SEC Commissioner Hester Peirce Calls for Less KYC Data and Greater Cryptographic Privacy
Key Takeaways
- •SEC Commissioner Hester Peirce argued that KYC and anti-money-laundering rules compel financial institutions to amass vast stores of personal data that are insufficiently protected and increasingly vulnerable to attack.
- •She promoted zero-knowledge proofs and attribute-based verification as cryptographic methods that would let individuals prove eligibility without disclosing their name, income, or address.
- •Recent breaches involving Revolut and vendors serving hardware-wallet maker Trezor have intensified fears that leaked KYC data could expose crypto holders to physical 'wrench attacks.'
- •Peirce proposed that regulators could outsource identity verification to third parties and issue users portable cryptographic certificates valid across platforms.
- •Her remarks amount to a policy signal rather than a formal rule, and with her term ending, implementation would depend on other commissioners or action by the SEC or Congress.

In a final speech as a commissioner at the SEC, the US agency that oversees securities markets, Hester Peirce argued that the financial system collects excessive personal information for identification while doing too little to protect the people whose data it stores. She said cryptography could address both problems at once.
The issue affects crypto holders whose passports and transaction histories are kept in vulnerable databases. It also comes as a series of know-your-customer (KYC) data leaks has heightened concerns that such information could threaten people’s physical safety.
Bigger data haystacks
At the same conference, Peirce criticized know-your-customer and anti-money laundering rules, which require financial institutions to verify customer identities and monitor account activity, built on the assumption that collecting information from enough people will help authorities identify criminals. She described that approach as outdated.
“It’s about building bigger and bigger data haystacks, and then hoping that we will find a needle or two in them,” Peirce said. “But the bigger data haystack, in turn, becomes less likely to reveal any needles.”
Her presentation, titled “Looking for Change in Haystacks,” described a crossroads for the financial system. One path would involve collecting increasing amounts of data through intermediaries until financial infrastructure becomes a panopticon — a system in which everyone can be watched at all times. The alternative would use new tools to identify criminals while gathering less personal information.
Peirce also criticized what she called “data maximalists.” In her view, that group includes government officials as well as private companies hired to collect customer data under the assumption that there is no such thing as too much information.
KYC without disclosing an identity
Peirce’s alternative involves zero-knowledge proofs — a cryptographic technique first formalized in the 1980s — which allow one party to verify that a statement is accurate without disclosing the underlying data. She discussed the technology alongside “attribute-based verification,” a system that checks compliance using a single attribute rather than storing a complete identity file.
In an interview, Peirce said that “one can prove that you qualify without that counterparty knowing your name, income, or address.” Similar technology is used in private and secure networks and in assets such as Zcash, a privacy-focused cryptocurrency.
Peirce also addressed privacy on public blockchains. In her view, public blockchains provide an unprecedented level of transparency and immutability, exceeding that of legacy record-keeping systems. She suggested that regulators could outsource identity verification to a third party and issue users cryptographic certificates that could be transferred from one platform to another.
The SEC published her remarks under the title “Looking for Change in Haystacks”.
Data breaches heighten the concern
Peirce’s argument comes amid a series of data breaches that have made the privacy issue more tangible. Recent incidents include Revolut exposing customers’ passport information and Bitcoin transaction history, as well as breaches involving vendors serving Trezor, the hardware-wallet maker. Related incidents have increased concern about so-called “wrench attacks,” in which attackers who learn that an individual holds cryptocurrency physically target that person.
Peirce’s argument is that every centralized database created to satisfy KYC requirements can become an attack vector against the people the rules are intended to protect.
She also linked her position to initiatives already underway at the agency. Peirce cited the “Innovation Exemption” adopted by the Commission a week before her speech. The exemption allows tokenized securities to be traded on cryptocurrency networks through automated market makers. Chairman Paul Atkins views the measure as a stepping-stone toward regulation, Peirce said.
A policy signal, not a formal rule
Peirce’s remarks represent a policy signal from an SEC commissioner, not a formal proposal. No proposal was filed, and the Commission did not announce specific guidelines. Peirce, who has served on the SEC since 2018 and has consistently advocated innovation in digital assets, also said that the views expressed were her own and might not be adopted by the Commission.
Her ability to implement the proposal may also be limited because her term is nearing its end — SEC commissioners serve staggered five-year terms — and she plans to move to Virginia Beach. The proposal’s prospects therefore depend on how other commissioners respond and whether the SEC or Congress develops it into formal guidance. Until then, the panopticon Peirce described remains unchanged.