Industry Moves

Crypto and the Travel Rule: KYC Reaches Decentralized Finance

The FATF Travel Rule brings bank-style sender and recipient data obligations to many crypto transfers. Its spread is pushing exchanges toward shared compliance infrastructure while testing the limits of decentralized finance.

Crypto and the Travel Rule: KYC Reaches Decentralized Finance

Crypto was built to move value across networks without the account relationships that define conventional finance. Regulators are increasingly asking parts of the sector to add those relationships back. The Financial Action Task Force, or FATF, has made its so-called Travel Rule a central global standard for virtual asset transfers, and national implementation is reshaping how exchanges process withdrawals and deposits.

The result is not a single worldwide crypto rulebook. Jurisdictions apply FATF standards through their own laws, supervisory expectations and technical guidance. But the direction is clear: regulated platforms are expected to know who their customers are and, in defined circumstances, exchange information about the people behind a transfer.

What the Travel Rule requires

FATF is an intergovernmental standard-setter focused on anti-money laundering and counter-terrorist financing. Its Travel Rule, reflected in Recommendation 16, has long required financial institutions to accompany certain wire transfers with information about the originator and beneficiary. In the virtual-asset context, the standard extends comparable expectations to virtual asset service providers, or VASPs.

A VASP generally includes businesses that exchange, transfer, safeguard or administer virtual assets on behalf of customers. Centralized crypto exchanges and some custodial wallet providers commonly fall within that category. The information expected to travel with a qualifying transfer can include names, account or wallet identifiers, and other identifying details required under local rules. The receiving provider must be able to screen and retain the data, and both sides may need to address missing or suspicious information.

The rule is not a demand to place personal data on a public blockchain. In practice, compliant providers generally transmit it through separate, secure messaging channels. Nor are thresholds and data fields identical everywhere. Local implementation determines when requirements apply and how firms must handle transfers that fall outside a given threshold.

Why blockchain transfers complicate the model

The Travel Rule assumes two regulated institutions can identify one another and exchange standardized data. Crypto transfers often do not fit that pattern. A blockchain address is a pseudonymous identifier, meaning its transaction history may be visible while its controller's real-world identity is not. A transfer can also pass across borders in minutes, involving platforms subject to different rules and data-protection regimes.

The most difficult case is the self-hosted wallet, sometimes called an unhosted wallet. It is controlled directly by an individual or organization rather than by a regulated intermediary. A customer withdrawing from an exchange to such a wallet may be able to provide an address, but there is no receiving VASP to confirm the beneficiary's identity or accept Travel Rule data. The reverse is also true for deposits arriving from self-hosted wallets.

  • Blockchain addresses do not inherently identify their controller.
  • A sending platform may not know whether a destination address belongs to another provider or a self-hosted wallet.
  • Providers must reconcile anti-money-laundering duties with privacy, data-minimization and cross-border data-transfer rules.
  • Transaction monitoring can flag risk patterns, but it cannot by itself prove who controls an address.

How exchanges are adapting

For centralized exchanges, Travel Rule compliance typically begins at onboarding. Know your customer, or KYC, checks collect and verify identity information before a customer can use services. That information gives the platform a basis for sanctions screening, transaction monitoring and, where required, sending originator information to another provider.

On transfers between participating providers, exchanges increasingly use specialist messaging networks or bilateral connections to identify a counterparty VASP and share encrypted data outside the chain. Operationally, this can mean a transfer is delayed while the platform establishes whether the receiving address is associated with a participating institution, requests missing information, or reviews an alert.

Transfers involving self-hosted wallets have produced more varied policies. Depending on the jurisdiction and a firm's risk assessment, an exchange may ask customers to identify the wallet owner, use technical checks intended to show control of an address, impose additional review, or restrict certain transactions. These approaches are imperfect. A signature from an address can demonstrate control at a moment in time, but does not necessarily establish the owner's legal identity or the purpose of a payment.

DeFi exposes the boundary of the rule

Decentralized finance, or DeFi, replaces or reduces the role of an operator with smart contracts, software that executes transactions under programmed conditions. Many DeFi protocols allow users to connect self-hosted wallets and trade, lend or swap assets without opening a conventional account. That design leaves no obvious entity to collect Travel Rule data, identify counterparties or receive compliance messages.

Regulators and market participants are still working through where responsibility sits when a protocol has developers, governance token holders, front-end operators, liquidity providers and other contributors, but no traditional intermediary. The answer can differ materially by activity and jurisdiction. A protocol described as decentralized may still have identifiable parties operating interfaces, controlling upgrades, collecting fees or providing customer-facing services.

Workarounds are emerging, though none resolves every legal and technical question. Some services are experimenting with verified credentials that let a user prove completion of an identity check without repeatedly disclosing all underlying data. Others apply compliance controls at web interfaces, gateways, custodial layers or fiat on- and off-ramps. Permissioned pools and institution-focused DeFi products can limit participation to verified users, at the cost of the open access associated with public networks.

A compliance layer, not a complete solution

Supporters argue that Travel Rule systems make it harder to move illicit funds through regulated crypto businesses and bring virtual-asset transfers closer to established financial-crime controls. Critics point to fragmented implementation, security risks created by sharing sensitive data, and the possibility that users will migrate to services outside regulated channels.

For now, the practical dividing line is often custody and intermediation. Where a business controls assets or facilitates transfers for customers, it is increasingly expected to perform identity and information-sharing functions. Where users transact directly through self-hosted wallets and autonomous software, enforcement is harder and policy remains unsettled. That tension is likely to define the next phase of KYC in crypto as rules, technical standards and DeFi business models continue to evolve.

More in Industry Moves

Passwordless Banking: How Identity Became the New LoginIndustry Moves

Passwordless Banking: How Identity Became the New Login

Banks and fintechs are replacing memorized passwords with authentication tied to a customer, a device and, increasingly, a verified identity record. The change can reduce fraud, but it makes enrollment and account recovery critical security controls.

Elena Marsh ·
iGaming Under Pressure: KYC as a License ConditionIndustry Moves

iGaming Under Pressure: KYC as a License Condition

Online gambling operators are judged not only on games and payments but on whether they can identify customers, keep minors out and intervene when play becomes harmful. Across regulated markets, those controls are increasingly treated as conditions of a licence, not back-office compliance.

Elena Marsh ·