Two separate security incidents this month—one involving millions of driver’s licenses and another targeting identity verification requests—are forcing a difficult question for the crypto industry and beyond: if KYC is supposed to make financial systems safer, why does it so often create high-value data “honeypots” for criminals?
According to Reuters, the FBI is investigating reports that more than 153 million US and Canadian driver’s licenses were exposed online, with the leaked IDs reportedly ending up on a dark web identity service called Nexus. In a separate case, fintech Revolut disclosed that it was tricked into releasing sensitive customer information, including passports and verification selfies, and that a hacker has been drip-feeding documents belonging to 680 customers while attempting to secure a 10,000 Bitcoin ransom, as covered earlier by Cointelegraph.
Key takeaways
- Large-scale ID leaks show that storing copies of identity documents turns compliance systems into lucrative targets.
- Zero-knowledge (ZK) proofs could allow users to prove facts (such as being over 18) without handing over or storing the underlying documents.
- Developers argue adoption is held back less by cryptography than by compliance workflows, governance incentives, and interoperability standards.
- Even with ZK, privacy depends on who controls the credential and what database the proof is ultimately tied to.
- Regulatory guidance is often interpreted by institutions in ways that lead them to “over-collect” and retain more data than necessary.
From identity verification to identity hoarding
KYC programs were built around a straightforward workflow: institutions collect a customer’s passport or driver’s license, record key fields, and store the evidence of the check. That model is useful for audits, but it also scales risk. As more vendors and compliance layers enter the process, more copies of sensitive identity data tend to accumulate across identity providers, databases, and service providers.
In the Revolut incident, the reported mechanism underscores how quickly the weakest link can become a procedural one. The hacker used email requests tied to what appeared to be a legitimate Italian law enforcement address to obtain KYC materials. Other observers point to regulatory requirements and enforcement pressure as part of why institutions can feel unable to refuse even when the request structure looks unusual.
One recurring theme in privacy-focused commentary is that “verification” and “retaining identity” are not the same thing. The more an organization treats them as interchangeable, the more it creates a problem that password resets can’t solve: once identity documents or their images are leaked, they can’t be regenerated like credentials.
Why zero-knowledge proofs are getting attention
For privacy advocates inside crypto, the alternative is well-defined. Zero-knowledge proofs let a user demonstrate that a statement is true—without disclosing the underlying data. In practice, that could mean proving a driver’s license confirms the holder is older than 18 without sending birth dates or transmitting an image of the license itself.
In this context, ZK is not presented as theoretical. Billions Network’s Evin McMullen, whose organization develops privacy-preserving digital identity and ZK solutions, told Magazine that the technology “works and is in production today,” but that deployment is constrained because compliance systems were designed around storing copies of documents rather than verifying claims cryptographically.
McMullen’s point is echoed by a broader framing: the impediment is not “the technology,” but the governance, standards, and institutional incentives that currently treat ID documents as the safest form of proof. As she described it, the challenge is a “governance and standards problem wearing a technology costume.”
Regulation, interpretation, and the interoperability problem
The European Union is already moving toward privacy-preserving age verification concepts in its digital identity and age verification design. According to the European Commission’s Digital Identity Wallet materials, the system supports selective disclosure—allowing users to reveal only what is needed for a given transaction—while also incorporating privacy-preserving age verification approaches that do not require users to expose their full identity or exact date of birth.
Still, financial KYC deployment remains limited, and McMullen identifies two core blockers: regulation and the internal understanding of compliance teams. One specific mechanism she highlights is the way teams may equate “seeing the ID” with “keeping the ID,” leading organizations to over-collect because it is perceived as safer under scrutiny from auditors and regulators.
Interoperability is the second major hurdle. Proofs only help if the party relying on them can validate them without repeatedly contacting whoever issued the credential. That requirement pushes the industry toward shared standards—something that is difficult to achieve when different regions, institutions, and identity providers follow distinct implementations.
ZK won’t automatically erase every risk
While ZK can reduce the need to transmit and store sensitive documents, it does not magically solve identity security on its own. Efrat Fenigson, host of You’re The Voice, emphasized a critical dependency: what the ZK credential is bound to. In her view, the incentive structure often points toward control rather than privacy—because proving a fact (like being over 18 or not being on a sanctions list) may still result in the proof being linked to an account inside someone else’s database.
That distinction matters because it determines where the real concentration of power and data risk sits. If a privacy-preserving proof is still tied to a centrally controlled identity record, users may remain dependent on a centralized intermediary—meaning the system’s security posture can still be undermined by failures or attacks against that intermediary.
What the rules require—versus what institutions do
Another tension highlighted by industry participants is the gap between regulatory requirements and operational habits. The Financial Action Task Force (FATF)’s guidance on digital identity focuses on how digital ID systems can be used to conduct customer due diligence, rather than mandating that institutions rely on physical documents as raw evidence.
FATF guidance also functions through a risk-based framework, leaving countries to implement standards through local legal structures. In that light, McMullen argues that in many regimes, the rule is often to verify identity and retain a record that verification occurred—not necessarily to keep permanent images or raw documents forever.
However, she also notes that the guidance can be ambiguous enough that institutions default to the most conservative approach: storing everything because compliance teams believe auditors and examiners will accept it. Susie Violet Ward, director and co-founder of Bitcoin Policy UK, characterizes the broader issue as the unnecessary conflation of identification with surrendering identity data.
Ward also frames the regulatory instinct in practical terms: more information is often treated as more control, and therefore more safety. But the recent evidence of massive breaches suggests that, at scale, “more data retained” can translate into more catastrophic exposure.
For readers watching this space, the next signal to track is whether compliance frameworks evolve from document hoarding toward verifiable attestations—especially ones that support selective disclosure and clearer credential binding. The technology is increasingly capable; the open question is how quickly regulation, standards, and institutional incentives will change to match what the cryptography can already deliver.





Be the first to comment