The Travel Rule: what has to travel with your crypto in the EU

When a European platform asks who owns the address you are withdrawing to, it is not being nosy. The EU extended its transfer-of-funds rules to crypto, so the platform has a legal duty to attach identifying information to your transfer. And unlike the bank version of the same rule, there is no amount small enough to escape it.
An old bank rule, moved onto a new rail
Banks have carried sender and recipient details alongside wire transfers for years. The purpose is plain enough: make the payment chain readable afterwards, so an investigator is not staring at an amount with no names attached to either end. In the international standard-setting world this is called the travel rule, because the information has to travel with the money.
Crypto sat outside it for a long time, for an obvious technical reason — a blockchain transaction carries an address, an amount and nothing else. No name, no country, no account holder. The EU closed that gap by writing crypto-asset transfers into the same instrument that governs bank wires, which is why the questions you now get at the withdrawal screen feel so much like a bank form. Legally, that is exactly what they are.
Most people meet the rule without ever hearing its name. You go to move coins to a hardware wallet or to a friend, and instead of a confirm button you get a page asking who owns the destination, what they are called, and where they live. It looks like the platform being difficult. It is the platform doing something it has no discretion about.
What the regulation actually says
The instrument is Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets, and amending Directive (EU) 2015/849. It was published in the Official Journal at L 150 on 9 June 2023, and EUR-Lex still lists it as in force.

Two parts of it explain most of what you will actually run into.
Article 14(1) puts the duty on the crypto-asset service provider, meaning the licensed platform rather than you. When it sends a transfer on your behalf, it has to ensure that specified information about the originator and the beneficiary goes with it.
Recital 30 is the part that surprises people. It says transfers of crypto-assets “should be subject to the same requirements regardless of their amount and of whether they are domestic or cross-border transfers”. No de minimis floor, no small-transfer exemption. Compare that with the conventional half of the same regulation, where certain checks on ordinary transfers of funds still hang off a EUR 1 000 threshold in Articles 5 and 6. Crypto got the stricter treatment deliberately, on the reasoning that splitting a transfer into small pieces is trivial when there is no bank in the middle.
Timing: the regulation ties its own start to the application date of the MiCA regulation next door, which is why the withdrawal forms and the new licensing regime turned up in people's accounts at roughly the same moment and got mentally filed as one change.
What you see when you hit withdraw
In practice the rule shows up as a short form between you and the confirm button. The wording differs by platform, the substance does not:
- Is the destination yours, or somebody else's? This is the first fork and it changes everything that follows.
- If it belongs to someone else — their full legal name, sometimes their country of residence or address.
- If it sits at another provider — which one, usually chosen from a dropdown rather than typed.
- If it is a wallet you hold the keys to — a declaration to that effect, and often a proof step afterwards.
The dropdown is what confuses people most. It exists because the receiving provider has to be identifiable, so the two firms can exchange the required data through whichever travel-rule messaging network they have both joined. If your destination platform is not on the list, you may get a free-text box, an extra warning, or a refusal. That is a routing problem between two firms, not a verdict on the platform you are sending to.
Sending to a provider outside the EU adds a wrinkle. The obligation still applies to the European firm sending on your behalf, but the receiving firm may sit under a different regime, or under none, and may not be able to accept the data. What that looks like in the app is an extra declaration, a longer review, or a destination that simply is not offered. Nothing you can argue your way past at the withdrawal screen.
Worth being blunt about one thing: these answers are on the record. Declaring an address as your own when it belongs to somebody else is a false statement made to a regulated firm, and it is the kind of thing that surfaces later, during a review, when you would much rather it did not.
Self-hosted wallets get an extra step
Withdrawing to a wallet you hold the keys for — hardware wallet, mobile wallet, anything with no company behind it — is normal and permitted. The regulation contemplates it directly. What it triggers is a proof step: the provider may ask you to show you actually control the address before it will send anything there. There is a line in the text here that explains why this does not happen every time. For a transfer to or from a self-hosted address, the provider is in principle not required to verify who is behind that address — but once the amount exceeds EUR 1 000, it is expected to check whether the address is actually owned or controlled by its own customer. So the size of the withdrawal, not the fact that it is self-hosted, is usually what decides whether you get asked to prove anything.
How that proof works varies by platform. The usual versions:
- Signing a message with the destination wallet's private key and pasting the signature back into the form.
- A small transaction sent from that wallet to the platform, demonstrating control from the other direction.
- A screenshot of the wallet showing the address, sometimes alongside something dated.
The signed message is the cleanest of the three and the one hardware wallets handle natively. Once an address has been verified, most providers let you whitelist it so the ceremony is not repeated every time. Do that on a quiet afternoon rather than mid-withdrawal — whitelists usually carry their own cooling-off delay, which is a good security feature that reads as an obstacle at exactly the wrong moment. The security setup guide covers whitelisting alongside the other controls worth switching on early.
Why a small typo freezes real money
On-chain, a transfer is final. The travel-rule information is not on-chain — it moves separately, provider to provider. So the two halves can disagree, and when they do, the coins have already arrived while the paperwork has not.
From the receiving side that looks like a credit sitting in a held or pending state, a support ticket asking you to confirm who sent it, and a wait measured by that provider's queue rather than by block time. Nothing is cancellable at that point. There is no undo.
The mismatches that cause it are mundane:
- A name spelled differently from the ID on the receiving account — a middle name on one side and not the other, a dropped diacritic, a married name against a maiden name.
- An address declared as self-hosted when it is in fact a deposit address at a provider, or the reverse.
- A transfer to another person's account. Many providers refuse third-party credits outright, and “my friend will pass it on” is not something the compliance system has a field for.
Missing or inconsistent travel-rule information is something receiving providers are expected to have a policy for, and that policy can mean holding the funds, asking you questions, or sending them back. Which of the three you get is their call, not yours. If your own account is already in a review loop, expect the slow version — verification that keeps failing tends to bleed into every other queue.
What to have ready before you withdraw
The name exactly as the receiving account holds it
Not what you call the person. The legal name their account was verified under, spelled character for character. If it is your own account somewhere else, that is the name on your own ID, including the parts you usually leave off.
The address, copied from the receiving deposit screen
Copy and paste, never retype. Check the network as well as the address — a correct address on the wrong network is a separate disaster with an identical symptom.
Proof of control, if the destination is self-hosted
Have the wallet in front of you and unlocked before you start, so a request to sign a message does not send you hunting for a device mid-flow.
A test amount first
Send something small, wait for it to land and clear any hold, then send the rest. Two network fees is a cheap price for discovering the name field was wrong while only a token amount is exposed.
The other direction has its own set of checks, run by banks rather than platforms, and they fail differently: returned euro transfers covers that half, and the euro deposit walkthrough covers getting money in without tripping them.