The one-sentence version
When a regulated crypto business sends your coins to another regulated crypto business, it must send identifying information about you along with the transaction, and the receiving business must check it.
That is the entire rule. Everything else is detail about four variables: who counts as regulated, what information travels, above what amount, and what happens when one end is not a business at all.
Where the requirement comes from
This is not a Bitcoin rule. It is a banking rule, written decades before Bitcoin existed to govern wire transfers, and later extended to crypto.
The structure has three layers, and understanding them explains almost every confusion in this area.
An international standard-setting body
The Financial Action Task Force publishes recommendations on financial crime. Recommendation 16 has long required identifying information to accompany wire transfers, and it was extended to virtual assets and to the businesses that handle them.
FATF has no legal authority anywhere. It cannot bind you, your exchange, or any government. It writes standards and assesses whether countries have implemented them.
National law that implements it
Each country legislates its own version. This is the layer that actually binds anyone. It is why the rule looks different in every jurisdiction: different thresholds, different data requirements, different treatment of self-custody, different enforcement.
When someone says "the travel rule requires X", the honest question is: under whose law?
Your exchange's own policy
Firms build compliance programmes on top of the law, and they are generally free to be stricter than it requires. A great deal of what people experience as "the travel rule" is actually one platform's risk appetite.
This is why two exchanges in the same country, subject to identical law, handle the same transfer completely differently.
VASP, virtual asset service provider: the standard-setting term for exchanges, custodians and similar businesses. Some jurisdictions use their own term for the same category. Originator is the sender, beneficiary the recipient. Self-hosted or unhosted wallet means a wallet you control yourself, with no business in between.
What travels, and how
The categories of information are stable even where the exact fields differ:
- Identifying information about the sender, verified against identity documents
- The sending account or wallet address
- Some form of address or identity number for the sender, with jurisdictions differing on which alternatives they accept
- The recipient's name
- The receiving account or wallet address
The receiving business carries out the checks its own rules require, which commonly include verifying that the required information is present and screening against applicable sanctions lists, and both sides retain records for a defined period. What exactly is verified, what screening is performed, which thresholds apply and how missing information must be handled are set by the applicable law and by the firm's own compliance programme, and differ between jurisdictions and between firms.
The crucial mechanical point: none of this data travels on the Bitcoin network. It moves through separate messaging systems that regulated firms operate alongside the blockchain. That is why an exchange can hold a withdrawal pending information that has nothing to do with the transaction itself, and why the requirement can exist at all on a network that carries no identity data.
How thresholds work
Rather than list numbers that expire, here is the shape they take, so you can read any jurisdiction's rule correctly.
There is usually a value threshold, below which reduced or no information is required. Standard-setters propose a figure; countries adopt it, lower it, or remove it.
Zero thresholds exist. Some jurisdictions apply the requirement to every transfer between regulated firms regardless of size. Do not assume a small transfer is exempt.
Domestic and cross-border are often different. A jurisdiction may set a threshold for internal transfers and none for transfers leaving the country.
Thresholds and requirements change, and usually not in your favour. Regulatory requirements in this area have frequently been extended rather than relaxed, and information obligations have tended to increase. That is a description of the recent direction, not a legal rule and not a prediction. Do not assume that today's threshold will still be today's threshold when it matters; check the current position at the time.
Proposals are not law. A great deal of reporting describes proposed threshold changes as though they were in force. Some proposals sit unadopted for years. Always check whether a rule has actually been finalised.
Self-custody: the part that matters for bitcoiners
Be precise here, because this is where most confusion and most misreporting lives.
The rule binds businesses, not individuals. The obligations it creates fall on regulated firms. It does not make you, as a private person, a regulated entity, and it does not impose reporting duties on you directly.
That is not the same as saying self-custody is outside the framework. This is the distinction most often got wrong, in both directions.
- A transfer between two self-hosted wallets, with no regulated firm at either end, involves no intermediary and no travel rule obligation. Sending Bitcoin from your hardware wallet to a friend's engages nobody who is subject to the rule.
- A transfer between a regulated firm and a self-hosted wallet is squarely within the framework. Several regimes address self-hosted addresses expressly. The European Union's transfer of funds regulation, for example, requires a crypto-asset service provider handling a transfer to or from a self-hosted address to take measures, above a defined value, to establish whether the address is owned or controlled by its own customer. The obligation is the firm's, but the transaction is yours, and the practical consequence lands on you.
"Self-custody is outside the rules" is repeated constantly and is false as a general statement. Whenever a regulated firm is at one end, the transfer is within the perimeter, and the firm will be required to do something about your wallet. What that something is depends on your jurisdiction and the value involved.
The accurate formulation is narrower and more useful: the duties are imposed on firms, not on you; but a transfer involving a firm is covered even when the other end is your own wallet.
But the boundary between an exchange and self-custody is regulated. When one end is a business and the other is your own wallet, there is no counterparty firm to send data to. Regulators therefore require the firm to apply its own risk-based measures instead. That produces what you actually experience:
- Being asked to name the owner of a destination wallet
- Being asked to declare whether a wallet is yours or a third party's
- Being asked to prove control, by signing a message or sending a test amount
- Limits or additional checks above certain values
These come from the firm's obligations under national law and its own policy, not from data being handed to a counterparty. Practice varies enormously between platforms in the same country, which is itself the clearest evidence that much of it is policy rather than law.
Coverage of this area routinely turns obligations on businesses into claims that governments are "banning self-custody" or "banning anonymous wallets". The pattern is consistent enough to treat as a rule of thumb: when you read that a jurisdiction has banned something about private holding, check whether the instrument actually regulates firms. It almost always does.
The practical effect on individuals is that regulated platforms ask more questions. That is a real cost and worth objecting to. It is not the same as private holding becoming unlawful.
Structural consequences worth understanding
The data is permanent and shared
Transfer data is retained for years and shared between institutions. Combined with a public ledger, a single disclosed address links an identity to a permanently searchable transaction history. This is the privacy cost, and unlike a bank record it cannot be undone, because the chain side is public forever.
Withdrawing to yourself is not a loophole
Moving coins to self-custody does not escape the framework retroactively. Your exchange already knows who you are and which address you withdrew to, and it keeps that record for years. Self-custody removes ongoing custodial risk. It does not remove the historical record.
The framework assumes an operator
The definition of a regulated business assumes there is a business: an entity with customers, control and a compliance function. Software with no operator does not fit the definition, which is an openly discussed structural gap rather than a loophole anyone is hiding.
Firms are stricter than the law
Because the penalty for under-compliance is severe and the penalty for over-compliance is an annoyed customer, firms systematically err toward more friction. If a requirement seems disproportionate, it may well be, and a different regulated platform may handle it differently.
How to find the current rule for yourself
This is the part that keeps working after every change. Four steps, in order.
Identify which law applies to you
Not your country necessarily. The relevant law is that of the jurisdiction regulating the entity you actually contracted with. Check the terms of service and the website footer for the licensed entity name, which is frequently different from the brand and frequently in a different country.
Go to the regulator, not the news
Financial regulators and financial intelligence units publish their own guidance, and it is free. This is the authoritative source. Reporting on regulatory change is the least reliable category of crypto journalism, because it requires reading a statutory instrument rather than a press release.
Check whether it is in force
For any rule you find, establish three things: has it been adopted, when does it apply from, and is there a transition period. Instruments are routinely reported as current years before they take effect, and equally routinely reported as proposals long after they have become binding.
Read the exchange's own policy separately
Once you know the legal floor, compare it against what your platform actually requires. The gap between the two is the platform's own choice, and it is information worth having when deciding where to hold an account.
What this means practically
- Expect to be asked about destination wallets. It is normal and not an accusation.
- Answer accurately. Misdeclaring whose wallet something is creates a far larger problem than the question it avoids.
- Assume any address you withdraw to is permanently linked to your identity in that firm's records.
- Keep your own acquisition records. Requirements in this area have only ever increased.
- Verify the current rule in your own jurisdiction before acting. Never rely on a general explanation, including this one, for a specific decision.
Everything here is written to stay true. It explains how the machinery works rather than what today's numbers are, because thresholds, rates and deadlines change every year and a stale legal page is worse than no page at all. Where a current figure matters to your decision, this page tells you how to find it rather than guessing on your behalf.
General information, not legal advice. This site does not provide legal advice, and no professional or advisory relationship is created. This page describes the general structure of virtual asset transfer reporting requirements. It deliberately omits specific thresholds, dates and national provisions, because those change frequently and any figure stated here would eventually mislead. The rules that bind you are those of the jurisdiction regulating the firm you deal with, as they stand today. Consult that regulator's current guidance and a qualified lawyer licensed where you live.