Glossary

Unhosted Wallet

An unhosted wallet is the regulatory term for a self-custodial cryptocurrency wallet where the user alone controls the private keys without a third-party intermediary.

Key Takeaways

  • An unhosted wallet is the regulatory label for a self-custodial wallet where the user holds their own private keys, with no VASP or custodian involved. The term originated in US and international regulatory frameworks to distinguish these wallets from exchange-managed accounts.
  • Regulators impose compliance obligations on VASPs when they process transfers to or from unhosted wallets: the EU requires ownership verification for transfers exceeding EUR 1,000 under the Transfer of Funds Regulation, while the Travel Rule mandates that VASPs collect originator and beneficiary data even when the counterparty is an unhosted wallet.
  • The crypto community widely rejects the term "unhosted" in favor of "self-custodial," arguing that framing user-controlled wallets as the exception implies custodial services are the default. The terminology debate reflects a deeper tension between financial surveillance and the right to hold assets without intermediaries.

What Is an Unhosted Wallet?

An unhosted wallet is the term regulators use to describe a cryptocurrency wallet where the user directly controls the private keys, without any third-party custodian managing the funds. When you download a wallet app like Sparrow, Electrum, or BlueWallet and write down your seed phrase, you are creating what regulators call an unhosted wallet: no company holds your keys, no institution can freeze your balance, and no intermediary sits between you and the blockchain.

The term was introduced by financial regulators to create a clear distinction from "hosted wallets," which are accounts managed by regulated entities such as exchanges and custodians. The FATF (Financial Action Task Force) and bodies like the US Treasury's FinCEN began using the term in 2020 to bring clarity to compliance frameworks that were originally designed for traditional financial intermediaries. In the EU's Transfer of Funds Regulation (TFR 2023/1113), the equivalent legal term is "self-hosted address."

The distinction matters because anti-money laundering rules like the Travel Rule require regulated entities to collect and transmit identity information about transaction participants. When both sides of a transfer are VASPs, this works the same as traditional wire transfers. But when one side is an unhosted wallet, there is no counterparty institution to receive or verify that information, creating a regulatory gap that jurisdictions around the world are addressing in different ways.

How It Works

From a technical standpoint, there is no difference between an "unhosted wallet" and any other self-custodial wallet. The distinction is purely regulatory. What makes a wallet "unhosted" is who controls the private keys:

  • Hosted wallet: a VASP (exchange, custodian, or other obliged entity) holds the private keys and manages assets on behalf of the user. The user has an account, not direct key control.
  • Unhosted wallet: the user generates and stores their own private keys. No third party can authorize transactions, freeze funds, or access the wallet. This includes hot wallets (software wallets connected to the internet), cold storage devices, and multisig setups where the user controls all signing keys.

How Regulators Classify Wallet Types

The FATF defines a VASP as any entity that conducts virtual asset activities as a business on behalf of another person: exchange, transfer, safekeeping, or participation in token offerings. A person using an unhosted wallet on their own behalf is explicitly not a VASP under FATF guidance. However, the moment an unhosted wallet interacts with a VASP (depositing to an exchange or withdrawing from one), compliance obligations are triggered on the VASP side.

This classification creates three transaction categories with different regulatory treatment:

Transfer TypeRegulatory Obligations
VASP to VASPFull Travel Rule compliance: originator and beneficiary data must accompany the transfer
VASP to/from unhosted walletVASP must collect required data; verification thresholds apply (e.g., EUR 1,000 in the EU)
Unhosted to unhosted (P2P)No VASP involved, no direct compliance obligation; regulators assess risk at the country level

The Regulatory Landscape

EU Transfer of Funds Regulation (TFR)

The EU's TFR (Regulation 2023/1113) became fully applicable on December 30, 2024, and includes the most detailed unhosted wallet provisions of any jurisdiction. For transfers between CASPs (Crypto-Asset Service Providers, the EU's equivalent of VASPs), there is no minimum threshold: originator and beneficiary information must accompany every transfer regardless of amount.

For transfers exceeding EUR 1,000 involving a self-hosted address, CASPs must verify whether the unhosted wallet is owned or controlled by their customer. Acceptable verification methods, defined in EBA Guidelines (EBA/GL/2024/11), include:

  1. Cryptographic signature proving private key control (a signed message from the address)
  2. A micro-transaction from the address (sometimes called a "Satoshi test")
  3. Digital signature using qualified electronic certificates
  4. Other technical means providing equivalent assurance

Self-declaration alone is not sufficient. Germany's BaFin confirmed this position in July 2025. The EU Commission must also complete an Article 37 assessment of self-hosted wallet risks by June 30, 2026, which could lead to additional restrictions such as transaction caps or mandatory address whitelisting via delegated act.

United States

In December 2020, FinCEN proposed a rule that would have required banks and money service businesses to report unhosted wallet transactions exceeding $10,000 and maintain records for those above $3,000. The proposal, sometimes called the "midnight rule" because it was issued in the final weeks of the Trump administration, received over 65,000 public comments (the highest volume in FinCEN's history) and was widely criticized for its 15-day comment period.

The US Treasury officially withdrew the proposed rule on August 19, 2024. As of 2026, the US has no crypto-specific Travel Rule statute. Existing Bank Secrecy Act thresholds apply: $3,000 for wire transfer recordkeeping and $10,000 for Currency Transaction Reports, but these predate virtual assets and were not designed for unhosted wallet transfers.

Other Jurisdictions

JurisdictionUnhosted Wallet ThresholdStatus
United KingdomGBP 800 CDD trigger for unhosted transfersEffective June 30, 2026
SingaporeSGD 1,500 determines data-set requirementsActive (DTSP licensing since June 2025)
SwitzerlandVerification required on all transfersActive
AustraliaNo minimum thresholdEffective July 1, 2026

As of 2026, over 50 jurisdictions have enacted some form of Travel Rule legislation, and the regulatory direction is toward tighter controls on VASP interactions with unhosted wallets. The FATF published a targeted report on stablecoins and unhosted wallets in March 2026, highlighting elevated money laundering and terrorist financing risks from stablecoins transferred peer-to-peer via unhosted wallets.

The Terminology Debate

The crypto community broadly rejects the term "unhosted wallet" and prefers "self-custodial wallet" or "non-custodial wallet." The objection is not merely semantic: the framing carries significant policy implications.

"Unhosted" defines the wallet by what it lacks (a host) rather than what it provides (user control). This creates a false binary where "hosted" is implicitly the norm and "unhosted" is the deviation. Critics argue this is like calling cash a "non-bank-account" payment method: technically accurate but deliberately framed to make the intermediated version seem like the default.

The framing matters because it shapes policy. If unhosted wallets are treated as the exception, it becomes easier to justify restrictions on their use. If self-custodial wallets are understood as the original and fundamental way to hold cryptocurrency, then restrictions require stronger justification as they limit a baseline capability.

Different regulators have landed on different terms. The EU's TFR uses "self-hosted address." FinCEN used "unhosted wallet." The UK FCA uses "unhosted wallet transfer." The industry consistently prefers "self-custodial," and this term has gained ground in more recent regulatory documents.

Use Cases

Unhosted wallets are the foundation of cryptocurrency's permissionless design. Every use case for self-custody is, in regulatory terms, a use case for unhosted wallets:

  • Personal savings: holding cryptocurrency or stablecoins without counterparty risk from an exchange or custodian
  • Cross-border transfers: sending value internationally without correspondent banking intermediaries, particularly important in regions with limited banking access
  • DeFi participation: interacting with decentralized finance protocols requires an unhosted wallet since smart contracts interact directly with user-controlled addresses
  • Privacy: transacting without an intermediary logging every transfer, preserving financial privacy similar to cash transactions
  • Censorship resistance: maintaining access to funds even when political or financial conditions make custodial services unreliable or unavailable

Layer 2 protocols like Spark extend unhosted wallet capabilities by enabling fast, low-cost transfers while preserving user key control. Users can hold and transfer Bitcoin and USDB stablecoins on Spark through self-custodial wallets without relying on a centralized intermediary.

Risks and Considerations

Regulatory Compliance Burden

For businesses operating as VASPs, handling transfers involving unhosted wallets creates significant compliance overhead. Each jurisdiction has different thresholds, verification methods, and reporting requirements. A VASP operating across the EU, UK, and Singapore must implement three different sets of rules for unhosted wallet interactions. For a deeper look at compliance requirements across jurisdictions, see the VASP licensing requirements guide and the stablecoin Travel Rule compliance guide.

User Responsibility

The flip side of self-custody is full responsibility. Users of unhosted wallets bear sole accountability for securing their private keys and seed phrases. There is no password reset, no customer support, and no recourse if keys are lost or stolen. This reality means unhosted wallets require a higher level of technical competence than custodial alternatives.

Evolving Restrictions

The regulatory trajectory points toward tighter controls. The EU's Article 37 review in 2026 could result in transaction caps on unhosted wallet transfers, mandatory address whitelisting, or other restrictions imposed via delegated act without full Parliamentary approval. Some jurisdictions like Switzerland already require verification on all transfers with no minimum threshold. Users and builders in this space should monitor the FATF guidance and local regulatory developments closely.

De-risking and Access

Some VASPs respond to compliance complexity by refusing to process unhosted wallet transfers entirely, a practice known as de-risking. This can limit users' ability to move funds between self-custodial wallets and exchanges, particularly in jurisdictions with strict verification requirements. The tension between compliance costs and user access remains one of the central challenges in unhosted wallet regulation.

This glossary entry is for informational purposes only and does not constitute financial or investment advice. Always do your own research before using any protocol or technology.