Most community banks will never custody a digital asset. Nearly all of them will encounter crypto anyway, through channels that have nothing to do with holding it — and the exposure that has actually damaged banks came through the least exotic channel available.
Deposits from crypto businesses. Exchanges, miners, payment processors, custodians, and their principals hold operating accounts. This is by far the most common channel for a community institution, requires no crypto capability whatsoever, and is where the realized losses have occurred.
Customers transacting with crypto platforms. Retail customers wiring or ACHing funds to and from exchanges. This creates BSA monitoring questions and a substantial fraud exposure, since crypto is the settlement rail of choice for investment scams and romance fraud.
Custody or safekeeping services, requiring capability the institution likely does not have.
Holding reserves for a stablecoin issuer — a deposit relationship with unusual liquidity characteristics.
Lending against digital assets as collateral, raising valuation, custody, and perfection questions with no settled answers.
Tokenized deposits and settlement experiments, largely confined to larger institutions.
Vendors with crypto exposure, which reaches the institution through third-party risk rather than directly.
The framing that matters: the first two channels are open to every bank right now, whether or not anyone has decided to enter this market.
The most important thing a community banker should take from this topic has nothing to do with blockchain.
In 2023, institutions with concentrated deposits from crypto-sector clients experienced rapid, correlated outflows. The deposits were conventional — dollar deposits in ordinary accounts — and the failure mode was conventional too: concentration in a single, highly correlated, rate- and confidence-sensitive customer segment, funding a balance sheet that could not liquidate fast enough.
Interagency statements issued in that period highlighted exactly this: liquidity risks arising from deposits placed by crypto-asset-related entities, whose behavior can be driven by conditions in crypto markets rather than by the depositor's own operations.
Four durable implications:
Concentration is the risk, not the technology. The same lesson applies to any correlated segment.
Deposit stability depends on the depositor's business, not the account type. An operating account for a business whose own funding can evaporate is not a stable deposit regardless of how it is titled.
Correlated outflow defeats normal liquidity planning. A contingency funding plan assuming independent depositor behavior does not model a sector-wide event.
Uninsured concentration compounds it, because large balances leave fastest.
An institution with meaningful deposits from this sector should be modeling a simultaneous outflow of the entire segment, not a proportional one.
These attach regardless of any permissibility question.
Crypto businesses may be money services businesses. FinCEN has treated certain convertible virtual currency businesses as money transmitters requiring registration. A bank serving such a customer should confirm registration status and treat the relationship as a money services business relationship, with the enhanced due diligence that implies.
Source of funds becomes genuinely hard. Tracing the origin of funds that passed through crypto markets is materially more difficult than tracing conventional flows, which raises the diligence burden rather than excusing it.
Blockchain analytics exist and are used. Institutions serving this sector are expected to have some capability to assess counterparty exposure, whether internally or through a vendor.
Sanctions exposure is real. Digital asset addresses have been designated, and sanctioned actors have used these channels. OFAC obligations apply with their usual strict liability.
Fraud typologies are distinctive. Investment scams, romance fraud, and pig-butchering schemes overwhelmingly settle in crypto, and the customer-facing indicator is a retail customer making unusual wires or purchases to a platform. This is a fraud and elder-exploitation control question as much as a BSA one.
A board-level decision, made explicitly and recorded.
If declining, the policy needs to define what is being declined — crypto business deposits, customer transactions with platforms, or both — with a means of identifying such customers at onboarding and in the existing portfolio, and consistent application. Institutions that decline informally serve some and not others with no recorded basis.
If engaging, the requirements are substantial: verification of the current supervisory position with the institution's own regulator, board risk acceptance, enhanced due diligence appropriate to money services businesses, blockchain analytics capability, monitoring calibrated to the sector, sanctions screening extended to digital asset exposure, concentration limits with liquidity modeling that assumes correlated outflow, and counsel engaged on the legal questions.
The concentration limit is the item most worth insisting on, because it is the control that would have mattered most in the episode described above.
Whatever the institution decides about the sector, tellers and personal bankers need three things:
Recognition of the scam pattern. A customer — frequently older, frequently describing a relationship or an investment opportunity — sending funds to purchase crypto, often having been told not to discuss it with the bank. This is the single highest-value crypto-related control in a community bank, and it is a fraud-prevention skill rather than a technical one.
Permission to slow the transaction down and escalate.
Accurate language about what the bank does and does not do, so nobody implies the institution holds, insures, or endorses digital assets.
Structured coverage of the underlying frameworks is available through our BSA training, AML training, the Certificate in BSA and AML Compliance, and bank fraud prevention training.
Worth understanding, because it explains why any dated article on this subject should be distrusted — including this one.
Bank regulators have moved through several postures in a short period: interpretive guidance addressing whether certain activities are permissible for national banks; subsequent expectations that institutions notify or obtain supervisory non-objection before engaging; and later revisions to those expectations. Accounting guidance on safeguarding obligations was issued and then superseded. Legislation addressing stablecoins was under consideration.
Three practical consequences for a compliance officer.
Verify with your own regulator, not from an article. Permissibility and notification expectations have differed by charter type and have changed, so the authoritative answer comes from the institution's primary federal regulator's current issuances.
Distinguish permissibility from prudence. An activity being permissible does not make it appropriate for a given institution's risk profile, capability, or capital.
Do not build on an expectation of a rule. The error pattern here mirrors cannabis banking: institutions that planned around anticipated legislation or anticipated guidance made commitments before the basis existed.
The durable content in this area is the risk analysis — concentration, liquidity correlation, BSA diligence difficulty, sanctions exposure, and the fraud typology. That analysis holds regardless of which posture the agencies currently occupy, which is why it is what this post leads with.
For the channel most community banks will actually face — a business in this sector wanting an operating account — the diligence looks different from ordinary commercial onboarding, and the questions worth asking are concrete.
What does the business actually do? "Crypto company" covers an exchange holding customer funds, a miner selling produced assets, a payment processor, a software developer with no custody function, an ATM operator, and a fund. Their risk profiles have almost nothing in common, and the first job is to place the customer precisely.
Does it hold customer funds? This is the pivotal question. A business holding assets for others carries obligations to those others, and its failure creates a population of harmed third parties with claims that reach into the bank's accounts. A business trading its own capital does not.
Is it registered where registration is required, and what is its own compliance program? An institution serving a money services business is expected to have assessed that program rather than accepted its existence.
Where do the funds come from and go? Counterparty exposure, jurisdictions, and whether the flows are consistent with the stated business. This is where blockchain analytics earn their cost.
How correlated is this deposit to crypto market conditions? A miner's balance behaves differently from an exchange's customer float, which behaves differently from a developer's payroll account. The liquidity question depends on the answer.
What happens to the account if the business fails? Whose money is in it, and can the bank tell?
Two structural controls are worth setting before the first such account opens. A segment concentration limit expressed as a proportion of total deposits, approved by the board, enforced in reporting, and low enough that a total outflow is survivable. And a requirement that these relationships be identifiable in the core system, coded so the institution can produce the segment's total balance on demand — several banks discovered during the 2023 episode that they could not readily determine their own exposure.
For most community institutions the honest conclusion is that a small number of well-understood relationships in this sector is manageable, and a concentration is not. The limit is the whole control.
One further note on customer conversations, because staff get asked. Customers do ask whether the bank has a view on digital assets, and the honest institutional answer is that the bank takes no position on the merits of any asset class and does not provide investment advice — which is both true and the only safe answer. What staff should avoid is the well-meaning middle ground: expressing a personal opinion, characterizing crypto as a scam in general terms, or implying the bank has evaluated a particular platform. The first two damage the relationship with customers who hold these assets legitimately, and the third creates an impression of diligence the institution never performed.
Primarily through deposits from crypto-sector businesses — exchanges, miners, processors, and their principals holding ordinary operating accounts — and through retail customers wiring or transferring funds to and from platforms. Neither requires any crypto capability, and the first is where banks have actually taken losses.
That institutions with concentrated deposits from crypto-sector clients experienced rapid, correlated outflows. The deposits were conventional dollar deposits; the failure was concentration in a single, highly correlated, confidence-sensitive segment funding a balance sheet that could not liquidate fast enough. An institution with meaningful exposure should model a simultaneous outflow of the whole segment rather than a proportional one.
Certain convertible virtual currency businesses have been treated by FinCEN as money transmitters requiring registration. A bank serving such a customer should confirm registration status and apply the enhanced due diligence appropriate to a money services business relationship, including scrutiny of source of funds, which is materially harder to trace through crypto markets.
Chiefly the scam pattern: a customer, frequently older, sending funds to purchase crypto in connection with a relationship or an investment opportunity, often having been instructed not to discuss it with the bank. Recognizing it, slowing the transaction down, and escalating is the highest-value crypto-related control in a community bank, and it is a fraud skill rather than a technical one.
Because it has changed repeatedly — permissive interpretive guidance, then notification and supervisory non-objection expectations, then revisions to those — with differences by charter type, alongside accounting guidance that was issued and superseded and legislation under consideration. The authoritative answer comes from the institution's own primary federal regulator's current issuances.
Not necessarily. Permissibility and prudence are separate questions. An activity a regulator permits may still be inappropriate for a particular institution's risk profile, operational capability, or capital position — and the institutions that got into difficulty generally treated permission as sufficient justification.


