cyberx_█
← back to indexCompliance & Regulation3 min read

The First DeCripto Filing Is Due August 31 — and the Obligation Reaches Exchanges With No Brazilian Address

Brazil's tax authority has implemented the OECD's CARF, revoked the 2019 regime and changed who reports. Foreign providers are captured by how they advertise; anyone operating offshore or on a decentralized platform now reports on their own account.

Robert F.
The First DeCripto Filing Is Due August 31 — and the Obligation Reaches Exchanges With No Brazilian Address
▸In this article

This Monday, August 31, is the deadline for the first Crypto-Asset Return — the DeCripto — covering July transactions. The obligation stems from Instrução Normativa RFB nº 2.291, of November 14, 2025, which aligned Brazil with the Crypto-Asset Reporting Framework (CARF), the OECD standard for the automatic exchange of tax information on crypto-assets.

The preamble to the rule cites the instrument directly: the Multilateral Competent Authority Agreement on Automatic Exchange of Information pursuant to the CARF, of November 21, 2024.

What is due, and when

The IN took effect on publication, but its provisions were phased in. Article 19 sets two dates: the due diligence duties under Article 8, which exist "for purposes of CARF compliance," have applied since January 1, 2026; Articles 7, 9 and 18 have produced effects since July 1, 2026.

It was on that second date that the DeCripto replaced the previous model. Article 18 revoked Instruções Normativas nº 1.888 and nº 1.899, both from 2019, which had underpinned the regime until then.

Article 12 sets the filing frequency: monthly, by the last business day of the following calendar month, and annually, by the last business day of January. July is the first reporting period, and the last business day of August 2026 is Monday the 31st.

The schema was approved by Ato Declaratório Executivo Copes nº 2, of December 31, 2025, version 1.0, with filing through e-CAC.

Who is now covered

Here is the change that drew the least attention. Article 5 imposes the obligation on crypto-asset service providers resident, incorporated or managed in Brazil — which was expected. But paragraph 1 also reaches foreign providers, under criteria that do not depend on their having an address here:

  • use of a .br domain;
  • a commercial agreement with a local company;
  • targeting of Brazilian residents;
  • service advertising clearly directed at Brazilian residents.

An exchange with no physical presence in the country falls under the obligation because of how it advertises. The test is commercial targeting, not domicile.

And those operating outside the system report on their own

The second change shifts the duty onto the user. Individuals and entities resident in Brazil must now report on their own account when they transact through a foreign provider, through a decentralized platform, or without any intermediary provider.

Under the previous regime, anyone operating outside the reach of domestic exchanges reported above a threshold of R$ 30,000 per month. The floor has risen to R$ 35,000 per month in aggregate value — but the logic changed along with it: this is no longer merely a reporting threshold, it is a structured monthly reporting duty in a defined schema.

The rule does not change taxation. The rate, capital gains treatment and the exemption for monthly sales up to R$ 35,000 remain as they were. What changed is what the tax authority now sees, about whom, and how often.

Why this is not just about tax

CARF is not a domestic form. It is a standard for the automatic exchange of information between tax authorities in different jurisdictions — the same design as the Common Reporting Standard, applied to crypto-assets. Data collected under the DeCripto was never meant to stay in Brazil.

That is what makes the issue bigger than a filing date. The discussion that follows is not about deadlines: it is about the conditions under which tax information on identifiable people crosses borders automatically, and what filter exists along that path.

Sources

  • Instrução Normativa RFB nº 2.291, of November 14, 2025 — Articles 5, 7, 8, 9, 12, 18 and 19.
  • Ato Declaratório Executivo Copes nº 2, of December 31, 2025 — DeCripto schema, version 1.0.
  • Instruções Normativas RFB nº 1.888 and nº 1.899, of 2019, revoked.
  • Multilateral Competent Authority Agreement on Automatic Exchange of Information pursuant to the Crypto-Asset Reporting Framework, of November 21, 2024.

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.

Related reading

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

how we write →