Overview
- Peirce told SIFMA’s Digital Assets Conference on September 23 that firms should use verifiable credentials and zero-knowledge proofs so platforms receive confirmations — for example, that a user is over 18 or not on a sanctions list — instead of collecting passports, addresses, and transaction histories.
- She framed the remarks as her personal policy view and did not propose a rule, and current legal duties under the Bank Secrecy Act and SEC broker-dealer recordkeeping still require firms to verify identities and keep records.
- Peirce said the current model creates “ever bigger data haystacks” that raise breach and extortion risks, citing recent leaks and vendor breaches that exposed passports, account histories, and customer contact data.
- Technical and operational hurdles remain, including how to check credential expiration and revocation, confirm issuer reliability, prevent stolen-wallet fraud, and preserve transaction monitoring and suspicious-activity reporting.
- Regulators and staff have already studied the tools — the President’s Working Group discussed zero-knowledge proofs in 2025, SEC Crypto Task Force met with Aztec in July, and FinCEN issued limited guidance on government digital credentials on September 8 — but formal rules to let proofs replace stored identity records are not yet settled.