For years, the defining regulatory threat for any crypto company operating in the United States was simple: don't let the SEC call your token a security. That classification battle consumed billions in legal fees, dominated compliance conversations, and ended careers. It was the war that defined an era. That era is over. According to CertiK's Skynet Intelligence Report 09 β "State of Digital Asset Regulations," published April 29, 2026 β Anti-Money Laundering enforcement has now overtaken securities classification as the primary regulatory kill-switch facing digital asset firms. The data behind this shift is not subtle. It is one of the sharpest enforcement pivots in the history of financial regulation.
The Report
What Is the CertiK Skynet Report 09?
CertiK is the world's largest Web3 security auditor, having secured over $600 billion in digital assets and worked with more than 5,000 enterprise clients including Binance, Ripple, and the Ethereum Foundation. Skynet Report 09 consolidates regulatory developments across the US, EU, UK, Hong Kong, Singapore, UAE, Japan, South Korea, Brazil, India, and Turkey. Its core conclusion: the industry has entered a "strong compliance era" where AML enforcement, mandatory security audits, and prudential capital standards define the risk landscape β not token classification battles.
Stefan Muehlbauer, CertiK's head of US government policy, put it plainly: "The era of ambiguity in digital-asset regulation is already over." The report covers not just enforcement trends, but stablecoin regulatory convergence, Basel Committee capital rules taking effect in 2026, and the growing mandatory nature of smart contract security audits across seven major jurisdictions.
"After more than a decade of uncertainty, this interpretation will provide market participants with a clear understanding of how the Commission treats crypto assets under federal securities laws. This is what regulatory agencies are supposed to do: draw clear lines in clear terms. It acknowledges what the former administration refused to recognise β that most crypto assets are not themselves securities."
Atkins' posture explains precisely why the SEC's enforcement numbers collapsed β it was a deliberate policy choice, not institutional weakness. The vacuum left by the SEC's retreat was filled immediately by the DOJ and FinCEN, who had no interest in scaling back.
Part I β The Enforcement Pivot
The Numbers: SEC vs AML β A 97% Collapse
The headline finding of the report is a dramatic reversal in enforcement priorities that unfolded across 2024 and 2025. The SEC, which had been the dominant regulatory force in crypto under Chair Gary Gensler, saw its crypto-specific enforcement activity collapse. Meanwhile, the Department of Justice and FinCEN stepped into the vacuum with a wave of AML and Bank Secrecy Act actions that dwarfed anything seen before.
| Agency / Metric | 2024 | 2025 | Change |
|---|---|---|---|
| SEC crypto penalty value | $4.9 billion | $142 million | β97% β |
| SEC crypto enforcement actions (volume) | 33 actions | 13 actions | β60% β |
| DOJ + FinCEN AML fines (H1 2025 only) | β | $900Mβ$1B+ | β New record |
| EU AML fines (YoY) | Baseline | +767% | +767% β |
| Sanctions-related crypto volume (YoY) | Baseline | +400% overall +694% state-driven |
β Explosive |
Sources: CertiK Skynet Report 09; SEC enforcement data; DOJ press releases; FinCEN enforcement actions.
Part II β The Landmark Cases
OKX, KuCoin, and the New Enforcement Playbook
Two settlements anchor the AML enforcement trend and define the new playbook regulators are using against crypto exchanges. Both cases involved exchanges that had served millions of users globally while operating without adequate anti-money laundering controls β or in some cases, without any US money transmission licence at all.
OKX pleaded guilty to operating an unlicensed money transmitting business. DOJ prosecutors cited more than $5 billion in suspicious transaction flows processed through the platform. The $504 million settlement is one of the largest AML penalties in crypto history. The case was built not on token classification but on failures of transaction monitoring, KYC, and licensing infrastructure β the operational backbone of AML compliance.
KuCoin's settlement covered similar Bank Secrecy Act failures. Its co-founders agreed to step down personally, and the exchange committed to exiting the US market for at least two years. The personal accountability dimension β founders stepping down as a settlement condition β signals a new prosecutorial appetite for individual liability, not just corporate fines.
"Transaction monitoring and licensing failures are now drawing penalties that rival or exceed many earlier crypto securities cases. The battlefield has moved from courtrooms arguing token classification to compliance operations rooms."
"Clear rules end uncertainty, but overreach could stifle startups. We'd rather see no bill than a bad bill." Armstrong has also been explicit that AML compliance is a commercial imperative: "Crypto is a technology update to the financial system β we want every bank, fintech company, and every payment company to be integrated." Coinbase itself paid a $100 million settlement to New York's DFS over compliance deficiencies in 2023, making it intimately familiar with the cost of AML failure.
These cases are not outliers. They are templates. European regulators applied parallel pressure over the same period, with AML fines in the EU surging 767% year-over-year. Asia-Pacific regulators increasingly favour licence revocations and business improvement orders over monetary penalties β a tool that can be more devastating than a fine because it shuts the business down entirely.
Part III β The Sanctions Dimension
Sanctions Volume Grew 400% β The Russia Factor
The CertiK report identifies a specific driver behind the surge in AML enforcement pressure: a dramatic increase in sanctions-related cryptocurrency activity, primarily driven by Russia-linked networks and state-aligned stablecoin infrastructure. Sanctions-related crypto volume grew over 400% year-over-year in 2025, with state-driven sanctions evasion volume up 694% over the same period.
"You've got to work with governments. That became a founding principle for the company β we're going to go in through the front door with policymakers and regulators." On the question of offshore issuers evading US rules, Allaire was blunt: "It shouldn't be a free pass. Where you can just ignore US law and go do whatever the hell you want wherever and sell into the United States." Allaire's argument β that regulation and institutional adoption are converging β has proven prophetic.
This is not random criminal activity. It is structured, state-supported financial infrastructure designed to circumvent Western sanctions regimes. The FATF flagged persistent gaps in Travel Rule implementation in its June 2025 update β a direct reference to the fact that stablecoin transfers do not natively carry the originator and beneficiary information that sanctions screening requires. Regulators across all major jurisdictions have responded by making transaction monitoring and cross-border financial crime compliance their top enforcement priority.
Part IV β Smart Contract Audits
From Voluntary Best Practice to Legal Requirement
One of the less-discussed but highly consequential findings in the CertiK report is the formalisation of smart contract security audits as a licensing and compliance requirement β not merely good practice. Seven major jurisdictions now impose statutory or quasi-statutory audit mandates: Hong Kong, UAE (VARA and ADGM), Singapore, the EU, Brazil, Turkey, and US state-level NYDFS.
The data behind this shift is sobering. CertiK's analysis of the top 100 exploited protocols found that 80% had never undergone a formal security audit before a breach occurred. Those unaudited protocols accounted for 89.2% of total value lost across all hacks. Furthermore, infrastructure compromises β private key theft, access control failures β drove 76% of 2025 losses by value, demonstrating that the threat landscape has moved beyond code exploits into operational and human attack vectors.
"Regulations legitimise crypto, unlocking institutional trillions." Binance β which paid a record $4.3 billion DOJ/FinCEN settlement in November 2023 for AML failures β has since invested heavily in compliance infrastructure. Teng, who took over from founder CZ Zhao following the settlement, has repositioned Binance's brand entirely around regulatory engagement, a strategic acknowledgment that the old model of operating in grey zones is no longer viable.
Part V β Basel & Capital Rules
Basel 2026: The Institutional Divide
Running in parallel to the AML enforcement surge is a structural shift in how banks are permitted to hold cryptocurrency on their balance sheets. The Basel Committee on Banking Supervision's cryptoasset prudential standard took effect January 1, 2026 (subject to local adoption), and it creates what CertiK calls a "structural divide" in institutional adoption.
Under the framework, Group 2 assets β which includes Bitcoin and Ether β face near-100% capital charges. This makes them economically punishing for banks to hold on their balance sheets: a bank must hold approximately $1 of capital for every $1 of Bitcoin exposure. Group 1 assets β tokenised traditional instruments and qualifying stablecoins β receive standard risk weighting, making them far more capital-efficient. The practical implication is that regulated financial institutions will structurally favour compliant stablecoins and tokenised assets over unbacked crypto, accelerating the bifurcation of institutional and retail crypto markets.
Part VI β Global Enforcement Map
How 11 Jurisdictions Are Responding
The CertiK report covers regulatory developments across eleven jurisdictions. The picture is one of rapid convergence on AML and compliance standards, even as the specific rules differ:
Part VII β What This Means
Five Implications for Compliance Teams and Crypto Businesses
The regulatory era of digital assets is no longer coming. It is here. CertiK's report lands not as a warning but as a post-mortem on the era of ambiguity. The firms that survived the SEC enforcement cycle largely did so by fighting classification battles β winning on securities law while operating with weak AML infrastructure. That arbitrage is closed. The DOJ, FinCEN, and their international counterparts have made clear: the compliance baseline in crypto is now the same as the compliance baseline in traditional finance. For those who built their businesses in the grey zone, the reckoning is overdue.
TIME wrote that Allaire "understood something most people in crypto missed β the internet didn't win because of any single application. It won because of open, interoperable infrastructure." His focus on "one-to-one backing, independent audits, and transparency" when others were chasing speculation is now the regulatory template every jurisdiction is codifying into law. The industry is catching up to where Circle was a decade ago.