Crypto & Web3
Identity verification is now a core compliance function for much of the crypto market, especially where platforms exchange crypto for money, hold customer assets or facilitate transfers. It remains contested in a sector built around self-custody, pseudonymous addresses and open networks.
Crypto and Web3 services increasingly sit within the same anti-money-laundering framework as banks, payment firms and brokerages. Identity verification, often called IDV, helps a provider establish who a customer is, assess risk and detect accounts linked to fraud, sanctions evasion or illicit finance. Its role is clearest at centralised exchanges, where a company controls the customer relationship and often custody of assets.
The model is less straightforward for self-hosted wallets, decentralised protocols and public blockchains. A blockchain address is usually pseudonymous: transactions are visible, but an address does not inherently reveal the person or organisation controlling it. This creates a persistent policy and product question: how far should compliance controls extend without turning the use of open blockchain networks into a permissioned activity?
KYC on centralised exchanges
Centralised exchanges and other crypto-asset service providers commonly apply know your customer, or KYC, checks at onboarding. KYC is the process of collecting and verifying customer information, typically a name, date of birth, address and government-issued identity document. Providers may use document authentication, biometric liveness checks and database checks to establish that the applicant and document are genuine.
The depth of due diligence should reflect risk. Retail customers may receive standard checks, while corporate accounts require verification of the legal entity, directors and beneficial owners, meaning people who ultimately own or control the business. Higher-risk cases can trigger enhanced due diligence, including questions about occupation, expected activity, source of wealth and source of funds.
KYC is not a one-time event. Exchanges monitor transactions after onboarding, screen customers and wallet addresses against sanctions and watchlists, and investigate unusual activity. Blockchain analytics can identify exposure to known fraud, ransomware, darknet market or sanctioned addresses, although such tools produce risk signals rather than conclusive proof of wrongdoing. Firms need human review, documented decision-making and ways for customers to challenge errors.
Travel Rule obligations for crypto transfers
The Financial Action Task Force, or FATF, sets global anti-money-laundering standards that national authorities implement through local law. Its so-called Travel Rule requires covered financial institutions and virtual asset service providers to obtain and transmit specified information about the originator and beneficiary of qualifying transfers. In crypto, the requirement is generally directed at transfers between regulated providers, such as one exchange sending assets to another.
Required data commonly includes names and account or wallet identifiers, with further identifying information required in defined circumstances. Providers must also screen transfers, retain records and manage data securely. The rule does not place personal information on a public blockchain. Instead, firms generally use separate, encrypted messaging systems to exchange the data linked to a transfer.
Implementation remains uneven across jurisdictions, creating operational friction. A provider must determine whether the receiving wallet belongs to another regulated provider or to a customer using self-custody, and whether the provider is able to receive Travel Rule data. Interoperability between vendor networks, data quality, privacy rules and different local thresholds continue to complicate compliance.
Self-hosted wallets and source-of-funds checks
A self-hosted, or unhosted, wallet is controlled by the user rather than an exchange or custodian. It may be a hardware wallet, software wallet or another arrangement in which the user holds the private keys. Sending funds to such a wallet does not by itself mean the transaction is suspicious, and self-custody is a legitimate feature of public blockchain systems.
Nevertheless, regulated firms may seek to verify control of a destination or source wallet when risk warrants it. Wallet ownership verification can involve signing a message with a private key, making a small test transaction, or completing a cryptographic challenge. These methods demonstrate control at a point in time, but they do not always identify the beneficial owner and can be difficult for shared, smart-contract or institutional wallet arrangements.
Source-of-funds verification asks where the assets used in a particular transaction came from, such as salary, savings, a business sale or another exchange. It is distinct from source of wealth, which concerns how a customer accumulated wealth more broadly. Evidence may include bank records, transaction histories, tax documents or sale agreements. The appropriate request depends on the customer, transaction size, risk indicators and applicable law.
- Proof of wallet control is not the same as identity verification or beneficial ownership verification.
- A blockchain transaction history can support an investigation, but it often cannot establish the lawful origin of assets on its own.
- Firms need proportionate controls that avoid treating every self-custody transfer as inherently high risk.
- Collecting wallet and financial evidence creates security, retention and data-protection responsibilities.
Decentralisation, pseudonymity and privacy
The push for stronger identity controls conflicts with important Web3 design principles. Permissionless networks allow users to create addresses without registering with a central operator. Decentralised finance, or DeFi, protocols may use smart contracts to provide trading, lending or other services without a conventional account relationship. Advocates argue that broad identity collection can expose users to surveillance, data breaches and exclusion.
Regulators generally focus less on the software itself than on whether identifiable persons or entities provide, control or profit from regulated services. The practical boundary is contested. A protocol can be technically decentralised while its interfaces, governance arrangements, development teams or service providers retain meaningful influence. Compliance approaches must distinguish between a public protocol and an intermediary that operates a business around it.
MiCA and the European regulatory framework
The EU Markets in Crypto-Assets Regulation, known as MiCA, establishes a common framework for crypto-asset issuers and crypto-asset service providers, or CASPs. Its stablecoin provisions began applying in 2024, followed by the broader CASP regime later that year, subject to national transitional arrangements. MiCA covers authorisation, governance, consumer disclosures, safeguarding and conduct requirements, among other areas.
MiCA works alongside the EU anti-money-laundering framework and the revised Transfer of Funds Regulation, which applies Travel Rule requirements to crypto-asset transfers. CASPs operating in the EU must therefore address both prudential and conduct obligations under MiCA and financial-crime controls. The rules have increased pressure for consistent onboarding, transaction monitoring, wallet-risk assessment and cross-border data governance.
Trends and open questions
The market is moving toward reusable identity, better fraud detection and more selective use of verification. Providers are combining document and biometric checks with device intelligence, behavioural signals and blockchain analytics. Privacy-preserving tools, including verifiable credentials and zero-knowledge proofs, may eventually let users prove a claim, such as age, residency or prior verification, without repeatedly sharing the underlying document. Adoption depends on standards, legal acceptance and usable recovery processes.
Open questions remain. Authorities must clarify how obligations apply to DeFi interfaces, smart-contract developers, validators and self-hosted wallet transfers. Businesses must reduce fraud and money laundering without denying legitimate users access because of imperfect blockchain risk scores. For US and EU firms, the durable challenge is not simply collecting more identity data. It is applying evidence-based, proportionate controls that are transparent to users and robust across an increasingly global crypto market.