A crypto transfer above a certain threshold may now carry your identity with it, swapped silently between exchanges behind the scenes. That is the Travel Rule, an anti-money laundering standard long applied to bank wires, now reshaping how regulated crypto transfers work. As of 2026, dozens of jurisdictions have enacted their own versions, with stark differences in thresholds and enforcement priorities.
From banks to crypto: origins and extension
The rule did not start with crypto. It traces back to the U.S. Bank Secrecy Act and FinCEN guidance from the 1990s, requiring banks to attach sender and recipient information on wire transfers above a set amount. In 2019, the Financial Action Task Force (FATF) extended Recommendation 16 to virtual assets, applying the same-risk-same-rules principle to crypto exchanges, custodial wallet providers, and other virtual asset service providers (VASPs). Since then, countries have written national laws, creating a patchwork of requirements.
Information shared and how it travels
The rule mandates that originator VASPs collect and share names, account or wallet identifiers, and sometimes physical addresses or ID numbers with beneficiary VASPs. Crucially, this data is transmitted off-chain through secure messaging channels between regulated entities, not written onto the blockchain. Standardized protocols now allow different providers to exchange data reliably and verify each other's identity before sending sensitive customer information. For regular users, the process is invisible but imposes a new layer of identity infrastructure beneath every compliant transfer.
Global threshold variations: $3,000 vs zero
No single global threshold exists. The U.S. maintains a $3,000 trigger under FinCEN rules, though proposals to lower it for international transfers are circulating. The European Union takes the strictest approach via its Transfer of Funds Regulation, effective since late 2024, which applies a zero threshold — every crypto transfer between providers, regardless of amount, must comply. This creates heavy operational burdens on exchanges and raises privacy concerns for small recurring transfers like dollar-cost averaging.
Who is covered — and who is not
The rule applies to all regulated intermediaries: exchanges, custodial wallets, OTC desks, and crypto payment processors. It does not generally cover direct peer-to-peer transfers between two self-hosted (unhosted) wallets, as no intermediary exists to collect and transmit data. However, when a regulated VASP sends funds to or receives from an unhosted wallet, it may still need to collect information even if no counterparty institution exists. DeFi protocols and non-custodial services occupy an ambiguous space, with regulators actively exploring how to extend the rules to them.
Privacy implications and gaps
The rule reduces the pseudonymity once associated with crypto, attaching verifiable identity to both ends of a transfer. This raises legitimate data-security questions: sensitive personal information is now held and transmitted by multiple entities, increasing exposure risk. The uneven global adoption — known as the sunrise problem — leaves enforcement gaps, as transfers between countries with different rules may fall through regulatory cracks.

