The term "unsafe or unsound practice" has governed American banking for decades. It has no fixed definition. It never needed one. Bank examiners wielded it like a blunt instrument, and for years, the crypto industry felt the impact of that ambiguity firsthand.
Now, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation are moving to change that. They are advancing a rulemaking that would finally define what constitutes an "unsafe or unsound" practice. The stated goal: prevent banks from dropping legitimate customers—including crypto companies—based on vague reputational concerns or procedural pressure.

This is not a technical upgrade. It is not a protocol fork. It is a structural adjustment to the plumbing that connects digital assets to the dollar system. And it deserves closer scrutiny than the market is giving it.
The Context: De-Banking as a Silent Attack Vector
Let me be precise about what is happening. The OCC and FDIC are not proposing new crypto regulations. They are proposing a definitional framework for how banks treat customers. The term "unsafe or unsound" has historically been a catch-all that gave examiners enormous discretion. That discretion, in practice, became a weapon.
Crypto companies have faced a quiet but persistent problem: banks refusing to open accounts, closing existing ones, or charging prohibitive compliance fees—all justified by "reputational risk." This phenomenon, known as de-banking, has been documented across multiple jurisdictions. In the United States, it reached a point where legitimate, regulated crypto businesses struggled to maintain basic banking relationships.
The new rule would require regulators to tie "unsafe or unsound" determinations to actual illegal activity or material financial risk. Not perception. Not association. Not the vague possibility that a crypto client might someday do something wrong.
This is a meaningful shift. It signals that regulators are acknowledging the de-banking problem exists and that the current framework enables it.
The Core: What This Actually Changes
From my perspective as someone who has spent years auditing smart contracts and analyzing protocol risk, this rulemaking is about reducing arbitrary decision-making in the financial system. The parallel to code is direct: when a function has undefined behavior, it can be exploited. When a regulatory term has no definition, it can be weaponized.
The current system operates on undefined behavior. Bank examiners have broad latitude to flag crypto-related clients as "reputational risks." This creates a chilling effect. Banks, being risk-averse institutions, simply avoid crypto clients altogether rather than risk regulatory pushback. The result is a de facto exclusionary policy that never had to be formally written down.
The proposed rule changes the incentive structure. If "unsafe or unsound" must be tied to demonstrable illegal activity or material financial risk, banks lose their cover for blanket refusals. They can no longer hide behind vague regulatory pressure. This is a structural improvement.
But here is where I diverge from the optimistic narrative. This rule does not solve the underlying problem. It merely shifts the burden.
Banks that do not want crypto clients will still find reasons to refuse them. Anti-money laundering requirements remain. Know-your-customer obligations remain. The rule does not eliminate a bank's ability to decline a customer based on compliance concerns. It only removes one specific justification—the vague "reputational risk" category.
The crypto industry should not mistake this for a green light. It is a yellow light with clearer signage.
The Contrarian Angle: The Blind Spot in the Rulemaking
Here is what most commentary misses. The OCC and FDIC rulemaking is about bank supervision, not securities law. The SEC's jurisdiction over crypto assets remains untouched. This means the rule could create a false sense of security.
Consider the practical scenario. A crypto exchange secures a banking relationship under the new, clearer rules. It feels validated. It expands operations. Then the SEC brings an enforcement action claiming certain tokens are unregistered securities. The bank, now exposed to regulatory scrutiny, reassesses the relationship. The de-banking problem returns, just through a different door.
The rule addresses one vector of exclusion but leaves others intact. It is a patch, not a fix. And in complex systems, patches can introduce new vulnerabilities.
There is also the question of enforcement. The rule, if finalized, would apply to how OCC and FDIC examiners evaluate banks. But the banking system is also influenced by Federal Reserve policy, by state regulators, by informal pressure from congressional committees. The rule cannot bind all of these actors. It creates a clearer standard for two agencies, but the broader ecosystem of financial exclusion remains fragmented.
I have seen this pattern before. In 2020, when I analyzed reentrancy vulnerabilities in early DeFi protocols, the flaw was never in a single function. It was in the interaction between functions. The same logic applies here. The vulnerability is not in the OCC or FDIC's discretionary power alone. It is in the interaction between multiple regulatory bodies, each with their own mandates and incentives.
The Takeaway: Watch the Implementation, Not the Announcement
This rulemaking is a positive signal. It suggests that US regulators are moving from implicit pressure to explicit standards. That is progress. But progress is not the same as resolution.
The timeline matters. Rulemakings of this nature typically take months, if not years. There will be a public comment period. There will be lobbying from both sides. The final text may be weaker than the proposal. That is the nature of the administrative process.
For crypto companies, the practical takeaway is straightforward: do not build your business model on the assumption that this rule will solve your banking problems. It may help. It may not. The uncertainty is the only certainty.

For those of us who audit systems for a living, the lesson is familiar. The proof is silent; the code screams the truth. In this case, the code is the regulatory framework, and it is still being compiled. The output is not yet known.
I do not trust the contract; I audit the logic. And the logic here is still incomplete. The rulemaking is a step toward clarity, but clarity is not the same as safety. The banking layer remains a centralized point of failure for the crypto ecosystem. This rule may reduce one vector of risk, but it does not eliminate the structural dependency.
The real question is whether the crypto industry will use this window to build alternative banking infrastructure, or whether it will continue to rely on the goodwill of traditional institutions. History suggests the latter. That is a risk no rulemaking can mitigate.