“Your crypto exchange records are less protected than your bank records. The financial-privacy statutes protect customers of enumerated charter types, and a money-transmitter crypto exchange appears on none of those lists; two federal circuits have held there is no Fourth Amendment privacy interest in exchange account records, and the Supreme Court declined to take the question up on June 30, 2025.”
In November 2017, a federal magistrate judge in San Francisco ordered Coinbase to hand the IRS identity and transaction records for every customer with the equivalent of $20,000 in any one transaction type in any year from 2013 through 2015: by Coinbase’s own count, 14,355 account holders and 8.9 million transactions.1 Since then, two federal courts of appeals have held that exchange customers have no Fourth Amendment privacy interest in those records at all, and on June 30, 2025 the Supreme Court declined to revisit the question.2
That legal landscape cuts both ways, and this guide walks both sides of it. If you are litigating a crypto dispute (a fraud recovery, a business divorce, a judgment you are trying to collect), the counterparty’s exchange records are usually the single most valuable discovery target in the case, and they are gettable. If you are the account holder, your exchange records are more exposed than your bank records, because the statutes written to protect bank customers mostly do not name the entities that custody crypto.
What follows: what an exchange production actually contains, the mechanics of serving a subpoena that works, the realistic grounds for resisting one, and where the Fourth Amendment and the financial-privacy statutes actually stand as of late August 2026.
Key Takeaways
- Exchange productions are identity plus ledger. The leading court order compelled names, taxpayer IDs, birth dates, addresses, full transaction logs with counterparty names, and account statements, while refusing KYC files and user correspondence.1
- No Fourth Amendment shield. United States v. Gratkowski (5th Cir. 2020) and Harper v. Werfel (1st Cir. 2024) both hold there is no reasonable expectation of privacy in exchange account records;34 certiorari was denied June 30, 2025.2
- The Stored Communications Act protects a sliver, not the ledger. Its contents bar reaches communications; it expressly permits providers to give non-content records “to any person other than a governmental entity,” which is what a civil subpoena seeks.5
- California’s consumer-notice statute names charter types, not crypto. CCP § 1985.3 protects customers of banks, trust companies, and brokerages; whether any crypto exchange entity fits the list is charter-dependent and unresolved in published California authority we have found.6
- Geography drives federal enforcement. Rule 45 caps compliance at 100 miles from where the exchange sits, so motions against California-headquartered exchanges concentrate in the Northern District of California no matter where the case is pending.7
What Records Does a Crypto Exchange Subpoena Actually Produce?
A crypto exchange production is identity plus ledger: who owns the account, and every transaction that touched it. The most authoritative description comes from the 2017 IRS enforcement order against Coinbase, because it is a court enumerating exactly which categories it would and would not compel. The court ordered production of each covered account holder’s taxpayer ID number, name, birth date, and address; “records of account activity including transaction logs or other records identifying the date, amount, and type of transaction (purchase/sale/exchange), the post transaction balance, and the names of counterparties to the transaction”; and all periodic statements of account.1
What the court refused matters just as much. It denied the government’s requests for know-your-customer due-diligence files, records of third-party account access, and correspondence between Coinbase and its users.1 That line (ledger yes, communications and diligence files no) is the practical boundary both sides should draft around.
{{table:exchange-production-scope}}
| Record category | Ordered produced in the Coinbase enforcement action | Practical value in civil litigation |
|---|---|---|
| Identity (name, taxpayer ID, birth date, address) | Yes | Ties wallet activity to a person; supports alter-ego and asset-tracing theories |
| Transaction logs with counterparty names and balances | Yes | The core evidence: flows, timing, and who was on the other side |
| Periodic account statements | Yes | Clean exhibits; balances at dates that matter |
| KYC due-diligence files | No | Denied as broader than needed in the enforcement posture |
| Third-party access records | No | Denied in the same order |
| User-exchange correspondence | No | Denied; also the category most plausibly protected as “contents” under the SCA5 |
If you are drafting the subpoena, ask for the ledger with counterparty names and wallet addresses expressly, and specify native electronic form: a transaction export and a PDF statement are not the same evidence.
How Do You Subpoena a Crypto Exchange?
Start with which court’s process you hold, because the mechanics differ.
In a California state case, the instrument is a deposition subpoena for business records under Code of Civil Procedure § 2020.410. It must describe the records “by specifically describing each individual item or by reasonably particularizing each category of item,” must specify the form for electronically stored information “if a particular form is desired,” and must set compliance no earlier than 20 days after issuance or 15 days after service, whichever is later.8 The ESI-form clause is not boilerplate: if you do not demand the native transaction export, you may get static PDFs.
The consumer-notice question comes next, and it turns on the entity, not the brand. CCP § 1985.3 requires 10-day advance notice to the consumer before personal records are produced, but only when the records are held by a “witness” on the statute’s list, which names charter types (a “state or national bank,” a “trust company,” a “security brokerage firm,” and others) and does not mention cryptocurrency exchanges or money transmitters.6 Some exchange groups custody assets through trust-chartered subsidiaries, and a trust company is on the list, so the same platform can arguably sit inside or outside the statute depending on which entity holds the records. As of late August 2026 we have found no published California decision holding a crypto exchange to be (or not to be) a § 1985.3 witness. The safe practice for the serving party is to comply with § 1985.3’s notice procedure anyway: if the statute applies and you skipped it, § 1985.3(k) makes that failure “sufficient basis for the witness to refuse to produce the personal records sought by a subpoena duces tecum.”6
If your case is pending outside California and the exchange sits here, the path in is the Interstate and International Depositions and Discovery Act: submit your foreign subpoena to the clerk of the superior court in the county where discovery will occur, together with an application “on a form prescribed by the Judicial Council” and the fee specified in Government Code § 70626, and the clerk “shall promptly issue a subpoena for service” with the same terms, without your making an appearance in California courts.9
In federal court, Rule 45 permits nationwide service but caps the place of compliance at 100 miles from where the recipient “resides, is employed, or regularly transacts business in person,” and it routes enforcement to “the district where compliance is required.”7 For the major California-headquartered exchanges, that concentrates motion practice in the Northern District of California regardless of where the case lives. The pattern is visible on the dockets: in 2023, litigants in a New York federal enforcement action had to open a miscellaneous action in the Northern District of California to move to compel Kraken’s operator, Payward, to comply with their subpoena, seeking transfer to New York only in the alternative.10
If your counterparty moved money through a U.S. custodial exchange, assume the records exist and are reachable; budget for a miscellaneous action in the exchange’s home district if it resists.
Can You Quash a Crypto Exchange Subpoena?
Sometimes, and your leverage depends on three things: whether you are a party, which entity holds your records, and what categories the subpoena seeks.
A party account holder in a California case has clear standing to move to quash under CCP § 1987.1, which lets the court quash or modify a subpoena and make “any other order as may be appropriate to protect the person from unreasonable or oppressive demands, including unreasonable violations of the right of privacy of the person.”11 Overbreadth arguments write themselves against subpoenas that demand every transaction ever, across every asset, with no date limits: the 2017 Coinbase order struck three entire request categories and pared two more as broader than necessary, and that was after the IRS had already narrowed its own demand to a $20,000 threshold across 2013 through 2015.1 A nonparty account holder is in a weaker spot. The self-executing protections (guaranteed notice, and a written objection that halts production without a motion) come from § 1985.3 and apply only if the exchange entity is a listed “witness”; outside the list, a nonparty must learn of the subpoena and get before the court on a motion.6
The Stored Communications Act adds a narrow but real federal layer. Its disclosure bar protects the “contents” of communications against everyone, including civil litigants; but for non-content records (identity, transaction data, logs), the statute expressly permits a provider to divulge them “to any person other than a governmental entity.”5 An exchange production is overwhelmingly non-content, so the SCA is not the shield account holders hope it is. The categories it plausibly does protect (support messages and user-exchange correspondence) are the same ones the Coinbase court refused to compel.1 Whether a crypto exchange even qualifies as a provider under the SCA appears unresolved in the case law we have located; the honest read is that the fight is narrow either way.
In federal court, the recipient’s first deadline is unforgiving: written objections must be served “before the earlier of the time specified for compliance or 14 days after the subpoena is served,” and a timely motion to quash lies where compliance is required for undue burden, privilege, or geographic overreach.7
“The realistic motion is not ‘you cannot have my exchange records.’ It is ‘you cannot have all of them’: date limits, asset limits, and the correspondence carve-out are where these fights are actually won.” ---Brandon Orewyler, Principal, Astraea Counsel APC
If you receive notice that your records were subpoenaed, calendar the objection deadline the same day; the federal objection deadline (the earlier of the compliance date or 14 days after service) and California’s pre-production timing forgive nothing.
Does the Fourth Amendment Protect Your Exchange Records?
No, under current law, and the account holder analysis has to start from that fact. In United States v. Gratkowski, the Fifth Circuit held that a customer “lacked a privacy interest in the records of his Bitcoin transactions on Coinbase,” reasoning that Coinbase “is a financial institution” subject to the Bank Secrecy Act, that its records “are more akin to the bank records in Miller” (the Supreme Court’s classic third-party-doctrine case) “than the CSLI in Carpenter,” and that users who want privacy “have the option to maintain a high level of privacy by transacting without a third-party intermediary.”3 The First Circuit reached the same result in Harper v. Werfel: the account holder “had neither a reasonable expectation of privacy in the Coinbase account information nor a cognizable property interest in Coinbase’s records,” and the court expressly rejected the argument that a summons sweeping in more than 14,000 accounts changes the analysis.4 The Supreme Court denied certiorari in Harper on June 30, 2025, over amicus support that included Coinbase itself.2
The notice picture is just as stark. When the government obtains non-content records, the SCA states that the agency “is not required to provide notice to a subscriber or customer.”12 Where notice obligations do attach (contents obtained by subpoena or court order), they can be delayed in renewable 90-day increments, and a court can separately order the provider not to tell anyone the process exists.13 When a client says “the exchange never told me,” that is often why.
If your threat model is government process rather than civil discovery, assume the records are available on legal process and plan custody and compliance accordingly, because the constitutional argument is foreclosed in the circuits that have decided it.
Do the Financial Privacy Statutes Cover Crypto Exchanges?
Mostly not, and the reason is structural: both the federal and California financial-privacy statutes define “financial institution” by charter category. The federal Right to Financial Privacy Act defines “financial institution” by charter category (banks, savings banks, card issuers, industrial loan companies, trust companies, savings associations, building and loan or homestead associations, credit unions, and consumer finance institutions), and its operative restraint provides that no “Government authority,” a term meaning federal agencies and their agents, may access customer records from a listed institution outside the statute’s enumerated channels.14 The California Right to Financial Privacy Act lists “state and national banks, state and federal savings associations, trust companies, industrial loan companies, and state and federal credit unions” (a list the statute frames as inclusive rather than exhaustive, though the only entities it excludes by name are title insurers, underwritten title companies, and escrow companies), and its operative restraint runs against “officer[s], employee[s], or agent[s] of a state or local agency.”15 A money-transmitter exchange appears on neither list, and neither statute speaks to private civil litigants at all.
Note the irony: the Fifth Circuit called Coinbase “a financial institution” for purposes of applying the third-party doctrine against the customer,3 while the statutes that would protect customers of financial institutions define the term too narrowly to include an exchange.1415 The phrase does opposite work in the two places, and the account holder loses both times. The one genuine opening is the trust-company category: where an exchange group’s trust-chartered entity holds the records, the charter arguably brings that entity inside both statutes’ lists, a question we have not seen decided in published authority.
If your records sit with an exchange’s trust-company entity rather than its money-transmitter entity, say so in your motion; the charter may be the difference between a listed institution and none of the above.
What Should You Do in the Next 30 Days?
For the litigant seeking records: identify every exchange the counterparty touched (bank statements showing ACH transfers to exchanges are the usual map); serve the correct entity, with § 1985.3 notice run as if it applies; particularize by date range, asset, and category; demand native ESI form; and ask for counterparty names and wallet addresses expressly, because they turn a ledger into a tracing exhibit. If the exchange objects, be ready to enforce in its home district.
For the account holder: calendar the objection deadline immediately; determine whether you are a party (standing to quash) or a nonparty (narrower tools); identify which entity holds your records and its charter; and aim the motion at scope (dates, assets, correspondence) rather than at production as such. If the process is governmental, get counsel before responding to anything, and understand that the fight is statutory and scope-based, not constitutional.
Longer term, both sides should treat exchange records as permanent. The ledger does not fade, the exchanges retain it, and where a U.S. custodial exchange holds the records, the law as of late August 2026 makes them reachable by any litigant with a subpoena and the patience to enforce it. Litigation strategy in crypto disputes increasingly reduces to who gets to the records first and who reads them better.
Astraea Counsel litigates crypto disputes on both sides of this problem: tracing assets through exchange records for recovery plaintiffs and judgment creditors, and defending account holders and companies facing overbroad discovery into their transaction history. If a crypto exchange subpoena is in your case (or about to be), talk to our crypto litigation team.
Related Resources
- Recovering Stolen Crypto in California: The Legal Playbook
- Suing Offshore Defendants: Personal Jurisdiction in California Crypto Cases
- Crypto Personal Jurisdiction After Briskin
- Responding to an SEC Wells Notice in a Crypto Investigation
This article provides general information for educational purposes only and does not constitute legal advice. Discovery and financial-privacy law in this area is evolving rapidly. Consult qualified legal counsel for advice on your specific situation.
Footnotes
-
United States v. Coinbase, Inc., No. 17-cv-01431-JSC, 2017 WL 5890052, at *8-9 (N.D. Cal. Nov. 28, 2017) (order granting in part and denying in part petition to enforce IRS summons), available at https://storage.courtlistener.com/recap/gov.uscourts.cand.308850/gov.uscourts.cand.308850.78.0.pdf. ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Harper v. Faulkender, No. 24-922 (U.S. June 30, 2025) (certiorari denied), docket available at https://www.supremecourt.gov/search.aspx?filename=/docket/docketfiles/html/public/24-922.html. ↩ ↩2 ↩3
-
United States v. Gratkowski, 964 F.3d 307, 312-13 (5th Cir. 2020), available at https://www.ca5.uscourts.gov/opinions/pub/19/19-50492-CR0.pdf. ↩ ↩2 ↩3
-
Harper v. Werfel, 118 F.4th 100 (1st Cir. 2024), available at https://www.govinfo.gov/content/pkg/USCOURTS-ca1-23-01565/pdf/USCOURTS-ca1-23-01565-0.pdf. ↩ ↩2
-
18 U.S.C. § 2702(a), (c)(6), available at https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section2702&num=0&edition=prelim. ↩ ↩2 ↩3
-
Cal. Code Civ. Proc. § 1985.3(a)(1), (b)(2), (g), (k), available at https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CCP§ionNum=1985.3. ↩ ↩2 ↩3 ↩4
-
Fed. R. Civ. P. 45(b)(2), (c), (d)(2)(B), (d)(3), available at https://www.law.cornell.edu/rules/frcp/rule_45. ↩ ↩2 ↩3
-
Cal. Code Civ. Proc. § 2020.410(a), (c), available at https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CCP§ionNum=2020.410. ↩
-
Cal. Code Civ. Proc. § 2029.300(a)-(c), available at https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CCP§ionNum=2029.300. ↩
-
In re Subpoena to Payward, Inc. d/b/a Kraken, No. 4:23-mc-80248 (N.D. Cal. filed Sept. 28, 2023), docket available at https://www.courtlistener.com/docket/67839989/in-re-subpoena-to-payward-inc-dba-kraken/. ↩
-
Cal. Code Civ. Proc. § 1987.1(a), (b)(1), available at https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CCP§ionNum=1987.1. ↩
-
18 U.S.C. § 2703(c)(3), available at https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section2703&num=0&edition=prelim. ↩
-
18 U.S.C. § 2705(a)-(b), available at https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section2705&num=0&edition=prelim. ↩
-
12 U.S.C. §§ 3401(1), (3), 3402, available at https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title12-section3401&num=0&edition=prelim and https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title12-section3402&num=0&edition=prelim. ↩ ↩2
-
Cal. Gov. Code §§ 7460, 7465(a), 7470(a), available at https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=7460, https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=7465, and https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=7470. ↩ ↩2
