Buy now

On October 1, 2026, Brazil switched on a self-custody reporting rule that treats a transfer to your own wallet as something a regulator wants to hear about. Under Resolution 588, institutions supervised by the Banco Central do Brasil must report any virtual-asset transfer worth 10,000 USD or more that moves to or from a wallet the user controls directly. Nothing in the rule asks a single thing of the person holding the keys. What changes is how much of that person's activity reaches a government desk without them being asked first.

What Resolution 588 asks for

The obligation sits on the regulated business, which is how nearly every rule in this area is built. When a Brazilian exchange or bank sends 10,000 USD of crypto to a self-custodied address, or takes that much in from one, the transfer has to be reported to Coaf, Brazil's financial intelligence unit, by the next business day. The central bank's reasoning was about visibility: it said self-custody can reduce the information available for monitoring and risk assessment, since a wallet under a user's direct control leaves none of the internal records that a supervised custodian keeps as a matter of course.

There's a detail worth holding onto here. The threshold is a trigger for paperwork rather than a ceiling on what you're allowed to move. Brazilians can still hold their own keys, and they can still transfer more than 10,000 USD; somebody else now files a form when they do.

What it doesn't do

Read past the headlines and the rule turns out to be narrower than its framing suggests. It doesn't register your wallet, licence your device, or require you to declare coins you never moved through a supervised institution. Two people transacting between their own wallets, with no regulated business standing in the middle, are outside its reach for the ordinary reason that a rule can only be enforced against an entity that holds a licence.

That limit is structural rather than a concession, and it explains why these rules keep landing on exchanges instead of on wallets. Reporting obligations attach to businesses. A signing device in a drawer has no compliance department, no licence to lose, and nothing to file.

The US proposed almost exactly this, then dropped it

Americans reading about Brazil may find the shape of the rule oddly familiar, because the Treasury floated its own version and then walked away from it. In December 2020, FinCEN published a proposal that would have required banks and money services businesses to keep records and verify their own customer's identity for transfers above 3,000 USD involving an unhosted wallet, and to file reports naming each counterparty and their street address once such activity passed 10,000 USD within 24 hours. The numbers should look familiar: Brazil has now implemented the reporting half of that idea at the higher of the two figures.

The American proposal never took effect. After heavy industry opposition, the Treasury withdrew it without finalising it, and the objection that carried most weight was practical rather than philosophical: an exchange can verify its own customer, but it cannot meaningfully verify who sits behind an address it has never interacted with.

What remains in force in the United States is the older and narrower travel rule, which requires financial institutions to collect and pass along sender and recipient details for transmittals of 3,000 USD or more. That obligation is about transfers between institutions. It stops well short of asking an exchange to identify the human behind a self-custodied address.

What a reporting rule can and cannot see

The gap between what gets filed and what gets understood is wider than most coverage admits. A report says that an account holder moved a sum to an address on a date. It carries no information about what happened afterwards, because once coins sit behind keys you generated, further movement leaves no trail at any supervised institution.

This cuts in two directions at once, and both deserve saying plainly. Holders who value privacy should understand that the withdrawal itself is the visible event, and a large one is now logged in Brazil by default. Anyone worried that reporting equals confiscation should note the equally clear point that a filing is an entry in a database and gives nobody the ability to move your coins.

Why the withdrawal is the moment that matters

If the visible event is the transfer out of an exchange, then the thing worth getting right is what happens at the other end of it. Moving 10,000 USD to an address you control is only an improvement if that address is backed by a key nobody else has and a recovery path you have tested.

On Ryder One the private key is generated inside an EAL6+ certified Infineon SLC38 secure element and never leaves the chip, so there is no copy sitting on a phone or a laptop for malware to find. Each transaction appears in readable detail on the 1.6-inch AMOLED touchscreen before you approve it, and the button that authorises a signature is wired directly to the secure element, which means no software path can sign without a deliberate press. Communication is NFC only, with no Bluetooth radio, no USB data transfer and no Wi-Fi, so the device is unreachable except while you're holding it against your phone. The receiving address is shown on the device screen for verification before you copy it into a withdrawal form, which is the defence against clipboard-hijacking malware that swaps an address between the moment you copy it and the moment you paste it.

The backup question a reporting rule never touches

Regulators care about where coins go. Nobody at a central bank has an interest in whether you can still reach yours in ten years, which makes recovery the part of self-custody that stays entirely yours to solve.

A written seed phrase on paper keeps the words away from every network and then has to survive damp, fire, and however many house moves the next decade brings. Stamping them into steel answers those hazards well and leaves the whole position depending on one object staying both intact and unfound, which improves your odds without changing the shape of the risk. TapSafe Recovery was built to take that single point of failure out of the design: half of what a restore needs lives on the Recovery Tag, and half travels with your paired phone, held encrypted in your own iCloud or Google Drive rather than on the handset itself. Neither half discloses anything usable on its own, and the two together rebuild the wallet. Recovery Contacts are optional, hold a quarter share each, and see no balances or addresses at any point. The words themselves stay reachable on the device as a last resort under the BIP-39 standard, so other hardware remains an option whenever you want it.

Where that leaves you

One country has decided that a transfer to a user-controlled wallet is worth logging, and the country that thought of it first decided the idea was unworkable and shelved it. Both facts are useful. Rules of this kind keep arriving at the exchange rather than at the device, they keep leaving self-custody itself alone, and they keep making the moment of withdrawal the point where your own arrangements start carrying the weight.

Ryder One is 149 USD for the Starter Combo and 179 USD for the Super Safe Combo, with a Recovery Tag, wireless charger and pouch in the box. The firmware has been audited by Halborn, with the full report public, and setup takes about 60 seconds across three NFC taps.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More