Brazil’s central bank has introduced a new fraud-control requirement that will slow some cryptocurrency transfers handled by regulated service providers. Under Resolution 584, covered virtual asset service providers must retain certain transfers for up to 24 hours while they conduct a risk review.
The measure applies to transfers above $10,000, including cases where a customer’s transactions reach that amount over the course of a single day. It targets transfers to foreign crypto entities and to self-custody wallets, and the rules also extend to fiat-linked virtual assets such as stablecoins.
Resolution 584 extends fraud rules to crypto services
The Central Bank of Brazil said the new resolution amends existing fraud-prevention rules for payment services so they also cover virtual asset services. In practice, that brings parts of the crypto sector into a framework that requires institutions to pause qualifying transfers while assessing whether a transaction presents fraud risk.
The retention requirement is described as a precautionary step rather than a permanent restriction on access to assets. Institutions are required to inform customers when a transfer has been placed on hold and must also state how long that hold will last.
Which transfers are covered
The mandatory 24-hour retention applies when the value of a transfer exceeds $10,000. The threshold is not limited to a single transfer: it also applies when a customer’s combined transactions on the same day pass that level.
According to the published rules, the hold covers transfers sent to foreign entities operating in the virtual asset market as well as transfers to self-custody wallets. The measure explicitly reaches virtual asset services covered by Brazilian law, including virtual assets pegged to fiat currencies, which means stablecoin transactions are included.
What providers must do after the review
Once the institution completes its risk assessment, it must take one of two actions: release the transfer or reject it. If the transaction is cleared, the funds must be released immediately after the 24-hour period ends.
The rules also allow an earlier release in some cases. A provider may let the transfer proceed before the deadline if it makes a reasoned decision based on risk analysis and documents that decision under the criteria set out in the regulation.
Extra monitoring and central bank powers
Resolution 584 adds broader record-keeping duties alongside the transfer hold. Covered institutions must keep daily records of fraud and attempted fraud involving both payment services and virtual asset services, including the corrective measures they adopted in response.
The central bank also reserved room to tighten the regime if it finds compliance problems. It can require longer retention periods, expand the procedure to transactions below the $10,000 threshold, and limit the early release of transfers where noncompliance is identified.
Start date and next confirmed step
The new requirements are scheduled to take effect on January 1, 2027. Until then, the confirmed next step is implementation by covered providers, which will need to update their fraud-review procedures, customer notifications, and record-keeping systems to meet the new standard set by the Central Bank of Brazil.
Source: beincrypto.com