- Thailand has adopted the crypto Travel Rule, and its version asks digital asset operators to verify that customers control the self-custodial wallets they transfer to, according to Cointelegraph.
- A separate proposal, approved for consultation on 3 September, would go further: deposits and withdrawals through licensed Thai operators would have to come from, and go to, a wallet verified as the customer’s own, blocking transfers to other people entirely.
- Operators must retain transaction data for five years. We have not seen the regulator’s own text, so thresholds, dates and penalties are not confirmed here, and the stablecoin measure is still a proposal.
Withdraw coins from a Thai exchange to a wallet on your own phone, and you may soon be asked to prove that wallet is really yours. Thailand has adopted a version of the crypto Travel Rule that reaches further into than Britain’s does.
Rules like this travel between countries. Thailand is applying an international standard that most governments have signed up to, and its self-custody check is the strictest widely reported version of it so far. A second Thai proposal, still at consultation stage, would go further again and stop you sending stablecoins to anybody else’s wallet through a licensed platform. Other regulators will look at how both work.
If you keep coins in a wallet you control yourself, the question of whether a platform can demand proof of that, and what it does with the answer, is the one worth following. Britain already has a Travel Rule. It does not currently include a blanket proof-of-control test.
What the Travel Rule actually is

The name is borrowed from banking. When money moves between banks, information about the sender and the recipient has to travel with it: names, account numbers, sometimes an address. The Financial Action Task Force, the intergovernmental body that writes global anti-money-laundering standards, extended that requirement to crypto in 2019.
In practice it means that when one licensed platform sends coins to another, it has to attach the originator and beneficiary details rather than just broadcasting an anonymous transaction. Dozens of jurisdictions have now written some form of it into law, at different thresholds and different speeds.
Thailand is not inventing anything by adopting it. The part that stands out is what happens when the coins are not going to another platform at all, but to a wallet held by the customer.
Proving a wallet is yours
There are two common ways to do this, and neither is exotic. The first is a signed message: the platform gives you a string of text, you sign it inside your wallet using the , and the signature proves the key was available to whoever produced it. The second is a small test transaction, sometimes called a Satoshi test, where you send a amount from the wallet back to the platform to show you can spend from it.
Some firms accept a screenshot or a written declaration instead. That proves considerably less.
What none of these methods establishes is beneficial ownership. A signature shows that somebody had access to the key at the moment of signing. It does not show that the person is the account holder rather than a friend, an employer, or somebody standing behind them. It also says nothing about the following week. Proof of control is a snapshot, and the strength of a rule built on it depends entirely on how often the snapshot is taken.
What Britain already does
The UK Travel Rule came into force on 1 September 2023, through amendments to the money laundering regulations. British firms have to collect and pass on sender and recipient information for crypto transfers, and the reason so many people noticed it was withdrawals: suddenly the exchange wanted to know who owned the destination address.
For unhosted wallets, meaning ones not held by a regulated business, the UK approach is risk-based. Firms collect the beneficiary details and are expected to verify them where the transfer looks higher risk, rather than testing every withdrawal. Several UK platforms do ask for a signed message on larger transfers, but that is their own policy rather than a legal requirement applied across the board.
So a British reader moving coins to a hardware wallet is already living with part of this. The Thai version tightens the same screw. If you have hit friction on this before, our guide to delayed and blocked withdrawals covers what platforms are usually asking for and why.
Five years of records
The retention requirement is the quieter half of the story. Transaction data held for five years means that anyone who has withdrawn from a covered Thai platform leaves a durable link between a verified identity and a wallet address, sitting in one company’s systems and available to the authorities on request.
records are permanent anyway. That is the point of them. What changes here is the name attached to the address, and how long a private firm is obliged to keep holding it.
The stablecoin proposal goes further
Since this piece was published, Thailand’s SEC has set out a second batch of principles, approved by its board on 3 September and now out for consultation, applying a same-owner test to stablecoin transfers through licensed operators. Proof of control asks whether you hold the key to the wallet you are sending to. This asks something narrower: whose wallet it is.
As drafted, a stablecoin arriving in a customer’s account at a Thai digital asset operator would have to come from an account or wallet verified as belonging to that customer, and a withdrawal would have to go to one. CryptoSlate reports the consequence as explicit in the text: a deposit from another person’s account, or a withdrawal to another person’s account, would be prohibited. Paying a friend in USDT through a licensed Thai platform would stop being possible.
Two limits are worth keeping in view. This is a consultation rather than an operative rule, so it can be narrowed, delayed or dropped. And its reach stops at transfers conducted through supervised operators, which leaves a transfer between two self-custodied wallets, with no Thai platform involved, outside it.
Nothing in the UK regime looks like this. British firms have to know who the recipient of a covered transfer is. They are not told the recipient has to be you, and sending crypto to another person from a UK exchange remains an ordinary thing to do. Thailand’s first move borrows a standard nearly everyone else has adopted. Its second does not.
What is confirmed and what is not
The Travel Rule adoption is reported by Cointelegraph and the stablecoin consultation by CryptoSlate. We have not read the Thai regulator’s own notification or the consultation paper, and no direct quotation from an official appears in the coverage we have seen, so we are not putting words in anyone’s mouth.
The detail that decides how much this actually bites is not settled in the reporting: whether the proof-of-control check applies to every self-custody withdrawal or only above a value threshold, when it takes effect, which verification methods are acceptable, and what happens to a customer who cannot or will not sign. Nor is it clear how a platform would establish that a destination wallet belongs to somebody else rather than to the customer, given that a signature proves access and not identity. Our inference, and we are labelling it as one, is that most platforms will default to signed messages, because it is the cheapest option that satisfies an auditor. More regulation coverage is here.
What to watch
The consultation first. Whether the same-owner requirement survives industry feedback, whether it stays confined to stablecoins or gets extended to other tokens, and what date it would take effect from.
Then the implementation guidance on the Travel Rule side, and specifically the threshold. A rule that applies to every withdrawal is a different animal from one that starts at the equivalent of several thousand pounds.
Closer to home, whether the FCA borrows either idea as it builds out the UK’s full crypto regime. Britain’s Travel Rule was written before proof-of-control checks became a standard product feature, and the gap between what the law demands and what exchanges already do voluntarily is the space where the next change usually happens.