that have historically relied on crypto as a core payment method, the guidance introduces structured compliance obligations that go beyond basic acceptance of digital assets. The CGA retains the authority to demand faster implementation if it identifies significant risk exposure.
Strict Role Limitations and Asset Controls
Under the new rules, Curaçao-licensed operators may accept cryptocurrencies exclusively as a means of payment for gambling activities. They are not permitted to function as exchanges, custodians, or virtual asset service providers.
The policy sets clear expectations regarding the types of digital assets that may be used. Fiat-backed stablecoins are preferred. Privacy coins, meme coins, and wrapped tokens of unclear origin must undergo assessment and may be excluded if they do not meet risk standards.
In addition, the CGA has imposed an outright ban on funds connected to mixers, tumblers, or sanctioned blockchain addresses. Operators must immediately prohibit transactions involving sanctioned wallets and may not process crypto linked to services designed to obscure transaction origins.
These measures directly affect how platforms structure their crypto offerings. Operators must ensure that asset acceptance policies reflect the regulator’s risk-based approach and documented due diligence.
Mandatory Blockchain Analytics and Wallet Segregation
A central component of the guidelines is the requirement for blockchain analytics capability. Licensees must implement wallet screening, risk scoring, and transaction monitoring for both deposits and withdrawals.
This obligation covers the identification of high-risk wallets and ongoing assessment of transactional behavior. Operators are also required to maintain transaction reconciliation processes and audit-ready records as part of their compliance framework.
The CGA further mandates strict wallet segregation. Player wallets, operational wallets, and treasury wallets must be kept separate. The use of personal wallets or wallets linked to ultimate beneficial owners is explicitly prohibited.
These requirements extend beyond front-end payment acceptance and reach into back-end treasury management. Operators must demonstrate structured internal controls that clearly distinguish customer funds from operational capital and corporate reserves.
Phased Timeline Through June 2027
The regulator has introduced a phased implementation schedule extending to mid-2027.
Within three months of the policy’s introduction, licensees must submit a compliant crypto policy through the CGA portal. Within six months, operators are expected to complete risk assessments, conduct due diligence on virtual asset service providers, and provide staff training on the new requirements.
Full compliance is required within twelve months, by June 2027. At that point, operators must have implemented wallet segregation, deployed blockchain analytics systems, ensured transaction reconciliation, and maintained documentation suitable for regulatory review.
Although the timeline allows gradual implementation, the CGA has stated that it may require accelerated compliance if significant risks emerge during the transition period.
Alignment With International AML Standards
The CGA’s updated guidance reflects broader international regulatory developments concerning virtual assets. The framework aligns with standards promoted by the Financial Action Task Force, including the incorporation of Travel Rule principles and enhanced transparency requirements.
The regulator’s approach mirrors a wider trend among gambling authorities that are intensifying oversight of crypto payments. Regulatory attention has increasingly focused on consumer protection and anti-money laundering safeguards in environments where digital assets are used.
By integrating blockchain analytics, asset risk classification, and strict wallet management into licensing conditions, the CGA is formalizing crypto oversight within its jurisdiction. The move places crypto handling on a comparable compliance footing to traditional financial controls.
Operational Impact for Curaçao-Licensed Platforms
For operators holding a Curaçao licence, the policy introduces measurable compliance obligations across multiple operational layers. Payment processing, treasury management, internal governance, and staff training will all require structured documentation and oversight.
Platforms that previously accepted a broad range of digital assets without systematic screening will need to reassess asset listings and integrate monitoring tools. Due diligence on external service providers, including virtual asset service providers, becomes a documented requirement.
The prohibition of sanctioned wallets and mixer-related funds also necessitates real-time screening capabilities. Failure to implement these controls could expose operators to regulatory action under the CGA’s updated framework.
Our Assessment
The Curaçao Gaming Authority has introduced a detailed and phased crypto compliance framework that applies to all B2C licensees from June 2026, with full implementation required by June 2027. The rules impose clear restrictions on the role of operators, define acceptable asset categories, mandate blockchain analytics and wallet segregation, and prohibit transactions linked to sanctioned or obfuscation-related addresses. For Curaçao-licensed gambling platforms, crypto operations will now be subject to structured anti-money laundering controls and documented oversight aligned with international standards.
StarkWare Launches Private KYC on Starknet – Zero Knowledge Proofs Aim to Reduce Personal Data Exposure
Key Takeaways
- StarkWare has introduced a Private KYC system on Starknet as a demo.
- The system uses zero knowledge STARK proofs and STRK20 privacy features to verify specific attributes without revealing full identity data.
- Users scan their passport via smartphone, encrypt the data to their Starknet wallet, and register attributes onchain.
- The rollout comes amid rising data breaches, with 3,322 reported compromises in the US in 2025.
- Verifiers can confirm eligibility through onchain proofs without accessing underlying personal documents.
StarkWare Introduces Private KYC on Starknet
StarkWare has unveiled a Private KYC system on its Starknet network, presenting it as a demo that allows users to complete know your customer checks without disclosing their full personal information. The system relies on zero knowledge STARK proofs and STRK20 privacy features to confirm specific eligibility criteria while limiting the exposure of sensitive data.
According to the company, the approach enables users to prove individual attributes such as being over 18, holding a valid credential, or meeting other eligibility requirements. Instead of sharing an entire passport or detailed personal record, users can submit a cryptographic proof that confirms only the required fact.
StarkWare stated that identity verification processes often request complete documents when only a single data point is necessary. The Private KYC model is designed to reduce the amount of information collected and stored by institutions, which can become security liabilities once accumulated in centralized databases.
How the Private KYC Process Works
The process begins with users scanning their passport using a smartphone. The system uses the device camera and NFC chip to read the passport and confirm that the document is genuine and digitally signed by the issuing authority.
Once verified, users encrypt their identity data directly to their Starknet wallet. Rather than uploading full identity documents to a centralized server, the encrypted information remains under the user’s control. Relevant attributes are then registered in a public onchain registry.
When verification is required, users submit zero knowledge proofs derived from their encrypted data. Smart contracts validate these proofs. Verifiers can read the public registry to confirm that the necessary condition has been met, but they do not gain access to the underlying identity information. As StarkWare describes it, contracts check the proofs, not the passports.
This design aims to separate verification from data custody. Institutions confirm compliance requirements without creating additional copies of identity documents that would need to be stored and protected.
Data Breaches Provide Context for Privacy Focus
The launch comes at a time when data breaches continue to increase across industries. In 2025, the United States recorded 3,322 data compromises, representing a 79 percent increase over five years, according to StationX. The global average cost of a data breach stands at 4.4 million dollars.
Healthcare data has been particularly affected. Axis Intelligence reports that more than 1 billion healthcare records have been breached as of 2026, with an average breach cost of 7.42 million dollars. In 2025 alone, 772 large healthcare data breaches were confirmed in the United States, marking the highest annual total on record.
The crypto industry has also experienced significant incidents. In 2020, hardware wallet provider Ledger suffered a major database breach that exposed more than 270,000 customer records. The leaked data led to extensive phishing campaigns that persisted long after the initial incident.
Against this backdrop, StarkWare positions Private KYC as an alternative to traditional models that require companies to collect and store full identity datasets.
Comparison With Other Zero Knowledge Identity Models
StarkWare’s Private KYC system has drawn comparisons to World ID, a project associated with Sam Altman’s Worldcoin initiative. World ID uses zero knowledge proofs to verify that a user is human, based on biometric iris scans collected through dedicated hardware devices.
However, World ID has faced criticism over centralized custody of biometric data. StarkWare’s model differs in that it emphasizes self custody. Users encrypt their identity information directly into their own Starknet wallets rather than relying on a central database of biometric identifiers.
Both systems rely on zero knowledge cryptography to separate verification from raw data exposure. The key distinction lies in how and where sensitive information is stored and controlled.
Relevance for Crypto Platforms Requiring KYC
For crypto platforms, including exchanges, payment services, and other regulated applications, KYC compliance remains a standard requirement. Typically, this involves collecting copies of passports, proof of address, and other personal documents, which are then stored in company databases.
Private KYC introduces a model in which compliance checks can be completed through cryptographic proofs rather than direct document transfers. Verifiers confirm that a user meets predefined criteria without retaining full identity files.
For users of crypto based financial or gaming services, the model addresses a central tension in digital compliance: meeting regulatory standards while limiting personal data exposure. The demo illustrates how onchain registries and zero knowledge proofs can be combined to achieve selective disclosure.
Our Assessment
StarkWare’s Private KYC demo on Starknet presents a verification framework that uses zero knowledge STARK proofs to confirm specific eligibility criteria without revealing full identity data. The system relies on passport scanning, encrypted self custody storage, and onchain attribute registration.
The rollout takes place amid rising global data breaches and increasing costs associated with centralized identity storage. By separating verification from data custody, the model aims to reduce the volume of personal information held by institutions while maintaining compliance checks through cryptographic validation.
Bull Bitcoin Secures MiCA License in France – EU Users Retain Full Self-Custody and Privacy Features
Key Takeaways
- Bull Bitcoin has obtained a Markets in Crypto-Assets Regulation license in France.
- The license allows the company to continue offering its Bitcoin exchange and payment services across EU member states.
- According to the company, all existing self-custody and privacy features remain unchanged.
- Bull Bitcoin passed PASSI and DORA cybersecurity audits without outsourcing its core infrastructure.
- The licensing process was self-financed and took nearly three years to complete.
MiCA License Secured in France After Multi-Year Compliance Process
Bull Bitcoin announced on June 23, 2026 that it has obtained a license under the European Union’s Markets in Crypto-Assets Regulation in France. The authorization enables the company to continue providing its Bitcoin exchange and payment services to users in EU member states without interruption.
Founder Francis Pouliot described the license as the result of a nearly three-year effort to enter the European market. According to his public statement, the process was fully self-financed, and the company did not seek funding from external investors or lenders.
The approval comes at a time when EU crypto rules under MiCA are tightening. Around the same period, the European Securities and Markets Authority ordered unlicensed crypto firms to exit the EU market as the MiCA deadline arrived. Against this backdrop, securing a license provides regulatory clarity for companies seeking to operate legally within the bloc.
Self-Custody Model and Privacy Tools Remain Unchanged
According to Bull Bitcoin, the MiCA license was obtained without altering its core operating model. The company states that all website and wallet features will remain the same as they were during the first half of 2026, with no additional restrictions or functional changes for users.
Bull Bitcoin operates as a Bitcoin-only, non-custodial exchange. Users must provide their own wallet address before completing a purchase. Bitcoin is then sent directly to the user’s wallet rather than being held in custody by the company. This structure means the platform does not retain control over client funds.
The company has long positioned itself around a self-custody approach. In addition to standard exchange services, it offers Bitcoin bill payment services for expenses such as rent, utilities, and real estate transactions. It also supports Lightning Network, Liquid, and Payjoin, which are tools associated with transaction efficiency and privacy.
Pouliot stated that obtaining the license did not require the company to compromise on what he described as its cypherpunk approach to self-custody and privacy. However, the announcement did not detail how potential tensions between user privacy expectations and MiCA compliance requirements were resolved.
Cybersecurity Audits Completed Without Third-Party Infrastructure
As part of the licensing process, Bull Bitcoin reported passing the required PASSI and DORA cybersecurity audits. The company emphasized that it did so without outsourcing its core Bitcoin infrastructure to external hosted providers.
According to Pouliot, relying on third-party infrastructure would have been easier and less costly but would have reduced internal control over systems. Instead, the firm maintained in-house management of its core infrastructure throughout the compliance process.
For users, this detail relates directly to how a service manages operational risk and technical control. Infrastructure decisions can affect data handling, system resilience, and service continuity. In this case, Bull Bitcoin states that its internal systems remain intact following regulatory approval.
BULL Wallet and Exchange Integration Continue Under New Authorization
In October 2025, Bull Bitcoin launched the BULL Wallet, described as a global, open-source, privacy-focused mobile application available on iOS and Android. The wallet includes opt-in integration with the company’s exchange.
Features include support for Payjoin, compatibility with Lightning and Liquid, and a policy of no data collection or push notifications. According to the company, both the wallet and its integration with the exchange remain unchanged under the newly obtained MiCA license.
For users in the EU who rely on integrated wallet and exchange services, the continuation of these features means the user experience remains consistent despite the regulatory shift.
European Expansion and Regulatory Positioning
Bull Bitcoin was founded in 2013 in Montreal by Francis Pouliot. The company has expanded its team in France and developed services tailored to the eurozone. The newly secured authorization provides what the company describes as a long-term regulatory foothold in Europe.
Pouliot has previously referenced the firm’s experience navigating Canadian oversight. The MiCA approval aligns with the company’s stated approach of meeting regulatory obligations while maintaining its core operational model.
The broader regulatory environment in the EU has prompted some crypto providers to alter operations or withdraw from certain markets. In this context, obtaining a MiCA license allows Bull Bitcoin to continue offering services legally across member states under a harmonized framework.
Our Assessment
Bull Bitcoin’s MiCA license in France allows it to continue operating its Bitcoin-only, non-custodial exchange and payment services across the European Union. The company states that its self-custody model, privacy features, wallet integration, and in-house infrastructure remain unchanged following regulatory approval. The development positions Bull Bitcoin among the providers that have secured authorization under the EU’s new crypto framework while maintaining their existing service structure.
US Senate Passes Housing Bill With CBDC Ban Until 2030 – Federal Reserve Barred From Issuing Digital Dollar Without Congressional Approval
Key Takeaways
- The US Senate voted 85-5 to pass the 21st Century Road to Housing Act, which includes a ban on a Federal Reserve central bank digital currency until 2030.
- The bill prohibits the Fed from issuing or creating a CBDC or any substantially similar digital asset.
- Even after 2030, the Federal Reserve would require explicit congressional authorization to move forward with a CBDC.
- The legislation includes a carve-out for dollar-denominated currencies that are open, permissionless, and private, including stablecoins.
- The bill now moves to the House of Representatives, where it is expected to pass before being sent to the president for signature.
Senate Approves Housing Package With Embedded CBDC Restriction
The US Senate has passed the 21st Century Road to Housing Act in an 85-5 vote, advancing a major housing affordability package that also includes a prohibition on the Federal Reserve developing or issuing a central bank digital currency until 2030.
The legislation aims to increase housing supply and follows an agreement reached last week by a bipartisan group of House and Senate leaders to move the bill forward. The CBDC provision has been part of the package since the Senate passed an earlier version in March.
According to the bill text referenced by the Senate Banking Committee, the Federal Reserve may not, directly or indirectly, issue or create a central bank digital currency or any digital asset that is substantially similar to a central bank digital currency. This restriction would remain in effect through 2030.
The bill will now proceed to the House of Representatives. Lawmakers there are expected to pass it quickly, following the agreement struck by House leaders last week. After House approval, the legislation will be sent to the president for signature.
Scope of the CBDC Ban and Stablecoin Carve-Out
The language of the bill goes beyond a narrow definition of a digital dollar. It prevents the Federal Reserve from issuing or creating any digital asset that is substantially similar to a CBDC, whether directly or indirectly.
However, the measure includes a carve-out for stablecoins and other dollar-denominated currencies that are described as open, permissionless, and private. This distinction separates privately issued digital dollar tokens from a centrally issued digital currency controlled by the Federal Reserve.
The legislation also establishes a longer-term limitation. Even after the 2030 ban expires, the Federal Reserve would not be able to proceed with a CBDC without explicit authorization from Congress. This condition places the decision over any future US central bank digital currency firmly in the hands of lawmakers rather than the central bank alone.
Political Context Behind the Provision
The CBDC clause was incorporated into the housing package as part of a broader political agreement. According to the report, it served as a measure to secure support from House Republicans and the administration for faster passage of the housing legislation.
Crypto advocates have criticized CBDCs, arguing that they could expand central bank control over digital currency. The provision is described as a win for Republicans who have attempted for years to block the development of a US CBDC.
By attaching the ban to a major housing bill, lawmakers combined digital currency policy with housing reform in a single legislative vehicle. The result is a temporary prohibition on central bank digital currency activity embedded within a broader affordability initiative.
Global CBDC Development Continues Outside the United States
While the US Senate has moved to restrict CBDC development at the federal level, other countries continue to advance their own digital currency initiatives.
Reuters reported on June 16 that China signed up 26 financial institutions to its digital yuan cross-border payment platform. The digital yuan, also known as e-CNY, is part of China’s broader effort to expand its central bank digital currency infrastructure.
According to data cited from the Atlantic Council, three countries have officially launched a CBDC. A further 41 countries are in the pilot phase, 33 are in development, and 40 are still in the research stage.
These figures indicate that central bank digital currency projects remain active globally, even as the United States moves to pause federal development through legislative action.
Implications for Digital Dollar Policy
The Senate’s decision establishes a defined timeline during which the Federal Reserve is barred from creating or working on a CBDC. The restriction applies to direct and indirect actions and covers assets substantially similar to a central bank digital currency.
At the same time, the explicit carve-out for open, permissionless, and private dollar-denominated currencies distinguishes privately issued stablecoins from a potential Fed-issued digital dollar. The bill therefore separates central bank digital currency policy from the treatment of certain private digital dollar instruments.
With the House expected to approve the legislation and send it to the president, the measure is positioned to become law, formalizing the CBDC restriction through 2030 and requiring future congressional approval for any change in direction.
Our Assessment
The Senate’s 85-5 vote places a temporary statutory barrier on the Federal Reserve’s ability to issue or develop a central bank digital currency until 2030. The bill also requires explicit congressional authorization for any CBDC initiative after that date and differentiates stablecoins from a central bank digital dollar. As other countries continue advancing CBDC projects, US digital currency policy will, under this legislation, remain subject to direct congressional control for the remainder of the decade.
South Korea Proposes Expanding Crypto Travel Rule to Smaller Transfers – Regulators Seek Tighter Global AML Alignment
Key Takeaways
- South Korea’s Financial Intelligence Unit proposed extending Travel Rule requirements to smaller crypto transfers at a FATF plenary in Paris.
- The country currently applies the Travel Rule to crypto transactions above 1 million won, or about $650.
- The FIU called for obligations to apply to both originating and receiving crypto asset service providers.
- FATF data from 2025 shows that only about 29% of jurisdictions are largely compliant or compliant with crypto AML standards.
South Korea Seeks Lower Threshold for Crypto Travel Rule Reporting
South Korea’s Financial Intelligence Unit, or FIU, has proposed expanding the scope of the crypto Travel Rule to cover smaller transactions. The proposal was presented during a plenary meeting of the Financial Action Task Force, or FATF, held in Paris last week.
Under current South Korean rules, crypto asset service providers must comply with Travel Rule requirements for transfers exceeding 1 million won, equivalent to roughly $650. The Travel Rule obliges platforms to share identifying information about both the sender and the recipient when certain transaction thresholds are met. The measure is designed to improve traceability of digital asset transfers and strengthen Anti-Money Laundering controls.
The FIU is now advocating for those reporting obligations to apply to transfers below the existing threshold. The initiative aims to align domestic standards more closely with evolving international expectations and to address what regulators describe as ongoing risks linked to cross border crypto flows.
Focus on Cross Border Gaps and Offshore Platforms
In its statement, the FIU emphasized that Travel Rule obligations should apply to both originating and receiving crypto asset service providers. According to the regulator, applying requirements symmetrically could reduce gaps in cross border transactions where information sharing may otherwise be incomplete.
The FIU also called for stronger action against offshore and unregistered crypto platforms. It cited increased misuse of such platforms in illicit finance cases and highlighted the risk of regulatory arbitrage. Regulatory arbitrage can occur when market participants exploit differences in licensing standards, supervisory intensity, or enforcement between jurisdictions.
FIU Commissioner Lee Hyung Ju addressed these issues during the FATF plenary session. He pointed to differences in licensing, supervision, and offshore oversight as key drivers of uneven enforcement across jurisdictions. According to the FIU, such differences continue to create vulnerabilities in the global crypto ecosystem.
For users of international crypto services, including those engaging with betting or gaming platforms that accept digital assets, these discussions underline the growing focus on transaction monitoring and identity verification standards across borders.
FATF Recommendation 15 and Uneven Global Compliance
The proposal forms part of broader discussions on FATF Recommendation 15. This recommendation was updated in 2019 to extend Anti-Money Laundering standards to crypto assets and crypto asset service providers.
Seven years after the update, global implementation remains uneven. A targeted update published by FATF in 2025 found that 49% of assessed jurisdictions were only partially compliant with requirements for crypto asset service providers. Another 21% were rated non compliant as of April 2025. Only about 29% of jurisdictions were assessed as largely compliant or fully compliant.
These figures were referenced in connection with the ongoing discussions at the FATF level. They illustrate that, despite the formal adoption of standards, practical enforcement and supervision differ significantly across countries.
For regulators such as South Korea’s FIU, this uneven implementation is linked to continued risks in cross border crypto transfers. When transaction monitoring standards vary, funds can move between jurisdictions with different levels of oversight.
DeFi Risks Also Addressed at FATF Meeting
Beyond the Travel Rule debate, FATF approved a new report examining risks associated with decentralized finance, or DeFi. The FIU welcomed the adoption of this DeFi related report during the plenary discussions.
While the announcement did not detail the contents of the report, its approval signals that decentralized protocols remain a focus of international AML discussions. The FIU linked regulatory arbitrage not only to offshore platforms but also to broader differences in how jurisdictions license and supervise crypto activities.
The combination of Travel Rule expansion and increased scrutiny of DeFi suggests that regulators are reviewing how existing AML frameworks apply to both centralized service providers and decentralized structures.
Implications for Crypto Service Providers and Cross Border Users
If Travel Rule requirements are extended to smaller transfers, crypto asset service providers operating in or connected to South Korea would need to collect and transmit identifying information for a greater number of transactions. This could increase compliance obligations, particularly for platforms handling high volumes of smaller transfers.
Because the FIU raised the proposal at the FATF level, the discussion also has an international dimension. FATF standards influence national legislation in many jurisdictions. Any shift in interpretation or guidance around thresholds may eventually shape how different countries calibrate their own reporting rules.
For users who rely on cross border crypto services, including exchanges and platforms that process payments for online activities, the direction of travel is clear: regulators are seeking broader data sharing and tighter monitoring of digital asset transfers.
Our Assessment
South Korea’s FIU has formally proposed lowering the threshold for Travel Rule reporting during FATF discussions, expanding its scope beyond the current 1 million won level. The proposal is part of wider efforts to address gaps in global AML enforcement, particularly in cross border transfers and offshore platform activity. FATF data showing that a majority of jurisdictions are not fully compliant with Recommendation 15 provides context for the initiative. The discussion signals continued regulatory focus on transaction traceability, crypto asset service providers, and DeFi related risks at the international level.
EU Opens MiCA 2.0 Consultation – Stablecoins and DeFi Rules Under Review
Key Takeaways
- The European Commission has opened a consultation to revise its Markets in Crypto Assets regulation, informally referred to as MiCA 2.0.
- The review covers regulatory scope, stablecoin requirements, crypto-asset service providers and areas not addressed in the original framework, including DeFi and prediction markets.
- Industry representatives are calling for adjustments to stablecoin reserve rules and restrictions on incentives.
- The consultation period runs until August 31, and legislative changes are not expected before 2028.
European Commission Seeks Feedback on MiCA Revisions
The European Commission has launched a formal comment period to gather feedback on potential changes to its Markets in Crypto Assets regulation. The initiative follows the full application and enforcement of MiCA, which began on December 30, 2024, with the first licenses issued in early 2025.
MiCA created a harmonised regulatory framework for crypto assets across European Union member states. It introduced a single rulebook designed to provide consumer protection and legal clarity for crypto businesses operating across the bloc.
The current consultation is widely described within the industry as the first step toward what could become MiCA 2.0. According to the Commission, the review is divided into four main areas: the regulatory scope and definitions for crypto assets other than asset-referenced tokens and e-money tokens, requirements for e-money tokens and asset-referenced tokens and their issuers, the legal framework for crypto-asset service providers, and topics not covered in the initial regulation, including decentralised finance and prediction markets.
For crypto users and platform operators, the outcome of this review may determine how services involving stablecoins, decentralised protocols or event-based markets are treated under EU law.
Stablecoins at the Center of Regulatory Debate
The section addressing e-money tokens and asset-referenced tokens is considered one of the most significant parts of the consultation. Stablecoins fall within these categories under MiCA.
Regulatory treatment may depend on how stablecoins are used in practice. If authorities view them mainly as trading instruments, the focus is likely to remain on investor protection and market integrity. If they are treated as payment infrastructure, supervisory attention could shift toward redemption rights, liquidity management, reserve composition, operational resilience and reporting obligations.
Catarina Veloso, director of regulatory and compliance at Notabene, stated that the risks associated with stablecoins depend on their scale, user base and links to other parts of the financial system. This functional approach could influence how detailed future requirements become.
Industry participants are also calling for targeted adjustments. Katie Harries, director and head of policy for Europe at Coinbase, said refinements could make euro-denominated stablecoins more competitive. She highlighted reserve rules, rewards and the so-called multi-issuance model as areas for recalibration.
Under the current MiCA framework, issuers of e-money tokens are prohibited from offering interest. According to Veloso, this restriction may reduce the competitiveness of euro stablecoins and potentially shift users toward foreign-currency stablecoins or yield structures outside the regulated framework. Harries indicated that non-interest incentives such as cashback or loyalty programs could be considered as an alternative, noting that such features are common in traditional payment services.
For users of crypto betting or iGaming platforms that rely on stablecoin payments, any changes to issuance, reserve management or incentive rules could affect which tokens are available and under what conditions they are offered within the EU.
Defining DeFi and Responsibilities of Service Providers
MiCA currently does not apply to fully decentralised crypto-asset service providers operating without intermediaries. However, the consultation signals that regulators are examining whether and how decentralised finance should be addressed.
Veloso noted that decentralisation is rarely binary. Policymakers must determine which indicators are relevant when assessing whether a platform is genuinely decentralised. Potential factors include control over protocol governance, possession of administrative keys, influence over front-end interfaces, revenue capture mechanisms and the ability to upgrade or modify smart contracts.
Miroslav Đurić, senior associate at Taylor Wessing, pointed out that many regulated crypto-asset service providers already connect clients to decentralised finance platforms. Because these platforms fall outside MiCA, regulators are now considering whether service providers should conduct due diligence before granting access.
One option under discussion would allow service providers to connect clients only to decentralised platforms that meet certain certification standards under a potential new regime. Such a move would affect how centralised exchanges and intermediaries integrate decentralised products.
Prediction Markets Face Overlapping Regulatory Questions
The consultation also addresses prediction markets, which were not covered explicitly in MiCA 1.0. Currently, there is no unified regulatory structure for such platforms in the EU, and they are banned in some member states.
The Commission is seeking feedback on whether prediction markets provide economic benefits to consumers and whether they fall under MiCA or the Markets in Financial Instruments Directive. According to Đurić, the regulatory classification will depend on the nature of the event contracts offered.
Depending on contract design, a platform operator could fall under multiple frameworks, including financial market regulation, gambling law or crypto asset regulation. For operators and users in the crypto betting sector, this distinction is particularly relevant, as it may determine licensing requirements and cross-border availability.
Timeline and Legislative Outlook
The comment period for the consultation runs until August 31. Stakeholders from across the crypto industry have indicated that they plan to remain engaged throughout the process.
However, legislative change at the EU level typically involves lengthy procedures. According to Đurić, given the complexity of the issues raised, concrete legislative proposals are unlikely to be adopted before 2028.
Until then, the current MiCA framework remains in force, including its provisions on stablecoin issuance, licensing of crypto-asset service providers and consumer protection measures.
Our Assessment
The European Commission’s consultation marks the first formal step toward revising MiCA after its full implementation in late 2024. The review focuses on stablecoins, decentralised finance, crypto-asset service provider obligations and prediction markets – areas that have gained prominence since the original framework was drafted.
For crypto users and operators, including those active in crypto-based betting and online gambling, the process may clarify how stablecoins can be structured, how decentralised platforms are assessed and which regulatory regimes apply to event-based markets. Any legislative amendments are expected to follow an extended EU process, with potential adoption not anticipated before 2028.
CFTC Permanently Bans Celsius Founder Alex Mashinsky From Trading – Settlement Concludes First Case Against a Crypto Lending Platform
Key Takeaways
- The US Commodity Futures Trading Commission has permanently banned Alex Mashinsky from trading in markets it oversees.
- A court consent order also prohibits Mashinsky from registering with the CFTC.
- The settlement concludes the CFTC’s first enforcement action against a digital asset lending platform.
- Mashinsky was sentenced to 12 years in prison in May 2025 after pleading guilty to securities and commodities fraud.
- Separate proceedings with the US Securities and Exchange Commission remain ongoing.
CFTC Settlement Imposes Lifetime Market Ban
The US Commodity Futures Trading Commission has resolved its enforcement action against Celsius Network founder Alex Mashinsky, permanently barring him from trading in markets under the agency’s supervision. According to the regulator, a court consent order not only imposes a lifetime trading ban but also prohibits Mashinsky from ever registering with the CFTC.
The order brings to a close the CFTC’s case first filed in 2023. With the settlement, the agency ends what it described as its first enforcement action against a digital asset lending platform.
The CFTC stated that Mashinsky and Celsius engaged in a scheme to defraud hundreds of thousands of customers. The regulator alleged that the company misrepresented the safety, profitability and regulatory compliance of its digital asset based finance platform.
As a result of the order, Mashinsky is now permanently excluded from participating in US commodities, futures and derivatives markets. Earlier this year, the CFTC and the US Securities and Exchange Commission issued guidance stating that they consider most major cryptocurrencies to be commodities. This classification places a broad segment of the crypto market within the CFTC’s oversight, increasing the practical scope of the trading ban.
Background: Celsius Collapse and Criminal Conviction
Celsius Network was a crypto lending platform that received approximately 20 billion dollars in customer funds, according to the CFTC’s allegations. The agency said the company made risky investments in order to meet the returns it had promised users.
The platform collapsed during a major market drawdown in 2022. The failure of Celsius became one of the high profile breakdowns in the digital asset lending sector during that period.
In May 2025, Mashinsky was sentenced to 12 years in prison after pleading guilty to securities and commodities fraud. Prosecutors accused him of misleading customers about the safety of the Celsius platform. The prison sentence followed his guilty plea and addressed conduct related to the platform’s operations and representations to users.
The CFTC settlement marks one of the final regulatory actions pending against Mashinsky. However, it does not conclude all legal proceedings connected to his role at Celsius.
Other Regulatory Actions: FTC and SEC Proceedings
In addition to the CFTC case, Mashinsky previously settled a complaint with the US Federal Trade Commission. In April, that agreement permanently barred him from working with any product or service that can be used to deposit, exchange, invest or withdraw assets. This restriction effectively prevents him from participating in crypto or broader financial services activities covered by the FTC order.
Separate civil charges brought by the US Securities and Exchange Commission in July 2023 remain unresolved. The SEC has accused Mashinsky of conducting an unregistered securities offering, misrepresenting Celsius’ business and safety practices and manipulating the price of the platform’s CEL token.
In late May, the SEC informed a federal court that it had engaged in substantive settlement discussions with Mashinsky. At that time, no agreement had been reached. The court granted the regulator’s request for an additional 60 days to continue negotiations.
Efforts to Vacate Criminal Sentence
On May 26, Mashinsky filed a motion seeking to vacate his 12 year criminal sentence. In his filing, he argued that his legal counsel had been ineffective and that evidence in the case had been tainted by authorities’ misconduct. He also claimed that Sam Bankman-Fried, co founder of FTX and a convicted fraudster, was responsible for manipulation of the CEL token.
A court ordered prosecutors to respond to Mashinsky’s request by mid August. The outcome of that motion remains pending.
Regulatory Significance for Crypto Markets
The conclusion of the CFTC’s first case against a digital asset lending platform provides a reference point for how US commodities regulators address misconduct in crypto related financial services. By imposing a lifetime trading and registration ban, the agency has removed Mashinsky from participation in markets it oversees.
Because the CFTC and SEC have stated that most major cryptocurrencies qualify as commodities, the trading prohibition covers a substantial portion of the crypto derivatives and commodities landscape in the United States. For market participants, including users of crypto based financial and trading platforms, the case underscores the regulatory consequences tied to representations about safety, returns and compliance.
At the same time, the ongoing SEC proceedings and the motion to vacate the criminal sentence indicate that legal exposure tied to the Celsius collapse has not fully concluded.
Our Assessment
The CFTC’s settlement with Alex Mashinsky permanently bars him from trading and registering in US commodities markets and closes the agency’s first enforcement action against a digital asset lending platform. Combined with his prior prison sentence and FTC ban, the order significantly restricts his future involvement in crypto and financial markets, while SEC proceedings and post conviction motions remain active.
Dutch Regulator Fines Chestoption €3.1 Million for Unlicensed Gambling – Enforcement Targets Crypto Payments and Market Access
Key Takeaways
- The Netherlands Gambling Authority fined Chestoption Sociedad de Responsabilidad Limitada €3.1 million for offering online gambling without a Dutch licence.
- Dutch players were able to access and gamble on Vave.com, Vave-luck.com, and 67evav55.com.
- The regulator cited Dutch-language affiliate marketing, Eredivisie betting markets, and insufficient geo-blocking as evidence of market targeting.
- Aggravating factors included missing visible age verification, use of autoplay, crypto payments, and restrictive withdrawal conditions.
- The company had previously been ordered to stop and incurred €840,000 in penalty payments after continued accessibility.
€3.1 Million Fine for Offering Gambling Without a Dutch Licence
The Netherlands Gambling Authority, known as the KSA, has imposed a €3.1 million fine on Costa Rica-based Chestoption Sociedad de Responsabilidad Limitada. The regulator concluded that the company offered online gambling services to players in the Netherlands without holding the required national licence.
According to the KSA, Dutch users were able to register accounts, deposit funds, and participate in online casino games via three websites operated by the company: Vave.com, Vave-luck.com, and 67evav55.com. The authority determined that these platforms were accessible from within the Netherlands and that Dutch players could actively use them.
The decision was issued on 9 June. Chestoption has six weeks from notification of the ruling to file an objection with the regulator.
Evidence of Targeting the Dutch Market
In its findings, the KSA stated that the platforms were at least partially directed at the Dutch market. The authority referred to several elements it considered relevant.
One factor was the use of Dutch-language affiliate marketing. Promotional content in Dutch indicated that the operator sought to reach users in the Netherlands. In addition, the websites offered betting markets on the Eredivisie, the country’s top football league, which the regulator interpreted as further evidence of local targeting.
The KSA also pointed to insufficient geo-blocking measures. According to the authority, the operator did not adequately prevent access from Dutch IP addresses. As a result, users located in the Netherlands were able to create accounts and participate in gambling activities.
For international users evaluating platforms, geo-blocking and language targeting are central compliance indicators. Regulators often assess whether operators actively restrict access in jurisdictions where they are not licensed.
Crypto Payments and Consumer Protection Concerns
The regulator identified several aggravating factors that influenced the level of the fine. Among them was the acceptance of cryptocurrency payments. While the KSA did not provide additional detail on the specific assets involved, it listed crypto acceptance as part of its assessment.
The authority also found that there was no visible age verification process on the platforms. In addition, it cited the use of autoplay features, which are prohibited under Dutch regulations.
Beyond access and payment methods, the KSA raised concerns about withdrawal conditions. It described requirements for repeated wagering before cashouts and restrictions on access to player balances. According to the regulator, such conditions could encourage continued gambling and may be harmful to consumers.
For users of crypto betting and casino platforms, withdrawal rules and wagering requirements are critical operational details. In this case, the regulator considered those mechanisms relevant to consumer protection enforcement.
Previous Enforcement and Additional Penalty Payments
The fine follows earlier regulatory action against the same operator. The KSA had previously ordered Chestoption to cease offering unlicensed gambling services in the Netherlands.
Despite that order, follow-up inspections reportedly found that the websites remained accessible to Dutch users. As a result, the company incurred additional penalty payments totaling €840,000.
The new €3.1 million fine reflects what the regulator described as continued non-compliance after earlier intervention. The case illustrates how repeated violations can lead to escalating financial consequences.
Broader Enforcement Measures Beyond Financial Penalties
In its statement, the KSA emphasized that enforcement against illegal gambling operators does not stop at administrative fines. The authority stated that it cooperates with third parties to restrict access to unlicensed offerings.
These third parties include payment providers, hosting companies, banks, and major technology platforms. Such cooperation can involve measures aimed at limiting payment processing, website hosting, or online visibility.
For international operators and users alike, this signals that regulatory enforcement can extend beyond direct sanctions against a company. Payment flows, platform infrastructure, and distribution channels may also be affected when a regulator determines that services are offered without authorization.
Our Assessment
The €3.1 million fine against Chestoption confirms that the Netherlands Gambling Authority is actively pursuing operators it considers to be targeting Dutch players without a licence. The decision highlights specific compliance areas under scrutiny, including geo-blocking, language targeting, crypto payments, age verification, autoplay features, and withdrawal conditions.
The case also shows that prior enforcement orders and continued accessibility can lead to additional penalty payments. For users and operators in the crypto gambling segment, the ruling underlines that regulatory oversight in the Netherlands includes both financial sanctions and cooperation with payment and technology partners to restrict market access.