Digital-asset kiosks can turn cash into cryptocurrency within minutes. That convenience also creates an attractive payment channel for scammers who pressure victims to act before they can reconsider, consult someone they trust, or contact law enforcement.
Section 10205 of the updated CLARITY Act proposes a federal framework designed to introduce more transparency, accountability, and time into those transactions. The provision is broader than a warning screen or a transaction cap. It would require kiosk operators to combine customer disclosures, transaction records, fraud controls, compliance personnel, blockchain analytics, a waiting period for certain new-customer transactions, refund procedures, customer support, and communication channels for law enforcement.
Preventing kiosk fraud requires more than recognizing a suspicious wallet after money has moved. It connects prevention at the machine with scam intelligence, operator controls, victim reporting, and investigation.
The updated CLARITY Act text released on July 22, 2026, remains proposed legislation. The Senate did not pass H.R. 3633 before its August state work period. A cloture motion on whether to advance to consideration is scheduled to ripen on September 15, 2026, but that is a procedural step, not final passage. Section 10205 has not become law, and its requirements could still change.
What is a digital-asset kiosk?
Section 10205 would define a digital-asset kiosk as a stand-alone machine capable of accepting or dispensing legal tender in exchange for digital assets. These machines are often called crypto ATMs or Bitcoin ATMs.
The provision would define a digital-asset kiosk operator as a person that owns, operates, or manages a kiosk in the United States or its territories. It would also define a new customer as a customer during the 14-day period beginning on the date of that person’s first kiosk transaction with the operator.
Several proposed protections would apply only during that 14-day new-customer period.
What would Section 10205 require?
Section 10205 would amend federal law in two main ways.
First, it would bring kiosk operators expressly into the federal money-service-business registration framework and require regular reporting of kiosk locations and associated digital-asset addresses.
Second, it would add a new federal section titled “Digital asset kiosk fraud prevention.” That section would establish a layered set of operational requirements.
| Proposed safeguard | What it would do |
| Operator and kiosk registration | Require operator information, kiosk locations, operating dates, and operator-used digital-asset addresses to be reported and updated |
| Customer disclosures | Explain transaction terms, fees, finality, common scam patterns, and where to report suspected fraud |
| Customer acknowledgment | Require the customer to acknowledge the disclosures each time the kiosk is used |
| Detailed receipts | Preserve operator, customer, transaction, fee, wallet-address, and transaction-hash information |
| Anti-fraud policy | Require written fraud-risk identification, controls, accountability, monitoring, and periodic revision |
| Compliance officer | Assign full-time responsibility for compliance to a qualified person independent of specified ownership and executive roles |
| Distributed-ledger analytics | Screen for wallets known to be associated with fraud and patterns indicative of fraud or illicit activity |
| Wallet pinning | Prevent more than one customer of the operator from using the same wallet address |
| New-customer confirmation | Require confirmation for new-customer transactions of $500 or more |
| 72-hour waiting period | Delay covered new-customer transfers to a specific wallet address and give the customer a cancellation right |
| Transaction limits | Establish an interim $3,500 aggregate 24-hour limit for new customers until Treasury regulations take effect |
| Fee refunds | Require transaction-fee refunds in qualifying fraud cases supported by a timely complaint and government report |
| Customer support | Require live business-hours support and an alternative system outside business hours |
| Law-enforcement contact | Require a dedicated, publicly available contact method for law-enforcement and regulatory agencies |
Together, the safeguards address prevention, record creation, and response.
Blockchain analytics would be required, but analytics are not the whole answer
The proposal would require each operator to use distributed-ledger analytics for two purposes:
- Prevent sending digital assets to a wallet known to be affiliated with fraudulent activity at the time of the transaction.
- Detect transaction patterns indicative of fraud or other illicit activity.
It would also require wallet pinning, meaning the operator would have to prevent more than one of its customers from using the same wallet address.
Blockchain analytics can show transaction flows and risk indicators associated with public-ledger activity. It does not automatically show that another agency has an open case, that a bank has verified related victim information, or that the same wallet is relevant to several investigations under different case names.
Analytics can identify suspicious on-chain patterns. Deconfliction can show authorized organizations whether the activity overlaps with known cases and who may be positioned to coordinate.
Neither source of information should be treated as an automatic determination that a wallet or person is involved in crime. Human review, institutional procedures, source evaluation, and lawful investigative process remain essential.
How would the 72-hour waiting period work?
An operator could not execute a new customer’s transaction sending digital assets to a specific wallet address until at least 72 hours had elapsed from initiation. During that period, the customer could cancel and receive a full refund of the amount paid, including fees.
If a customer tried to cancel but could not contact the operator, the proposal would require the transaction to be treated as canceled.
For covered transactions, the delay could create a valuable intervention window:
- The customer may recognize the scam after speaking with a family member, bank employee, investigator, or customer-support representative.
- A fraud warning or follow-up conversation may overcome the urgency imposed by the scammer.
- The operator may detect a concerning pattern or receive new information about the destination address.
- Law enforcement or another authorized organization may connect the address to a related complaint or investigation.
The 72-hour period is different from the temporary-hold framework proposed in Section 10305. Section 10205 would impose a waiting period on covered new-customer kiosk transfers. Section 10305 would establish a separate liability protection for qualifying voluntary holds by certain covered providers under specified circumstances. The two provisions should not be described as interchangeable.
What refunds would be available?
Section 10205 proposes two distinct refund mechanisms.
First, a new customer subject to the 72-hour waiting period could cancel before the period expired and receive a full refund of the transaction amount, including fees.
Second, a kiosk operator would have to refund transaction fees within 30 days if the customer was fraudulently induced and filed a complaint with the operator. That complaint would need to include identifying and transaction information, along with a copy of a report made to a state or local law-enforcement or government agency no later than 30 days after the transaction.
The second mechanism concerns transaction fees, not automatic reimbursement of all cryptocurrency or cash lost to a completed scam.
The requirement for a government report also creates an operational connection between victim intake, operator response, and law enforcement. Agencies may need procedures that help victims document the transaction hash, wallet address, kiosk location, operator, time, and amount before evidence becomes harder to collect.
Where Deconflict fits
Section 10205 focuses on kiosk-operator duties and customer safeguards. Deconflict addresses the related coordination problem by helping authorized users identify overlap involving wallets, entities, and cases.
For law enforcement, that may reveal another agency working the same wallet or scam infrastructure. For a financial institution, verified context may improve a fraud or AML review within its own legal and compliance framework.
Deconflict does not label a wallet criminal merely because it appears in the platform. It does not replace blockchain analytics, a kiosk operator’s anti-fraud controls, institutional transaction monitoring, customer due diligence, legal process, or an investigator’s judgment. It is also not named, approved, or automatically recognized under the proposed CLARITY Act.
Its role is narrower: help authorized organizations determine whether relevant intelligence or investigative overlap exists and make coordination possible.
Financial institutions evaluating kiosk-related exposure can request a demonstration focused on how Verified Intelligence complements existing fraud and AML controls. Law-enforcement access is free.