By Nick Smart, Chief Intelligence Officer at Crystal
New York has one of the most developed crypto regulatory environments in the US, yet significant unlicensed activity persists alongside it. Crystal Intelligence’s research identified 62 cash-to-crypto services operating in New York without the required licenses, including 48 that offer physical cash transactions. Some also support privacy-focused assets, creating additional challenges for businesses attempting to understand their exposure.
Crystal’s recent webinar examined what this means for compliance teams operating in one of the world’s most closely watched crypto markets. Moderated by Nick Smart, Chief Intelligence Officer at Crystal, the discussion brought together Daniella Labarbera, VP of Business Development and Sales for North America at Sumsub; Johanna Collins-Wood, General Counsel and Head of Compliance for US Asset Management at Bitwise Asset Management; and Ryan Rasmussen, Head of Research at Bitwise.
The discussion explored the relationship between regulated and unlicensed activity, the growing importance of counterparty due diligence, and the influence of regulatory expectations on institutional participation in crypto.
Only got a New York minute to spare? Catch the compact webinar summary here.
Key takeaways
- KYB is becoming continuous. Establishing a business’s identity and regulatory status at onboarding is only the beginning. Changes in ownership, licensing, and business activity require ongoing monitoring.
- Licensing must match the activity. A company can hold legitimate regulatory credentials without being authorized to provide every service it offers.
- Compliance influences institutional access. Regulatory standing, qualified custody and exchange support can determine whether an asset is eligible for institutional investment products.
- Self-custody changes where obligations sit. The panel expects greater regulatory attention on businesses facilitating transactions rather than individual wallet addresses.
- Compliance needs to work alongside businesses. Effective programs require operationally realistic policies and close collaboration between legal, compliance, and commercial teams.
How big is New York’s unlicensed crypto economy under the BitLicense?
New York provides an important case study because of the maturity of its regulatory framework. Despite its established licensing requirements, Crystal’s research identified 62 cash-to-crypto services* operating without appropriate authorization. Of those, 48 offered physical cash transactions, while many maintained operations across other major cities and financial centers.
Above: New York cash-for-crypto figures labeled unlicensed: 63 services (live-accurate, point-in-time count), 1,156 listings, 48 taking physical cash, $593M losses, 443 cities, 85% London overlap. Source: Crystal Intelligence.
The research also identified approximately $593M in crypto fraud losses in New York, representing a 58% year-over-year increase. Although these figures describe different aspects of the market, together they illustrate the financial crime environment in which regulated institutions operate.
Privacy-focused assets introduce another dimension. Several of the identified services supported Monero, Dash, or Zcash, while Crystal’s monitoring revealed a decline in Monero holdings among these providers over a six-month period. During the webinar, Nick suggested that increased cash-to-Monero conversions could explain some of this activity, although the international operations of these businesses make it difficult to attribute the trend specifically to New York.

Above: Chart showing privacy-coin cash desks in New York: bi-directional conversion counts for Monero, Dash and Zcash across 62 exchangers, with a $10,000 minimum ticket. Source: Crystal Intelligence.
The concern for regulated businesses is how these services interact with the wider financial system. Unlicensed operators still require liquidity and access to crypto, potentially bringing them into contact with regulated exchanges and other financial institutions. Understanding those relationships by tracing how funds move between them is becoming an increasingly important compliance responsibility.
*62 in historical total as of late September 2026.
Why does KYB need to go beyond onboarding?
Daniella identified Know Your Business (KYB) as an area facing increasing regulatory pressure. While Know Your Customer (KYC) has received considerable attention across the crypto industry, the ability to identify and continuously assess corporate counterparties is becoming equally important.
Traditional KYB establishes whether an entity legally exists, remains in good standing and has identifiable ultimate beneficial owners. However, Daniella described a shift toward perpetual or reusable KYB, involving continuous, event-driven rescreening throughout the customer relationship.
This reflects the reality that businesses change after onboarding. Their ownership structures may evolve, licenses can expire, and new activities may be introduced that fall outside their original authorization. A counterparty assessed as relatively low risk when the relationship began may therefore present a different risk profile several months later.
For compliance teams, this means examining whether declared business activities align with observed operations and whether regulatory permissions continue to cover the services provided. The initial onboarding decision becomes the starting point for an ongoing assessment rather than the conclusion of due diligence.
Why is having a Bitlicense not enough?
Johanna explained that licensing assessments are particularly important in the US, where regulatory authorization depends heavily on the activity a business conducts. Before establishing partnerships or counterparty relationships, Bitwise reviews formation documents, regulatory records, and licensing information, sometimes using external assistance to support its assessment.
A money services business registration, for example, is not equivalent to holding a New York BitLicense. Similarly, state money transmission licenses do not automatically authorize activities such as custody. A company may therefore be legitimately registered without possessing the permissions required for a particular service.
This creates additional complexity for businesses operating across multiple US states, where regulatory requirements and licensing arrangements can differ. Compliance teams must establish which activities their counterparties conduct, where those activities take place and whether the relevant authorizations cover them.
The discussion also reinforced the importance of reviewing these relationships as businesses evolve. A company that originally provided one service may subsequently introduce additional products or expand into new markets, making ongoing verification essential.
How does regulation influence institutional investment?
Regulatory compliance also affects which crypto assets institutional investors can access. Ryan explained that investors increasingly consider an asset’s regulatory position alongside traditional investment criteria, with particular attention to where it can be traded, how it can be custodied and whether its associated project has faced enforcement action.
The Bitwise 10 Large Cap Crypto Index provides an example. In addition to eligibility criteria such as liquidity and market capitalization, assets must be supported by specified US-regulated exchanges and qualified institutional custodians. These requirements can influence whether an asset is eligible for inclusion before an investment decision is made.
Privacy coins illustrate the challenges involved. Ryan acknowledged that privacy has been an important feature of cryptocurrency since its earliest development, with continuing interest in technologies such as Monero and Zcash. However, regulatory uncertainty surrounding privacy-focused assets means they are excluded from certain Bitwise public funds.
This creates a commercial consideration for crypto projects and service providers. Regulatory standing and access to compliant infrastructure can influence institutional participation, making compliance an important factor in how businesses develop their products and approach potential partners.
How can New York crypto compliance become a foundation for growth?
The panel also explored how attitudes toward compliance have changed as the cryptocurrency industry has matured. Nick recalled the historical description of compliance officers as “General No,” reflecting the perception that their primary responsibility was to prevent businesses from taking risks.
Daniella argued that successful businesses increasingly recognize compliance as an integral part of their growth strategy. Organizations that establish robust processes early are better positioned to adapt as regulatory expectations evolve, while those treating compliance as an obstacle may encounter difficulties when attempting to scale.
Johanna described a similar shift across the industry. Having worked as a crypto lawyer since 2017, she has observed businesses move away from the assumption that new technology necessarily operates outside established financial regulation. The discussion now focuses more heavily on determining how existing frameworks apply to new products and where further regulatory clarification is required.
Ryan highlighted the continuing influence of FTX on institutional perceptions of cryptocurrency. Although its collapse occurred in 2022, it remains relevant to investors who may have spent the intervening years focusing on other markets. Businesses seeking institutional partnerships must therefore recognize that confidence in their governance and compliance arrangements can influence commercial decisions.
When asked whether tighter regulation could have prevented FTX, Johanna cautioned against assuming that additional rules can eliminate deliberate fraud. Regulation provides important oversight and enforcement mechanisms, but businesses must also establish the internal controls and accountability necessary to operate responsibly.
Can self-custodial wallets be regulated?
An audience question introduced another challenge: managing cross-border B2B payments involving self-custodial wallets, particularly in emerging markets.
The panel broadly agreed that regulating individual wallets directly presents significant practical difficulties. Unlike a traditional financial institution, an individual wallet may have no identifiable business or intermediary for regulators to supervise.
Daniella suggested that regulatory attention is therefore more likely to concentrate on the businesses facilitating transactions. She described these as regulatory “choke points,” where obligations involving wallet screening, counterparty verification, and transaction monitoring can be applied.
Johanna agreed that businesses that conduct activities involving self-custodial wallets offer more practical opportunities for supervision. Companies that facilitate transfers or convert digital assets can be subject to registration and licensing requirements, depending on their activities and jurisdiction.
Ryan also highlighted the development of regulated platforms offering self-custodial capabilities. This could create additional opportunities for institutional adoption while allowing businesses to maintain appropriate compliance arrangements.
For compliance teams, the distinction is important. Self-custody does not automatically remove compliance responsibilities, but it can change which parties are responsible and how those obligations are fulfilled. Understanding the structure of the transactions and the businesses involved remains essential.
How should firms prepare for changes to New York crypto regulation?
The discussion also addressed the evolving US regulatory environment and the uncertainty surrounding comprehensive federal crypto legislation.
Johanna explained that regulatory development continues even when major legislation remains unresolved. Agencies including the SEC and CFTC can introduce proposals and regulatory measures that affect the industry, while businesses have opportunities to participate in consultations and respond to proposed rules.
For companies operating in New York and elsewhere in the US, this creates a need for compliance programs that can accommodate change. Businesses must remain informed about regulatory developments while ensuring their existing policies continue to reflect their activities and obligations.
The panel’s practical recommendations reflected this emphasis on adaptability. Daniella encouraged businesses to approach compliance proactively and thoroughly, while Johanna recommended reviewing compliance manuals directly with business teams to ensure documented procedures work in practice.
Ryan emphasized the importance of investing in experienced legal and compliance professionals. At Bitwise, close collaboration between these teams and the wider business helps inform product development, partnership assessments and commercial decisions.
Together, these recommendations highlight the importance of integrating compliance into everyday operations rather than treating it as a separate function that reviews decisions after they have been made.
Frequently asked questions
What should firms check when conducting KYB on a crypto business?
KYB should establish the business’s legal existence, ownership, and regulatory standing. Ongoing monitoring should also identify changes in ownership, licensing, and business activities that could affect its risk profile.
Does having a US crypto license authorize every crypto activity?
No. Regulatory requirements depend on the activity being conducted and the relevant jurisdiction. Compliance teams need to verify that a counterparty holds the appropriate authorizations for the specific services it provides.
Why does regulatory status matter when assessing a crypto asset?
Institutional investors may consider whether an asset is supported by regulated exchanges and qualified custodians, as well as its regulatory and enforcement history. These considerations can influence eligibility for institutional investment products.
Are self-custodial wallets exempt from compliance requirements?
Self-custody does not automatically remove compliance obligations. Depending on the applicable regulatory framework, businesses facilitating or originating transactions involving self-custodial wallets may have screening, verification and other compliance responsibilities.
What does this mean for crypto compliance teams?
New York demonstrates the complexity of operating in a mature crypto market where regulated institutions and unlicensed services exist within the same wider ecosystem. Crystal’s New York Regulation & Risk Report 2026 examines the financial crime risks associated with New York’s crypto market, including unlicensed cash-to-crypto services, fraud exposure, and privacy-focused assets.

For compliance teams, understanding that environment requires continued attention to counterparties, licensing arrangements, and the infrastructure supporting individual assets.
The webinar highlighted a consistent direction across these challenges. Counterparty assessments need to continue beyond onboarding, licensing checks must reflect actual business activities, and compliance processes need to evolve alongside new technologies and regulatory expectations.
As institutional participation develops, businesses also face growing expectations from potential partners and customers. The ability to demonstrate credible, operationally effective compliance arrangements can influence access to investment, partnerships, and new markets.
Watch the full webinar here.
Disclaimer: Views expressed by panelists are their own and do not necessarily reflect the position of Crystal Intelligence. This summary is for informational purposes only and is not legal, compliance, financial or investment advice.
