On June 9, 2026, Hyperliquid Policy Center and Paradigm filed a joint comment on the U.S. Treasury’s proposed AML/CFT and sanctions rules for payment stablecoin issuers.

At first glance, this is a U.S. policy fight around the GENIUS Act. For Eurasian markets, the useful question is sharper: how far can issuer obligations extend into DeFi once the issuer no longer has the customer in front of it?

What happened

The Block reported that Hyperliquid Policy Center and Paradigm asked the U.S. Treasury to revise a proposed anti-money laundering rule.

In their primary comment, HPC and Paradigm say they broadly support FinCEN’s primary-market approach. Their objection is about secondary-market obligations, especially OFAC’s treatment of smart contract interactions.

The core facts:

  • FinCEN and OFAC published the proposed rule in April for permitted payment stablecoin issuers.
  • Primary market activities include issuance, redemption, and custody, where the issuer usually knows the customer.
  • Secondary market activities include downstream transactions, peer-to-peer transfers, and trading through DeFi protocols.
  • HPC and Paradigm ask the agencies to clarify lawful-order obligations, customer relationship for CDD, the definition of payment stablecoin-related activity, and sanctions treatment of smart contract interactions.

How I read it

The secondary-perimeter test asks where a compliance duty is still attached to real control, and where it becomes liability for infrastructure the issuer does not directly operate.

Issuance and redemption are natural AML control points. There is a customer relationship, KYC, a redemption flow, bank accounts, reserves, and an operating perimeter. If an issuer sells the token directly to a customer, the question “why did you not know your customer?” is fair.

The secondary DeFi market is different. The issuer may see addresses and amounts, but often does not see the owner, the economic context, the transaction purpose, or the protocol path across contracts. If the rule makes the issuer responsible for any downstream smart-contract use, the rational response is to avoid issuing regulated stablecoins into permissionless environments.

For DeFi, that is a bad incentive design. It does not make the secondary market more transparent. It makes regulated dollar stablecoins less available in open protocols.

Why this matters outside the US

Eurasian regulators are still assembling their stablecoin oversight models. Uzbekistan has chosen a pilot regime for fiat-backed stable tokens. Kyrgyzstan is testing the state-backed USDKG. Georgia has shown a private issuer under a state framework.

All of those models will face the same technical question: what remains inside the issuer’s responsibility after the token leaves the primary perimeter?

If a country is building a closed payment product, the answer is easier. The issuer, wallet operator, and payment rail can sit inside one regulated scheme. If a country wants the token to live on public networks, the question changes: the secondary market cannot be described with the same language as a bank account.

I would treat this as an early stress test for any Eurasian stablecoin policy. A good rule has to separate three layers:

  • who issues and redeems the token;
  • who has the direct customer relationship;
  • who only writes, validates, or uses open infrastructure.

Collapsing those layers creates the appearance of control. In practice, it pushes stronger issuers toward permissioned rails and leaves open markets to actors that were never planning to follow local rules.

What this changes

For issuers, the question is no longer only reserves and redemption. They will have to prove where their compliance perimeter ends.

For DeFi protocols, this is a signal that sanctions and AML design will increasingly arrive through the stablecoin layer rather than through direct licensing of every protocol.

For regulators in Central Asia and the Caucasus, my practical rule would be: obligations should follow control. If a participant has the customer, balance sheet, custody, or redemption, full AML process belongs there. If a participant only provides an open smart-contract layer, the tool should be different: address blocklists, disclosure, monitoring, forensic cooperation, but not a fictional customer-checking duty.

What to watch

  • The final Treasury rule: if OFAC narrows secondary-market language, the U.S. will offer a model for regulated stablecoins in DeFi.
  • The customer relationship definition: if it excludes secondary-market holders with no direct issuer relationship, other jurisdictions will notice.
  • Smart contract interactions: if they remain a “provision of services” under strict-liability logic, regulated issuers will move toward permissioned deployments.
  • Circle, Paxos, and bank issuer reactions: their compliance policies will show how the rule is read by operators, not only lawyers.
  • Translation into Eurasian regimes: the next local stablecoin framework will be tested not only by reserves, but by how it treats secondary-market use.

A rule that cannot tell control from infrastructure can look strict on paper while weakening the market design it is meant to protect.


Bakhrom Kholmatov has been in DeFi since 2017. Designed risk frameworks, DeFi agents, and risk-monitoring systems for tokenized assets.