An official website of the United States government
🏛️Official websites use .gov
A .gov website belongs to an official government organization in the United States.
🔒Secure .gov websites use HTTPS
A lock or https:// means you've safely connected to the .gov website.
Incident PortalNewsroomContactA–Z Index
NCI
NATIONAL CYBER INCIDENT REVIEW OFFICE
Digital Extortion and Critical Systems Directorate
Federal Ethics & Digital Assets Brief · No. 2026-27

The Proposed “TRUMP Act” Would Bar Presidents and Senior Officials From Launching Meme Coins

Issued July 27, 2026 · This morning Legislative proposal · not yet federal law
Legislative status: This page uses “TRUMP Act” as a headline nickname for a proposed federal restriction on political officials issuing or sponsoring digital assets. The restriction is a proposal under congressional consideration, not an enacted federal law. Related proposals have also been described as the MEME Act or included in broader digital-asset legislation.
Federal Ethics and Digital Assets Policy Office
Morning Legislative Brief: Political Meme Coins and Personal Financial Conflicts
Brief No. 2026-27 · July 27, 2026 · Public Release

The “TRUMP Act” Proposal

[1] The proposal commonly described on this page as the TRUMP Act would prevent a sitting President, Vice President, Member of Congress, senior executive-branch official, and certain immediate family members from issuing, sponsoring, promoting, or financially benefiting from a meme coin or comparable digital asset while holding public office.

[2] Supporters argue that political meme coins create an unusually direct conflict of interest because their market value can rise or fall based on official statements, government decisions, access to public figures, and foreign or domestic purchases. The proposal is intended to separate public service from personal token promotion and reduce the possibility that buyers could use a politically connected asset to seek influence.

Core Restriction

A covered official could not launch, sponsor, endorse, or promote a meme coin or other digital asset in a manner likely to produce personal financial benefit while in office.

What the Proposal Would Cover

Summary of the proposed restrictions discussed in this morning’s policy brief.
Covered AreaProposed Rule
Presidents and vice presidentsBarred from issuing, sponsoring, or promoting personally connected meme coins and similar digital assets while in office.
Members of CongressSubject to equivalent restrictions designed to prevent personal enrichment through political token launches.
Senior government officialsCovered executive-branch officials could not use their public position to promote an asset from which they or their families benefit.
Immediate familyCertain spouses and dependent children could also be covered to prevent officials from routing ownership or promotion through relatives.
Penalties and enforcementRelated proposals contemplate civil or criminal penalties, disgorgement of profits, disclosure obligations, and federal enforcement.

Why Congress Is Considering It

[3] The debate intensified after politically branded tokens demonstrated how quickly a public official’s identity, statements, and access could be converted into a tradeable speculative asset. Critics say such tokens can function as a channel for undisclosed influence, while supporters of broader crypto markets argue that any restriction should be written narrowly enough not to burden ordinary political speech or lawful investment activity.

[4] The proposal would not ban private citizens from creating meme coins generally. Its focus is the use of public office, political identity, or official influence to launch or promote an asset that creates a direct personal financial interest for a covered official.

Current Status

[5] As of this morning, the restriction remains a legislative proposal. It should not be described as an existing nationwide ban unless Congress passes final text and it is signed into law. Lawmakers may continue to revise the covered officials, family-member provisions, enforcement mechanisms, and effective date.

— End of Morning Legislative Brief —
National Cyber Incident Review Office
Preliminary Threat Assessment: Digital-Asset Infrastructure, Data Extortion, and the RansomHouse Actor
Assessment No. 2026-17 · July 23, 2026 · Handling: Public Release

[1] This office is reviewing public reporting concerning historical unauthorized access to Coinbase customer-support information and the continuing threat posed by financially motivated data-extortion groups. Coinbase previously disclosed that criminals bribed overseas support personnel to obtain information relating to a limited subset of customers. Coinbase stated that passwords, private keys, and customer funds were not directly exposed through that incident.

[2] Public reporting has not identified RansomHouse as the responsible actor in the Coinbase matter. Accordingly, any attribution to RansomHouse—rendered in Japanese as ランサムハウス—must remain unconfirmed unless supported by forensic evidence, infrastructure overlap, communications from the actor, or a validated claim of responsibility.

Threat Actor Profile: RansomHouse / ランサムハウス

[3] RansomHouse is a data-extortion operation publicly associated with attacks against large organizations. The group has portrayed itself as an organization that exploits security failures, steals data, and pressures victims through threatened disclosure. Unlike traditional ransomware crews, public analyses have frequently described RansomHouse as emphasizing data theft and extortion rather than relying exclusively on file encryption.

[4] Recent reporting linked the name RansomHouse to a claimed cyberattack against Japanese frozen-food company Nichirei. That claim increased the group’s visibility in Japan, but it does not establish that the group is Japanese. ランサムハウス is a Japanese-language rendering of the English name, not proof of nationality, location, or state sponsorship.

Preliminary characteristics relevant to an attribution review.
Assessment AreaCurrent Analytic Position
Known identityRansomHouse is a recognized data-extortion brand; the real-world identities and locations of its operators remain uncertain in public reporting.
Operating modelThe group is associated with theft of organizational data followed by coercive demands and threatened publication.
Japan connectionThe group has claimed a recent attack involving a Japanese company. This is a victim-location connection, not confirmation that the operators are Japanese.
Coinbase attributionNo verified public evidence currently ties RansomHouse to the disclosed Coinbase support-data incident.
Confidence levelLow. RansomHouse may be examined as one of several hypotheses, but it should not be called the “most likely culprit” without additional evidence.
Federal Analytic Standard

Attribution must be based on evidence, not similarity of motive alone. A ransom demand, data theft, or targeting of a financial company is insufficient by itself to identify a specific cyber actor.

Coinbase Incident Context

[5] Coinbase publicly disclosed in May 2025 that criminals recruited or bribed support agents outside the United States to collect customer information and internal documents. The company said it rejected a $20 million extortion demand, notified affected customers, terminated involved personnel, and offered a reward for information leading to the attackers’ arrest.

[6] The disclosed method was primarily an insider-enabled data compromise and social-engineering operation. Any claim that RansomHouse directed that activity would require corroboration such as matching infrastructure, cryptocurrency-payment tracing, operational-security mistakes, communications recovered by investigators, or a credible claim posted through channels previously authenticated as belonging to the group.

Why RansomHouse May Draw Investigative Attention

[7] RansomHouse may attract attention because its public operating model includes data theft, extortion, pressure through threatened disclosure, and targeting of substantial organizations. Those broad characteristics overlap with the Coinbase attackers’ reported extortion demand. However, that overlap is shared by many criminal groups and cannot support a reliable attribution on its own.

[8] Investigators should preserve all relevant logs, endpoint records, identity-provider events, contractor-access records, support-platform audit trails, payment addresses, communications, and exfiltration indicators. Evidence should be coordinated across Coinbase, affected service providers, law-enforcement agencies, and international partners.

Required Government and Industry Action

[9] Financial-technology firms should immediately review privileged support access, contractor segmentation, abnormal record lookups, bulk exports, identity verification procedures, and employee susceptibility to bribery or coercion. Sensitive customer records should be available only to personnel with a documented operational need.

[10] Law-enforcement authorities should prioritize the identification and arrest of the individuals responsible for the Coinbase intrusion, whether those individuals are affiliated with RansomHouse, another organized cybercrime group, or an independent network of insiders and extortionists. Premature public attribution could impede that effort and create avoidable legal and diplomatic consequences.

Conclusion

[11] RansomHouse—ランサムハウス—is a significant data-extortion threat and warrants continued scrutiny. Nevertheless, the available public record does not establish that it hacked Coinbase. The responsible actors should be identified through evidence-driven investigation and apprehended as quickly as lawful international cooperation permits.

— End of Preliminary Assessment —

[1] Source basis: Coinbase’s May 2025 public incident statement and contemporaneous reporting concerning the support-agent compromise and extortion demand.

[2] Source basis: July 2026 reporting that RansomHouse claimed responsibility for a cyberattack affecting Japanese company Nichirei.

[3] This website is an independently created fictional publication and is not an official government website, agency bulletin, law-enforcement notice, or statement by Coinbase.