Securities Regulation Daily Wrap Up, BLOCKCHAIN—NASAA’s suggestions for crypto regulation include strong investor protections, robust disclosures, (May 28, 2025)
Organizations Mentioned:North American Securities Administrators Association
By Suzanne Cosgrove
Responding to an RFI from the SEC’s Crypto Task Force, the organization noted crypto has been “rife with fraud” and suggests the Commission consider the assets’ vulnerabilities when rulemaking.
The North American Securities Administrators Association (NASAA) last week sent the SEC a detailed list of recommendations that it said offers “principles and prescriptions” to the SEC’s Crypto Task Force that are intended to achieve balanced regulatory solutions for issuing and trading crypto-assets.
Investor protection must be the central part of any proposed regulation, NASAA said, and robust disclosures must be simple enough for novice investors to understand the risks of buying and trading crypto-assets—available on a trusted site that is administered by a regulator.
In addition, exemptive frameworks for crypto-assets and businesses are better than jurisdictional exclusions because they can be tailored and adjusted as circumstances change, and state anti-fraud and examination authorities must be preserved, NASAA said.
Investor protections. The world of cryptocurrencies “has been rife with fraud,” NASAA noted. “This is due in part to features of distributed ledger technology that can facilitate bad actors, particularly the pseudonymous nature of crypto-assets, their vulnerability to theft from hacking, and the irreversibility of blockchain transactions.”
The SEC Task Force should account for these unique features of cryptocurrencies when forming their recommendations, the group advised. So long as the SEC maintains a focus on solutions that protect investors, including robust disclosures and the preservation of antifraud authorities, it can pursue innovation in a way that is safe and confidence-boosting for investors and the markets, NASAA said.
Looking at potential trading activities, NASAA noted the SEC’s RFI asked if open-source data is sufficient for the market to monitor trading. It isn’t, NASAA said. Open-source data may be able to indicate improper trading, but it will not show who is involved. Crypto-asset intermediaries should therefore be required to follow “know your customer” requirements so they can answer regulator inquiries about potentially improper trading.
“Regulators need to have the same powers to monitor and examine crypto-asset intermediaries as currently exist for securities market intermediaries,” NASAA said. Further, trading platforms should be required to develop written policies and procedures to ensure that trades are legitimately authorized by customers.
Custody requirements. The RFI also asks whether the Commission should “amend existing rules, propose new rules, or provide guidance to facilitate custody arrangements for crypto assets.” In general, custody requirements should apply any time a customer gives an asset to an intermediary, NASAA said, and any new or amended rules should fully serve the purposes of existing custody requirements, namely, to protect customer assets from misuse, loss, theft, conflicts of interest, or the failure of the registrant holding them.
The group acknowledged crypto-asset wallets and encryption keys “present unique handling challenges,” but it added that necessary accommodations should be determined by the technological limitations of distributed ledger technology and not by the preferences of current crypto-businesses.
“Separate custody could also have prevented outright frauds like FTX,” NASAA said. “Further, there is nothing inherent in distributed ledger technology that prevents the use of current custody safeguards, including rigorous written policies and procedures, periodic and surprise audits, a robust examination schedule, and recordkeeping requirements.”
Cybersecurity warnings. The group said while the Commission’s RFI does not mention cybersecurity, it plays a critical role in the handling and safekeeping of crypto assets. U.S. exchanges are subject to Regulation SCI, which requires them to maintain strict cyber hygiene standards. “If anything, the cybersecurity needs of (crypto) trading platforms are even more critical,” NASAA said.
“Trading platforms have repeatedly fallen victim to hacking, and crypto-assets are particularly attractive to thieves because the irreversibility of blockchain trades means they are largely unrecoverable once stolen.” The platforms should meet standards at least as rigorous as those applied to exchanges, the group said.
RegulatoryActivity: Blockchain CyberPrivacyFeed DataSecurity SECNewsSpeeches