Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Anyone moving crypto-assets from an exchange to a self-custodied wallet has, since the MiCA transition period ended, run into an intermediate step that does not arise on a transfer to another exchange: the provider wants to know whether the destination address really belongs to you. This is neither obstruction nor a house rule. It is an obligation under the European transfer of funds regulation, set out in Article 14(5) of Regulation (EU) 2023/1113. It bites above €1,000, and it falls on the provider, not on you.
The consequence for you is nonetheless a very practical one. When a withdrawal deadline is running, when an exchange is winding down or a token is pulled from trading, you want your balance moved to your own wallet quickly. That is exactly the moment proof of ownership inserts itself, and depending on the method chosen it costs you minutes or several hours. Knowing beforehand what may be demanded, and what your wallet needs to be capable of, saves that time.
Self-hosted address: what the transfer of funds regulation means by the term
The term everything turns on is defined in Article 3(20) of Regulation (EU) 2023/1113. A “self-hosted address” is a distributed ledger address that is not linked to a crypto-asset service provider, nor to an entity established outside the Union providing comparable services.
What matters is therefore not the physical form of the wallet but whether a service provider sits behind the address. A hardware wallet falls under the definition, a software wallet on your own machine does too, and so does a paper address whose key you have never stored digitally. The deposit address of a second exchange, by contrast, is not a self-hosted address, even where it has been assigned to you personally. On a transfer between two exchanges the two houses pass the prescribed information to each other; the question of proof never arises there.
Article 14(5): above €1,000 the exchange must establish that you own the address
The wording is short and unambiguous in its aim. On a transfer to a self-hosted address, the originator’s crypto-asset service provider collects the prescribed information on originator and beneficiary, retains it, and ensures that the transfer can be individually identified. Where the amount exceeds €1,000, the substance is added: the provider then takes appropriate measures to establish whether that address is owned or controlled by the originator.
Two points here are routinely skimmed over. First, the regulation speaks of “ownership or control” and not of proof of identity; what is being tested is the link between you and one specific address, not your person all over again. Second, Article 14(8) sets a hard sequence: the provider shall not allow a transfer to be initiated or executed before full compliance with the article is assured. As long as the proof is missing, the withdrawal does not go out. That is why a withdrawal sometimes sits in the queue with no visible error.
Below €1,000 the duty does not stop: what is collected on every crypto transfer
The €1,000 threshold applies solely to the qualified determination of ownership or control. The information requirement itself has no lower limit. Under Article 14(1), the information on the originator includes the name, the distributed ledger address, the account number of the crypto-asset account and the address including the country, together with the number of an official personal document and the customer identification number, or failing that the date and place of birth. Paragraph 2 requires the corresponding information on the beneficiary.
On a transfer to your own wallet you are both parties in one person, originator and beneficiary. That is why the process feels unremarkable from where you sit: the exchange already holds the data and enters it itself. The rule only becomes visible above the threshold, because a step is added there that only you can perform. Anyone withdrawing smaller amounts regularly will rarely meet it; anyone clearing out an account will meet it almost every time.
Under Article 14(6) the provider additionally verifies the accuracy of the information on the originator on the basis of documents, data or information obtained from a reliable and independent source. Paragraph 7 makes clear that this verification counts as done where your identity has already been established under the anti-money laundering rules and the data retained. On an account that has been through full verification, that part is therefore settled before you trigger the withdrawal. At an exchange holding a European authorisation it is a precondition of the account in any case, and a look at the comparison of regulated crypto exchanges shows which houses meet that framework for European customers.
The exchange rate at the time of the transfer: how the €1,000 threshold is calculated
The threshold is a euro amount; the transfer consists of crypto-assets. How the two are brought together is governed by the European Banking Authority’s travel rule guidelines (EBA/GL/2024/11), applicable since 30 December 2024. Paragraph 82 records that the provider uses the exchange rate of the crypto-asset to be transferred at the time of the transfer in order to determine its value in euro, irrespective of any transaction fees.
In practice that means the decisive moment is the withdrawal itself, not the point at which you bought, and not the amount net of the network fee. A holding that sat clearly below the threshold at purchase can cross it on the way out. Splitting a withdrawal into several smaller ones is no advisable way around it either, since providers are independently obliged to detect and assess unusual transaction patterns.

Article 16(2): why a deposit from your own wallet triggers the same check
The return leg is governed symmetrically. Under Article 16(2) of the regulation, on a transfer from a self-hosted address the beneficiary’s provider collects the same information and retains it; where the amount exceeds €1,000, it too takes appropriate measures to establish whether the address is owned or controlled by the beneficiary. Paragraph 3 further requires it to verify the information on the beneficiary before making the crypto-assets available.
Anyone bringing holdings back out of self-custody onto an exchange in order to sell there should plan for this. The credit can hang until the proof is in, and it does so precisely in a situation where speed is usually the point. The procedure is the same as in the opposite direction, except that the check now sits on the receiving side.
Regulated crypto exchanges comparedFive verification methods: what the EBA travel rule guidelines permit
The regulation says that a check must happen, but not how. Paragraph 83 of the EBA guidelines fills that gap. Providers should apply at least one of five verification methods to assess whether a self-hosted address is owned or controlled by the originator or the beneficiary.
Those named are unattended verification procedures under the EBA guidelines on the use of remote customer onboarding solutions, with the address stated; attended procedures under the same guidelines; sending a predefined amount from or to the self-hosted address to an account of the provider; asking the customer to digitally sign a specific message with the key belonging to the address; and other suitable technical means, provided they allow a reliable and secure assessment.
Which method is used is, under paragraph 84, the provider’s decision, taken on three considerations: the technical capabilities of the self-hosted address, the robustness of the assessment a method can deliver, and the money laundering and terrorist financing risk. Paragraph 85 adds that a combination of several methods should be applied where one alone is not reliable enough. You have no claim on that choice, but you can expect the two middle variants to dominate in practice.
The reference transfer: why the exchange wants to see a micro-amount from your address
Under this method the provider sets an amount, preferably the smallest denomination of the crypto-asset in question, and you send it from the self-hosted address to an account of the provider. If the payment arrives from exactly that address, control is taken as demonstrated. With bitcoin the smallest unit is a satoshi, which is why the industry often names the procedure after it.
The advantage is that the method works with practically any wallet, since sending is something every wallet can do. The drawback is the time it takes. You need a confirmation on the network in question, and you pay a network fee for it that can exceed the micro-amount transferred many times over. Anyone going through the procedure for the first time should not count on completing the actual withdrawal within the same quarter of an hour.
A second point concerns the order of events. The micro-amount has to come from the address you later intend to use as the destination. With wallets that generate a fresh address for every receipt this is a trap: the address you use for the proof and the address the wallet displays for the withdrawal can diverge. A look at the settings of your hardware wallet before the first proof saves you repeating the whole exercise here.
The signed message: how you sign with the private key without handing it over
The second variant common in practice requires no transaction. The provider gives you a text, which you sign in your wallet software with the key belonging to the address in question. What you hand back is the signature, a character string from which it can be derived computationally that it can only have been produced with the matching private key.
The private key never leaves the device in the process. That is the essential difference from anything that sounds like surrendering it, and the reason the procedure is unobjectionable in security terms, as long as you sign only the text specified by the provider. Caution is warranted the other way round, where someone outside a withdrawal you have initiated asks you to sign an arbitrary message or even a transaction. A signature request you did not trigger yourself is not one to approve.
Technically, though, the method is more demanding than the reference transfer, because not every wallet supports signing arbitrary messages and the implementation differs by address type. That is exactly what the first of the three considerations in paragraph 84 of the guidelines is aimed at: the technical capabilities of the address.
Section 15a of the German AML Act: the enhanced due diligence that applies on top
Alongside the European regulation, German law adds Section 15a of the Money Laundering Act. It obliges undertakings executing a transfer of crypto-assets whose beneficiary or originator is a self-hosted address to identify and assess the associated risk and to take appropriate risk mitigation measures.
Paragraph 2 lists the minimum that belongs to this, one of the measures being sufficient and a combination possible: collecting, verifying and storing the identity of the beneficiary or originator and of the beneficial owner of the self-hosted address; measures to determine the origin and destination of the crypto-assets to be transferred; enhanced and continuous monitoring of those transactions and of the associated business relationship; or other measures to mitigate and manage the risks.
That explains a line of questioning many experience as intrusive. Where a provider asks you where the crypto-assets are going or where they came from, it is implementing the second of those measures. That is a free-standing obligation alongside proof of ownership and not the same thing. The proof settles who owns the address; the origin question settles what is meant to happen on it.

Whitelisting: why the check usually falls away the second time
Paragraph 86 of the guidelines describes the relief that keeps the burden manageable day to day. Where the provider has fully satisfied itself that the self-hosted address is owned or controlled by its customer, it should document this in its systems; it may then not need to apply those measures again on later transactions from or to the same address. The guidelines call this whitelisting in as many words.
A condition is attached. A provider using whitelisting should have controls in place to detect changes in the risk and in ownership or control. Where it finds that the risk has changed, or that there are indications the customer no longer owns or controls the address, it should remove it from the whitelist.
For you a plain recommendation on sequencing follows. Getting the proof done once, calmly, before any time pressure arises is considerably more comfortable than catching up on it on the last day of a deadline. Register your destination address early and have it cleared, and the step is behind you when it matters.
Hardware wallets comparedHardware wallet without a signing function: when the address lacks the technical capability
Not every wallet handles every method, and the guidelines expressly accommodate this with the technical capabilities criterion. Where a provider demands a signed message and your wallet does not offer the function, the reference transfer is the usual way out. Conversely, a wallet set up purely to receive, holding no balance to cover a network fee, cannot manage the reference transfer.
From that follows a point rarely weighed before buying a device: a wallet that can do both spares you any dependence on the provider’s choice of method. Before setting one up it is worth checking the wallet documentation on two questions: whether signing arbitrary messages is provided for in the companion software, and whether a fixed receiving address can be used.
Withdrawal deadlines and proof of ownership: why the two together get tight
The proof turns into a scheduling problem the moment a date is on the table. BitMEX, for one, has announced it will cease operating the exchange on 23 September 2026 at 04:00 UTC. Under the same announcement on the company’s own site, risk limits preventing the opening of new positions take effect from 26 August 2026 at 04:00 UTC; from that point the house closes existing open positions itself. Anyone still holding balances there and wanting to move them into self-custody has to fit the proof of ownership into that window, and it is the one step in the sequence that does not depend on the exchange alone.
The same pattern applies to a delisting that runs without the exchange closing. How the sequence of deposit suspension, trading halt and withdrawal deadline hangs together is set out in detail in the cryptoticker piece on delisting at a crypto exchange of 17 August 2026. For planning purposes: proof of ownership belongs at the start of the chain, not at the end.
What you can do when the withdrawal stalls
Where a withdrawal you have initiated sits there with no visible reason, the first place to look is the account notifications, since the request for proof is frequently delivered there rather than by email. If that leads nowhere, the regular route is a formal complaint to the provider, which every authorised provider must operate under MiCA; that procedure is free of charge and tied to no prescribed form.
What proof of ownership is not: KYC, tax and proof of reserves distinguished
Three confusions come up regularly, and all three produce false expectations.
Proof of ownership is not a repeat identity check. Your person was established when the account was opened; what is at stake here is solely the attribution of an address. Nor is it a tax event. Moving your own holdings between your own addresses is not in itself a disposal, and the proof changes nothing about that. And it is not a proof of reserves either: proof of reserves concerns whether the exchange holds its customers’ balances, whereas proof of ownership points the other way and concerns your address.
That leaves the point most likely to cause unease. Through the proof the provider learns which address is yours, and a history is attached to that address on the public blockchain. This is a consequence of the rules that cannot be argued away, and at the same time the price of transfers into self-custody remaining possible at all at authorised providers, rather than being blocked outright on risk grounds.
Wallet proof of ownership: what to take away
- Get the proof done before you need it. Register your wallet’s destination address once, calmly, and have it cleared, so that the whitelisting under paragraph 86 of the EBA guidelines applies. Which devices support message signing is shown in the hardware wallet comparison.
- Check which method your wallet handles. If it can sign a message, the proof is done in minutes; if it cannot, keep a small reserve on hand for the network fee of the reference transfer. The feature sets are set out in the software wallet comparison.
- Calculate the €1,000 threshold at the time of withdrawal. Under paragraph 82 the decisive figure is the rate at the moment of transfer, not your cost basis. Whether your provider applies the European requirements at all is settled by the comparison of regulated crypto exchanges.
Anyone wanting to read the procedure in full will find the guidelines under reference EBA/GL/2024/11 on the European Banking Authority’s publications page; they have applied since 30 December 2024 and replaced the earlier joint guidelines from 2017.
(As of August 19, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
- Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
- Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
- Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
- Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
July 10, 2026 10:30 AM

Binance Reveals Where Its EU Users Went After MiCA
Binance just revealed where most departing EU users moved their crypto after MiCA — and the answer is raising hard questions about the new rulebook.
September 26, 2026 4:14 PM

Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
Bitget is releasing the withdrawals frozen after the September 24 incident in four stages from September 28. For a residual balance held from Germany that is a deadline, not a reason to wait.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 11, 2026 1:26 PM

Alby Hub Security Flaw: How to Check Whether Your Bitcoin Lightning Node Is Reachable From the Internet
Alby confirmed a critical flaw in Alby Hub v1.7.0 through v1.18.5 on September 9, 2026; it is only exploitable if the management interface sits openly on the internet. What to check on your node, why the fix is a good twelve months older than the warning, and which step comes before the update.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
September 29, 2026 10:28 PM

Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
After the attack of September 24, customers pulled around $463 million out of Bitget within a day, the largest single-day outflow since DefiLlama began tracking reserves. The user protection fund fell from $464 million to below $200 million in the process.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 3, 2026 4:41 AM

Kraken Delists 21 Tokens: Trading End on September 11 Has Passed, Withdrawals Run Until December 10
As of September 27, 2026: Kraken had set the end of trading and deposits for 21 cryptocurrencies for September 11, 2026 at 14:00 UTC, and that date has passed. According to the exchange, withdrawals remain possible until December 10, 2026 at 15:00 UTC. Our September 3 survey showed that none of these tokens could be deposited at Bitvavo, Coinbase or Bitstamp.
August 22, 2026 10:37 PM

Transferring Delisted Tokens: 16 of 21 Kraken Assets Have No Fallback Exchange
On 27 August at 14:00 UTC Kraken closes withdrawals for 21 delisted tokens, and from 1 September the exchange sells the remainder itself. Our count of 34 tokens against six venues shows which assets still have a transfer destination at all.
August 20, 2026 4:20 AM

Crypto Exchange Delisting: What Happens to Your Tokens When Trading and Withdrawals Close
A delisting runs in four stages, and only one of them is genuinely dangerous: the end of the withdrawal deadline. Using two live OKX dates as the example, we show what happens at each stage and how to tell whether it affects you.
August 19, 2026 10:24 AM

Privacy Coins and EU Anti-Money-Laundering Law: An Assessment of the Ban From July 2027
Article 79 of the EU anti-money-laundering regulation bars crypto service providers from keeping accounts that obscure transactions, and it names anonymity-enhancing cryptocurrencies explicitly. This assessment separates the documented wording, including the 10 July 2027 application date, from what follows for individual coins.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 25, 2026 4:20 AM

Crypto as a Down Payment for a German Mortgage: What Banks Require
Since April 2023 a house in Germany can no longer be paid for in Bitcoin; section 16a of the Money Laundering Act bans it outright. Your crypto holdings still work as a down payment, provided you take the route through the euro and prove the origin without gaps.
September 24, 2026 10:29 AM

Bank Closed Your Account Over Crypto: Your Rights and the Route to a Replacement Account
After a withdrawal from a crypto exchange, banks repeatedly end the banking relationship, usually without giving a reason. What the German Payment Accounts Act guarantees you anyway, which notice period applies, and in what order you approach the supervisor, arbitration and the courts.
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
September 25, 2026 4:13 PM

Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
The $351.6 million attack on Bitget would eat up three quarters of the exchange's in-house protection fund. We retrieved the protection promises of several exchanges ourselves and measured them against deposit insurance and MiCA liability.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 25, 2026 7:11 AM

EU Supervisors Rate Quantum Risk as High: What to Check on Crypto Custody and Exchange Choice
EBA, EIOPA and ESMA name quantum computers explicitly as a threat to blockchain cryptography in their autumn risk picture of September 23. What the paper says, which migration deadlines run to 2030, and three things you can check about your custody.
September 19, 2026 7:17 AM

Chainlink Jumps Above $12: What LINK Holders Should Check Now
Chainlink trades at $12.34, 7.4 percent higher than yesterday. What part of the move is the broad market rally, what Chainlink itself contributes, and the three things you should check as a LINK holder.
More from CryptoTicker
