Crypto-funded debit card in Malaysia
A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.
Crypto debit card is conditionally permitted in Malaysia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD required per AMLATFPUAA 2001 and BNM's AML/CFT TFS for FIs Policy Document: obtain and verify identity (name, address, DOB, nationality, ID document) for all cardholders
- Beneficial ownership identification for legal entity cardholders per my.aml.beneficial-ownership-identify-and-verify
- Non-face-to-face CDD measures required (multi-factor authentication, video verification, cross-referencing) per my.aml.non-face-to-face-nff-customers-given-the
- Ongoing transaction monitoring to ensure consistency with customer risk profile per my.aml.ongoing-monitoring-continuously-monitor-the
- Enhanced Due Diligence (EDD) for PEPs and high-risk customers per my.aml.politically-exposed-persons-peps-implement and my.aml.high-risk-customers-peps-customers-from
- Suspicious Transaction Reports (STRs) to Bank Negara Malaysia's Financial Intelligence Unit per my.aml.bank-negara-malaysia-bnm
- Source of funds/wealth information required for higher-risk customers or transactions per my.aml.source-of-fundswealth-for-higher-risk
- If the crypto-to-fiat leg involves a DAX-registered exchange: SC-regulated AML/CFT requirements under CMSA and SC Guidelines on Recognised Markets also apply per my.aml.capital-markets-and-services-act and my.aml.guidelines-on-recognised-markets-sc
Key Restrictions
- Crypto-to-fiat conversion at point of sale likely requires either (a) a DAX-registered exchange (RMO) to handle the off-ramp, or (b) the stablecoin must be classified as e-money issued by a BNM-licensed e-money issuer
- If the card loads stablecoins classified as e-money, the issuer needs a BNM e-money issuer license under the Payment Systems Act 2003, with RM 5M minimum capital per my.stablecoin.capital-adequacy-e-money-issuers-must
- If the card loads a digital asset classified as a security (including certain stablecoins), the SC's DAX framework applies, requiring RMO registration with MYR 5M shareholders' funds per my.licensing.exchange
- Only 5 registered DAX operators exist (Luno, Tokenize, MX Global, Sinegy, Hata); sponsor arrangements limited to these or new registrations which take 6-12 months per my.licensing.vasp
- Partner-bank/BIN-sponsor must be a licensed financial institution in Malaysia; BNM regulates all payment systems under the Payment Systems Act 2003
- Funds received for e-money issuance must be segregated in trust accounts with licensed financial institutions per my.stablecoin.segregation-of-funds-funds-received and my.stablecoin.placement-in-trust-accounts-these
Key Risks
- SC has active enforcement precedent—issued cease-and-desist orders against Binance (2021) and other unregistered operators per my.enforcement.entity-targeted-binance-holdings-limited and my.enforcement.entity-targeted-various-unauthorized-digital
- Regulatory classification risk: a stablecoin used for card top-ups could be deemed e-money (BNM) or a security (SC) depending on structure—dual regulator ambiguity creates legal uncertainty
- No capital gains tax for individuals, but systematic trading may be taxed as business income under ITA 1967—card top-ups/conversions could create taxable events per my.tax
- Only 5 registered DAX operators; limited partner availability and SC is 'strict and slow on registrations' per my.licensing.vasp
- Non-face-to-face onboarding (typical for crypto card programs) triggers enhanced scrutiny under BNM's AML/CFT TFS for FIs Policy Document
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
SC Malaysia — Digital asset exchange registration, IEO oversight, cease-and-desist enforcement
VASP: Recognized Market Operator (RMO) — DAX registration with SC. Only 5 operators registered (Luno, Tokenize, MX Global, Sinegy, Hata). SC strict and slow on registrations. 6-12 months.
EXCHANGE: DAX registration with SC — MYR 5M (~$1.1M USD) minimum shareholders' funds. SC issued cease-and-desist orders against unregistered operators (incl. Binance 2021). IEO framework requires separate SC approval.
CUSTODY: Included under DAX registration; customer asset segregation required
As E-Money/Payment Token (Regulated by Bank Negara Malaysia - BNM):
Payment Systems Act 2003: https://www.bnm.gov.my/documents/20124/960537/Payment+Systems+Act+2003.pdf
Financial Services Act 2013: https://www.bnm.gov.my/documents/20124/960537/Financial+Services+Act+2013.pdf
Guidelines on E-Money (updated 2021): https://www.bnm.gov.my/documents/20124/938096/Guidelines+on+E-Money.pdf
Capital Adequacy: E-money issuers must meet minimum capital funds requirements, usually RM 5 million (for non-bank entities).
Segregation of Funds: Funds received for the issuance of e-money must be safeguarded and clearly separated from the issuer's own funds.
Placement in Trust Accounts: These funds typically need to be placed in trust accounts with licensed financial institutions, ensuring their availability for redemption.
Any entity wishing to issue a stablecoin classified as e-money must obtain an e-money issuer license from Bank Negara Malaysia under the PSA. This process involves thorough due diligence, assessment of financial soundness, risk management capabilities, and compliance with all relevant guidelines.
As Securities/Digital Token (Regulated by Securities Commission Malaysia - SC):
Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLATFPUAA 2001)
AML/CFT and Targeted Financial Sanctions for Financial Institutions (AML/CFT TFS for FIs) Policy Document (BNM Policy Document): Issued by Bank Negara Malaysia, this comprehensive policy document provides detailed guidance and requirements for reporting institutions to comply with AMLATFPUAA 2001. This document has specific sections/appendices applicable to "Digital Currencies" or "Virtual Assets."
Capital Markets and Services Act 2007 (CMSA): For digital assets that are deemed "securities," the Securities Commission Malaysia (SC) regulates entities like Digital Asset Exchanges (DAX) under this Act and its accompanying guidelines. These entities are also subject to specific AML/CFT requirements imposed by the SC.
Customer Identification and Verification:
Beneficial Ownership: Identify and verify the ultimate beneficial owner (UBO) for all corporate and legal arrangements. This involves looking through layers of ownership to identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.
Non-Face-to-Face (NFF) Customers: Given the online nature of many VASPs, robust measures for NFF CDD are crucial, including multi-factor authentication, video verification, and cross-referencing with reliable independent sources.
Politically Exposed Persons (PEPs): Implement Enhanced Due Diligence (EDD) measures for PEPs, their family members, and close associates, including obtaining senior management approval to establish or continue the relationship and taking reasonable measures to establish the source of wealth and funds.
High-Risk Customers: PEPs, customers from high-risk jurisdictions (e.g., those identified by FATF), customers involved in cash-intensive businesses.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure consistency with the VASP's knowledge of the customer, their business, risk profile, and source of funds. Update customer information regularly.
Source of Funds/Wealth: For higher-risk customers or transactions, obtain information on the source of funds or source of wealth.
Entity Targeted: Binance Holdings Limited and its CEO, Changpeng Zhao (CZ). Violation Type: Operating a Digital Asset Exchange (DAX) without registration/license, which is a violation under the Capital Markets and Services Act 2007. The SC considers digital assets as securities, and operating a platform for trading them requires authorization. Penalty Amount: No explicit monetary fine was announced at the time of the public reprimand. The penalties were operational: a public reprimand, an order to cease all operations in Malaysia, disable access to its website and mobile applications, and cease all media and marketing activities targeting Malaysian investors. Outcome: Binance was forced to shut down its direct operations in Malaysia. Malaysian users were advised to withdraw their funds. The action led Binance to later pursue a compliant pathway to re-enter the Malaysian market by acquiring a stake in and partnering with a licensed local Digital Asset Exchange (DAX), MX Global, demonstrating the effectiveness of the SC's enforcement in driving regulatory compliance.
Entity Targeted: Various unauthorized digital asset platforms, investment schemes involving crypto, and individuals promoting them. (Specific names are too numerous to list here, but are updated frequently). Violation Type: Operating or promoting unauthorized investment schemes, digital asset exchanges, or services without the necessary licenses or approvals from the SC Malaysia. Penalty Amount: Typically no specific monetary penalty is announced publicly for being added to the alert list. The "penalty" is a public warning, which often leads to the platform being unable to operate effectively in Malaysia and subsequent cessation of operations or blocking of access. Outcome: Public awareness is raised, and investors are warned against dealing with these entities. This often leads to reduced or ceased operations for the targeted entities within Malaysia.
Evidence fact my.tax not found (may have been renamed).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A crypto-funded debit card program in Malaysia requires either a BNM e-money issuer license (if using stablecoins classified as e-money with RM 5M capital and trust-account safeguards) or an SC-registered DAX exchange partner (RMO, MYR 5M shareholders' funds) for the crypto-to-fiat conversion leg, plus a licensed financial institution for BIN sponsorship; full AML/CFT obligations under AMLATFPUAA 2001 apply to all cardholders, and SC has demonstrated aggressive enforcement against unregistered operators.
Questions this verdict aims to answer
- What e-money / payment-institution license is required?
- How is the crypto-to-fiat conversion regulated?
- What KYC and AML obligations apply to cardholders?
- What partner-bank or BIN-sponsor arrangements are required?