Fifteen crypto platforms get PMLA notices; the products stay unregulated
The FIU-IND Director issued Section 13 notices to fifteen virtual digital asset service providers and sought takedown of their apps and URLs, while the same release calls crypto products unregulated.
What happened
- The Director, FIU-IND issued notices for non-compliance to fifteen Virtual Digital Assets Service Providers under Section 13 of the Prevention of Money Laundering Act, 2002.
- The trade names are Weex, Blofin, Rezorex, Bitunix, DigiFinex, Toobit, XT.com, Latoken, WOO X, Pionex, ChangeNow, SimpleSwap, Fixedfloat, WhiteBIT and Guardarian, each listed against a separate corporate entity name.
- As nodal officer under Section 79(3)(b) of the Information Technology Act, 2000 read with rule 3(1)(d) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025, the Director also issued notices to take down those applications and URLs from public access.
- VDA SPs were brought into the AML/CFT framework under the PMLA in March 2023; providers operating in India, offshore or onshore, must register with FIU-IND as reporting entities.
- The obligations are activity-based and not contingent on physical presence in India, and the release states that crypto products and NFTs are unregulated and can be highly risky.
For Prelims
- FIU-IND: the Financial Intelligence Unit-India, whose Director issued the non-compliance notices to fifteen VDA SPs on 9 September 2026.
- Section 13, PMLA 2002: the provision the notices were issued under; the release cites it and does not set out what the Director may do next.
- VDA SP: a provider engaged in four named activity classes - exchange between virtual digital assets and fiat currencies, transfer of virtual digital assets, safekeeping or administration, and instruments enabling control over them.
- March 2023: when VDA SPs were brought into the AML/CFT framework under the Prevention of Money Laundering Act, 2002.
- Reporting entity: the status a VDA SP must take by registering with FIU-IND, carrying reporting and record-keeping obligations under the PMLA and its Rules.
- Activity-based test: the obligations apply to providers operating in India whether offshore or onshore and are not contingent on physical presence in India.
- Takedown route: Section 79(3)(b) of the Information Technology Act, 2000 read with rule 3(1)(d) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025; the FIU-IND Director is the nodal officer.
- Regulatory status of the asset: the release states that crypto products and NFTs are unregulated and that there may be no regulatory recourse for any loss.
For UPSC: This is the cleanest available illustration that India polices crypto through anti-money-laundering law rather than through a dedicated statute. Use it on AML/CFT architecture and reporting entities, on the extraterritorial reach of activity-based regulation, and on the gap between regulating an intermediary and regulating an asset. It also pairs a compliance power with an intermediary takedown power, which is useful on enforcement design.
What it is NOT: The release records no penalty: it does not state what Section 13 permits the Director to impose, whether any of the fifteen has been heard, by when they must reply, to whom the takedown notices went, or whether any application or URL has actually been blocked. It alleges no transaction volume, no laundered amount and no specific breach against any named entity, gives no total of VDA SPs registered with FIU-IND against which fifteen could be read, and names no statute governing crypto assets themselves - on its own account those products remain unregulated.
For Mains
Syllabus: GS3.18 · GS2.9 · Linkage L2
Anchor
India enforces against crypto without having legislated on it. The fifteen notices of 9 September 2026 were issued under the Prevention of Money Laundering Act, 2002, not under any crypto statute, and the same release warns that crypto products and NFTs are unregulated. The intermediary is governed; the asset is not.
Substantiation (data)
Fifteen VDA SPs noticed under Section 13 of the PMLA, 2002; a parallel set of notices to take down their applications and URLs under Section 79(3)(b) of the IT Act, 2000 read with rule 3(1)(d) of the 2025 Intermediary Guidelines Amendment Rules; and a regime dating to March 2023, when VDA SPs entered the AML/CFT framework.
Exemplification
Use the activity-based test as the worked example of extraterritorial regulatory reach. Obligations attach to exchange between virtual digital assets and fiat currency, transfer, safekeeping, administration and instruments enabling control - and are not contingent on physical presence, so a platform with no office in India is still a reporting entity.
Comparison
Set the two instruments side by side. The Section 13 notice is a compliance demand on a reporting entity and assumes the firm will answer. The Section 79(3)(b) notice works on the intermediary layer to pull an application or URL out of public access. One disciplines the firm; the other reaches the user even when the firm ignores India.
Problematisation
A notice opens a proceeding; it does not close one. The release records no penalty, no hearing, no amount alleged to have been laundered and no date by which the fifteen must reply. It also gives no total of VDA SPs registered with FIU-IND, so the figure fifteen carries no denominator and no measure of how much of the market is outside the net.
Position
Argue that anti-money-laundering law is doing work a crypto statute has not been written to do. Registration, record-keeping and reporting give the state visibility into flows and a takedown lever, but they settle nothing about legality, custody or investor protection in the asset itself - which the release concedes when it calls crypto products unregulated.
Deploys into: Regulating an activity rather than an entity's location · AML/CFT architecture and reporting entities under the PMLA · Regulating crypto exchanges in the absence of a crypto statute · Intermediary liability and takedown powers under the IT Act · Enforcement notice versus adjudicated penalty
Ministry of Finance · 2026-09-09 · PRID 2308131 · PIB source ↗