Former SEC commissioner Hester Peirce used her final public appearance at a digital-assets conference to argue that the current "know your customer" (KYC) and anti-money-laundering regime relies on an unsustainable accumulation of personal data and that emerging cryptographic tools offer a safer alternative.
Peirce’s Critique of the Existing KYC Model
During her remarks, Peirce described the prevailing approach as building ever larger "data haystacks" in the hope of finding a few illicit actors. She warned that the more information institutions retain, the more attractive the repositories become for hackers, and the harder it is for investigators to locate genuine threats. The former commissioner labeled advocates of continual data collection as "data maximalists," suggesting that their belief that more data automatically improves oversight is fundamentally flawed.
Zero-Knowledge Proofs and Attribute-Based Credentials
Peirce highlighted zero-knowledge proofs (ZKPs) as a technology capable of confirming user attributes—such as age, residency, or sanctions status—without revealing the underlying personal information. By allowing a party to demonstrate compliance with a requirement while keeping details like name, income, or address hidden, ZKPs could enable a privacy-preserving form of verification. Peirce called for a regulatory framework that encourages the use of such attribute-based credentials, positioning them as a replacement for the current data-intensive KYC processes.
Recent Breaches Reinforce the Privacy Argument
The call for change comes against a backdrop of high-profile data exposures. Fintech provider Revolut inadvertently disclosed customers' passports and Bitcoin transaction histories after complying with a fraudulent government request. Meanwhile, hardware-wallet maker Trezor suffered a breach at a third-party vendor that exposed tens of thousands of user records, later fueling phishing attacks. These incidents have amplified concerns about "wrench attacks," where criminals physically target individuals whose wealth and identities have been exposed.
Potential Regulatory Shifts and Industry Response
Peirce suggested that regulators allow firms to rely on third-party identity verification services rather than each institution independently storing the same sensitive data. Such a model could reduce duplication, lower the risk of large-scale leaks, and align with the broader push for privacy-enhancing technologies in finance. While the SEC has not yet signaled a formal move toward ZKP-based compliance, Peirce’s statements add weight to ongoing debates about modernizing AML/KYC rules.
Why it matters
If regulators adopt cryptographic verification methods, the financial ecosystem could see a reduction in data-driven vulnerabilities while maintaining compliance with anti-money-laundering objectives. A transition toward zero-knowledge proofs would reshape how crypto firms and traditional financial institutions handle customer onboarding, potentially setting new standards for privacy and security across the industry.




