Rethinking Responsibility in Cross-Border Financial Crimes – The RMLNLU Law Review Blog

    0
    5
    ADVERTISEMENT

    By Yukta Chanda and Netraa Rathee


    INTRODUCTION

    SPONSORED

    In November 2023, the United States Department of Justice announced[1] the largest corporate fine in the history of cryptocurrency. A settlement of 4.3 billion US billion dollars [“USD”] with Binance,[2] the world’s leading digital asset exchange for failures in anti-money laundering [“AML”] compliance.[3]

    At the heart of these enforcement actions were stablecoins. Stablecoins are a type of non-volatile cryptocurrency which are tied to the value of another asset such as gold or a currency.[4] In this essay, the authors focus on fiat-based stablecoins, those that are tied to the 1:1 value of the dollar or any other currency. A useful analogy is to think of them as arcade tokens, one can exchange 1 USD for a token that’s always meant to be worth 1 USD inside the arcade.

    Stablecoins were designed to address the major issue of stability in the crypto market which volatile currencies like Bitcoin could not fulfil. Additionally, stablecoins allow for faster settlement, with transactions clearing in minutes regardless of banking hours or time zones. Costs are lower since they avoid the intermediary fees and exchange spreads that often come with multi-hop international wires.[5] In countries like Venezuela, where inflation rates occasionally skyrocket, the constant devaluation of the currency puts the economy in a vulnerable position. In such situations, stablecoins have allowed users to maintain their purchasing powers acting as “digital dollars”.[6]

    These features make stablecoins an attractive option for cross-border money transfers and remittances, especially when compared to traditional cryptocurrencies like Ethereum. However, there are two sides to every coin. According to the Chainanalysis report published in 2025,[7] stablecoins have been heralded as the new kingpin of illicit crypto activity overthrowing Bitcoin. Stablecoins comprised approximately 63 percent of all illicit cryptocurrency transaction volume, with total illicit flows amounting to at least 40.9 billion USD and estimates suggesting total abuse may rise above 51 billion.[8]

    Today, the global market for stablecoins stands at approximately 255 billion USD, with nearly 99 percent pegged to the USD.[9] Hence, Stablecoins are a double-edged sword. On one hand, they empower financial inclusion facilitating inexpensive, rapid cross-border payments and access for underserved populations. On the other hand, their structural features make them an attractive vehicle for white-collar crimes: money laundering, sanctions evasion, fraudulent reporting and ransomware proceeds movement.

    This poses a critical regulatory challenge: how do we pin liability in stablecoin-enabled financial crime? Traditional corporate criminal liability doctrines such as the UK’s “identification doctrine”, the US “doctrine of respondeat superior” or India’s approach under the Companies Act, 2013,[10] Foreign Exchange Management Act, 1999 [“FEMA”][11] and Prevention of Money Laundering Act, 2002 [“PMLA”][12] were developed for centralised, hierarchical entities where intent and responsibility could be traced to a “directing mind and will.” But in decentralized stablecoin ecosystems, responsibility is distributed among issuers, exchanges, decentralized autonomous organizations [“DAOs”] and validators.

    As Garland remarked in the wake of prosecutions against Binance and FTX: “Using new technology to break the law does not make you a disruptor, it makes you a criminal.”[13] The challenge for corporate criminal liability doctrines is to ensure that this principle is enforceable even in a decentralised scheme. Can a corporation be said to possess mens rea if laundering occurs automatically via its technology? Does deliberate weakening of compliance controls imply constructive knowledge? And if liability is blurred between multiple actors across jurisdictions, who ultimately bears responsibility – the issuer, the exchange or the corporate end-user?

    These questions matter urgently for India where the government has extended AML obligations to Virtual Digital Asset [“VDA”] service providers in 2023,[14] meaning crypto exchanges and related platforms now fall under stricter compliance rules. The Reserve Bank of India [“RBI”] has repeatedly warned that digital assets could undermine monetary sovereignty, but there is still no dedicated law to govern them.[15]

    The essay proceeds as follows. Part II develops the conceptual frame of white collar crime in the FinTech era, situating stablecoins within classic categories of laundering, fraud and sanctions evasion. Part III explores the doctrinal problems of attributing corporate liability in stablecoin ecosystems. Part IV provides a comparative study of liability frameworks across the United States [“US”], European Union [“EU”], United Kingdom [“UK”], India, Japan and the United Arab Emirates [“UAE”], while also highlighting how regulatory arbitrage and cross-border mismatches are exploited by corporations and illicit actors. Part V proposes a new liability model anchored in a “chain-of-liability” and an “algorithmic mens rea” test. Part VI concludes by restating the problem and proposing a consolidated corporate liability code for India in line with global standards.

    WHITE COLLAR CRIMES IN THE FINTECH ERA

    The concept of white-collar crime was first articulated by Edwin Sutherland in 1939. He referred to it as “a crime committed by a person of respectability and high social status in the course of his occupation.”[16] Traditionally, such crimes took shape through mechanisms such as misreporting financial reports, creating shell companies and using offshore banking arrangements. These mechanisms relied on a string or proverbial blockchain of banks, accountants, lawyers and corporate service providers who knowingly or unknowingly facilitated them. Further, traditional systems relied on a centralised single entity for storage of data, which also created identifiable points of oversight.

    In the financial technology [“fintech”] era, this structure has shed its foundational defects.[17] Virtual assets by their design, are such that they cancel out this proverbial blockchain often by introducing a technological one. The rise of fintech has introduced near-instant, borderless transfers without reliance on regulated intermediaries, enabling offenders to replicate the functions of offshore structures at a fraction of the cost and with far greater opacity.[18] As the Bank for International Settlements [“BIS”] has observed, digital tokens now perform many of the same roles that offshore banks once did but on a larger and less regulated scale.[19]

    Within this ecosystem, white-collar crimes involving stablecoins typically fall into three broad categories: sanctions evasion and money laundering, unlicensed money transmissions and digital adaptations of hawala networks.

    The risks are not theoretical. In 2025, the U.S. Department of Justice [“DOJ”][20] charged the CEO of Evitapay with running a scheme that funnelled over 530 million USD to sanctioned Russian banks through stablecoin transactions[21]. While in Europe, a joint Europol and National Crime Agency investigation revealed a sprawling network of criminals using stablecoins to launder billions for Russian intelligence operatives and organised crime groups.[22] The operation spanned thirty countries and resulted in more than eighty arrests, highlighting how stablecoins’ speed and liquidity make them the preferred settlement tool for illicit networks.[23]

    Stablecoin issuers themselves often operate in legal grey zones. They offer services that resemble bank deposits, facilitate payments and maintain reserves but do so without a banking license.[24] This creates systemic risks comparable to those of shadow banking, only with even less transparency.

    The problem is magnified when age-old informal practices such as hawala are digitized.[25] Historically based on trust networks in South Asia and the Middle East, hawala is increasingly combined with stablecoins which provide efficiency, liquidity and anonymity at one’s fingertips.

    The dangers extend to national security. The Financial Action Task Force [“FATF”] has repeatedly warned that terrorist groups may adopt stablecoins as financing tools.[26] In 2023, the Israeli National Bureau for Counter Terror Financing reported that Hamas-affiliated networks were moving away from Bitcoin and adopting Tether for cross-border financing. They cited its price stability and ease of conversion into local currencies as reasons.[27]

    Together, these developments show how the tools of white-collar crime have transformed in the fintech era. What once required elaborate offshore structures and professional intermediaries can now be achieved with a few keystrokes.

     STABLECOINS AND CORPORATE CRIMINAL LIABILITY: THE DOCTRINAL PROBLEM

    The central difficulty with regulating stablecoins is not only about tracing suspicious transactions but also about deciding who should be held responsible when things go wrong. Traditional doctrines of corporate criminal liability were designed for organisations with clear hierarchies, where responsibility could be traced up a chain of command. Stablecoins, by contrast operate in a decentralised ecosystem where responsibility is spread across multiple unknown entities such as issuers, exchanges, validators, and even DAOs. This fragmentation of responsibility in addition to the anonymity provided by the blockchain exposes a profound doctrinal gap.

    In common law systems such as the UK, the dominant framework has been the identification doctrine.[28] Under this doctrine a corporation may only be held criminally liable where the offending act can be attributed to a person who embodies the “directing mind and will” of the company. This test functions best when applied to hierarchical corporations. In D’Aloia v Persons Unknown,[29] the Court accepted that exchanges could face unjust enrichment claims over tainted funds, even though no “directing mind” was identified. Most strikingly, in Tulip Trading Ltd. v Bitcoin Association,[30] the Court of Appeal left open the possibility that dispersed groups of software developers might owe fiduciary duties to users of blockchain networks an acknowledgment[31] that traditional attribution models struggle in decentralized or collective structures. Lord Justice Birss remarked that developers might “owe fiduciary duties to the true owners of that property.”[32]

    Across the Atlantic, the US follows the broader doctrine of respondeat superior,[33] commonly known as vicarious liability under which a corporation may be held liable for the acts of its employees committed within the scope of employment. Unlike the UK’s identification doctrine, there is no need to trace wrongdoing to the directing mind. This model is more adaptable to the stablecoin ecosystem. If applied to issuers like Tether liability could cover compliance staff, traders or even employees dealing directly with customers who enable illicit transactions. The problem is that the doctrine can be too broad, making companies liable for the unauthorised actions of rogue employees and leading to over-deterrence.[34]

    In India, the doctrine of corporate criminal liability has been shaped by both case law and statute. In Iridium India Telecom Ltd. v Motorola,[35] the Supreme Court confirmed that corporations can possess mens rea and be prosecuted for offences requiring intent, rejecting the earlier view that a juristic person cannot form a guilty mind. Earlier, in Standard Chartered Bank v Directorate of Enforcement,[36] the Court held that companies may also be liable under strict liability statutes such as FEMA even where no mens rea is required, making clear that corporate entities cannot escape prosecution merely because imprisonment is prescribed. This judicial position is reinforced by statutory frameworks: the Companies Act, 2013 and the PMLA explicitly creates vicarious liability for directors and officers, holding them accountable alongside the company for regulatory breaches and financial crime.

    For stablecoins, neither model is entirely adequate. A hybrid approach[37] wherein liability attaches at multiple levels i.e. issuers for reserve misrepresentation, exchanges for facilitating illicit flows and DAOs or validators where governance involves collective decision making. Statutory reform in recent times has built on this by imposing a duty of care standard, holding corporate actors criminally liable where they fail to implement effective AML[38] and know-your-customer [“KYC”] controls.[39] These seem to be the best recourse since blockchains cannot be altered.

    The cross-border nature of stablecoins makes liability even harder to pin down. Entities often register in permissive jurisdictions but target consumers in highly regulated markets, leaving accountability fragmented. This suggests the need for a distributed corporate liability model, similar to product liability law. Here responsibility is allocated across the “supply chain”[40] of actors such as issuers, exchanges, developers and validators. The programmability of stablecoins reinforces this argument. Compliance safeguards such as blacklisting, transaction freezing or automated reporting can be built directly into code.[41] If a stablecoin provider deliberately omits these features, it’s not just a design flaw instead, it could be a compliance failure.

    These developments point towards the need for a doctrinal shift. Rather than clinging to models of liability tied to individual decision-makers, the law must evolve to focus on compliance and systematic responsibility.

    A COMPARATIVE ANALYSIS AND REGULATORY ARBITRAGE IN STABLECOIN LIABILITY

    The regulation of stablecoins has become a defining test of whether the legal system can keep pace with financial innovation. These instruments cut across borders, weaken traditional regulatory controls and carry the potential for systemic risk. Comprehensive ex-ante statutes are the choice of some jurisdictions while enforcement-heavy models are the choice of others. Despite their differences, a clear pattern is emerging: stablecoin issuers and intermediaries are being treated less like experimental tech start-ups and more like financial institutions subject to strict rules on reserves, disclosures and AML.

    The US has taken a statute-led approach to stablecoin regulation through the Guiding and Establishing National Innovation for U.S. Stablecoins Act [“GENIUS Act”].[42] Signed into law on 18 July 2025, the GENIUS Act was enacted as the first federal framework for payment stablecoins. This creates a federally backed scheme for stablecoins. Under the Act, only insured and authorised institutions are permitted to issue stablecoins. Further, every stablecoin must be backed by a one-on-one reserve. It is also imperative to note that these institutions[43] are to be treated as financial institutions under the Bank Secrecy Act [“BSA”].[44] This puts them under an obligation to initiate and implement AML, KYC and other compliance programs. However, the Act does not impose any such express obligations on exchanges, brokers. These obligations are largely limited to issuers. These intermediaries remain regulated[45] only insofar as existing frameworks like FinCEN’s money-services-business rules apply. In April this year the New York Attorney General urged Congress to fill these gaps and extend such obligations to intermediaries as well.[46] The Act also stops short of requiring issuers to monitor on-chain trading activity of their tokens or to file suspicious activity reports based on blockchain evidence. Without such duties, issuers who invest in monitoring may be commercially disadvantaged compared with competitors that do not.[47] Thus, the Act may discourage monitoring. Finally, the legislation does not address the unresolved sanctions loophole for mixers. Under the International Emergency Economic Powers Act [“IEEPA”],[48] the U.S. Treasury’s Office of Foreign Assets Control [“OFAC”] can sanction people, companies and their property. In 2022, OFAC sanctioned Tornado Cash which the Treasury said North Korean hackers used to launder funds.[49] In Van Loon v Department of the Treasury the Court (Fifth Circuit, 26 November 2024) held that autonomous smart contracts are not “property” under IEEPA, so OFAC cannot sanction them.[50] Rather than appeal, the Treasury Department opted on 21 March 2025 to delist Tornado Cash from the SDN List entirely, citing the “novel legal and policy issues” raised by the Fifth Circuit. This development confirms that the sanctions loophole for code-based mixers is now judicially and administratively settled, and it remains unaddressed by the GENIUS Act.[51] Unless Congress changes the law, mixers that run as code escape sanctions. The GENIUS Act does not fix this gap. It regulates issuers but does not place full anti-money laundering duties on exchanges or decentralised finance platforms.[52]

    By contrast, the EU regulates stablecoins under the Markets in Crypto-Assets Regulation [“MiCA”]. MiCA creates a single framework for all EU member states and divides tokens into “asset-referenced tokens” [“ARTs”] and “e-money tokens” [“EMTs”]. EMTs are stablecoins tied to one official currency and can only be issued by licensed banks or electronic money institutions. Additionally, Crypto-Asset Service Providers such as exchanges and wallet providers must get licenses from national regulators and comply with AML and counter-terrorist financing standards. This ensures that both issuers and intermediaries are supervised under financial rules instead of operating without oversight.[53]

    The UK has chosen a hybrid strategy weaving stablecoins into existing payments law while also introducing new corporate liability offences. The Financial Services and Markets Act placed “digital settlement assets” under the Financial Conduct Authority with systemic tokens overseen by the Bank of England.[54] Simultaneously, the Economic Crime and Corporate Transparency Act, 2023 expanded the concepts of the Bribery Act, 2010 by creating a corporate crime of “failure to prevent fraud”.[55] This offence came into force on 1 September 2025 under s.199 ECCTA (SI 2025/349), making large organisations (those meeting two of: more than 250 employees, over £36 million turnover, or over £18 million in assets) criminally liable where an associated person commits fraud for the organisation’s benefit and the organisation lacked reasonable fraud-prevention procedures, with extraterritorial reach extending to any entity with a UK nexus, including stablecoin platforms serving UK users.[56] By enforcing corporate duties of prevention instead of depending exclusively on attribution doctrines, the UK shows ambition to brand itself as a fintech hub. The UK strategy incorporates stablecoins into its corporate crime and payments frameworks, in contrast to MiCA’s uniform regime. The UK’s model is flexible but risks producing fragmentation.[57]

    The regulatory diversity defines the Asia-Pacific region, though there is a common trend toward full reserve backing and strict licensing. Japan limited issuance to licensed banks, trust companies or transfer agents by amending its Payment Services Act, 2022.[58] Issuers are subject to stringent AML/ Counter-Terrorism Financing [“CTF”] oversight and reserves must be held in trust to ensure bankruptcy remoteness. A conservative stance centered on stability and consumer protection.[59] Singapore’s Stablecoin Regulatory Framework (finalised in 2025) takes a more calibrated route. It focuses on single-currency stablecoins pegged to the Singapore Dollar [“SGD”] or G10 currencies. Issuers must hold reserves in cash or equivalents, publish daily disclosures and guarantee redemption rights.[60] The Stablecoins Bill (2025) was passed in Hong Kong, mandating issuers of HKD-referenced or fiat stablecoins seek authorisation from the Hong Kong Monetary Authority. Aligning with Hong Kong’s Fintech 2025 strategy, the central pillars are Governance, risk management and consumer safeguards.[61] The UAE through its Payment Token Services Regulation 2024, restricts only dirham-pegged stablecoins for domestic settlement and mandates AML compliance, audits and licensing. This is enhanced by a sandbox regime for innovation provided by Dubai’s Virtual Assets Regulatory Authority [“VARA”].[62]

    Unlike the EU’s codified MiCA regime or U.S. GENIUS Act, India still relies on a patchwork of existing statutes. Under the PMLA, the Ministry of Finance brought VDA service providers as “reporting entities” in March 2023, imposing KYC and reporting obligations.[63] These obligations were significantly strengthened when, on 8 January 2026, FIU-IND issued updated AML/CFT Guidelines for VDA service providers, replacing the 2023 Guidelines and requiring VDASPs to operate at bank-equivalent compliance standards, including mandatory FIU registration, a designated Principal Officer, PAN/Aadhaar verification with liveness detection at onboarding, and Travel Rule compliance on all transfers.[64] Separately, from 1 April 2025 SEBI assumed supervisory jurisdiction over crypto tokens that function like securities, creating a two-tier regulatory structure alongside FIU-IND’s oversight, and in 2025 the Madras High Court recognised crypto assets as property under Indian law.[65] Cross-border value transfers are still governed by the FEMA although it is unclear how this law applies to stablecoins. The Enforcement Directorate [“ED”] has looked into exchanges such as WazirX that use stablecoins to launder criminal proceeds.[66] Despite these developments, India has yet to adopt a specific law on stablecoin issuance or intermediary regulation. Yet no dedicated statute governs issuers or intermediaries, leaving overlapping regulators (RBI, ED, Securities and Exchange Board of India [“SEBI”], MeitY) and opportunities for regulatory arbitrage. Offshore issuers like Tether serve Indian markets without licensing and foreign-domiciled exchanges operate without clear authorization. The Finance Bill 2025 also expanded the definition of “Virtual Digital Assets” under the Income Tax Act to bring a wider range of crypto-assets within the tax framework from 1 April 2026, though comprehensive stablecoin-specific legislation remains shelved as of mid-2026 amid an apparent impasse between the RBI and the Ministry of Finance over whether to formally legitimise the sector.[67]

    This situation reflects the broader challenge of regulatory arbitrage. In order to serve users worldwide, corporates often incorporate in permissive jurisdictions with lighter regimes (like Tether in the British Virgin Islands), move their headquarters to avoid obvious oversight (like Binance’s “no headquarters” model) or look for legitimacy in lax hubs like Dubai.

    Despite differences across jurisdictions, three points of convergence stand out. First, stablecoin issuers are now being regulated more like financial institutions than technology firms. Second, obligations relating to reserve transparency, redemption guarantees and anti-money laundering compliance are becoming standard expectations. Third, liability frameworks are shifting from proving subjective intent toward requiring preventive measures evident in the UK’s new corporate offence of “failure to prevent fraud” and in the U.S. GENIUS Act’s obligations on freezing and reporting suspect activity. Still, important divergences remain: the EU has opted for a uniform ex ante statute under MiCA, the U.S. is moving from case-by-case enforcement toward banking-style licensing, the UK has integrated stablecoins into both payments and corporate crime law, Asia-Pacific jurisdictions range from conservative (Japan, Singapore) to innovation-oriented (Hong Kong, UAE) and India continues to rely on fragmented oversight.[68]

    Yet, arbitrage remains the Achilles’ heel: corporates migrate to lax jurisdictions and illicit flows follow. The persistence of regulatory arbitrage underscores the urgency of greater cross-border coordination extending FATF standards to stablecoin actors and ensuring reciprocal recognition of supervisory and enforcement actions, are essential steps to prevent any jurisdiction from becoming a haven for crime facilitated through stablecoins.

    PROPOSED MODEL: CORPORATE LIABILITY IN STABLECOIN ECOSYSTEMS

    The preceding analysis shows that some jurisdictions, like the US, the EU and the UK, have started to strengthen their oversight of stablecoins while others, like Japan, Singapore, and the UAE, focus on licensing frameworks. Because accountability is shared among issuers, exchanges, validators, DAOs and corporate end users, traditional theories of corporate criminal liability fall short in the context of stablecoins. On top of that, as discussed in Part IV, regulatory arbitrage makes matters worse by allowing actors to migrate to permissive jurisdictions or operate transnationally without facing uniform rules.

    This essay suggests a reform model based on two related innovations to address these doctrinal and jurisdictional blind spots: a chain-of-liability framework that divides responsibilities among all important players in the stablecoin ecosystem and an algorithmic mens rea standard that imputes corporate knowledge when firms purposefully design compliance-light systems.

    Product liability law’s reasoning, which distributes accountability throughout the supply chain, is incorporated into the chain-of-liability framework. This would indicate that each actor in the stablecoin context has responsibilities that correspond to their roles. Issuers would need to maintain fully backed reserves of high-quality liquid assets, undergo independent audits, guarantee redemption at par and build in real-time KYC and sanctions screening at the points of issuance and redemption. These requirements echo elements already found in the EU’s MiCA Regulation and in the U.S. GENIUS Act, both of which place heavy emphasis on reserves, redemption rights and technical capacity to freeze unbacked tokens. Exchanges and custodians that serve as the main gateways for users would be bound to risk-based AML/KYC controls, implementation of the FATF Travel Rule, and robust suspicious transaction reporting. The importance of this layer has been underlined by recent U.S. enforcement actions, such as the DOJ’s case against Binance for systemic AML failures. Finally, protocol operators and DAOs would face duties where they exercise real governance or control for instance, integrating sanctions oracles or blocking access from sanctioned jurisdictions. If governance is truly decentralised, liability could be moderated with a “reasonable steps” defense, but voting to reject compliance measures would clearly attract accountability.

    The second innovation, algorithmic mens rea, tackles the problem of intent in systems where transactions and laundering can occur automatically through code. If liability is tied only to human intention, corporations will continue to hide behind the shield of “we don’t control the code.” Algorithmic mens rea closes this loophole by imputing knowledge where system design predictably enables illicit activity. If an issuer knowingly releases a system without sanctions screening, strips out freeze functionality in defiance of FATF guidance or waters down KYC to chase user growth, regulators should treat the resulting misuse as foreseeable and intended. This reflects more general changes in the law. Instead of depending on finding a directing mind, the UK’s Economic Crime and Corporate Transparency Act, 2023 shifted liability towards assessing the effectiveness of preventive systems. Similar to this, issuers are required by the GENIUS Act in the US to design compliant systems in addition to acting compliantly. In both situations, the antiquated dependence on arbitrary corporate intent is starting to give way to outcome-based liability.

    A third pillar of reform must be international cooperation. Stablecoins are uniquely adept at exploiting jurisdictional gaps: issuers domiciled in offshore havens, exchanges moving headquarters to sidestep oversight and firms leveraging permissive hubs such as Dubai’s VARA while serving users globally. To curb this, regulators could adopt supervisory colleges for major issuers and exchanges, borrowing from the playbook of cross-border banking supervision. Reciprocal recognition should also be standard. If a license is revoked or an enforcement action is taken in one jurisdiction, others should impose at least interim restrictions. Lastly, in order to guarantee Travel Rule compliance and licensing as prerequisites for market access globally, FATF’s targeted updates on VDAs and Virtual Asset Service Providers [“VASPs”] must develop into a legally binding global baseline.

    These lessons highlight India’s pressing need for consolidation. The country currently uses a patchwork of policies: the RBI continues to identify threats to monetary sovereignty; the FEMA regulates cross-border flows without specifically addressing stablecoins; and the PMLA treats VDA service providers as reporting entities. FIU-IND’s January 2026 Guidelines and SEBI’s expanded mandate over security-like tokens are welcome incremental steps, but they remain additions to a fragmented system rather than a coherent framework. Enforcement actions against exchanges like WazirX demonstrate the fragmented nature of the current strategy, which is divided among SEBI, the ED and the RBI. Offshore issuers and foreign-based exchanges can therefore operate freely, leaving Indian users exposed. A Digital Asset Liability Code could close this gap by unifying PMLA, FEMA and IT Act provisions. Such a code would mandate licensing for all issuers and VASPs serving Indian users, impose MiCA-style reserve and redemption obligations, and create a “failure to prevent” offence for money laundering and terrorism financing with an adequate defense. A Joint crypto-Financial Intelligence Unit [“FIU”] comprising the ED, RBI and FIU-IND could coordinate enforcement, making it impossible for actors to simply move their operations offshore to avoid detection.

    Liability in stablecoin ecosystems is ultimately reframed by this model. The question of who pressed “send” on a transaction becomes less important than the more fundamental one of who created the system and whether sufficient measures were taken to deter crime. The suggested framework supports the preventive turn in international financial regulation by integrating accountability throughout the supply chain and assuming intent through design decisions. It harmonises domestic doctrines with international standards, limits opportunities for arbitrage and offers India and others a blueprint for resilient, future-proof regulation.

    CONCLUSION

    The rise of stablecoins highlights a central dilemma of financial innovation: technology moves faster than the law. What began as a clever fix for cryptocurrency volatility has quickly become core financial infrastructure, used for everything from cross-border remittances to settlement layers for digital markets. Yet the very features that make stablecoins efficient speed, borderless reach and liquidity also make them attractive tools for laundering ransomware proceeds, evading sanctions and facilitating fraud. As noted earlier in this essay, stablecoins have effectively taken on the functions once performed by shell companies, offshore accounts and informal transfer systems like hawala, but at a scale and velocity those older mechanisms could never achieve.

    Against this backdrop, traditional doctrines of corporate criminal liability are showing their age. The UK’s “directing mind and will” model, the U.S. doctrine of respondeat superior and India’s mixed jurisprudence were all built for hierarchical companies with identifiable chains of command. In decentralised financial ecosystems, however, responsibility is scattered across issuers, exchanges, DAOs and protocols. This fragmentation allows corporations to claim that no one individual has the requisite intent or control, even as they benefit from the foreseeable misuse of their systems.

    A comparative survey of regulatory responses underscores both convergence and divergence. In Europe, the MiCA Regulation stands out as the most comprehensive framework, imposing uniform requirements on issuers across the EU. The US, after years of relying on high-profile enforcement actions such as the Binance settlement in 2023, has shifted towards legislative clarity through the GENIUS Act, which embeds reserve and AML duties directly into law. The UK has taken a different tack, incorporating stablecoins into payments law while expanding its “failure to prevent” model of corporate offences. In Asia, Japan and Singapore favour a prudential, bank-like approach built on strict reserve rules, while Hong Kong and the UAE position themselves as innovation hubs, experimenting with sandbox regimes but still anchoring them in compliance obligations. By contrast, India continues to rely on a patchwork of measures such as notifications under the PMLA, foreign exchange controls under FEMA, repeated warnings from the RBI, and enforcement by the ED leaving significant regulatory gaps. The International Monetary Fund and FATF have already warned that such divergences invite regulatory arbitrage, heightening systemic risks.

    To address these challenges, this essay proposes a reform model that reconceptualises corporate liability for the stablecoin era. At its core is a chain-of-liability framework, which distributes responsibility across all actors in the stablecoin supply chain, coupled with an algorithmic mens rea standard. Under this approach, liability does not hinge on proving individual intent but on recognising when a system’s very design predictably enables misconduct. This shift mirrors broader global trends, from the UK’s “failure to prevent” offences to the compliance-by-design duties codified in the U.S. GENIUS Act.

    For India, the stakes are especially pressing. Reliance on fragmented statutes and ad hoc enforcement risks leaving the country perpetually reactive and vulnerable to offshore exploitation. A unified Digital Asset Liability Code could change this. By harmonising PMLA, FEMA and RBI oversight, imposing MiCA-style reserve and redemption rules, codifying a failure-to-prevent offence, and establishing a dedicated crypto-FIU, India could protect its monetary sovereignty while aligning with emerging international norms.

    In conclusion, stablecoins are no longer peripheral experiments at the edges of finance. They are fast becoming embedded in the digital backbone of the global economy. Without robust liability frameworks, they may also become embedded in the architecture of transnational white-collar crime. To prevent this outcome, corporate liability doctrines must evolve shifting from a narrow focus on individual intent to a broader test of systemic responsibility. Only then can stablecoins realise their promise as tools for financial inclusion and efficiency, rather than as the infrastructure of global financial crime.

    [1]Commodity Futures Trading Commission, ‘Binance and Its CEO, Changpeng Zhao, Agree to Pay $2.85 Billion for Willfully Evading US Law, Illegally Operating a Digital Asset Derivatives Exchange, and Other Violations’ (Press Release 8825-23, 21 November 2023) <https://www.cftc.gov/PressRoom/PressReleases/8825-23&gt; accessed 2 September 2025.

    [2]U.S. Department of Justice, ‘Binance and CEO Plead Guilty to Federal Charges in $4 B Resolution’ (Press Release 23-1323, 21 November 2023) <https://www.justice.gov/archives/opa/pr/binance-and-ceo-plead-guilty-federal-charges-4b-resolution&gt; accessed 2 September 2025.

    [3]U.S. Department of Justice, ‘United States v Binance Holdings Limited, d/b/a Binance.com’ (Criminal Division case page, 21 November 2023) <https://www.justice.gov/criminal/case/united-states-v-binance-holdings-limited-dba-binancecom&gt; accessed 2 September 2025.

    [4]Angelos Delivorias, *Stablecoins: Private-sector Quest for Cryptostability* (EPRS Briefing, European Parliamentary Research Service, PE 698.803, November 2021) <https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/698803/EPRS_BRI(2021)698803_EN.pdf&gt; accessed 2 September 2025.

    [5]Yellowcard, ‘Stablecoins in Remittances: Benefits and Challenges’ (Yellowcard Blog, 2024) <https://yellowcard.io/blog/stablecoins-remittances-benefits-challenges&gt; accessed 2 September 2025.

    [6]Bitso, ‘The Stablecoin Revolution in Latin America: Beyond Volatility’ (Bitso blog, 12 August 2025) <https://blog.bitso.com/stablecoin-in-latin-america/&gt; accessed 2 September 2025.

    [7]Chainalysis Team, ‘2025 Crypto Crime Trends: Illicit Volumes Portend Record Year as On-Chain Crime Becomes Increasingly Diverse and Professionalized’ (Chainalysis blog, 15 January 2025) <https://www.chainalysis.com/blog/2025-crypto-crime-report-introduction/&gt; accessed 2 September 2025.

    [8]Rezaul Karim, ‘Stablecoins: The New Epicentre of Crypto Fraud’ (ICA Insight, 3 March 2025) <https://www.int-comp.org/insight/stablecoins-the-new-epicentre-of-crypto-fraud/&gt; accessed 2 September 2025.

    [9]Ashley Lannquist, ‘Stablecoins Are Trending, but What Frictions and Risks Are Getting Overlooked?’ (Atlantic Council Econographics, 8 July 2025) <https://www.atlanticcouncil.org/blogs/econographics/stablecoins-are-trending-but-what-frictions-and-risks-are-getting-overlooked/&gt; accessed 2 September 2025.

    [10]The Companies Act 2013, No. 18 of 2013.

    [11]Foreign Exchange Management Act 1999 (India) No. 42 of 1999.

    [12]The Prevention of Money Laundering Act 2002, No. 15 of 2002.

    [13]U.S. Department of Justice, ‘Binance and CEO Plead Guilty to Federal Charges in $4B Resolution’ (21 November 2023) <https://www.justice.gov/archives/opa/pr/binance-and-ceo-plead-guilty-federal-charges-4b-resolution&gt; accessed 6 September 2025.

    [14]Financial Intelligence Unit-India, ‘AML & CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets’ (Financial Intelligence Unit-India 10 March 2023) <https://fiuindia.gov.in/pdfs/AML_legislation/AMLCFTguidelines10032023.pdf&gt; accessed 6 September 2025.

    [15]Reserve Bank of India, ‘Financial Stability Report – December 2024’ (Reserve Bank of India 2024) <https://www.rbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=49724&gt; accessed 6 September 2025.

    [16]Edwin H Sutherland, White Collar Crime (Dryden Press 1949).

    [17]Monika Juneja, “Blockchain Technology: Benefits, Challenges, Applications and Future Direction,” IJFMR – International Journal For Multidisciplinary Research 6, no. 6 (December 2, 2024): 1–21, <https://doi.org/10.36948/IJFMR.2024.V06I06.32265&gt;.

    [18]Bank for International Settlements, Annual Economic Report 2025: Chapter III—The Next-Generation Monetary and Financial System (24 June 2025) <https://www.bis.org/publ/arpdf/ar2025e3.htm&gt; accessed 31 August 2025.

    [19]Iñaki Aldasoro, Jon Frost, Sang Hyuk Lim, Fernando Perez-Cruz and Hyun Song Shin, ‘An Approach to Anti-Money Laundering Compliance for Cryptoassets’ (Bank for International Settlements, Bulletin No 111, 13 August 2025).

    [20]U.S. Department of Justice (EDNY), Founder of Cryptocurrency Payment Company Charged with Evading Sanctions and Export Controls, Defrauding Financial Institutions, and Violating the Bank Secrecy Act (Press Release, 9 June 2025) <https://www.justice.gov/usao-edny/pr/founder-cryptocurrency-payment-company-charged-evading-sanctions-and-export-controls&gt; accessed 31 August 2025.

    [21]Wall Street Journal, While Senate Considers Genius Act, Russian Is Charged With Stablecoin Laundering (Wall Street Journal, 10 June 2025) <https://www.wsj.com/finance/regulation/while-senate-considers-genius-act-russian-is-charged-with-stablecoin-laundering-da507c74&gt; accessed 31 August 2025.

    [22]Financial Times, UK-Led Operation Destabilise Uncovers Global Stablecoin Laundering Network (Financial Times, 27 May 2025) <https://www.ft.com/content/8cf5e911-7821-40b1-8112-ba0f5e1ef071&gt; accessed 31 August 2025.

    [23]Vlad Vovk, ‘Europol Takes Down “Mafia Crypto Bank” Laundering Millions’ (Coinomist, 19 May 2025) <https://coinomist.com/news/europol-takes-down-money-laundering-mafia-crypto-bank/&gt; accessed 31 August 2025.

    [24]Financial Times, Stablecoin Issuers Mimic Shadow Banking Risks Without Oversight (Financial Times, 22 April 2025) <https://www.ft.com/content/321321b3-55ab-4152-88dd-bee3d41b5b6a&gt; accessed 31 August 2025.

    [25]Cointelegraph, ‘Crypto-Enabled Hawala Transactions: Legal and Regulatory Implications’ (Cointelegraph, 2024) <https://cointelegraph.com/explained/crypto-enabled-hawala-transactions-legal-and-regulatory-implications&gt; accessed 31 August 2025.

    [26]Chainalysis, Israeli Authorities Disrupt Hezbollah and Iran Quds Force Terrorism Financing Crypto Infrastructure, Seize $1.7 Million in USDT (Chainalysis Blog, 27 June 2023) <https://www.chainalysis.com/blog/israel-nbctf-hezbollah-iran-quds-crypto-seizure&gt; accessed 31 August 2025.

    [27]Adam Rousselle, Hezbollah’s Latin American Networks: Stablecoins, Smuggling, and Sanctions Evasion (GNET, 21 July 2025) <https://gnet-research.org/2025/07/21/hezbollahs-latin-american-networks-stablecoins-smuggling-and-sanctions-evasion/&gt; accessed 31 August 2025.

    [28]Tesco Supermarkets Ltd v Nattrass [1972] AC 153.

    [29]D’Aloia v Persons Unknown [2024] EWHC 2342 (Ch).

    [30]Tulip Trading Ltd v Bitcoin Association for BSV & Ors [2023] EWCA Civ 83.

    [31]Webber Wentzel, ‘Developers vs Owners: Who Does the Fiduciary Duty of Cryptocurrency Lie With?’ (Webber Wentzel, 3 February 2023) <https://www.webberwentzel.com/News/Pages/developers-vs-owners-who-does-the-fiduciary-duty-of-cryptocurrency-lie-with.aspx&gt; accessed 31 August 2025.

    [32]Kennedys, ‘Do software developers owe fiduciary duties to bitcoin owners? Court of Appeal considers there is a serious issue to be tried’ (Kennedys Thought Leadership, 25 May 2023) <https://kennedyslaw.com/en/thought-leadership/case-review/2023/do-software-developers-owe-fiduciary-duties-tobitcoin-owners-court-of-appeal-considers-there-is-a-serious-issue-to-be-tried/&gt; accessed 31 August 2025.

    [33]New York Central & Hudson River Railroad Co v United States 212 US 481 (1909).

    [34]Andrew Ashworth, Principles of Criminal Law (9th edn, OUP 2022) 254–256.

    [35]Iridium India Telecom Ltd v Motorola Inc, (2011) 1 SCC 211.

    [36]Standard Chartered Bank v Directorate of Enforcement, (2005) 129 Comp Cas 477 (Delhi HC).

    [37]European Securities and Markets Authority (ESMA), ‘MiCA Technical Advice’ (2023).

    [38]Bank for International Settlements (BIS), ‘An approach to anti-money laundering compliance for cryptoassets’ BIS Bulletin No 111 (2025).

    [39]FATF, ‘Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs’ (2021).

    [40]Dirk A. Zetzsche, Ross P. Buckley & Douglas W. Arner, The Distributed Liability of Distributed Ledgers (2018) 2018 U Ill L Rev 1361.

    [41]A Comprehensive Framework for Stablecoin Regulation (SEC, 2025).

    [42]Guiding and Establishing National Innovation for US Stablecoins Act 2025 (GENIUS Act 2025), Pub L No 118-394, 139 Stat 752 (18 July 2025).

    [43]Myths v Facts: The GENIUS Act (US Senate Committee on Banking, Housing, and Urban Affairs, May 2025) <https://www.banking.senate.gov/imo/media/doc/myths_v_facts_-_genius_act_5_8_25pdf.pdf&gt; accessed 31 August 2025.

    [44]Bank Secrecy Act (31 USC §§ 5311–5332).

    [45]Financial Crimes Enforcement Network, ‘Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies’ (Guidance, 9 May 2019).

    [46]Attorney General James Urges Congress to Pass Federal Legislation to Regulate Cryptocurrencies (Press Release, Office of the NY Attorney General, 10 April 2025) <https://www.ag.ny.gov/press-release/2025/attorney-general-james-urges-congress-pass-federal-legislation-regulate&gt; accessed 6 September 2025.

    [47]The GENIUS Act Risks U.S. National Security, U.S. Senate Committee on Banking, Housing, and Urban Affairs (Apr 2025) 2 <https://www.banking.senate.gov/imo/media/doc/The%20GENIUS%20Act%20Risks%20U.S.%20National%20Security.pdf&gt; accessed 31 August 2025.

    [48]International Emergency Economic Powers Act (IEEPA) 50 USC §§ 1701–1708.

    [49]US Department of the Treasury, U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash (Press Release, 8 August 2022) <https://home.treasury.gov/news/press-releases/jy0916&gt; accessed 6 September 2025.

    [50]Van Loon v Department of the Treasury (5th Cir, 26 November 2024).

    [51] US Department of the Treasury, Treasury Department Delists Tornado Cash (21 March 2025) https://home.treasury.gov/news/press-releases/sb0087 accessed 6 July 2026.

    [52]Paul Hastings, The GENIUS Act: A Comprehensive Guide to US Stablecoin Regulation (Client Alert, 18 July 2025) <https://www.paulhastings.com/insights/crypto-policy-tracker/the-genius-act-a-comprehensive-guide-to-us-stablecoin-regulation&gt; accessed 6 September 2025.

    [53]Apol·lònia Martínez Nadal, ‘Stablecoins in the MiCA Regulation’, in Governance and Control of Data and Digital Economy in the European Single Market (Springer 2025) 177–198.

    [54]Financial Services and Markets Act 2023 (UK).

    [55]Economic Crime and Corporate Transparency Act 2023 (UK).

    [56] Home Office, Economic Crime and Corporate Transparency Act 2023: Guidance to Organisations on the Offence of Failure to Prevent Fraud (6 November 2024, updated 10 October 2025) https://www.gov.uk/government/publications/offence-of-failure-to-prevent-fraud-introduced-by-eccta accessed 6 July 2026.

    [57]“A Tale of Two Jurisdictions: Contrasting Cryptocurrency Regulations in Hong Kong and the UK” (2023) Journal of Banking Regulation <https://www.sciencedirect.com/science/article/pii/S2949791425000260&gt;.

    [58]Payment Services Act 2022 (Japan) Act No. 59 of 2009, amended 2022.

    [59]Japan Financial Services Agency, ‘Stablecoin Regulation under the Payment Services Act’ (10 April 2025) <https://www.fsa.go.jp/en/news/2025/20250410_2/01.pdf&gt; accessed 6 September 2025.

    [60]Monetary Authority of Singapore, ‘MAS Finalises Stablecoin Regulatory Framework’ (15 August 2023) <https://www.mas.gov.sg/news/media-releases/2023/mas-finalises-stablecoin-regulatory-framework&gt; accessed 6 September 2025.

    [61]CNBC, ‘Hong Kong Passes Stablecoin Bill’ (23 May 2025) <https://www.cnbc.com/2025/05/22/hong-kong-passes-stablecoin-bill-as-more-governments-recognize-the-digital-assets-.html&gt; accessed 6 September 2025.

    [62]Central Bank of the UAE, Payment Token Services Regulation (C 2/2024, effective 31 August 2024) <https://rulebook.centralbank.ae/en/rulebook/payment-token-services-regulation&gt; accessed 6 September 2025.

    [63]Financial Intelligence Unit-India, ‘VDASP 04072023’ (4 July 2023) <https://fiuindia.gov.in/pdfs/downloads/VDASP04072023.pdf&gt; accessed 6 September 2025.

    [64] Financial Intelligence Unit–India, AML & CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets (VDAs) (8 January 2026).

    [65] Prevention of Money-laundering (Maintenance of Records) Amendment Rules 2023, GSR 107(E), rr 2(1)(sa) and 2(1)(wa).

    [66]Enforcement Directorate, ‘Freezing of Assets of WazirX Crypto Exchange’ (5 August 2022) <https://enforcementdirectorate.gov.in/sites/default/files/latestnews/PR%20HYZO_Freezing%20of%20assets%20of%20WazirX%20Crypto%20Exchange.pdf&gt; accessed 6 September 2025.

    [67] Finance Act 2025, s 3, amending Income-tax Act 1961, s 2(47A), with effect from 1 April 2026.

    [68]Elliptic, ‘Navigating the APAC Stablecoin Regulatory Landscape’ (26 July 2024) <https://www.elliptic.co/blog/navigating-the-apac-stablecoin-regulatory-landscape-with-ecosystem-monitoring&gt; accessed 6 September 2025.


    (Yukta Chanda and Netraa Rathee are fourth-year law students at National Law Institute University, Bhopal. They may be contacted via email at yuktachanda.ballb@nliu.ac.in and netraarathee.ballb@nliu.ac.in respectively.)

    Cite as: Yukta Chanda and Netraa Rathee, Stablecoins and Corporate Criminal Liability: Rethinking Responsibility in Cross-Border Financial Crimes, 28 July 2026 <https://rmlnlulawreview.com/2026/07/28/stablecoins-and-corporate-criminal-liability-rethinking-responsibility-in-cross-border-financial-crimes/>; date of access.



    Source link

    LEAVE A REPLY

    Please enter your comment!
    Please enter your name here