Loading live prices...

Curaçao Sets New Compliance Standards for Crypto Casinos

The Curaçao Gaming Authority (CGA) has issued an extensive set of crypto policy guidelines for its business to consumer (B2C) licensees. The new requirements mandate rigid compliance policies covering the entire lifecycle of virtual assets, which signals an important regulatory shift for the jurisdiction known for its flexible approach to cryptocurrencies. Licensed operators will have until mid-2027 to complete all requirements and achieve operational alignment.

Bitcoin, casino chips, dice, roulette wheel, and legal shield before the Curaçao flag.
Daniel Mercer
Written by Daniel Mercer
Updated Jul 13, 2026 7 min. read
|

The New Crypto Compliance Framework at a Glance

The CGA’s comprehensive framework introduces fundamental changes to how offshore online gambling brands will handle crypto deposits, wagering and payouts as well as corporate treasure management.

What the New Rules Mean in Practice

  • Licensees will be restricted to accepting cryptocurrency as a payment method for online gambling. They are now explicitly banned from offering exchange or custody services. Operators are also prohibited from functioning as virtual asset service providers (VASPs).

  • Curaçao-licensed online casinos will be required to integrate enterprise-grade blockchain analytics tools, such as Chainalysis or Elliptic, to perform real-time wallet screening, risk-scoring, and transaction monitoring.

  • With an explicit preference for fiat-backed stablecoins, the CGA has introduced mandatory risk assessment protocols, or even outright exclusion, for privacy-centric coins (such as Monero), high-risk memecons, and wrapped assets of unclear origin.

  • CGA-licensed crypto casinos will have to isolate their digital assets into three different groups: player-flow wallets, everyday operational wallets, and strategic treasury wallets.

  • The use of digital assets coming in from, or interacting with, privacy mixers, transaction tumblers, or international sanctions lists will be strictly prohibited.

Curaçao Gaming Authority’s New Crypto Casino Guidelines Explained

Shared on LinkedIn by Aideen Shortt, CGA marketing and PR advisor, the new guidelines are closely related to the National Ordinance on Games of Chance (LOK) framework, which seeks to improve the island’s reputation as a loosely regulated offshore jurisdiction.

The recently shared guidelines have important implications for crypto online casinos, and include regulations in the following headings.

Governance and Crypto Asset Oversight

CGA licensees are mandated to create and maintain a formally approved crypto policy that includes governance guidelines, review procedures, and accountability measures. Additional requirements include documenting and reporting any changes to the policy, implementing blockchain analytics and transaction monitoring, reporting any incidents to the CGA, and rejecting or freezing suspicious transactions as needed.

Operators Are Not Financial Service Providers

The current guidelines clearly state that crypto-focused online casinos, including Bitcoin casino sites and operators accepting other digital assets, are not to provide any financial or exchange services to players. CGA-licensed crypto casinos are also prohibited from converting cryptocurrencies or behalf on behalf of users, and offering trading, swapping, custody, or wallet services irrelevant to online gambling.

AML/KYC Requirements for Cryptocurrency

For many players, the stand-out appeal of crypto casinos is the perceived lack of KYC controls. However, reliable operators have been conducting KYC checks to stay compliant, and as part of AML regulations. With the new guidelines, the CGA has made it clear that cryptocurrency transactions are fully subject to AML/CFT and responsible gambling requirements. In contrast to most players’ misconception that crypto casino equals no KYC casino, CGA-licensed casinos are now explicitly required to implement the CGA’s AML policy to crypto transactions, and clearly state how crypto-specific controls are applied as part of their AML framework.

Blockchain Analytics and Transaction Monitoring

While the CGA does not mandate the use of a specific service provider, it does require operators to implement blockchain activity monitoring to efficiently track deposits and withdrawals, conduct risk assessment, and investigate transactions if necessary. New operator obligations now include:

  • Identify the origin and destination of funds
  • Detect links to sanctioned entities, mixers, scams, and other high-risk activity
  • Assess the risk level of wallets and transactions
  • Review incoming deposits before they are accepted
  • Monitor transactions continuously for suspicious activity
  • Verify the origin of funds to support KYC and enhanced due diligence
  • Screen withdrawal addresses before funds are sent
  • Maintain audit trails to support investigations and regulatory reporting

Risk Assessment of Digital Assets

Considering cryptocurrencies as high-risk assets, the CGA requires licensees to continuously assess the digital coins they accept. The regulator clearly expresses preference for stablecoins, and requires operator policies to address higher-risk asset categories listed below.

  • Privacy Coins: Cryptocurrencies that make transactions difficult to trace, such as Monero, Zcash (shielded transactions), Dash (when privacy features are used), and Litecoin with MWEB.
  • Pooled or Omnibus Wallets: These crypto wallets are permitted only if transactions can be attributed to individual customers, and make it possible to conduct source of funds checks, transaction monitoring, and regulatory reporting.
  • Meme and Highly Speculative Tokens: Speculative memecoins should be assessed based on factors such as liquidity, price volatility, governance, ecosystem maturity, and financial crime risks.
  • Wrapped and Bridged Assets: Deposits involving wrapped or bridged tokens should only be accepted when the underlying asset’s origin, custody, and transaction history can be independently verified.

Prohibited Crypto Assets and Transactions

On the grounds that they might undermine transparency and regulatory oversight, certain cryptocurrency sources and transaction mechanisms are explicitly prohibited. Operators are banned from accepting digital assets associated with cryptocurrency mixers or tumblers, in addition to crypto assets linked to wallet addresses that appear on on any applicable sanctions list, or flagged by blockchain analytics providers. The regulator also states that it may prohibit additional asset types in the future.

FATF Travel Rule Compliance

Commonly known as the “Travel Rule,” Recommendation 16 by the Financial Action Task Force (FATF) requires financial institutions and VASPs to transmit accurate sender and recipient information with every transfer throughout the payment chain. In its newly shared guidelines, the CGA requires operators to follow the said recommendation. This means that where applicable, crypto-asset transfers between regulated entities, including crypto exchanges, custodial wallet providers, and VASPs, must include the required originator and beneficiary information, and be available to the relevant authorities upon request.

Third-Party Providers and Unhosted Wallets

CGA licensees will be allowed to use third-party VASPs, payment providers, unhosted wallets and DeFi protocols, on the condition that the operators implement sufficient risk control measures. To this end, key requirements for operators include the following:

  • Conduct due diligence on third-party providers to verify they are appropriately regulated or supervised.
  • Document provider risk assessments, and maintain evidence of due diligence for regulatory purposes.
  • Retain full responsibility for AML/CFT compliance, transaction monitoring, player protection, and incident reporting, even when using third-party providers.
  • Apply enhanced controls to unhosted (self-custodied) wallets and DeFi transactions, including verifying wallet ownership or control.
  • Perform enhanced due diligence (EDD) where higher-risk activity is identified.
  • Ensure transactions from unhosted wallets do not compromise AML/CFT monitoring, record-keeping, or reporting obligations.

Management of Crypto Transactions

The CGA states that withdrawals should ideally be made to the same wallet and in the same crypto asset as the original deposit. However, the regulator does allow for alternatives on certain conditions. Withdrawals to a different wallet address is permitted only if the wallet has been whitelisted, pre-screened, verified as belonging to the same customer, and has passed KYC/AML checks. Operators can allow withdrawals in a different cryptocurrency or stablecoin, but the transaction must be fully transparent and auditable, and asset conversions must be carried out through a regulated VASP. Player to player transfers are not allowed.

Operator Wallet Management

Under the new guidelines, crypto casinos licensed by the CGA are required to hold player funds in a different wallet than those used for operational and treasury funds. Moreover, wallets must be owned by the licensed entity, or an approved group entity. Online casinos are not allowed to use personal wallets, UBO-linked wallets, employee wallets, or informal wallet arrangements for operational purposes.

Hot, Warm, and Cold Wallet Controls

The CGA permits the use of different wallet types, on the condition that they are properly documented, secured, and managed.

  • Hot wallets may be used for day-to-day deposits and withdrawals but should only hold the funds needed for normal operations.
  • Warm wallets may be used to manage liquidity, with enhanced access controls and transaction approval processes in place.
  • Cold wallets are allowed for treasury, reserve, or long-term fund storage, provided robust key management, reconciliation, and audit controls are maintained.
  • Security controls such as multi-signature approval, withdrawal whitelisting, multi-factor authentication (MFA), and hardware security modules (HSMs) should be applied where appropriate to the wallet’s value and risk.
  • Comprehensive records should be maintained to demonstrate wallet ownership or control, transaction history, reconciliations, access permissions, approvals, and transfers between wallets.

Incident Reporting

Finally, licensees are required to identify, assess, and report crypto-related incidents in line with the LOK incident reporting requirements. Reportable incidents include security breaches, fraud, system failures, wallet balance discrepancies, smart contract failures, blockchain disruptions, and exposure to sanctioned or other prohibited sources.

Implementation Timeline

To give licensees enough time to implement the necessary controls, the policy, shared in June, will become effective in phases.

  • Immediate (June 2026): Comply with prohibitions on sanctioned wallets, mixers, prohibited crypto assets, personal or UBO-linked wallets, and operating as an exchange, payment provider, or VASP.
  • Within 3 months (September 2026): Submit a crypto policy to the CGA, including an implementation roadmap and plans to build the necessary crypto expertise.
  • Within 6 months (December 2026): Complete crypto risk assessments, VASP due diligence, wallet ownership controls, transaction monitoring procedures, and staff training.
  • Within 12 months (June 2027): Fully implement wallet segregation, blockchain analytics, reconciliation processes, withdrawal whitelisting (or equivalent controls), and audit-ready record-keeping.

What the CGA’s New Crypto Rules Mean for Operators and Players

The Curaçao Gaming Authority’s new guidelines regarding crypto operations at online casinos will have significant implications for both operators and players. For operators, including crypto casinos and crypto sports betting sites, this could potentially signal the end of flexible and streamlined licensing. Crypto casino operators will need to move beyond simply obtaining a license, and instead demonstrate solid compliance through stronger transaction monitoring, effective KYC and AML controls, and a more substantive operational presence. While these new requirements are bound to increase compliance costs and challenge smaller operators, they are also expected to strengthen the credibility of Curaçao as a preferred jurisdiction.

For players, on the other hand, the reforms are introduced with the goal of enhancing consumer protection. However, they also mean additional verification requirements, which are likely to put off players who prefer cryptocurrencies for their pseudonymous nature. While enhanced compliance measures should reduce the risk of fraud, players can expect more frequent identity verification and greater scrutiny of crypto transactions.

Compliance Global Policy Regulation
Daniel Mercer
Daniel is an experienced author with a background in financial journalism. He writes about digital assets and crypto with a focus on clear, risk-aware explanations rather than hype, approaches price predictions cautiously and prioritises verifiable facts over exaggerated market expectations. When sharing cryptocurrency research and news, exchange reviews, and crypto gambling articles, Daniel's aim is to highlight topics that might not receive the attention they deserve, such as fees, custody, proof of reserves and more. His articles here on TradeBlock are intended for informational purposes only and do not constitute financial advice.