

When a digital-asset cyberattack is underway, the relevant intelligence rarely sits in one place.
A financial institution may see attempted cash-out activity. An exchange may control a receiving account. Analytics and cybersecurity firms may hold different technical indicators. One federal agency may have intelligence about a state-sponsored actor while another has authority to act.
The challenge is connecting them before the threat actor moves the assets, changes infrastructure, or reaches another jurisdiction.
Section 10904 of the updated CLARITY Act addresses that coordination problem. It would establish a Digital Asset Cyber Innovation Center, called the DACIC, within the Treasury Department. The proposed center would bring federal agencies and private-sector organizations into a coordinated response structure focused primarily on state actors that target digital assets or use them for illicit purposes.
The July 22 text analyzed in this article remains proposed legislation. The Senate did not pass H.R. 3633 before its August state work period. A cloture motion on whether to advance to consideration is scheduled to ripen on September 15, 2026, but that is a procedural step, not final passage, and Section 10904 could still change.
Short answer: Section 10904 would establish a Treasury-based Digital Asset Cyber Innovation Center operated with federal partners and in collaboration with the private sector. The center would focus on state-linked cyberattacks, theft, scams, money laundering, and sanctions evasion. It would support real-time information sharing, emergency response, lawful fund recovery, international coordination, security standards, and annual reporting on outcomes such as threat actors disrupted, dollars recovered, and the speed of information sharing.
The DACIC would be established inside the Treasury Department and operated in partnership with:
Its stated role would be to counter threats from state actors that target digital assets for funding or use digital assets for illicit purposes. At the same time, it would be directed to support innovation, digital economic safety, and advances in digital-asset security and compliance.
Section 10904 names the Democratic People’s Republic of Korea and the Islamic Republic of Iran as examples of state actors whose activity the center would seek to identify and disrupt.
This is therefore not a general consumer-complaint center or a replacement for every existing cybercrime program. It is a proposed coordination focal point with a national-security emphasis.
The text would require the center to be fully operational no later than one year after enactment.
Section 10904 gives the proposed center several connected responsibilities.
The Treasury, coordinating with participating agencies, would analyze state-generated money laundering, sanctions evasion, and other illicit financial flows involving digital assets.
It would also assess:
The assessment would test whether existing capabilities work, where adoption remains limited, and how public and private resources can be combined.
The center would work to disrupt cyberattacks, scams, theft, sanctions evasion, and money laundering in the digital-asset ecosystem, with a focus on state actors.
It would coordinate federal authorities, private-sector partners, and international law-enforcement and intelligence agencies.
The bill specifically contemplates efforts to neutralize the use of noncompliant international exchanges and over-the-counter desks as cash-out points.
The DACIC would support efforts to seize criminal proceeds derived from illicit digital-asset transactions. The text calls for stolen funds to be promptly identified, traced, and recovered, with seizures conducted under appropriate legal frameworks.
StepOperational purposeIdentifyDetermine which assets, wallets, accounts, or transactions may be relevantTraceFollow the movement of assets and develop the financial pictureCoordinateConnect the organizations with intelligence, control, jurisdiction, or legal authorityPreserve or restrictUse available institutional controls or lawful process to prevent further movement when appropriateSeizeGovernment takes control of assets through applicable legal authorityRecoverComplete the legal and operational process needed to restore or otherwise dispose of assets
Information sharing can support each stage, but it does not replace legal process. A wallet label or investigative lead does not by itself authorize a seizure.
Section 10904 would direct the center to establish an Emergency Response Initiative for active digital-asset attacks and major security incidents.
The initiative would identify:
That team could include technical experts, legal advisors, blockchain-forensics specialists, and coordination officers. It would work with affected entities to contain attacks, preserve evidence, and initiate recovery efforts.
The operational lesson is direct: during an incident, organizations should not have to determine authority, communication channels, and available actions from scratch.
Digital-asset theft and laundering routinely cross national borders. Section 10904 would create an International Coordination Office to engage foreign law-enforcement agencies, regulators, financial institutions, and international organizations.
Its work could include coordinating cross-border responses and applying pressure to noncompliant exchanges or over-the-counter desks used by sanctioned persons, adversarial states, or other illicit actors.
Even effective domestic coordination may fail if assets reach an overseas service that will not cooperate.
The center would work with public and private standards bodies, including the National Institute of Standards and Technology, to develop technical standards and widely accepted security benchmarks.
It would also partner with:
The text would direct the center to establish a digital-asset-focused Rewards for Justice program. It could offer incentives to white-hat hackers and security researchers who identify vulnerabilities, provide actionable intelligence about threat actors, or assist in recovering stolen assets.
Section 10904 specifically identifies exchanges, blockchain analytics firms, cybersecurity companies, web3 development platforms, private-sector consortia, and other relevant parties.
Their continuous information exchange would focus on:
The center would promote frequent, real-time information sharing between the public and private sectors so that emerging threats could receive an efficient response.
Banks, exchanges, payment companies, and other regulated organizations can become critical nodes when illicit assets enter, exit, or move between systems. Participation would still require lawful sharing, authentication, permissions, escalation procedures, and protection of sensitive information.
Deconfliction answers a focused but important question: does this wallet, entity, transaction, or piece of intelligence overlap with activity another authorized organization is already examining?
That can help users discover related investigations, identify a coordination partner, connect an institutional alert to verified context, and route intelligence toward an organization with relevant authority or control.
Deconflict supports this work by helping authorized law-enforcement and financial-institution users connect Verified Intelligence across organizational boundaries.
It does not replace blockchain analytics, cybersecurity incident response, transaction monitoring, sanctions screening, case management, legal review, or lawful process. It does not determine that a person or wallet is criminal. It does not seize or recover assets.
Its role is to help participants see overlap and connect fragmented context in time to affect an outcome.
The Digital Asset Cyber Innovation Center, or DACIC, is a proposed Treasury-led coordination center under Section 10904 of the CLARITY Act. It would focus on state-linked cyberattacks and illicit activity involving digital assets, including theft, scams, money laundering and sanctions evasion.
No. Section 10904 remains proposed legislation. The Senate has not passed H.R. 3633, and the provision could change during the legislative process.
The proposed center would work with federal agencies including DOJ, DHS, FBI, Secret Service, DoD, SEC and CFTC. It would also collaborate with exchanges, blockchain analytics firms, cybersecurity companies, Web3 platforms, researchers and international partners.
No. The proposed center would support the identification, tracing and recovery of illicit digital assets, but a seizure or recovery would still require the appropriate legal authority and cooperation from the entities that control the assets or accounts.
Deconfliction helps authorized participants determine whether a wallet, transaction, entity or technical indicator overlaps with another active investigation. It can connect fragmented intelligence and direct teams to the relevant coordination partner earlier, while leaving investigative decisions, legal review and asset recovery to the organizations with authority to act.