Back to news

SEC Commissioner Hester Peirce: Stop Large-Scale KYC Collection

U.S. Securities and Exchange Commission Commissioner Hester Peirce stated at the New York Securities Industry and Financial Markets Association Digital Assets Conference that the current Know Your Customer (KYC) and Anti-Money Laundering (AML) frameworks are turning the financial landscape into a panoramic prison. She presented a binary choice: continue piling up data, increasing intermediary surveillance, and verification requirements; or use new technologies to collect less personal information, monitor more efficiently, and improve capture rates.

She pointed out that the system is based on a simple assumption: institutions collect enough information about enough people as per regulatory orders, and law enforcement can identify criminals from the law-abiding majority. The actual result is that the haystack keeps getting bigger, making it harder to find the needle. The data collection items mentioned include names, birth dates, addresses, identification numbers, and transaction details, even though institutions often only need to confirm narrower eligibility facts. She criticized the data maximization mindset, comparing the notion that "data must go up" to the cryptocurrency industry's obsession with price increases.

Alternatives include attribute credentials and zero-knowledge proofs. Credentials can prove age, nationality, accredited investor status, or non-inclusion on sanctions lists without disclosing the underlying materials that generate these facts. Zero-knowledge proofs can respond to counterparties with only "this person meets your requirements," without the need to disclose names, income, or addresses. She stated that the tools are available, but what is lacking is a regulatory framework that allows and encourages adoption, advocating a shift from mandated data collection fields to attribute verification where technically feasible, and allowing institutions to rely more on identity verifications already completed by other regulated entities, avoiding each one storing the same records.

This is her personal stance in the second-to-last week of her term and does not represent the views of other commissioners. A working group met with the cryptography company Aztec in July to hear about its ZKPassport verification solution. Her remarks followed a series of data breaches: Revolut was accused of exposing passport and Bitcoin transaction data in a false public authority request; Trezor's email vendor Brevo leaked approximately 347,000 marketing contacts, while logistics provider ShipMonk affected about 81,000 customers, increasing phishing and personal risks; Coinbase experienced a leak of around 69,000 customer identities and account information due to a compromised overseas customer service contractor last year. The media has compared these breaches to wrench attacks and home invasions: once identity and asset facts are in the same database, the cost of phishing and home visits decreases.

Discussions on stablecoin regulations simultaneously require issuers to retain identification records for years, effectively recreating a batch of replicable identity honeypots. Peirce advocates for reusable digital credentials that allow the next institution to verify facts without needing to collect original documents again.

In market mechanisms, this shifts compliance costs from "each entity archives" to "one verification, multiple proofs." The burden falls on exchanges and brokers that must repeatedly scan documents and build their own AML systems; the beneficiaries are companies that create zero-knowledge identities, portable credentials, and third-party verifications, as well as holders who do not want to write their addresses into the tenth customer database. Funds shift from operational expenses of copying passports to proof generation, credential issuance, and auditing. Whoever can turn "meeting regulatory requirements" into a mathematical proof without exposing records will gain pricing power in the next round of licensing attachments. Law enforcement will not disappear; what changes is the location of data storage: from a breachable central database to verifiable assertions on user devices.

Source: Public Information

ABAB AI Insight

Peirce has long been one of the least hostile commissioners towards cryptocurrency, opposing the replacement of rule-making with enforcement, hence her nickname. As her term comes to a close, she has shifted her focus from whether tokens are securities to the verification system itself: it is not about whether assets should be listed, but whether institutions need originals or just a yes or no. The July working group meeting with Aztec indicates that the office has begun to consider zero-knowledge passports as a compliance component worthy of discussion, rather than a marginal cryptographic exhibition.

The capital path is to detach repetitive data collection from legal obligations. Each exchange, broker, and stablecoin issuer storing a passport and selfie effectively replicates the attack surface of the same individual n times. After breaches at Revolut, Trezor suppliers, and Coinbase contractors, phishing and home visits no longer require on-chain analysis, just a leaked form. Attribute credentials turn verification into a one-time issuance with multiple presentations, shifting costs from scanning and storage to proof generation and revocation lists. The lobbying focus shifts from "give us clearer securities tests" to "allow us to trust proofs already verified by others."

A historical parallel is the credit card networks and credit bureaus: Visa does not keep copies of your ID at every store; merchants accept the network's assertion of "card valid, not over limit." The EU's electronic identity and verifiable credentials follow the same logic, but financial crime rules still require original documents to be stored. After Ledger's 2020 customer address leak, hardware wallet buyers began receiving home threats, illustrating that "collecting for safety" can reverse into location intelligence. The industry phase is to set gates: stablecoin legislation requires records to be kept for five years, and Peirce wants to replace that with mathematical proofs before the gates close, or else the honeypots will multiply according to the number of licenses.

The structural judgment is regulatory change. The mechanism is rewriting compliance from "having records" to "having valid proofs." Records create sellable personal coordinates, while proofs only answer eligibility questions. Pricing power shifts from intermediaries holding the largest customer databases to those who can issue, revoke, and be recognized by regulators for their credentials. The larger the haystack grows, the harder it is to find the needle, and the more valuable it becomes—both to hackers and to those selling monitoring products to regulators.

Source

·ABAB News
·
9 min read
·12 hrs ago
分享: