← All CCE Flashcard Decks

Regulatory & Legal Framework Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Regulatory & Legal Framework flashcards as text
  1. Under the EU's Markets in Crypto-Assets (MiCA) regulation, which specific provision governs the liability of a crypto-asset service provider (CASP) when client assets are lost due to a cyberattack on a third-party custodian it contracted?

    Answer: The CASP retains full strict liability toward the client regardless of fault, because MiCA prohibits contractual transfer of custody liability to sub-custodians

    MiCA Article 70(4) establishes that CASPs providing custody services cannot contractually transfer their liability for loss of client crypto-assets to a sub-custodian. The CASP remains fully liable to the client even when a contracted third-party custodian causes the loss, ensuring clients always have a direct, unambiguous claim against the regulated entity they engaged.

  2. A U.S. decentralized exchange (DEX) protocol operates purely through smart contracts with no identifiable administrators, yet processes over $1 billion in monthly volume. Under the SEC's 'Howey Test' doctrine combined with the CFTC's Ooki DAO enforcement precedent, what is the most legally accurate characterization of the protocol's regulatory exposure?

    Answer: Governance token holders who vote on protocol parameters may individually bear liability as unregistered exchange operators, even without formal organizational structure

    The CFTC's Ooki DAO enforcement (2022) established that DAO token holders who vote on governance proposals can be personally liable as unincorporated associations operating unregistered commodity trading platforms. Combined with SEC theories that governance token sales may constitute securities offerings under Howey, individual governance participants—not just the protocol itself—can bear regulatory liability even in fully decentralized, admin-free architectures.

  3. The Financial Action Task Force (FATF) Travel Rule, as implemented under FATF Recommendation 16, requires Virtual Asset Service Providers (VASPs) to transmit originator and beneficiary information. Which of the following transaction scenarios creates the most complex compliance gap under current global implementations?

    Answer: A transfer from a regulated VASP to an unhosted wallet where the VASP cannot technically compel the counterparty to receive or verify the required data

    Transfers from regulated VASPs to unhosted (self-custody) wallets represent the most critical compliance gap because there is no counterparty VASP to receive and verify Travel Rule data. The originating VASP must collect the information but cannot technically transmit it to or obtain acknowledgment from a non-custodial wallet. Regulators differ on how to handle this — some require enhanced due diligence, others apply threshold rules — creating a structurally unresolved compliance problem that protocol translation issues (answer D) do not match in severity.

  4. Under the U.S. Bank Secrecy Act (BSA) as interpreted by FinCEN's 2019 guidance on convertible virtual currency, which of the following actors is definitively classified as a Money Services Business (MSB) required to register with FinCEN and implement a full AML program?

    Answer: An individual who operates an anonymizing mixing service and charges a fee to tumble cryptocurrency transactions for third parties

    FinCEN's 2019 guidance explicitly classifies operators of mixers or tumblers that provide anonymizing services for third parties as money transmitters (an MSB category) because they accept and transmit value on behalf of others for compensation. Miners (answer B) are generally not MSBs when selling self-mined coins. Non-custodial software developers (answer A) are excluded by FinCEN's 'software exemption.' DAOs issuing governance tokens to contributors without a public sale do not clearly meet the money transmission definition.

  5. A stablecoin issuer redeems its tokens 1:1 for USD but holds reserves entirely in short-duration U.S. Treasury bills rather than bank deposits. Under the proposed U.S. STABLE Act framework and existing state money transmission laws, what is the primary unresolved legal tension this reserve composition creates?

    Answer: While T-bills satisfy proposed federal liquidity requirements, certain state money transmission laws require reserves to be held in FDIC-insured deposits, creating a state-federal conflict for multi-state issuers

    The STABLE Act and similar federal proposals generally accept short-duration Treasuries as qualifying liquid assets. However, several state money transmitter licensing regimes require permissible investments to include FDIC-insured deposits or define 'permissible investments' in ways that may not clearly encompass T-bills. Multi-state stablecoin issuers must reconcile federal frameworks that approve T-bills with state-level rules that impose narrower reserve requirements, creating genuine compliance conflicts without a preemption resolution.

  6. In the context of cross-border cryptocurrency enforcement, the U.S. Department of Justice successfully prosecuted the founders of BitMEX under the Bank Secrecy Act despite BitMEX being incorporated in the Seychelles and explicitly blocking U.S. IP addresses. Which legal doctrine primarily enabled U.S. jurisdiction in this case?

    Answer: The 'effects doctrine,' under which U.S. law applies to any foreign entity whose conduct produces substantial effects within U.S. territory, including serving U.S. persons who circumvent geoblocks

    The BitMEX prosecution rested primarily on the effects doctrine (also called the 'conduct and effects' test) — U.S. courts have long held that foreign entities that knowingly serve U.S. customers, even while nominally blocking them, subject themselves to U.S. law because their conduct produces effects within U.S. territory. Prosecutors showed BitMEX accepted U.S. customers who bypassed VPN blocks and that key business decisions were made from U.S. soil, satisfying both the conduct and effects prongs. No specific USD-contract doctrine or Seychelles MLAT was the operative theory.