cyberx_█
← back to indexCompliance & Regulation7 min read

The 80 days for Pix are only half of what changed — the other half lands on October 26

The rule that extended the contestation window carries two effective dates. Coverage reported the first one. On the second, the infraction report will be required to state which layer of the tracing graph the transaction sits in.

Robert F.
The 80 days for Pix are only half of what changed — the other half lands on October 26
▸In this article

As of yesterday, anyone hit by a Mecanismo Especial de Devolução (MED) refund has 80 days to contest it, not 30. The change was widely reported.

What almost nobody covered: the act that made this happen carries a second date, and what it switches on matters more to fraud practitioners than the deadline itself.

What actually changed on September 1

The most repeated phrasing deserves a correction, because it leaves the wrong impression. It isn't that "the MED window went from 30 to 80 days." What existed was an asymmetry, and it's gone.

Until August 31, the Manual Operacional do DICT ran two different clocks on the two sides. In version 8.4, the validation rule was explicit:

pacs.008: may be contested within 80 days; and pacs.004: may be contested within 30 days.

Decoding the alphabet soup: pacs.008 is the original transaction — the Pix the scam victim sent. pacs.004 is the refund transaction — the money MED pulled from someone and returned. The party with 80 days was the victim invoking the mechanism. The party with 30 was the other side, the one that took the debit.

In version 8.5, that same passage became:

The DICT will validate whether the transaction falls within the permitted contestation window, which is 80 days for both the original transaction (pacs.008) and the refund transaction (pacs.004).

Section 20.1.9 follows suit, swapping "within 30 days" for "within 80 days." And section 20.2, the initiation flow, changes at step 5 — the recovering PSP's decision — which no longer lists two deadlines and instead requires a transaction "carried out within the last 80 calendar days (for both PACS.008 and PACS.004)."

Three sections changing for the same reason. We published this distinction on August 18, two weeks before it took effect: the victim's window is 80 days and always was; what tripled is the window for the party on the other side.

Same mechanism, and the suspicion switches sides

Section 20.1.1 explains why the symmetry makes sense, and it's the passage that best describes the instrument.

When a participant opens a Recuperação de Valores citing a pacs.008, the DICT reads it as a refund request, and the suspicion of fraud falls on the receiving user. When it opens one citing a pacs.004, the DICT reads it as a contestation of a refund, and the suspicion shifts to the payer of the original transaction.

The manual is explicit about the rest: "despite the difference in framing, the Recuperação de Valores process is exactly the same in both cases."

It's the same track, run in both directions. The only restriction on contesting a refund is that it must not stem from an operational failure.

The second date nobody reported

Instrução Normativa BCB nº 766, de 27 de julho de 2026, published version 8.5 of the manual. Article 3, as currently worded, sets two dates: September 1, 2026 for the changes to sections 20.1.1, 20.1.9 and 20.2 — the 80-day ones — and October 26, 2026 for the changes to sections 10.1 and 20.1.5.

That second date isn't the original one, and it's worth recording how it came about, because it explains what is still circulating incorrectly. IN 766 ran in the Diário Oficial on July 29 setting August 10 for sections 10.1 and 20.1.5. The day after publication, Instrução Normativa BCB nº 767, de 30 de julho de 2026 — whose summary line is, literally, to alter the effective date of certain provisions — rewrote the entire article and pushed those two sections, along with the repeal of Instrução Normativa BCB nº 752, to October 26. The original wording was replaced before the first date had even arrived.

There's an institutional reason for that speed, and the Banco Central states it itself in a note to IN 767: the Regulamento do Pix and the documents that form part of it do not constitute a binding regulatory act, being "eminently contractual in nature," per Voto 280/2021. Changes to it are therefore not subject to prior regulatory impact analysis. It's a rulebook that can be rewritten fast — and was: two acts in three days, the second one filed the day after the first was published.

The second batch is of a different order. Section 10.1 governs the content of the infraction report (notificação de infração), and it gains a mandatory field:

Graph depth (TransactionDepth). Layer of the tracing graph in which the transaction linked to the infraction report is located. The infraction report for the root transaction has depth 1. Infraction reports for transactions identified in the second layer have depth 2, and so on.

And the footnote to that field does what almost no layout change does: it reaches into the past. Reports generated before the change will be updated under the same rule, and those not linked to a Recuperação de Valores will be assigned the value 1.

Section 20.1.5, which describes the analysis stage, gets the matching paragraph: the PSP may identify the graph layer corresponding to the transaction under analysis via that attribute.

Why this is worth more than the deadline

Anyone reviewing an infraction report today receives, in essence, the assertion that fraud occurred at the origin. From October 26 on, they also receive the transaction's position in the graph — whether it is the root transaction or sits three or four layers away from it.

Those are two different questions. "My client received fraud proceeds" and "my client received money that passed through four other accounts before reaching him" call for different analyses, and produce different decisions about freezing, refunding and flagging.

It's the same thesis we argued when we unpacked the MED deadlines: fraud recovery is a topology problem. What changes in October is that the topology stops being inferred and starts arriving written into the field — including in old reports, which will be recalculated.

The detail that ties the deadline to the flagging

There's one effect of the extension that consumer coverage doesn't reach, and it's the one that matters most to anyone hit by an improper refund.

Contesting isn't only about clawing money back. Section 20.1.9 states that if the PSP that received the refund accepts the infraction report, it must cancel the Recuperação de Valores it had previously opened, "so that improperly generated fraud flags can be cancelled by the DICT." Section 20.1.10 confirms the duty: the recovering PSP must cancel when it identifies that it opened the Recuperação improperly, or after accepting a contestation report.

In other words: the window that went from 30 to 80 days isn't just the window to get the money back. It's also the window to undo a DICT fraud flag that should never have existed. Tripling it changes what can be put right.

Sources

Manual Operacional do DICT, published by the Banco Central — version 8.4 and version 8.5, sections 10.1, 20.1.1, 20.1.5, 20.1.9, 20.1.10 and 20.2, plus the 8.5 revision history, which summarizes what changes on each of the two dates. The comparison between the two versions is the basis for the passages quoted here. Check carefully: the first address still serves 8.4, which carries the 30 days repealed on September 1.

Instrução Normativa BCB nº 766, de 27 de julho de 2026 — publishes version 8.5 and repeals Instrução Normativa BCB nº 752.

Instrução Normativa BCB nº 767, de 30 de julho de 2026 — amends IN 766 to change the effective date of certain provisions, giving items I and II of Article 3 their current wording, and carries the note on the contractual nature of the Regulamento do Pix and the waiver of regulatory impact analysis.

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.

Related reading

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

how we write →