Showing posts with label FinCEN. Show all posts
Showing posts with label FinCEN. Show all posts

Thursday, July 11, 2024

Your finances are being snooped on. Here's how


We all have a pretty good idea that our finances are being snooped on, but most of us aren't quite able to articulate how. We know that we're being snooped on by two groups, corporations and the government. This post will focus on how the government surveils our transactions, because democratic governments generally (but certainly not always!) tell us ahead of time what information they will gather, and how the data will be used.

Governments snoop on law abiding citizens' financial data for good reasons  they are trying to trace the money in order to catch bad guys. The government has been given the power to collect this information without having to ask a judge for approval, say by requesting a search warrant. 

I think there is a degree of acceptance among citizens that some amount of warrantless financial snooping is okay, because it reduces crime. But as the intensity of surveillance increases it eventually reaches creepy territory, at which point most of us would prefer the brakes be applied.

Where is this line? I'm a committed comparativist. To get a good sense of how one is snooped on, and whether it has passed over the line to being creepy, one needs a reference point. So in this blog post, I'll compare how two groups of citizens  Americans and Canadians are being surveiled by their respective governments, so that both groups can better understand, by reference to each other, where they stand.

The first section focuses on the inflows of personal financial data from citizens to the government. The second section will focus on the outflows of data from the government to law enforcement.

***How citizens' personal financial data flows into the government***

Both the U.S and Canadian governments collect large amounts of financial data about their citizens. They do so by requiring banks and other financial institutions to record information about their customers and submit reports to the government about their customers' transactions when certain triggers have been met.

First, let's touch on the total amount of data being hoovered up. On this count, Canada far exceeds the U.S. In the 2022-23 reporting period, Canadian financial institutions submitted a total of 36 million reports to the government containing information about Canadians' financial transactions. That's almost one report per Canadian every year. 

Meanwhile, U.S. institutions sent 27.5 million reports to their government about Americans' financial dealings in 2023, a rate of around 0.1 report for every American, which is ten-times less intensive than in Canada. So based purely on the quantity of data collected, Canada seems to be closer to the "it's getting uncomfortable" level than the U.S. (See table below).

What accounts for this big difference in reporting intensity? In short, it's due entirely to cross-border wire transfers. In Canada, every electronic fund transfer leaving or arriving in Canada must be reported by banks to the government if it sums up to $10,000 or more. So if you've sent an $11,500 wire transfer from your Bank of Montreal account to your son or daughter who lives in London or Paris, congratulations, your name is in a Canadian government database. Or if you run a business and have received a $15,000 digital payment from a U.S. company for services rendered, your corporate data is sitting somewhere in an Ottawa government server.

If you're an American making a foreign wire transfer, your information will not get sent to a government database. The U.S. authorities do not require financial institutions to submit personal information on digital cross-border flows. (Mind you, they have been trying for some time to get the ability to collect this data.)

In the 2022-23 financial year, 27 million of these cross-border wire reports were submitted by Canadian banks, accounting for the lion's share of all 36 million reports submitted to the Canadian government that year.

Apart from cross-border transaction reporting, the nature of Canadian and U.S. eavesdropping is broadly similar.

Let's start with cash transaction reports, or CTRs. When a Canadian goes to their bank and deposits $10,000 or more in cash, the bank will generate a report that it sends to the Canadian government. U.S. banks report deposits and withdrawals of $10,000 in cash to the US government.

So if you're selling a used car and the buyer pays you $12,000 in banknotes, and you deposit that to your bank account, you're now in a government database, whether that be in Canada or the U.S.

Canadian banks generated 8 million CTRs in 2022-23 whereas U.S. banks generated 20.8 million in 2023. Pound for pound, Canadian banks submit more cash transaction reports to their government than U.S. banks, around 0.21 per Canadian compared to 0.06 per American. I'm not sure why. The threshold for reporting a cash transaction in Canada is lower in the U.S. (CAD$10,000 is worth around US$7,300) which may explain some of the difference? Dunno.

With CTRs and cross-border wire transfers, the invasiveness is kept relatively low thanks to the objective criteria that triggers a filing. Exceed the $10,000 threshold and at least you know ahead of time that your information is going to be recorded. A law-abiding citizen who is uncomfortable having their finances being collected by the government can choose to avoid sending cross-border payments or dealing in large amounts of cash. But this objectivity doesn't exist with the next type of report: those related to suspicious activities. 

On both sides of the border, financial institutions must submit reports about transactions deemed suspicious to their respective governments. If you've made a transaction that a bank deems to be suspicious, you'll never know that you've landed in a government database. That's because banks are prohibited from notifying their customers that their activity has been snitched on.  

The determination of what qualifies as suspicious involves a fair amount of subjectivity. Canada requires that financial institutions have a reasonable grounds to suspect that a transactions is linked to terrorism or money laundering before reporting it. That means that mere hunch won't cut it  a Canadian banker must be able to articulate a clear reason for suspicion. Mind you, there's no penalty for banks that fail to attach a specific reason to a report, so the reasonable grounds to suspect standard is often ignored. 

We know that many of these hunch-based reports end up in the government's database. Over the years the Office of the Privacy Commissioner of Canada has collected a list of reports that failed to reach the reasonable grounds to suspect standard, including one case in which some individuals were suspected simply because they had Middle Eastern passports:

From the Office of the Privacy Commissioner's 2017 audit of FINTRAC [source]

My reading of the U.S. requirements for reporting a suspicious transaction suggest a looser standard than in Canada. While U.S. bankers are encouraged to provide a specific red flag in their CTRs, the implementing regulations say they can still file a report if they merely "suspect" a transaction to be associated with money laundering or terrorism, which is a lower standard then the requirement to have a "reason to suspect."

In Canada, there is no size threshold for suspicious activity reporting: even a $50 payment can be reported by a bank. By contrast, the U.S. has set a $5,000 threshold before a suspicious action report must be filed. (When suspicious activity reports were first introduced to the U.S. in 1994, the government floated the idea of not including a threshold at all, as Canada would later do in 2001, but retreated because this would impose a "burden of reporting.")

This difference in thresholds suggests Canada should have a much higher intensity of suspicious transaction reporting than the U.S. Not so. Canadian banks generated 560,858 suspicious transaction reports in 2022-23, around 1.4 reports for every 100 Canadians. Compare this to the 4.6 million reports filed by U.S. banks in 2023, which also comes out to 1.4 reports per 100 Americans. So even though bankers in the U.S. are required to ignore small suspicious transactions below $5,000, they more than make up for it by reporting a larger proportion of transactions than Canadian bankers do. I can only guess why, but this may be due to the looser standard for suspicion, discussed above.

There are several other types of transactions that must be reported to the government, including large virtual currency reports in Canada and foreign bank and financial accounts reports (FBAR) in the U.S., but the volume of this sort of reporting isn't as significant as the other types already discussed, so I won't touch on them.

So to briefly sum up, pound for pound a Canadian is more likely to appear in their government's financial database than an American is. This is because Canadian financial institutions collect personal information linked to cross-border wire transfers the U.S. doesn't. The most privacy-invasive reports are suspicious ones. Compared to Canadian banks, U.S. banks are more trigger-happy when it comes to deeming a given transaction as suspicious, but the US$5,000 floor on reporting suspicious transactions somewhat mitigates this eagerness. 

Having dealt with what sorts of data flow in to the government, let's talk about what happens next with the data.    

***How personal financial data flows from the government to law enforcement***

The personal financial data accumulated by the two governments are managed by each nation's respective financial intelligent unit, or FIU. In Canada, this institution is known as the Financial Transactions and Reports Analysis Centre of Canada, or FINTRAC. In the U.S., the body that collects personal financial data is known as the Financial Crime Enforcement Network, or FinCEN.

It's here with the management of harvested financial data that the policies of the two countries really start to diverge.

To begin with, let's start with the length of time that data can be kept. In the U.S., FinCEN holds data indefinitely, so its database is forever growing. Canada allows FINTRAC to keep data for at least ten years and up to fifteen years, but after that FINTRAC must destroy any identifying information if it was not disclosed to law enforcement. Since most of FINTRAC's data is not disclosed, that means large amounts of data fall out of FINTRAC's database every year, and thus the amount of personal information collected grows at a slower rate than FinCEN's data hoard.

The differences between the two countries grows even wider when it comes to the question of who has access to citizens' financial data. In brief, U.S. law enforcement is granted broad access to the raw data whereas Canadian law enforcement's ability to see the data is strictly limited.

472 different U.S. law enforcement agencies at the Federal, state, and local levels have the ability to directly query FinCEN's database of CTRs, suspicious activity reports, and more. This amounts to around 14,000 law enforcement officers who can search through the personal financial data of American citizens. In 2023, these 14,000 users conducted 2.3 million searches using FinCEN's query tool.

FinCEN's data can also be downloaded in bulk form to the in-house servers of eleven different federal agencies, including the FBI, ICE, and the IRS. Bulk access (also known as Agency Integrated Access) means that the FBI, ICE, IRS, and eight other agencies don't need to use FinCEN's query tool. This bulk data can be access by another 35,000 agents. Alas, FinCEN doesn't track how many in-house searches were conducted by these agents in 2023, but I'd guess it's in the tens if not hundreds of millions.

By contrast, Canadian law enforcement agencies do not get direct access to FINTRAC's financial data trove. Instead, FINTRAC employs an internal force of a few hundred data analysts to parse the database for clues that suggest participation in money laundering or terrorist financing. Only when FINTRAC employees have attained a reasonable grounds to suspect that a pattern of transactions has crossed the line can they pass a report on to a Canadian law enforcement body, such as the RCMP or municipal police. This report is known as a financial intelligence disclosure and includes information like the name of the transactor, their address, telephone number, criminal record, and more.

FINTRAC submitted 2,085 of these disclosures to law enforcement in 2022-2023.

So to step back for a moment, tens of thousands of U.S. law enforcement officials conduct tens of millions of searches through Americans' personal financial data to get leads. In Canada, this same database can only be accessed a small number of FinCEN FINTRAC analysts, who selectively push a few thousand reports out to Canadian law enforcement each year. 

That's quite the contrast. Put differently, unlike their U.S. equivalents the RCMP, Sûreté du Québec, Ontario Police Police, and other policy agencies do not have the power to pull personal financial data willy-nilly from the government's database. This means far fewer eyeballs on Canadian financial records. As far as protecting the financial privacy of citizens, the Canadian access model does a better job. The U.S. access model is friendlier to law enforcement and stopping crime.

A disadvantage (or advantage, depending on your tolerance for being watched) of the American system is it allows the 11 agencies with bulk access to create "data cocktails"  personal financial data downloaded from FinCEN spiked with their own data sources  in order to better investigate suspects. For instance, according to a 2009 report from the Government Accountability Office, the FBI incorporates bulk FinCEN suspicious activity reports into its Investigative Data Warehouse along with 50 other data sets from different sources. The IRS's Reveal System, portrayed below, ingests FinCEN reports along with tax data to conduct more complex investigations.

The IRS's Reveal System, which ingests FinCEN CTRs along with other non-FinCEN data [source]

I don't know if the FBI and IRS data cocktails still exist, and in what form, but they certainly give a flavor of what sorts of broad access law enforcement can get to personal financial records in the U.S.

By contrast, Canadian law doesn't allow for U.S.-style data cocktails. An agency like the RCMP can't mix FINTRAC's store of personal financial data with their own bespoke data sources because the RCMP is prohibited from pulling raw CTRs, cross-border wire transfer reports, and suspicious transaction reports out of FINTRAC. Only FINTRAC gets to determine what information gets pushed out to the RCMP.

This firewall isn't accidental. As Horst Intscher, a former director of FINTRAC explains, a degree of privacy protection was purposefully built into FINTRAC's original design: "Because of the very broad range of information that the [Proceeds of Crime (Money Laundering) and Terrorist Financing Act] makes it possible for us to receive from reporting entities, it was determined at the original passage of the legislation that protections had to be built, so it would not be construed that there was a flow-through of massive amounts of personal information directed to law enforcement agencies."

In other words, FINTRAC was designed to prevent the likes of the RCMP from creating an FBI-style Investigative Data Warehouse. 

However, the wall imposed between Canadian law enforcement and FINTRAC does have a degree of porosity, enough to provide law enforcement with an indirect way for pulling data out of FINTRAC. If the RCMP is investigating a suspected money launderer, it can submit information about the suspect to FINTRAC in the form of a voluntary information record. For example, it might say that "Joe Blow and his sister-in-law Martha are the subjects of an investigation for drug trafficking and money laundering, and we just thought you should know that." This new data becomes part of FINTRAC's database, against which FINTRAC's agents will check all other data. If the agents spot a match, and it meets the bar for a "reasonable grounds for suspicion", then they must send the RCMP a disclosure containing the relevant personal financial information.  

In 2022-23 FINTRAC received 2,550 voluntary information records from Canada’s law enforcement and national security agencies (including from members of the public), a large number of these eventually boomeranging back to law enforcement in the form of a disclosure. How many? The head of FINTRAC once claimed that "65% to 70%" of FINTRAC's ultimate disclosures to law enforcement are triggered by voluntary information submitted by law enforcement, which hints at how porous the wall is.

----

That sums up my comparison of the inflows and outflows of personal financial data to the U.S. and Canadian governments. This is just a cursory analysis. There are all sorts of other vectors across which to compare the scope of the two nations' data collection efforts that I haven't explored. I've focused on the factors that I think are the most important.

Readers from other countries may be curious to find out about their own FIUs to determine where they stand relative to Canada and the U.S. If so, leave your findings in the comments. My Australian readers, for instance, may be interested to note that their government collects far more private information than the U.S. and Canada combined. AUSTRAC, the Australian FIU, collected 192 million transaction reports in 2023, an astonishing 7 reports per Australian!  This is because AUSTRAC receives information on all cross-border wires, with no lower threshold.

At the outset of this article I suggested that many of us would tolerate some loss of privacy in order to make it easier for the police to catch criminals. A few of us will accept a large loss. Others will not tolerate even the smallest infringement on privacy. An individual's line in the sand is very much a personal matter. I'm going to leave it to the reader to decide which country (if either) approaches the right balance. Is Canada too lax relative to the U.S.? Does the firewall we've erected between the cops and the trove of financial information give criminals free rein? Or does the U.S. not sufficiently respect privacy? Should the FBI and its sister agencies lose some of their unfettered access to Americans' personal financial data?

Friday, December 1, 2023

Even crypto mixing deserves a threshold

Many of you may not realize this, but in most parts of the developed world, banks automatically record and report our transactions to law enforcement. The logic behind this is that by giving up our personal data, we get more security, albeit at the cost of 1) losing our privacy, and 2) adding an extra layer of costly red tape into financial life.

It's a pragmatic compromise, and one hopes that the benefits outweigh the costs. The way that we've been balancing this compromise up till now is by using thresholds, so as to reduce the cost side of the equation. Below a certain dollar threshold (i.e. $10,000 for cash), transactions don't get reported. The folks making these sub-threshold transactions thus enjoy the dignity of not having their privacy invaded, nor do they add to the financial sector's administrative burden. However, they also don't contribute to the effort to improve security and safety.

Anyways, last month, the U.S. government announced a new anti-money laundering reporting requirement, one for crypto mixing. In doing so it broke with a long tradition of not including a threshold. That got my hackles up. Thresholds have always been key to balancing the costs and benefits of automatic reporting requirements.

In short, the government thinks that mixing of cryptocurrency is of primary money laundering concern. Any U.S. financial institution that knows, suspects, or has reason to suspect that a customer's incoming or outgoing crypto transaction, in any amount, involves the use of a mixer will have to flag it and send a report to the government. That report must include information like the customer's name, date of birth, address, and tax ID. 

I submitted the following comment on the proposed rule for crypto mixing. If you agree, feel free to copy it and add your own comment to the growing pile. 

Dear sir/madam,

Re: Proposal of Special Measure Regarding Convertible Virtual Currency Mixing, as a Class of Transactions of Primary Money Laundering Concern

Historically, all U.S. anti-money laundering recordkeeping and reporting requirements have been accompanied by a monetary threshold. The current proposal to impose recordkeeping and reporting requirements for crypto mixing is the sole exception. This should be fixed.

When Treasury Secretary Henry Morgenthau published an executive order to implement the U.S.'s first large cash transaction reporting regime all the way back in 1945, for instance, he established a $1,000 reporting requirement for transactions in which only bills in denominations over $50 were present. He also set a $10,000 reporting threshold when small and large denomination bills were involved in the transaction.

Morgenthau's thresholds remained in place through the 1950s and 1960s. They were eventually ratified in 1972 with the implementation of a $10,000 cash reporting threshold for the purposes of implementing the Bank Secrecy Act.

When suspicious activity reports were introduced in 1996, the government's initial proposal did not include a reporting threshold. But after receiving public comments, the government admitted that its first version of the rule would impose a "burden of reporting." In its final version it introduced a $5,000 threshold for filing a suspicious activity report, which remains to this day.

In addition to reporting thresholds for cash transactions and suspicious activity, the government has set a number of thresholds for recordkeeping requirements. For instance, financial institutions are required to keep a log of all cash purchases of monetary instruments between $3,000 and $10,000.

The government's long history of twinning reporting and recordkeeping requirements with thresholds is a pragmatic compromise. It balances law enforcement's need for information against the administrative burden imposed on the private sector as well the invasion of privacy imposed on civil society. It only seems fair and prudent to extend this pragmatic compromise to cryptocurrency mixing recordkeeping and reporting requirements, especially in light of the fact that, as FinCEN admits, there are "legitimate purposes" for mixing.

I would suggest a threshold of at least $10,000, which is in-line with the cash transaction reporting threshold.

Sincerely,
JP Koning
Moneyness Blog

Tuesday, September 26, 2023

Thoughts on Privacy Pools and the law


Here's my quick first-pass take on Privacy Pools, the heir apparent to privacy tool Tornado Cash. My comments are on the legal side, and less so the technical side, although the two aren't mutually exclusive. 

I've already written a bunch of times about Tornado Cash on this blog. Financial privacy is an important topic. 

The quick story is that after attracting a few billion in criminal funds, the Tornado Cash "stack" was sanctioned by the Office of Foreign Assets Control (or OFAC, the U.S.'s sanctioning authority). Privacy Pools is the Ethereum community's attempt to offer up an olive branch to OFAC. "We know you didn't like the last attempt, but we're going to make some changes. What do you think?"

I'm fascinated with the Privacy Pools idea, which will allow users to pick and choose who they associate with, thus excluding potentially bad actors. With fewer bad actors, OFAC may be less hasty to sanction the tool. 

While in theory that sounds great, here's my worry. Privacy Pools still relies on an old Tornado Cash feature: relayers. (For this observation, I'm indebted to Jon Reiter, who wrote a useful article on Privacy Pools for Blockhead.) It also relies on a new type of third-party: association set providers or ASPs.

Relayers and association set providers are a problem, as I'll show below. And the reason has nothing to do with OFAC or sanctions law, but a set of Federal statutes against racketeering found in Chapter 95 of the U.S. criminal code.

Let's assume that Privacy Pools gets deployed and begins to successfully screen out bad actors. That'll make it an even more tempting target for dirty money seeking redemption, bad actors devoting ever more resources to sneak into the mix. Inevitably, some of them will get through and when they do, the authorities will have to find an actor in the Privacy Pools stack to blame. I suspect they'll target relayers and ASPs.

Let's start with relayers. It's likely that the authorities can show that relayers are engaged in an activity defined under a key section of U.S. racketeering law, § 1960, as "money transmission." To avoid breaking this law, relayers will need to register with the Financial Crimes Enforcement Network, or FinCEN, the U.S. government's money laundering watchdog. Registration will obligate relayers to set up an iron-clad customer identification program, which involves collecting and verifying user ID cards, as well as filing Suspicious Activity Reports (SARs) with FinCEN, thus undoing much of Privacy Pools' stated benefits.

Let's back up a sec. Who are relayers?

Doing stuff on the Ethereum blockchain requires paying a small processing fee, and these fees are visible to everyone. When a privacy seeker withdraws from Privacy Pools or Tornado Cash, this fee payment effectively reveals who the user is. To solve this problem, both systems rely on a group of third-party individuals or entities relayers to pay this fee on behalf of users, thus restoring privacy, an effort they are remunerated for. But this sounds to me like "transferring funds on behalf of the public," which is Chapter 95's definition of money transmission, which leads me to suspect that relayers can be drawn into said law's licensing and registration requirements.*

Now, I'm just a maritime lawyer, so if I suspect that relayers are money transmitters, who really cares, right? But it's not just me who is making this claim. In its recent indictment of individuals involved in the Tornado Cash stack, the Department of Justice named relayers as engaging in money transmission.

Let's move on to ASPs. With Privacy Pools, users can build unique association sets that allow them to dissociate from potential bad actors. In a recent paper, the Privacy Pools designers suggest that in practice, professional intermediaries – association set providers will emerge to set up and curate these sets. Users will in turn subscribe to whatever ASP-provided sets meet their needs.

It's inevitable that ASPs will make mistakes and let bad actors into their sets, resulting in illicit money being laundered through Privacy Pools. In response, the authorities may try to follow the same script they used for relayers and accuse a faulty ASP of being an unlicensed money transmitter. But that may not stick; unlike a relayer, an ASP doesn't actually transfer any money. The Department of Justice has more up its sleeve than that, though. They can charge faulty ASPs with breaking other laws in Chapter 95, specifically the money laundering statutes §1956 and 1957.

To avoid a potential money laundering indictment, the intermediaries that curate association sets will have to make a good faith effort to exclude bad actors. Simple blacklists derived from chain tracing tools provided by companies like Chainalysis probably won't cut it. ASPs will have to undertake the same level of customer due diligence as banks and other financial institution. That means painstakingly collecting ID, doing background checks, and more. As before, that may unravel some of the purported anonymity of the Privacy Pools system.

The fact that relayers and ASPs may face FinCEN registration requirements and/or other anti-money laundering obligations isn't necessarily a death knell for projects like Privacy Pools, but it may pose some challenges.

1) Relayers and ASPs may try to sidestep U.S. law by operating outside the U.S. and, if possible, set up their operations to exclude Americans. That means cutting off a big chunk of the world from using the tool. With fewer users, the ability of Privacy Pools to obfuscate the tracks of all its non-U.S. users will be limited.

2) Some relayers and ASPs may choose to accept American customers in a compliant way. They'll verify their users, submit reports to FinCEN, and more. But at that point an American will probably be roughly indifferent between getting privacy from Privacy Pools or Coinbase, a centralized exchange that already complies with the requirements. Any U.S. user who becomes a customer of Coinbase can deposit ether and withdraw it to a new address, thus removing the outside world's ability to track the transaction, albeit at the expense of disclosing their personal information to Coinbase. Privacy Pools would afford this same level of privacy. It would offer U.S. users privacy from the broader community, but not from the employees of a relayer or ASP.**

If Privacy Pools is only providing Coinbase-levels of privacy to Americans, what's the point?

3) Lastly, perhaps the developers can figure out now  before Privacy Pools is even deployed  how to do away with relayers while still preserving privacy, thus entirely bypassing Federal racketeering law's definition of money transmission. Or maybe they can figure out how to design the relaying system such that it falls out of the definition. 

Whether that's even possible is a technical issue that goes waaay beyond my abilities.


* Why can't other elements of the Privacy Pools stack, including the core smart contracts and the people who develop them, be pulled into being defined as money transmitters? My assumption in this post is that if the smart contracts are: 1) non-upgradeable, that is, they are set in stone from the moment they are published, 2) the developer no longer has any association with the "stack" after publishing the contracts; 3) the system is not governed by a DAO; 4) there is no stream of profits thrown off by the system; and 4) there is no token (as was the case with Tornado Cash's TORN), then it is probably less likely that the smart contracts and/or their designers would fall under the definition of a money transmitter. But I could be wrong.

** Mind you, Coinbase and a fully-compliant Privacy Pools wouldn't be perfect substitutes. Whereas Coinbase takes ownership of one's ether, thus subjecting privacy seekers to the risk of Coinbase going bankrupt, Privacy Pools is just a smart contract, and not subject to that same risk. For a sub-group of privacy seekers who worry about Coinbase going bust, FinCEN-compliant relayers and ASPs may be strictly superior to Coinbase.  

Friday, August 6, 2021

Stablecoin regulatory strategies

Critics of stablecoins often describe them as unregulated. But that's not accurate.

Over the last few months I've been familiarizing myself with the various financial regulatory strategies stablecoin issuers have been adopting. I thought I'd share my findings in a blog post. Perhaps journalists, investors, and others will find this information useful. (For those not interested in stablecoins, I apologize. This will mostly be gobbledygook to you.) I'll most definitely make a few mistakes in this post, so readers: do not hesitate to provide feedback in the comments section.

I tweeted out the short version of this post last month:

As you can see I've isolated four regulatory strategies that the major U.S. dollar stablecoin issuers have adopted. In this post I'll provide some details on each strategy.

My guess is that when people criticize stablecoins for being unregulated, they have the fourth strategy in mind: stay offshore. But they are ignoring or unaware of the other three.

A few caveats before starting. I'm only going to deal with U.S. dollar stablecoins in this post. Which means I'm ruling out euro-based stablecoins that operate within the EU's e-money regulatory framework. But there aren't really any big non-U.S. dollar stablecoins, so focusing on U.S. stablecoins covers most of the market.

Second, I won't be talking about Dai, Terra USD, Frax or any of the more exotic decentralized stablecoins. I'm sticking to centralized stablecoins: Tether, USD Coin, Gemini Dollar, HUSD, Binance USD, Paxos Standard, and TrueUSD. By centralized, I mean that the stablecoin's backing assets are compromised of traditional assets like Treasury bills, commercial paper, or deposit accounts held at a bank. Redemption or creation of new stablecoin tokens occurs via underlying bank infrastructure.

Lastly, this post doesn't address so-called "FinCEN regulation." Stablecoins will sometimes market themselves as being regulated by the Financial Crimes Enforcement Network, a department of the US Treasury that oversees America's anti-money laundering regulations. In the tweet below, a Tether executive makes this claim:

However, this is mis-marketing. When stablecoins interface with FinCEN, they are best described as being registered with FinCEN, not regulated by FinCEN.

Further more, FinCEN registration doesn't qualify as operating under a financial regulatory framework. A financial regulatory framework sets out the rules an issuer has to follow in order to ensure that the product is safe for consumers. It is at this level that fraudsters are caught and poorly designed stablecoins pre-empted. A financial regulatory framework may also address issues like overall stability of the financial system. For its part, FinCEN has nothing to do with financial regulation. It is a money laundering watch dog.

So let's start.  

1. The New York DFS model


The first stablecoin regulatory model is the New York Department of Financial Services (NYDFS) model. The NYDFS regulates money transmitters, trust companies, and banks that do business in the state of New York.

The NYDFS has created an explicit framework for regulating stablecoin issuers. Two issuers currently conform to this model, Paxos Trust and Gemini Trust. Paxos issues its own Paxos Standard stablecoin. It also manages Binance USD (BUSD) on behalf of Binance, a large offshore cryptocurrency exchange. For its part, Gemini Trust issues the Gemini Dollar stablecoin.

Under the NYDFS model, a would-be stablecoin issuer first secures a limited-purpose trust company charter from the NYDFS. This means that it must comply with the NYDFS rules concerning trusts and submit to ongoing oversight.

Once chartered as a trust, the institution can then seek additional NYDFS approval to issue a "price-stable cryptocurrency – commonly known as 'stablecoin'– pegged to the U. S. dollar." The NYDFS says that its approvals for individual stablecoins are based on "stringent requirements for these products," and follow a "comprehensive and rigourous review." Post approval, the stablecoins are subject to continuing "examination and inspection" by DFS examiners.

2. The Nevada Trust model  

The second regulatory framework I have encountered is the Nevada trust model. There are two stablecoins that have chosen to use Nevada as their regulatory jurisdiction: HUSD and TrueUSD.

Let's deal with each stablecoin separately, because they use slightly different versions of the Nevada trust model.

Huobi Technology Holdings, the company that owns both the HUSD stablecoin and the Huobi cryptocurrency exchange, also owns a trust company, Huobi Trust Company. This trust company has been chartered by the Nevada Department of Business and Industry, or DBI. The Nevada DBI is Nevada's counterpart to New York's DFS.

The second stablecoin operating under the Nevada model is TrueUSD. TrueUSD has adopted a rent-a-charter, or multi-layered regulatory model. The TrueUSD stablecoin itself is owned by Techteryx, a Chinese company. But this isn't the layer at which the financial regulatory framework is applied; that occurs several steps removed.

Tecteryx has hired another company, TrustToken, to manage the stablecoin. TrustToken has in turn hired a third company, Prime Trust, a Nevada DBI chartered trust to manage the stablecoin's finances. Prime Trust acts as the regulated container for TrueUSD.

Prime Trust and Huobi Trust are regularly examined by the Nevada DBI to make sure that they are in compliance with Nevada's rules and regulations surrounding trusts.

What makes the Nevada model different from the New York model is that the NYDFS has explicitly acknowledged that New York trust companies can engage in stablecoin-related business. The NYDFS has a process in place to approve the stablecoins themselves, and provides continual inspections of these stablecoins.

The Nevada DBI has not explicitly acknowledged that trusts may (or may not) engage with stablecoin issuers. Unlike the NYDFS, the DBI has not explicitly familiarized itself with stablecoins, and has not set up additional procedures in place to regulate trusts that are engaged in stablecoin business.

For consumers and investors, it may be preferable to own stablecoins that have received explicit regulatory approval.

You'll notice that both the New York and Nevada models are based on trust companies. A trust company is what is known as a fiduciary. That is, it has a legal obligation to place customers' interests above the company's own interests.

The fiduciary nature of the relationship between stablecoin customer and stablecoin issuer is important. When Gemini Trust, Paxos Trust, Prime Trust, or Huobi Trust take in customer funds, their duty as fiduciaries prevents them (in theory) from investing this money in risky high-yielding investments. Were they to do so, they would be breaking their fiduciary duty to end users, the stablecoin owners, and could lose their charter.

The trust structure also protects customer funds in the case that the parent company, which owns the stablecoin, goes bankrupt. That is, if Binance or Tecteryx were to go bankrupt, BUSD or TrueUSD stablecoin owners needn't worry about fighting with other creditors for a piece of the company's resources. Their funds are protected at the trust company level.

3. The dozens of money transmitter licenses model

The only stablecoin that has adopted the dozens of money transmitter licenses regulatory model is the world's second largest stablecoin, USD Coin, issued by Circle. This is the same model that is used by well-known non-bank payments companies such as Square, PayPal, Skrill, Payoneer, Transferwise, Western Union, and Moneygram.

To operate under this model, an issuer gets a money transmitter license from each and every state that requires firms that engage in the business of money transmittal to be licensed. Montana is one of the states that lets money transmitters operate without a license. A few states such as Wyoming have exceptions for firms involved in crypto.

For its part, Circle has obtained 44 money transmittal licenses.

State licensing boards impose audit requirements on money transmitters and conduct examinations. Each state sets its own unique requirements, too. These include what sorts of investments money transmitters are permitted to make, capital requirements, and the size of the surety bond they are required to post. Some states are lenient, others are strict. (Dan Awrey has a good paper on the state-by-state requirements.) 

But in general, my understanding is that the requirements placed by states on money transmitters are not as demanding as those that they impose on trust companies and banks. So pound for pound, a dollar issued under the NYDFS or Nevada trust model will have more oversight than a dollar issued under the dozens of money transmitter licenses model.

That's not the only advantage of the trust model relative to the dozens of money transmitter licenses model.

Circle is not regulated as a trust company, and thus it doesn't have a fiduciary obligation to its customers. That is, the funds Circle receives to back its stablecoins can be invested in such a way that may be good for Circle's investors and not necessarily good for Circle's customers. By contrast, issuers operating under either the New York or Nevada trust models are fiduciaries and must prioritize the customer's financial interests. Presumably that means that trusts can't put stablecoin customers' money in unsegregated accounts or risky instruments – but Circle can.

In addition, if Circle were to go bankrupt it's not apparent whether USD Coin holders would have better rights to Circle's remaining resources than other unsecured creditors. At least with the trust company model, stablecoin customers are insulated from the bankruptcy of the parent.

So from a customer's perspective, you are probably better off owning a stablecoin operating under either the NYDFS or Nevada model, rather than the dozens of money transmitter licenses model. Not only do the NYDFS or Nevada model have more oversight (because trusts generally face more oversight than money transmitters), but they are legally obligated as fiduciaries to keep the interests of their customers first and foremost. And the trust model probably provides better protection in the event of bankruptcy.

There is another difference between the NYDFS model and the dozens of money transmitter licenses model. Money transmitter licenses are generic. That is, they are a regulatory umbrella for a variety of very different businesses models, including remittance companies like Western Union, wallets like PayPal or Skrill, and finally stablecoins like USD Coin.

Compare this to the NYDFS model, which explicitly recognizes stablecoins and has created a specific process for authorizing and examining these products. (Nevada has not. The Nevada model is also a generic one). If I owned a bunch of stablecoins, I'd probably prefer if the regulator of these products had acknowledged them.

One last difference worth noting is that USD Coin must get 44 money transmitter licenses to operate across the U.S., but stablecoins operating under the Nevada and New York trust models seem to only need that one charter. Why is that?

A state chartered trust is typically exempt from having to get a money transmitters license in its home state. Depending on the circumstances, they may also be able to do business in other states without having to be independently chartered or licensed as a trust and/or money transmitter in those states. This seems to depend on whether the trust's home state has negotiated a reciprocity agreement with other states. Alas, I don't have a list of these agreements.

In any case, because trust company charters have a degree of portability, a single trust company charter seems capable of doing the work of 44 money transmitter licenses.

4. Stay offshore

The largest of the stablecoins, Tether, has adopted the last regulatory strategy: stay offshore. That is, Tether operates from the Cayman British Virgin Islands where it issues a U.S. dollar stablecoin. Tether's Cayman's-based Bahamas-based bank, Deltec, manages Tether's banking needs. And thus Tether avoids the necessity of setting up a New York or Nevada trust, or acquiring 44 money transmitter licenses.

The drawback of this structure is that that Tether can't operate in the U.S. Tether's terms of service prohibits "U.S. persons" from using the product.

Conclusion

In sum, those are the four regulatory strategies I've seen stablecoins pursue. Whereas stablecoins are often criticized for being unregulated, I think my post suggests the opposite. Yes, Tether can be criticized as such. But the New York and Nevada trust company models stand out for providing a significant amount of safety to stablecoin consumers, the NYDFS's approach particularly so because it has explicitly named and recognized stablecoins as products.

If you have comments or criticisms, do share them in the comments section of this post.

Postscript:

You'll notice that the first three strategies all operate at the state level. That is, the financial regulatory framework under which the major stablecoins are currently operating is governed by state licensing boards, and not at the national level by Federal banking regulators.

Might stablecoins eventually jump from a state-by-state framework to the national one?

One of the major financial banking regulators, the Office of the Comptroller of the Currency (OCC), has suggested that Federal financial institutions can support stablecoin transactions, but only if they involve "hosted wallets." A hosted wallet is a digital account hosted by a third-party financial institution. An unhosted one is controlled by the consumer.

But all of the big stablecoins I've mentioned in my blog post allow oodles of unhosted activity, so I suspect that Federal banks regulated by the OCC can't do business with them. Paxos, for instance, has recently secured a national trust bank charter from the OCC. But it appears that Paxos won't be using this national charter as the regulatory home for either the Paxos Standard and Binance USD stablecoins. Its NYDFS-chartered trust company will continue to be the regulatory anchor for its two stablecoin products.

Friday, June 11, 2021

Why do ransomware gangs like bitcoin? It's the censorship resistance

A new type of crime has recently emerged: big-ticket repeatable ransomware. Bitcoin is the chosen payments method for ransomware gangs. But these gangs don't use bitcoin because it is anonymous. They've chosen it because it is censorship-resistant.

Here's a quick illustration of how ransomware works. A university's servers are encrypted by a ransomware operator. Common victims also include corporations, hospitals, or police departments. Only a payment of, say, $1.14 million in bitcoins will release them (see below). The gang may up the ante by threatening to auction off the institution's data if a ransom isn't paid.

Ransomware isn't new. What is new and unique about the recent spate of ransom attacks is that they are:
 
big-ticket
factory-scale

That is, the average size of these attacks registers around $170,000, according to Sophos. Prior bouts of ransomware involved much smaller amounts. Secondly, these aren't isolated one-off attacks. They are manufactured at industry-scale with gangs like Ryuk or REvil carrying out dozens of attacks each day.

What makes bitcoin such a great tool for carrying out big-ticket repeatable attacks?

It's not the anonymity. A lot of people think that bitcoin is anonymous it's actually pseudonymous. All bitcoin transfers can be seen on the blockchain, or Bitcoin's public ledger. This is inconvenient for ransomware gangs because a ransom can be tracked from the original victim to its final destination. While it's possible to use a tool called a mixer to obfuscate one's bitcoin transactions, most ransomware gangs don't bother. Nor do gangs use cryptocurrencies that provide native anonymity, like Monero.

All of this points to the fact that anonymity is not really important to Ryuk, REvil, and other ransomware operators.

So what is it about Bitcoin that is attractive to these gangs? The feature they are after is something called censorship resistance. That is, Bitcoin allows value to be electronically transferred across vast distances without being halted or frozen. A ransomware gang can extort $1.14 from a victim in a country like the U.S. with strong law enforcement and repatriate it to a country with weak law enforcement like Russia, and then sell it for hard cash all without having to worry about a bank or the FBI freezing their funds somewhere in-between.

Bitcoin isn't the only censorship resistant payment network.

You wouldn't think it, but gift cards like iTunes and Google Play cards are (semi) censorship resistant payments networks, and it is for this reason that they've become popular with criminals. Scammers in call centres located in India frighten their U.S. victims with the fake threat of being apprehended by IRS agents, then tell the victim send a $500 gift card number by text in order to be exonerated. The gang will either resell the card number for cash or spend the balances in an app that they control. Gift card issuers don't have effective measures to freeze balances, so the bad guys can more-or-less use gift card networks with impunity.

So why are today's ransomware gangs using bitcoin instead of gift cards to extort money from the likes of the University of California San Francisco?

At the outset of this post I specified that one of the unique features of modern ransomware is that it is big ticket. A gang that wants to extort a victim for $1.14 million can't do so using gift cards. The maximum gift card size is $500. University of California San Francisco would have to buy 2,500 cards and send the attacker all the card numbers. And then the gang would have to launder all those cards. It's just too inconvenient. 

No, some other payment rail is necessary to do big ticket ransoms. Bitcoin is perfect for this there is no limit on transfer size.

What about carrying out big ticket ransom attacks via wire transfers? A wire transfer is an electronic payment from one bank account to another, often overseas.

Wire transfers are ideal for big ticket payments, but they aren't censorship resistant. Banks require identification and can freeze suspicious transfers. Our ransomware gang might be able work around this by setting up a network of money mules and accounts using fake ID in a foreign jurisdiction with weak law enforcement. They could then order a victim such as the University of California San Francisco to wire $1.14 million to the gang's foreign bank account. If the $10 million successfully arrives without being frozen, the gang  quickly withdraws the funds as cash before an injunction arrives.

But remember, the second key feature of modern day ransomware is that these gangs are carrying out multiple attacks each day. Setting up fake accounts at various foreign banks in order to receive wire transfers requires a lot of effort. Once one account has been used, it is compromised forever. By contrast, using the Bitcoin network over and over is a cinch. 

In short, wire transfers don't scale. Only Bitcoin allows for the mass production of ransom payments.

So now we know why ransomware gangs like to use Bitcoin. It's not the anonymity. Rather, Bitcoin opens up the field to big-ticket repeatable censorship-resistant payments. 

The next question we may want to ask ourselves is this: should we try and modify the Bitcoin payment network to stop these attacks?

We have a long history of making changes to payments systems that have become popular with criminals. When electronic gold issuer E-Gold became a tool for carders, it had to introduce a customer identification program. Western Union became a haven for “wire money to get me out of jail!” scams. It was fined and introduced much stricter know-your-customer rules. In the early 2010s Green Dot's MoneyPak became a popular network for FBI scams. Green Dot shut MoneyPak down for a year and rebuilt it from scratch to make it much harder for scammers to penetrate.

Bitcoin can't be modified, though. It is censorship-resistant. Which means we need other responses.

One possibility is to ban cryptocurrency. But as I wrote in a recent article for the Sound Money Project, I'm not a big fan of that solution. It seems like overkill. Rather, I suggested putting an embargo on the ransom payments themselves in order to cut off ransomware gangs' revenue. (I also fleshed this idea in an article for Coindesk in 2020.)

Here's another option. The U.S. government could make it difficult for ransomware operators by dusting off Section 311 of the USA Patriot Act. Let me explain how this would work.

A big chunk of the ransom payments that gangs like REvil collect are routed to cryptocurrency exchanges in jurisdictions with minimal anti-money laundering controls. The bitcoins then get converted into cash. Without these liquid offshore exchanges, it would be difficult for ransomware operators to launder their funds into spendable cash.

According to cryptocurrency analysis firm Chainalysis, one large Russian cryptocurrency took in nearly 44% of all ransomware funds sent to exchanges in 2019. (Chainalysis refused to name names). More recently, I stumbled on the following anecdote. It shows how a certain Russian exchange (perhaps the same one that Chainalysis mentions?) converts incoming bitcoin ransomware directly to U.S. dollar banknotes.

Now, without rogue exchanges such as the one above it would be difficult for ransomware operators to engage in business. But these exchanges are usually located outside of U.S. jurisdiction, so there seems to be little that the U.S. can be done about it.

This is where Section 311 comes in.

Section 311 allows the the Financial Crimes Enforcement Network (FinCEN), an arm of the U.S. Treasury, to designate any foreign based financial institution (like our Russian cryptocurrency exchange) as a primary money laundering concern. Once so designated, it becomes illegal for any U.S. financial institution to interact with the listed entity. 

For those readers with long memories, Section 311 was used to shut down Liberty Reserve, a Costa Rican-based electronic money issuer that became popular with criminals involved in identity fraud and credit card theft. Below is a list of entities that have been designated under Section 311.

Entities designated by FinCEN under Section 311 of the Patriot Act

What really provides Section 311 with the extra oomph for reaching rogue exchanges is that it allows FinCEN to require that U.S. financial institutions stop doing business with any other entity that provides banking services to the designated entity. Think of this strategy as the friend of my enemy is my enemy. Any Russian bank that offers an account to the offending Russian cryptocurrency exchange could be cut off from the U.S. banking system, too. Because the U.S. market is such an important market, most Russian banks will stop doing business with the exchange just to stay friendly with the US.

So Section 311 would cripple ransomware-friendly exchanges by severing them from the financial system. And without these rogue exchanges, it becomes much trickier to be a ransomware gang.

To sum up, Bitcoin is censorship-resistant. That's why ransomware gangs like it. This very same feature also prevents democratic societies from modifying the Bitcoin protocol to exclude ransomware gangs. Bitcoin may be censorship resistant, but the venues where it is traded are not. Section 311 and other tools that allow for leverage over these venues remain one of the best ways to attack bitcoin-based ransomware.

Thursday, January 28, 2021

Defining the "regulated" in "regulated stablecoin"

1/n This is a thread on what is means to be a "regulated stablecoin." (This was originally meant for Twitter, but I didn't feel like wrestling with the 240-word limit and threading, plus it got a bit long, so now it's a blog post).

2/n People in the cryptocurrency space often use the term of art "regulated stablecoin." No one has a monopoly over what "regulated stablecoin" means. It is a community-defined term. It's not terribly well-defined. But it should be. 

3/n It should be well defined because when newcomers enter the crypto space, and they have to choose what stablecoins to adopt, they may assume that those stablecoins that are tagged as "regulated stablecoins" are products that offer a degree of government-provided consumer financial protection.

4/n But are there government agencies that actually provide consumer financial protection to stablecoin users? If so, which agencies? What is the nature of this protection? And what stablecoin should you buy if you want to benefit from this protection?

5/n Novices can take heart. In the U.S., state financial agencies such as the New York Department of Financial Services (NYDFS), Florida Office of Financial Regulation, and Texas Department of Banking do in fact check the assets, investments, and reserves of financial institutions that issue stablecoins and/or other payments instruments. The also vet executives and directors of these payments companies, conduct examinations, and ask for audited financial statements.

6/n For instance, below is a screenshot of "eligible securities" as set out by California's Department of Financial Protection & Innovation (DFPI). When a customer deposits funds with a payments company operating in California, this list circumscribes how that company can invest those funds. In theory this should stop a payments provider from betting their customers' savings on wild and dangerous speculations, and losing it all.

California Money Transmission Act [source]

7/n So what companies do these regulators supervise? PayPal is licensed by the NYDFS. So are stablecoin issuers Paxos Trust, Circle, Coinbase, and Gemini Trust. 

PayPal, Coinbase and Circle are also regulated by the Florida Office of Financial Regulation, the Texas Department of Banking, California's DFPI, and a number of other regulators.

8/n To repeat, all of these state departments provide users of supervised payments instruments and stablecoins with an extra layer of financial protection. 

9/n Other countries may have agencies that also provide customers of payments platforms with a degree financial protection. For instance, in Singapore the Monetary Authority of Singapore (MAS) provides a financial regulatory framework for payment companies. In the U.K., the Financial Conduct Authority (FCA) does. 

However, many jurisdiction do not have an established regulatory frameworks for protecting customers of payments companies. These are unregulated jurisdictions.

10/n So to qualify as a "regulated stablecoin," a stablecoin issuer should be licensed with a regulatory body like the NYDFS or DFPI in the U.S., MAS in Singapore, the FCA in UK, or any other similar body. 

11/n FinCEN-registration isn't sufficient for qualification as a "regulated stablecoin." The U.S Financial Crimes Enforcement Network (FinCEN) does not get involved in consumer financial protection. FinCEN is an anti-money laundering watchdog.

12/n Which gets us to a recent article I wrote for Coindesk about one particular stablecoin, Tether. A spokesperson for Deltec, Tether's banker, suggests that Tether should be included in the category "regulated stablecoin." He puts forward Tether's FinCEN registration as the basis for inclusion.

13/n Deltec further invokes Tether's FinCEN-registration to say that Tether's regulation is just as iron-clad as its stablecoin competitors. Paolo Ardoino, a Tether executive, approves, saying: "It's deceitful how some competitors claim to be 'more regulated' as part of their pitch. No such thing."

 

14/n Unlike its competitors, Tether is not regulated by an agency that provides consumer financial protection.

15/n That is, Tether appears to operate from a jurisdiction that does not have a financial regulatory framework for payments companies.

16/n Meanwhile, Tether's stablecoin competitors such as Paxos, Coinbase, and Circle have gone to great lengths to be approved by agencies that do in fact offer these assurances to consumers (i.e the NYDFS). These stablecoins are, in short, better regulated than Tether, which lacks a license from a regulator that provide consumer financial protection.

17/n  Tether's counsel disagrees with my article.

By the way, I think it's laudable that Tether is registered with FinCEN and has a solid anti-money laundering (AML) program. As best as I can tell, Tether is based in the British Virgin Islands, which would mean that it is legally obligated to follow AML standards set by the British Virgin Island's anti-money laundering authority. Presumably it has doubled-up by also registering with FinCEN.

18/n However, to earn the moniker "regulated stablecoin", an issuer shouldat a minimumcombine registration with an anti-money laundering agency like FinCEN AND supervision by an agency that provides a degree of consumer financial protection. That way a crypto novice's expectations of "regulated", i.e. offering a degree of government-controlled consumer protection, do in fact correspond with reality. I'm afraid Tether doesn't make the cut. But USD Coin, Gemini Dollar, and Paxos Standard do.

19/n That isn't to say that Tether isn't safe for consumers to use. Over the course of history there have been many well-run financial institutions that have not operated under a specific financial regulatory framework.

20/n In fact, to this very day Canada still does not have a financial regulatory framework for payments companies. So whereas PayPal USA operates under a financial regulatory framework that provides consumers a degree of financial protection, PayPal Canada operates as an unregulated payments company, just like Tether. But even though PayPal Canada is unregulated, I still use it.

21/n In last week's blog post, I brought up the Banque d'Hochelega, a successful private Canadian note-issuer in the 1800s, an era with minimal financial regulation. I gave some examples about how the Banque d'Hochelaga managed to communicate to the public how safe their payments media were.

22/n To demonstrate how well Tether consumers are protected, Tether could borrow from the Banque d'Hochelega's bag of tricks. Why not start providing the public with more verified financial information?

23/23 Alternatively, it could seek to become a "regulated stablecoin." That is, it could try to get licensed in a jurisdiction that has a financial regulatory framework that protects customers.

Fin.

Sunday, March 31, 2019

Prepaid debit cards. The other anonymous payments method


When it comes to financial privacy, good old fashioned banknotes and privacy cryptocurrencies like Zcash & Monero get all the attention. But as I recently wrote for the Sound Money Project, let's not forget about prepaid debit cards.

Having written a bunch of posts over the last two years about financial privacy, I recently decided that it was time to step up my own personal financial privacy game. A few months ago I walked into my local pharmacy and bought my first non-reloadable prepaid debit card (i.e. gift card), a Vanilla card.

You've probably seen the rack of prepaid cards near the front of pharmacies and department stores. Some of them are closed-loop cards. They can only be used to buy things at the issuer, say Tim Horton's or Starbucks. But some of them, like my new Vanilla Prepaid card, are open-loop cards. That means they can be used wherever Visa or MasterCard are accepted. In Canada, Vanilla cards are sold in denominations from $25 to $250.

The Vanilla card that I bought doesn't have my name on it, nor did I have to show any ID to buy it. I paid for it in cash. This means that whenever I use my card, my identity won't be associated with the purchase. My card is backed by dollars held in a pooled account at Peoples Trust Company, a Canadian bank. It gives me the right to anonymously route my portion of the pooled funds along the MasterCard network to a retailer who operates a MasterCard terminal.

Given that authorities and banks have spend decades constructing a vast financial surveillance apparatus (the Bank Secrecy Act, FATF, AML, CFT, suspicious transaction reporting etc), it seems odd that this small window for accessing the digital payments system anonymously would have remained intact. To comply with Canadian anti-money laundering requirements, card-issuing banks require that the prepaid card seller (my pharmacy) collect the buyer's personal information if the face value of the card exceeds $1000. For amounts below that, due diligence is waived. The same practice is followed in the U.S. This regulatory exemption is why I didn't have to give up my anonymity when I bought my card.

The idea motivating the sub-$1000 exemption is that small amounts of anonymity can't easily facilitate criminal activity, but larger amounts can. (Note that I can convert my non-reloadable Vanilla card into reloadable format—i.e. a card that I'll be able to add money after the first batch is used up—but I'll have to register and forfeit my information. Only non-reloadable cards below the $1000 cap are exempt from due diligence.)

I'm not obsessed with privacy. I still use my information-laden credit card for a big chunk of my day-to-day purchases. But from time-to-time I want to have the option of shielding my data from outside observers. Cash is good for that. I already use banknotes and coins to pay for about half of my face-to-face purchases. This is usually for the sake of convenience, but sometimes it's because I'd prefer not to give up too many of my personal details to the retailer (especially small shops I've never been to before).

By adding a non-reloadable prepaid debit card to my wallet, I've gained an extra degree of protection. Say that I've used up all of the cash in my wallet, or I need to make a purchase in a place that doesn't accept cash, or I want to buy something online—well, a prepaid gift card offers me a way to make a transaction while still protecting my data.   

Law abiding citizens who are conscious of their financial privacy are a pretty small demographic. Sellers of non-reloadable prepaid cards have much larger markets in mind, specifically: 1) people looking to buy convenient gifts for friends and family or; 2) the unbanked and underbanked, i.e. those who don't have bank accounts or have them but don't use them. By allowing people to buy prepaid cards without identification, those without formal credentials such as driver's licenses, social insurance numbers, or credit scores can still make digital payments. Think the homeless, children and teenagers, immigrants, and refugees.

The post-9/11 brigade of security-at-all-costs zealots would love for regulators to shut the prepaid anonymity window. They worry that terrorists and money launderers will abuse prepaid cards. The anonymous prepaid window has only stayed open because these zealots have been countered by a collection of banking lobbyists who want to keep doing business with the unbanked and politicians who care about the disadvantaged.

I'm neither unbanked nor underbanked. I've got several bank accounts that I often use. Nor am I buying these cards as gifts. So I'm not really the target market for non-reloadable debit cards. My ability to get anonymous access the digital payments system is really just a by-product of the wider effort to make it easy for the unbanked to plug in. This is a precarious position for a privacy-conscious individual to be. In the U.S., where only ~93% of the population is banked, the constituency for anonymous prepaid access is relatively large. But in places where the banked population is approaching 100% (Canada, Finland, Germany, Netherlands, Denmark, Belgium, Sweden, UK), there is probably diminishing political support for providing anonymous access to the banking system.

In Europe, for instance, the window for anonymous access to digital payments seems to be closing. When the EU's 4th Anti-money laundering directive was passed in 2015, up to €250 in electronic money (the EU's term for prepaid instruments that reside on a device, say a card or a phone) could be bought without being asked to give up personal information. With the passage of the 5th Anti-money laundering directive in 2018, this amount has been reduced to just €150. And a new ceiling on online purchases of €50 was introduced. As I wrote in my recent Breakermag article, such a tiny amount of anonymity just isn't that useful.

One thing I've noticed about prepaid financial anonymity is that it is expensive. My first Vanilla card had a face value of $25. But I had to pay an onerous $3.95 to activate it. Buying higher value cards defrays this expense, but it still costs $7.50 to activate a card with a face value of $250. That's a 3% levy. Keep in mind that when I use an anonymous prepaid card not only am I paying the activation fee, I am also forgoing 2% cash back that my not-so anonymous credit card would otherwise provide me with.

Think about it this way. Let's say I decide to buy my groceries anonymously using a prepaid card. My $250 only gets me $242.50 worth of goods ($250 less the $7.50 activation fee). With my credit card, I can get $255 worth of food ($250 plus $5 cash back). That's an extra $12.50 in spending power if I decide to go the non-anonymous route. Sure, by using a prepaid card I've prevented my grocery store from being able to collect information about my eating habits. But is the $12.50 I've given up worth it? (Incidentally, this calculation also indicates how costly it is to be unbanked!)

While prepaid anonymity is handicapped by a low ceiling and high fees, the drawbacks don't stop there. Non-reloadable prepaid debit cards are great for buyers who want small amounts of privacy, but they don't help out retailers who want to shield themselves. In a recent article, privacy advocate Timothy May made a great distinction between buyer privacy and seller privacy:    

If someone is selling a controversial product (May uses birth control information as an example), they must always be wary of snitches who make a purchase only to "out" the seller, either by reporting the transaction to the authorities or posting it to social media. Controversy-wary payments providers will quickly cut the seller off. To protect themselves, sellers need a payments method that doesn't leave a paper trail. They also need a payments system from which they can't be censored. Cash is a good example—it doesn't leave a paper trail and is censorship resistant. So are privacy-friendly cryptocurrencies. But prepaid cards don't cut it. The seller can easily be reported to the network and banished.

The last drawback of non-reloadable prepaid debit cards is that they can't be used to make anonymous person-to-person payments. As far as I know, there is no technical reason that I shouldn't be able to use my Vanilla debit card to anonymously send $100 to anyone else with a Visa card, just by inputting their card number and clicking send on a website. In theory, this payment should get pushed across the Visa network.

But there are regulatory reasons that I can't do so. In the U.S., the Financial Crimes Enforcement Network (FinCEN) prohibits anonymous debit cards from offering person-to-person capabilities, and I believe the same rule applies in Canada. Meanwhile, cash and privacy-friendly cryptocurrencies do allow for anonymous person-to-person payments.

In sum, non-reloadable prepaid debit cards allow for a small extension of one's financial privacy. But in an age where the ability to make payments without someone snooping is getting increasingly rare, I suppose we have to take whatever crumbs we can get.