Skip to main content
Legal Reference

A public blockchain is not a records archive

Nick Kampe
10 min read

A transaction may remain visible on a public blockchain for years. That does not mean the chain preserves the complete record a regulated firm must keep, or the evidence counsel will need in a dispute.

On September 24, 2026, three divisions of the Commodity Futures Trading Commission added new recordkeeping answers to their crypto assets and blockchain technologies FAQ. The staff position is practical: a covered entity may use blockchain technology to create and maintain regulatory records. The technology does not displace the recordkeeping obligation.

That distinction matters when a trading venue, clearing organization, swap dealer, futures commission merchant, or swap counterparty says the responsive record is "on the blockchain." The public transaction may be one part of the record. The entity's metadata, account mapping, correction history, system controls, and production capability may be separate evidence.

What CFTC staff changed on September 24

The CFTC release announcing the update says staff added guidance on tokenized investments of customer funds and the use of blockchain technology for recordkeeping. Questions 13 through 15 address records.

Question 13 says CFTC Regulation 1.31 is technology neutral. Staff would not object if a records entity used blockchain technology to create and maintain onchain records, provided the entity fully satisfies the rule.

Question 14 applies the same position to swap records under Regulation 45.2. It names swap execution facilities, designated contract markets, derivatives clearing organizations, swap dealers, major swap participants, and certain other counterparties.

Question 15 addresses a narrower point. Staff would not object solely because one of those entities chose not to maintain an offchain version of a record. If the entity uses a public and permissionless network, staff said it should establish systems and controls that allow it to retain and produce the record during an emergency or disruption, including an outage affecting the network or its associated block explorer.

The FAQ is staff guidance, not a Commission rule. Footnote 2 says the answers represent the views of the named divisions, create no enforceable rights, do not amend existing rules, and do not supply a no-action position. Counsel should cite the underlying regulation for the obligation and use the FAQ to understand how staff currently applies it to blockchain systems.

The regulatory record is larger than the transaction

Regulation 1.31 defines a regulatory record to include books and records required by the Commodity Exchange Act or CFTC regulations. For electronically stored books and records, the definition also reaches data needed to access, search, or display them, plus electronically stored data describing how and when they were created, formatted, or modified.

That text matters in discovery. A block explorer page may display a transaction hash, addresses, an amount, a block reference, and emitted events. It usually does not identify the firm's customer account, the order or position that caused the transfer, the employee or automated process that approved it, the source used to decode contract data, or a later internal correction.

Regulation 1.31 also requires systems and controls that support the authenticity and reliability of electronic regulatory records. Electronic records must remain accessible for the required retention period. Upon a CFTC request, the entity must promptly produce them in the form and medium specified by the Commission, unless the Commission directs otherwise.

Regulation 45.2 requires covered entities to keep full, complete, and systematic swap records with pertinent data and memoranda. It also makes those records available for inspection by designated government authorities and addresses the form in which copies must be provided.

Neither rule treats public visibility as completeness. The chain can show that a particular network accepted a transaction at a particular place in its history. Whether that transaction settled a customer's obligation, changed a firm's books, satisfied a margin call, or corresponded to an authorized instruction may depend on records outside the chain.

Immutability does not solve production

People often use "immutable" as shorthand for permanent, complete, and self-explaining. Those are different propositions.

A public chain may preserve transaction data while an explorer changes its interface, removes decoded fields, loses an API feature, or becomes unavailable. Contract interpretation can also change when an ABI is corrected or a proxy begins using a new implementation. The underlying bytes may remain, but the means used to search and explain them may not.

The CFTC addressed this point when it revised Regulation 1.31 in 2017. The final recordkeeping rule was intended to make the form and manner of retention technology neutral while preserving authenticity, reliability, retention, and production requirements. The 2026 FAQ applies that existing design to blockchain systems.

For counsel, an explorer URL should be treated as a locator, not the whole acquisition. Reproducible blockchain evidence requires the network, block and transaction identifiers, collection time, raw response, query method, and source provenance. When the producing party is a regulated entity, the request should also reach the internal records that give the public transaction business meaning.

Ask which system holds each fact

"Produce the blockchain records" is too vague for most contested matters. It invites a stack of explorer PDFs and leaves the important systems untouched.

Start by separating the facts in dispute. If the issue is whether a transfer executed, request the raw transaction, receipt, relevant logs, block reference, and the decoding materials used by the entity. If the issue is authorization, request the instruction, account mapping, approval record, access logs, and applicable role or policy data. If the issue is valuation or margin, request the price source, timestamp, haircut, calculation inputs, and the ledger entry that used them.

A focused request may seek:

  • the canonical network identifier, transaction hash, block number, and raw node or provider response retained by the entity;
  • data needed to search, access, display, and decode the record, including the contract address, ABI version, proxy implementation, token decimals, and relevant internal schema;
  • the mapping between blockchain addresses and the firm's customer, account, order, position, wallet, or custody records;
  • corrections, annotations, reversals, exception records, and modification metadata associated with the transaction;
  • policies, architecture documents, control tests, and outage procedures for the blockchain recordkeeping system; and
  • records showing whether the firm could produce the material when its normal explorer, provider, or network path was unavailable.

The correct scope depends on the claim, the entity, and the governing retention rule. Regulation 1.31 does not make every system artifact relevant to every case. It does make it harder to defend a blanket response that the explorer page is all that exists.

In federal civil litigation, Rule 34 allows a request to specify the form of electronically stored information and requires requests to describe items with reasonable particularity. The rule does not create routine direct access to an opponent's systems. A request for raw JSON, native audit records, and the data dictionary may be more useful and less intrusive than asking to inspect a production database.

Hypothetical: an onchain margin transfer

Assume, hypothetically, that a futures commission merchant accepts an eligible crypto asset as customer margin and records the movement on a public EVM network. A later dispute concerns whether the firm credited the correct account before liquidation.

The transaction receipt can show that tokens moved from one address to another and that execution succeeded. It cannot, by itself, establish which customer account the destination represented in the firm's books. It also may not show when the firm's risk engine recognized the deposit, which price and haircut the firm applied, whether a confirmation threshold delayed credit, or who handled an exception.

Counsel should preserve the public transaction immediately. The production request should then connect it to the firm's account ledger, address registry, margin calculation, confirmation policy, exception queue, and system timestamps. If the firm says its blockchain record is the regulatory record, questions 13 and 15 of the FAQ make its authenticity, reliability, and outage-production controls fair subjects for examination.

This does not prove misconduct. A timing difference may follow a disclosed confirmation policy or another valid control. The point is narrower: the public transaction and the firm's legal or operational treatment of it are separate facts.

What the new FAQ does not decide

The update does not turn every onchain record into a CFTC regulatory record. The underlying Commodity Exchange Act provision or regulation must first require the entity to keep the record.

It does not make a blockchain entry self-authenticating in litigation, prove that a decoded explorer page is accurate, or establish who controlled an address. Those questions depend on the offered evidence, the governing evidentiary rules, and any supporting testimony.

Staff said it would not object solely because a covered entity did not maintain an offchain duplicate. For a public and permissionless network, staff said the entity should establish systems and controls that enable retention and production during a disruption. An internal archival node, redundant provider, permissioned replica, export process, or another control might serve that purpose. The FAQ does not prescribe one architecture.

Finally, the FAQ does not resolve state discovery rules, contractual record duties, or preservation obligations created by pending or anticipated litigation. Those questions need separate analysis in the governing forum.

Questions for the records witness

A Rule 30(b)(6) notice, records-custodian deposition, or informal technical conference should test the path from the business event to the produced file.

Ask which application created the record and which system is authoritative. Identify the network, node or provider, explorer, indexer, decoding source, and internal database involved. Determine how the entity maps an address to an account and how it records corrections without rewriting chain history.

Then test production. What happens if the primary provider or explorer is unavailable? Can the entity reproduce the exact record and its metadata from another source? Which timestamps come from the blockchain, the provider, and the firm's own systems? Can the witness explain why those times differ?

The technical evidence review service examines those links instead of treating an explorer display as the final record. The same separation appears in ConsensusIntel's published methodology: source data, processing, and conclusions are documented independently.

Frequently Asked Questions

Q: Did the CFTC authorize blockchain recordkeeping?

A: CFTC staff said it would not object to covered entities using blockchain technology to create and maintain records under Regulations 1.31 and 45.2 if they fully satisfy the existing requirements. The FAQ is a staff view, not a new Commission rule or a general safe harbor.

Q: Must a regulated firm keep an offchain copy?

A: The September 24 FAQ says staff would not object solely because a covered entity elected not to keep an offchain version. For a firm using a public and permissionless network, staff said the firm should establish systems and controls that permit retention and production during an outage or other disruption.

Q: Is a block explorer page enough for discovery?

A: Usually not if the dispute concerns account ownership, authorization, valuation, margin treatment, or the firm's internal response. The explorer may show public transaction data. It may omit the internal records that connect the transaction to the business event.

Q: Does an onchain record prove who authorized a transfer?

A: No. It may identify the submitting address or transaction signer at the protocol level. Attribution to a person, customer, employee, or automated process usually requires account records, access logs, key-management evidence, testimony, or other offchain proof.

If a production stops at an explorer screenshot, the missing question is simple: what records did the firm use to understand and act on that transaction? Contact ConsensusIntel to assess the onchain record, the surrounding systems, and the limits of the resulting evidence.

Related Articles

Was this article helpful?

If your matter involves blockchain evidence, ConsensusIntel can help you evaluate your options.

Get in Touch