h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

Crypto KYC in 2026: Verify Once, Prove Anywhere

Crypto KYC makes you hand your identity to every exchange, building honeypots that get breached. In 2026, reusable and zero-knowledge credentials aim to verify you once and prove it anywhere.

Anyone who has opened more than one crypto account knows the ritual. Photograph the passport, tilt your face at the camera until a green tick appears, wait for approval, then repeat the whole thing at the next exchange, and the one after that. Each venue keeps its own copy of the same identity file. With Bitcoin trading just above $77,000 and a market capitalization near $1.55 trillion on 13 September 2026 (CoinGecko), the industry has never been larger, and it has never asked its users to hand over more personal data to more places at once.

That design has a cost. The identity dossiers pile up in databases that get breached, the checks do surprisingly little to stop determined criminals, and honest users get turned away by the friction. 2026 is the year the alternative stopped being a slide in a conference deck. Reusable credentials, zero-knowledge proofs, and government-issued digital wallets are shipping, all built on one idea: verify once, then prove what you need anywhere, without surrendering the whole file each time.

This is a guide to how crypto KYC and AML actually work in 2026, why the model almost every exchange uses is breaking, and what the reusable-identity stack arriving now does differently, including where it collides with privacy law and where regulators have quietly left the door open.

What KYC and AML Actually Mean (and Why It Is Not the SEC)

Start with the vocabulary, because the two terms get muddled constantly. Anti-money-laundering, or AML, is the whole apparatus of laws and controls meant to keep dirty money out of the financial system and to help catch the people moving it. Know Your Customer, or KYC, is the identity component inside that apparatus: the checks a regulated firm runs to confirm who its customer is when an account opens, and to keep that picture current over time.

In the United States the legal spine is the Bank Secrecy Act of 1970. The Financial Crimes Enforcement Network (FinCEN), part of the Treasury, writes and enforces the rules; the Office of Foreign Assets Control (OFAC) runs the sanctions lists. Crypto exchanges register with FinCEN as money services businesses. Note who is not on that list: AML sits with FinCEN and OFAC, not the Securities and Exchange Commission, which polices whether a token is a security and not the plumbing of anti-money-laundering. Conflating the two is the single most common mistake in crypto policy debates.

Underneath sit five pillars every program must have: a designated compliance officer, written internal controls, ongoing staff training, independent testing, and risk-based customer due diligence that reaches through to the real people who own an account. Launderers, meanwhile, work in three classic stages, placement, layering, and integration, and crypto is at its most useful to them in the layering stage, where funds are shuffled to break the trail. The table below shows what the rulebook actually requires.

ControlWhat it doesTrigger or thresholdOverseer
Customer Identification (KYC)Verify who the customer isAll customers, at account openingFinCEN
Customer Due DiligenceUnderstand the customer and expected activityOngoing, risk-basedFinCEN
Enhanced Due DiligenceExtra scrutiny for higher-risk customersPEPs, high value, opaque source of fundsFinCEN
Suspicious Activity ReportFlag suspicious transactions to TreasuryAt or above $2,000 at an MSB; file within 30 days; tipping off is a crimeFinCEN
Currency Transaction ReportReport large cash movementsCash above $10,000; file within 15 daysFinCEN
Travel RulePass sender and receiver data with a transferAt or above $3,000 (US)FinCEN
Sanctions screeningBlock sanctioned persons and addressesAny match to an OFAC listOFAC
RecordkeepingRetain identity and transaction recordsFive yearsFinCEN

How a KYC Check Works Today

When you onboard at an exchange, a fairly standard sequence runs behind the progress bar. First, document capture: you photograph a passport or national ID, sometimes with a proof of address. Second, a liveness and biometric step: a selfie plus a short motion check that matches your face to the document and tries to rule out a printed photo or a screen. Third, screening: your name is run against sanctions lists, politically exposed person databases, and adverse-media feeds. Fourth, ongoing monitoring: your transactions are watched, and you are periodically re-screened.

Most exchanges do not build this themselves. They rent it from identity vendors such as Sumsub, Jumio, Onfido, Persona, and IDnow, which specialize in document forensics and liveness detection. The baseline is customer due diligence; when something raises the risk (a high-value account, an opaque source of funds, a politically exposed person), the firm is expected to apply enhanced due diligence, which means more documents and closer monitoring.

The important structural fact is that the exchange, not any regulator, carries the liability if it gets this wrong. That asymmetry pushes firms to over-collect: keep everything, in case an examiner or a prosecutor asks. Every one of those retained files is a small liability that, aggregated across the industry, becomes an enormous one.

Three Things Wrong With the KYC We Have

The first problem is repetition. Because each venue must satisfy its own obligations, each one runs the full check and stores the result, so users repeat the same onboarding again and again, and a meaningful share abandon it partway through. Friction is not a cosmetic complaint; it is lost customers and a standing incentive to cut corners.

The second problem is the honeypot. When your passport scan and home address live in dozens of separate databases, each database is a target. Coinbase learned this in May 2025, when bribed overseas support contractors copied the personal data of roughly 69,461 customers, about 1 percent of its users; the attackers demanded a $20 million ransom, which chief executive Brian Armstrong refused, offering a $20 million bounty for information instead, and the company estimated remediation at $180 million to $400 million (CoinDesk). The stolen field that matters most is the government-ID photo, the exact artifact KYC forces users to surrender.

The third problem is that the regime does surprisingly little for the money spent. Chainalysis reports that illicit addresses received more than $154 billion in 2025, up roughly 162 percent year over year, though that is still under 1 percent of on-chain activity, and that stablecoins, now a market of about $291 billion (CoinGecko), carried roughly 84 percent of the illicit value (Chainalysis). Peter Van Valkenburgh of Coin Center argues in the group’s 2025 report that the existing regime does “remarkably little” to prevent illicit finance while imposing more than $26 billion a year in US compliance costs and heavy privacy burdens (Coin Center).

There is a subtler cost too. Because filing a suspicious activity report is cheap and failing to file one can be catastrophic, compliance teams file defensively, burying investigators in low-value reports. The result is a system that generates enormous volumes of paperwork while, by the industry’s own analytics, catching a thin slice of the illicit flow. Reformers do not argue that screening should stop; they argue that the current design maximizes data collection while minimizing both privacy and, arguably, effectiveness.

And yet the penalties for getting it wrong are enormous, which is exactly why exchanges hoard data. Binance paid $4.3 billion in 2023 (a $3.4 billion FinCEN penalty plus $968 million to OFAC), pleaded guilty to Bank Secrecy Act violations, and had never filed a single suspicious activity report (US Department of Justice). Announcing the case, then Attorney General Merrick Garland said, “Using new technology to break the law does not make you a disruptor. It makes you a criminal.” The reform question the rest of this piece takes up is simple: can a firm satisfy that rulebook without building the honeypot?

The Fix in One Sentence: Verify Once, Prove Anywhere

The alternative has a tidy summary: verify once, prove anywhere. An accredited provider checks your identity a single time and issues a cryptographically signed credential that you hold in your own wallet. Later, when you join a new exchange or app, it does not re-collect your documents; it checks the issuer’s digital signature, in seconds, and accepts the claim. Industry estimates put the onboarding cost saving at 30 to 50 percent versus document scanning, with far less sensitive data sitting at each venue (Start with Identity).

The change is architectural. Today, every verifier holds a copy of your identity. In the reusable model, the holder keeps the credential and the verifier checks a proof, so the same three parties, issuer, holder, and verifier, are wired together differently. Think of the issuer as the passport office, the holder as you carrying the passport, and the verifier as the border guard who reads it without keeping a photocopy. The exchange still learns that you passed KYC; it just stops needing to store the passport to know it.

DimensionSiloed KYC (today)Reusable, decentralized KYC
Where your ID data livesA copy in every exchange’s databaseIn a wallet you control
Who you trust with documentsEvery venue you joinOne accredited issuer
Re-verificationRepeat in full at each venuePresent a credential, checked in seconds
Breach exposureMany honeypots, each a targetMinimal data at the verifier
What the verifier learnsYour full document setOnly the claim it needs
PortabilityNoneAcross apps, chains, and borders
MaturityUniversal, entrenchedShipping in 2026, uneven

The Plumbing: Decentralized IDs and Verifiable Credentials

This works because the standards finally exist. In May 2025 the World Wide Web Consortium published the Verifiable Credentials 2.0 family as a formal Recommendation, a set of seven specifications covering the data model, the cryptographic signature suites, and a status-list mechanism for revoking a credential that is no longer valid (W3C). A verifiable credential is simply a signed, machine-checkable claim, the digital equivalent of a stamped and countersigned document.

The companion piece is the Decentralized Identifier, or DID, a type of identifier its holder controls without any central registry or login provider (W3C). When a credential arrives, the verifier resolves the issuer’s DID to fetch the public key and confirm the signature is genuine. Two features make this privacy-preserving rather than a new tracking layer: selective disclosure, which lets you reveal a single field instead of the whole document, and revocation lists, which let an issuer withdraw a credential without contacting every verifier. It is unglamorous infrastructure, and it is the part that turns a photo of a passport into a claim a machine can trust. The honest caveats in 2026 are that resolver infrastructure is still maturing and consumer wallet software is uneven, so the experience is not yet as smooth as the theory.

Zero-Knowledge KYC: Proving You Pass Without Showing Your Papers

Selective disclosure has a more radical cousin. A zero-knowledge proof lets you demonstrate that a statement is true, that you are over 18, that you are not on a sanctions list, that you completed KYC with a licensed provider, without revealing any of the underlying data that makes it true. For a public blockchain, where anything you post is visible forever, that is the difference between compliance and self-doxxing.

A concrete example makes the idea less abstract. Suppose a tokenized US Treasury product may be sold only to verified, non-sanctioned investors outside the US. In the old model, every buyer uploads a passport to the issuer. With a zero-knowledge credential, the buyer’s wallet proves it holds a valid credential asserting all three facts, the issuer learns only pass or fail, and no document changes hands. The same pattern can gate a compliant lending pool or the mint function of a regulated stablecoin.

A cluster of projects now builds exactly this. Privado ID offers reusable zero-knowledge KYC and ran a 2025 pilot with Deutsche Bank on blockchain-based identity verification; zkMe markets a zero-knowledge KYC product it says is aligned with FATF customer-identification standards; and Human Passport, the protocol formerly known as Gitcoin Passport and now part of Holonym’s human.tech, targets sybil resistance and proof of unique humanity (FinanceFeeds). The pitch to crypto is concrete: you could gate a lending pool or a tokenized-asset product to KYC-passed, non-sanctioned wallets without publishing a single user’s identity on-chain. The catch, which the legal section returns to, is that regulators have not yet formally recognized a zero-knowledge proof as a stand-alone compliance mechanism.

The Crypto-Native Version: Onchain Attestations

There is also a distinctly crypto approach that skips the credential wallet and writes the result to a blockchain. Coinbase Verifications uses the Ethereum Attestation Service to issue onchain attestations tied to a self-custodial wallet you control. The only thing published on-chain is that your address is linked to a verified Coinbase account, plus, optionally, your country of residence; nothing else about you travels, and the attestation cannot be transferred to another address (Coinbase).

The scale is already meaningful. Base Verify has processed more than 200,000 verifications, and a smart-contract-focused version, Base Verify Onchain, is running on the Base Sepolia test network as of mid-2026 (The Crypto Times). Apps use these attestations to filter bots from real users and to gate airdrops, governance, or compliant pools without demanding a fresh document upload. Because the credential lives in a wallet you hold rather than a company vault, the same self-custody discipline that protects your coins now protects your identity too, which is one more reason the hardware wallet you choose matters.

The obvious weakness is trust in the issuer. An attestation is only as good as the party that signed it, and a signed lie is still a lie, which is the same governance problem that dogs the rest of crypto’s verification economy, from security audits to the badges that vouch for smart contracts. Reusable identity does not remove the need to trust someone; it concentrates that trust in fewer, hopefully more accountable, hands.

Governments Join In: eIDAS 2.0 and the EU Wallet

The largest force pushing reusable identity into the mainstream is not a crypto company; it is the European Union. Under the revised eIDAS regulation (Regulation 2024/1183), every member state must offer at least one European Digital Identity Wallet by the end of 2026, and from December 2027 the regulated private sector, including banks and financial services, must accept it (EUR-Lex).

These wallets are designed to hold high-assurance, government-backed credentials, alongside mobile driving licences built to the ISO 18013-5 standard, with selective disclosure as a first-class feature, and the rollout is already underway; Denmark’s AltID wallet went into production in June 2026 (eID Easy). For a licensed European exchange, that points to a future where onboarding means accepting a state-issued credential from a citizen’s wallet, with the user revealing only the fields the rule requires, rather than scanning a passport into yet another database. It also solves the credibility problem for the whole reusable model, because a credential issued by a government carries exactly the reliable and independent pedigree that AML law demands of an identity source.

One wrinkle is worth flagging. MiCA, the EU’s crypto market rulebook, governs licensing and conduct, but anti-money-laundering sits in the separate AML Regulation and the Transfer of Funds Regulation. A government credential from a citizen’s wallet would feed those AML checks; it would not replace a platform’s MiCA authorization, and the two regimes have to be satisfied in parallel.

Proof of Personhood: World’s Iris Bet

The most contested branch of this movement tries to prove something narrower and stranger: not just who you are, but that you are a unique, living human. That distinction matters more every month, as AI agents and deepfakes make it trivial to spin up convincing fake people at scale, a threat that security researchers have warned grows sharper as autonomous agents start acting on their own.

World, the project formerly called Worldcoin, co-founded by Sam Altman and run by Tools for Humanity, has enrolled roughly 18 million people who have deduplicated their iris at a device it calls the Orb (World). The Orb converts an iris into a numerical IrisCode and checks it against a registry using zero-knowledge proofs, confirming that a person has not enrolled before without linking the verification to the underlying biometric. Alex Blania, chief executive of Tools for Humanity, has pitched World ID as a “proof of human” layer for a web increasingly crowded with machines, and in April 2026 the company announced integrations with mainstream platforms including Tinder in the US, Zoom, and Docusign to separate verified humans from bots (Computerworld).

World is not only an identity project; it launched with a cryptocurrency, and that pairing has drawn both users and suspicion, because paying people to enroll their biometrics is exactly what several regulators objected to. Through 2026 the company leaned harder into the enterprise proof-of-human pitch, positioning World ID as a bot filter for mainstream platforms rather than a token play. The repositioning matters for KYC because it is the identity claim, not the coin, that any compliance system would ever rely on.

The Privacy Backlash

A single, global proof of humanity is also, viewed from another angle, the most powerful surveillance instrument ever proposed, and regulators have pushed back on the biometric version hard. World has been ordered to halt operations or delete data in a string of countries: Brazil moved against it in early 2025 after finding it paid people for iris scans in breach of free-consent rules; the Philippines and Thailand ordered it to stop, with Thai authorities demanding deletion of records collected from more than a million people; Colombia ordered a shutdown; and data-protection authorities in Spain and Germany issued deletion orders on GDPR grounds (Rest of World).

The objection is not squeamishness. A password can be reset; an iris cannot, so a biometric honeypot is a permanent one. And reusable credentials, if designed carelessly, could let issuers or verifiers correlate everywhere a person goes, rebuilding the tracking problem the technology was supposed to solve. The counterargument is that zero-knowledge proofs and selective disclosure exist precisely to prevent that, provided the standards hold and the wallets are honest. This fight is not a footnote to the reusable-identity story; it is the story.

Does the Law Even Allow This?

It is fair to ask whether any of this is legal for KYC. In principle, the door is open. FATF’s 2020 Guidance on Digital Identity told regulated firms they may use reliable, independent digital identity systems to perform customer due diligence under Recommendation 10, and that non-face-to-face onboarding built on such systems can be treated as standard, or even lower, risk (FATF). The direction of travel among standard-setters favors good digital ID, not paper.

The specifics, though, lag the technology. Neither the EU’s AML Regulation nor current FATF guidance has formally endorsed zero-knowledge proofs as a stand-alone compliance tool, so providers operate in a grey zone while the European Banking Authority works on technical standards (FinanceFeeds). And one thing does not change no matter how clever the cryptography: the regulated entity keeps the liability. A credential does not dissolve an exchange’s duty to know its customer, to screen sanctions, or to produce records and unmask a user on a lawful order, the break-glass path that every serious design has to preserve.

The cleanest legal path, for now, runs through the government wallets. Because a European Digital Identity credential is issued by a member state to a defined assurance level, an exchange that accepts it stands on the same ground as one that checks a physical passport, which is why banks and other regulated firms are the wallets’ first mandated audience. Zero-knowledge and proof-of-personhood schemes have to earn that standing the harder way, through supervisory practice and, eventually, the European Banking Authority’s technical standards. The table below maps the toolkit and where each piece stands.

ApproachExamplesWhat it provesWhere it stands
Government digital walletEU EUDI Wallet, mobile driving licencesHigh-assurance, state-backed identityMandated across the EU by end of 2026
Verifiable CredentialsW3C VC 2.0, Decentralized IdentifiersSigned, portable claimsStandard finalized May 2025
Onchain attestationsCoinbase Verifications, Base VerifyA wallet is linked to a verified accountLive; smart-contract version in testnet
Zero-knowledge KYCPrivado ID, zkMe, Human PassportKYC status without the documentsGrowing; not yet blessed by AML law
Proof of personhoodWorld IDA unique, living humanAbout 18M enrolled; paused in several countries

The EU and the US Are Splitting

The two big Western blocs are heading in different directions. In Europe, AML is consolidating into a single rulebook. The AML Regulation (Regulation 2024/1624) takes full effect on 10 July 2027 and will ban anonymous crypto accounts and privacy coins, while the Transfer of Funds Regulation already applies the Travel Rule to crypto with no minimum threshold and requires extra checks on transfers above 1,000 euros between custodial and self-hosted wallets (EUR-Lex). A new Frankfurt authority, AMLA, will directly supervise the highest-risk firms from 2028 and has named crypto-assets a priority risk as it builds out (AML Intelligence).

The US is doing the opposite. There is no federal push for a government digital-ID wallet, and AML remains with FinCEN and OFAC rather than the SEC. Washington’s one big recent move was the GENIUS Act, which made permitted stablecoin issuers Bank Secrecy Act institutions and prompted a joint FinCEN and OFAC proposal in April 2026 setting out their anti-money-laundering and sanctions-compliance duties (Federal Register). The practical result is that Europe is laying public rails for reusable identity, while the US leaves the job to the private market, to Coinbase, to World, and to the zero-knowledge startups.

Where This Meets DeFi and Self-Custody

The hardest problems sit where KYC meets code. The Travel Rule and customer due diligence both assume a regulated intermediary in the middle of a transaction, and the point of self-custody and decentralized finance is to remove that intermediary. Europe’s answer, for now, is to demand enhanced checks whenever value crosses between a custodial platform and a self-hosted wallet, and the US answer has teeth of a different kind: in the Tornado Cash case, developer Roman Storm was convicted in August 2025 of conspiring to run an unlicensed money-transmitting business, with a retrial on the two deadlocked counts set for 26 April 2027 (The Block).

Reusable, zero-knowledge credentials are the industry’s proposed truce. Prove you are a KYC-passed, non-sanctioned human, and a permissioned pool can let you in, or a lending market can let you borrow against your coins, without a smart contract ever holding your identity file. Whether that arrangement actually satisfies regulators, or merely looks tidy, is one of the central unresolved questions in the fight over how far compliance reaches into DeFi.

The tension is jurisdictional as much as technical. A permissioned pool that checks credentials still needs someone accountable for the checking, and the more decentralized a protocol is, the less it has any such someone. That is the circle reusable identity has not yet squared: it can make a user prove the right things, but it cannot, on its own, decide who is legally on the hook when the proof turns out to be wrong.

What It Means for You

For an ordinary user, the transition will be uneven before it is universal. A few practical expectations for 2026 and the year after:

  • Expect onboarding to get lighter where reusable credentials are accepted and to stay heavy where they are not; adoption will be patchy across exchanges and borders.
  • Share the minimum. A well-built system asks you to prove a specific claim, not to upload your entire identity, so be wary of any venue that still wants the full file when a proof would do.
  • Guard the wallet. In the new model your credential lives with you, not in a company database, which is safer against breaches but only as strong as your own key hygiene.
  • Watch the issuer, because a credential is worth exactly as much as the trust you place in whoever signed it.
  • Do not expect anonymity. Reusable and zero-knowledge KYC hide your data from most parties, not from a lawful investigation.

The larger point is that the pieces are, for the first time, all on the table at once. The standards are finalized, the government wallets are mandated, and the crypto-native tools are live. Universal, frictionless reuse is still a few years away, held back as much by law and habit as by technology. But 2026 is the year crypto KYC stopped being only a burden to endure and started becoming infrastructure to build, one that could, if the privacy safeguards hold, ask users to give up far less than they do today.

Frequently Asked Questions

What is the difference between KYC and AML?

AML, or anti-money-laundering, is the whole framework of laws and controls meant to keep dirty money out of the financial system. KYC, or Know Your Customer, is the identity piece inside it, the checks a firm runs to confirm who its customer is at onboarding and over time. In the United States the authority is FinCEN and OFAC under the Bank Secrecy Act, not the SEC, which only handles the securities side of crypto.

What is reusable KYC and is it safe?

Reusable KYC means an accredited provider verifies you once and issues a signed credential you keep in your own wallet, so future apps check a proof instead of re-collecting your documents. It reduces how much personal data each venue stores, which lowers the risk from breaches, but it is only as safe as the issuer that signed the credential and the wallet where you keep it.

Can a zero-knowledge proof really satisfy KYC rules?

Technically a zero-knowledge proof can confirm that you passed KYC or are not sanctioned without exposing your documents. Legally it is not settled, because neither FATF guidance nor the EU AML Regulation has formally recognized zero-knowledge proofs as a stand-alone compliance tool, so most deployments still pair them with a licensed issuer and a lawful-access audit trail.

Do I have to scan my iris with World to use crypto?

No. World ID is one approach to proving you are a unique human, and it is optional and contested, with several countries pausing or banning its iris scanning over data-protection law. Government wallets, verifiable credentials, and conventional document-based KYC are all separate paths, and most exchanges still use ordinary checks.

Will reusable identity make crypto anonymous again?

No. These tools minimize the data you expose to any single company, but they are built to preserve an audit trail for lawful investigations. Sanctions screening, suspicious-activity reporting, and recordkeeping duties all remain, so reusable KYC is about privacy from over-collection, not anonymity from the law.

By Anneke de Vries, senior regulation correspondent at HOGE Wire.

Share 𝕏 Post Telegram