Crypto Regulation & Tax: The Principles
How crypto is regulated and taxed worldwide, at the level of principles that hold everywhere: KYC and AML, Travel Rule, MiCA, taxable events, reporting. Not legal or tax advice.
Quick answer
Crypto regulation is older law - anti-money-laundering, securities, payments, and tax - applied to a new technology, and it lands mostly on the exchanges and custodians in the middle rather than the network itself. Expect KYC checks, transfer-information rules, token classification fights, and property-style taxation of disposals. Details differ by country and change often; principles travel, specifics do not. This is not legal or tax advice.
10 things to know about crypto regulation & tax
Principles-level orientation, not legal or tax advice. Rules differ by country and change - confirm your own jurisdiction with a qualified professional.
| # | Topic | What it means | Why it matters |
|---|---|---|---|
| 01 | Why crypto is regulated | Rules target four harms: financial crime, investor harm, financial stability, and untaxed gains. | Asking which harm a rule targets explains its shape and why several regulators touch one asset. |
| 02 | KYC and AML | Regulated crypto businesses must identify customers, monitor activity, and report suspicious transactions. | The duties fall on intermediaries, not the protocol or individuals, which shapes the whole field. |
| 03 | FATF Travel Rule | Sender and recipient information must travel with transfers between regulated crypto businesses. | It extends a banking rule to crypto and treats self-hosted wallet transfers with extra scrutiny. |
| 04 | Security vs commodity | The Howey test decides if a token is a security; commodities fall to a different regulator. | Classification sets which rulebook applies and can differ by jurisdiction and change over time. |
| 05 | EU MiCA | A single comprehensive EU regime that classifies tokens and licenses service providers. | It is the most-copied template worldwide, so learning it helps you read other regimes. |
| 06 | US landscape | Overlapping federal agencies and state laws apply pre-existing rules, largely through enforcement. | You must always ask which regulator and which level of government a development concerns. |
| 07 | UK regime | AML registration with the FCA today, moving toward full conduct regulation of core activities. | FCA registration is an anti-money-laundering permission, not an endorsement of a firm or product. |
| 08 | Taxable events | Crypto is usually property, so disposals - selling, swapping, spending - can be taxable. | Swaps and small purchases feel like using money but are disposals that can trigger tax. |
| 09 | Cost basis and records | Gain equals proceeds minus what you paid; unsubstantiated basis can default to zero. | Contemporaneous records of every acquisition and disposal decide whether your return is defensible. |
| 10 | Reporting and CARF | Exchanges increasingly report to tax authorities, and CARF exchanges data across borders. | Activity through regulated on-ramps is becoming visible to your home tax authority by default. |
Key points
Crypto rules target four harms - financial crime, investor harm, financial stability, and untaxed gains - using tools borrowed from existing legal traditions.
Anti-money-laundering duties (KYC, monitoring, reporting) fall on intermediaries such as exchanges and custodians, not on the protocol or individual users.
The FATF Travel Rule requires sender and recipient information to travel with transfers between regulated crypto businesses, mirroring bank wire rules.
Whether a token is a security or a commodity turns on facts (the Howey test), can differ by jurisdiction, and can change as a network decentralises.
The EU's MiCA is a single comprehensive regime and the most-copied global template; the US relies on overlapping agencies and enforcement instead.
In most jurisdictions crypto is taxed as property: disposals (selling, swapping, spending) can be taxable, and CARF is making cross-border reporting automatic.
Almost every question people ask about crypto rules turns out to be two questions wearing the same coat. One is a matter of principle that is broadly stable across the world: does a given activity look like moving money, offering an investment, or realising a gain? The other is a matter of local detail that changes constantly: which agency has jurisdiction, which threshold applies, which form is due, and by when. This guide deals almost entirely with the first kind of question. It is a map of the ideas that recur everywhere, so that when you read a rule in your own country you already recognise the shape of it.
Crypto regulation is not one field. It is the collision of several older fields, each of which reached the technology from a different direction: anti-money-laundering law arrived through the exchanges, securities law through token sales, tax law through the simple fact that people made and lost money, and payments law through stablecoins. Understanding regulation means understanding which of these lenses a regulator is looking through at any given moment, because the same token can be a security to one authority, a commodity to another, and property to the tax office, all at once and without contradiction. The sections below take each lens in turn, then bring them together in a regional table and a plain account of how tax principles actually work.
This article is principles-level general information for education only. It is not legal advice, not tax advice, and not investment advice, and it does not create any professional relationship. Crypto rules differ significantly from one country to the next and change frequently, sometimes with little notice. Nothing here is a substitute for guidance from a qualified lawyer or tax professional who knows the facts of your situation and the law in your jurisdiction. Where we describe a threshold, a date, or an agency, treat it as an orientation point to verify against a primary source, not as a current statement of the law where you live.
The key ideas in crypto regulation
Ten ideas do most of the work. If you hold these clearly, almost every headline about a new rule, enforcement action, or tax change will slot into place as a variation on something you already understand. They are ordered roughly from the general to the specific: why regulation exists at all, then the identity and anti-crime rules that touch ordinary users first, then the classification fights that decide who regulates what, then the major regional frameworks, and finally the tax and reporting principles that reach almost everyone who transacts.
1. Why crypto is regulated at all
It helps to start with the motive, because regulators are not reacting to the technology in the abstract. They are reacting to specific harms that the technology makes easier or cheaper. Broadly there are four. The first is financial crime: pseudonymous, borderless, near-instant transfers are attractive to money launderers, sanctions evaders, ransomware operators, and fraudsters, and the international system that governs the traditional financial sector was not built to see them. The second is investor and consumer harm: unregistered offerings, opaque exchanges, custodial failures, and outright fraud have cost ordinary people real savings, and the law that exists to prevent this in stocks and deposits did not automatically extend to tokens.
The third motive is financial stability and monetary sovereignty, which arrived late but forcefully with stablecoins. A privately issued instrument that promises to be worth one unit of a national currency, held by millions, begins to look like a bank or a payment system, and authorities that manage the money supply do not want a parallel one they cannot see or backstop. The fourth is taxation: governments assert that gains are gains regardless of the asset class, and a large, fast-growing pool of untaxed activity is intolerable to a treasury. Every rule you will meet is an attempt to address one of these four harms with tools borrowed from an existing legal tradition. When a rule seems strange, asking which harm is this aimed at usually explains it. It also explains why the same asset attracts several regulators: a stablecoin can raise crime, consumer, stability, and tax concerns simultaneously, and each concern belongs to a different agency.
2. KYC and AML: know your customer, catch the money
The rule ordinary users meet first is not a crypto rule at all. It is anti-money-laundering (AML) law, applied to crypto businesses the same way it applies to banks. Its front door is Know Your Customer (KYC): the requirement that a regulated business identify and verify who its customers are before serving them, which is why a centralised exchange asks for a government ID, a selfie, and a proof of address. Behind KYC sits the larger AML programme the business must run: risk assessment, ongoing transaction monitoring, sanctions screening, record-keeping, and the filing of suspicious activity reports to a national financial-intelligence unit when something looks wrong. See our companion explainer on KYC and AML in crypto for how these obligations play out in practice.
The important principle is where these duties land. They fall on intermediaries — the exchanges, custodians, and payment firms that stand between users and the network — not on the protocol or on individuals transacting for themselves. In United States terms, an exchange is typically a money services business and specifically a money transmitter under the Bank Secrecy Act; FinCEN's guidance made clear as early as 2013 that administrators and exchangers of convertible virtual currency carry these obligations while ordinary users do not. Around the world the label differs but the logic is the same: if you hold or move value for other people, you inherit the bank's compliance burden. This is also why self-custody feels lightly regulated by comparison. There is no intermediary to place the duty on. That gap between the regulated on-ramps and the unregulated open network is the single most important tension in the whole field, and most new rules are attempts to narrow it.
It is worth being precise about what KYC is and is not. It is not a judgement about you or your funds; it is a standardised process a business must run to satisfy a regulator that it knows who it is dealing with. The corollary matters for security: because regulated businesses hold verified identity data, they become targets, and the personal information you hand an exchange is only as safe as that exchange's own controls. FinCEN sharpened its guidance in 2019 to cover a wider range of business models involving convertible virtual currency, including certain peer-to-peer arrangements and mixing services, underlining that the analysis is about the activity — moving value for others — rather than the label a service gives itself. The recurring lesson is that AML obligations follow function, not branding, and that a service calling itself decentralised is not automatically outside them.
3. The FATF Travel Rule
The Financial Action Task Force (FATF) is the intergovernmental body that sets the global standards for combating money laundering and terrorist financing. It has no power to make law itself; instead its Recommendations are adopted by member jurisdictions and enforced through mutual evaluation and the reputational cost of being listed as non-compliant. In 2019 FATF extended its standards to cover virtual assets and virtual asset service providers (VASPs), the international vocabulary that most national rules now echo.
The most consequential piece is the Travel Rule, drawn from FATF Recommendation 16. In traditional finance, information about the sender and recipient of a wire "travels" with the payment so that each bank in the chain can screen it. The Travel Rule applies the same expectation to crypto transfers between VASPs: the originating provider must obtain and transmit required originator and beneficiary information — names, account or wallet identifiers, and further identifying details — to the receiving provider, and both must screen it. FATF sets a de minimis threshold of USD/EUR 1,000, below which a lighter set of information may apply, though jurisdictions may set it lower and some, such as the European Union, apply the requirement with no threshold. Two features make the rule genuinely hard. First, it assumes both ends are regulated VASPs, so transfers to and from self-hosted (unhosted) wallets sit awkwardly outside its normal flow and attract extra scrutiny. Second, there was no native way for providers to exchange this data, so an industry of interoperating Travel Rule messaging solutions had to be built. The Travel Rule is the clearest example of the field's central move: take a rule that already governs banks and stretch it over crypto's intermediaries.
4. Is it a security or a commodity?
In the United States especially, the fiercest and longest-running question is classification: is a given token a security, a commodity, or something else? The answer decides which regulator has authority, which rulebook applies, and whether an offering needed registration and disclosure. Securities fall largely to the Securities and Exchange Commission (SEC), whose mission is investor protection through disclosure; commodities and their derivatives fall largely to the Commodity Futures Trading Commission (CFTC), whose mission is market integrity.
The test that decides it is the Howey test, from a 1946 Supreme Court case about orange groves. An arrangement is an "investment contract" — and therefore a security — when there is an investment of money in a common enterprise with a reasonable expectation of profit derived from the efforts of others. The last clause does the heavy lifting for crypto. A token sold to fund a project, whose value depends on a central team delivering a roadmap, looks like a security. A token on a network so decentralised that no identifiable group's efforts drive its value looks less like one; this is the reasoning behind the widely noted view that Bitcoin is not a security, and behind the argument that a token can begin life as a security and later cease to be one as its network matures. Because the test is applied to facts rather than declared by category, classification has been fought largely through enforcement and litigation rather than settled by a clean rulebook, though the SEC and CFTC have moved toward jointly clarifying how the securities laws apply to crypto assets. For a user, the practical takeaway is modest but real: a token's legal character is not fixed by its marketing, it can differ by jurisdiction, and "commodity" does not mean "unregulated".
5. The European Union: MiCA
The European Union took the opposite path to the United States. Rather than litigate classification case by case, it wrote a single, comprehensive regime: the Markets in Crypto-Assets Regulation (MiCA), Regulation (EU) 2023/1114, with the European Securities and Markets Authority (ESMA) and the European Banking Authority developing the technical detail. Because it is a Regulation rather than a Directive, it applies directly and fairly uniformly across all member states, which is what makes it the most-copied crypto framework in the world.
MiCA's design rests on two ideas. First, it classifies crypto-assets not already covered by existing financial law into a few buckets and regulates the issuer of each: asset-referenced tokens (stablecoins referencing a basket or multiple currencies or assets), e-money tokens (stablecoins referencing a single official currency), and other crypto-assets such as utility tokens, each with its own disclosure and, for the stablecoin types, reserve and governance requirements. Second, it licenses the businesses: any firm providing crypto-asset services — an exchange, a custodian, a broker — must be authorised as a crypto-asset service provider (CASP) and then carries obligations on custody, conflicts, complaints, and market abuse. The rules for stablecoin-type tokens began applying in mid-2024 and the CASP and broader provisions from 30 December 2024, with a transitional window for existing firms that ESMA has indicated runs up to 1 July 2026, subject to each member state's discretion to shorten it. The significance for the rest of the world is less the detail than the template: identify the token types, regulate their issuers, license the intermediaries, and passport the result across a single market.
6. The United States landscape
The United States has no single crypto statute of MiCA's kind. Instead it has a crowded field of authorities applying pre-existing laws, which is why its regime is best understood as a map of overlapping jurisdictions rather than a rulebook. At the federal level, the SEC pursues tokens and platforms it views as dealing in securities; the CFTC treats Bitcoin and Ether as commodities and polices derivatives and fraud in the spot market; FinCEN administers the Bank Secrecy Act and treats exchanges as money transmitters; the IRS taxes digital-asset activity as property; and the Office of the Comptroller of the Currency and the banking agencies govern how banks touch the space.
Layered on top of the federal picture is the states. Money transmission is licensed state by state, so a US exchange typically needs a mosaic of state money-transmitter licences in addition to its federal registrations, and New York's bespoke "BitLicense" is the best-known example of a state going further still. The result for anyone reading US developments is that you must always ask which regulator and which level of government a story concerns, because a favourable position with one says nothing about the others. It also means US rules have been made substantially through enforcement actions and court decisions rather than through comprehensive legislation, so the "law" on a given question is often a pattern read across cases rather than a clean statute — though targeted federal legislation, particularly around stablecoins and market structure, has been the direction of travel. Treat any single US data point as one tile in a large and shifting mosaic.
7. The United Kingdom regime
The United Kingdom sits between the American and European models and is mid-transition. Its established layer is anti-money-laundering: since 2020 a crypto business operating in or from the UK must register with the Financial Conduct Authority (FCA) under the Money Laundering Regulations, and the FCA supervises and enforces that regime. Crucially, this registration has historically been an AML permission only — it is not a seal of approval on a firm's soundness or its products, a distinction the FCA itself stresses and that consumers frequently misread.
Alongside this, the UK has brought the promotion of cryptoassets within its financial-promotions rules, so marketing to UK consumers must be fair, clear, not misleading, and carry risk warnings and cooling-off frictions. The larger change is the move, in progress, to bring core crypto activities — operating a trading platform, custody, dealing, and stablecoin issuance — inside the FCA's full regulatory perimeter for the first time, rather than treating them as an AML-only concern. Because that broader authorisation regime is being phased in through secondary legislation and FCA rulemaking, the exact commencement dates and perimeter are still settling; describe them qualitatively and check the FCA's own pages before relying on any specific deadline. On tax, HMRC treats cryptoassets as property and sets out its approach in the Cryptoassets Manual, applying Capital Gains Tax and, in some cases, Income Tax; the tax section below covers the shared principles that this reflects.
8. Taxable events: when a transaction is a taxable event
The most useful tax idea to internalise is the taxable event: the specific moment a transaction crystallises something the tax system cares about. In most major jurisdictions the foundational choice was made years ago and is remarkably consistent — crypto is treated as property (or a capital asset), not as currency. The United States established this in IRS Notice 2014-21; the United Kingdom, Canada, Australia and many others reached materially the same place. Treating crypto as property has one dominant consequence: disposing of it is a potential capital-gains event, and a disposal is far broader than "selling for cash."
Under the property model, you generally trigger a capital gain or loss whenever you dispose of a unit — selling it for fiat, swapping one crypto for another, or spending it on goods or services — measured as the difference between what you receive (at fair market value) and your cost basis. The trap most people fall into is the crypto-to-crypto swap and the small purchase: both feel like using money, but under the property model each is a disposal of one asset and an acquisition of another, and each can produce a taxable gain even though no cash was involved. Separately, receiving new crypto as income — mining rewards, staking rewards, most airdrops, or payment for work — is generally taxed as ordinary income at the value when you gain control of it, and that value then becomes your cost basis for the eventual capital-gains calculation when you dispose of it. Merely buying and holding, or moving your own coins between your own wallets, is generally not a taxable event. The core distinction, then, is between disposals (capital) and receipts (income), and the table further down sorts common actions into each. Our deeper treatment lives at crypto tax: the core principles.
9. Cost basis and record-keeping
If taxable events are the when of crypto tax, cost basis is the how much, and it is where compliance actually lives or dies. Cost basis is what you paid to acquire a unit, including acquisition fees, expressed in your home currency at the time. Your gain or loss on a disposal is the proceeds minus that basis, so without an accurate basis you cannot compute a correct figure, and tax authorities will often assume a basis of zero — the worst case — if you cannot substantiate one. For income receipts, the value counted as income becomes the basis going forward, which is why the two ideas are joined.
The complication is that most people acquire the same asset many times at different prices, so when they dispose of part of a holding, which units did they sell? Jurisdictions answer this with cost-basis methods — first-in-first-out, specific identification, or averaging rules such as the pooling ("Section 104") approach used in the UK — and the permitted method and any same-day or short-window matching rules vary by country. You generally cannot mix methods arbitrarily. The practical discipline that follows is unglamorous but decisive: keep contemporaneous records of every acquisition and disposal — dates, amounts, the home-currency value at the time, fees, counterparties, and transaction hashes — because reconstructing years of activity across several exchanges and wallets after the fact is painful, error-prone, and expensive. Exchange exports and reconciliation software help, but they are only as good as the completeness of the data you feed them, and transfers between platforms are where records most often break. Good record-keeping is not merely prudent; in a self-reported system it is the difference between a defensible return and a guess.
10. Reporting: CARF and exchange reporting
The final idea is the one changing fastest: the shift from a world where tax authorities largely relied on taxpayers to self-report to one where they receive crypto data automatically. Two forces drive it. Domestically, jurisdictions are extending the third-party reporting that already exists for banks and brokers to crypto intermediaries, so exchanges increasingly issue tax forms to customers and file the same information with the authority — meaning the tax office may know about your disposals before you file. Internationally, the counterpart is the Crypto-Asset Reporting Framework (CARF), developed by the OECD and finalised in 2023 alongside amendments to the Common Reporting Standard.
CARF does for crypto what the Common Reporting Standard already does for bank accounts: it requires crypto-asset service providers to collect information about their users — including tax residence and tax identification numbers — and report their transactions to their local tax authority, which then automatically exchanges that information with the authorities of the countries where the users are resident. Implementation is phased, with first exchanges of information beginning around 2027 for the earliest wave of committed jurisdictions and due-diligence and data-collection obligations starting shortly before that. The strategic point for any user is simple and worth stating plainly: the practical anonymity that some assumed at the intermediary layer is ending, cross-border activity through regulated exchanges is becoming visible to home tax authorities by default, and the sensible planning assumption is that regulated on-ramps report. None of this changes what is owed; it changes how likely a discrepancy is to be noticed.
Regulation by region, at a glance
The table below compresses the regional models into their essentials. It is an orientation aid, not a compliance checklist: the named frameworks are the primary anchors in each place, but each sits alongside other rules, and details and dates move. Read it to fix the shape of each regime in mind, then verify specifics against the primary sources listed at the end and, where it matters to you, against professional advice. Our jurisdiction-by-jurisdiction explainer at how crypto is regulated by jurisdiction goes further country by country.
| Region | Primary framework(s) | Model in one line | Who supervises |
|---|---|---|---|
| European Union | MiCA (Regulation (EU) 2023/1114) | Single comprehensive regime: classify token types, regulate issuers, license service providers across the bloc. | ESMA and EBA with national competent authorities |
| United States | Securities and commodities laws, Bank Secrecy Act, Internal Revenue Code, state money-transmission law | Overlapping agencies applying pre-existing law, developed heavily through enforcement and the courts. | SEC, CFTC, FinCEN, IRS, banking regulators, and the states |
| United Kingdom | Money Laundering Regulations; financial-promotions rules; a broader authorisation regime being phased in | AML registration today, moving toward full conduct regulation of core crypto activities. | Financial Conduct Authority; HMRC for tax |
| Global AML standard | FATF Recommendations, including the Travel Rule (Recommendation 16) | Non-binding standards adopted nationally: identify VASPs, apply KYC/AML, make transfer information travel. | FATF sets standards; national regulators enforce |
| Singapore | Payment Services Act; Financial Services and Markets Act | Activity-based licensing of digital-payment-token services with AML and consumer-protection duties. | Monetary Authority of Singapore (MAS) |
| Japan | Payment Services Act (and financial-instruments law) | Early, exchange-registration-based regime treating crypto assets as a defined category. | Financial Services Agency (FSA) |
| Global tax reporting | OECD Crypto-Asset Reporting Framework (CARF); amended CRS | Automatic cross-border exchange of crypto transaction data between tax authorities. | OECD standard; national tax authorities implement |
Two cautions about reading any such table. First, "primary framework" does not mean "only rule": a European CASP still faces AML law, tax law, and data-protection law on top of MiCA, and a US firm faces state and federal rules at once. Second, the models are converging in substance even where the drafting differs. The FATF standards, MiCA's template, and CARF's reporting are pulling jurisdictions toward a common core — identify the intermediary, know the customer, make information travel, and report to the tax authority — so learning one regime well makes the others far easier to read.
Crypto tax: the core principles
This section restates the tax ideas from above as a set of principles you can carry into any jurisdiction, because while rates, allowances, forms, and deadlines differ enormously, the underlying logic is strikingly shared. It is general information only and, as the disclaimer below repeats, not tax advice.
The following is a principles-level summary, not tax advice. Crypto tax rules — rates, allowances, permitted cost-basis methods, filing thresholds, and the treatment of specific events such as staking, airdrops, and DeFi activity — vary by jurisdiction and change from year to year. Amounts and rates are omitted deliberately because they date quickly and differ by country. Confirm how any of this applies to you with a qualified tax professional and your national tax authority's current guidance before you act or file.
Principle one: crypto is property, so gains are gains. The starting point in most major systems is that crypto is a capital asset, not money, so disposing of it can realise a taxable gain or loss just as selling shares would. Principle two: a disposal is broader than a sale. Selling for fiat, swapping one token for another, and spending crypto on goods or services are all typically disposals, each measured against cost basis — the swap and the small purchase being the two that most often surprise people. Principle three: receipts are income at the point of control. Crypto received as mining or staking rewards, as most airdrops, or as payment for work is generally ordinary income valued when you gain control of it, and that value becomes your basis for the later capital calculation. Principle four: basis and records determine the number. Your gain is proceeds minus basis, so accurate, contemporaneous records are not optional; an unsubstantiated basis can default to zero. Principle five: reporting is becoming automatic. Between domestic exchange reporting and the OECD's CARF, tax authorities increasingly receive your data directly, so self-reporting now operates against a backdrop of third-party visibility.
Principle six: losses and timing usually matter, but the rules are local. Most systems let capital losses offset capital gains, sometimes with carry-forward, and many have anti-avoidance rules about selling and rebuying to harvest a loss — but whether, and how, these apply to crypto specifically is jurisdiction-dependent and is exactly the kind of detail to confirm rather than assume. Principle seven: novel activities are the frontier. Lending, liquidity provision, wrapping, bridging, and other decentralised-finance actions can each be a disposal, an income event, both, or neither depending on the jurisdiction and the mechanics, and authoritative guidance often lags the products; treat confident claims about their treatment with suspicion and get advice. The table below sorts common actions into likely-taxable and likely-not-taxable buckets to make the disposals-versus-receipts distinction concrete — with the same caveat that your jurisdiction is the authority, not this list.
| Action | Usual treatment | Why |
|---|---|---|
| Buying crypto with fiat and holding it | Generally not a taxable event | Acquiring a capital asset only sets your cost basis; nothing is realised until you dispose of it. |
| Moving your own crypto between your own wallets | Generally not a taxable event | No change of beneficial ownership and no disposal, though network fees paid in crypto can themselves be small disposals. |
| Holding through a price change (unrealised) | Generally not taxable (in most systems) | Most jurisdictions tax realised gains, not paper gains; a few tax regimes differ, which is why local rules govern. |
| Selling crypto for fiat currency | Typically a capital-gains event | A disposal: proceeds minus cost basis is your gain or loss. |
| Swapping one crypto for another | Typically a capital-gains event | Disposing of one asset to acquire another is a disposal even though no cash changes hands. |
| Spending crypto on goods or services | Typically a capital-gains event | Using crypto as payment is a disposal at fair market value, distinct from any sales tax on the purchase. |
| Receiving mining or staking rewards | Typically ordinary income when controlled | New value received for an activity is income at its value when you gain dominion and control; that value becomes basis. |
| Receiving crypto as payment for work | Typically ordinary income | Compensation is income at fair market value when received, regardless of the form it takes. |
| Receiving an airdrop | Often income; sometimes deferred | Frequently income at receipt, but treatment varies by jurisdiction and by whether anything was required in return. |
| Gifting or donating crypto | Highly jurisdiction-dependent | May be exempt, a disposal, or subject to gift rules depending on the country, amount, and recipient. |
Read that table as a map of principles, not a ruling. The left-hand actions are near-universal; the treatments hold as tendencies across the major property-model jurisdictions, but the exceptions are precisely where liability and penalties live, and they are local. If you take one thing from this whole guide, let it be the disciplined habit rather than any single fact: identify which of your actions are disposals and which are receipts, record the home-currency value and basis at the moment each occurs, and confirm the treatment of anything unusual — staking, DeFi, airdrops, gifts — against your own jurisdiction's current guidance and a qualified professional. For definitions of the terms used throughout, see the glossary. Principles travel; details do not, and in crypto regulation and tax the details are where the law actually bites.
Sources
- ESMA - Markets in Crypto-Assets Regulation (MiCA)
- EUR-Lex - Regulation (EU) 2023/1114 (MiCA), full text
- FATF - Virtual Assets (standards and Travel Rule)
- FATF - Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs (2021)
- U.S. SEC - Framework for Investment Contract Analysis of Digital Assets
- U.S. CFTC - Digital Assets
- FinCEN - Application of Regulations to Persons Administering, Exchanging, or Using Virtual Currencies (FIN-2013-G001)
- FinCEN - Application of Regulations to Certain Business Models Involving Convertible Virtual Currencies (2019 CVC Guidance)
- IRS - Notice 2014-21 (virtual currency treated as property)
- IRS - Digital Assets (overview and reporting)
- IRS - Frequently Asked Questions on Virtual Currency Transactions
- UK FCA - Cryptoassets: AML / CTF regime
- UK FCA - A new regime for cryptoasset regulation
- HMRC - Cryptoassets Manual
- OECD - Crypto-Asset Reporting Framework (CARF) and amendments to the CRS
- Monetary Authority of Singapore - Payment Services Act
- Japan Financial Services Agency (FSA)
Frequently asked questions
Is cryptocurrency legal?
Why does a crypto exchange ask for my ID?
What is the FATF Travel Rule in plain terms?
Is a token a security or a commodity?
What is MiCA and does it affect me?
When do I owe tax on crypto?
Is swapping one crypto for another a taxable event?
What is cost basis and why does it matter?
Will tax authorities know about my crypto?
How is DeFi taxed?
Guides in this section
How crypto is regulated, by jurisdiction
Crypto regulation is a patchwork because each country applies its own securities, commodities, payments, and anti-money-laundering laws, and sometimes adds new ones.…
RegulationCrypto tax: the core principles
In most major jurisdictions crypto is taxed as property, so disposing of it can create a gain or loss. Disposals often include…
RegulationKYC and AML in crypto, explained
Anti-money laundering (AML) is the framework that stops the financial system being used for illicit finance; Know Your Customer (KYC) is the…
Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.