Outgoing SEC Commissioner Hester Peirce Calls for Replacing the KYC 'Panopticon' With Zero-Knowledge Proofs
Key Takeaways
- •Peirce, speaking in her penultimate week as an SEC commissioner, criticized the KYC and AML framework for building ever-larger data collections that she argued make criminals harder to find while exposing ordinary customers.
- •She endorsed zero-knowledge proofs, a cryptographic technique first formalized in the 1980s and now used in systems like Zcash, which can verify facts such as age or sanctions status without revealing names, income, or addresses.
- •Recent incidents, Revolut's exposure of customer passports and Bitcoin histories after a fraudulent data request and a third-party breach affecting tens of thousands of Trezor customers, illustrate the risks of centralized identity data.
- •Peirce proposed that regulators allow firms to rely on shared third-party identity verification instead of each institution independently copying and storing the same sensitive records, and warned against 'wrench attacks' targeting crypto holders whose identities are exposed.
- •Because KYC and AML obligations are embedded in federal statute and regulation, adopting the attribute-based verification model she describes would require formal action by Congress or the enforcing agencies.

Departing SEC Commissioner Hester Peirce is making the case for using cryptography to overhaul how the financial system polices crime, arguing that regulators' hunger for personal data has built vast, hackable troves that endanger the very people they aim to protect.
Speaking Wednesday at the Securities Industry and Financial Markets Association's (SIFMA) Digital Assets Conference in New York, according to her prepared remarks, Peirce said the "know your customer" (KYC) and anti-money laundering (AML) regime rests on a flawed premise: that collecting enough information on enough people will help authorities spot criminals hiding among the law-abiding. That framework traces its roots to the Bank Secrecy Act of 1970 and was significantly expanded by the USA PATRIOT Act of 2001, which requires financial institutions to identify their customers, maintain records, and flag suspicious activity.
"We build ever bigger data haystacks on the theory that we will find a needle or two inside," she said. "The bigger haystack, however, makes it harder to find the needles."
She argued that technology now offers a better path. Zero-knowledge proofs, a cryptographic method that verifies a fact without exposing the underlying data, could let someone prove they meet a requirement without handing over sensitive personal details. First formalized by researchers in the 1980s, the technique has since moved from academic theory into working blockchain systems; it is the same technology that underpins private cryptocurrency networks and assets such as Zcash.
A proof can tell a counterparty that a person qualifies "without that counterparty knowing your name, income, or address," Peirce said, calling for a regulatory framework that encourages such attribute-based verification, in which credentials attest to specific facts like age or sanctions status instead of exposing full identity records. The alternative the regulator affectionately known as "crypto mom" argued, is "more data collection, more intermediary surveillance, more 'know your customer' requirements that turn our financial rails into a panopticon."
The remarks land against a grim backdrop of KYC data itself becoming a liability. Fintech company Revolut recently exposed customers' passports and full Bitcoin transaction histories after fulfilling a fraudulent government data request, while hardware wallet maker Trezor suffered breaches at a third-party vendor that exposed tens of thousands of customers and later fueled phishing attacks.
Such leaks have heightened fears of "wrench attacks," in which criminals physically target crypto holders whose wealth and identities are exposed.
Peirce, long the SEC's most crypto-friendly voice and known for criticizing the agency's past "regulation by enforcement" approach, warned against what she called "data maximalists" who assume more collection is always better. She suggested regulators let firms rely on third-party identity verification rather than each independently copying and storing the same sensitive records "across dozens of institutions."
It is a theme Peirce has pressed before, including at an August 2025 blockchain conference. The pitch carries added weight now: she disclosed that the speech came during her "penultimate week" as a commissioner. Individual commissioners' speeches do not by themselves change rules, and the KYC and AML obligations she criticizes are embedded in federal statute and regulation — meaning any shift toward the attribute-based model she describes would require formal action by Congress or the agencies that enforce the rules.
This article was originally published by Decrypt.