[{"data":1,"prerenderedAt":19},["ShallowReactive",2],{"blog-content-en-exchange-asks-to-verify-self-hosted-wallet":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9},"exchange-asks-to-verify-self-hosted-wallet","Why Is My Exchange Asking Me to Verify My Wallet? Travel Rule, Satoshi Tests and Message Signing Explained","Withdrawal on hold until you \"verify your wallet\"? Travel Rule laws, including the EU's since 30 December 2024, make exchanges collect information on and sometimes verify self-hosted addresses. How Satoshi tests and signed messages work, what is safe to sign, and how to spot fake requests.","Exchange wallet verification explained: why the Travel Rule makes exchanges ask you to prove a self-hosted wallet, plus Satoshi tests and safe signing.","\u003Cblockquote>\u003Cp>Exchanges ask you to prove that a self-hosted wallet is yours because anti-money-laundering \"Travel Rule\" laws require them to know who is on the other end of a transfer. In the EU, Regulation (EU) 2023\u002F1113 has applied since 30 December 2024, and for transfers of EUR 1,000 or more with a self-hosted address the exchange must assess whether its customer owns or controls that address (as of October 2026). You usually prove ownership with a small \"Satoshi test\" transfer or by signing a plain-text message; start the request only inside the exchange's own app or site, and never share your seed phrase.\u003C\u002Fp>\u003C\u002Fblockquote>\n\u003Ch2>Why is my exchange asking me to verify my wallet?\u003C\u002Fh2>\n\u003Cp>Because crypto exchanges must follow the Travel Rule, an anti-money-laundering standard that requires sender and recipient information to accompany a transfer, as it does with bank wires.\u003C\u002Fp>\n\u003Cp>A hosted wallet is an account at another exchange. A self-hosted (or unhosted) wallet is software or hardware where you administer the private key yourself; the UK regulations define an unhosted wallet in much the same way. Two exchanges can swap data with each other, but a self-hosted address has no counterpart exchange, so your exchange asks you and, in some jurisdictions, checks that the address is yours.\u003C\u002Fp>\n\u003Cp>Being asked is normal and does not mean you are suspected of anything. Some exchanges verify every new self-hosted address as policy, even where the law sets a threshold.\u003C\u002Fp>\n\u003Ch2>What do the rules actually require?\u003C\u002Fh2>\n\u003Cp>It depends on the country: the EU requires an ownership assessment from EUR 1,000, Switzerland requires proof of ownership, and the UK is risk-based.\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\u003Ctr>\u003Cth>Jurisdiction\u003C\u002Fth>\u003Cth>Rule and source\u003C\u002Fth>\u003Cth>Date\u003C\u002Fth>\u003Cth>Self-hosted wallets\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\u003Ctd>EU\u003C\u002Ftd>\u003Ctd>Regulation (EU) 2023\u002F1113, Articles 14(5) and 16(2); EBA Guidelines EBA\u002FGL\u002F2024\u002F11\u003C\u002Ftd>\u003Ctd>Applies from 30 December 2024\u003C\u002Ftd>\u003Ctd>From EUR 1,000, the exchange must assess whether the address is owned or controlled by its customer. Below that, it still collects originator and beneficiary information.\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Switzerland\u003C\u002Ftd>\u003Ctd>FINMA Guidance 02\u002F2019, \"Payments on the blockchain\"\u003C\u002Ftd>\u003Ctd>26 August 2019\u003C\u002Ftd>\u003Ctd>External wallets are allowed only if they belong to the institution's own customer, and ownership must be proven using suitable technical means. The guidance states no amount threshold.\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>UK\u003C\u002Ftd>\u003Ctd>Money Laundering Regulations 2017, Part 7A (SI 2022\u002F860), regulation 64G\u003C\u002Ftd>\u003Ctd>In force 1 September 2023\u003C\u002Ftd>\u003Ctd>Risk-based: the business may request information about an unhosted wallet transfer, and must not make the crypto available if the requested information is not received. This is information collection, not a mandatory ownership proof.\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Singapore\u003C\u002Ftd>\u003Ctd>MAS Notice PSN02, paragraphs 6.27 and 13.3 to 13.11\u003C\u002Ftd>\u003Ctd>Amendment issued 30 June 2025 (effective 1 July 2025)\u003C\u002Ftd>\u003Ctd>The notice does not mention unhosted wallets or prescribe an ownership proof. It requires enhanced risk mitigation for transfers to or from any entity other than a regulated financial institution (paragraph 6.27), and originator and beneficiary details with each transfer, with the originator's identity verified and more details included above S$1,500 (paragraphs 13.4 to 13.6).\u003C\u002Ftd>\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Cp>In the EU, the EUR 1,000 threshold is measured at the euro value when the transfer is ordered or received, regardless of fees, per the EBA guidelines. Rules differ by country and change over time. This is not legal advice; your exchange's help page says what it applies to you.\u003C\u002Fp>\n\u003Ch2>Which verification methods will I see?\u003C\u002Fh2>\n\u003Cp>The common ones are a Satoshi test, a signed message and visual proof; EU exchanges are told to use at least one of several listed methods and to combine them when one is not reliable enough.\u003C\u002Fp>\n\u003Cp>Paragraph 83 of the EBA guidelines lists attended or unattended verification that displays the address, sending a predefined amount set by the exchange, digitally signing a specific message with the key for that address, and other suitable technical means. Paragraph 85 says to combine methods where one is not reliable enough.\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\u003Ctr>\u003Cth>Method\u003C\u002Fth>\u003Cth>What you do\u003C\u002Fth>\u003Cth>Moves funds?\u003C\u002Fth>\u003Cth>Watch-outs\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\u003Ctd>Satoshi test\u003C\u002Ftd>\u003Ctd>Send an exact small amount to the exchange's deposit address\u003C\u002Ftd>\u003Ctd>Yes\u003C\u002Ftd>\u003Ctd>You pay the network fee; wrong network or amount fails\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Signed message\u003C\u002Ftd>\u003Ctd>Sign a text the exchange gives you, often through WalletConnect\u003C\u002Ftd>\u003Ctd>No\u003C\u002Ftd>\u003Ctd>The wallet must support signing; read what you sign\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Visual proof\u003C\u002Ftd>\u003Ctd>Show a screenshot or video of the wallet displaying the address\u003C\u002Ftd>\u003Ctd>No\u003C\u002Ftd>\u003Ctd>Manually reviewed and can be tampered with, according to 21 Analytics\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>AOPP\u003C\u002Ftd>\u003Ctd>Automated signed-message flow through a portal\u003C\u002Ftd>\u003Ctd>No\u003C\u002Ftd>\u003Ctd>Wallet support varies\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Self-declaration\u003C\u002Ftd>\u003Ctd>Tick a box saying the address is yours\u003C\u002Ftd>\u003Ctd>No\u003C\u002Ftd>\u003Ctd>Offered by some verification providers (for example Notabene); not among the EBA's listed methods\u003C\u002Ftd>\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Cp>Use a signed message if your wallet supports it and you want to avoid a network fee, and a Satoshi test if it does not. Signing standards vary by chain: Notabene's documentation cites EIP-191 on EVM chains and ed25519 on Solana. Screenshots map only loosely to the EBA's \"displaying the address\" method, so an exchange may ask for a second method as well.\u003C\u002Fp>\n\u003Ch2>How does a Satoshi test work?\u003C\u002Fh2>\n\u003Cp>A Satoshi test is a small transfer from the wallet you are verifying to the exchange, which shows you control that address.\u003C\u002Fp>\n\u003Col>\n\u003Cli>Start the withdrawal or deposit in your logged-in exchange account and choose the self-hosted wallet option.\u003C\u002Fli>\n\u003Cli>Note the network, exact amount, deposit address (plus memo or tag, if any) and deadline the exchange shows.\u003C\u002Fli>\n\u003Cli>Send exactly that from the address you are verifying, and paste the transaction ID if asked.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Copy the deposit address only from inside your account, never from an email or chat, and match the network exactly; \u003Ca href=\"\u002Fblog\u002Fsent-crypto-to-wrong-network-how-to-recover\">sending on the wrong network\u003C\u002Fa> can strand funds. According to 21 Analytics, test amounts are typically around 1 EUR or USD, larger amounts may signal a fraudulent request, and network fees are typically not reimbursed. Whether the test amount itself is refunded or credited depends on the exchange.\u003C\u002Fp>\n\u003Cp>Once an EU exchange is satisfied, it may record (\"whitelist\") the address and skip repeat checks, but it can re-check if risk or ownership changes (EBA guidelines, paragraph 86). The test also ties your identity to that address in the exchange's records, and \u003Ca href=\"\u002Fblog\u002Fcrypto-wallet-privacy-what-your-address-reveals\">anyone can read an address's public history\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Is it safe to sign a message to verify my wallet?\u003C\u002Fh2>\n\u003Cp>Signing a plain, readable message is generally safe because it proves key control without moving funds, but not every signature request is a plain message.\u003C\u002Fp>\n\u003Cp>Binance.US's help center (July 2026) says off-chain signing does not change anything on the blockchain, yet scammers abuse it. It calls eth_sign the riskiest method because it signs unreadable raw data; \u003Ca href=\"\u002Fblog\u002Fwhat-is-blind-signing\">signing data you cannot read\u003C\u002Fa> is a known trap. Structured typed data can also be a token Permit or approval, which can let someone spend your tokens without another transaction; see \u003Ca href=\"\u002Fblog\u002Ftoken-approvals-and-permit-explained\">how Permit signatures work\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>The rule: sign only human-readable text that names the exchange and your address, often with a timestamp or nonce, in a flow you started from the exchange's own site or app. If the wallet shows a spending approval, a token amount or a transaction, reject it. A phishing site can try to pass a transaction off as a message.\u003C\u002Fp>\n\u003Ch2>How do I tell a real verification request from phishing?\u003C\u002Fh2>\n\u003Cp>A real request appears inside your logged-in exchange account, tied to a transfer you started; a phishing request arrives by link or message and creates urgency.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>No legitimate exchange, regulator or wallet needs your seed phrase or private key.\u003C\u002Fli>\n\u003Cli>A Satoshi test asks for a tiny amount sent to a deposit address shown in your account, never \"send funds to unlock\" and never to an address from a DM.\u003C\u002Fli>\n\u003Cli>Threats such as \"wallet frozen in 24 hours\" are a warning sign.\u003C\u002Fli>\n\u003Cli>Message text should be readable and name the exchange's real domain.\u003C\u002Fli>\n\u003Cli>Do not click \"verify your wallet\" links in email, SMS, Telegram or X. Open the exchange yourself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>A common pattern is a fake \"Travel Rule\" email that leads to a drainer site asking for a seed phrase or a malicious signature. More in \u003Ca href=\"\u002Fblog\u002Fhow-to-spot-crypto-phishing\">how to spot crypto phishing\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>What does wallet verification mean for privacy and taxes?\u003C\u002Fh2>\n\u003Cp>It links your verified identity to an address in the exchange's records, and it is separate from tax reporting.\u003C\u002Fp>\n\u003Cp>The Travel Rule governs transfer data. Tax reporting is a different regime: the EU's DAC8 directive, which builds on the OECD's CARF framework and applies from 1 January 2026, and in the US Form 1099-DA, on which brokers report digital asset sales and exchanges (gross proceeds for 2025 transactions, per the IRS). See \u003Ca href=\"\u002Fblog\u002Fself-custody-wallet-taxes-1099-da\">Form 1099-DA and self-custody wallets\u003C\u002Fa>. This is not tax advice.\u003C\u002Fp>\n\u003Ch2>How does WATS Wallet fit in?\u003C\u002Fh2>\n\u003Cp>An exchange will generally treat a WATS Wallet address as a self-hosted wallet, because WATS Wallet is non-custodial: you create and hold your own keys and seed phrase in the Chrome extension or the iOS\u002FAndroid app, and WATS never holds a key. A withdrawal to it may therefore trigger the checks above.\u003C\u002Fp>\n\u003Cp>A Satoshi test from WATS Wallet is an ordinary send of the asset and amount the exchange specifies, on the network it specifies. On EVM networks the fee is paid in ATS through an ERC-4337 paymaster from one \u003Ca href=\"\u002Fats-fee\">ATS balance on BSC\u003C\u002Fa>, so you need ATS there rather than the native gas coin; on Solana it is SOL and on TON it is GRAM (formerly Toncoin). The ATS fee tracks the live network cost and is not a discount. WATS Wallet has no native Bitcoin support, so a BTC test cannot use it. If you use the \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card\u003C\u002Fa>, tapping it confirms the send in the mobile app; the card holds no keys.\u003C\u002Fp>\n\u003Cp>If an exchange requires a method you cannot complete, use another it offers or ask its support. Never give anyone your seed phrase.\u003C\u002Fp>\n",[10,13,16],{"q":11,"a":12},"Does the Travel Rule apply to withdrawals under EUR 1,000?","In the EU, the ownership or control check under Regulation (EU) 2023\u002F1113 is tied to transfers of EUR 1,000 or more, valued at the time of transfer. Below that, the exchange still collects your originator and beneficiary details and may verify anyway under its own risk policy. Outside the EU the rules differ: UK regulation 64G is risk-based and FINMA Guidance 02\u002F2019 states no threshold. Check your exchange's help page; this is not legal advice.",{"q":14,"a":15},"Do I have to verify my wallet every time I withdraw?","Usually not. Under paragraph 86 of the EBA guidelines, once an EU exchange is satisfied that an address is yours it can record (whitelist) it and may skip repeat checks. It can re-verify if the risk or ownership changes, and a new address normally means a new check. Practice varies by exchange.",{"q":17,"a":18},"What if my wallet can't sign messages?","Use another method the exchange offers. Many exchanges offer a Satoshi test, a tiny send from that address, and some accept visual proof such as a screenshot or video, or a combination. The EBA guidelines let exchanges choose methods based on the wallet's technical capabilities and combine them if one is not reliable enough. Never hand over a seed phrase or private key as proof; no legitimate exchange asks for it.",1791403881641]