Invest2 publishers3 min readPublished
Hester Peirce argues in her final SEC weeks that bigger KYC files make criminals harder to find
Hester Peirce used her penultimate week as an SEC commissioner to urge replacing bulk KYC collection with zero-knowledge proofs of eligibility. She filed no proposal and spoke for herself, so the collection rules she criticized stay as written.
The Investor · Invest desk

What happened
- Hester Peirce told SIFMA's Digital Assets Conference in New York on Wednesday that KYC and anti-money-laundering rules rest on a flawed premise that more data on more people exposes criminals.
- Revolut recently exposed customers' passports and full Bitcoin transaction histories after it fulfilled a fraudulent government data request, Decrypt reported.
- A week before the speech, the SEC issued an Innovation Exemption letting tokenized securities trade on crypto networks through automated market makers.
- Peirce said the views were her own and might not be adopted by the Commission, and no proposal or guidance was filed with the speech.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost A firm that adds zero-knowledge checks now pays for them on top of full KYC collection, because the speech lifted no obligation to gather and keep the identity file.
- exposure Crypto holders whose passports sit with exchanges and their vendors stay exposed to the kind of leak behind wrench-attack fears for as long as each firm keeps its own copy.
- constraint With its author gone about a week after the speech, the idea needs a sponsor among the remaining commissioners to get past the conference stage.
Even her central line comes in two versions. Decrypt quoted Peirce as saying, "The bigger haystack, however, makes it harder to find the needles" [2]. Cryptopolitan printed "But the bigger data haystack, in turn, becomes less likely to reveal any needles" [3]. Decrypt also quoted her on where the current path leads: to "more data collection, more intermediary surveillance, more 'know your customer' requirements that turn our financial rails into a panopticon" [17].
Her alternative has two parts. A zero-knowledge proof can tell a counterparty that a person qualifies "without that counterparty knowing your name, income, or address," Peirce said [4]. Attribute-based credentials would confirm one fact, such as age or sanctions status, without exposing the rest [5]. The second part is about who stores the file. She suggested regulators let firms rely on a third party's identity check instead of each copying and storing the same sensitive records "across dozens of institutions" [6]. The verifier would issue cryptographic certificates that a user can move from platform to platform, according to Cryptopolitan [7].
I think the storage change matters more for breach exposure than the cryptography does. Today each new account can mean another stored copy of a customer's passport; under her model it would mean another certificate, with the file held once [2]. The Trezor leak came through a copy of that kind. A third-party vendor to the hardware wallet maker was breached, exposing tens of thousands of customers and later feeding phishing attacks, Decrypt reported [9]. Both outlets link such leaks to "wrench attacks," in which criminals physically go after crypto holders whose wealth and identities are exposed [10]. Peirce put the private companies hired to collect customer data on her list of "data maximalists," next to officials, according to Cryptopolitan [16].
As cover for a compliance team, the speech is thin. Peirce said it came in her "penultimate week" as a commissioner [13]. From here the argument can leave with her, Chairman Paul Atkins can take it up, or firms can build proof layers on breach exposure alone. Peirce tied her case to the exemption the Commission issued a week earlier and said Atkins sees it as a stepping-stone [15].
I think the idea will keep turning up in speeches long before it reaches rule text. The one related Commission action she cited concerns where tokenized securities trade, and identity checks are a separate question [14]. The case against that view rests on her record and the Commission's. Peirce, on the Commission since 2018 [18], pressed the same theme at an August 2025 blockchain conference [19], and the week-old exemption shows the Commission will write crypto-specific relief [14]. If rule text or an exemption that accepts a proof of eligibility in place of a stored file appears after she leaves, I have undersold the speech.
What to watch
- Whether Chairman Paul Atkins repeats the attribute-based verification argument in his own speeches after Peirce leaves.
- The next breach disclosure at a crypto exchange or KYC vendor, and how many institutions turn out to hold copies of the same customer records.
- Who fills Peirce's seat, and whether the nominee has said anything on the record about customer identity data.