At the time of this writing, bitcoin was $80,466 (12:17 a.m. ET, Sunday, September 20). Bitcoin moves several percent in the time it takes to write a paragraph, so treat every price here as stamped, not current.

By THE MAXIMALIST

I read the statute and the two rules that put it in place. Know Your Customer became mandatory on October 1, 2003. Here is why it was written, what it actually requires, and where the file goes when it gets out.

Opening an account in the United States has meant handing over a verified copy of who you are since October 1, 2003. That is the date the Treasury’s Customer Identification Program rule took mandatory effect (68 Fed. Reg. 25090, published May 9, 2003; effective June 9, 2003; compliance mandatory October 1, 2003). The rule exists because Congress ordered it in Section 326 of the USA PATRIOT Act, signed October 26, 2001, forty-five days after the towers came down.

Twenty-three years later, the file that rule made every bank build is the thing that gets handed to a stranger with the right-looking paperwork, and the thing a government can switch off without touching your keys. That is the story. Not a hack of the money. A working, legal system doing exactly what it was built to do, aimed the other way. If you hold bitcoin because you want to hold the thing and not a claim on it, this is the case study in why the account is the weak point and the coin is not.

1. Why it was written, and the date it became mandatory

Congress said why in the text. The relevant part of the PATRIOT Act is Title III, and its full name is the argument: the International Money Laundering Abatement and Anti-Terrorist Financing Act of 2001. Section 302 sets out the findings, and this is the one the whole architecture rests on:

❝

“money laundering, and the defects in financial transparency on which money launderers rely, are critical to the financing of global terrorism and the provision of funds for terrorist attacks”

USA PATRIOT Act, Title III, Sec. 302, finding (2)

And the purpose:

❝

“to increase the strength of United States measures to prevent, detect, and prosecute international money laundering and the financing of terrorism”

Sec. 302, purposes

Note the logic, because it is the load-bearing claim. Terrorists need money. Money moves through accounts. If nobody knows who owns an account, the money is invisible. Therefore: know who owns every account. The identity file is not a side effect of the law. It is the mechanism the law chose.

Section 326 did not ask nicely. It amended the money-laundering statute (31 U.S.C. 5318) to add a new subsection, and the language is an order to the Treasury:

❝

“The Secretary of the Treasury shall prescribe regulations setting forth the minimum standards for financial institutions and their customers regarding the identity of the customer that shall apply in connection with the opening of an account at a financial institution.”

31 U.S.C. 5318(l)(1)

The same section told banks to check new customers against a government list:

❝

“consulting lists of known or suspected terrorists or terrorist organizations provided to the financial institution by any government agency to determine whether a person seeking to open an account appears on any such list”

31 U.S.C. 5318(l)(2)(C)

Hold on a minute. That is the whole architecture in two sentences. Verify everyone at the door, and check everyone against a list the government hands you. The Treasury wrote the rule, and on October 1, 2003 it stopped being optional.

There was a financial-identity system in the United States before 9/11. The Bank Secrecy Act dates to 1970. But the requirement that every institution verify and record who you are, as a condition of having an account at all, is a post-9/11 invention with a hard start date and a stated purpose you can hold it to. Remember the purpose. We will come back to it.

2. What they must collect, and how it grew

The rule that took effect that day is now codified at 31 CFR 1020.220. I read it. A bank’s program must obtain, at a minimum, four things before it opens your account:

❝

“(1) Name; (2) Date of birth, for an individual; (3) Address; and (4) Identification number”

31 CFR 1020.220(a)(2)(i)(A)

Name, birthday, home address, tax or ID number, verified against a document. That is the floor, not the ceiling. In 2016 the Treasury added a second rule, the Customer Due Diligence rule (81 Fed. Reg. 29398, compliance date May 11, 2018), which reached past the account holder to the humans behind a company. It requires the bank to identify:

❝

“Each individual, if any, who, directly or indirectly... owns 25 percent or more of the equity interests of a legal entity customer”

31 CFR 1010.230(d)(1)

So the file grew from “the customer” to “the customer, plus anyone who owns a quarter of the customer, plus whoever runs it.” Each expansion arrived with a good reason. None of them ever shrank the file.

3. The reports pile up behind the counter

The account is the front door. Behind it, the same system generates a running record of what you do with your money. Banks file a Suspicious Activity Report when something trips a threshold, and they file a Currency Transaction Report on cash movements over a fixed line:

❝

“The $10,000 threshold, set in regulation by the Department of the Treasury in 1972, has not been adjusted for inflation.”

U.S. Government Accountability Office, GAO-25-106500, December 2024

The GAO put the 2023 inflation-adjusted equivalent of that 1972 line at about $72,880. The threshold has not moved. So a limit meant to catch large, unusual cash movements now catches ordinary ones, and the reporting climbs with it. FinCEN’s own count: roughly 4.8 million Suspicious Activity Reports were filed in fiscal 2025, against about 507,000 in 2003. That is close to a tenfold rise in one working lifetime of the rule.

The government also reaches into the file directly. Under Section 314(a) of the same PATRIOT Act, law enforcement can send a name through every institution at once. FinCEN’s fact sheet, last updated September 15, 2026, records 9,403 such requests processed to date. In fiscal 2025 alone, 1,065 requests covered 6,883 subjects, went out to 13,887 financial institutions, and came back with 64,259 positive matches. Read that again. One year, one program, and the file answered sixty-four thousand times.

❝

THE FINDING

The outputs of the system are all counts of activity. 4.8 million reports in a year. 9,403 information requests since 2001. 64,259 matches in fiscal 2025 alone. There is no published count of the thing the statute said it was for.

4. It came for bitcoin

None of this stopped at banks. On March 18, 2013, FinCEN said the rules already covered the on-ramp:

❝

“An administrator or exchanger is an MSB under FinCEN’s regulations, specifically, a money transmitter, unless a limitation to or exemption from the definition applies.”

FinCEN Guidance FIN-2013-G001

In plain words: if you run an exchange, you are a money transmitter, and the identity rules are yours too. A 2019 FinCEN guidance restated it for every business model anyone had invented since. Then the international body that writes the standards, the Financial Action Task Force, extended its “travel rule” to virtual-asset businesses in June 2019, at a threshold of USD/EUR 1,000. Above that line, an exchange must collect and pass along who sent and who received. This is not a proposal anymore. FATF’s own July 16, 2026 update:

❝

“83% of respondents (91 of 109 jurisdictions) have passed legislation implementing the Travel Rule.”

FATF, 7th Targeted Update, July 16, 2026

So the same file, with the same four fields, now sits at the edge of the bitcoin network in ninety-one countries. The one FinCEN rule that would have pushed identity collection onto self-custodied wallets, proposed in December 2020, covering transactions over $3,000, was never finalized. It is still sitting there, unwithdrawn.

5. The honeypot leaks

Here is where the promise meets the plumbing. A verified identity file, tied to a record of what you own, is the single most valuable thing a thief can take. And it leaves the building.

Ledger, the hardware-wallet maker, had its marketing database breached on June 25, 2020. When the full dump surfaced that December it held 1,075,382 email addresses and, worse, 272,853 buyers’ complete records: name, postal address, phone number. A device that exists to keep your coins offline had handed criminals a list of confirmed owners and their front doors. What followed was not abstract. Victims got emails threatening home invasion. In 2021, some received physically tampered “replacement” devices in the mail, built to steal the recovery phrase. The data was the weapon.

Coinbase filed the modern version with the SEC on May 15, 2025 (Form 8-K). Overseas support agents were bribed to pull customer data. What left included names, addresses, phone numbers, masked Social Security digits, masked bank numbers, images of government IDs, and account balances. The company was blunt about the bill:

❝

“$180 million to $400 million” in “remediation costs and voluntary customer reimbursements”

Coinbase Form 8-K, May 15, 2025

No passwords, no keys, no coins were taken. The identity file alone was worth up to four hundred million dollars in damage. That is the KYC dossier, exactly what the 2003 rule requires an exchange to hold, priced by the people who lost it.

The file does not even need a thief. When Celsius went bankrupt, a routine court filing in October 2022 put the names and full transaction histories of more than 600,000 customers into the public docket. Lawful process, no breach, and a KYC’d customer base was doxxed by the system working normally.

6. Frozen because it could be

A leak is the file used against you by a thief. A freeze is the file used against you by an owner of the switch.

The cleanest example on record is Canada. On February 14, 2022, the government invoked the Emergencies Act; the financial order followed the next day. Banks froze accounts with no court order. The tallies entered into the House of Commons committee record: the RCMP pointed to at least 257 accounts frozen, roughly $7.8 million in Canadian dollars, and 170 bitcoin wallet addresses passed to institutions. On January 23, 2024, the Federal Court ruled the invocation unreasonable, outside the law, and a breach of the Charter’s protections on expression and on unreasonable search and seizure. The freeze happened first. The ruling that it was unlawful came two years later, after the accounts had already been shut.

The pattern repeats at the protocol edge. In August 2022 the U.S. Treasury sanctioned the software tool Tornado Cash; in November 2024 a federal appeals court found the Treasury had exceeded its authority because immutable code is not “property,” and the tool was delisted in March 2025. And the enforcement machine is scaling: the Justice Department’s Scam Center Strike Force reported restraining about $52 million of virtual currency in a single day this month, bringing its running total to roughly $938 million. That $938 million is the cumulative figure, not one seizure, but the direction is the point.

The identity rail makes the money addressable. Once it is addressable, it can be turned off. Not by breaking anything. By using it.

What the coverage left out

KYC gets written about as plumbing. A compliance cost, a friction, a box you tick when you open an account, the reason onboarding takes three days. What almost never appears in the coverage is that it has a birthday, an author, and a stated purpose written into the statute.

That matters because a rule with a stated purpose can be measured against it. Title III said the point was to cut off terrorist financing. Twenty-three years on, the published outputs are volumes: 4.8 million reports a year, 9,403 information requests, 64,259 matches in one year. Those are counts of activity, not counts of outcome. I could not find a published figure for how many accounts the 2003 mandate kept out of the hands of terrorists. The number may exist. It is not where a citizen can read it.

Meanwhile the file it required is measurable in the other direction, because the people who lost it had to file the number with the SEC.

Critics will say

Critics will say KYC catches real criminals, that the reports and the freezes stop trafficking and terror financing, and that the Canadian and Tornado Cash reversals prove the courts still work. Fair enough, some of that is true, and the Strike Force numbers are real proceeds of real fraud. But “the courts fixed it two years later” is not a defense of a switch that can be flipped in a day; it is a description of the harm. And a database does not know the difference between a terrorist and a trucker. It only knows how to answer. The question was never whether the file can be aimed at bad people. It is who else can aim it, and how fast, and whether you find out before or after your account is closed.

The questions that remain

  1. Of the 9,403 Section 314(a) requests processed to date, how many were later found to be unfounded, and is any customer ever told their file was searched?

  2. Twenty-three years after the mandate, is there a published measure of how many accounts KYC has kept out of the hands of terrorists, weighed against the cost of the files it required everyone else to build?

  3. The $10,000 reporting line was set in 1972 and has never been adjusted. Is the current volume of reports evidence the system is working, or evidence the threshold is broken?

  4. When a regulated institution fails, as Celsius did, who owns the KYC file it was required to build, and what stops it entering a public docket?

  5. The December 2020 FinCEN proposal to extend identity collection to self-custodied wallets was never finalized and never withdrawn. Is it dead, or is it waiting?

❝

They wrote the rule to keep the wrong people out of the account. They built a file that lets the wrong people into yours. The coin they never touched is the only part of the story that stayed where you put it.

Maximalist.

Receipts

  • USA PATRIOT Act, Pub. L. 107-56, signed October 26, 2001; Title III findings and purposes at Sec. 302; Section 326 codified at 31 U.S.C. 5318(l): govinfo.gov and uscode.house.gov

  • CIP final rule, 68 Fed. Reg. 25090 (May 9, 2003); effective June 9, 2003; mandatory compliance October 1, 2003: federalregister.gov

  • CIP data minimums, 31 CFR 1020.220(a)(2)(i)(A): ecfr.gov

  • CDD beneficial-ownership rule, 81 Fed. Reg. 29398 (compliance May 11, 2018); 31 CFR 1010.230(d)(1): federalregister.gov

  • CTR threshold, GAO-25-106500 (December 2024): gao.gov

  • SAR volumes and 314(a) totals, FinCEN Year in Review FY2025 and 314(a) Fact Sheet (updated September 15, 2026): FinCEN Year in Review and 314(a) Fact Sheet

  • FinCEN virtual-currency guidance FIN-2013-G001: fincen.gov

  • FATF Travel Rule, 7th Targeted Update, July 16, 2026 (83%, 91 of 109): fatf-gafi.org

  • Ledger breach disclosure (June 25 and July 29, 2020; 272,853 records in the December dump): ledger.com

  • Coinbase Form 8-K, May 15, 2025 (“$180 million to $400 million”): sec.gov

  • Celsius customer records in the bankruptcy docket, October 2022: theregister.com

  • Canada Emergencies Act freezes; House of Commons FINA record; Federal Court ruling January 23, 2024: ourcommons.ca

  • Tornado Cash sanction (August 2022), Van Loon v. Treasury (November 26, 2024), delisting (March 21, 2025): paulhastings.com

  • DOJ Scam Center Strike Force, September 9, 2026 ($52M in a day, roughly $938M cumulative): justice.gov

Reporting note

Every statute and rule quoted here was read at the source this run. Nobody was asked for comment. The price stamp is Crypto.com Exchange BTC_USD last, 12:17 a.m. ET, Sunday, September 20, 2026.