Curaçao regulator issues crypto guideline for B2C licensees
- The Curaçao Gaming Authority has published a crypto policy guideline for B2C licensees, covering blockchain analytics, wallet controls, and high-risk asset restrictions.
- The guideline requires FATF Travel Rule compliance and prohibits operators from acting as exchanges, custodians, or payment service providers.
- The document is dated June 2025 but sets compliance deadlines of September 2026, December 2026, and June 2027.
The Curaçao Gaming Authority (CGA) has published a crypto policy guideline for B2C licensees, setting minimum controls for how digital assets are accepted, held, and processed in remote gambling operations.
The guideline applies across all crypto-asset workflows, covering deposits, wagering, withdrawals, and treasury management, and sits within the jurisdiction’s National Ordinance on Games of Chance (LOK) framework.
Analytics and AML controls
The CGA treats cryptocurrencies as high-risk assets, requiring licensees to conduct asset-specific risk assessments before accepting any digital currency. Fiat-backed regulated stablecoins are the authority’s preferred instrument for operator transactions.
Operators must deploy blockchain analytics tools capable of tracing and risk-assessing virtual asset transactions. Requirements cover wallet screening at the point of deposit, ongoing activity monitoring, source of funds verification, and destination wallet screening before outbound transfers.
The guideline names Chainalysis, Elliptic, and TRM Labs as examples of commonly used solutions. Equivalent functionality may be delivered through a combination of internal systems and external providers, and no single tool is mandated.
Existing AML/KYC obligations apply in full to crypto transactions. Operators must document crypto-specific controls within their AML/CFT policy on the CGA portal. The requirement reflects a widening international trend. Ireland this week published a national risk assessment naming gambling among its highest money-laundering risk categories.
The CGA itself required T&C rewrites from licensees in April, with cryptocurrency handling among the listed areas.
Operators may accept crypto from unhosted or self-custodied wallets and DeFi protocols, provided risk-based controls are in place. These include verifying wallet ownership or control, applying blockchain analytics to assess transaction risk, and carrying out enhanced due diligence where elevated risk is identified. The guideline states that such transactions must not impair the operator’s AML/CFT, monitoring, and reporting obligations.
The policy requires compliance with FATF Recommendation 16, the Travel Rule. Originator and beneficiary information must accompany all virtual asset transfers between regulated entities.
Operators are also prohibited from functioning as exchanges, custodians, or payment service providers. Converting crypto to fiat or other digital assets for players, and offering wallet or trading services outside gambling-related transactions, are expressly banned.
Prohibited assets and wallets
Funds linked to sanctioned mixers or tumblers, and wallet addresses on applicable sanctions lists or flagged by recognised blockchain analytics providers, are prohibited outright. The CGA reserves the right to designate additional asset types as prohibited.
Privacy-enhancing cryptocurrencies require specific policy treatment. The guideline references Monero, Zcash (including shielded transactions), Dash where privacy features are active, and Litecoin’s MWEB as examples. These assets can obscure transaction data, preventing effective monitoring and source-of-funds verification.
Wrapped or bridged assets are not permitted where the provenance of the underlying asset cannot be independently verified. Wrapped Bitcoin is cited as one example, given the additional opacity and counterparty risk introduced by custody and bridging arrangements.
Meme coins and highly speculative tokens are not subject to a blanket ban. The guideline requires operators to categorise and assess them against objective criteria: liquidity and volatility profile, governance maturity, and financial-crime risk considerations such as anonymity-enhancing design features.
Personal wallets, UBO-linked wallets, and informal wallet arrangements are prohibited. All operator wallets must be owned or controlled by the licensed legal entity and segregated between player-flow, operational, and treasury purposes. Player funds must be held in segregated wallets at all times.
A hot, warm, and cold wallet architecture is permitted, provided each tier has documented access controls, approval procedures, and audit trails. Multi-signature controls, withdrawal whitelisting, and hardware security modules are expected where proportionate to the value and risk involved.
Withdrawals should, as a default, be processed to the same wallet and in the same crypto asset as the original deposit. Alternatives are permitted where the destination wallet has been whitelisted and passed KYC/AML checks. They are also permitted where conversion is conducted via a regulated VASP with a fully auditable transaction record.
Implementation deadlines
The guideline carries a June 2025 date, but its transition provisions reference compliance deadlines of September 2026, December 2026, and June 2027. The CGA has not publicly explained the discrepancy.
Certain prohibitions take immediate effect under the guideline. These cover sanctioned wallets, mixer-linked assets, prohibited crypto assets, and personal or UBO-linked wallets.
By September 2026, licensees must upload a compliant crypto policy to the CGA portal with a clear adoption timeline. December 2026 is the deadline for completing risk assessments, VASP due diligence, wallet ownership controls, transaction monitoring procedures, and staff training.
Full implementation, including wallet segregation, blockchain analytics capability, reconciliation processes, and audit-ready record-keeping, is required by June 2027.
The CGA may require earlier compliance where material risks are identified. For operators holding CGA licences and accepting cryptocurrency, the September portal deadline is the first concrete test of post-LOK compliance readiness.
The crypto platform closures seen throughout 2025 and 2026 have signalled where regulators stand. Operators without formalised blockchain compliance infrastructure face the most significant work ahead.
Do you have a story worth sharing?
Send it over to our editors!