Self-custodial wallet / non-custodial software in Ecuador
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is conditionally permitted in Ecuador with a local entity, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- Registration with UAFE as an Obligated Subject (Sujeto Obligado) under Resolución No. UAFE-DG-2022-0001, which explicitly designates VASPs as obligated subjects.
- Customer identification and verification (CDD): obtain full name, date of birth, nationality, identification number, address, contact information, occupation/activity for natural persons; legal name, registration number, incorporation date, legal form, address, directors/partners/shareholders for legal entities.
- Beneficial ownership identification and verification for legal entity customers.
- Purpose and intended nature of the business relationship must be understood and documented.
- Ongoing transaction monitoring to ensure activity is consistent with customer risk profile.
- Risk assessment framework: develop and implement policies to identify, assess, and mitigate ML/TF risks.
- Enhanced due diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, and anonymous technologies.
- Suspicious transaction reporting (STR): any transaction or attempted transaction that raises suspicion of ML/TF must be reported to UAFE via the SARLAFT electronic system, regardless of amount.
- No tipping-off: prohibited from disclosing to customer or third parties that a report has been or will be submitted.
- Record-keeping: transaction records including amount, type of virtual asset, sender/recipient addresses, timestamps, fiat equivalents, transaction hashes.
- Internal policies and procedures for identifying, evaluating, and reporting suspicious transactions.
Key Restrictions
- The publisher must not hold, control, or have access to user private keys or funds — this is definitional to the self-custodial model.
- The software must not facilitate the use of virtual assets as a means of payment or alternative currency — BCE Resolution 014-2014-M prohibits crypto as legal tender, and financial institutions are barred from facilitating crypto transactions.
- If the wallet software integrates token sales or features that could be classified as securities offerings (e.g., staking pools marketed as investments, token swap protocols with profit-sharing), it may trigger SCVS securities registration, prospectus, and disclosure requirements.
- Pure non-custodial wallet software publishing likely does not trigger VASP classification under UAFE Resolution UAFE-DG-2022-0001, which focuses on 'Virtual Asset Service Providers' — entities providing exchange, transfer, or custody services, not software publishers.
- Any integration with Ecuadorian financial institutions may be prohibited if the software enables crypto-as-payment functionality.
Key Risks
- Regulatory ambiguity: Ecuador has no specific regulatory classification for non-custodial software publishers — it remains unclear whether publishing wallet software alone constitutes a 'VASP' under UAFE Resolution UAFE-DG-2022-0001.
- Enforcement risk from BCE: Resolution 014-2014-M broadly prohibits crypto use as a means of payment; a wallet that facilitates payment to merchants could be targeted as facilitating an illegal activity.
- Securities classification risk: if the wallet software integrates DeFi or staking features that create an 'expectation of profit' from third-party efforts, the software or its tokens could be deemed securities under SCVS criteria.
- Low legal certainty: the lack of crypto-specific software publishing laws means operators depend on analogies to traditional financial regulations, creating unpredictability.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Superintendencia de Compañías, Valores y Seguros (SCVS): The superintendency responsible for regulating companies, securities, and insurance. This body would classify tokens as securities.
Banco Central del Ecuador (BCE): The Central Bank, which has historically taken a very strict stance against cryptocurrencies being used as means of payment.
Security Tokens: These are explicitly designed to represent traditional securities such as shares, bonds, or interests in a fund. They confer rights like dividends, voting rights, profit sharing, or a claim on assets.
Investment Tokens: Tokens that are primarily sold to raise capital for a project or company, where purchasers expect a return on their investment due to the efforts of the issuer or a third party. This includes tokens that grant a share of future revenues, profits, or are marketed with promises of appreciation based on the success of a venture.
Certain Utility Tokens: While "pure" utility tokens that solely provide access to a product or service at the time of purchase might not be considered securities, if they are:
Payment Tokens / Cryptocurrencies (e.g., Bitcoin, Ethereum): These are generally not considered "securities" in the traditional sense, but their use as legal tender or alternative currency is explicitly prohibited by the Banco Central del Ecuador. Financial institutions are barred from facilitating transactions with them. This prohibition makes their status in Ecuador highly problematic, regardless of whether they are securities.
Stablecoins: While the SCVS focuses on securities, it's worth noting that the BCE would likely view any stablecoin as problematic if it attempts to function as a means of payment, especially if it is not backed by the USD or if its backing is not transparent and regulated by Ecuadorian authorities.
Registration with SCVS: Mandatory registration of the offering and the issuer with the Superintendencia de Compañías, Valores y Seguros.
Prospectus Requirements: Preparation and submission of a detailed prospectus containing comprehensive information about the issuer, the project, financial statements, risks, and the rights associated with the token.
Information Disclosure: Ongoing periodic and material event disclosures to the SCVS and the public.
Unidad de Análisis Financiero y Económico (UAFE) - The Financial and Economic Analysis Unit.
Ley Orgánica de Prevención, Detección y Erradicación del Delito de Lavado de Activos y Financiamiento de Delitos (Organic Law for the Prevention, Detection, and Eradication of the Crime of Money Laundering and Financing of Crimes)
Resolución No. UAFE-DG-2022-0001 (Resolution No. UAFE-DG-2022-0001)
Continuously monitor customer transactions and activities to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Develop and implement a risk assessment framework to identify, assess, and mitigate ML/TF risks.
Apply enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex or unusually large transactions, new technologies and products that favor anonymity).
Reporting Obligation: Any transaction, attempted transaction, or activity that raises suspicion of money laundering or terrorist financing, regardless of the amount, must be reported.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a report has been or will be submitted to UAFE.
Reporting Mechanism: Reports are typically submitted through UAFE's electronic system (SARLAFT system).
Internal Policies: VASPs must have internal policies and procedures to identify, evaluate, and report suspicious transactions.
Transaction Records: All details of virtual asset transactions (e.g., amount, type of virtual asset, sender/recipient addresses, timestamps, fiat currency equivalents, transaction hashes).
Legal Basis: Resolution 014-2014-M (or its subsequent reiterations) issued by the Monetary and Financial Policy and Regulation Board (Junta de Política y Regulación Monetaria y Financiera) and implemented by the Central Bank of Ecuador (BCE). This resolution, dated July 28, 2014, effectively banned private cryptocurrencies, stating that they are not recognized as legal tender and cannot be used as a means of payment within the country.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A self-custodial wallet software publisher that never holds user private keys likely does not trigger VASP classification under UAFE's Resolution UAFE-DG-2022-0001, but faces significant legal uncertainty; the publisher must avoid facilitating crypto-as-payment (barred by BCE Resolution 014-2014-M), avoid features that could constitute securities offerings (SCVS), and may still need to consider AML registration if the software is considered a VASP activity, though this is unclear.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?