kyc-creep-how-crypto-becomes-what-it-swore-to-replace.md ~/netts/blog/posts 3,587 words · 18 min read
Insights Jul 14 2026 Netts.io 18 min read 108 views

KYC Creep: How Crypto Becomes What It Swore to Replace

KYC creep shows how crypto’s promise of permissionless finance turns into passport scans, wallet screening, and bank-like surveillance.

KYC Creep: How Crypto Becomes What It Swore to Replace

When Bitcoin came, it was not a new bank UI. It did not promise a better onboarding flow, a friendly chatbot, a debit card with cashback. It promised permissionless settlement - money moving not through banks, processors, cards, or state-sanctioned DTC (Digital Transaction Clearing) systems, but through a decentralized cryptographic medium.

Crypto’s founding mythos centered on freedom: partly true, partly aspirational. Bitcoin was not fully anonymous; it provided only pseudo-anonymity. It had a public ledger - a feature that in practice often acted as a privacy differential. Nevertheless, the distance between a person initiating a transaction on a node and their passport scan in an exchange KYC (Know Your Customer) procedure was wide enough to provide a sense of independence. One was not bound to a bank account, a card, a processor application, a capital control authority, or a government depositary. Crypto, in its initial phase, was seen as a way to circumvent an entire layer of permissioned financial infrastructure.

In the early days, sovereignty rhetoric was everywhere - not your keys, not your coins; be your own bank; code is law; trusted third parties are security vulnerabilities. All that had a certain romanticism to it - a feeling of something fundamentally wrong with the system (state-sponsored surveillance capitalism) and a corrective mechanism.

Then crypto networks began to accumulate value - substantial, liquid, attention-grabbing value. Exchanges turned from small inconvenient over-the-counter dealers into financial infrastructure necessities. Stablecoins became settlement rails. Traditional finance complexes entered the space - venture funds, asset managers, regulators, and retail speculators. The latter often had little interest in disintermediating anything. All they wanted was an app, a token, a dollar proxy with a convenient UI/UX, some reliability, and a trusted custodian. Not your keys, not your coins was a nice phrase, but an unbanked Nigerian miner probably had more interest in someone else’s keys securing his life savings.


That is how crypto networks got exposed to the long pincer of KYC creep. The permissionless settlement layer did not stay permissionless for long - it began to accumulate friction at its edges, slowly transforming into a fully KYC-compliant financial instrument.

Crypto’s first privacy compromises rarely came as shocking deplatforming decrees. They came in the form of convenient improvements - email verification, phone binding, selfie ID, address proof, source of funds, beneficiary forms, wallet screening - all normal transaction frictions in any financial relationship, from a bank account opening to a crypto exchange user verification. The user, perhaps, did not even mind - he had nothing to hide, after all. He only wanted to buy some coins, speculate on the pump, move his stablecoins from one wallet to another without being blocked or delayed. He became used to KYC creep - the gradual accumulation of personally identifying transaction data, which, in turn, became valuable to bad actors.

The same “I have nothing to hide” delusion fuels KYC creep in crypto: the user convinces himself and the system that he is simply another digital bank customer, one who pays fees but enjoys greater yields on his stablecoin deposits. Yet even as the crypto custodian grants him greater financial autonomy, it quietly ties his account to an ever-growing list of personal identifiers and transaction histories, all of which may come in handy when the Feds investigate ransomware payments, money laundering schemes, or state terrorism financing.

When Law Found the Ledger

The first KYC creep pressure points did not emerge from thin air. They responded to the early bitcoin adopters’ keen desire to disintermediate as many layers of the financial infrastructure as possible. Inadvertently, BTC and crypto networks became multi-use settlement platforms - for remittances, dark web purchases, gambling websites, ransomware payments, offshore tax evasion, and everyday transactions. The bad reputation was partially deserved - Silk Road 2.0, the dark web marketplace shut down in 2013, was, in part, paid for in bitcoins.

Nevertheless, it only took law enforcement a few years to realize that bitcoins were, indeed, cash. Virtual currency user bases were growing and diversifying - and that meant risks to national security and financial integrity. In 2013, the FinCEN guidance formalized a few restrictions for virtual currency wallet admins and exchanges. While users were not categorized as MSB (Money Services Businesses), their administrators had to deal with increased KYC and anti-money laundering (AML) compliance obligations. In other words, the law acknowledged the possibility that bitcoin wallets could be used for money laundering and illicit financing of terrorism, just as traditional currency could.

The guidance did not kill the crypto industry; in fact, it accelerated its growth and institutionalization. It only re-engineered the separation between the permissionless blockchain and the permissioned crypto exchanges that catered to real users. The latter were in many ways similar to traditional financial institutions: they had to undergo banking secrecy checks, have appropriate AML/countering financing of terrorism (CFT) programs, register as MSBs with FinCEN, and so on.


The same dynamic was at work in New York, where crypto businesses were required to get a BitLicense in 2015. The requirements were seen as overly onerous by many in the industry, and some companies (e.g., Bitstamp) left the state. In practice, however, crypto businesses got used to the idea of functioning as regulated financial entities. The industry survived and was transformed: businesses learned to handle increased know-your-customer and transaction surveillance obligations.

The most prominent example of privacy creep pressure came in the form of the IRS Coinbase summons in 2016. The Internal Revenue Service (IRS) requested Coinbase to disclose information on all U.S. residents who had engaged in any bitcoin transactions in the past years. Coinbase resisted the request, and the initial summons was narrowed in scope in 2017, when the court ordered Coinbase to provide information on the subset of taxpayers that had used its service.

The Coinbase case illustrates one essential aspect of privacy creep - that it often comes in the guise of a third party subpoena and not a direct government order. In the long run, the case allowed the government to establish a critical link between pseudonymous wallets and real-world persons. From this point on, the anonymizing potential of the blockchain was significantly reduced, as the exchange had personal information on its users.

In effect, the Coinbase case marked the beginning of the end for privacy in crypto. The IRS summons acted as a shock to the system, after which crypto networks became significantly more transparent to government agencies. One could say that the decentralization, transparency, and anonymity of crypto have been significantly compromised due to a single exchange being ordered by a court to disclose information on all its users.

Law enforcers are also realizing that public blockchains are permanent evidence vaults. A bank can take your cash, but a blockchain will store forever that you ever had it. If a wallet belonged to an anonymous user, it is now potentially possible to identify it by analyzing the addresses it interacted with on-chain. Even better, if a cryptocurrency exchange has already tied one of these addresses to a person, it will likely be able to identify all other addresses linked to that person. Once again, the privacy of crypto transactions turns out to be contextual and temporary.


The IRS summons and the subsequent Coinbase disclosure represent just one lever of the larger KYC creep apparatus. As virtual currencies gained wider acceptance and popularity, their adoption became inextricably linked with the traditional financial system. This is how the KYC requirements became applied to crypto networks - first in the form of transaction tracing and wallet screening, and subsequently as direct data inquiries from government agencies.

Reasonable people may object to the details, arguing that crypto’s privacy compromises are justified by the need to combat fraud and money laundering. After all, crypto networks are frequently used to move illicit funds: ransomware payments, drug trafficking proceeds, terrorism financing, and more. It would be irresponsible for financial infrastructures, including crypto exchanges, to ignore these risks. As such, it is reasonable to expect KYC requirements to be applied to crypto transactions as a way to separate illegitimate funds from those that are not.

The AML industry has long dealt with similar objections to traditional bank secrecy. As it turned out, the more instruments are available to trace illicit funds, the more loopholes appear for moving them. The entire AML framework is a response to the perceived inadequacy of the traditional financial system in countering money laundering, terrorist financing, and other forms of value diversion. By analogy, one can imagine the crypto industry developing increasingly sophisticated KYC technologies to combat privacy-focused bad actors. In that light, the current KYC creep in crypto compliance is only the beginning.

Compliance Machine Gets a Memory

The next stage in the eternal struggle between privacy and regulation went by the name of KYT: Know Your Transaction. The industry shifted from KYC (Know Your Customer) protocols on account opening to ongoing transaction monitoring as AML (Anti-Money Laundering) officers sought to identify and flag illicit funds. The focus of transaction monitoring shifted from whether a given wallet belonged to a terrorist to whether it sent or received payments from scam addresses, dark web markets, ransomware domains, mixing services, and other dubious on-chain entities.

To a large extent, this development was prompted by the FATF (Financial Action Task Force) recommendations on virtual assets, which were finalized in 2019. In response to the rising prominence of illicit crypto use cases, the FATF issued updated AML/CFT (Countering the Financing of Terrorism) guidelines for virtual asset service providers (VASP). Most notably, the Travel Rule now requires VASP to obtain and share originator and beneficiary information on cross-border transactions of value above a certain threshold.

In effect, the crypto industry bids a fond farewell to privacy, as the burden of proof now falls on the user to demonstrate that a given wallet is not linked to any illicit activity. At the same time, several jurisdictions are poised to impose even stricter oversight. For instance, the EU’s Transfer of Funds Regulation, which became directly applicable in Member States in 2023, targets any crypto-asset transfers. In tandem with the Travel Rule, EU’s MiCA (Markets in Crypto-Assets) regulation, which enters into force in 2024, will impose licensing and supervisory obligations on crypto-asset service providers. In effect, to operate freely inside the EU economic space, a crypto business will have to function like a bank.



The latest KYC creep is epitomized by the KYT-driven intensified transaction monitoring and illicit fund tracing efforts. At the first sign of suspicious activity, crypto exchanges employ AML compliance software to scan through transactions and assign risk scores to addresses involved in dark web spending, sanctions evasion, and other prohibited activities. As a result, the withdrawal of funds can be temporarily suspended, a deposit rejected, or the account balance placed on hold while the compliance team investigates.

In effect, a crypto user now expects the same level of privacy as a conventional bank customer, and for the same reason: the crypto exchange compliance infrastructure serves to keep illicit funds at bay. At the same time, the user who opted to engage in permissionless transactions with full anonymity may be in for a surprise as several aspects of his financial behavior now fall under increased scrutiny. In this respect, the KYT-driven due diligence mirrors the traditional finance paradigm, where financial institutions employ transaction monitoring solutions to flag suspicious fund movements. In the end, the crypto exchange infrastructure serves the same purpose: to reduce the exposure to money laundering risk.

Users of crypto exchanges, at the lowest levels of the protocol stack, face the same privacy risks as their counterparts in traditional finance. While the system is by no means simple, it boils down to the same questions asked of the traditional bank customer: who are you and what do you intend to do with my money?

Tornado Cash Incident and Privacy Coin Blacklisting

In 2022, Tornado Cash – a popular privacy mixer – was subjected to OFAC (Office of Foreign Assets Control) sanctions that placed significant restrictions on its further development and growth. In doing so, the U.S. Treasury effectively put many privacy-focused crypto initiatives at risk, as the U.S.-based jurisdiction is by far the most influential in the crypto industry. The Tornado Cash sanctions triggered a heated debate not only among privacy advocates but also the general public, as the very idea of on-chain financial privacy is anything but popular with mainstream audiences.

In fact, the very existence of Tornado Cash and similar privacy-focused protocols is in direct contradiction with the U.S. government’s stance on crypto regulation. The litigation finally concluded in 2025 when the Treasury decided to delist Tornado Cash, with many in the privacy community interpreting the event as OFAC’s tacit approval of privacy-friendly smart contract protocols.


In reality, the Tornado Cash incident serves as yet another illustration of the erosion of privacy. In this case, the users of privacy-focused wallets were the ones to bear the brunt of the crackdown. Even more importantly, the Tornado Cash sanctions and subsequent delisting of privacy coin deposits by crypto exchanges serve as a stark reminder to the crypto industry that anonymity is a privilege extended by regulation, not a right guaranteed by design. In this respect, the Tornado Cash incident and the ongoing privacy coin delistings are two sides of the same coin. As privacy-friendly wallets and coinjoin protocols become increasingly difficult to use, even the most privacy-conscious individuals are subjected to heightened scrutiny by crypto exchanges.


Moreover, the Tornado Cash incident serves as a sobering reminder to crypto businesses that the use cases for privacy coins are incompatible with the existing KYC/AML regime. In response to the Tornado Cash sanctions, several crypto exchanges blacklisted privacy coins, rendering their deposits and withdrawals difficult or even impossible. Similar delistings and restrictions applied to privacy-focused wallets and other anonymity-enhancing tools.

Binance Settlement and Privacy Coin Delistings

Binance’s multibillion-dollar settlement with the U.S. government over AML and sanctions violations serves as a cautionary tale for the entire crypto industry. Notably, Binance’s founder has pleaded guilty to facilitating the illicit financial activity, while the company itself faces prohibitive fines and enhanced AML scrutiny in the years to come. In effect, the rampant expansion of the crypto exchange, which relied heavily on light KYC/AML protocols, comes at a significant cost. In the same vein, the history of other crypto networks is replete with KYC-related controversies that arose due to the firms’ willingness to scale at all costs.

In the end, the face scan became normal. The proof of address became normal. The asking why I received the funds became normal. The risk score review became normal. Everything that once would have struck the early adopter as unduly KYC-intrusive is now a routine part of a crypto exchange user experience. Users who once balked at a KYC request from a crypto company are now much less likely to object, having accepted KYC as a condition of participation in the system.

Ideology That Lost to Convenience

There should have been a revolt, at least among the most ideological users. There was none, really. Some users opted out - they shifted to self-custody, decentralized exchanges, privacy coins, coinjoin protocols, peer-to-peer trading, non-KYC venues - but they were the minority. The majority simply complied, uploading their documents to whatever wallet the exchange asked them to and continuing on their way. In large part, it was because they never wanted the features that crypto disintermediation promised.

To reiterate, it was not the state surveillance but the lack of yield that convinced people to migrate to stablecoins. It was not the control of politics that motivated people to use crypto; it was the ability to speculate. It was the possibility for the individual miner to turn a few thousand dollars into a multi-million-dollar exit. It was the promise of permissionless banking for the unbanked, not the anarcho-capitalist fantasies of truly decentralization. The users cared about the system insofar as it served their interests. As such, they were willing to compromise on its libertarian ideals in favor of convenience, security, and better yields.

This is not to diminish their choices - if anything, it is to recognize them as human. People do not want to spend their life trying to evade state surveillance; they want their salary in stablecoins to actually be stable. They want to pay rent, not launder money. They want the freelancer’s USD deposit to be processed, not stolen. They want the family home investment secured, not defrauded. So when the choice comes between a self-custody wallet and a KYC-friendly exchange, the latter has few difficulties winning over the average user. And the user keeps using that exchange - not knowing what else is in store for him. The KYC is only the doorway: the exchange has his personal information, and it can use it to make him pay more.

This is where the naiveté of “I have nothing to hide” meets the practicalities of the long tail of personal information. Anonymity is good, but it has its costs. A user who only wants to buy, sell, or hold stablecoins can reasonably believe that his transaction should not be subjected to the same KYC scrutiny as an Oligarch’s crypto transfer.


That user would be right insofar as nothing is stopping him from choosing another exchange: one without KYC, KYT, or AML obligations. In reality, however, he often has little choice in the matter: he values stability and convenience, and the other options do not provide either. As such, he complies with the KYC checks, believing himself to be merely another bank customer. He does not consider the fact that the bank customer’s equivalent to a KYC scan is far less intrusive.

“I have nothing to hide” is a reasonable argument in the vacuum of choice, but it stops being one once the alternatives are removed. The user does not know that his convenience has a price. He has little interest in paying that price, and he has even less interest in understanding it.

False positives are an issue, of course - a user gets frozen because his stablecoins passed through a mixer, a gambling website, a hacked exchange, a sanctioned address, or an OFAC-listed wallet. Sometimes it is the user’s fault, sometimes it is not. In either case, the coin is now a liability, not an asset: its on-chain history is a threat to the user’s financial existence. He becomes aware, if only in a distant way, of the costs that convenience extracts. Nevertheless, the outliers remain outliers: their problems are inconvenient but manageable within the larger system.

What Freedom Means After Mass Adoption

There is one fundamentally sad question at the heart of this piece. What good is an anti-establishment, anti-conformity, freedom-focused currency that quietly transforms into the same old, same old with a blockchain layer on top? Where is the freedom when all the doors require identity, all the big exchanges perform AML checks, stablecoins can freeze accounts, every wallet has a risk score, and every privacy tool is blacklisted as illegitimate?

It should not matter. The adoption of crypto for everyone is great if the adoption is by choice - but there are plenty of compromises to be had as long as the default privacy is not compromised by design. Crypto is much better than legacy finance at almost every single point of value capture, but users that want to live in a permissioned crypto economy are implicitly accepting worse terms than they would receive elsewhere. That is normal - we are all using crypto for different reasons - but when it comes to the fundamentals of financial sovereignty, nobody is likely to ask for what they want if they are not aware of what they already have.

Buying bitcoin on a KYC exchange is not financial freedom. Settling USDT on a custodied exchange is not permissionless digital cash. Passing an AML check on the way to deposit stablecoins for DeFi yield farming makes the user not special, not enlightened, not one of those people that understood crypto from the beginning - it makes them a person that got permission to participate, and probably an excellent student in the permissioned system.


The same line of thinking applies to the state of USDT and stablecoins in general. As much as users around the world want to move money from one jurisdiction to another without risk of confiscation or surveillance, most of them are much more concerned about how much it costs to move the money. Netts USDT Transfer Calculator is a great tool that estimates USDT fees before sending, letting you compare burning TRX with renting Energy at different gateways and figuring out what the cheapest option is. It helps you understand how the TRON USDT transfer works, so that you can save money on burning TRX - it tells you that having a friend that can receive 0 USDT may actually cost you more; it helps you identify the cheapest USDT fees, plan ahead; estimate TRC20 USDT transfer fees without guessing at the cost; it shows which USDT transfers are low-cost, predictable and safe ways to get exposure to dollars, while explaining that TRON transfers burn Energy and Bandwidth, and that renting Energy may well be much cheaper than the default. TRON Bandwidth and Energy can be rented out or purchased, which allows a wider adoption of the TRON network as bandwidth costs are significantly reduced, so that anyone can make inexpensive transactions for small amounts.