What Is KYC in Crypto? Verification Tiers, the Travel Rule and What "No KYC" Means
KYC is the identity check anti-money-laundering law requires before a business handles your money; on an exchange it sits between sign-up and the first withdrawal. What is checked and why, the verification tiers of the eight exchanges we rate side by side, the travel rule that now follows a withdrawal to another exchange or your own wallet, what the "no-KYC" exchangers on our monitor actually do instead, and the database your passport ends up in.
What is KYC in crypto? It is the identity check a business has to run on a customer before it handles their money, and on a crypto exchange it is the step between opening an account and the first withdrawal: a photo of a government ID, a selfie, sometimes a utility bill. The letters stand for "know your customer". The check exists because of anti-money-laundering law, not because the exchange is curious, and the same law is the reason an exchange later asks whose wallet you are withdrawing to, why a deposit can sit in review for days, and why the "no-KYC" exchangers on our monitor still occasionally ask for a passport.
This page explains what is actually being checked and by whom, puts the verification tiers of the eight exchanges in our rating side by side, walks through the travel rule that now follows a withdrawal from one company to another, shows what "no KYC" means in practice on the exchanger market, and finishes with the part of KYC nobody mentions at sign-up: the database your passport ends up in.
KYC, due diligence and AML are three different things
People use the three words as one, and the confusion costs them, because a person can pass every identity check and still have a deposit frozen.
KYC is the narrow part: who you are. Identify the customer, verify the identity against a reliable document, record it. In regulatory texts the fuller term is customer due diligence, which adds two things a selfie cannot do: understanding what the customer is going to use the account for, and watching the account afterwards to see whether it matches. A business that finds a higher risk, a politically exposed person, a large unexplained transfer, an unusual country, applies enhanced due diligence, which is where the "source of funds" and "source of wealth" questions come from.
AML, anti-money-laundering, is the whole framework those checks live inside, and most of it is not about you at all. It is about the money: screening the addresses coins came from, scoring the history behind them, reporting patterns, holding transfers that look wrong. That screening runs on every deposit regardless of how thoroughly you were verified, which is why a fully verified account can still be frozen over coins bought in good faith from a seller three hops away from a flagged address. KYC is the door; AML is the building.
Why every licensed exchange asks: the chain of rules
No exchange invented this. In October 2018 the Financial Action Task Force, the body whose recommendations national anti-money-laundering laws are written to match, amended its Recommendation 15 to cover virtual assets and the businesses that handle them, and in June 2019 adopted the interpretive note that tells countries how. Two lines in that note shape everything below: a crypto business must run customer due diligence on one-off transactions above 1,000 US dollars or euros, and must pass sender and receiver details along with a transfer the way banks do. Countries then wrote that into law, each in its own shape.
- European Union. A crypto exchange needs authorisation as a crypto-asset service provider under MiCA, which applied to service providers from 30 December 2024, with a transition for firms already operating that ended on 1 July 2026 at the latest. Authorisation comes with the full anti-money-laundering rulebook, and a separate regulation, the recast Transfer of Funds Regulation, has applied to crypto transfers since the same December date.
- United States. Since 2013 the Treasury's FinCEN has classed anyone who exchanges convertible virtual currency for money as a money transmitter under the Bank Secrecy Act, which means registration, a customer identification programme, and the same record-keeping rules as a wire service.
- United Kingdom. The FCA has been the anti-money-laundering supervisor of cryptoasset firms since 10 January 2020, and the travel rule has applied to them since 1 September 2023.
The practical reading is simple. An exchange that lets you trade and withdraw with no identity check in any of these places is either not licensed there or is serving you from an entity that is not. That is not automatically a reason to avoid it, but it is what you are choosing, and it is exactly the thing the regulation component of our crypto exchange rating scores, next to security and the exchange's record when things went wrong.
Verification tiers on the eight exchanges we rate
"KYC tiers" is the phrase people search once they have hit the first wall, and the tiers are where the exchanges genuinely differ, so we read the help centre of every exchange in our rating on 27 September 2026 and put the answers side by side. "Not published" means the exchange shows the number only inside a logged-in account, which is more common than the guides that quote precise figures suggest.
| Exchange | Before verification | First tier | Higher tier | Stated time | Travel-rule prompt |
|---|---|---|---|---|---|
| Binance | No deposits or trades for a new account | "Verified": government ID, front and back, plus a liveness check; the withdrawal limit is shown only in the app | "Verified Plus": proof of address or of income, for higher fiat limits | "Usually reviewed within 48 hours" | Questionnaires and a "Satoshi test" for self-hosted wallets where the rule applies; no threshold stated |
| OKX | Nothing until verified | One flow: name, date of birth, ID number, residential address, government ID and a selfie | The 24-hour withdrawal cap follows the fee tier, not a KYC level | Not stated | EEA: over €1,000 to or from a private wallet, ownership check by Satoshi test or WalletConnect |
| Kraken | Nothing until verified | "Verified": government ID and proof of address; cash under 100,000 USD a month, crypto withdrawals up to 500,000 USD a day | "Higher limits": same documents, manual review; cash above 100,000 USD a month, crypto from 10,000,000 USD a day | "Typically less than 30 minutes" | EU and UK: over 1,000 EUR, self-certification or a Satoshi test |
| Bybit | Standard level mandatory for all products | "Standard": a physical government ID; up to 1,000,000 USDT a day, no monthly cap | "Advanced": proof of address dated within three months; 2,000,000 USDT a day; "Pro" adds enhanced due diligence | "Approximately 15 minutes", up to 48 hours | Not stated on its KYC pages |
| Coinbase | Sending and receiving crypto needs "Level 3" | Phone number, then a photo ID | Level 3: proof of address; limits are personalised and visible only when signed in | Not stated | Not stated on the pages read |
| KuCoin | Nothing, for accounts opened since 31 August 2023 | One "Individual" tier: ID front and back plus facial verification; limits in an in-account table | No separate individual tier | Not stated | Not stated |
| WhiteBIT | Level 0 sees the interface and demo tokens only | Level 1: ID, selfie and a questionnaire; unlocks crypto deposits, withdrawals and trading | Level 3 (Level 2 on EU accounts): proof of address, beneficial-owner declaration, phone; the only level with fiat | "A few minutes to 24 hours" | EEA withdrawals carry travel-rule data since 19 May 2025, no threshold stated; new EEA sign-ups go to a separate MiCA entity |
| Backpack | Nothing until verified | One tier: name, date of birth, address, occupation and source of income, government ID and a face scan; no limits published | A separate business flow only | Automated; manual review "up to 3 days" | Not stated |
Four things stand out from the table.
The first step is the same everywhere. Not one of the eight lets a new account deposit, trade or withdraw before a government ID and a face check. The "withdraw-only" and "sell-only" states that Binance and KuCoin describe apply to accounts opened before their cut-off dates, not to anyone signing up now. If a guide tells you that some major exchange still trades unverified, it is describing 2021.
The tiers differ in what they unlock, not in whether they exist. At most exchanges the first tier is the whole crypto product and the second tier is about fiat and larger limits: Kraken asks for proof of address on day one, Bybit and WhiteBIT ask for it only when you want the higher ceiling or a bank rail, Coinbase gates crypto transfers themselves behind its address step. The document you will be asked for at the second tier is the same at all of them, a utility bill or bank statement in your name and less than three months old.
Most published limits are not published. Only Kraken and Bybit put plain numbers on a public page. Binance, OKX and KuCoin defer to a table inside the account; Coinbase says outright that limits are personalised. For a normal retail balance the published ceilings are irrelevant anyway: 500,000 USD a day at Kraken's first tier is not the constraint on anyone reading this.
The travel rule shows up as a wallet question, and the threshold is the EU's. Kraken and OKX independently state the same line, 1,000 EUR, for the point at which a withdrawal to your own wallet needs an ownership check, which is Article 14(5) of the EU regulation described below made into a product feature. WhiteBIT, which serves the EEA from a separate licensed entity, attaches travel-rule data to every EEA withdrawal regardless of size. The exchanges whose pages say nothing about it are not exempt; they simply describe it elsewhere or apply it by region.
The travel rule: why an exchange asks whose wallet it is
The second thing the FATF note asks for has taken longer to arrive and confuses more people than the identity check itself. When a bank wires money, the sender's name and account travel with the payment and the receiving bank sees them. Blockchains carry none of that: an address is a string, and the exchange sending your coins to it has no idea whether it belongs to another exchange, to you, or to someone else. The travel rule closes that gap, off-chain.
- Withdrawing to another exchange. Your exchange sends the receiving one your name and account details alongside the transfer, and the receiving exchange checks that they match its own customer before crediting the coins. In the EU this applies to every crypto transfer between service providers, with no minimum amount, since 30 December 2024; the corresponding rule for ordinary money transfers only starts at 1,000 euros. In the US the funds travel rule applies to transmittals of 3,000 dollars or more; a 2020 proposal to lower the cross-border threshold to 250 dollars is still, in the Federal Register's own record, a proposed rule. The UK has applied its version since September 2023.
- Withdrawing to your own wallet. Nobody receives your name, because there is no company on the other side, but the exchange records where the coins went. In the EU, for a transfer of more than 1,000 euros to a self-hosted address, the exchange has to take "adequate measures to assess whether that address is owned or controlled" by you, in the regulation's words. In practice that means one of a few things: signing a message from the wallet, sending a small test amount first, connecting the wallet through its browser extension, or, at the less careful venues, a screenshot and a declaration.
This is why an exchange that never asked anything about your wallet in 2024 started asking in 2025, and why the questions differ by the country your account is registered in rather than by the exchange's brand. It is also why sending exchange-to-exchange has become the smoother path for larger amounts inside the EU: the two companies exchange the paperwork between themselves, and you only wait.
What "no KYC" actually means
Type "no KYC" into a search box and most of what comes back is casinos. Underneath that is a real and useful market: exchangers and instant-swap services that take coins on one side and pay out coins, cards or e-wallet balances on the other, with no account and no identity check up front. Our exchanger monitor reads the live quotes of 37 such services as of 27 September 2026. Four of them, ChangeNOW, StealthEX, LetsExchange and SimpleSwap, were instant-swap platforms of the kind that only ever touch crypto; the rest are classic exchangers whose payout side is often a card, a bank account or an e-wallet. LetsExchange ceased operations on 1 October 2026, and its wording is kept here as a record; the four platforms' own policy pages described the same model in four different tones.
ChangeNOW puts it most plainly: "We do not require registration or continuous identity checks." StealthEX says that "KYC is not routine for every standard swap", and in the next sentence that "this does not make every transaction guaranteed no-KYC". SimpleSwap applies the no-verification flow "exclusively in scenarios identified as low risk". LetsExchange reserves the right to verify "at its sole discretion", and lists what wakes that discretion: unusual transaction patterns, transfers above the FATF threshold, and customers "requesting an exchange of untraceable cryptocurrencies", which is a policy way of saying Monero.
What all four run instead of KYC is the AML half: an automated risk score on the address your coins came from, produced by screening firms of the kind LetsExchange names (AMLBot, in its case) and ChangeNOW declines to describe ("they can't be made public"). When the score is low, the swap completes and nobody ever learns your name. When it trips a rule, three things happen in this order, and each service says so in its own terms: the coins are held ("the relevant Digital Assets will not be exchanged or released until the compliance review has been completed", in StealthEX's), you are asked for what a licensed exchange would have asked for on day one, a government ID, sometimes proof of address and a source of funds, and at SimpleSwap a live face check against the document, and if you decline or fail, the deposit goes back to the address it came from minus fees. ChangeNOW commits to doing that within 24 hours and to deducting network fees only; StealthEX deducts its service fee as well.
Two conclusions follow, and both are less comfortable than the phrase "no KYC" suggests. First, the identity check has not been abolished on these services, it has been moved from you to your coins, and it fires exactly when you would least like it to: mid-transfer, with the funds in someone else's custody. The FATF standard's own line for one-off transactions is 1,000 dollars or euros, and how far below or above that a given service actually starts asking depends on where it is registered, which is often nowhere in particular. Our Litecoin to Monero guide covers what that means for the one direction where people care most. Second, "no KYC" describes the exchanger, not the whole route. If the payout lands on a bank card, a Skrill or Wise balance or a Monobank account, the company that opened that account verified you long ago, and the exchanger is simply paying a business that already holds your documents. That is the honest version of the pitch, and it is still a good one: for a card you already hold, an exchanger is the route where the identity check already happened at your bank, rather than a second one.
The cost of KYC is the database
Every verification creates a record: your name, address, date of birth, the images of your passport and your face, and, at an exchange, the balance and transaction history attached to them. Record-keeping rules require the business to keep that for years after you leave. The risk that record carries is not theoretical, and three of the biggest names in our own crypto ratings have each had it happen.
- Coinbase, May 2025. In its filing to the US securities regulator, Coinbase listed what a group of bribed support contractors had taken: names, addresses, phone numbers and e-mails; the last four digits of social security numbers; masked bank account numbers; government-ID images; and account balances and transaction histories. No passwords, private keys or funds. It estimated the cost of remediation and customer reimbursement at 180 to 400 million dollars, and the number it gave the Maine attorney general, as reported, was 69,461 people. The attackers demanded a ransom; Coinbase refused and disclosed the incident instead, and data of that shape is exactly what a convincing phishing call is built from. Our Coinbase review treats the incident as part of the exchange's record rather than a footnote.
- Ledger, 2020. Not a KYC database, an e-commerce one, and the lesson is the same. Ledger's own statement in July 2020 counted about a million e-mail addresses and 9,500 customers' names, postal addresses and phone numbers; when the full database surfaced in December, its January 2021 update raised that to approximately 272,000 records with name, address and phone. Six years on, the phishing built on that list is still the first thing our Ledger review warns about.
- Trezor, 2026. In August 2026 Trezor disclosed that a shipping partner, ShipMonk, had exposed 11,742 customers' names, e-mails, phone numbers and shipping addresses and 1,947 more customers' names, cities and e-mails; on 4 September it added that the partner had also kept order data from 2019 to 2021 it had certified as deleted, affecting "another approximately 67,000 US customers". A home address attached to a hardware-wallet order is a more physical kind of risk than a leaked e-mail, which is why the reputation component of our Trezor review and rating weighs it.
None of the three lost a customer's coins through these leaks. All three turned a customer list into a target list, and the target list does not expire when you close the account. The practical rule is the boring one: verify on as few venues as you actually need, treat every "upload your passport" prompt from a service you do not otherwise use as a cost rather than a formality, and expect that anyone who e-mails you knowing which exchange you use and how much you hold got both facts from a breach, not from the exchange.
How long it takes, and what fails
The exchanges that state a time state a short one. Kraken says verification typically takes less than 30 minutes, Bybit approximately 15, WhiteBIT a few minutes to 24 hours, Binance up to 48, and Backpack's automated check is quick unless it flags the account for a human, in which case up to three days at busy times. Every one of those pages adds the same qualifier in the next sentence: if the application needs manual review, it takes longer. The instant-swap services quote no time at all for a triggered review; the only clock any of them commits to is ChangeNOW's 24 hours for the refund if you decline.
What fails is rarely the person and usually the picture. A glare across the photo page, a cropped corner, a document that expired last month, a name that is spelled one way on the passport and another on the utility bill, a selfie taken in a dark room. Automated checks reject those in seconds and the second attempt usually passes; a third rejection typically routes you to a human queue, which is where "up to a few days" comes from. Two things fail for reasons you cannot fix with a better photo: a country the exchange's licence does not cover, and a mismatch between the country on your documents and the one your connection appears to come from, which is why verifying over a VPN is a way to buy yourself a manual review.
Bottom line
KYC in crypto is the identity check the anti-money-laundering law behind every licence requires, and on a licensed exchange it stands between your account and your first withdrawal. The tiers differ in what they unlock, not in whether they exist. The travel rule extends the same idea to where your coins go, so the exchange will ask about your wallet and share your name with another exchange, off-chain, before larger transfers move. "No KYC" services have not escaped the framework; they run its other half, on your coins instead of you, and ask for your documents only when a score says so, which is precisely when you least want to be asked. And every check you pass leaves a copy of your passport in a database that has, at three of the biggest names in our own ratings, already leaked once. Pass it where you must, and nowhere else.
