TL;DR — Since December 30, 2024, EU crypto exchanges must verify you actually control a self-hosted wallet before processing any transfer to or from it worth more than EUR 1,000.
Self-custody doesn't get you a free pass from EU financial surveillance. It just moves the compliance check from account opening to the moment you actually move money above EUR 1,000. The rule is Article 14(5) of Regulation (EU) 2023/1113, the EU's crypto Travel Rule, in force since December 30, 2024 alongside MiCA's full application. Most explainers cover the exchange-to-exchange side of the Travel Rule and skip the part that actually touches a self-custody wallet.
The EU's Travel Rule and Self-Hosted Wallets
The EU Travel Rule, formally the Transfer of Funds Regulation, requires every EU-licensed crypto-asset service provider to attach sender and recipient information to a transfer, and it sets that requirement at a EUR 0 threshold for transfers between two CASPs. Self-hosted wallets get different treatment. Recital 45 of the regulation flags them as a higher-risk category, because a CASP can't always confirm who holds the private key on the other end.
That's the gap Article 14(5) closes. It doesn't ban self-hosted wallets or route them through a different rulebook. It adds one specific check, and that check only switches on above a set amount.
What Counts as a Self-Hosted Wallet Transfer Under the EU Travel Rule?
Any transfer that moves crypto-assets between a CASP account and an address the CASP doesn't custody counts, in both directions. Send funds from your Kraken or Bitstamp account to your own MetaMask address, and the exchange sits on the originator's end. Withdraw from that same self-hosted wallet back into a CASP account later, and the rule applies again, this time to the beneficiary's side.
Direction doesn't matter. Amount does.
The EUR 1,000 Threshold and What Crosses It
Below EUR 1,000, Article 14(5) doesn't require anything extra. Above it, the originator's CASP - if you're sending out - or the beneficiary's CASP - if you're receiving in - has to take "adequate measures" to assess whether you actually own or control that self-hosted address.
The regulation doesn't hand CASPs a single approved method for that check. In practice most run one of three: a signed message from the wallet, a small "satoshi test" deposit the exchange asks you to send back from the same address, or a wallet-linking flow through a connector like WalletConnect. Fail the check, or ignore the request, and the transfer sits until you clear it.
Under Article 14(5) of Regulation (EU) 2023/1113, a self-hosted wallet transfer over EUR 1,000 triggers a mandatory ownership check that a smaller transfer skips entirely.
How Do Exchanges Verify You Control the Wallet?
Most EU CASPs default to the signature challenge, because it's the cheapest to automate: the exchange generates a message, you sign it with the wallet's private key through your own wallet app, and the signature proves control without moving any funds. A handful still prefer the micro-deposit method - sending a tiny amount you then have to withdraw and confirm from that same address.
Neither check tells the exchange anything about what that wallet has actually done on-chain. That's a separate screen, and it's the one most people skip until a deposit gets frozen for an unrelated reason - a mixer hop, a sanctioned counterparty, exposure to a hacked contract.
What Self-Custody Users Should Do Before Sending
Ownership verification and risk screening are two different gates, and clearing the first tells you nothing about the second. A wallet can pass a signature challenge in seconds and still carry exposure that gets the transfer flagged by the exchange's own AML system minutes later.
You can look up a wallet's own transaction history by hand on Etherscan before you send anything near that EUR 1,000 line, but reading a raw transaction list won't tell you if an address five hops back touched a sanctioned entity. Screen the wallet with Plastron first, and you get sanctions, mixer, and stolen-funds exposure across Ethereum and six other EVM chains in one pass. Plastron's own screening corpus tracks 3,901 labeled wallets and the full 780-entry OFAC SDN list, and the check is free.
Verify ownership. Then verify risk. Not the other way around.
FAQ
Does the EUR 1,000 threshold apply per transaction or cumulatively?
Article 14(5) is written around a transfer of an amount exceeding EUR 1,000, not a rolling total. Most CASPs apply it transaction by transaction unless their own internal risk policy layers a structuring check on top.
Does the threshold apply to transfers between two self-hosted wallets?
No. Article 14(5) only triggers when one side of the transfer is a CASP account. A transfer directly from one self-hosted wallet to another never touches a regulated intermediary, so no CASP has an obligation to verify anything.
What happens if I fail the wallet-ownership check?
Policies vary by exchange. Some hold the transfer for manual review, others reject it outright and ask you to retry with a different verification method, such as switching from a micro-deposit to a signed message.
Is the EUR 1,000 threshold the same across every EU country?
Yes. Regulation (EU) 2023/1113 is a directly applicable regulation, not a directive, so the EUR 1,000 figure is uniform across every EU member state with no local transposition variance.
Does MiCA licensing change any of this?
No. MiCA governs who can operate as a licensed CASP in the EU. The Travel Rule and its self-hosted wallet threshold come from the separate Transfer of Funds Regulation, and both became fully applicable on the same date, December 30, 2024.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.