Blog

The Crypto Travel Rule Explained: Who It Covers, What to Do

The Crypto Travel Rule explained: how it works, who must comply, where implementation breaks down, and why Travel Rule data can support but not replace blockchain tracing.

Blockchain transaction flow diagram showing funds traced across multiple chains

The crypto Travel Rule sounds simple: information about who sends and receives cryptocurrency should accompany certain transfers between regulated service providers.

In practice, it sits at the intersection of AML compliance, customer identification, blockchain infrastructure, privacy and cross-border regulation. Requirements also vary between jurisdictions, which is why a transfer that proceeds normally on one platform may trigger additional questions on another.

For investigators, the rule has another important consequence. Blockchain transactions show where assets moved, but they usually do not reveal the verified identity behind an exchange account. Travel Rule information can help regulated providers and competent authorities connect on-chain transactions with off-chain customer records.

This article explains what the Travel Rule is, who it applies to, what information is collected, how self-hosted wallets are treated and why the rule matters in blockchain investigations.

What is the crypto travel rule?

The crypto Travel Rule is an anti-money laundering and counter-terrorist financing requirement designed to ensure that identifying information about the sender and recipient accompanies qualifying virtual-asset transfers.

The concept comes from Financial Action Task Force standards. FATF extended its AML/CFT framework to virtual assets and Virtual Asset Service Providers, commonly called VASPs, and requires jurisdictions to implement controls around transfers of virtual assets.

The purpose is similar to transparency rules for traditional financial transfers. A regulated provider should not receive cryptocurrency with no meaningful information about where it came from or for whom it is intended.

Importantly, the personal data does not necessarily travel publicly on the blockchain. The blockchain transaction and the Travel Rule information are separate layers. The transfer remains visible on-chain, while customer information is transmitted or retained through compliant systems operated by the relevant providers.

Implementation is increasingly widespread. FATF reported in July 2026 that 83% of surveyed jurisdictions had passed legislation implementing the Travel Rule, compared with 73% in 2025, although significant practical implementation gaps remain.

Who soes the crypto travel rule apply to?

At FATF level, the key concept is the Virtual Asset Service Provider.

FATF defines a VASP functionally. The definition can include businesses conducting activities such as exchanging virtual assets for fiat currency, exchanging one virtual asset for another, transferring assets on behalf of customers, safeguarding or administering assets, and providing certain financial services connected with an issuer's offer or sale of a virtual asset.

That means centralized crypto exchanges and custodial providers are obvious examples, but the legal analysis is based on what a business actually does, not simply the label it uses.

Terminology differs by jurisdiction. In the European Union, legislation commonly refers to Crypto-Asset Service Providers, or CASPs.

The rule generally becomes relevant where a regulated service provider is involved in the transfer. Pure person-to-person transfers conducted directly between self-hosted wallets without a service provider may be treated differently.

For example, the EU's Regulation (EU) 2023/1113 expressly excludes person-to-person crypto transfers where no crypto-asset service provider is involved. Once a CASP enters the transaction, however, Travel Rule obligations can apply.

Businesses should therefore assess their obligations based on the services they provide and the jurisdictions in which they operate, rather than assuming that being "non-bank" or "crypto-native" places them outside the framework.

Because terminology and implementation differ across jurisdictions, the classification of a business as a VASP, CASP or equivalent should be assessed under the law that applies to its activities.

What information has to travel with a crypto transfer?

At its core, the Travel Rule is about linking a transfer to information about its originator and beneficiary.

The precise fields depend on applicable law.

Under the EU framework, for example, the originating CASP must ensure that a transfer includes specified information about the originator, including the person's name and relevant distributed-ledger address or crypto-asset account information. Additional identifying information can include an address, official document information, customer identification information, or date and place of birth.

Information about the beneficiary includes the beneficiary's name and relevant distributed-ledger address or crypto-asset account information. The regulation requires this information to be submitted securely before, simultaneously with or concurrently with the crypto transfer. It does not have to be embedded directly into the blockchain transaction itself.

This distinction is important from both a privacy and investigative perspective.

A public blockchain may show:

Wallet A -> Wallet B -> Exchange deposit address

Travel Rule records may separately help establish:

Verified customer A -> regulated provider -> verified customer or account B

The second layer is not publicly visible simply by inspecting the blockchain.

How does the travel rule work in practice?

Imagine a customer sends crypto from Exchange A to an account hosted by Exchange B.

Exchange A identifies its customer through its KYC process. Before or alongside the transfer, the relevant required information is transmitted securely to Exchange B through the providers' compliance infrastructure.

Exchange B then checks whether the information it receives is complete and handles the transaction according to its risk procedures.

If information is missing, inconsistent or otherwise problematic, the receiving provider may need to request additional information, hold the transfer for review, reject it or take other risk-based action.

In the EU, the EBA's applicable Travel Rule Guidelines specify how payment providers and crypto-asset service providers should detect missing or incomplete information and manage transfers where required information is absent. Those guidelines have applied since 30 December 2024.

That is why users sometimes encounter requests such as:

  • identifying the destination exchange
  • providing the recipient's name
  • confirming whether a wallet belongs to them
  • supplying additional identification
  • confirming the purpose or origin of a transfer.

These checks may appear separate from blockchain activity, but they form part of the regulated information layer surrounding the transaction.

Where does the travel rule become difficult in practice?

The Travel Rule is conceptually straightforward, but implementation is not. The main difficulties arise because the regulatory requirement has developed faster than a single global operating model for exchanging the required information.

Uneven implementation across jurisdictions. FATF has described this as the "sunrise issue". Jurisdictions introduce Travel Rule obligations at different times and supervise or enforce them with different intensity. A provider in one country may therefore be required to collect and transmit information while the counterparty operates in a jurisdiction where equivalent obligations are not yet in force or are applied differently. The result can be additional checks, uncertainty, delays or rejected transfers.

Interoperability between Travel Rule systems. There is no single mandatory global transport protocol or universally adopted network for Travel Rule data. Service providers use different compliance vendors and messaging solutions. Data standards such as IVMS can help standardize the information being exchanged, but they do not automatically make every network interoperable. When two providers use systems that cannot communicate directly, firms may need multiple integrations, manual workarounds or an alternative channel, adding technical, operational and financial cost.

Data protection and cross-border PII. In the EU, Regulation (EU) 2023/1113 requires providers to comply with GDPR when processing and transmitting Travel Rule data. Providers therefore have to exchange enough personal information to meet AML obligations while also applying purpose limitation, data minimization, security and the rules governing transfers of personal data to third countries. The issue is not that GDPR cancels the Travel Rule; it is that both frameworks have to be satisfied at the same time, which can create significant operational friction in cross-border transfers.

Counterparty discovery and data quality. A provider may know the blockchain destination but still need to determine whether the address belongs to another regulated provider, an intermediary or a self-hosted wallet. Different naming conventions, incomplete beneficiary information, mismatched customer data and uncertainty about the counterparty can push otherwise ordinary transfers into manual review.

These problems explain why Travel Rule compliance is not simply a matter of switching on a compliance tool. It requires legal interpretation, counterparty identification, secure data exchange, exception handling and operational processes that work across jurisdictions and technology stacks.

What about self-hosted wallets?

Self-hosted wallets are one of the most misunderstood areas of the crypto Travel Rule.

A self-hosted wallet is not automatically prohibited, nor does the fact that someone controls their own private keys automatically create a VASP relationship.

The regulatory issue arises when a transfer moves between a self-hosted address and a regulated provider.

The EU provides a useful example. Regulation (EU) 2023/1113 applies Travel Rule requirements to transfers involving self-hosted addresses when a CASP is involved. For transfers above EUR 1,000 between a customer's account and a self-hosted address, the CASP must take adequate measures to assess whether the address is owned or controlled by that customer.

The regulation also makes an important distinction: crypto transfers themselves are generally subject to the required information rules regardless of amount. The EUR 1,000 figure in the self-hosted-wallet provisions relates specifically to additional ownership or control verification, not a general exemption for smaller crypto transfers.

This is a good example of why businesses should avoid relying on simplified summaries such as "the Travel Rule only applies above EUR 1,000."

The applicable rule depends on the jurisdiction and the transaction structure.

Can travel rule information help trace crypto?

Yes, but it should be understood as one part of an investigation.

Blockchain forensics begins with on-chain evidence: transaction hashes, addresses, timestamps, token movements, clustering, bridges, swaps and service attribution.

The crypto Travel Rule adds a potentially important off-chain evidence layer.

Suppose stolen cryptocurrency is traced through multiple wallets before reaching an address attributed to a regulated exchange. Blockchain analysis may establish the path into that service, but it usually cannot reveal the verified customer controlling the recipient account.

That information may exist in the exchange's KYC and Travel Rule records.

Access to it is another matter.

A private investigator cannot simply demand confidential customer information from an exchange. Disclosure generally depends on the provider's procedures, applicable law and, where necessary, requests from law enforcement, courts or other competent authorities.

This is why professional forensic reports focus on evidential continuity. Investigators need to show clearly how the victim transaction connects to the relevant deposit or service address so that the appropriate authority or platform has something actionable to work with.

"A Travel Rule record attaches to a single transfer between two providers. It does not describe a path, and nothing in it points backwards through the hops that came before. Travel Rule data identifies parties, but only where a regulated provider sits at both ends, and it goes quiet the moment assets move to a self-hosted address. In a laundering path that alternates between services and self-custody, coverage is intermittent by design. Continuity has to come from the trace. " Žiga Karič, Bloctopus Intelligence

For victims, the important distinction remains the same: identifying where funds went is not identical to recovering them.

What should crypto businesses do in 2026?

For businesses subject to the Travel Rule, compliance is not simply a question of installing a messaging protocol.

The operational process needs to work across onboarding, KYC, transaction monitoring, wallet screening, record keeping and escalation procedures.

In practice, firms should be able to determine:

  • whether the counterparty is another regulated service provider
  • what originator and beneficiary information must be exchanged
  • whether received information is complete
  • how self-hosted-wallet transfers are handled
  • when additional verification is required
  • how missing information affects a transfer
  • when a transaction requires enhanced review
  • how Travel Rule records can be retrieved for legitimate authority requests
  • how personal data is transmitted securely.
  • which Travel Rule network or messaging solution the counterparty can use
  • how interoperability failures and unavailable counterparties are handled
  • how cross-border transfers of personal data comply with applicable data-protection rules.

This matters increasingly in 2026 because regulatory adoption is no longer the only issue. FATF's latest assessment emphasizes the gap between countries having rules on paper and implementing them effectively in supervision and enforcement.

There is another source of potential confusion. FATF revised Recommendation 16 in 2025, including changes designed to standardize information in certain cross-border payment messages and clarify responsibilities in the payment chain. FATF states that those revised standards are expected to take effect by the end of 2030.

Businesses should therefore distinguish future FATF changes from Travel Rule obligations already in force under existing national or regional law.

Why the travel rule matters beyond compliance

The crypto Travel Rule is usually discussed as an AML obligation, but its evidential value is equally important.

Blockchains create durable transaction records. KYC creates customer attribution. Travel Rule systems help preserve information about the parties associated with transfers between regulated providers.

When those layers can be lawfully combined, investigators and authorities gain a more complete picture than either source provides alone.

That does not make every wallet identifiable or every stolen asset recoverable. Funds can still move through unregulated providers, self-hosted wallets, cross-chain infrastructure and jurisdictions with weaker implementation.

But the regulatory environment is becoming more interconnected. For businesses, that means Travel Rule compliance should be treated as part of a broader AML and transaction-monitoring architecture. For investigators, it creates another potential bridge between on-chain evidence and real-world attribution.

Professional blockchain forensics remains necessary to establish the transaction path. The Travel Rule can make certain points along that path considerably more meaningful.

Need help with a case?

Get in touch and we will help you understand how we can support your investigation.

Contact us