FATF & Stablecoin AML

FATF's 2026 Stablecoin & Unhosted Wallet Report: P2P AML Risks, Controls & Red Flags

What FATF’s 2026 report says about stablecoin and unhosted-wallet risks, P2P activity, red flags, and practical AML controls for issuers and VASPs.

On this page
Get Expert Help

Key takeaways

  • FATF’s March 2026 report focuses specifically on stablecoin, P2P and unhosted-wallet AML/CFT risks, but the report itself does not create binding obligations for private businesses.
  • Stablecoins accounted for roughly 84% of illicit virtual-asset transaction volume in 2025, according to Chainalysis data cited by FATF.
  • P2P transfers between unhosted wallets create a distinct compliance gap because transactions can occur without a VASP or financial institution acting as an AML/CFT intermediary.
  • FATF highlights controls such as allow-listing, deny-listing, transaction limits, freeze/burn capabilities and blockchain analytics as practical risk-mitigation approaches.
  • Canadian and U.S. businesses should treat the report as a regulatory-risk signal and assess their controls, while continuing to follow applicable domestic FINTRAC, PCMLTFA, FinCEN and BSA requirements.

In March 2026, the Financial Action Task Force (FATF) published a targeted report focused specifically on stablecoins and unhosted wallets, with an emphasis on peer-to-peer (P2P) transactions. It builds on FATF's earlier stablecoin work dating back to 2019, but this is the first report to isolate P2P and unhosted-wallet risk as a standalone problem rather than treating it as one feature of the broader virtual asset ecosystem.

For MSBs, VASPs, payment companies and other stablecoin-adjacent businesses, the report matters for two reasons. First, it confirms with fresh data that stablecoins have overtaken other virtual assets as the preferred tool for laundering illicit proceeds. Second, it sets out a working menu of controls β€” allow-listing, deny-listing, transaction limits, freeze and burn functions β€” that supervisors in multiple jurisdictions are now expecting issuers and intermediaries to consider.

This article summarizes what the report actually says, distinguishes FATF recommendations from binding legal requirements, and sets out the practical control measures compliance teams should be evaluating.

What the Report Covers

The report reflects developments in the stablecoin ecosystem through the end of 2025. FATF built it from two rounds of information requests to its Virtual Asset Contact Group, which produced case studies and jurisdictional input, plus a private-sector outreach survey and a roundtable with stablecoin issuers and blockchain analytics providers.

The report is organized around three questions: how the stablecoin ecosystem currently works and who the participants are, how threat actors are actually using stablecoins and where the vulnerabilities sit, and what practices jurisdictions and industry are using to mitigate that risk. Like all FATF guidance products, the report itself is non-binding on private businesses β€” a point worth holding onto throughout, because it shapes how the rest of this article should be read.

Why Stablecoins Have Become the Preferred Illicit Asset

The report's data points explain why FATF chose to isolate stablecoins for targeted treatment rather than folding them into general virtual asset guidance. By October 2025, stablecoin market capitalization had reached roughly USD 316 billion, and 24-hour trading volume had climbed to around USD 156 billion β€” nearly three times Bitcoin's volume on the same measure. Fiat-backed stablecoins, overwhelmingly USD-referenced, dominate that market.

The same features that make stablecoins attractive to legitimate users β€” price stability, deep liquidity, and cross-chain interoperability β€” are what make them useful to launderers, terrorist financiers and sanctions evaders. According to Chainalysis data cited in the report, stablecoins accounted for roughly 84% of illicit virtual asset transaction volume in 2025, overtaking Bitcoin as the dominant asset in cybercrime-linked on-chain activity.

The report walks through several threat-actor patterns rather than treating illicit use as a single category:

  • State-linked actors. DPRK groups including Lazarus, Andariel and Onyx Sleet have shifted toward stablecoins, typically USDT on Tron, as a laundering vehicle following large-scale virtual asset theft. The report also describes DPRK's 221 General Bureau using stablecoins to pay for goods prohibited under UN Security Council resolutions, including materials connected to weapons production β€” a use case FATF treats as an emerging proliferation-financing concern rather than a purely laundering one. Iranian actors, including entities linked to the IRGC, have been assessed as using virtual assets, with stablecoins preferred for their utility in financing international trade under sanctions pressure.
  • Fraud and drug trafficking proceeds. The report describes laundering chains that move stolen or drug-trafficking funds through unregistered VASPs, DEXs without KYC, and OTC brokers, often converting between stablecoins and other virtual assets to obscure the trail before cashing out.
  • Terrorist financing. Groups including ISIL and Al-Qaeda affiliates have solicited stablecoin donations through social media and encrypted platforms, using rotating wallet addresses and structuring techniques to fragment larger transfers and reduce detection risk.

The report includes several jurisdictional case studies illustrating these patterns in practice, including a French VASP detection case involving gambling proceeds converted rapidly into stablecoins, a Canadian case involving drug-trafficking proceeds layered through DEX swaps and a shell import-export company, and an Indian case involving stablecoin flows tied to trafficked labor in Southeast Asian scam compounds.

Why P2P Transactions via Unhosted Wallets Are a Distinct Risk

The report's central structural point is that P2P transfers between unhosted wallets fall largely outside the AML/CFT framework FATF has built for virtual assets β€” not because FATF overlooked the gap, but because its Standards place obligations on intermediaries (VASPs and financial institutions), not on individuals transacting directly with each other.

That creates a specific set of problems the report walks through:

  • No obliged entity to report. Where a transaction happens entirely between two unhosted wallets, there is no VASP positioned to file a suspicious transaction report, because no VASP is involved in the transfer.
  • Pseudonymity compounds the gap. Blockchain transactions are visible and traceable in principle, but wallet addresses are pseudonymous. Criminals who generate new addresses frequently and abandon old ones make it harder for authorities to link P2P activity to a known identity or entity.
  • Cross-chain fragmentation. Because stablecoins increasingly operate across multiple blockchains via bridges and wrapped-token mechanisms, transaction trails can be split across networks that don't natively interact, which also weakens issuers' ability to apply freeze or blacklist functions consistently.
  • Redemption doesn't require official channels. Stablecoin holders can convert to fiat through informal or non-compliant OTC brokers and P2P platforms rather than through a licensed intermediary, which the report identifies as a distinct vulnerability at the redemption stage.

Importantly, the report does not claim that FATF Standards should be extended to directly regulate individuals conducting P2P transfers. Instead, it directs jurisdictions to assess and understand the scale of P2P activity in their markets and implement risk mitigation measures proportionate to that risk β€” a materially different ask than a blanket prohibition or licensing requirement on individuals.

Good Practices FATF Identifies for Issuers and Intermediaries

The report's most operationally useful section sets out control measures jurisdictions and the private sector are already using. These are not FATF requirements in the legal sense β€” they are practices FATF is highlighting as effective, several of which it recommends jurisdictions consider mandating through domestic frameworks.

Allow-listing and deny-listing

Stablecoin issuers can embed access-control logic directly into a stablecoin's smart contract.

Approach How it works Trade-off
Allow-listing (whitelisting) Only pre-approved, identity-verified wallet addresses can transact in the stablecoin. Proactive and identity-based, but may push privacy-conscious users out of the regulated ecosystem.
Deny-listing (blacklisting) Specific wallet addresses are blocked from transacting, typically based on law enforcement or sanctions data. More commonly used in practice, but reactive β€” action is usually triggered only after an address is already flagged.

The report notes deny-listing is currently the more widely used approach precisely because it's reactive and lower-friction, while allow-listing offers stronger preventive control at the cost of user onboarding complexity. Switzerland's approach, described in the report, combines an on-chain allow-list with third-party verification of unhosted wallet holders by banks or VASPs before those wallets are added to the list.

Transaction limits and block/freeze/withdraw capability

Issuers are also applying per-transaction or daily transfer limits on wallet addresses, and building in the technical ability to block a specific transaction, freeze an entire wallet, or withdraw stablecoins by burning and re-issuing them. The report frames these as complementary to allow-listing or deny-listing rather than substitutes for it, and notes this capability is also what allows issuers to comply with law enforcement freeze or confiscation orders.

Blockchain analytics, on both sides

Both supervisors and private-sector participants are using blockchain analytics tools to trace stablecoin flows and flag exposure to high-risk or sanctioned addresses. The report is candid about the limits of these tools β€” inconsistent taxonomies between providers, cost, and the specialized skill needed to interpret outputs β€” and stresses they work best combined with human investigative judgment rather than as a standalone control.

Regulatory frameworks that name stablecoins specifically

A relatively small number of jurisdictions have built stablecoin-specific AML/CFT frameworks rather than relying on general virtual asset rules. Japan's regime places CDD obligations on issuers at both issuance and redemption and separately registers intermediaries. The EU's MiCA framework distinguishes e-money tokens from asset-referenced tokens, with different AML/CFT treatment depending on classification. The report also highlights approaches from Kazakhstan's Astana International Financial Centre and Hong Kong's Stablecoins Ordinance, both of which combine licensing requirements with risk-based AML/CFT expectations tailored to unhosted wallet exposure.

FATF's Risk Indicators for Stablecoin Misuse

The report's annex sets out a detailed list of red flags across three categories. Rather than reproducing the full list, the categories and a sample of the most operationally relevant indicators are below.

Transaction-pattern indicators β€” large or rapid cross-border stablecoin movements inconsistent with a customer's profile; transfers from multiple unrelated parties converging on the same wallet in a short window; stablecoins funding gambling accounts followed by "refunds" routed to unrelated wallets; repeated fiat-to-stablecoin conversions with no apparent economic rationale.

Anonymity-related indicators β€” transfers involving unhosted wallets multiple hops away from any Travel Rule-covered wallet; wallets that reactivate after long dormancy, execute rapid cross-chain activity, then go quiet again; integration with DeFi protocols specifically to obscure a transaction trail; use of offshore issuers not authorized in the relevant jurisdiction.

TF/PF-specific indicators β€” frequently changing donation wallets that nonetheless share technical fingerprints such as QR codes or domains; stablecoin inflows framed as humanitarian support that are rapidly diverted into trading or mixing activity; payments routed to intermediaries near free trade zones for dual-use goods, with shipment documentation that doesn't match the underlying stablecoin value transfer.

These indicators are most useful as inputs into existing transaction monitoring and EDD frameworks, not as a standalone checklist β€” a single indicator rarely justifies escalation on its own, but clustering of several against one customer or wallet pattern is a stronger signal.

What FATF Guidance Does β€” and Doesn't β€” Require

This is the point most worth getting right. FATF reports and recommendations are not, by themselves, binding legal obligations on a private business. FATF sets the global standard that its member jurisdictions are expected to implement through domestic law and regulation β€” but until a jurisdiction actually legislates or a regulator actually issues binding rules based on this report, a Canadian or U.S. business's legal obligations continue to come from FINTRAC and the PCMLTFA, or from FinCEN and the Bank Secrecy Act, not from the FATF report directly.

The report itself is explicit that P2P transactions via unhosted wallets are not explicitly brought within AML/CFT obligations under the FATF Standards β€” the obligations sit with VASPs and financial institutions acting as intermediaries. Where the report recommends jurisdictions "consider" requiring issuers to implement allow-lists, transaction limits, or enhanced due diligence on unhosted wallet counterparties, that is a recommendation for domestic policymakers to weigh, not an obligation that already binds issuers today.

For Canadian MSBs and stablecoin-related businesses, this means treating the report as an early signal of where FINTRAC expectations may move, not as a current compliance requirement in its own right. The same applies to FinCEN and U.S. federal regulators. Businesses operating in the stablecoin space should track how domestic regulators respond to this report over the coming months, rather than assuming its recommendations are already enforceable.

What This Means in Practice

For MSBs, VASPs, and payment businesses with stablecoin exposure, the practical takeaway is less about the report's data and more about program readiness. If your AML program doesn't currently address unhosted wallet counterparty risk, transaction limits for P2P-adjacent activity, or a documented rationale for how you assess exposure to stablecoin flows, this report is a reasonable prompt to close that gap before a domestic regulator makes it a requirement rather than a recommendation.

That's a governance and program design question as much as a technology one β€” deciding where your business sits on the allow-list-versus-deny-list spectrum, what enhanced due diligence looks like for unhosted wallet transfers, and how findings get fed back into your risk assessment are structural decisions, not just tooling decisions.

If your compliance program needs a current assessment against this kind of emerging guidance, ComplyFactor's AML Advisory services can help you work through what applies to your business model now versus what to monitor for later regulatory action.

FAQ

Does this report create new legal obligations for Canadian MSBs?

‍No. It's FATF guidance, not Canadian law. Any binding obligations for Canadian MSBs continue to come from FINTRAC and the PCMLTFA. The report may influence how those requirements evolve, but it isn't itself enforceable.

Are unhosted wallets illegal under FATF Standards?

‍No. FATF does not prohibit unhosted wallets. Its Standards place obligations on VASPs and financial institutions that act as intermediaries; individuals transacting directly between unhosted wallets fall outside that intermediary-based framework, which is precisely the gap this report addresses.

Is allow-listing required for stablecoin issuers?

‍No. The report describes allow-listing as one good practice some jurisdictions and issuers use, alongside deny-listing and transaction limits. Whether it's required depends on the issuer's domestic regulatory framework, not on the FATF report itself.

How is this different from the GENIUS Act or Canada's stablecoin framework?

‍The GENIUS Act and Canada's stablecoin framework are domestic regulatory regimes with their own binding requirements. This FATF report is an international standard-setter's assessment of global risk and practice β€” it may inform how those domestic frameworks develop, but it operates at a different level and shouldn't be read as equivalent to either.

‍

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.