For years, the defining regulatory threat for any crypto company operating in the United States was simple: don't let the SEC call your token a security. That classification battle consumed billions in legal fees, dominated compliance conversations, and ended careers. It was the war that defined an era. That era is over. According to CertiK's Skynet Intelligence Report 09 β€” "State of Digital Asset Regulations," published April 29, 2026 β€” Anti-Money Laundering enforcement has now overtaken securities classification as the primary regulatory kill-switch facing digital asset firms. The data behind this shift is not subtle. It is one of the sharpest enforcement pivots in the history of financial regulation.


What Is the CertiK Skynet Report 09?

CertiK Skynet Intelligence Report 09 β€” "State of Digital Asset Regulations"
Published April 29, 2026 Β· certik.com Β· Covers 11 jurisdictions

CertiK is the world's largest Web3 security auditor, having secured over $600 billion in digital assets and worked with more than 5,000 enterprise clients including Binance, Ripple, and the Ethereum Foundation. Skynet Report 09 consolidates regulatory developments across the US, EU, UK, Hong Kong, Singapore, UAE, Japan, South Korea, Brazil, India, and Turkey. Its core conclusion: the industry has entered a "strong compliance era" where AML enforcement, mandatory security audits, and prudential capital standards define the risk landscape β€” not token classification battles.

Stefan Muehlbauer, CertiK's head of US government policy, put it plainly: "The era of ambiguity in digital-asset regulation is already over." The report covers not just enforcement trends, but stablecoin regulatory convergence, Basel Committee capital rules taking effect in 2026, and the growing mandatory nature of smart contract security audits across seven major jurisdictions.

πŸ’¬ Paul S. Atkins β€” SEC Chairman
SEC.gov Β· March 17, 2026 Β· On clarifying crypto securities law

"After more than a decade of uncertainty, this interpretation will provide market participants with a clear understanding of how the Commission treats crypto assets under federal securities laws. This is what regulatory agencies are supposed to do: draw clear lines in clear terms. It acknowledges what the former administration refused to recognise β€” that most crypto assets are not themselves securities."

Atkins' posture explains precisely why the SEC's enforcement numbers collapsed β€” it was a deliberate policy choice, not institutional weakness. The vacuum left by the SEC's retreat was filled immediately by the DOJ and FinCEN, who had no interest in scaling back.


The Numbers: SEC vs AML β€” A 97% Collapse

The headline finding of the report is a dramatic reversal in enforcement priorities that unfolded across 2024 and 2025. The SEC, which had been the dominant regulatory force in crypto under Chair Gary Gensler, saw its crypto-specific enforcement activity collapse. Meanwhile, the Department of Justice and FinCEN stepped into the vacuum with a wave of AML and Bank Secrecy Act actions that dwarfed anything seen before.

Agency / Metric 2024 2025 Change
SEC crypto penalty value $4.9 billion $142 million βˆ’97% ↓
SEC crypto enforcement actions (volume) 33 actions 13 actions βˆ’60% ↓
DOJ + FinCEN AML fines (H1 2025 only) β€” $900M–$1B+ ↑ New record
EU AML fines (YoY) Baseline +767% +767% ↑
Sanctions-related crypto volume (YoY) Baseline +400% overall
+694% state-driven
↑ Explosive

Sources: CertiK Skynet Report 09; SEC enforcement data; DOJ press releases; FinCEN enforcement actions.

πŸ“Š On-Chain Data Β· CEX Outflows During Legal Settlements
OKX & KuCoin Wallet Outflows Around Settlement Dates (Jan–Mar 2025)
On-chain data showing capital outflows from OKX (red) and KuCoin (green) exchange wallets during their DOJ settlement period. The spikes correspond directly with the $504M OKX settlement (Feb 2025) and $297M KuCoin settlement (Jan 2025). Negative values indicate net outflows β€” capital leaving the exchange.
OKX & KuCoin Wallet Outflows Around Settlement Dates (Jan–Mar 2025)
Source: @chainsutra on Dune Analytics

OKX, KuCoin, and the New Enforcement Playbook

Two settlements anchor the AML enforcement trend and define the new playbook regulators are using against crypto exchanges. Both cases involved exchanges that had served millions of users globally while operating without adequate anti-money laundering controls β€” or in some cases, without any US money transmission licence at all.

OKX β€” $504 Million Settlement
DOJ Β· February 2025 Β· Bank Secrecy Act + Unlicensed Money Transmission

OKX pleaded guilty to operating an unlicensed money transmitting business. DOJ prosecutors cited more than $5 billion in suspicious transaction flows processed through the platform. The $504 million settlement is one of the largest AML penalties in crypto history. The case was built not on token classification but on failures of transaction monitoring, KYC, and licensing infrastructure β€” the operational backbone of AML compliance.

KuCoin β€” $297 Million Settlement + Market Exit
DOJ Β· January 2025 Β· Bank Secrecy Act + Unlicensed Money Transmission

KuCoin's settlement covered similar Bank Secrecy Act failures. Its co-founders agreed to step down personally, and the exchange committed to exiting the US market for at least two years. The personal accountability dimension β€” founders stepping down as a settlement condition β€” signals a new prosecutorial appetite for individual liability, not just corporate fines.

"Transaction monitoring and licensing failures are now drawing penalties that rival or exceed many earlier crypto securities cases. The battlefield has moved from courtrooms arguing token classification to compliance operations rooms."

πŸ’¬ Brian Armstrong β€” CEO, Coinbase
Public statement Β· January 2026 Β· On the CLARITY Act and compliance

"Clear rules end uncertainty, but overreach could stifle startups. We'd rather see no bill than a bad bill." Armstrong has also been explicit that AML compliance is a commercial imperative: "Crypto is a technology update to the financial system β€” we want every bank, fintech company, and every payment company to be integrated." Coinbase itself paid a $100 million settlement to New York's DFS over compliance deficiencies in 2023, making it intimately familiar with the cost of AML failure.

These cases are not outliers. They are templates. European regulators applied parallel pressure over the same period, with AML fines in the EU surging 767% year-over-year. Asia-Pacific regulators increasingly favour licence revocations and business improvement orders over monetary penalties β€” a tool that can be more devastating than a fine because it shuts the business down entirely.


Sanctions Volume Grew 400% β€” The Russia Factor

The CertiK report identifies a specific driver behind the surge in AML enforcement pressure: a dramatic increase in sanctions-related cryptocurrency activity, primarily driven by Russia-linked networks and state-aligned stablecoin infrastructure. Sanctions-related crypto volume grew over 400% year-over-year in 2025, with state-driven sanctions evasion volume up 694% over the same period.

πŸ’¬ Jeremy Allaire β€” CEO, Circle (USDC)
Semafor interview Β· August 2025 Β· On compliance and market access

"You've got to work with governments. That became a founding principle for the company β€” we're going to go in through the front door with policymakers and regulators." On the question of offshore issuers evading US rules, Allaire was blunt: "It shouldn't be a free pass. Where you can just ignore US law and go do whatever the hell you want wherever and sell into the United States." Allaire's argument β€” that regulation and institutional adoption are converging β€” has proven prophetic.

This is not random criminal activity. It is structured, state-supported financial infrastructure designed to circumvent Western sanctions regimes. The FATF flagged persistent gaps in Travel Rule implementation in its June 2025 update β€” a direct reference to the fact that stablecoin transfers do not natively carry the originator and beneficiary information that sanctions screening requires. Regulators across all major jurisdictions have responded by making transaction monitoring and cross-border financial crime compliance their top enforcement priority.

πŸ“Š On-Chain Data Β· TRON USDT Volume Surge 2023–2025
TRON USDT Transfer Volume: Jan 2023 – Jan 2025 (in Trillions USD)
TRON hosts the majority of USDT used in high-risk and sanctions-related flows due to its near-zero fees. The chart shows a consistent 3x surge from $0.2T to over $0.6T in monthly volume β€” mirroring the 400% increase in sanctions-related crypto activity identified in the CertiK Skynet Report 09.
TRON USDT Transfer Volume: Jan 2023 – Jan 2025 (in Trillions USD)
Source: @chainsutra on Dune Analytics

From Voluntary Best Practice to Legal Requirement

One of the less-discussed but highly consequential findings in the CertiK report is the formalisation of smart contract security audits as a licensing and compliance requirement β€” not merely good practice. Seven major jurisdictions now impose statutory or quasi-statutory audit mandates: Hong Kong, UAE (VARA and ADGM), Singapore, the EU, Brazil, Turkey, and US state-level NYDFS.

The data behind this shift is sobering. CertiK's analysis of the top 100 exploited protocols found that 80% had never undergone a formal security audit before a breach occurred. Those unaudited protocols accounted for 89.2% of total value lost across all hacks. Furthermore, infrastructure compromises β€” private key theft, access control failures β€” drove 76% of 2025 losses by value, demonstrating that the threat landscape has moved beyond code exploits into operational and human attack vectors.

πŸ’¬ Richard Teng β€” CEO, Binance
Industry commentary Β· 2026 Β· On the value of regulatory compliance

"Regulations legitimise crypto, unlocking institutional trillions." Binance β€” which paid a record $4.3 billion DOJ/FinCEN settlement in November 2023 for AML failures β€” has since invested heavily in compliance infrastructure. Teng, who took over from founder CZ Zhao following the settlement, has repositioned Binance's brand entirely around regulatory engagement, a strategic acknowledgment that the old model of operating in grey zones is no longer viable.

Security audit landscape β€” key statistics from CertiK Skynet Report 09
80% of top 100 exploited protocols had no formal security audit before their breach.
89.2% of total value lost across hacks came from unaudited protocols.
76% of 2025 on-chain losses by value came from infrastructure compromises, not code bugs β€” private key theft and access control failures.
7 jurisdictions now mandate smart contract audits as statutory or quasi-statutory licensing conditions.
Trajectory: CertiK projects that rigorous security assessments will be a de facto prerequisite for market access across all major jurisdictions within two years.
πŸ“Š On-Chain Data Β· Crypto Hacks by Attack Type
Crypto Hack Incidents by Type of Vulnerability
Access Control failures dominate with 40+ incidents β€” confirming CertiK's finding that 76% of 2025 losses came from infrastructure and operational failures rather than code bugs. The tall central bar represents "Other" category incidents, while Contract Vulnerabilities and Flash Loan Attacks make up the remainder.
Crypto Hack Incidents by Type of Vulnerability
Source: @chainsutra on Dune Analytics

Basel 2026: The Institutional Divide

Running in parallel to the AML enforcement surge is a structural shift in how banks are permitted to hold cryptocurrency on their balance sheets. The Basel Committee on Banking Supervision's cryptoasset prudential standard took effect January 1, 2026 (subject to local adoption), and it creates what CertiK calls a "structural divide" in institutional adoption.

Under the framework, Group 2 assets β€” which includes Bitcoin and Ether β€” face near-100% capital charges. This makes them economically punishing for banks to hold on their balance sheets: a bank must hold approximately $1 of capital for every $1 of Bitcoin exposure. Group 1 assets β€” tokenised traditional instruments and qualifying stablecoins β€” receive standard risk weighting, making them far more capital-efficient. The practical implication is that regulated financial institutions will structurally favour compliant stablecoins and tokenised assets over unbacked crypto, accelerating the bifurcation of institutional and retail crypto markets.


How 11 Jurisdictions Are Responding

The CertiK report covers regulatory developments across eleven jurisdictions. The picture is one of rapid convergence on AML and compliance standards, even as the specific rules differ:

πŸ‡ΊπŸ‡Έ
United States
DOJ/FinCEN AML enforcement dominant. GENIUS Act brings stablecoins under BSA. SEC enforcement down 97% in value. Focus: transaction monitoring, SAR filing, licensing.
πŸ‡ͺπŸ‡Ί
European Union
MiCA fully operative. AML fines up 767%. ESMA oversight with fines up to 12.5% of annual turnover. Smart contract audits embedded in CASP licensing.
πŸ‡¬πŸ‡§
United Kingdom
FCA crypto framework advancing. Bank of England oversight for systemic stablecoins. DeFi platforms above Β£25M in assets face risk disclosure requirements.
πŸ‡­πŸ‡°
Hong Kong
Stablecoin Ordinance live Aug 2025. Smart contract audit mandates statutory. Seen as Asia's most complete framework β€” regional benchmark for competitors.
πŸ‡ΈπŸ‡¬
Singapore
MAS Framework 2.0 in 2026. Conservative reserve standards. Non-bank issuer supply capped. AML/CFT obligations clearly defined. Quasi-statutory audit mandates in place.
πŸ‡¦πŸ‡ͺ
UAE (VARA + ADGM)
VARA and ADGM both impose statutory smart contract audit mandates. Seen as a competitive hub attracting firms exiting less-regulated jurisdictions under compliance pressure.
πŸ‡―πŸ‡΅
Japan
FSA updates post-2025. Early mover on stablecoin licensing. Web3 business registrations mandated. Crypto in real estate transactions flagged as AML risk by four government agencies.
πŸ‡ΉπŸ‡·
Turkey
Capital Markets Board rules (Mar 2025) set minimum capital at TRY 150M for CASPs. TÜBİTAK technical audits are a precondition for licensing. Statutory audit mandates in place.

Five Implications for Compliance Teams and Crypto Businesses

Practical takeaways from CertiK Skynet Report 09
Multi-jurisdictional licensing is the new cost of entry. Operating from a single offshore licence is no longer viable for any institution that needs regulatory credibility with counterparties and supervisors. The report frames multi-jurisdictional licensing as a baseline operating cost, not an optional expansion strategy.
AML compliance has overtaken securities classification as the primary enforcement risk. Compliance teams must now prioritise transaction monitoring, sanctions screening, and SAR filing capabilities benchmarked against current DOJ and FinCEN standards β€” not token legal opinions.
Security audits are now effectively mandatory. For any protocol seeking listings on major centralised exchanges or access to institutional capital, recurring audits from recognised firms are a de facto prerequisite. The 89.2% statistic β€” unaudited protocols accounting for nearly all value lost β€” is the number that will be quoted in every board risk committee.
Smaller venues face existential compliance cost pressure. The report notes that "whether smaller venues can carry the same compliance load as the largest firms will shape the next phase of consolidation." Compliance costs are accelerating industry consolidation toward well-capitalised incumbents.
The next battle is DeFi. CertiK and the FATF both flag DeFi governance, privacy-enhancing technologies, and cross-border transactions as the emerging frontier of regulatory scrutiny. The current framework crackdown on centralised exchanges is the first wave β€” DeFi protocols are next.

The regulatory era of digital assets is no longer coming. It is here. CertiK's report lands not as a warning but as a post-mortem on the era of ambiguity. The firms that survived the SEC enforcement cycle largely did so by fighting classification battles β€” winning on securities law while operating with weak AML infrastructure. That arbitrage is closed. The DOJ, FinCEN, and their international counterparts have made clear: the compliance baseline in crypto is now the same as the compliance baseline in traditional finance. For those who built their businesses in the grey zone, the reckoning is overdue.

πŸ’¬ Jeremy Allaire β€” Named to TIME100 Most Influential People 2026
TIME Magazine Β· April 2026 Β· Profile citation

TIME wrote that Allaire "understood something most people in crypto missed β€” the internet didn't win because of any single application. It won because of open, interoperable infrastructure." His focus on "one-to-one backing, independent audits, and transparency" when others were chasing speculation is now the regulatory template every jurisdiction is codifying into law. The industry is catching up to where Circle was a decade ago.