NewsCryptoSEC's Hester Peirce Urges Zero-Knowledge Proof KYC Overhaul for Bitcoin

SEC's Hester Peirce Urges Zero-Knowledge Proof KYC Overhaul for Bitcoin

Author: Coinotag·

Key Takeaways

  • •SEC Commissioner Hester Peirce called on September 23 for a redesign of the US KYC and AML framework, arguing it collects expanding amounts of civilian data while becoming less effective at isolating financial crime.
  • •She endorsed zero-knowledge proofs and attribute-based credentials, which would let customers prove attributes such as legal age, citizenship, accredited-investor status, or sanctions-list clearance without disclosing underlying identity details.
  • •Peirce criticized rules that force every supervised firm to re-verify existing customers, arguing that relying on prior checks from trusted regulated counterparties would strengthen privacy and lower compliance costs.
  • •She rejected the claim that permissionless systems resist oversight, pointing to permanent auditable records on public smart-contract layers that increasingly capable on-chain forensic tools can analyze.
  • •The speech carries no binding force or effective date, but signals a shift toward crypto-native compliance and connects to the SEC's innovation exemption launched less than a week earlier.
SEC's Hester Peirce Urges Zero-Knowledge Proof KYC Overhaul for Bitcoin

SEC Commissioner Hester Peirce called on September 23 for a sweeping redesign of America's customer-identification regime, arguing that the current KYC and AML framework collects ever more data while catching ever fewer criminals — and that zero-knowledge proofs could deliver compliance without mass data collection.

Speaking at the SIFMA Digital Assets Conference — an event of the Securities Industry and Financial Markets Association, the trade group whose securities-firm and asset-manager members sit squarely inside the customer-verification regime she described — the Commission's best-known crypto advocate laid out her case remarks posted on the SEC's official newsroom. Peirce, an SEC commissioner since 2018 who leads the agency's Crypto Task Force and is long known in the industry as “Crypto Mom,” said supervisors have adopted a “Data Go Up” mentality — a mirror of crypto's “Number Go Up” fixation — in which every added reporting requirement is counted as progress regardless of whether it actually curbs financial crime.

A Bigger Haystack, Fewer Needles

Peirce's haystack metaphor cut to the logic of the system: regulators keep building a larger pile of civilian data so investigators can eventually find a few criminal needles, yet the bigger the pile grows, the harder those needles become to isolate.

Much of the architecture she is questioning has deep statutory roots: the Bank Secrecy Act of 1970 created the reporting backbone, and the customer-identification mandate itself arrived via Section 326 of the USA PATRIOT Act, passed in the weeks after the September 11 attacks, with final rules issued in 2003.

Under the Customer Identification Program rules that bind banks and other regulated intermediaries — from lenders to card networks like Visa — every firm must independently gather a customer's name, birthdate, address and identification number, then continuously monitor transactions and file Currency Transaction Reports and Suspicious Activity Reports.

Peirce questioned whether the cost of sustaining this surveillance architecture now exceeds its crime-prevention value. Ordinary people's files sit in databases exposed to accidents, hacks and deliberate abuse, frequently without the data subject ever knowing the collection occurred, she noted. Each duplicate copy, she warned, adds another breachable node, and regulators rarely revisit whether the original justification for a data point still stands.

She framed the choice as a fork: keep expanding collection until financial infrastructure becomes a panopticon, or adopt cryptographic tools that shrink the data footprint while improving illicit-finance detection.

Zero-Knowledge Proofs as the Compliance Path

The alternative Peirce outlined rests on cryptography rather than paperwork. Through attribute-based credentials and zero-knowledge proof systems — the technology family pioneered by privacy-focused chains such as Zcash — a customer could prove to a financial institution that they are of legal age, a citizen of a given country, an accredited investor, or absent from sanctions lists, without surrendering the name, income or address behind those conclusions.

In her framing, if the only fact a firm truly needs is whether someone passes the accredited-investor threshold that governs private crypto raises under a Simple Agreement for Future Tokens, harvesting full identity documents to derive that answer is no longer technically necessary.

She also attacked redundant onboarding. Outside narrow exceptions, US rules compel each supervised firm to re-verify customers who already cleared checks elsewhere, meaning one person's sensitive file may sit across dozens of institutions. Letting firms rely on an existing verification from a trusted, regulated counterpart, she argued, would improve privacy and cut compliance budgets at the same time.

Peirce further rejected the premise that permissionless systems resist oversight. A genuine permissionless network, as she defined it, runs on automated, immutable code with no intermediary custodying user assets, and its public smart contract layer leaves permanent, auditable records that increasingly capable on-chain forensic tools can analyze — so the absence of a traditional intermediary does not mean the absence of supervisory information.

Remarks, Not Rules — Yet

Peirce closed by tying the theme to the SEC's innovation exemption, launched less than a week earlier, saying tokenized securities should trade on crypto networks and automated market makers while durable rules are built — and that tokenization is coming, a shift she wants to happen onshore rather than through overseas markets first.

Read against the primary text on the SEC's newsroom rather than secondhand summaries, the speech is a commissioner's argument, not a rulemaking: it binds no entity and carries no effective date, but it sketches the compliance architecture regulators could codify. Turning that sketch into binding rules would run through formal notice-and-comment processes, giving banks, fintech firms and privacy advocates a defined window to argue over whether ZKP credentials can meet CIP-grade assurance. For Bitcoin (BTC) and the broader market, the arc runs from an enforcement-first posture toward crypto-native compliance, where cryptography itself satisfies supervisory goals.

Peirce's closing claim — that Americans can have both security and privacy — recasts KYC as a technical design choice rather than an inevitability. The markers that would show the argument moving from speech toward rule text are procedural rather than market-facing: a formal request for comment or a task-force roundtable on digital identity. COINOTAG's assessment is that pressure for a ZKP-aware framework will now move from speeches into the formal rulemaking track the exemption is meant to seed.

Source: Coinotag