Skip to content
All insights
ComplianceAugust 17, 2026 · 9 min read

SAR and STR filing for stablecoin transactions: what to report, what on-chain detail to include and when

SAR filing for stablecoin activity uses the same suspicion test as fiat, but the report must carry hashes, addresses and chain, and the clock differs by nation.

By Jay Kambo
Illustration — SAR and STR filing for stablecoin transactions: what to report, what on-chain detail to include and when
Key takeaways
  • The trigger for a SAR in the US or an STR in Canada is the same for stablecoin activity as for fiat: known or suspected illicit activity, or reasonable grounds to suspect, not the mere use of a blockchain.
  • A useful on-chain filing names the chain, the token, the transaction hash, the sending and receiving addresses and the fiat equivalent at the time, in the narrative or the designated fields.
  • In the US a SAR is due within 30 calendar days of initial detection, extendable to 60 days if no suspect is identified; in Canada an STR is due as soon as practicable once reasonable grounds to suspect are reached.
  • Confidentiality is absolute: the subject must not be told a report was filed, and that constraint shapes how a held stablecoin settlement is explained to a customer.
  • Continuing activity needs continuing reports, which means the case must link the original filing to later transactions by address and hash.

SAR filing for stablecoin transactions works on the same legal test as for any other activity: in the United States a financial institution files a Suspicious Activity Report with FinCEN when it knows, suspects or has reason to suspect that a transaction involves illicit funds or has no apparent lawful purpose, and in Canada a reporting entity files a Suspicious Transaction Report with FINTRAC when it has reasonable grounds to suspect a link to money laundering or terrorist financing. The blockchain does not lower or raise that bar. What changes is the evidence, because an on-chain settlement gives the filer facts that a wire never could, and the report is only useful if those facts are included. This article covers the triggers, the on-chain detail to include, the timing rules as of mid-2026 and the confidentiality obligations.

What triggers a SAR or an STR when the settlement leg is on-chain?

The trigger is the conduct, not the rail. A stablecoin settlement that is fully explained by the underlying commercial transaction, with a customer whose KYB is current and a counterparty wallet that screens clean, is not suspicious because it moved on Ethereum or the XRP Ledger. Suspicion arises from the same patterns as in fiat, plus a set that is specific to on-chain activity. The specific patterns include a receiving wallet that a screening tool links to a sanctioned entity, a mixer or a darknet market; funds that arrive from an address only a few hops from a known illicit source; structuring of transfers just below a reporting threshold across a 24-hour window; a customer who insists on a self-hosted wallet after refusing to explain its origin; and a chain hop pattern where funds move across bridges with no commercial reason.

Thresholds matter for the US filing decision. A money services business must file a SAR for a transaction of USD 2,000 or more that it knows, suspects or has reason to suspect meets one of the reporting categories, while banks apply a USD 5,000 threshold for most categories. Canada has no monetary threshold for an STR; reasonable grounds to suspect on a CAD 50 transfer requires a report. The operational rule for a KYT alert on a stablecoin flow is therefore: the alert opens a case, the case is reviewed against the pattern list, and the case closes either with a documented no-filing decision or with a filing.

What on-chain detail should the report include?

FinCEN's 2019 advisory on illicit activity involving convertible virtual currency asked filers to include virtual currency addresses, transaction hashes and related identifiers in the SAR narrative, and to use the designated virtual currency fields where the form provides them. FINTRAC's STR form and its guidance for virtual currency reporting entities ask for similar detail, including the virtual currency type, the amount, the exchange rate used and the wallet addresses involved. A report that says a customer sent stablecoins to a suspicious wallet, without naming the wallet, gives the analyst at the financial intelligence unit nothing to link.

  • Name the blockchain and the token, for example USDC on Ethereum mainnet or USDT on Tron, because the same address format can exist on several networks and the token contract identifies the asset.
  • Include every relevant transaction hash, in full, as a separate line in the narrative so that it can be copied and searched without transcription error.
  • List the sending and receiving addresses for each transaction, and state which address belongs to the customer, which is the counterparty and which, if any, is an intermediary or bridge contract.
  • State the fiat equivalent at the time of each transaction, the exchange rate used and the source of that rate, which is the same discipline FINTRAC requires for large virtual currency transaction reports.
  • Record the screening result that raised the alert, including the tool used, the risk category assigned to the counterparty address and the date of the screen.
  • Attach the ISO 20022 identifiers where the flow began as a payment instruction, in particular the UETR and the end-to-end identification, so that the fiat and on-chain legs can be tied together.

The structured filing fields should carry what they can, and the narrative should carry the rest in a consistent order: who, what, when, where, why suspicious, and how the institution responded. The narrative is read by a human analyst, so a chronological account of the pattern, followed by the list of hashes and addresses, is more useful than a wall of identifiers with no explanation.

What are the timing rules in the United States and Canada as of mid-2026?

In the United States the rule has not changed in substance for many years. A SAR must be filed no later than 30 calendar days after the date of initial detection of facts that may constitute a basis for filing. If no suspect is identified on that date, the institution may delay filing for a further 30 calendar days to identify a suspect, but in no case may the filing be later than 60 calendar days after initial detection. Continuing activity is reported on a 90-day review cycle, with the continuing SAR filed within 120 days of the previous filing. The date of initial detection is a decision point that examiners probe: it is the date the institution concluded that the activity warranted review at the SAR level, not the date the first alert fired, and the institution should record how it fixed that date.

In Canada the rule changed in 2021. The former 30-day deadline was replaced by an obligation to submit the STR as soon as practicable after the reporting entity has completed the measures that enabled it to establish reasonable grounds to suspect. FINTRAC's guidance is that once that threshold is reached, preparing and submitting the report must be treated as a priority. There is no fixed day count, which in practice means the institution must be able to show a short and documented interval between the reasonable grounds determination and the submission. A stablecoin settlement that is held pending review therefore has two clocks: the customer's expectation of settlement in minutes, and the compliance requirement to reach a determination without delay.

The blockchain gives the filer a complete, timestamped record of where the money went. A suspicious report that leaves the hashes out is choosing to file with less evidence than it holds.

How does a held stablecoin settlement interact with the filing decision?

A settlement on a public blockchain is final once confirmed, so the moment to intervene is before signing. When KYT raises an alert on an outbound instruction, the compliance workbench holds the instruction, a pacs.002 status report goes back to the originating institution with a pending status, and the case opens. Three outcomes are possible. The case clears and the transfer proceeds. The case results in a decline, and a pacs.002 reject with a reason code is issued, with or without a filing. Or the case results in a filing and the institution decides, on a risk basis, whether to proceed with the transaction, which is a lawful choice in both jurisdictions provided the report is made.

A filing is not the same as a block. Neither FinCEN nor FINTRAC requires an institution to refuse a transaction because it reported it, and there are cases where completing a transaction preserves the evidential trail. What the institution must not do is tell the customer that a report was filed or is being considered. When an inbound stablecoin receipt has already settled on-chain and the alert fires on receipt, the institution cannot reverse the transfer, but it can hold the credit to the customer's ledger balance, file, and decide whether to return the funds by a fresh transaction, which is the on-chain equivalent of a pacs.004 return.

What are the confidentiality obligations, and how do they affect customer communication?

In the United States, 31 USC 5318(g)(2) prohibits an institution and its staff from notifying any person involved in the transaction that a SAR has been filed, and the prohibition extends to any information that would reveal the existence of the report. In Canada, tipping off is an offence under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, and FINTRAC guidance treats disclosure of an STR or of the intent to file as prohibited. Both regimes allow disclosure to the regulator and to law enforcement, and the US regime allows sharing within a corporate group under specific conditions.

The practical consequence is that customer-facing staff need a script that explains a hold without explaining the reason. The pacs.002 reason code sent to a counterparty institution should be a neutral code such as pending compliance review rather than anything that signals a report. Internal case notes should be held in a restricted area of the compliance system, and the audit trail should record who accessed the case. The examiner will ask for the institution's confidentiality policy, evidence of training, and the access controls on the case management system.

How should the institution handle continuing activity and record retention?

Suspicious activity rarely stops after the first report. In the US, continuing activity should be reviewed at least every 90 days and a continuing SAR filed where it persists, referencing the prior report. In Canada, a further STR is expected each time new suspicious activity is identified, and FINTRAC accepts reports that reference earlier submissions. On-chain activity makes linkage easier, because the addresses persist: the case management system should store the customer's known addresses and the flagged counterparty addresses, and every new transaction touching them should attach to the open case automatically.

Both regimes require the report and its supporting documentation to be retained for five years. Supporting documentation for a stablecoin case includes the screening result, the case notes, the hashes and addresses, the fiat conversion record and the decision log. Because the blockchain itself is public, the institution does not need to preserve the ledger, but it does need to preserve its own view of it at the time of the decision, since address risk scores change as new information emerges. A tamper evident audit trail that timestamps each step is what turns a case file into evidence.

Where StableNet fits

StableNet, built by SpendTheBits, is a cross border B2B payment and settlement platform for banks, credit unions, licensed money service businesses, exchange houses and remittance fintechs, and it is designed so that the suspicious activity decision happens before the on-chain leg rather than after it. KYT transaction monitoring, wallet screening and sanctions and PEP screening run inside the flow, and a hit holds the instruction in the compliance workbench while a pacs.002 status report, tracked by UETR, tells the originating institution the payment is pending. Settlement is in regulated stablecoins such as USDC and USDT on public blockchains, so every completed transfer has a hash and addresses that the tamper evident audit trail preserves alongside the ISO 20022 identifiers, ready to be lifted into a SAR or STR narrative. Customers keep custody throughout. SpendTheBits is a Bank of Canada registered payment service provider and a named finalist in the Swift Hackathon 2026 Technical Challenge.

See it on your corridors

Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.

FAQ

Common questions

No. The legal test in both the United States and Canada is about the conduct and the facts known to the institution, not the rail. A stablecoin settlement that is explained by a documented commercial transaction, with a current KYB file and counterparty wallets that screen clean, is not suspicious because it is on-chain. Suspicion arises from patterns such as links to sanctioned or illicit addresses, structuring, unexplained self-hosted wallets or chain hopping with no business reason.