SEC Commissioner Hester Peirce wants U.S. regulators to use reusable digital credentials for customer checks, warning that new stablecoin rules could make financial firms hold even more sensitive data.
U.S. regulators are tightening their grip on stablecoins. SEC Commissioner Hester Peirce says the current way of checking customer identities is building a patchwork of risky data silos. She has pushed for zero-knowledge proofs and digital credentials that let users prove things like age, citizenship, or investor status without every financial company collecting the same personal details. Peirce argues this could lower the risks that come with mass data collection, a problem that keeps growing as crypto expands.
Recent hacks have shown how exposed the current know-your-customer (KYC) system is. In one major breach, attackers bribed overseas contractors to get into Coinbase's internal systems. They got the personal data of 69,461 customers-names, addresses, phone numbers, parts of Social Security numbers, and images of government IDs. Passwords and private keys were safe, but the leak left people open to scams and identity theft. Coinbase CEO Brian Armstrong said financial firms are being forced to collect more data than they want, and lawmakers should rethink these rules.
SEC Commissioner Hester Peirce has called for zero-knowledge proofs and decentralized identity to confirm regulatory requirements without mass collection of personal data.
Another breach hit Revolut. Someone used a real government email domain to ask for customer info. Revolut handed over identity documents, contact details, and even verification selfies. The company said its own systems and customer funds were safe. Reports showed the breach came from a third-party provider, DriveWealth, not a direct attack on Revolut. These cases show that once companies gather identity records, hackers don't need to steal crypto itself-personal data becomes a target for fraud and extortion.
Notices to affected users listed what might have been exposed: dates of birth, postal and email addresses, phone numbers, document copies, selfies, account statements, and transaction histories. Revolut said passwords, card details, or ID documents for Irish clients were not leaked. Still, these incidents show just how much personal data is at risk under current KYC rules and the operational dangers for crypto firms.
The pressure is rising as Congress and regulators draft new rules for stablecoin issuers. The proposed GENIUS Act would make permitted payment stablecoin issuers run customer-ID programs, collecting names, addresses, birth dates, and ID numbers before opening accounts. These records would have to be kept for five years after an account closes. Verification details would also be stored for five years. The rules focus on customers with direct ties to issuers, but they could still trigger a new wave of data collection across crypto.
Zero-knowledge proofs and decentralized identity are being discussed as part of a broader review of KYC/AML approaches, but remain recommendations rather than regulatory standards. The SEC has not yet adopted rules allowing digital proofs to replace traditional KYC documentation without storing personal data.
Regulators have left some room for digital identity tech. Stablecoin issuers can use digital credentials for checks and, in some cases, rely on checks done by other regulated financial firms. The Financial Crimes Enforcement Network (FinCEN) says banks and credit unions can use government-issued digital IDs, like mobile driver's licenses, in their programs. But these steps don't go as far as the portable, privacy-first model Peirce wants, where users prove eligibility without handing over raw personal data again and again.
As final stablecoin rules are debated, regulators are asking if digital identity systems or verifiable credentials should be written into the law. They admit that non-government credentials could let users prove who they are without giving up extra details, but the draft rules don't spell this out. The final decision will set whether stablecoin issuers must build new identity databases or can use systems that check only what's needed and keep less data.
For crypto companies, this choice matters. Building and running big stores of sensitive customer data raises risk, drives up compliance costs, and makes breaches more damaging. As reported earlier, identity rules have already changed how exchanges handle withdrawals and account access. The fight over stablecoin KYC rules will shape not just compliance work, but also privacy and security for millions of users.
The SEC says the GENIUS Act would treat permitted stablecoin issuers as financial institutions under the Bank Secrecy Act. They would have to run strong customer-ID programs to fight money laundering and other crimes. The final rules will decide how much data must be collected, how long it stays on file, and if new tech can cut the risks of storing it all in one place.
Reusable digital credentials could change how identity works in finance. Instead of every company collecting full personal profiles, users could show cryptographic proofs that they meet the rules-like being over a certain age or not on a sanctions list-without revealing more than needed. This could shrink the target for hackers, limit the damage from leaks, and give users more control over their data. But it all depends on regulators, technical standards, and industry buy-in. As stablecoin rules are finalized, finding the right balance between compliance, privacy, and security will stay at the heart of the crypto debate.