SEC Commissioner Hester Peirce calls for zero-knowledge proofs to overhaul KYC compliance
U.S. Securities and Exchange Commission Commissioner Hester Peirce has criticized conventional know-your-customer requirements, warning that stockpiling personal data creates vulnerable "data haystacks" and turns the financial system into a "panopticon." Peirce advocated using zero-knowledge proofs and reusable digital credentials to verify compliance without repeatedly collecting sensitive personal information.

In a speech reported in September 2026, SEC Commissioner Hester Peirce called for a rethink of know-your-customer (KYC) and anti-money-laundering (AML) oversight, urging regulators and institutions to move away from centralized data collection. Peirce argued that the current model turns financial rails into a "panopticon" and creates massive "data haystacks" that expose crypto holders to risks including data leaks, phishing, and physical attacks. Instead, she pushed for the adoption of zero-knowledge proofs and reusable attribute-based credentials, which can verify whether a customer meets criteria such as age requirements, citizenship, or sanctions clearance without revealing their name, income, or physical address. Peirce noted that the remarks reflected her own views rather than those of the commission.[8][5][4][1][7][3]
Peirce's critique comes in the wake of high-profile data incidents at major financial platforms, including a breach at Coinbase that compromised the records of 69,461 customers and a fraudulent information request scheme that exposed customer identification documents at Revolut. The debate also intersects with pending U.S. stablecoin regulations under the GENIUS Act, whose proposed implementation rules would require permitted payment stablecoin issuers to collect identifying details and retain them for five years after an account closes. While banking regulators and FinCEN have permitted certain digital credentials within existing programs, they have left open whether final stablecoin regulations will formally accommodate verifiable-credential systems.[8][2]
Key facts
- SEC Commissioner Hester Peirce called for replacing conventional KYC and AML data collection with zero-knowledge proofs and reusable digital credentials.
- Peirce warned that current KYC practices turn financial rails into a "panopticon" and assemble "data haystacks" that expose users to leaks, phishing, and physical attacks.
- Attribute-based credentials could prove facts such as age, citizenship, or sanctions status without disclosing a customer's name, income, or address.
- Peirce noted her remarks represented her personal views rather than those of the SEC, with Decrypt reporting the address took place during her final weeks as commissioner.
- The remarks followed identity-data exposures, including a breach at Coinbase affecting 69,461 customers and a deceptive government-domain email scheme targeting Revolut.
- Proposed rules under the GENIUS Act would require permitted payment stablecoin issuers to collect identifying customer information and retain it for five years after an account closes.
Sources · 8 sources
- WG
Watcher.Guru@WatcherGuruPost on X ·
JUST IN: 🇺🇸 SEC Commissioner Hester Peirce calls to end mass KYC data collection, warning it puts crypto holders at risk of phishing and physical attacks. Pierce says the current KYC/AML system creates massive databases of sensitive information that can be hacked, leaked, or exploited. She's pushing for zero-knowledge proofs (ZK proofs) that could verify users meet regulatory requirements without exposing their personal information.
Open source - CR
CryptoSlate@CryptoSlatePost on X ·
Proposed US rules would make stablecoin issuers keep customer ID data for five years after covered accounts close. SEC Commissioner Hester Peirce wants reusable credentials to reduce duplicate KYC databases that attackers can target. https://t.co/jl8hvjBnxy
Open source - SI
Solid Intel 📡@solidintel_xPost on X ·
INTEL: KYC should collect less personal data and use zero-knowledge proofs to verify compliance without revealing names, income or addresses, SEC Commissioner Hester Peirce says https://t.co/vW6wSfoMwI
Open source - WB
Wu Blockchain@WuBlockchainPost on X ·
SEC Commissioner Peirce Calls for Zero-Knowledge Proofs to Replace Data-Heavy KYC/AML Practices SEC Commissioner Hester Peirce said the agency’s Innovation Exemption provides a temporary pathway for tokenized securities to trade through AMMs, helping prevent overseas markets from monopolizing tokenized exposure to U.S. equities while serving as a bridge to longer-term rules. She also criticized the current KYC/AML model for creating ever-larger “data haystacks” with limited effectiveness while turning the financial system into a “panopticon,” and called for zero-knowledge proofs and attribute-based credentials to verify compliance without collecting or repeatedly storing users’ sensitive personal data.
Open source - DE
DecryptArticle ·
In Her Final Weeks, SEC's Peirce Calls for Ending the KYC 'Panopticon' In one of her final speeches as commissioner, Peirce argued that regulators' "data haystacks" endanger the people they aim to protect—as recent KYC leaks expose crypto holders to phishing and physical attacks.
Open source - CO
Cointelegraph@CointelegraphPost on X ·
🚨 LATEST: SEC Commissioner Hester Peirce says zero-knowledge proofs could verify compliance without collecting users’ personal data. She warns current KYC/AML practices create “data haystacks.” https://t.co/oiNM8q7CFz
Open source - CO
CoinDesk@CoinDeskPost on X ·
INSIGHT: SEC Commissioner Hester Peirce calls for a rethink of KYC and AML oversight. She argues the "more data, the better" approach creates haystacks too big to find needles, and that zero-knowledge proofs could verify compliance without exposing personal data. https://t.co/1MWTimJ5Ew
Open source - CR
CryptoSlateArticle ·
SEC’s Hester Peirce wants to end crypto’s KYC honeypots before stablecoin rules create more of them US Securities and Exchange Commission (SEC) Commissioner Hester Peirce wants financial firms to stop stockpiling customer data after breaches exposed the cost of mandatory identity collection. This week, the SEC Commissioner called for wider use of reusable digital credentials that could establish facts about customers without requiring every financial institution to collect the underlying personal information again. According to her: “Today society is at a crossroads. Down one path lies the status quo: more data collection, more intermediary surveillance, more “know your customer' requirements that turn our financial rails into a panopticon. Down the other path lies an opportunity to use new technologies to improve our ability to catch criminals while collecting less personal information than ever before, and monitoring more sparingly to protect Americans’ privacy.” Her remarks follow recent security incidents at major financial platforms like Revolut that exposed identity documents, addresses, and other information these companies collect to meet customer-verification and anti-money-laundering requirements. Peirce said regulators should reconsider whether institutions need particular pieces of information or merely need confirmation of the facts those records establish. Attribute-based credentials, she said, could prove whether someone meets an age requirement, holds a particular citizenship or appears on sanctions lists without revealing information such as their name, income or address. “Does more than one firm need to collect it?” Peirce asked, arguing that technology already exists to reduce the information customers surrender and the number of institutions that receive it. She said the remarks represented her own views rather than those of the SEC. The question is becoming more consequential as Washington builds a new compliance regime for stablecoins. The GENIUS Act requires permitted payment stablecoin issuers to maintain customer-identification programs, and regulators are proposing rules that would continue requiring covered issuers to obtain and retain identifying information from customers. Breaches turn KYC records into targets Coinbase provided one of the clearest examples of the risk last year. Attackers bribed contractors or employees working in overseas customer-support roles to obtain information from the exchange's internal systems. Coinbase later disclosed that 69,461 customers were affected. The compromised information included names, addresses, phone numbers, email addresses, partial Social Security numbers, government-issued identification images, account balances and transaction histories. Passwords and private keys were not stolen, but Coinbase warned that the information could be used in social-engineering attacks against customers. Chief Executive Officer Brian Armstrong then turned the breach into an argument against how much information financial companies are required to retain. “We don't want to collect it, and our customers hate it,” Armstrong said while calling for lawmakers to reconsider the Bank Secrecy Act and anti-money-laundering requirements. He also argued that Congress should review the laws or they should face a constitutional challenge, a position that goes considerably further than Peirce's proposal to change how required information is collected and verified. The problem resurfaced this month at Revolut through a different route. The fintech company said an unauthorized party used a legitimate government-agency email domain to send fraudulent information requests. Revolut disclosed customer information in response , including identity and contact details and copies of passports and driver's licenses. Depending on the customer, the material could also include verification selfies, account statements, and transaction histories. Revolut said its systems and customer funds were unaffected. The episodes illustrate the vulnerability Peirce is targeting: once institutions accumulate identity records, stealing money does not require breaching private keys or directly compromising financial accounts. Personal information can itself become an asset for extortion, impersonation, and subsequent attacks. Stablecoin rules preserve the collection model The policy challenge is that US regulators are simultaneously extending customer-identification requirements to another part of the financial system. Under the proposed GENIUS Act implementation , a permitted payment stablecoin issuer would generally have to obtain a customer's name, date of birth or formation, address, and identification number before opening a covered account. The identifying information would then be retained for five years after the account closes, while records describing verification methods and results would generally remain for five years after they are created. The requirement does not cover every person who receives or holds a stablecoin. It targets customers establishing covered relationships with issuers, including relationships involving direct issuance or redemption. Regulators say the requirements implement Congress's direction that permitted stablecoin issuers be treated as financial institutions under the Bank Secrecy Act and maintain effective customer-identification programs designed to combat money laundering, terrorist financing and other illicit activity. The proposal already leaves some room for technology. An issuer may use digital credentials as part of identity verification and, under specified conditions, rely on procedures performed by another regulated financial institution. FinCEN also said this month that banks and credit unions may use qualifying government-issued digital credentials, including mobile driver's licenses, within their existing customer-identification programs. Those mechanisms stop short of the portable model Peirce described. Verification technology can change how an institution confirms an identity without necessarily eliminating its obligation to obtain prescribed customer information or maintain records. The fight moves to the final rule Regulators have left that question open. FinCEN and the banking agencies explicitly asked whether the final stablecoin rule should address digital identity systems or verifiable credentials and what benefits and risks would accompany their use. They acknowledged that a nongovernmental credential could allow someone to prove who they are without revealing additional information, but declined to include specific verifiable-credential provisions in the proposed regulatory text. That creates room for the final rules to determine how much duplicate collection survives. Regulators could broaden the circumstances in which stablecoin issuers rely on identity checks conducted elsewhere, give clearer recognition to cryptographically verifiable credentials, or allow firms to retain evidence that required checks occurred without keeping additional copies of the underlying documents where the law permits. Related Reading US bank lobby wants stablecoin holders to open an account before cashing out For stablecoin companies , the outcome will determine whether compliance requires building another generation of databases containing customer identity information or investing in systems designed to verify required attributes while holding less of the raw data themselves. The GENIUS Act has already settled that regulated issuers must know their customers. The remaining rulemaking will determine how many companies need to keep copies of the information used to prove who those customers are. The post SEC’s Hester Peirce wants to end crypto’s KYC honeypots before stablecoin rules create more of them appeared first on CryptoSlate .
Open source

