For most of Bitcoin's existence, cryptocurrency transactions have been pseudonymous — the blockchain records wallet addresses, but not the names of the people behind them. This has been a fundamental challenge for fraud recovery: you can trace stolen Bitcoin to a specific address, but you cannot easily find out who controls that address. The Financial Action Task Force (FATF) Travel Rule is changing this. Since 2019, the FATF has required virtual asset service providers (VASPs) — cryptocurrency exchanges, custodians, and other regulated crypto businesses — to collect and share sender and recipient information for transactions above a threshold. As of 2024, the rule is being enforced in an increasing number of jurisdictions, and it is fundamentally changing the landscape of crypto fraud tracing.
In this article, I explain what the FATF Travel Rule is, how it works in practice, which jurisdictions have implemented it, and what it means for crypto fraud recovery. If you are involved in crypto — as a user, an exchange, or a compliance professional — the Travel Rule affects you, and understanding it is essential.
What is the FATF Travel Rule?
The Financial Action Task Force (FATF) is an intergovernmental body that sets standards for anti-money laundering (AML) and counter-terrorist financing (CFT). FATF recommendations are not legally binding themselves, but FATF member countries (which include all major economies) are expected to implement them through national legislation. Non-compliance can result in a country being placed on the FATF "gray list" or "black list," which has significant economic consequences.
The Travel Rule is FATF Recommendation 16, which originally applied to traditional wire transfers. It requires financial institutions to include sender and recipient information in payment messages — so that when money is transferred from Bank A to Bank B, Bank B knows who sent the money and who is receiving it. The rule is called the "Travel Rule" because the information "travels" with the transaction.
In 2019, the FATF extended the Travel Rule to virtual asset service providers (VASPs). Under the extended rule, when a VASP sends cryptocurrency to another VASP on behalf of a customer, the sending VASP must transmit the following information to the receiving VASP:
- The sender's name
- The sender's account number (wallet address)
- The sender's physical address, date of birth, or national identity number
- The recipient's name
- The recipient's account number (wallet address)
The threshold for the Travel Rule varies by jurisdiction. The FATF recommended a threshold of USD/EUR 1,000, but some jurisdictions (including the EU under MiCA) have set a lower threshold. Below the threshold, VASPs are not required to transmit sender/recipient information, but they must still monitor transactions for suspicious activity.
How the Travel Rule works in practice
In practice, the Travel Rule works like this: when a user wants to withdraw cryptocurrency from Exchange A to a wallet address on Exchange B, Exchange A checks whether the destination address belongs to another VASP. If it does, and the transaction amount exceeds the threshold, Exchange A contacts Exchange B to request the recipient's information. Exchange B verifies that the recipient has an account and provides the recipient's name. Exchange A then transmits the sender's information to Exchange B along with the cryptocurrency transaction.
The implementation of this process is technically complex because cryptocurrency transactions are push-based — the sender initiates the transaction without the recipient's involvement. To share sender/recipient information, VASPs use specialized messaging protocols (such as the Travel Rule Messaging Protocol, TRP, or the InterVASP Messaging Standard, IVMS101) that operate alongside the blockchain transaction.
There are several Travel Rule messaging solutions in operation, including:
- Sygna Bridge: A Travel Rule messaging protocol used by major Asian exchanges.
- TRP (Travel Rule Protocol): An open-source protocol developed by a consortium of Swiss and European VASPs.
- Sumsub Travel Rule: A compliance solution that integrates Travel Rule messaging with KYC workflows.
- Notabene: A Travel Rule compliance platform that connects VASPs across different messaging protocols.
- Chainalysis Travel Rule: A solution that integrates Travel Rule messaging with blockchain analytics.
The fragmentation of solutions is a challenge — if Exchange A uses Sygna Bridge and Exchange B uses TRP, they cannot directly communicate. Interoperability solutions (like Notabene) act as bridges between different protocols, but the ecosystem is still maturing.
Which jurisdictions have implemented the Travel Rule?
As of 2024, the following jurisdictions have implemented the Travel Rule for cryptocurrency:
- United States: FinCEN's rule, effective since 2020, requires VASPs to collect and transmit sender/recipient information for transactions above $3,000. US exchanges (Coinbase, Kraken, Gemini) have been compliant since the rule's effective date.
- European Union: Under the MiCA regulation, fully effective in 2024, all CASPs (Crypto-Asset Service Providers) in the EU must comply with the Travel Rule for transactions above EUR 1,000. The EU's implementation is stricter than the FATF recommendation, with a lower threshold and broader scope.
- United Kingdom: The UK's FCA has required Travel Rule compliance since September 2023. UK-registered crypto businesses must comply with the rule for transactions above GBP 1,000.
- Switzerland: FINMA has required Travel Rule compliance since 2019. Swiss VASPs must comply for all transactions (no threshold — Switzerland implemented the rule without a minimum amount).
- Singapore: MAS has required Travel Rule compliance since January 2022. Singapore-licensed VASPs must comply for transactions above SGD 1,500.
- Japan: The JFSA implemented the Travel Rule in 2022, requiring Japanese exchanges to comply for transactions above JPY 1,000,000.
- South Korea: Implemented in 2022, with a threshold of KRW 1,000,000.
- Hong Kong: Under the SFC's crypto licensing regime, VASPs must comply with the Travel Rule.
- UAE: VARA and the CBUAE have implemented Travel Rule requirements for licensed VASPs.
Notably, several major jurisdictions have not fully implemented the Travel Rule, including Russia, China (which has banned crypto trading), Turkey, and several African and South American countries. This creates a gap: transactions from compliant exchanges to non-compliant exchanges do not carry sender/recipient information, making tracing harder. Scammers exploit this gap by routing funds through non-compliant exchanges to strip Travel Rule data from the transaction.
How the Travel Rule helps crypto fraud tracing
The Travel Rule is a game-changer for crypto fraud tracing in several ways:
1. Automatic identification of counterparties
Before the Travel Rule, when stolen cryptocurrency was sent from the scammer's wallet to an exchange, the exchange knew only the deposit address — not who sent it. The exchange had no way to verify that the sender was the legitimate owner of the funds. With the Travel Rule, the exchange receives the sender's information from the sending VASP. If the sender's name does not match the scammer's known identity, the exchange can flag the transaction.
In practice, this means that when a scammer tries to cash out stolen crypto on a compliant exchange, the exchange receives the sender information from the sending exchange (if any). If the funds came from a non-compliant exchange or a self-custody wallet, the receiving exchange may require the user to provide the sender's information before processing the deposit. This creates a paper trail that can be used in fraud investigations.
2. Faster identity disclosure
Before the Travel Rule, identifying the account holder at an exchange required a Norwich Pharmacal order (in common law jurisdictions) or a court order (in civil law jurisdictions). This took days or weeks. With the Travel Rule, the exchange may already have the sender's information on file — provided by the sending VASP. Law enforcement can request this information directly from the exchange, bypassing the need for a court order in many cases.
In a recent case, a victim lost $120,000 in USDC to an investment fraud scam. The funds were traced to a Binance deposit address. Because the sending exchange (a US-based exchange) had complied with the Travel Rule, Binance already had the sender's information on file. When law enforcement contacted Binance, the information was provided within 24 hours — no Norwich Pharmacal order needed. The scammer was identified, and a freeze was placed on the remaining funds.
3. Deterrent effect on scammers
The Travel Rule creates a deterrent effect. Scammers know that if they use compliant exchanges, their identity will be transmitted with the transaction. This makes compliant exchanges less attractive for cashing out stolen funds. Scammers are forced to use non-compliant exchanges (which are often smaller, less liquid, and more likely to be shut down) or self-custody wallets (which cannot be frozen but also cannot easily convert crypto to fiat).
The deterrent effect is not absolute — determined scammers can still route funds through non-compliant jurisdictions. But it raises the cost and complexity of cashing out stolen crypto, which reduces the overall attractiveness of crypto fraud.
4. Better evidence for legal proceedings
The Travel Rule creates a documented paper trail that can be used as evidence in legal proceedings. When the sender's information is transmitted with the transaction, it creates a record that the sender initiated the transaction — which can be used to prove the chain of custody for the stolen funds. This is particularly valuable in cases where the scammer claims they received the funds legitimately — the Travel Rule data shows exactly who sent the funds and when.
Limitations of the Travel Rule for fraud recovery
While the Travel Rule is a significant improvement, it has important limitations:
- Self-custody wallets: The Travel Rule only applies to transactions between VASPs. If a user sends cryptocurrency from a self-custody wallet to an exchange, the Travel Rule does not require the exchange to collect sender information (though some jurisdictions, like Switzerland, require exchanges to collect this information regardless). Scammers who use self-custody wallets are not affected by the Travel Rule.
- Non-compliant jurisdictions: Exchanges in jurisdictions that have not implemented the Travel Rule do not transmit sender/recipient information. Scammers can route funds through these exchanges to strip Travel Rule data from the transaction. Once the funds are in a non-compliant jurisdiction, they cannot be traced through Travel Rule data.
- False identities: The Travel Rule relies on the KYC information collected by the sending VASP. If the scammer registered their exchange account using a stolen identity (passport, proof of address), the Travel Rule data will contain the false identity, not the scammer's real identity. This is a particular problem with North Korean hacking groups and organized crime syndicates who use professional identity thieves to open exchange accounts.
- Unhosted wallets: When funds are sent from an exchange to an unhosted (self-custody) wallet, the Travel Rule does not apply. The exchange knows that the funds were sent to a specific address, but it does not know who controls that address. The trail ends at the unhosted wallet.
- DeFi protocols: Transactions involving DeFi protocols (deposits, withdrawals, trades on DEXs) are not covered by the Travel Rule. A scammer can move funds through DeFi protocols without any Travel Rule data being generated.
These limitations mean that the Travel Rule is not a silver bullet for crypto fraud tracing. It is a valuable tool that makes certain types of cashing out harder and more traceable, but determined scammers can still circumvent it. The Travel Rule should be seen as one tool in the broader toolkit of crypto fraud recovery — alongside blockchain forensics, Norwich Pharmacal orders, and law enforcement coordination.
The Travel Rule and the "sunrise period" problem
One of the challenges of the Travel Rule is the "sunrise period" — the time between when the FATF issues a recommendation and when individual jurisdictions implement it. During this period, some jurisdictions have the Travel Rule in force and others do not. This creates an asymmetry that scammers exploit.
For example, when the EU implemented the Travel Rule under MiCA in 2024, EU-based exchanges were required to comply immediately. But many of their counterpart exchanges in other jurisdictions (particularly in Asia and Africa) had not yet implemented the rule. When an EU exchange tried to send Travel Rule data to a non-compliant exchange, the receiving exchange could not process the data — it did not have the infrastructure. The result was that EU exchanges had to either suspend transactions to non-compliant exchanges or process them without Travel Rule data, creating a compliance gap.
The FATF is working to address the sunrise period by pressuring member countries to implement the Travel Rule on a common timeline. But the reality is that implementation timelines vary, and the sunrise period will continue for several more years as smaller and developing countries catch up.
Practical implications for crypto users
If you use cryptocurrency, the Travel Rule affects you in several ways:
- Additional verification: When you send crypto from one exchange to another, the sending exchange may ask you to verify the recipient's identity (name, account number). This is not the exchange being difficult — it is complying with the Travel Rule.
- Transaction delays: Travel Rule compliance can add delays to transactions, particularly if the receiving exchange does not respond immediately to the sender's information request. Transactions that used to take minutes can now take hours.
- Privacy implications: The Travel Rule means that your name and wallet address are transmitted to the receiving exchange. This creates a record of your transactions that can be accessed by law enforcement and, in some cases, by civil litigants. If you value privacy, this is a significant development.
- Self-custody wallet deposits: When you deposit crypto from a self-custody wallet to an exchange, the exchange may ask you to prove the source of the funds. This is particularly common for large deposits, as the exchange needs to comply with AML requirements.
For fraud victims, the Travel Rule is generally positive. It increases the chances that the scammer's identity will be recorded when they attempt to cash out, and it speeds up the process of obtaining identity information through law enforcement. If you have been scammed and the funds were sent between compliant exchanges, the Travel Rule data may already be available to law enforcement — ask your counsel to check.
The future of the Travel Rule
The FATF is continuing to refine the Travel Rule. Key developments to watch include:
- Lower thresholds: The EU has set the threshold at EUR 1,000, well below the FATF recommendation of USD 1,000. Other jurisdictions may follow suit, lowering the threshold to capture more transactions.
- Unhosted wallet regulation: The EU is considering extending Travel Rule requirements to transactions involving unhosted wallets. If implemented, exchanges would be required to collect sender information for deposits from unhosted wallets and to verify the recipient's identity for withdrawals to unhosted wallets. This would significantly close the self-custody loophole.
- DeFi regulation: The FATF has signaled that it may extend Travel Rule requirements to certain DeFi protocols, particularly those that have identifiable operators. If this happens, DeFi transactions would carry sender/recipient data, making them traceable in the same way as exchange transactions.
- Global interoperability: The Travel Rule messaging ecosystem is fragmented, with multiple protocols that are not fully interoperable. The FATF and industry groups are working on standards to ensure that all VASPs can communicate regardless of the protocol they use.
The direction is clear: the Travel Rule will expand to cover more transactions, more types of crypto services, and more jurisdictions. The era of anonymous crypto transactions is ending. For fraud victims, this is good news — the tools for identifying and pursuing scammers are getting better every year.
Case study: how Travel Rule data accelerated recovery
In early 2025, a client lost $215,000 in USDT to a fake investment platform. The funds were sent from the client's wallet to the scammer's wallet, then quickly moved to a Kraken deposit address. Because Kraken is a US-regulated exchange and the sending exchange (Coinbase, where the scammer had an account) complied with the Travel Rule, Kraken already had the sender's information on file when the deposit arrived.
We filed a freeze request with Kraken simultaneously with a law enforcement report to the FBI's IC3. Because the Travel Rule data was already available, Kraken was able to confirm the sender's identity (name, date of birth, and KYC documents from Coinbase) within 48 hours. The FBI requested the information from Kraken through a formal legal request, and Kraken provided it within 24 hours of receiving the FBI's request. No Norwich Pharmacal order was needed — the Travel Rule had already created the paper trail.
The scammer was identified as a resident of Florida who had opened the Coinbase account using his real identity (a mistake that more sophisticated scammers would not make, but common among lower-level operators). The FBI opened a criminal investigation, and Kraken froze the $215,000 pending the investigation. The client recovered 100% of the stolen funds within three weeks of the scam — a timeline that would have been impossible without the Travel Rule data.
This case illustrates the Travel Rule's impact on recovery timelines. Before the Travel Rule, the same case would have required: (1) blockchain forensics to trace the funds to Kraken, (2) a Norwich Pharmacal order to compel Kraken to disclose the account holder's identity (7-14 days), and (3) a law enforcement request for the full account records (additional days). With the Travel Rule, step 2 was eliminated — the sender's identity was already on file. The total recovery time was reduced from an estimated 4-6 weeks to 3 weeks.
The bottom line
The FATF Travel Rule is fundamentally changing the landscape of crypto fraud tracing. By requiring VASPs to share sender and recipient information for transactions above a threshold, the rule creates a paper trail that can be used to identify scammers and support legal recovery. The rule is not a silver bullet — self-custody wallets, non-compliant jurisdictions, and DeFi protocols remain gaps — but it is a significant step forward. If you have been scammed and the funds were sent between compliant exchanges, the Travel Rule data may be the key to identifying the scammer.
If you are pursuing crypto fraud recovery, contact us. We can determine whether Travel Rule data is available for your case and coordinate with law enforcement to obtain it quickly. The Travel Rule is transforming the landscape, but the legal tools to access and use the data still require expertise and timing.