# crypto-web3

Source: https://startwithidentity.com/verticals/crypto-web3/
Last updated: 2026-06-18
License: content by Start with Identity. Cite the source URL.

---

## The job identity does in crypto and Web3

Crypto sits between two identity worlds. Regulated exchanges and on-ramps must do rigorous KYC and AML like any financial institution, while the on-chain world is pseudonymous and self-custodial by design. The hard problems are verifying real people at onboarding, screening for fraud and sanctions, and handling wallet and key recovery without recreating the custodial single point of failure that crypto exists to avoid.

## The regulatory and compliance floor

The FATF Travel Rule requires identifying parties to certain transfers, KYC and AML obligations apply to exchanges and custodians, and the EU's MiCA framework formalizes requirements for crypto-asset service providers. GDPR governs the personal data collected during verification. Compliance pressure has risen sharply as the sector matures.

## The threat landscape here

Crypto is uniquely high-stakes: [account takeover](https://startwithidentity.com/glossary/account-takeover/) and [session/token theft](https://startwithidentity.com/breaches/infostealer-session-hijacking/) lead to irreversible theft, SIM-swap attacks target exchange accounts, and phishing and approval-draining scams are constant. Sanctions evasion and synthetic identities at onboarding are major compliance risks.

## What good looks like

- Strong [KYC and identity verification](https://startwithidentity.com/vendors/identity-verification/) at onboarding, with sanctions and AML screening.
- Phishing-resistant authentication and [passkeys](https://startwithidentity.com/guides/authentication/passkeys-101/) for exchange accounts, never SMS OTP alone.
- Thoughtful wallet and key recovery (social recovery, MPC) that avoids a custodial single point of failure.
- Emerging [verifiable credentials](https://startwithidentity.com/standards/verifiable-credentials/) and reusable KYC to reduce repeated proofing.

## Vendors and fit

Global KYC and AML fit [Sumsub](https://startwithidentity.com/vendors/identity-verification/sumsub/) and [Persona](https://startwithidentity.com/vendors/identity-verification/persona/); reusable and on-chain identity fits [Civic](https://startwithidentity.com/vendors/decentralized-identity/civic/); account authentication fits [Auth0](https://startwithidentity.com/vendors/ciam/auth0/) and peers in [CIAM](https://startwithidentity.com/vendors/ciam/).

## Common pitfalls

- Relying on SMS OTP for exchange accounts, the exact vector SIM-swap attacks defeat.
- Weak onboarding controls that let synthetic identities and sanctioned actors through.
- Recovery designs that quietly reintroduce custodial risk.

## Where it is heading

Reusable verifiable credentials promise lower-friction, privacy-preserving KYC across the ecosystem, while regulation under MiCA and the Travel Rule pushes exchanges toward bank-grade identity controls.
