- A new report from the Financial Action Task Force highlights illicit finance risks linked to criminals’ misuse of stablecoins, particularly through peer-to-peer transactions via unhosted wallets, and sets out recommended actions to strengthen controls to protect the integrity of the financial system.
- The report highlights that the majority of ML/TF involving digital assets involves stablecoins, being the most popular digital asset for illicit transactions, particularly in the secondary market.
- This report provides recommended actions that stablecoin issuers should take into account when building out compliance programs to mitigate ML/TF/PF risks connected with the stablecoin ecosystem and sets out typologies of stablecoin misuse.
What are FATF’s findings on stablecoins and unhosted wallets?
On 3 March 2026, the Financial Action Task Force (FATF) published a report titled ‘Targeted Report on Stablecoins and Unhosted Wallets: Peer-to-Peer Transactions’, which highlights the money laundering, terrorist financing and proliferation financing (ML/TF/PF) risks and vulnerabilities associated with stablecoins, particularly in connection with peer-to-peer (P2P) transactions via unhosted wallets.
The report states that stablecoins are the most popular virtual assets used in illicit transactions, with the majority of such activity occurring on secondary markets. However, this may reflect that stablecoins now hold a significant market share in the digital asset economy and are likely being used in a manner similar to fiat, which remains untraceable, is quick to trade, and is a popular way to wash dirty proceeds.
Stablecoins have the distinctive characteristics of purported price stability, high liquidity and interoperability with the traditional finance system, which, coupled with ease of cross-border transfer, means they mirror fiat currency and are attractive for legitimate use but also for criminal misuse. Digital assets are generally more susceptible to misuse by cybercriminal groups due to the online nature of exchanges and speed of transactions. According to the report, threat actors are increasingly using stablecoins in P2P transactions via unhosted wallets to effect ML/TF/PF schemes. Unhosted wallets are not subject to the same controls as wallets offered by regulated financial institutions, which are generally required to comply with the travel rule.
According to FATF, the blockchain-based architecture of stablecoins both helps and hinders AML/ATF oversight. Although every transaction is immutably recorded on public blockchains, these records, in FATF’s view, lack critical context and are pseudonymous. As such, the collection of CDD information, including geographical location, in line with FATF Recommendations 10 and 15, is critical to ensuring that law enforcement can obtain information from digital asset businesses (DABs).
What are the good practices that FATF has identified to mitigate the misuse of stablecoins?
The report notes that, to date, a relatively small number of jurisdictions have implemented regulations for stablecoins that explicitly take into account their characteristics that differ from other digital assets. The report identifies a range of good practices that can be implemented by jurisdictions to help mitigate the misuse of stablecoins. These good practices include:
- imposing clear AML/ATF obligations, as detailed in Recommendation 15 of the FATF Standards, on participants in the stablecoin ecosystem, including digital asset businesses;
- the application of controls by stablecoin issuers to stablecoin transactions, such as using the programmability afforded to smart contracts to either allow certain wallet addresses to transact in the stablecoin (allow-listing) or prevent certain wallet addresses from transacting in the stablecoin (deny-listing) and implementing technical measures to block, freeze or withdraw stablecoins if there are transactions to or from non-allowed-listed or deny-listed wallets;
- using advanced tools for detecting and monitoring suspicious transactions, such as blockchain analytics tools;
- implementing effective supervision of stablecoin issuers and other entities involved in stablecoin arrangements, which may include cooperative frameworks that bring together home and host supervisors to share information and coordinate supervision of relevant entities, thereby helping address cross-border oversight challenges;
- robust public-private sector collaboration to enhance understanding of evolving trends, strengthen co-operation on typologies and risk indicators and build the knowledge and skills of relevant experts, thereby strengthening the integrity and security of the stablecoin ecosystem;
- following investigative leads in relation to the misuse of stablecoins; and
- implementing ML/TF/PF risk mitigation measures in relation to unhosted wallets and P2P transactions, such as digital asset businesses limiting the amount of funds that can be transferred by their customers to unhosted wallets, DABs applying enhanced customer due diligence (CDD) measures for transactions with unhosted wallets, DABs using blockchain analytics tools to determine the risk-level of their customers’ counterparties who own unhosted wallets, entities involved in stablecoin arrangements subjecting unhosted wallets to AML/CFT obligations (such as CDD at issuance and redemption) and prohibiting or denying licenses to platforms that allow transfers to unhosted wallets.
What does this mean for the Cayman Islands?
While there is no separate regulatory framework for stablecoins in the Cayman Islands, stablecoins are typically deemed to be ‘virtual assets’ under the Virtual Asset (Service Providers) Act and therefore the public issuance of stablecoins and/or the provision of exchange, custody, transfer and/or certain other financial services in relation to stablecoins is regulated in the Cayman Islands and supervised by the Cayman Islands Monetary Authority.
The provision of any such services in relation to stablecoins is also within the scope of the Cayman Islands Anti-Money Laundering Regulations (AMLRs), which include mandatory customer due diligence, transaction monitoring, suspicious transaction reporting, sanctions and asset-freezing requirements, and the implementation of related policies, procedures and internal controls. The provision of transfer services in relation to stablecoins is specifically subject to the ‘Travel Rule’ requirements set out in Part 10A of the AMLRs, which requires service providers to identify, verify, and transmit specific information regarding the originators and beneficiaries of virtual asset transfers. Service providers receiving a transfer from an entity that is not a regulated VASP or other obliged entity (e.g., from an individual user using his/her own DLT software, such as an unhosted wallet) or sending to a non-obliged entity, must obtain the required originator/beneficiary information from their customer.
Next steps for participants in the stablecoin ecosystem
Those that participate in the stablecoin ecosystem should be aware of ML/TF/PF risks and vulnerabilities associated with stablecoins, particularly in connection with P2P transactions via unhosted wallets. Such participants may wish to consider, and where relevant implement, the good practices detailed in the Report to mitigate the misuse of stablecoins for financial crime.

Lucy Frew is a partner at Walkers and heads up the firm’s Global Regulatory & Risk Advisory Group.
