Cryptoeconomics

News, data and analysis on tokenized assets, market design and digital economic systems.

Concept

Travel rule

Brussels attaches an identity file to a crypto transfer of any size while Washington still lets $2,999 move unnamed, and neither rule reaches the counterparty that never obtained a licence.

Why it matters

A bank wire has carried the names of both parties for decades. A transfer on a public ledger carries an address, an amount and nothing else. This rule closes that gap by obliging the intermediaries at either end to exchange the identity data the ledger does not hold, and it decides which firms can transact with which, and which corridors pay to serve.

It also fixes the perimeter of a supervised transfer. Where the rule binds, a payment between two licensed firms resembles a correspondent banking transaction with a message attached. Where it does not, or where the destination is an address the customer controls himself, the whole obligation falls on the one firm still inside the system.

How it works

Three layers sit on top of one another: a standard with no legal force, national law that varies by an order of magnitude, and private messaging arrangements that carry the data. The interpretive note to the Financial Action Task Force's Recommendation 15 extends the wire-transfer requirement of Recommendation 16 to virtual assets: the originating institution must obtain, hold and transmit originator and beneficiary information, and the receiving institution must obtain and hold it. FATF writes no law of its own, and every threshold is national.

The European Union chose the strictest version available. Regulation (EU) 2023/1113 has applied since 30 December 2024, and the European Banking Authority's Travel Rule Guidelines apply from the same date. Crypto-asset transfers get no de minimis: the regulation keeps a €1,000 threshold for certain conventional funds transfers and sets none for crypto-assets, so the first euro carries the same file as the millionth. That file names both parties, carries the ledger address and account identifier, and adds one further identifier for the originator, such as an official document number or a date and place of birth. Where the destination is a self-hosted address and the transfer exceeds €1,000, the provider must verify that its customer owns or controls it; the guidelines list acceptable methods at paragraphs 81 to 83, including interactive remote verification, a small test transfer and a signature produced with the private key.

The United States runs the same standard at a much higher threshold: the recordkeeping and travel rules at 31 CFR 1010.410 bite at $3,000. FinCEN and the Federal Reserve Board proposed on 27 October 2020 to lower that to $250 for transmittals beginning or ending outside the country, and stated expressly that convertible virtual currency falls within scope. The proposal was never finalised, and $3,000 still governs.

The newest layer reaches issuers rather than intermediaries. A FinCEN and OFAC proposed rule published on 10 April 2026, on which comment closed on 9 June 2026, would apply the recordkeeping and transmittal provisions of 31 CFR 1010.410(a) to (d) to permitted payment stablecoin issuers, amend the definition of a transmittal order, and require issuers to hold the technical capability to block, freeze and reject transactions and to comply with lawful seizure orders.

Economic mechanism

The obligation is priced per counterparty relationship, not per transfer. Establishing a link means identifying the firm at the other end, satisfying yourself it is licensed and can hold personal data lawfully, agreeing a message format and completing due diligence. That is a fixed cost, largely independent of volume, after which the marginal cost of the ten-thousandth message is close to zero.

With a fixed cost per link and possible links growing with the square of the number of firms, this is a network-formation problem: each firm that joins benefits every firm already connected and cannot charge for it. Uncaptured positive externalities produce under-provision, which is why the market resolved into several incompatible messaging networks rather than one, and why interoperability is where the vendors earn their margin.

The sunrise problem is the concrete form of that failure. A firm in a jurisdiction that has implemented the rule must send data to a firm in one that has not, and which may have neither the means nor a lawful basis to receive it. FATF's seventh targeted update of 16 July 2026 reports progress on licensing and travel-rule implementation while identifying significant gaps in operationalising licensing regimes, in identifying the firms conducting virtual asset service activity, and in risk-based supervision. Flow does not stop at that boundary; it routes to whoever will accept it, so part of the cost is paid in displaced rather than suppressed volume. Threshold asymmetry pushes the same way: $2,000 between two American firms carries no obligation, the identical transfer between two European firms carries the full data set, and an EU-licensed provider serving a remittance corridor with a median ticket of a few hundred euro bears a cost its American competitor does not.

The €1,000 self-hosted verification threshold prices the boundary between an intermediated and a non-intermediated transfer. Below it a withdrawal to the customer's own wallet is ordinary; above it the provider must prove control of the destination, at the cost of a test transaction, a signature or an interactive session. That is a levy on self-custody at size, and it keeps balances resident with the provider.

The April 2026 proposal does something larger to issuers. A reserve manager that mints and burns against bank wires becomes a party to a transmittal, with recordkeeping duties and freezing capability to maintain, so transferability comes to depend on the issuer's cooperation rather than the ledger alone. The contingent cost falls on the holder whose balance can be immobilised.

Participants

Exchanges, brokers, custodians and payment firms are the obliged entities. Messaging network operators and compliance vendors sell the connectivity and capture the interoperability rent. FATF sets the standard and grades implementation; enforcement sits with FinCEN and OFAC, with national competent authorities under the European regulation, and with the Financial Conduct Authority. Stablecoin issuers are drawn in for the first time by the American proposal. Holders of self-hosted addresses sit outside the perimeter, and are the reason the verification rule exists.

Examples

The European guidelines descend to data plumbing: paragraph 35 directs providers, where naming conventions differ, to transmit at minimum the first given name and the last surname.

The American threshold is the clearest case of a rule that stalled. The proposal of 27 October 2020 was never finalised, so the operative number is still $3,000, an order of magnitude above the European position on a standard both jurisdictions claim to implement.

Spread is wide even among implementers. On the table maintained by 21 Analytics, the United Kingdom and Switzerland apply no threshold, Singapore applies SGD 1,500, and several jurisdictions have legislated with commencement dates still ahead.

Risks and limitations

Whether the data does anything is the open question: no public evidence base connects travel-rule messages to investigative outcomes at scale, and FATF's own assessment is qualitative. A measurable cost against an unmeasured benefit invites the argument the rule has received.

Data protection is the sharpest dispute, and both sides have a case. Transmitting identity data alongside a ledger address links a persistent public identifier to a named person and replicates that link across every firm in the chain. Industry submissions argue this manufactures concentrations of sensitive data at firms with no reason to hold it; supervisors reply that the alternative is unattributable value transfer at institutional scale. The European rule takes the supervisory side with no threshold to soften it.

The perimeter itself is unsettled. FATF's finding that jurisdictions struggle to identify the firms conducting virtual asset service activity means the denominator is unknown: a completion rate cannot be computed against a population nobody has enumerated. The same update names misuse of stablecoins, peer-to-peer transactions through unhosted wallets and offshore providers outside effective oversight as growing risks, all three of them categories the rule by construction cannot reach.

Key metrics

No series here measures the rule, which is itself a finding: no published, comparable count of transfers accompanied by compliant data exists. What can be tracked is the number of jurisdictions with the rule in force against the number demonstrably supervising it, the share of a firm's outbound volume going to licensed counterparties rather than self-hosted addresses, the number of mutually interoperating messaging networks, and the American threshold, which has stood at $3,000 through two proposed changes.

The EBA Travel Rule Guidelines are the most operationally detailed public statement of what the obligation requires. FATF's seventh targeted update is the only regular assessment of global implementation, and the two Federal Register documents show the American perimeter extended at the issuer end while the retail threshold stays put.

The weekly read on onchain market economics

What issued, what settled, what the supervisors changed, with the numbers behind it and a note on what the numbers do not show. One email, Thursday mornings.

No tracking pixels. Unsubscribe in one click. We do not sell or share the list.