If you send crypto through a regulated exchange or wallet provider above a set dollar amount, that provider is required to attach your name and your recipient’s name — and sometimes more — to the transfer, and pass it to the receiving institution. The amount that triggers this differs sharply by jurisdiction: it is $1,000 under the global FATF baseline, $3,000 in the United States, and zero for crypto transfers inside the European Union.
The Financial Action Task Force, an intergovernmental standard-setter, extended its existing wire-transfer rule — Recommendation 16 — to virtual assets in June 2019, according to Chainalysis, Elliptic and Merkle Science. The mechanism is the same one banks have used for decades: when a customer moves value through a regulated institution, that institution has to identify the sender, obtain the recipient’s details from the counterparty institution, screen both against sanctions lists, and keep a record — all off-chain, alongside the transfer itself, according to Hacken’s summary of the FATF framework. Hacken’s reference report lays out the obligations as split roles: the sending institution identifies and retains data on the originator and passes it on; the receiving institution verifies that data, screens for sanctions, and keeps its own record.
For crypto specifically, this is harder than it sounds. A bank wire moves between two known institutions using SWIFT messaging. A crypto transfer moves to a wallet address, and the sending exchange first has to work out whether that address belongs to another regulated exchange or to a private individual’s self-hosted wallet — a step Elliptic calls a critical identification challenge, since the two paths carry different obligations.
The figures below are as reported in each source’s own description of current law, not projections. Where only one outlet in this set covers a jurisdiction, that is noted.
| Jurisdiction | Threshold | Legal basis | Source |
|---|---|---|---|
| FATF baseline | USD/EUR 1,000 | Recommendation 16 | Hacken, Chainalysis, Merkle Science, Elliptic |
| United States | $3,000 | Bank Secrecy Act, 31 CFR 1010.410(f), enforced by FinCEN | Hacken, Chainalysis, Elliptic, AMLBot, Mayer Brown |
| European Union | €0 for crypto-asset transfers | Transfer of Funds Regulation, Regulation 2023/1113, effective 30 December 2024 | Chainalysis, Elliptic |
| United Kingdom | £1,000 for fiat; effectively €0-equivalent for crypto transfers | Money Laundering Regulations 2017 as amended | Chainalysis only — single-sourced in this set |
| Singapore | SGD 1,500 for digital payment tokens | MAS Payment Services Act / PSN02 | Chainalysis only — single-sourced in this set |
| Switzerland | CHF 1,000 | FINMA guidance on virtual assets | Chainalysis only — single-sourced in this set |
Below the FATF threshold, the obligation does not disappear entirely — it just gets lighter. Hacken’s breakdown of the FATF fields shows that a transfer under $1,000/€1,000 still requires the sender’s and recipient’s names plus a wallet address or transaction identifier; verifying that data is only required if a money-laundering or terrorist-financing risk is flagged. Above the threshold, Elliptic’s field list adds the sender’s physical address, date of birth, and a legal-entity or business identifier where relevant, plus the recipient’s account or wallet reference and country and town.
Merkle Science, in an April 2025 explainer, describes how criminals try to stay under these thresholds by splitting a transfer into pieces — a tactic known as structuring or smurfing. Its illustrative example: someone wanting to move $18,000 worth of crypto instead sends it as 20 separate $900 transfers from different wallets over several days. Each individual transfer sits under the $1,000 FATF threshold and the $3,000 US threshold, so none of them individually forces a VASP to attach full originator and beneficiary data. Merkle Science argues this is exactly why compliance teams need behavior-based monitoring rather than a threshold check alone — the pattern across transactions, not any single one, is the signal.
Readers frequently assume the Travel Rule threshold is $10,000, because that number is well known from a separate US requirement — the Currency Transaction Report, filed when cash transactions exceed $10,000 in a day. Chainalysis states plainly that this is incorrect on two counts: the actual Travel Rule threshold is $1,000 under the FATF baseline and $3,000 in the US, and it applies to domestic transfers in many jurisdictions, not only cross-border wires. Under the EU’s zero-threshold rule, Chainalysis notes, even a $500 crypto transfer to a European exchange can be fully in scope. The CTR and the Travel Rule are separate Bank Secrecy Act obligations that can each apply, both apply, or neither apply, depending on the transaction — conflating them, Chainalysis warns, creates compliance gaps in both directions.
The second common misreading concerns self-hosted wallets. Neither Chainalysis nor Hacken treats a transfer to a private, non-custodial wallet as automatically in or out of scope. Chainalysis notes that FATF guidance leaves significant discretion to individual regulators, so some jurisdictions require enhanced due diligence on above-threshold transfers to self-hosted wallets while others impose no data-sharing obligation where no counterparty VASP is involved. Hacken similarly notes that businesses moving funds to unhosted wallets must collect the required information themselves, but are not required to transmit it to the individual’s wallet directly.
Two figures that circulate in coverage of the Travel Rule describe proposals, not current law. FinCEN proposed in 2020 to lower the US cross-border crypto threshold to $250 and to add reporting for transactions above $10,000; both Hacken and Elliptic confirm this proposal remains unfinalized. And on 18 June 2025, FATF revised Recommendation 16 again — adding new beneficiary-institution obligations and aligning the rule with ISO 20022 messaging — but Mayer Brown’s August 2025 analysis is explicit that these 2025 Revisions generally take effect at the end of 2030 and still require adoption by individual national regulators. The rule in force for most VASPs today is still the 2019 version, built on the $1,000/€1,000 FATF baseline and, in the US, the $3,000 threshold set out in 31 CFR 1010.410(f).
This page cannot tell a reader whether a specific transfer to a self-hosted wallet will be treated as in-scope by their exchange, because that judgment sits with national regulators and individual VASPs’ own risk-based policies, and the sources here describe divergent approaches rather than a single rule.
It does not give a current, verified global compliance rate. The only figure available in this evidence — Merkle Science’s claim that 75% of jurisdictions were partially or non-compliant with Travel Rule implementation as of FATF’s July 2024 review — is now over a year old, is Merkle Science’s own characterization of that review rather than a quote from FATF itself, and has not been checked here against FATF’s subsequent reviews.
It cannot resolve a factual disagreement in the source set: the Institute for Financial Integrity attributes the EU’s zero-threshold crypto rule to the Markets in Crypto-Assets Regulation (MiCA), while Chainalysis and Elliptic both attribute it to the separate Transfer of Funds Regulation (2023/1113). This page follows Chainalysis and Elliptic because two independent sources agree, but the discrepancy itself is worth knowing if a reader encounters MiCA cited as the legal basis elsewhere.
The Singapore, Switzerland and UK thresholds in the table above rely on a single source (Chainalysis) and have not been cross-checked against a second independent source in this evidence set.
Finally, this page describes thresholds and rules as reported in the sources gathered; it is not a substitute for checking a specific VASP’s own compliance policy or a jurisdiction’s current regulatory text, both of which can change independently of the international standard.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect