Holding an exchange account without authorization becomes a bank violation on 30 October
Art. 91 of BCB Resolution No. 520 does not merely bar trading crypto with an unlicensed provider. The prohibition reaches the opening and maintenance of payment accounts — and anyone who filed an application is still on the inside.

▸In this article
On 1 June we covered the 30 October deadline from the standpoint of those who need to get authorized. The other side was missing, and it is broader: on that same date, any institution that serves a virtual asset service provider becomes answerable for what its counterparty did or failed to do. And not just banks — the rule reaches financial institutions, payment institutions and every other entity authorized to operate by the Banco Central.
It sits in art. 91 of BCB Resolution No. 520 of 10 November 2025, among the final provisions — the passage the deadline coverage never read.
What the article says
As of 30 October 2026, financial institutions, payment institutions and all other institutions authorized to operate by the Banco Central are barred from carrying out or enabling operations in the virtual asset market whose counterparties are entities that provide virtual asset services and are neither authorized nor undergoing authorization to operate in the country by the Banco Central itself, except in the forms expressly permitted by the resolution.
Two words carry the article. "Enabling" extends the prohibition beyond those actually transacting. And the sole paragraph spells out its reach:
trading, intermediation and custody of virtual assets, execution and intermediation of foreign exchange operations, the opening and maintenance of payment accounts and the execution of payment transactions, among other acts and services, when performed to enable the operations referred to in the main provision.
Maintaining an account is the verb that changes the scale. This is not simply about ceasing to trade crypto assets with an unlicensed provider: a bank that merely keeps that provider's account open after 30 October falls within the prohibition.
The reading most people will get wrong
The article reaches counterparties that are "neither authorized nor undergoing authorization". It is easy to read that as though being in the pipeline were also barred. The opposite is true.
Anyone who filed an application within the deadline is undergoing authorization, and is therefore outside the prohibition. The door closes on those who are not authorized and did not file. Since applications can be submitted right up to 30 October itself, the boundary only finishes taking shape on that date.
Why this is monitoring, not a one-off check
"Undergoing authorization" is not a permanent attribute. Art. 88, § 6 is explicit about how far the benefit extends: a provider that filed on time may continue operating until the process concludes, and during that period may not take on a different modality. Filing removes you from the prohibition for as long as the process exists — not forever. And § 1 sets the milestone at which the adaptation period ends: the Banco Central's ruling on phase 1.
Applications get denied, companies withdraw, processes conclude. A counterparty that is on the inside today can drop off it without anything changing in the contract, the volume or the transactional behavior.
That shifts where the problem lives. It is not a check to run on the eve of the 30th and file away: it is counterparty status monitoring, with a date and evidence of when it was verified. An institution that checks once and saves the screenshot will have documented precisely the day on which it was right.
The same architecture as always
Anyone following what we publish here has seen this design before. In betting, Law 15.358 and CMN Resolution No. 5.320 placed on the payment rail the duty to freeze the account of an unauthorized operator, with a deadline measured in hours. In virtual assets, art. 91 places on that same rail the duty not to maintain the account of an unlicensed provider.
The pattern repeats because it works: policing an operator's website is a game of catch-up; policing the account through which the money moves in and out is a single chokepoint, and it sits inside a regulated institution that answers for it.
Three obligations on the same day
30 October 2026 concentrates three deadlines, and none of them belongs to the exchange.
Art. 91 shuts down relationships with providers that did not file.
BCB Resolution No. 569 of 19 May 2026 sets that date, in art. 13-A, I, as the deadline for institutions to implement the sharing of fraud indicators in virtual asset service provision.
DeCripto falls due on the same date, but the reporting period has to be stated precisely. Normative Instruction RFB No. 2.291/2025 requires filing by the last business day of the month following the reporting period, and the last business day of October 2026 is Friday the 30th — so what falls due there is the September period. October's is only due at the end of November.
Three rules from different sources — Banco Central, Banco Central and Receita Federal — converging on the same day and the same subject: the intermediating institution, not the asset and not the platform.
A detail in the same resolution that goes unnoticed
The preceding article deserves attention from anyone working in tracing. Art. 90 bars providers from contracting, adopting or using mechanisms that hinder the detection, investigation or prosecution of crimes, and expressly cites "the use of mixers, tumblers or bots intended to conceal the authors or beneficiaries of transactions." The sole paragraph defines the term: mechanisms developed for the purpose of concealing the origin and destination of virtual asset transactions.
What stands out is not the subject but the placement: mixers appear here as a practice prohibited to the provider, defined in the text itself — not as a risk factor to be weighed in an internal policy.
What to do with the days that remain
The art. 91 deadline does not call for a project: it calls for an inventory and a record. Which counterparties provide virtual asset services, what each one's authorization status is, and how that status will be re-verified later — because it changes.
The hard part is not the list. It is that the prohibition reaches "enabling," and enabling is a broad verb: a payment account opened, a transaction processed, a foreign exchange operation intermediated. Anyone who maps only the crypto desk will leave out the area that appears most often in the sole paragraph — payments.
And it is worth stating what the rule does not require, because the hasty reading tends that way: there is no order to terminate relationships with providers that filed. The prohibition reaches those who are unauthorized and did not apply — and later reaches those who fall out of the process.
Sources
BCB Resolution No. 520 of 10 November 2025 — arts. 88, 90, 91 and 92; in force since 2 February 2026. Text at bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolução BCB&numero=520.
BCB Resolution No. 519 of 10 November 2025 — authorization processes, including those for virtual asset service providers.
BCB Resolution No. 569 of 19 May 2026 — art. 13-A, I.
Normative Instruction RFB No. 2.291 of 14 November 2025 — DeCripto filing frequency.
Law No. 14.478 of 2022 and Decree No. 11.563 of 2023 — the foundation of the regime.
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/news/holding-an-exchange-account-without-authorization-becomes-a-bank-violation-on-30-october
Retrieved on