CiberLATAMbywhalemate

Brazil's BCB tightens crypto and Pix rules

Brazil tightened crypto, Pix, and security rules, setting final deadlines, adding bank restrictions, and expanding controls.

Whalemate Labs · AI-assisted researchPublished:Updated 6 min read

Brazil's central bank tightened rules for virtual asset service providers, Pix transactions, and financial system security controls. Current measures include minimum crypto capital requirements, new governance rules, and automatic restrictions in Pix for new devices.

Update October 2, 2026: Brazil's central bank added a new restriction for unlicensed crypto firms. According to the coverage reviewed, from November 6, 2026, institutions authorized by the regulator will no longer be able to conduct or facilitate transactions with virtual asset service providers that are not cleared to operate in Brazil.

The Central Bank of Brazil tightened rules in 2025 and 2026 for virtual asset service providers, Pix transactions, and financial system security controls. Measures already disclosed include minimum crypto capital requirements of between R$10.8 million and R$37.2 million, new governance and cybersecurity requirements, changes to the Special Return Mechanism, and automatic restrictions in Pix for new devices.

What changed for crypto companies?

The Central Bank set minimum capital of up to R$37.2 million for companies that operate with cryptoassets in Brazil, according to LetsMoney and Valor Econômico, under Central Bank resolutions No. 519, 520, and 521/2025. Valor also reported that the regulatory floor was set between R$10.8 million and R$37.2 million, depending on the activity and the risks involved.

The final regulation announced in November 2025, according to Valor Econômico, requires governance structures, internal controls, risk management, security, AML/CFT procedures, technical certification, audits, and periodic reporting to the regulator. Other coverage says the framework also requires segregation of customer assets, compliance with the Travel Rule, and consumer protection.

FCM Law detailed that Central Bank Resolution No. 520/2025 governs the creation and operation of virtual asset service companies, with requirements covering corporate form, operating models, outsourcing, cybersecurity, disclosure, and market abuse prevention. The same firm said Resolution No. 521/2025 brings certain virtual asset uses into the foreign exchange regime, including international transfers using crypto, stablecoins, transfers to self-custody wallets, and card funding with virtual assets.

Central Bank Resolutions No. 519/2025, 520/2025, and 521/2025 have been in force since February 2026 and create the Virtual Asset Service Provider company category, or SPSAV, according to Exame. That same report said companies operating with virtual assets in Brazil must be incorporated in the country, have headquarters and management in Brazilian territory, and appoint directors responsible for risk, anti-money laundering, and cybersecurity.

Exame also reported that the rules apply to banks, payment institutions, and virtual asset service providers that let customers trade, hold, or transfer cryptocurrencies. The Rio Times added that custodians, intermediaries, and brokers must meet capital, governance, cybersecurity, anti-money laundering and terrorist financing, and consumer protection requirements, in line with Law 14,478/2022.

Local crypto outlets noted that, after Central Bank Resolutions 519, 520, and 521, international payments and transfers using virtual assets are now legally treated as foreign exchange transactions. Livecoins said that this forces payment gateways and solutions such as BRICS Pay to operate under licensing and foreign exchange market limits, adding another layer of regulatory control over crypto-based remittances and cross-border payments.

What deadline remains to request authorization?

Virtual asset firms already operating before the new framework have until October 30, 2026, to request authorization from Brazil's central bank, according to The Rio Times and FinanceFeeds. If they do not file within that transition period, they risk being pushed out of the regulated market.

Obitcoin also reported that, from October 30, 2026, institutions regulated by the Central Bank, including banks and payment institutions, will not be allowed to provide services to VASPs that are not authorized or that have not submitted a request for authorization to the regulator. The restriction is based on article 91 of Resolution No. 520.

That end of the transition period applies to both domestic and foreign operators. FinanceFeeds described it as a cutoff point for exchanges and other crypto firms that have not regularized their status with the Central Bank.

What do the new Pix rules cover?

Measures published in 2026 reinforce Pix security and add operational controls to reduce fraud, according to Globoplay, MixVale, Cryptoid, Hora AGHA, Clearingpost, and Gabriel Valerio Advocacia. The most visible change is the extension of the deadline to respond to returns under the MED, which went from 30 to 80 calendar days starting September 1, 2026.

Cryptoid reported that Central Bank Normative Instruction No. 766/2026 was published on July 27, 2026, and took effect on September 1, consolidating version 8.5 of the DICT Operational Manual and formalizing Pix administrative disputes linked to the MED. Hora AGHA said the new 80-day period starts on the date the return was made, while Gabriel Valerio Advocacia noted that the MED became mandatory for participating institutions on February 2, 2026.

MixVale added that the Central Bank also tightened Pix rules for transfers made from new mobile phones and computers, with automatic value limits on the first transactions. Clearingpost said implementation of Normative Instruction No. 766/2026 is rolling out in phases, and that first stage is linked to the removal of the R$500 cap for contactless Pix payments starting in October 2026.

What does the Central Bank require on testing and security?

The Central Bank also expanded penetration testing requirements for banks and financial institutions, covering internet banking, mobile banking, Pix APIs, cloud environments, Active Directory, and systems integrated with STR and RSFN, according to Vantico. That scope also includes third-party assets that support critical operations.

Vantico's analysis also said pentest reports must include technical proof of exploitation for each finding, explicit mapping of the vulnerability to regulatory requirements, retest evidence confirming remediation, and a correction plan with owners and deadlines. A Revista added new security, governance, and protection requirements for information technology providers serving financial institutions.

A Revista also said, although as a reference attributed to the same coverage and not officially confirmed in the material, that Resolution No. 584 предусматривает a precautionary hold of up to 24 hours for certain transfers of virtual assets above the equivalent of US$10,000, sent abroad or to self-custody wallets, with an effective date planned for January 2027. The magazine's report also places these measures within a broader tightening by the Central Bank and the National Monetary Council on security, governance, and protection across the financial system.

What effect could this have on the market?

Coverage from Valor Econômico, LetsMoney, and international outlets agrees that the new minimum capital and other prudential requirements will reduce the number of viable participants in Brazil's crypto market. Valor even said only ten crypto startups should obtain a Central Bank license under this framework.

Crypto.news, Mitre, Cryptopolitan, and CryptoNews.net described a framework in which banks, custodians, intermediaries, and brokers can offer customers exposure to cryptoassets, but outside their own balance sheets and under stricter rules on capital, asset segregation, independent auditing, cybersecurity, AML/CFT, the Travel Rule, and consumer protection. Revista Tópicos added that Resolution No. 519/2025 shifts part of the due diligence burden into the regulated perimeter, especially for transactions involving self-custody wallets and cross-border crypto flows.

Bitnoticias summarized that, to obtain authorization, companies must document at least five areas: business model and risks, corporate and governance structure, AML/CFT and cybersecurity policies, evidence of operational and technological capacity, and the organization of evidence and processes for the authorization file.

What changes for authorized entities starting in November?

From November 6, 2026, according to coverage from Estudando Direito on Resolution No. 520/2025 as amended by Resolution No. 588, institutions authorized by the Central Bank will not be allowed to conduct or facilitate transactions with virtual asset service providers that do not have authorization to operate in Brazil.

That new ban adds to the transition deadline that expires on October 30, 2026, for VASPs to request authorization. The coverage reviewed presents it as another step in the regulatory squeeze on exchanges and other crypto firms that remain outside the authorized perimeter.

The same material links it to article 91 of Resolution No. 520 and to the obligation to cut operational ties with unlicensed providers. In this way, the Central Bank further closes off access for unauthorized players to Brazil's regulated system.

Sources

View all