You click withdraw. The exchange asks for the name of the person who controls the receiving address, and whether that address belongs to another platform or to a wallet on your own phone. The transaction will not broadcast until the form is filled. Support cannot wave it through, because the person answering the chat has no button that skips it.
The rule behind that screen is the travel rule, and understanding it removes most of the frustration. It also explains why the same withdrawal is instant on one platform and stuck for a day on another.
A wire transfer rule pointed at blockchains
The Financial Action Task Force wrote Recommendation 16 for bank wires. When money moves, the originator and beneficiary details move with it inside the payment message, so the receiving bank can screen the names against sanctions and watch lists before crediting the account. That principle has been in place in correspondent banking for decades.
In June 2019, FATF extended the same requirement to virtual assets through its interpretive note to Recommendation 15. Virtual asset service providers, VASPs, now sit under the same obligation as banks: collect the identity data, verify it, transmit it to the counterparty, and screen what arrives.
The mechanical problem is that a blockchain has nowhere to put it. A Bitcoin transaction carries inputs, outputs, a fee and an optional data field nobody sane fills with a customer's date of birth. So the identity record has to travel off-chain, firm to firm, over a separate channel, and the sending firm has to work out who the receiving firm is from nothing but a string of characters. That single design gap is the source of nearly every travel rule friction a trader experiences.
The data set, and why it looks like a bank form
The industry settled on a shared schema called IVMS101, the interVASP messaging standard, so that a firm in Singapore and a firm in Lithuania describe a customer the same way. The payload is small: originator name, the originator's account identifier, which for crypto is the sending wallet address, and one more identifying element such as a physical address, a national identity number, a customer number, or date and place of birth. Then the beneficiary name and the receiving address.
Notice what is absent. There is no transaction purpose, no source of wealth narrative, no document upload. Those belong to onboarding and to the wider AML directives, not to the travel rule. When a platform asks for a payslip before releasing a withdrawal, that is a separate control, usually an enhanced due diligence trigger, and it is worth knowing the difference when you are arguing about a delay.
Thresholds are not the same in any two places
The single most confusing part is that the number changes with geography, and a transfer crosses two jurisdictions at once.
| Regime | Threshold approach | Practical effect |
|---|---|---|
| FATF standard | De minimis of USD or EUR 1,000 permitted | Below it, a reduced data set may be used, names and addresses without full verification |
| European Union | No de minimis for crypto-asset transfers | Full data on every transfer, regardless of size |
| United States | Bank Secrecy Act funds transfer threshold of USD 3,000 | Higher floor, though firms often apply their own lower internal limit |
A European platform will therefore ask questions on a EUR 40 transfer that an offshore venue ignores entirely. Neither is doing anything unusual. They are each following the rule book that licensed them, which is also why the answer to "is this normal?" is nearly always yes.
Self-hosted wallets and proving the address is yours
Sending to another exchange is the easy case: two regulated firms, one data exchange. Sending to a wallet you hold yourself is harder, because there is no counterparty firm to receive the message. The obligation does not disappear, it changes into a verification duty on the sending platform.
Above the applicable threshold, European rules require the provider to confirm that the customer actually controls the self-hosted wallet. In practice that means one of three methods: a message signed with the wallet's private key, a small test transfer from the wallet back to the platform, or a screen recording that shows the address inside the wallet application. The signed message is the strongest and the least intrusive. If a platform offers it, use it, because the alternatives cost more time.
The travel rule is an obligation on the firm, not on you. No amount of arguing changes what its compliance team is permitted to release, and a firm that quietly skips it is a firm whose licence is at risk, which eventually becomes your problem too.
The sunrise gap, and what it means for withdrawals
Countries adopted the rule on different dates. Some still have not. That mismatch is known in the industry as the sunrise issue: a compliant firm has to send data to a counterparty that has no legal duty to receive it, sometimes no technical means to receive it, and occasionally no interest in the conversation. Firms respond by building counterparty lists. Send to a platform they already exchange data with, and the withdrawal moves. Send to one they have never handshaked with, and the transfer waits in a queue for manual review.
This is worth knowing before you pick a deposit route. If you are funding a trading account with stablecoins, the path from a large exchange to a well-connected processor clears faster than a path through an obscure venue, purely because the data channel already exists. It has nothing to do with the coin.
What a trading firm has to do about it
Any broker or prop firm that accepts crypto deposits meets this rule from the other side. Either the firm is itself registered as a VASP, in which case the full obligation lands on it, or it accepts crypto through a licensed payment processor that carries the registration and hands over fiat or stablecoin settlement. The second route is the sane one for most firms, and it is one of the practical reasons VASP registration is a decision to make deliberately rather than by accident.
What the firm cannot outsource is the record. The deposit, the wallet address it came from, the identity data attached to it and the sanctions screening result all have to sit together and be retrievable years later when a regulator or a bank asks. Firms that keep payments in one system and clients in another spend their audits reconciling spreadsheets. Keeping the money trail and the client file in a single back office is the unglamorous fix.
"Traders think the exchange is being difficult. It rarely is. Somebody in that building signed a rule book that says the coins stay put until the name is on file, and the support agent you are messaging has no button to override it."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- The travel rule is FATF Recommendation 16 applied to virtual assets since 2019: identity data must accompany a transfer, and since a blockchain has no field for it, firms exchange it off-chain.
- The data set is standardised as IVMS101 and is narrow: names, wallet addresses and one extra identifier. Requests for payslips or source of funds come from a different control.
- Thresholds differ: FATF permits a de minimis around USD or EUR 1,000, the EU applies none for crypto transfers, and the US works from the older USD 3,000 wire threshold.
- Withdrawal speed depends on whether the two firms already exchange travel rule data. Well-connected routes clear quickly, unknown counterparties fall into manual review.
Frequently Asked Questions
Does the crypto travel rule apply when I withdraw to my own wallet?
Yes, in most regimes it still applies, but the obligation changes shape. Instead of passing data to another regulated firm, the sending provider has to satisfy itself that you control the destination address. Above the applicable threshold, EU rules require the provider to verify ownership of a self-hosted wallet, which is why exchanges ask for a signed message, a small test transfer or a wallet screenshot.
Why does an exchange need the recipient's name for a blockchain transfer?
Because the identity data cannot ride on the blockchain itself. FATF Recommendation 16, extended to virtual assets in 2019, requires originator and beneficiary details to accompany a transfer so the receiving institution can screen them. Since a Bitcoin or Ethereum transaction has no field for that, providers exchange the data off-chain, and they need the name before they can send it.
What is the travel rule threshold?
It depends on the jurisdiction. FATF suggests a de minimis of USD or EUR 1,000, below which a reduced data set can be used. The United States applies the older Bank Secrecy Act wire threshold of USD 3,000 to funds transfers. The European Union chose no de minimis at all for crypto-asset transfers, so the data requirement applies from the first cent.