Market literacy / Updated 2026-09-03

Prove the Wallet Is Yours: Why Your Exchange Suddenly Asks, and How the Real Request Differs From the Fake

Exchanges increasingly ask you to prove you control the wallet you are withdrawing to. The rule behind it, the two verification methods, and the test that separates it from signature phishing.

How this guide is checked

Official sources first, no wallet connection, no guaranteed returns.

Reviewed on 2026-09-03 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.

Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.

prove wallet ownership exchange withdrawal matters because Being asked to prove you own a wallet you have controlled for years feels absurd, and the request arrives with no explanation of who is asking or why — which leaves you guessing whether to comply or to treat it as an attack.

This guide sets out what the travel rule actually requires of your exchange, what the two standard verification methods do and do not expose, and the concrete test that separates a genuine ownership check from a signature-phishing attempt built to imitate one.

You will learn the exact wording of the EU threshold that triggers verification, what information already travels alongside your transfers, why message signing cannot move funds while a transaction signature can, why a customer's own say-so is explicitly not accepted, and why deliberately splitting a withdrawal to stay under a threshold is a serious mistake rather than a clever one.

The withdrawal that stops and asks who owns the address

You have used the same self-custody wallet for years. You paste its address into the withdrawal field of an exchange you have withdrawn from before, and instead of a confirmation you get a question: is this address yours, and can you prove it? Sometimes the interface wants you to sign a message. Sometimes it wants you to send a tiny amount from that wallet back to the exchange first. Sometimes it wants a name and a country for the person who owns it.

Two reactions are both common and both wrong. The first is to assume the exchange has invented an obstacle, perhaps to keep your funds on its platform. The second is to assume the request must be an attack, because everything you have learned about crypto safety says that unsolicited requests to sign things are how wallets get drained. The truth is less dramatic: this is a compliance obligation that has arrived at ordinary retail withdrawals within the last couple of years, and it is spreading across jurisdictions. Understanding it is worth ten minutes, because you will meet it repeatedly, and because the version of it that is a scam is genuinely difficult to distinguish from the version that is not — unless you know precisely what the real one asks for.

Checklist

  • Ownership checks on withdrawals are a compliance requirement, not an obstruction tactic.
  • The three common forms: sign a message, send a micro-transfer, or supply recipient details.
  • The requirement is spreading across jurisdictions, so expect it repeatedly.
  • The fraudulent imitation of this request is the specific risk to learn.

What the rule actually requires, and what it does not

The underlying idea comes from the anti-money-laundering standard usually called the travel rule: information about the sender and recipient must travel alongside a transfer, so that regulated institutions are not moving value between anonymous parties. It is not new to crypto. In the United States, the long-standing travel rule provision at 31 CFR 1010.410(f) requires a transmittor's financial institution to include, in transmittal orders of 3,000 dollars or more, the transmittor's name, account number and address, the identity of the transmittor's financial institution, the amount and execution date of the order, and the identity of the recipient's financial institution — along with recipient details to the extent they are received. What has changed is that this logic now applies to crypto-asset transfers, and that crypto has something conventional finance does not: an address that belongs to no institution at all.

That gap is what the self-hosted wallet provisions address. In the European Union, Regulation (EU) 2023/1113 states at Article 14(5) that in the case of a transfer of an amount exceeding EUR 1 000 to a self-hosted address, the crypto-asset service provider of the originator shall take adequate measures to assess whether that address is owned or controlled by the originator. Article 16(2) imposes the mirror-image duty on incoming transfers: above the same threshold, the beneficiary's provider must assess whether the self-hosted address is owned or controlled by the beneficiary. The regulation also specifies what accompanies transfers between providers, including the originator's name and distributed ledger address together with an address, official personal document number and customer identification number, or alternatively date and place of birth, and the beneficiary's name, distributed ledger address and account number.

It is worth being precise about what this does and does not mean, because both exaggerations circulate. It does not make self-custody illegal, and it does not require you to explain what you intend to do with your own money. It does not, in itself, hand your wallet address to the public. What it does mean is that a regulated provider must be able to say who its customer is and, above the threshold, must have taken a real step to establish that the destination is that customer's own wallet rather than an unidentified third party's. It also means your identifying information travels with transfers between regulated providers, which is a genuine privacy consequence and one you should factor in rather than discover later. The thresholds and specifics differ by jurisdiction — the EUR 1 000 figure is the EU's, the 3,000 dollar figure is the US rule for funds transfers — so the applicable line depends on where your provider is regulated, not on where you happen to be sitting.

Checklist

  • The travel rule predates crypto: US recordkeeping applies at 3,000 dollars and above.
  • EU Article 14(5): above EUR 1 000, the provider must assess whether a self-hosted address is owned or controlled by its customer.
  • Article 16(2) applies the same duty to incoming transfers from self-hosted addresses.
  • Identifying information accompanies transfers between regulated providers.
  • The rule does not prohibit self-custody or require you to justify your intentions.
  • Thresholds differ by jurisdiction; your provider's regulator sets the line that applies to you.

The two verification methods you will actually be asked for

In practice, the request narrows to a short list. The European Banking Authority's Travel Rule Guidelines, which have applied since 30 December 2024, set out which approaches are acceptable and require at least one of them to be used. The compliance firm Notabene, in its analysis of those guidelines, summarises the permitted options as advanced analytical tools, unattended verification such as displaying the address, attended verification involving live interaction with the customer, sending a predefined amount from the wallet to the provider, and signing a specific message in the wallet software; the exact list a given provider offers you will be narrower than that. One point in the framework does more work than the rest: a customer's own declaration that the wallet is theirs does not qualify. That is why you cannot simply tick a box, and it is the reason the process feels heavier than it looks like it should be.

Message signing is the method most people meet, and it is worth understanding because its safety properties are not obvious. Your wallet can produce a cryptographic signature over an arbitrary piece of text, proving that whoever produced it holds the private key for that address. A plain message signature is not a transaction: it does not move funds, does not grant anyone permission to move funds, costs no network fee, and is not broadcast to the blockchain. You are demonstrating control, not exercising it. This is why the method is acceptable to regulators and why, used correctly, it is harmless.

The micro-transfer method — often called a satoshi test — asks you to send a small predefined amount from the self-hosted wallet to the provider, which demonstrates control by demonstrating spending. It is equally legitimate and has one specific hazard worth naming: it involves an actual transfer to an address that you must be certain came from your own logged-in account rather than from a message someone sent you. The amount is trivial, so the risk is not the amount; the risk is that a fraudulent version of this instruction sends your test transfer, and then perhaps a much larger one, to an attacker's address.

You may also be asked for the recipient's name and whether the destination is your own wallet or someone else's. That is the same rule operating at the information level rather than the cryptographic one, and answering it honestly is straightforward. Answering it dishonestly to make a transfer go through is a different matter entirely and is not a shortcut worth taking.

Checklist

  • EBA guidelines have applied since 30 December 2024 and require at least one verification method.
  • A customer's self-declaration alone is explicitly not sufficient.
  • Message signing proves key control without moving funds or paying a fee.
  • A plain message signature is not broadcast and executes nothing.
  • The micro-transfer method proves control by spending a trivial amount.
  • The only real hazard in a satoshi test is sending it to an address you did not obtain from your own account.
  • Recipient-name questions are the same rule at the information level.

The dangerous resemblance: this is also a phishing template

Here is the problem that makes this topic a safety subject rather than a bureaucratic one. The most effective wallet-draining technique in circulation is signature phishing: an interface asks you to sign something, the request looks procedural, and what you actually authorise is a transfer or an open-ended spending permission over your tokens. Research into permit-style phishing has documented how effectively these requests are dressed up as routine verification steps. A compliance-driven ownership check is, from your side of the screen, the same gesture — connect wallet, approve a signature — performed for an entirely legitimate reason. As these checks become normal, the instinctive alarm that used to accompany any signing request fades, and that fading is exactly what an attacker needs.

Three tests separate them, and they work together. The first is direction of contact. A genuine verification step is one you encounter because you initiated a withdrawal, inside a session you opened by typing the exchange's address yourself. It does not arrive as an email, a chat message, a support agent contacting you first, or a link. The FBI's Internet Crime Complaint Center has repeatedly warned about criminals impersonating cryptocurrency exchange support to reach victims first, and that structural rule holds here without modification: real processes answer channels you opened.

The second test is the content of what you are signing. A legitimate ownership check asks for a signature over a plain text message — often containing your account reference, the address, and a timestamp — and it should be readable. If the request is for a transaction, an approval, a permit, or anything your wallet warns will let another party spend your tokens, it is not an ownership check regardless of what the surrounding page says. Wallets increasingly distinguish these visually; read the warning rather than dismissing it, and refuse anything you cannot read.

The third test is what is being asked for beyond the signature. No verification process of any kind requires your recovery phrase or private key. None. A genuine check needs a signature or a small transfer, both of which you perform yourself in your own wallet; nobody needs to hold your keys to confirm that you hold them. Any request that reaches for the phrase has answered the question of what it is. And if the process asks you to send a test amount, take the destination address from the withdrawal screen inside your logged-in account, never from a message, and never from a page you reached by clicking a link.

Checklist

  • Signature phishing and ownership checks look identical from the user's side.
  • Direction of contact: a real check appears because you started a withdrawal yourself.
  • IC3 has warned about criminals impersonating exchange support and contacting victims first.
  • A real check signs readable plain text, not a transaction, approval or permit.
  • Heed the wallet's warning when a signature would grant spending permission.
  • No legitimate verification ever needs your recovery phrase or private key.
  • Take any test-transfer address from your own logged-in account, never from a message.

A routine that keeps withdrawals boring

The practical version of all this is short. Before you move a meaningful amount off an exchange, check what that provider requires for the destination type and size you have in mind, so the requirement is something you planned for rather than something that ambushes you mid-withdrawal. Do the verification once, from inside your own session, and keep a note of which addresses you have already verified with which provider — most will remember, and repeat withdrawals to a verified address usually pass without friction.

Expect withdrawals to a third party's self-hosted wallet to be harder than withdrawals to your own, because the rule is specifically concerned with whether the destination belongs to the customer. Paying a contractor, sending money to a family member, or funding someone else's wallet may require additional information or may simply not be supported by that provider. That is worth discovering before you promise someone a payment on a deadline.

One thing to avoid firmly: do not break a withdrawal into several smaller ones to stay below a reporting or verification threshold. Deliberately structuring transactions to evade a reporting requirement is a serious offence in many jurisdictions and is treated as an indicator of exactly the behaviour these rules exist to detect — it converts an ordinary transfer into something that looks like concealment, and it can result in frozen funds and account closure at best. If the threshold is inconvenient, the correct response is to complete the verification, not to route around it.

Finally, hold the privacy consequence honestly rather than pretending it away. Once a self-hosted address has been verified and associated with your identity at a regulated provider, that link exists in that provider's records, and information about transfers between providers travels with them. That is a real cost of using regulated on-ramps and off-ramps, and it is a reason to think about which addresses you use for which purposes — not a reason to hide anything, but a reason to be deliberate. Using a dedicated address for exchange withdrawals rather than one you also publish elsewhere is a small, entirely legitimate piece of hygiene that keeps your on-chain activity from being more legible than you intended.

Checklist

  • Check the provider's requirements before you need to withdraw, not during.
  • Verify once from inside your own session, and note which addresses are already verified.
  • Withdrawals to someone else's self-hosted wallet may need extra information or be unsupported.
  • Never split a withdrawal to stay under a threshold — structuring is a serious offence.
  • Verification links your identity to that address in the provider's records.
  • Use a dedicated address for exchange withdrawals rather than one you publish publicly.

Authority sources used

Outbound links are included for verification and entity authority, not decoration.

FAQ

Why does my exchange want proof that I own a wallet I already control?

Because above a threshold it is required to establish that the destination belongs to its customer rather than to an unidentified third party. In the European Union, Regulation (EU) 2023/1113 provides at Article 14(5) that for a transfer exceeding EUR 1 000 to a self-hosted address, the originator's crypto-asset service provider must take adequate measures to assess whether that address is owned or controlled by the originator, with Article 16(2) imposing the equivalent duty on incoming transfers. The underlying principle is not new — the United States has long required identifying information to accompany funds transfers of 3,000 dollars or more under 31 CFR 1010.410(f) — but crypto introduced something conventional payments do not have, namely a destination that belongs to no institution and can therefore be checked by no one. Verifying that you control the address is how that gap is closed. It is not a judgement about you, and it does not restrict self-custody; it is a step your provider is obliged to take before releasing funds to an address it cannot otherwise attribute.

Is signing a message safe? Could it move my funds?

A plain message signature cannot move funds, and understanding why is the most useful thing in this whole subject. Your wallet can sign an arbitrary piece of text with the private key for an address, producing proof that the signer holds that key. That proof is not a transaction: it is not broadcast to the blockchain, it costs no network fee, and it authorises nothing. You are demonstrating control rather than exercising it. The danger lies entirely in what you are actually signing. Signature phishing works by presenting something that looks like a routine verification prompt but is in fact a transaction or a token approval that grants an attacker permission to spend your assets, and research into permit-style phishing has documented how convincingly these are disguised. So the rule is to read what the wallet says it is signing, and to refuse anything that is a transfer, an approval or a permit, or that your wallet warns will let another party move your tokens. A genuine ownership check signs readable text — typically your account reference, the address and a timestamp — and nothing else.

What is a satoshi test, and is it risky?

It is the alternative verification method: instead of signing a message, you send a small predefined amount from the self-hosted wallet to the provider, proving control by demonstrating that you can spend from the address. The European Banking Authority's Travel Rule Guidelines, applicable since 30 December 2024, require at least one acceptable verification method to be used, and analysis of those guidelines lists sending a predefined amount from the wallet alongside message signing, live customer interaction and analytical tools. The amount involved is trivial, so the money at stake is not the risk. The risk is the destination. Because this method involves a real transfer, a fraudulent imitation of the instruction sends your test to an attacker's address, and a convincing follow-up may then ask for something much larger. The defence is procedural rather than technical: obtain the destination address from the withdrawal screen inside an account session you opened yourself, never from an email, a chat message or a link, and never continue a verification process that reached you rather than the other way around.

Can I still send crypto to someone else's self-hosted wallet?

Usually yes, but expect more friction than sending to your own, because the rule's specific concern is whether the destination belongs to the customer. When it does not, your provider generally needs information about the recipient rather than proof of your control — the EU regulation lists the beneficiary's name, distributed ledger address and account number among the information that accompanies transfers. Some providers handle third-party destinations routinely with a form; some restrict them; some support them only up to certain amounts. What matters practically is discovering your provider's position before you commit to paying someone by a deadline, because finding out during the transfer is how people end up improvising. Two things not to do: do not describe someone else's wallet as your own to make the transfer go through, and do not break the payment into pieces to stay under a threshold. Both convert an ordinary transaction into something that looks like concealment, which is a far worse outcome than a delayed payment.

A support agent contacted me and asked me to verify my wallet. Is that legitimate?

Treat it as fraudulent and stop, regardless of how procedural it sounds. The decisive test is direction of contact: a genuine verification step exists inside a withdrawal you started, in a session you opened by typing the exchange's address yourself. It does not arrive as an unsolicited email, message or call, and no legitimate provider needs to walk you through it live. The FBI's Internet Crime Complaint Center has warned repeatedly about criminals impersonating cryptocurrency exchange support to reach victims first, and this particular request is an unusually attractive template for them precisely because the real thing now exists and users have learned to expect it. Two absolutes sit behind the test. No verification process of any kind requires your recovery phrase or private key, because proving you hold a key never involves handing it over. And no verification process requires you to sign a transaction or approval — only readable text. If a request violates either, it is not a verification step whatever the page around it claims. When in doubt, close everything, open a new browser tab, type the exchange's address yourself, and see whether anything is genuinely waiting for you.

Does this mean my wallet address is now linked to my identity?

At that provider, yes, and it is more honest to plan around this than to hope otherwise. Once you verify a self-hosted address, the association between your identity and that address exists in the provider's records, subject to whatever record-retention obligations apply to that provider, which in several jurisdictions run to years rather than months. In addition, information about transfers between regulated providers travels with the transfer itself: the EU regulation specifies the originator and beneficiary details that must accompany crypto-asset transfers between service providers. None of this makes your holdings public, and none of it means the address is published. But it does mean that a regulated on-ramp or off-ramp is a point at which your on-chain activity and your legal identity meet, and that a single address used for everything makes far more of your activity legible from that point than you may intend. The proportionate response is deliberate address hygiene: use a dedicated address for exchange withdrawals rather than one you also publish on a profile, a donation page or a public invoice.