SEC’s Hester Peirce wants to end crypto’s KYC honeypots before stablecoin rules create more of them
US Securities and Exchange Commission (SEC) Commissioner Hester Peirce wants monetary companies to cease stockpiling buyer knowledge after breaches uncovered the price of obligatory identification assortment.
This week, the SEC Commissioner called for wider use of reusable digital credentials that would set up information about clients with out requiring each monetary establishment to accumulate the underlying private info once more.
According to her:
“Today society is at a crossroads. Down one path lies the established order: more knowledge assortment, more middleman surveillance, more “know your buyer’ necessities that flip our monetary rails right into a panopticon. Down the opposite path lies a possibility to use new applied sciences to enhance our skill to catch criminals whereas gathering much less private info than ever before, and monitoring more sparingly to shield Americans’ privateness.”
Her remarks observe current safety incidents at main monetary platforms like Revolut that uncovered identification paperwork, addresses, and different info these corporations accumulate to meet customer-verification and anti-money-laundering necessities.
Peirce stated regulators ought to rethink whether or not establishments want specific items of info or merely want affirmation of the information these data set up. Attribute-based credentials, she stated, may show whether or not somebody meets an age requirement, holds a selected citizenship or seems on sanctions lists with out revealing info similar to their identify, revenue or tackle.
“Does more than one agency want to accumulate it?” Peirce requested, arguing that expertise already exists to scale back the knowledge clients give up and the quantity of establishments that obtain it. She stated the remarks represented her personal views fairly than these of the SEC.
The query is turning into more consequential as Washington builds a new compliance regime for stablecoins.
The GENIUS Act requires permitted cost stablecoin issuers to keep customer-identification packages, and regulators are proposing rules that will proceed requiring coated issuers to receive and retain figuring out info from clients.
Breaches flip KYC data into targets
Coinbase offered one of the clearest examples of the danger final 12 months.
Attackers bribed contractors or staff working in abroad customer-support roles to receive info from the trade’s inner techniques. Coinbase later disclosed that 69,461 customers were affected.
The compromised info included names, addresses, cellphone numbers, e-mail addresses, partial Social Security numbers, government-issued identification pictures, account balances and transaction histories. Passwords and personal keys weren’t stolen, however Coinbase warned that the knowledge might be utilized in social-engineering attacks towards clients.
Chief Executive Officer Brian Armstrong then turned the breach into an argument towards how a lot info monetary corporations are required to retain.
“We don’t need to accumulate it, and our clients hate it,” Armstrong stated whereas calling for lawmakers to rethink the Bank Secrecy Act and anti-money-laundering necessities.
He additionally argued that Congress ought to evaluation the legal guidelines or they need to face a constitutional problem, a place that goes significantly additional than Peirce’s proposal to change how required info is collected and verified.
The downside resurfaced this month at Revolut by a unique route.
The fintech firm stated an unauthorized celebration used a official government-agency e-mail area to ship fraudulent info requests.
Revolut disclosed customer information in response, together with identification and phone particulars and copies of passports and driver’s licenses. Depending on the shopper, the fabric may additionally embrace verification selfies, account statements, and transaction histories. Revolut stated its techniques and buyer funds have been unaffected.
The episodes illustrate the vulnerability Peirce is concentrating on: as soon as establishments accumulate identification data, stealing cash doesn’t require breaching non-public keys or immediately compromising monetary accounts. Personal info can itself develop into an asset for extortion, impersonation, and subsequent assaults.
Stablecoin rules protect the gathering mannequin
The coverage problem is that US regulators are concurrently extending customer-identification necessities to one other half of the monetary system.
Under the proposed GENIUS Act implementation, a permitted cost stablecoin issuer would typically have to receive a buyer’s identify, date of beginning or formation, tackle, and identification quantity before opening a coated account.
The figuring out info would then be retained for 5 years after the account closes, whereas data describing verification strategies and outcomes would typically stay for 5 years after they’re created.
The requirement doesn’t cowl each one that receives or holds a stablecoin. It targets clients establishing coated relationships with issuers, together with relationships involving direct issuance or redemption.
Regulators say the necessities implement Congress’s route that permitted stablecoin issuers be handled as monetary establishments below the Bank Secrecy Act and keep efficient customer-identification packages designed to fight cash laundering, terrorist financing and different illicit exercise.
The proposal already leaves some room for expertise. An issuer might use digital credentials as half of identification verification and, below specified circumstances, depend on procedures carried out by one other regulated monetary establishment.

FinCEN additionally said this month that banks and credit score unions might use qualifying government-issued digital credentials, together with cell driver’s licenses, inside their current customer-identification packages.
Those mechanisms cease quick of the transportable mannequin Peirce described. Verification expertise can change how an establishment confirms an identification with out essentially eliminating its obligation to receive prescribed buyer info or keep data.
The combat strikes to the ultimate rule
Regulators have left that query open.
FinCEN and the banking companies explicitly requested whether or not the ultimate stablecoin rule ought to tackle digital identification techniques or verifiable credentials and what advantages and dangers would accompany their use.
They acknowledged {that a} nongovernmental credential may enable somebody to show who they’re with out revealing extra info, however declined to embrace particular verifiable-credential provisions within the proposed regulatory textual content.
That creates room for the ultimate rules to decide how a lot duplicate assortment survives.
Regulators may broaden the circumstances wherein stablecoin issuers depend on identification checks carried out elsewhere, give clearer recognition to cryptographically verifiable credentials, or enable companies to retain proof that required checks occurred with out retaining extra copies of the underlying paperwork the place the legislation permits.
For stablecoin companies, the result will decide whether or not compliance requires constructing one other technology of databases containing buyer identification info or investing in techniques designed to confirm required attributes whereas holding much less of the uncooked knowledge themselves.
The GENIUS Act has already settled that regulated issuers should know their clients. The remaining rulemaking will decide what number of corporations want to maintain copies of the knowledge used to show who these clients are.
The publish SEC’s Hester Peirce wants to end crypto’s KYC honeypots before stablecoin rules create more of them appeared first on CryptoSlate.
