Unhosted Wallet
An unhosted wallet is a type of cryptocurrency wallet where the user holds their own private keys directly, rather than having a third party such as a regulated exchange or platform store them on the user's behalf. Because there is no intermediary custodying the keys, the user retains direct control over the assets. This is different from a hosted (custodial) wallet, where a service provider controls the keys.
An unhosted wallet (also termed self-hosted, non-custodial, or self-custody wallet) is a digital wallet for crypto assets in which the private keys are generated and controlled directly by the user, with no third-party intermediary custodying those keys. It sits outside regulated exchanges or platforms, which distinguishes it from hosted wallets provided by an obliged entity such as a virtual asset service provider (VASP). This distinction is operationally significant for Travel Rule compliance, since transfers to or from unhosted wallets do not involve a counterparty VASP to exchange required originator and beneficiary information; the treatment of such transfers varies by jurisdiction and should be confirmed against the applicable regime. The presence of an unhosted wallet is not, by itself, indicative of illicit activity, and per Chainalysis blockchain analysis such wallets are not inherently risky and do not inherently inhibit law enforcement.
Why it matters
Unhosted wallets sit at the center of a significant compliance challenge for the virtual asset sector: the application of the Travel Rule. Under the FATF standards, and as implemented in various forms across jurisdictions, obliged entities such as VASPs are generally required to collect and transmit originator and beneficiary information for qualifying transfers. When a transfer moves to or from an unhosted wallet, there is no counterparty VASP on the other side to receive or exchange that information. This structural feature means the standard information-sharing mechanism does not function as it does in VASP-to-VASP transfers, and the treatment of such transactions varies materially by jurisdiction and should be confirmed against the applicable regime.
The distinction between hosted (custodial) and unhosted (non-custodial) wallets is also operationally important because it determines who controls the private keys and therefore who, if anyone, is an obliged entity with customer due diligence responsibilities. In a hosted arrangement, a regulated intermediary custodies keys and can be expected to conduct CDD; with an unhosted wallet, the user holds the keys directly and there is no intermediary in that role. Compliance teams need to understand this difference to correctly scope their obligations and to design proportionate, risk-based controls around transactions involving self-custodied counterparties.
Importantly, the presence of an unhosted wallet is not, by itself, indicative of illicit activity. According to Chainalysis blockchain analysis, unhosted wallets are not inherently risky and do not inherently inhibit law enforcement. Firms should therefore avoid treating self-custody as a red flag in isolation and instead assess it within a broader risk-based framework, recognizing that self-custody is a legitimate and common feature of the crypto ecosystem.
Who it's relevant to
Inside Unhosted Wallet
Common questions
Answers to the questions practitioners most commonly ask about Unhosted Wallet.