Sanctuary Research

The Markets in Crypto-Assets Regulation (MiCA) is not new — it was adopted in 2023. But enforcement of the Travel Rule provisions begins July 1, 2026. That is the date that matters.
For every crypto transfer, the originating VASP must collect and transmit:
This applies to all transfers, not just those above a threshold. The EUR 1,000 threshold from the original FATF guidance does not apply under MiCA — all transfers are in scope.
Counterparty VASP identification. When your customer sends crypto to an external address, you need to determine whether the receiving address belongs to a regulated VASP. This requires an address attribution database.
Data collection workflow. If the recipient is a VASP, you need to transmit originator data. If the recipient is an unhosted wallet, you need to perform enhanced due diligence above EUR 1,000.
Record keeping. All Travel Rule data must be retained for 5 years. Every transfer must be auditable.
Most exchanges do not have address attribution databases. They cannot tell whether an external address belongs to Binance, a DEX router, or a personal wallet. Without this capability, Travel Rule compliance is impossible.
This is exactly the problem AML screening tools solve. A wallet check returns entity attribution — whether the address belongs to a known exchange, bridge, or DeFi protocol. That attribution is the foundation of Travel Rule compliance.
---
Sanctuary identifies entities across 12 chains. Check any address for free: @sanctuaryapp_bot