A customer passes identity verification, buys stablecoins and requests a withdrawal to an external wallet. The platform knows the customer’s identity. What connects that customer to the destination address?
That missing connection creates an operational challenge for crypto businesses. A blockchain records the transfer, but the address alone does not explain who controls the wallet, who benefits from the payment or why the funds are moving.
On 3 March 2026, FATF published a targeted report highlighting illicit finance risks associated with stablecoins and peer-to-peer transfers through unhosted wallets. These transfers can occur without a regulated intermediary collecting customer information or applying transaction controls. FATF’s targeted report on stablecoins and unhosted wallets.
For platforms handling crypto deposits and withdrawals, the practical task is to connect three things: the customer, the external wallet and the risk of the transfer.
Why unhosted wallets create an AML visibility gap
An unhosted wallet, also called a self-hosted or self-custody wallet, lets a person control crypto assets without a custodial provider holding the private keys on their behalf.
Self-custody is a legitimate way to hold and use crypto. The compliance challenge arises when an external address interacts with a regulated platform and the relationship between the address and the customer remains unclear.
Consider a withdrawal to a newly added address. The customer could be:
- Moving assets into their own wallet.
- Paying another person.
- Sending funds under a scammer’s instructions.
- Acting on behalf of an undisclosed third party.
The transfer can look similar on-chain in each case. Its purpose and the appropriate response may be very different.
A completed KYC check establishes information about the platform’s customer. Additional evidence is needed to understand the customer’s relationship with the external wallet.
Stablecoins and illicit activity: what the 84% figure means
Chainalysis reported that stablecoins accounted for 84% of identified illicit cryptocurrency transaction volume in 2025.
That figure describes the composition of identified illicit activity. It does not mean that 84% of stablecoin transactions were illicit, or that unhosted wallets were involved in all of that volume.
In the same analysis, Chainalysis estimated that illicit activity represented less than 1% of all attributed cryptocurrency transaction volume under its methodology. These estimates can change as additional illicit addresses are identified. Chainalysis’ 2026 Crypto Crime Report introduction.
For product and compliance teams, the useful takeaway is specific: stablecoin transfers need the same attention to customer context, wallet evidence and transaction risk as other supported crypto assets.
What wallet ownership verification actually establishes
Wallet verification helps connect a customer’s declaration to evidence about an external address.
The strength of that evidence depends on the method. A written declaration records what the customer claims. A suitably designed on-chain verification transaction can provide evidence of control. Neither automatically establishes the origin of the funds or the full economic purpose of a transfer.
A practical verification record should answer four questions:
- Which customer submitted the address?
- Did they identify it as their own wallet or someone else’s?
- What evidence supports that statement?
- Who or what accepted the evidence?
This distinction matters when designing the customer journey. A customer paying a third party should not be pushed into declaring that the destination wallet is their own. The workflow needs a route for the actual relationship.
Finhost’s unhosted wallet management documents verification through a customer declaration or an on-chain ownership transaction. It also allows customers to correct a wallet classified as unhosted by identifying the custodial provider.
The verification service requires separate activation. Teams should confirm that the enabled methods meet their operating requirements and provide appropriate evidence for the relevant transfer scenario.
Why a verified wallet still needs blockchain analysis
A customer can demonstrate control of an address that later receives funds associated with illicit activity. The earlier control check may remain valid while the wallet’s risk profile changes.
Wallet verification and transaction screening therefore answer different questions.
- Customer identity verification: Who is using the platform? This does not establish control of every external address.
- Wallet verification: What connects the customer to this address? This does not establish the legitimacy of funds.
- Blockchain analysis: What risk indicators are associated with the address or transfer? This does not independently establish the customer’s relationship with the wallet.
- Compliance review: How should the platform handle this case? The decision depends on the quality and completeness of available evidence.
When evaluating crypto blockchain analysis, teams should confirm asset and network coverage, the meaning of risk indicators and the conditions that require review.
A useful investigation considers the amount, timing and nature of the exposure. Direct receipt from an identified illicit address and an indirect connection several transfers away require different interpretation.
For example, a customer’s verified wallet may receive a deposit that is inconsistent with their expected activity. The reviewer needs the customer profile, relevant transaction history and screening findings together to assess the case.
A previous verification result should remain one piece of evidence in that decision.
How the Travel Rule fits into unhosted wallet transfers
The counterparty type determines the information workflow.
A transfer involving another virtual asset service provider can involve exchanging information with that provider. A transfer involving a self-hosted address has no custodial provider at that end to receive or supply the same information.
FATF identifies the absence of regulated intermediaries in direct peer-to-peer transfers as a vulnerability. Its report provides recommendations; the specific obligations applicable to a platform depend on the relevant jurisdiction and regulatory framework. FATF’s report and recommendations.
For product teams, this means identifying the counterparty early enough to route the transfer correctly.
When reviewing crypto travel rule compliance, establish how the process handles:
- A recognised custodial provider.
- A customer’s own self-hosted wallet.
- A third party’s self-hosted wallet.
- An address whose classification remains uncertain.
- Missing or conflicting counterparty information.
The customer should understand what information is needed and how to provide it. Compliance reviewers need visibility into what is missing and whether the outstanding issue concerns identity, wallet control or transaction risk.
Build wallet checks into the deposit and withdrawal flow
The following workflow provides a practical starting point for implementation. Verification methods, decision rules and review requirements should reflect the operator’s obligations and supported integrations.
Establish the wallet relationship
Capture the address and network, then ask whether the destination belongs to the customer, another person or a custodial service.
Allow corrections. An address that is not recognised as belonging to a provider may still be hosted.Collect the required evidence
Where verification is required, explain the supported method and the action the customer must take.
Record which method was used, when it was completed and what the result establishes. A declaration and technical evidence of control should remain distinguishable in the case record.Assess address and transaction risk
Bring screening findings into the same review context as customer and wallet information.
Define which findings allow normal processing, which require further information and which prevent the transfer from proceeding under the applicable rules.Give unresolved cases a clear status
Failed verification, conflicting declarations and material risk indicators need an assigned review path.
Finhost’s documented unhosted wallet flow includes customer verification links, a two-calendar-week completion window and manual compliance handling after expiry. Ownership confirmation and risk screening remain separate checks. Finhost’s unhosted wallet verification workflow.
For the customer, a pending transfer should have an understandable explanation and a clear next action where one is available.Handle incoming deposits separately
An on-chain deposit may arrive before the platform has completed its review.
Product and compliance teams should define when received funds become available, how restrictions are displayed and who resolves outstanding cases. Returning funds also requires an assessed workflow; an unresolved deposit should not trigger an unexamined automatic return.Preserve the decision record
Keep the evidence needed to explain the outcome:
- Address, network and transaction reference.
- Customer declaration and counterparty details.
- Verification method and result.
- Screening findings and timestamps.
- Reviewer actions and decision rationale.
This record helps a later reviewer understand why the platform allowed, restricted or rejected the transaction.
Connect the controls around one transfer decision
An effective unhosted wallet workflow brings customer identity, wallet evidence and blockchain risk into the same decision.
Ownership verification helps establish the relationship with an address. Blockchain analysis supplies information about transaction exposure. Travel Rule processes address the relevant transfer information requirements.
Each contributes a different part of the evidence. The platform’s operating procedures determine how those inputs affect the transfer.
For a team building a crypto product, a useful implementation review starts with one withdrawal: can the reviewer explain who is sending, who controls the destination, what risks were identified and why the transfer can proceed?
Then run the same review for an incoming deposit, a third-party wallet and an unresolved verification. Those cases show whether the process works beyond the simplest customer journey.
Top comments (0)