Summary
- Outgoing SEC Commissioner Hester Peirce spoke at SIFMA's Digital Assets Conference, advocating for the use of zero-knowledge proofs and attribute-based credentials as alternatives to traditional KYC processes.
- She criticized the current KYC/AML framework for creating "ever bigger data haystacks," which complicates the detection of illegal activities, and cautioned against the mindset of "data maximalists" who believe that more data collection is inherently beneficial.
- Her comments come in light of recent KYC data breaches, such as Revolut's exposure of sensitive customer information and Trezor's vendor-related data leaks, raising concerns over "wrench attacks" on crypto holders.
Hester Peirce, who is leaving her position as SEC Commissioner, is advocating for a reformed approach to how the financial sector addresses crime, emphasizing that the current focus on collecting personal data has resulted in large, vulnerable databases that could jeopardize the safety of individuals.
During her address on Wednesday at SIFMA's Digital Assets Conference in New York, Peirce contended that the existing know your customer (KYC) and anti-money laundering (AML) systems are based on a misguided belief: that gathering extensive information about individuals will aid in identifying criminals among law-abiding citizens.
"We build ever bigger data haystacks on the theory that we will find a needle or two inside," she remarked. "However, the larger the haystack, the more challenging it becomes to find those needles."
Peirce suggested that advancements in technology could provide a more effective solution. For instance, zero-knowledge proofs—a cryptographic technique that allows verification of a fact without revealing the underlying data—could enable individuals to demonstrate compliance with requirements without disclosing sensitive information. This technology is already utilized in private cryptocurrency networks and assets like Zcash.
She explained that a proof could enable a party to confirm that someone meets a requirement "without knowing your name, income, or address." Peirce urged for the establishment of a regulatory framework that supports such attribute-based verification, cautioning that the alternative would lead to increased data collection, more intrusive surveillance, and a KYC system that turns financial infrastructure into a "panopticon."
Her remarks come at a time when KYC data itself has become a potential risk. Recently, Revolut inadvertently disclosed customer passports and complete Bitcoin transaction histories after complying with a fraudulent government request, while hardware wallet manufacturer Trezor experienced breaches at a third-party vendor, compromising the data of tens of thousands of users and leading to subsequent phishing scams.
These incidents have intensified fears regarding "wrench attacks," where criminals specifically target cryptocurrency holders whose personal information and wealth have been exposed.
Known for her pro-crypto stance and critical view of the SEC's past "regulation by enforcement" approach, Peirce cautioned against what she referred to as "data maximalists" who assume that increased data collection is always advantageous.
She recommended that regulators allow companies to utilize third-party identity verification services, which would prevent the need for each institution to redundantly gather and store sensitive records across numerous organizations. Peirce has previously advocated for this approach, including during her remarks at an August 2025 blockchain conference. Her call for change is particularly poignant as she noted that this speech took place during her "penultimate week" as a commissioner.
