Travel rule and self-hosted wallets
Latest change ·
First version, covering India, Singapore and Hong Kong.
Sources: fiuindia.gov.in, mas.gov.sg, sfc.hk
What crypto firms in India, Singapore and Hong Kong must send with a transfer, and how transfers to and from self-hosted wallets are treated
As of 30 September 2026, all three markets apply the travel rule to crypto transfers between service providers: the sending firm must collect and pass on who is sending and who is receiving. They differ on thresholds and on self-hosted wallets, meaning wallets whose keys the user holds rather than a service provider. Hong Kong has the most detailed rule for self-hosted wallets, requiring firms to collect the counterparty’s details and check that the wallet is reliable. Singapore treats such transfers as higher risk and expects enhanced measures. India’s January 2026 guidelines apply the travel rule between service providers and do not say how it applies to self-hosted wallets.
Side by side
| India | Singapore | Hong Kong | |
|---|---|---|---|
| Instrument | FIU-IND AML guidelines for virtual digital asset service providers (January 2026) | MAS Notice PSN02 and its Guidelines | Anti-Money Laundering and Counter-Terrorist Financing Ordinance, Sch. 2 s.13A; SFC AML Guideline, chapter 12 |
| Threshold | None stated | Reduced information at or below S$1,500; full information above | Reduced information below HK$8,000; full information at or above |
| Timing | Before or with the transfer; no after-the-fact submission | Immediately | Immediately and securely |
| Self-hosted wallets | Not addressed | Outside the travel rule; higher risk, with enhanced measures such as proof of wallet control | Collect originator and recipient details, assess the wallet’s reliability, verify ownership, and limit where appropriate |
| Applies to | Registered VDA service providers, including offshore ones serving Indian users | Licensed digital payment token service providers | SFC-licensed platforms and intermediaries |
By market
India
FIU-IND’s guidelines of 8 January 2026 require the originating service provider to obtain, hold and send the originator’s PAN, identity document number, name, wallet address, physical address and date of birth, and the beneficiary’s name and wallet address (para 5.3.5). The information must travel before or with the transfer, and after-the-fact submission is not allowed (para 5.3.4). Providers should use a technical solution, with self-declaration only where that is not feasible (para 5.3.3). The section addresses transfers between service providers and is silent on self-hosted wallets.
The obligations apply to any provider serving Indian users, whether or not it has an Indian presence, and FIU-IND enforces registration against offshore platforms.
Singapore
MAS Notice PSN02, last revised on 30 June 2025, applies the travel rule to digital payment token transfers in paragraph 13. For transfers at or below S$1,500 the ordering institution sends the originator’s and beneficiary’s names and account numbers or transaction references (para 13.4). Above S$1,500 it must also verify the originator’s identity and add an address, an identification number, or a date and place of birth (para 13.6).
The Guidelines to PSN02 say paragraph 13 does not apply to transfers to or from persons that are not financial institutions, which covers self-hosted wallets (para 13-7). Firms should treat those transfers as higher risk and apply enhanced measures, which may include requiring a customer to prove control of their own wallet by sending a specified amount, verifying third-party counterparties, and enhanced monitoring. MAS’s stablecoin consultation lists restrictions on unhosted wallets among measures other jurisdictions have considered, and says it will assess whether more is needed (para 3.23).
Hong Kong
Section 13A of Schedule 2 to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance sets the travel rule, and chapter 12 of the SFC’s AML Guideline explains it. For transfers of HK$8,000 or more, the ordering institution must obtain and send the originator’s name, account number, address or identity number, and the recipient’s name and account number (para 12.11.5). Smaller transfers carry less (para 12.11.6).
For self-hosted wallets, the firm must obtain the originator and recipient details from its customer before sending or receiving (para 12.14.2). It must also assess the risk, conduct enhanced monitoring, accept transfers only to or from wallets it has assessed as reliable, and impose transaction limits where appropriate (para 12.14.3). Ownership can be verified by a micropayment test or a message-signing test (para 12.10.6).
For Ethereum
Self-hosted wallets are how most people use Ethereum directly, so these rules decide how easily value moves between regulated firms and on-chain applications. Hong Kong’s approach adds friction but keeps the route open: a customer can withdraw to their own wallet once they prove ownership, for example by signing a message. Singapore takes a similar route through guidance. India’s rule is silent, which leaves the treatment to each provider. The next pressure point is stablecoins: Singapore is considering whether MAS-regulated stablecoins need wallet restrictions, and freeze functions in stablecoin contracts already let issuers act on flagged addresses.
Open questions
- How FIU-IND expects Indian providers to handle withdrawals to self-hosted wallets.
- Whether Singapore adopts holder identification or wallet restrictions for MAS-regulated stablecoins.
- How the FATF’s revised Recommendation 16, published in June 2025 with compliance expected from 2030, changes what crypto firms must carry.
Next milestones
- 16 October 2026: comments close on Singapore’s stablecoin amendments, including the unhosted wallet question.
- Ongoing: FIU-IND inspections under the January 2026 guidelines.
- 2030: compliance date for the revised FATF Recommendation 16.