Skip to main content
Category: Virtual Assets and Technology

Unhosted Wallet

Also known as: Self-hosted wallet, Non-custodial wallet, Self-custody wallet
Simply put

An unhosted wallet is a type of cryptocurrency wallet where the user holds their own private keys directly, rather than having a third party such as a regulated exchange or platform store them on the user's behalf. Because there is no intermediary custodying the keys, the user retains direct control over the assets. This is different from a hosted (custodial) wallet, where a service provider controls the keys.

Formal definition

An unhosted wallet (also termed self-hosted, non-custodial, or self-custody wallet) is a digital wallet for crypto assets in which the private keys are generated and controlled directly by the user, with no third-party intermediary custodying those keys. It sits outside regulated exchanges or platforms, which distinguishes it from hosted wallets provided by an obliged entity such as a virtual asset service provider (VASP). This distinction is operationally significant for Travel Rule compliance, since transfers to or from unhosted wallets do not involve a counterparty VASP to exchange required originator and beneficiary information; the treatment of such transfers varies by jurisdiction and should be confirmed against the applicable regime. The presence of an unhosted wallet is not, by itself, indicative of illicit activity, and per Chainalysis blockchain analysis such wallets are not inherently risky and do not inherently inhibit law enforcement.

Why it matters

Unhosted wallets sit at the center of a significant compliance challenge for the virtual asset sector: the application of the Travel Rule. Under the FATF standards, and as implemented in various forms across jurisdictions, obliged entities such as VASPs are generally required to collect and transmit originator and beneficiary information for qualifying transfers. When a transfer moves to or from an unhosted wallet, there is no counterparty VASP on the other side to receive or exchange that information. This structural feature means the standard information-sharing mechanism does not function as it does in VASP-to-VASP transfers, and the treatment of such transactions varies materially by jurisdiction and should be confirmed against the applicable regime.

The distinction between hosted (custodial) and unhosted (non-custodial) wallets is also operationally important because it determines who controls the private keys and therefore who, if anyone, is an obliged entity with customer due diligence responsibilities. In a hosted arrangement, a regulated intermediary custodies keys and can be expected to conduct CDD; with an unhosted wallet, the user holds the keys directly and there is no intermediary in that role. Compliance teams need to understand this difference to correctly scope their obligations and to design proportionate, risk-based controls around transactions involving self-custodied counterparties.

Importantly, the presence of an unhosted wallet is not, by itself, indicative of illicit activity. According to Chainalysis blockchain analysis, unhosted wallets are not inherently risky and do not inherently inhibit law enforcement. Firms should therefore avoid treating self-custody as a red flag in isolation and instead assess it within a broader risk-based framework, recognizing that self-custody is a legitimate and common feature of the crypto ecosystem.

Who it's relevant to

VASP compliance officers
Compliance teams at virtual asset service providers must determine how their firm treats transfers to and from unhosted wallets, including what information to collect and how Travel Rule obligations apply where there is no counterparty VASP. Because treatment varies by jurisdiction, these officers should confirm requirements against the applicable regime rather than assume a single global standard.
AML and financial crime analysts
Analysts assessing crypto transactions need to distinguish hosted from unhosted counterparties when evaluating risk. They should treat the presence of an unhosted wallet as one factor within a broader risk-based assessment rather than as a standalone indicator of illicit activity, consistent with blockchain analysis findings that such wallets are not inherently risky.
Regulators and policymakers
Bodies responsible for implementing FATF standards and setting national rules for virtual assets must grapple with how the Travel Rule and CDD obligations apply where no intermediary custodies keys. This is an area where regimes diverge, making the scoping of obligations around self-custody a live policy question.
Blockchain analytics and RegTech providers
Vendors offering wallet verification, screening, and Travel Rule solutions build tools to help obliged entities identify unhosted counterparties and gather information where required. Their offerings support firms in managing, though not eliminating, the risks associated with transfers involving self-custodied wallets.

Inside Unhosted Wallet

Self-Custody of Private Keys
An unhosted wallet (also called a self-hosted, non-custodial, or self-custody wallet) is a virtual asset wallet where the user controls their own private keys directly, rather than relying on a third-party custodian such as a virtual asset service provider (VASP). This distinguishes it from hosted or custodial wallets, where an exchange or other intermediary holds the keys on the user's behalf.
Absence of an Intermediary Obliged Entity
Because there is typically no VASP or financial institution controlling the wallet, an unhosted wallet generally does not have an associated obliged entity performing customer due diligence (CDD) on the wallet holder. This is a key reason such wallets attract regulatory attention, as they can fall outside the standard AML/CFT gatekeeping performed by intermediaries.
Counterparty in VASP Transactions
Unhosted wallets are frequently discussed in the context of transfers between a VASP and a wallet not controlled by another VASP. FATF guidance and various jurisdictions address how obliged entities should treat transactions involving unhosted wallet counterparties, though the specific requirements vary by regime and should be confirmed against applicable regulation.
Travel Rule Considerations
The FATF Recommendations set standards (not binding law) relating to the collection and transmission of originator and beneficiary information for virtual asset transfers, commonly known as the travel rule. Application of these requirements to transactions involving unhosted wallets differs across jurisdictions, and there is no single universal rule; the treatment depends on how each regime has transposed the standard.
Terminology Variation
The term is used somewhat interchangeably with 'non-custodial wallet,' 'self-hosted wallet,' and 'self-custody wallet.' Terminology may differ by jurisdiction and by regulatory instrument, so practitioners should note the specific definition used in the applicable framework.

Common questions

Answers to the questions practitioners most commonly ask about Unhosted Wallet.

Does an unhosted wallet mean transactions are anonymous and untraceable?
No. "Unhosted" (also called self-hosted or non-custodial) refers to a wallet where the user controls the private keys directly, rather than a third-party custodian holding them. It does not mean transactions are anonymous. On most public blockchains, transactions are recorded on a transparent ledger and are generally pseudonymous rather than anonymous, meaning addresses and transaction flows can often be analyzed. The distinguishing feature of an unhosted wallet is the absence of an intermediary custodian, not the absence of a transaction record.
Are transfers to or from unhosted wallets prohibited under AML rules?
Generally, no. In most regimes, transacting with unhosted wallets is not prohibited as such. Instead, obliged entities such as virtual asset service providers may be subject to enhanced or additional measures when dealing with unhosted wallet counterparties, and the applicable expectations vary by jurisdiction. Requirements should be confirmed against the relevant regulation, as approaches differ between the FATF standards, the EU framework, and national regimes. The presence of an unhosted wallet counterparty is a risk factor to assess, not automatic evidence of wrongdoing.
When a VASP sends or receives a transfer involving an unhosted wallet, what counterparty information is typically expected?
Where the so-called travel rule applies, obliged entities are generally expected to obtain and, where relevant, verify certain originator and beneficiary information for virtual asset transfers. For transfers involving unhosted wallets, expectations differ by jurisdiction and may include collecting information about the customer and, in some cases, taking reasonable measures to identify the unhosted wallet counterparty. Because there is no counterparty institution to exchange information with, the specific obligations, thresholds, and verification steps should be confirmed against the applicable regime rather than assumed to be uniform.
How can an obliged entity verify that a customer controls an unhosted wallet they claim to own?
Firms commonly use techniques intended to provide reasonable assurance of control, such as requesting a cryptographic signature from the wallet or a small verification transaction from the claimed address. These are operational measures to help establish a link between the customer and the wallet; they are used to manage and mitigate risk rather than to guarantee ownership or the legitimacy of underlying funds. The acceptability and required rigor of particular methods may depend on the applicable regulation and the entity's risk-based approach.
How should unhosted wallet exposure be factored into a risk-based approach?
Transactions involving unhosted wallets are typically treated as one factor within a broader risk assessment, considered alongside customer profile, geographic exposure, transaction patterns, and blockchain analytics findings. Depending on the assessed risk, a firm may apply additional due diligence or enhanced measures. Such controls are designed to detect, deter, and manage risk, not to eliminate it, and no single measure removes financial crime risk on its own. The weight given to unhosted wallet exposure should align with the firm's methodology and applicable regulatory expectations.
Does identifying an unhosted wallet counterparty or generating an alert establish that money laundering has occurred?
No. An alert, a match, or the identification of an unhosted wallet counterparty is an operational trigger for further review, not a determination of wrongdoing. Whether suspicious activity should be reported is assessed under the applicable reporting framework, and any resulting filing reflects suspicion rather than proof. The compliance function's role is to detect and assess potential risk indicators, while establishing that a criminal offense occurred is a matter for competent authorities under the relevant criminal law.

Common misconceptions

An unhosted wallet is inherently illegal or a definitive indicator of money laundering or terrorist financing.
Self-custody of virtual assets is a legitimate feature of the technology and is used by many lawful holders. The presence of an unhosted wallet counterparty is, at most, one risk-relevant factor to be assessed within a risk-based approach; it is not proof of wrongdoing, and it does not by itself establish that a transaction is criminal.
The same travel rule and due diligence obligations apply to unhosted wallets everywhere in the world.
Requirements diverge significantly across regimes. The FATF Recommendations are standards rather than binding law, and jurisdictions have transposed obligations relating to unhosted wallet transactions differently. Exact obligations, thresholds, and information requirements should be confirmed against the applicable regulation.
An unhosted wallet is completely anonymous and outside the reach of any AML controls.
While an unhosted wallet typically lacks an associated obliged entity performing CDD, transactions between such wallets and a VASP generally bring the VASP's own controls into play. Obliged entities may apply measures to identify, assess, and manage the risk associated with unhosted wallet counterparties, though these measures help detect and mitigate risk rather than guarantee prevention.

Best practices

Apply a risk-based approach when assessing transactions involving unhosted wallet counterparties, treating the unhosted status as one factor among several rather than as conclusive evidence of illicit activity.
Confirm the specific obligations that apply in your jurisdiction, including how travel rule requirements have been transposed for unhosted wallet transactions, and do not assume a single global standard governs your program.
Document the rationale for the treatment of unhosted wallet transactions within your CDD and, where warranted, enhanced due diligence (EDD) procedures, distinguishing clearly between the wallet's self-custody nature and any actual indicators of risk.
Where an unhosted wallet interacts with a VASP, ensure the obliged entity's own controls and originator/beneficiary information procedures are applied consistently, recognizing that the counterparty wallet may not have an intermediary performing CDD.
Use consistent, defined terminology internally to avoid conflating unhosted (non-custodial) wallets with hosted (custodial) wallets, and align internal definitions with the terms used in the applicable regulatory instrument.
Avoid treating any single control or screening result as a guarantee against financial crime risk, and ensure that alerts or matches related to unhosted wallet activity are investigated before any conclusion of wrongdoing is drawn.