In Her Final Weeks, SEC's Peirce Calls for Ending the KYC 'Panopticon' - Decrypt
by Guillermo Jimenez · Decrypt · JoinIn brief
- Departing SEC Commissioner Hester Peirce argued at SIFMA's Digital Assets Conference that zero-knowledge proofs and attribute-based credentials could verify facts like age or sanctions status without exposing personal data, replacing invasive KYC collection.
- She said the KYC/AML regime builds "ever bigger data haystacks" that make needles harder to find, and warned against "data maximalists" who assume more collection is always better.
- The pitch lands amid recent KYC leaks: Revolut exposing passports and Bitcoin histories, Trezor's vendor breaches—that heighten "wrench attack" fears.
Departing SEC Commissioner Hester Peirce is making a case for using cryptography to overhaul how the financial system polices crime, arguing that regulators' hunger for personal data has built vast, hackable troves that endanger the very people they aim to protect.
Speaking Wednesday at SIFMA's Digital Assets Conference in New York, Peirce said the "know your customer" and anti-money laundering regime rests on a flawed premise: that collecting enough information on enough people will help authorities spot criminals hiding among the law-abiding.
"We build ever bigger data haystacks on the theory that we will find a needle or two inside," she said. "The bigger haystack, however, makes it harder to find the needles."
She argued that technology now offers a better path. Zero-knowledge proofs, a cryptographic method that verifies a fact without exposing the underlying data, could let someone prove they meet a requirement without handing over sensitive details. It’s the same technology that underpins private cryptocurrency networks and assets, such as Zcash.
A proof can tell a counterparty a person qualifies "without that counterparty knowing your name, income, or address," Peirce said, calling for a regulatory framework that encourages such attribute-based verification. The alternative, the regulator affectionately known as “crypto mom” argued, is “more data collection, more intermediary surveillance, more ‘know your customer’ requirements that turn our financial rails into a panopticon.”
The remarks land against a grim backdrop of KYC data itself becoming a liability.
BitcoinBTC · USD
$84,257+9.9%
24H7D1M1YYTD
Sep 17Sep 19Sep 21Sep 22Sep 24
$87.2k$83.6k$80.0k$76.4k
24h HighHigh$84,843
24h LowLow$82,941
VolVol$1.6B
Market projectionsOdds by Myriad
This weekAbove $84,000Above $84k56% chanceThis monthAbove $84,000Above $84k56% chance
→
Buy Bitcoin with USDT
Powered by Jupiter
$50$100$500
Buy
Price data by CoinGeckoCoinGeckoMore Bitcoin news and projections →
Fintech company Revolut recently exposed customers' passports and full Bitcoin transaction histories after fulfilling a fraudulent government data request, while hardware wallet maker Trezor suffered breaches at a third-party vendor that exposed tens of thousands of customers and later fueled phishing attacks.
Such leaks have heightened fears of "wrench attacks," in which criminals physically target crypto holders whose wealth and identities are exposed.
Peirce, long the SEC's most crypto-friendly voice and known for criticizing the agency's past "regulation by enforcement," warned against what she called "data maximalists" who assume more collection is always better.
She suggested regulators let firms rely on third-party identity verification rather than each independently copying and storing the same sensitive records "across dozens of institutions."
It's a theme Peirce has pressed before, including at an August 2025 blockchain conference. The pitch carries added weight now: she disclosed the speech came during her "penultimate week" as a commissioner.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
Your Email
Get it!
Get it!