Monetary Sovereignty & Digital Money · Geopolitics · Privacy Technology
From Account KYC to Wallet KYC: When Identity Becomes Financial Infrastructure
The Travel Rule was designed to make intermediaries identify senders and recipients. Its implementation is increasingly doing something more consequential: linking verified people to self-hosted addresses, transaction histories and risk scores at the gateways to digital money.
By Dr. Max Anon · September 20th, 2026
Executive Summary
Know-your-customer rules once appeared to stop at the account boundary. An exchange identified the customer, monitored the account and reported suspicious activity. The wallet beyond the exchange was treated primarily as a technical destination.
That boundary is moving.
In September 2026, Thailand’s Securities and Exchange Commission issued a Travel Rule requiring digital-asset operators to collect information about customers and counterparties, conduct counterparty due diligence and verify ownership of, or control over, self-hosted wallets. The rule takes effect on 27 February 2027. A separate Thai stablecoin proposal goes further: transfers through licensed operators would generally have to move between wallets verified as belonging to the customer, while operators would use customer profiling, wallet screening and blockchain analytics to assess the transaction.[1][2]
Thailand is not creating one universal model for every wallet. It is, however, making visible a wider institutional shift. The European Union already requires information to accompany crypto-asset transfers involving regulated service providers and, above €1,000, requires measures to assess whether a self-hosted address is owned or controlled by the customer. Switzerland has required technically proven control of external wallets in defined circumstances since 2019. Exchanges now translate these rules into address books, ownership attestations, digital signatures, small test transfers and reusable wallet whitelists.[5][7][8][9]
This article calls that development wallet KYC: the institutional process of linking a verified person to a blockchain address, evaluating the address and its transaction history, and using that relationship to decide whether a transfer may proceed. The term is descriptive, not a single legal category.
The change does not place a passport inside a seed phrase. It builds an off-chain identity map around the gateways to digital money. On a transparent ledger, that map can connect civil identity to a persistent transaction graph. Self-custody therefore remains real but incomplete: the user may control the key while an institution controls access to regulated liquidity, stablecoins or fiat conversion.
The central question is not whether fraud prevention and anti-money-laundering controls are legitimate. Many are. The question is architectural: must compliance produce a reusable financial dossier, or can a person prove only what a particular transaction requires?
Key Takeaways
- Wallet KYC is not one universal law. It describes the emerging practice of joining verified identity, wallet control, counterparty information and transaction risk at regulated gateways.
- Identity is generally not written into the wallet protocol. The consequential mapping is usually held off-chain by exchanges, compliance providers and other regulated institutions.
- Control, ownership and beneficial ownership are different. A signature or test transfer can demonstrate present key control; it does not necessarily establish the complete legal or economic relationship to the assets.
- The Travel Rule is becoming operational. FATF reported that 91 of 109 responding jurisdictions had passed implementing legislation in 2026, although enforcement and supervision remained uneven.[3]
- Corporate policy can be stricter than legislation. A regulated platform may restrict transfers to first-party wallets or approved providers as part of its own risk appetite.
- Self-custody controls the key, not the perimeter. A protocol-valid transaction can still be delayed, rejected or excluded by an exchange, issuer or fiat gateway.
- Compliance does not inherently require universal observability. Selective disclosure and zero-knowledge proofs offer a different design path from permanent identity-to-address linkage.
Conceptual continuity: This analysis extends the frameworks developed in The Permission Layer, From Database to Doorstep, The Capital Control Problem and The End of the Ring. Those articles examined institutional permission, KYC data exposure, monetary gateways and private digital money. This article examines the infrastructure now connecting them: the verified relationship between a person, a wallet and a transaction graph.
I. The Wallet That Had to Prove Itself
The user has already supplied a passport.
The exchange has recorded a legal name, date of birth, address and source-of-funds information. It has screened the customer against sanctions lists, assigned a risk profile and monitored the account.
Then the user attempts to withdraw cryptocurrency.
A second identity process begins.
Is the destination another exchange or a private wallet? Which provider controls it? Does the wallet belong to the customer? Can the customer sign a message or return a small test transaction? If another person is the beneficiary, who are they? If the address has interacted with a mixer, scam cluster, sanctioned service or merely an address labelled as high-risk by an analytics provider, should the withdrawal proceed?
The customer has not opened another account. Yet the destination begins to acquire account-like attributes.
Thailand made this transition unusually explicit on 2 September 2026. Its SEC announced that digital-asset operators would have to verify ownership of, or control over, self-hosted wallets when sending assets to them or receiving assets from them. Operators must also collect customer and counterparty information, assess counterparties, transmit originator and beneficiary information to the receiving provider and retain accompanying transaction information for at least five years. These requirements take effect on 27 February 2027.[1]
The following day, the SEC announced a separate set of proposed principles for stablecoin transfers. Those principles would generally prevent customers from moving stablecoins through licensed operators to or from another person’s account or wallet. They also contemplate customer profiling, screening for mule or high-risk wallets, blockchain analytics, comparison with the customer’s income and financial position, and inbound and outbound limits of five million baht per day per person per operator, with specified exceptions for transfers between supervised operators.[2]
The distinction is essential. The Travel Rule has been issued but is not yet effective. The stablecoin restrictions are proposed principles subject to consultation, not enacted rules.
But viewed together, they expose the direction of institutional design:
Known customer → known wallet → screened transaction graph → permission decision.
KYC is moving from the identity of the account holder toward the identity and history of the transfer endpoint.
Featured in the Ryo Directory
Businesses accepting RYO
II. What “Wallet KYC” Means
“Wallet KYC” is not the formal name of a single statute or FATF recommendation. It is a useful description of several practices that are increasingly being assembled into one compliance workflow.
Figure 1 shows how the object of compliance expands. Account KYC identifies the institutional customer; wallet KYC extends the inquiry to the external address, its asserted controller, the counterparty and the surrounding transaction history.
The expansion shown in Figure 1 makes one distinction especially important: control, ownership and beneficial ownership are not interchangeable.
A digital signature can demonstrate that someone controls the private key corresponding to an address. A small test transfer can provide similar operational evidence. Neither method proves every legal fact. A company employee may control a treasury key without owning the company’s assets. A custodian may hold keys for a client. A borrower may temporarily control funds belonging economically to somebody else. A multisignature arrangement may distribute authority across several parties.
Control is cryptographic. Ownership is legal. Risk is probabilistic. The emerging compliance stack often asks one workflow to stand in for all three.
Wallet KYC also does not usually mean that a government name is inserted into a blockchain transaction. Identification information can travel through separate communication systems and remain in institutional databases. FINMA stated this explicitly in 2019: the required information does not have to be transmitted on-chain.[7] The European regulation likewise requires secure submission in advance of, or together with, the transfer rather than publication to the ledger.[5]
The address can therefore remain pseudonymous to the public while being identified to an exchange, regulator or analytics provider. That separation reduces direct public disclosure, but it does not eliminate the identity map. It changes who holds it.
III. The Travel Rule Moves Compliance to the Transfer
The institutional logic comes from the Travel Rule. Originally developed for conventional wire transfers, it requires specified information about the originator and beneficiary to accompany a transfer between regulated institutions.
FATF extended its standards to virtual assets and virtual-asset service providers. Its July 2026 update described the Travel Rule as requiring VASPs and financial institutions to obtain, hold and transmit specified originator and beneficiary information immediately and securely when making payments or value transfers.[3]
The rule is increasingly widespread, but its implementation is not uniform. FATF reported that 83 per cent of the jurisdictions responding to the relevant 2026 survey question—91 of 109—had passed Travel Rule legislation, up from 73 per cent in 2025. Yet 55 of those 91 jurisdictions had not issued findings or directives or taken enforcement or other supervisory action focused on Travel Rule compliance. The underlying survey was self-reported and responses were not independently verified.[3]
This is not a world in which every wallet operates under one settled rule. It is a world in which a common regulatory template is being translated into different national laws, supervisory expectations and product interfaces.
The self-hosted wallet creates the difficult edge case. Between two regulated providers, identity data can travel institution to institution. When one side is a self-hosted address, there may be no second institution from which to obtain the information. The regulated provider therefore turns to its own customer: declare the destination, identify the beneficiary, prove control where required and submit the address to risk analysis.
FATF’s 2026 work on stablecoins and self-hosted wallets describes measures including enhanced due diligence, transfer limits, wallet screening, blockchain analytics, allowlists, denylists and issuer capabilities to freeze or burn assets in appropriate circumstances.[4] These are standards, recommendations and jurisdictional examples rather than one directly applicable global law. They nevertheless reveal where the regulatory perimeter is concentrating.
The historical question was: Who opened this account?
The operational question is becoming: Who controls this endpoint, who benefits from the transfer, and what has the endpoint touched?
IV. Thailand: A Test Case in Endpoint Regulation
Thailand matters because it places multiple elements of wallet KYC in the same policy sequence.
The issued Travel Rule
The SEC’s issued regulation requires digital-asset operators to create risk-management policies for transfers, collect information about customers and counterparties, conduct counterparty due diligence, verify relevant counterparties and intermediaries, and verify ownership of or control over self-hosted wallets. Originator and beneficiary information must accompany transfer orders between operators, and the records must remain retrievable for at least five years.[1]
That is already a significant extension beyond account onboarding. The compliance record can now join a verified customer to an address outside the institution.
The proposed stablecoin controls
The stablecoin principles would take the next step. Through a licensed Thai operator, the originating and destination accounts or wallets would have to be verified as belonging to the customer making the transfer. Transfers into the customer’s account from another person, or out to another person, would be prohibited under the proposal. The address would be screened not only for ownership but for associations with mule accounts, illegal activity, high-risk clusters and watchlists. Transfer values would be assessed against the customer’s income and financial position.[2]
Again, these principles are not final rules. Their importance lies in the proposed architecture.
A stablecoin may circulate on a public blockchain as a transferable token. Yet access through the regulated operator would be organised around a verified identity-to-wallet relationship. The token remains technically transferable; the supervised gateway decides which transfers it will recognise, facilitate or accept.
This creates two overlapping systems.
- The protocol system asks whether the transaction is cryptographically valid.
- The institutional system asks whether the customer, counterparty, wallet history and transfer purpose satisfy its rules.
A transaction can pass the first test and fail the second.
Thailand should therefore not be presented as proof that self-custody has been abolished. It shows something subtler: self-custody can continue while its connections to supervised finance become identity-specific and conditional.
V. Europe and Switzerland: Regulation Becomes Interface Design
The European Union’s Transfer of Funds Regulation has applied since 30 December 2024. It covers crypto-asset transfers where a crypto-asset service provider or intermediary provider on either side is established in the Union. It does not apply to a person-to-person transfer conducted without any service provider.[5]
Where a provider is involved, information concerning the originator and beneficiary must accompany the transfer. For a transfer above €1,000 to or from a self-hosted address, the provider must take adequate measures to assess whether the address is owned or controlled by its customer. That threshold concerns the additional ownership-or-control assessment; it is not a general exemption from the information requirements below €1,000. Records are generally retained for five years, and providers must have risk-based procedures for missing or incomplete information.[5][6]
Switzerland supplied an earlier and stricter example. FINMA stated in 2019 that, where the necessary information could not be transmitted between supervised institutions, transfers involving external wallets were permitted only where those wallets belonged to the institution’s customer and ownership was proven by suitable technical means. Transfers involving a third party’s external wallet required the institution to verify that third party’s identity, establish the beneficial owner and prove ownership of the wallet.[7]
These regimes point in the same direction without imposing identical duties. Figure 2 separates global standards, requirements already in force, rules issued for future effect and proposals that remain under consultation.
The comparison matters because institutional interfaces may be stricter than the legal minimum. These legal and supervisory requirements become tangible through exchange software.
Kraken tells EU and UK customers that crypto deposits or withdrawals above €1,000 may trigger private-wallet ownership verification. Its published process offers self-attestation or a small “Satoshi Test”; after verification, the address can be whitelisted to avoid future holds. Kraken also states that it allows only first-party transactions under this policy.[8]
Coinbase Exchange customers of Coinbase Europe and Coinbase Germany must place destination addresses in an address book, select whether each belongs to an exchange or a self-hosted wallet and supply the requested counterparty information. For a self-hosted destination, the customer must attest control and verify it through a digital signature or small-deposit test. Coinbase says a transfer may not be possible if the information cannot be provided or the destination provider is unsupported.[9]
The distinction between law and company policy matters. A regulation may require risk-based verification in specified circumstances. A platform may choose a first-party-only rule because it is simpler to operate, easier to audit or compatible with its risk appetite. The customer experiences both as a restriction, but the source of authority is different.
The statute establishes the obligation. The interface turns it into an identity map.
VI. When an Address Becomes Personal Data
A public blockchain address is not necessarily anonymous. It is more accurately described as pseudonymous: a persistent identifier whose real-world owner may be unknown until additional information supplies the link.
The European Data Protection Board’s July 2026 blockchain guidelines state that public keys can qualify as personal data where they can be used to identify a natural person by means reasonably likely to be used—including following a data breach. The EDPB adds that on-chain metadata such as transaction identifiers, wallet addresses, event logs and related traces may constitute personal data where they enable direct or indirect identification.[10]
Wallet KYC supplies precisely that missing link.
An institution can hold:
- verified civil identity;
- an account and device history;
- evidence that the customer controlled a particular address;
- originator, beneficiary and transfer-purpose information;
- the address’s public transaction history; and
- analytics labels, clusters and risk scores derived from that history.
Taken together, those records create the identity-to-access pipeline shown in Figure 3.
The address itself has not changed. What has changed is the informational environment around it—and the number of decisions that can be based on the joined record.
Once the join is made, earlier transactions may become retrospectively attributable and later transactions may extend the dossier. The result can reveal counterparties, balances, timing, business relationships, donations, purchases and movement between services. Not every inference will be correct. Shared custodial addresses, temporary control, change-address heuristics, address poisoning, dusting and clustering errors can all complicate attribution.
This is why the distinction between evidence and classification must remain visible. A signed message can be strong evidence of control at a moment in time. An analytics label may be a probabilistic inference derived from several hops of activity. A sanctions match, a fraud report and an exposure score are not equivalent findings.
Yet all may feed the same operational outcome: the transfer is delayed or refused.
A pseudonymous ledger becomes a personal financial record when identity and address can be reliably joined.
VII. Identity Becomes Reusable Infrastructure
The development is larger than cryptocurrency regulation. Digital identity itself is becoming reusable infrastructure.
The European Digital Identity framework requires Member States to provide digital identity wallets and the European Commission says they are to be available by the end of 2026. The framework anticipates use across public and private services, including banking and financial services. It also describes the use of verified attributes for customer identification, customer due diligence and strong authentication.[11][12]
That does not make the European identity wallet a crypto wallet. Nor does it make digital identity inherently hostile to privacy. The regulation requires user control, data minimisation and selective disclosure. It expressly discusses zero-knowledge proofs that can validate a statement without revealing the underlying data.[11]
A commercial example makes the broader convergence visible. World now separates its identity and financial functions into World ID App and World Money. The company describes one as the place to manage identity and credentials and the other as the wallet for crypto and finance, while stating that the two applications share the same underlying identity and that credentials carry over.[13] World ID describes its protocol as a privacy-preserving means of proving that a user is real and unique without disclosing underlying personal information.[14]
The architecture, not the label, determines the privacy outcome.
A credential can prove a narrow fact: over eighteen, resident in an eligible jurisdiction, not already registered, or successfully screened. Alternatively, a persistent identifier can be reused to connect services, wallets and transaction histories.
Both systems may be called digital identity. They produce very different distributions of knowledge and power.
VIII. The Security Paradox
The same identity-to-address map shown in Figure 3 has a second audience. The more valuable it becomes for compliance, the more valuable it becomes to an attacker.
In September 2026, Revolut confirmed that an unauthorised third party used a legitimate government-agency email domain to submit fraudulent information requests. Revolut said its own systems and customer funds were unaffected and that it had contacted the limited number of affected individuals. The Guardian reported that approximately 680 customers were affected and that the incident concerned customers believed to hold cryptocurrency.[15]
Reporting based on claims by a purported attacker said on-chain analysis had been used to select targets. That claim had not been independently established and should not be treated as a confirmed finding.[16]
The architectural lesson does not depend on the unverified claim. A financial institution may protect the private key perfectly and still hold identity, address and activity information capable of turning pseudonymous wealth into a physical-security risk.
The private key can remain secure while the identity map around it becomes an attack surface.
This article does not repeat the wider breach analysis developed in From Database to Doorstep: 153 Million Driver’s Licenses, Crypto Data Leaks and the KYC Paradox. The narrower point is that wallet KYC creates a particularly consequential category of data: not simply who the customer is, but what blockchain wealth and activity may be associated with that person.
IX. The Case for Traceability—and Its Limits
The regulatory case should be stated in its strongest form.
Digital assets can move continuously, across borders and between services. Scam proceeds may be dispersed rapidly. Stablecoins can provide liquid settlement outside normal banking hours. Sanctions evasion, ransomware, cyber theft and organised fraud can exploit speed, pseudonymity and jurisdictional fragmentation. A regulated provider that knows nothing about the destination may be unable to recognise an obvious victim, mule account or sanctioned counterparty.
Originator and beneficiary information can preserve evidence. Wallet screening can identify direct exposure to known theft addresses. Enhanced review can prevent a compromised account from emptying into an attacker’s wallet. Cross-provider information exchange can support asset recovery.
These are legitimate objectives.
But legitimate objectives do not make every possible control accurate, proportionate or necessary.
Proof of key control does not prove the complete source of wealth. An address with indirect exposure to a prohibited service is not automatically controlled by that service. A risk score is not a conviction. A first-party-only transfer policy may prevent an ordinary customer from paying a contractor while doing little to stop a sophisticated criminal from creating another wallet. A restriction applied only at domestic regulated firms may shift activity to offshore providers or direct peer-to-peer channels.
FATF’s own 2026 assessment shows the enforcement gap. Legislation is spreading faster than consistent supervision, while offshore providers, self-hosted wallets, DeFi systems and cross-chain activity remain difficult to govern.[3]
A proportional system should therefore answer six questions:
- What information is necessary for this transaction?
- At what value or risk threshold should additional verification begin?
- Who stores the identity-to-address relationship, and for how long?
- May that relationship be reused for unrelated purposes?
- Can a customer see and challenge an erroneous risk classification?
- Can eligibility be proven without exposing a complete financial history?
A legitimate objective does not dictate a single technical architecture.
X. Self-Custody Survives, but the Perimeter Changes
Self-custody is sometimes discussed as if it solves every question of financial sovereignty. It solves one indispensable question: who possesses the keys required to authorise a transaction?
It does not, by itself, answer whether an exchange will process the withdrawal, whether a stablecoin issuer can freeze an address, whether a bank will accept the fiat proceeds, whether a merchant will accept the asset or whether an analytics provider has labelled the transaction history as high-risk.
The protocol and the perimeter exercise different forms of authority.
- The protocol can recognise a valid signature.
- The exchange can refuse to send or receive.
- The issuer can enforce powers built into a centrally administered token.
- The bank can reject the fiat leg.
- The regulator can impose duties on each supervised institution.
None of these actors needs to confiscate the seed phrase to influence practical access to the wider economy.
The wallet does not become an account. The gateway begins treating it like one.
This is the limit of the familiar phrase “not your keys, not your coins.” Control of keys remains necessary. But a more complete account of monetary sovereignty must also examine observation, liquidity and access.
Self-custody controls the key. It does not control the perimeter.
XI. Three Architectures for Digital Money
Wallet KYC does not lead inevitably to one future. Figure 4 compares three competing architectures according to their treatment of identity, disclosure, ledger visibility and institutional control.
The same compliance objective can therefore produce radically different information systems.
1. Identity-bound money
In the first architecture, approved participation depends on a durable relationship between identity and address. Institutions maintain verified-address books; issuers or smart contracts may use allowlists and denylists; analytics continually updates address risk. The model offers strong attribution and rapid institutional intervention. It also makes mistaken classification, database compromise and upstream exclusion unusually consequential.
2. Privacy-preserving compliance
The second architecture asks whether the required fact can be proven without revealing the whole identity or history. A credential could demonstrate that a user passed screening, resides in an eligible jurisdiction or controls a wallet without making a reusable civil-identity record available to every counterparty. Zero-knowledge systems can reduce disclosure, although they do not eliminate governance, revocation or metadata risks.
The European identity framework’s emphasis on selective disclosure shows that this is not merely a privacy-community demand. Data minimisation can be part of institutional infrastructure.[11]
3. Private bearer digital money
The third architecture attempts to reproduce the privacy and direct possession of bearer cash in digital form. The ledger itself reveals less, and a valid peer-to-peer transfer does not require an account provider’s continuing approval. This reduces the raw material available for retrospective graph analysis, but it does not guarantee exchange access, merchant acceptance or deep liquidity.
These architectures can coexist and overlap. The important question is which one becomes the default.
Should compliance require universal observability, or only proportionate proof?
XII. Where Ryo Fits
Within the framework shown in Figure 4, Ryo belongs primarily to the private-bearer architecture at the protocol layer. That placement requires a careful distinction between privacy at the ledger and access at the perimeter.
Ryo is designed as a private-by-default cryptocurrency. Its current protocol uses Ring Confidential Transactions with a default ring size of 25 to conceal transaction details. Its published development direction points toward Halo 2 zero-knowledge proofs, but that planned architecture should not be described as a capability already deployed on mainnet.[17]
A private ledger does not erase an exchange’s customer records. It does not prevent an operator from demanding proof of wallet control. It does not guarantee fiat access or immunity from lawful process. It does not make operational security unnecessary.
It changes what can be learned from the chain itself.
If a transparent address is joined to a person, the public ledger may expose a wider history and continuing activity. In a private-by-default system, an identity breach or institutional disclosure should reveal less of the surrounding transaction graph. The value of privacy is therefore not only secrecy at the moment of payment. It is resistance to retrospective financial reconstruction.
The transition from RingCT toward the proposed Halo 2 architecture, and the need to combine transaction privacy with network privacy and decentralised access, are examined in The End of the Ring: Privacy Coins and the Architecture of Digital Sovereignty.
Ryo does not abolish the institutional perimeter.
It attempts to ensure that the perimeter does not automatically inherit a complete public map of life beyond it.
XIII. Self-Custody of Money, Self-Sovereignty of Identity
The user in the opening example still holds the private key.
No regulator has entered the seed phrase. No exchange has rewritten the consensus rules. The wallet can still create a valid transaction.
Yet the practical ability to move between private possession and the regulated economy increasingly depends on another asset: an institutionally accepted relationship between identity and wallet.
This is why the movement from account KYC to wallet KYC matters. It changes the unit of compliance. The institution no longer evaluates only a customer relationship. It evaluates an endpoint, a counterparty and a graph of prior activity. Identity becomes infrastructure through which access to digital money can be granted, monitored and withdrawn.
That infrastructure can be designed in several ways. It can accumulate permanent links between people and addresses. It can limit itself to transaction-specific evidence. It can use selective credentials that prove a necessary fact without disclosing the underlying dossier. Or it can coexist with forms of private bearer money that minimise the public information available for fusion in the first place.
The policy choice is not between perfect anonymity and perfect enforcement. Neither exists.
It is between architectures that collect different amounts of information, retain it for different periods, expose it to different actors and give the subject different rights of challenge and exit.
Self-custody of money is therefore only one part of monetary sovereignty.
Self-sovereignty of identity—the ability to prove what is necessary without making every financial relationship permanently linkable—is becoming the other.
The law cannot reach into a seed phrase. It can shape the doorway through which that seed phrase meets the financial system.
Further Reading from ryo.news
From Database to Doorstep: 153 Million Driver’s Licenses, Crypto Data Leaks and the KYC Paradox
How identity databases, transparent ledgers and physical-security risks can converge after a breach.
The Permission Layer: Debanking and the Power to Exclude
Why possession of money and practical access to financial infrastructure are not the same thing.
The Capital Control Problem: Stablecoins, Crypto and the End of the Old Monetary Perimeter
How alternative monetary routes interact with banking, foreign-exchange controls and regulated gateways.
The End of the Ring: Privacy Coins and the Architecture of Digital Sovereignty
Why private digital money must be evaluated across transaction privacy, network privacy, consensus and access.
References
- Thailand Securities and Exchange Commission. SEC issues Travel Rule for Digital Assets to strengthen anti-money laundering and prevent technology-related crimes in line with international standards. 2 September 2026. See also Notification No. Sor Thor. 9/2026, dated 25 August 2026.
- Thailand Securities and Exchange Commission. SEC Board approves principles for enhancing the supervision of stablecoin transactions conducted through digital asset business operators. 3 September 2026. These are proposed principles subject to consultation, not final rules.
- Financial Action Task Force. Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs. 16 July 2026.
- Financial Action Task Force. Targeted Report on Stablecoins and Unhosted Wallets: Peer-to-Peer Transactions. 2026.
- European Union. Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets. Applicable from 30 December 2024.
- European Banking Authority. Guidelines on information requirements in relation to transfers of funds and certain crypto-assets transfers under Regulation (EU) 2023/1113. EBA/GL/2024/11.
- Swiss Financial Market Supervisory Authority. FINMA Guidance 02/2019: Payments on the Blockchain. 26 August 2019.
- Kraken. Updates to Crypto Transfer Procedures for EU and UK Clients. Updated 6 March 2026.
- Coinbase. Coinbase Europe Travel Rule Regulations. Coinbase Exchange help documentation.
- European Data Protection Board. Guidelines 02/2025 on processing of personal data through blockchain technologies, Version 2.0. Adopted 7 July 2026.
- European Union. Regulation (EU) 2024/1183 establishing the European Digital Identity Framework. 11 April 2024.
- European Commission. European Digital Identity Regulation. Updated 22 June 2026.
- World Help Center. What’s the Difference between World ID App and World Money App? Updated 16 September 2026.
- World. World ID Overview. Product documentation.
- The Guardian. Revolut reportedly facing $3m ransom demand after hackers steal hundreds of customers’ data. 17 September 2026.
- Financial Times. Follow-up reporting on the Revolut incident and the perpetrators’ claims about target selection. September 2026. The on-chain-selection claim is attributed to the purported attackers and was not independently established.
- Ryo Currency. Official project website and current protocol overview. Accessed September 2026.
This article is for research and informational purposes only. It does not constitute investment, legal, financial or compliance advice.



