Inside the USA crypto regulatory maze: what it means for centralized exchanges

Anna Demirska
Anna Demirska
Marketing Specialist

Introduction

This article continues our global series on crypto regulation, following our previous analyses of regulatory frameworks for centralized exchanges in the European Union, Asia, and Latin America.

Today we are focusing on the United States — a market that sets many de-facto standards for the industry while presenting one of the most legally complex environments for centralized exchanges. Although the U.S. is home to major exchange operators and deep liquidity, it lacks a single, unified federal framework for crypto, forcing centralized platforms to navigate overlapping rules, multiple regulators, and divergent state frameworks.

For centralized exchanges (CEXs) the practical consequence is clear: access to U.S. dollar rails and American customers brings commercial opportunity, but also heightened compliance obligations and legal risk. In the sections that follow, we map who the key regulators are, explain how CEXs are treated under existing rules, review major enforcement actions, and outline the legislative and operational responses that are shaping the near-term future for exchanges operating in — or excluding — the USA market.

Who Regulates Crypto in the U.S.

The United States doesn’t have a single authority overseeing the crypto market. Instead, several federal agencies share responsibility depending on how a specific digital asset is classified and used. This fragmented approach often leads to overlapping jurisdictions and legal uncertainty for businesses and investors.

The Securities and Exchange Commission (SEC) regulates digital assets considered securities. Its focus is on protecting investors and enforcing disclosure requirements, especially for token offerings that resemble traditional investment contracts. The SEC has brought several high-profile cases against crypto exchanges and projects for unregistered securities sales.

The Commodity Futures Trading Commission (CFTC) oversees cryptocurrencies treated as commodities, such as Bitcoin and Ethereum, and regulates derivatives like futures and swaps. Meanwhile, the Financial Crimes Enforcement Network (FinCEN) enforces anti-money laundering (AML) and know-your-customer (KYC) rules, requiring exchanges and wallet providers to register as money services businesses (MSBs) and report suspicious transactions.

In the United States, centralized exchanges are primarily classified as money services businesses (MSBs) under the Bank Secrecy Act (BSA). This means they must register with the Financial Crimes Enforcement Network (FinCEN) and implement strict anti-money-laundering (AML) and know-your-customer (KYC) programs. These requirements aim to ensure transparency in crypto transactions and prevent illicit financial activity.

To comply with FinCEN regulations, exchanges must maintain detailed records of transactions, verify customer identities, and report suspicious activity. They are also responsible for ensuring the safekeeping of customer funds, implementing internal controls, and maintaining audit trails that can be reviewed by regulators.

On top of federal obligations, centralized exchanges face state-level licensing frameworks. The most notable is New York’s BitLicense, which imposes additional requirements for capital reserves, cybersecurity, and consumer protection. While intended to enhance trust, such frameworks have been criticized for their complexity and high compliance costs, prompting some firms to avoid operating in those states altogether.

SEC vs. Exchanges: Major Disputes and Enforcement Actions

The U.S. Securities and Exchange Commission (SEC) has taken an aggressive stance toward centralized exchanges, arguing that many crypto assets traded on these platforms are unregistered securities. The agency’s lawsuits against Coinbase and Binance.US became landmark cases, shaping how the market interprets securities law in the digital era. Both cases center on whether exchanges should have registered as securities brokers and clearing agencies.

In the Coinbase case, filed in 2023, the SEC claimed the exchange operated as an unregistered securities platform by listing tokens it considered investment contracts under the Howey Test. The Binance lawsuit, meanwhile, included broader allegations of commingling customer funds and operating an unregistered exchange that offered U.S. users access to prohibited products.

These legal battles have had far-reaching consequences. Many exchanges have tightened token listing policies, suspended certain services for U.S. users, or created separate entities for compliance. The uncertainty surrounding SEC’s classification of digital assets continues to drive calls for a clearer federal framework and consistent definitions across agencies.

Legislative Initiatives and the Road Ahead

Lawmakers have recognized the challenges posed by fragmented oversight and are exploring legislative solutions to clarify crypto regulation. One such proposal is the Financial Innovation and Technology for the 21st Century Act (FIT21 Act), which seeks to define a clearer boundary between securities and commodities, and to assign regulatory authority accordingly.

If enacted, the bill would provide centralized exchanges with more legal certainty when listing tokens and offering services to U.S. customers. It aims to harmonize federal oversight, reduce cross-agency conflicts, and establish standardized compliance requirements, potentially lowering the risk of enforcement actions.

However, progress is uncertain, and the political landscape in 2024–2025 could influence its scope. Exchanges are monitoring developments closely, as legislative clarity could significantly impact strategic decisions, including U.S. market participation, token listings, and compliance investments.

Key Challenges for Centralized Exchanges

Centralized exchanges in the U.S. face a complex regulatory environment with high compliance costs. They must navigate overlapping federal and state rules, maintain robust AML/KYC programs, and adhere to financial reporting and custody requirements (Bank Secrecy Act),

Another major challenge is the “gray zone” of token classification. Uncertainty about whether a token is a security or a commodity can expose exchanges to enforcement actions from the SEC or CFTC, creating legal and financial risks (SEC v. Coinbase, 2023; SEC v. Binance, 2023).

To adapt, many exchanges have established separate U.S. entities, implemented stricter token listing criteria, adopted proof-of-reserves practices, and increased user transparency. These measures help mitigate regulatory risk but also raise operational costs and limit flexibility in product offerings.

Practical Recommendations for American Centralized Exchanges

Centralized exchanges operating in the U.S. should prioritize regulatory compliance as a core part of their operations. This includes implementing robust AML/KYC programs, maintaining secure custody of customer funds, and ensuring accurate transaction reporting FinCEN Guidance, May 2019.

Exchanges should also establish internal controls for token listing and classification, to mitigate risks related to SEC or CFTC enforcement. Clear procedures for assessing whether a token is a security or commodity, combined with thorough documentation, help reduce legal exposure SEC v. Coinbase, 2023, SEC v. Binance, 2023.

Finally, forming separate U.S. entities, adopting proof-of-reserves practices, and increasing user transparency can enhance trust with both regulators and customers. Staying informed on legislative developments, such as the FIT21 Act, allows exchanges to adapt proactively and maintain operational resilience FIT21 Act, H.R. 4763, 2024.

Conclusion

The United States remains both a global leader and a complex environment for crypto regulation. Centralized exchanges must navigate a fragmented landscape of federal and state rules, with enforcement actions and legislative proposals shaping operational practices (Bank Secrecy Act, 31 U.S.C. §5311, SEC v. Coinbase, 2023, SEC v. Binance, 2023, FIT21 Act, H.R. 4763, 2024)

Compliance is no longer just a legal necessity; it has become a competitive differentiator. Exchanges that invest in robust AML/KYC programs, transparent token listings, and user safeguards gain trust and reduce exposure to regulatory risks FinCEN Guidance, May 2019.

Finally, forming separate U.S. entities, adopting proof-of-reserves practices, and increasing user transparency can enhance trust with both regulators and customers. Engaging in bug bounty programs is another practical measure: regular security audits and public vulnerability reporting help exchanges demonstrate proactive risk management and strengthen compliance efforts. Learn more about implementing a bug bounty program from expert consultations here.

FAQ

1. Who regulates cryptocurrencies in the United States?

In the U.S., cryptocurrencies are regulated by several agencies. The SEC oversees securities, the CFTC regulates commodities and derivatives, and FinCEN enforces anti-money-laundering (AML) and know-your-customer (KYC) rules FinCEN Guidance, May 2019. State-level regulators, like New York’s DFS, also impose licensing requirements such as the BitLicense NYDFS Virtual Currency Businesses.

2. Are centralized crypto exchanges legal in the U.S.?

Yes, centralized exchanges are legal but must register as money services businesses (MSBs) with FinCEN. They are required to follow AML/KYC rules, maintain transaction records, and report suspicious activities Bank Secrecy Act, 31 U.S.C. §5311.

3. What compliance requirements do U.S. centralized exchanges have?

U.S. exchanges must implement robust AML/KYC programs, safeguard customer funds, maintain detailed audit trails, and comply with both federal and state licensing, such as New York’s BitLicense NYDFS Virtual Currency Businesses.

4. Why is token classification important for U.S. exchanges?

Token classification determines whether an asset is considered a security or commodity, affecting which agency regulates it. Misclassifying tokens can lead to enforcement actions, fines, or lawsuits SEC v. Coinbase, 2023, SEC v. Binance, 2023.

5. What is the FIT21 Act and how does it affect crypto exchanges?

The FIT21 Act (H.R. 4763, 2024) aims to clarify the legal framework for digital assets, define boundaries between securities and commodities, and harmonize federal oversight. If passed, it would provide centralized exchanges with more certainty for operations in the U.S. FIT21 Act, H.R. 4763.

6. How do U.S. regulations impact exchange operations and user safety?

High compliance costs and fragmented oversight push exchanges to adopt stricter token listing policies, create separate U.S. entities, implement proof-of-reserves, and increase user transparency, improving trust and reducing regulatory risks FinCEN Guidance, May 2019.

7. What should crypto users know about trading on U.S. centralized exchanges?

Users should trade on exchanges that comply with federal and state regulations, follow AML/KYC rules, and safeguard customer funds. Checking regulatory registration and understanding which agency oversees each type of activity helps ensure safe trading practices.

Share article:

Read more on HackenProof Blog