← Regulations / Estonia / Operating Models / Self-custodial wallet

Self-custodial wallet / non-custodial software in Estonia

Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.

Conditional AI-Generated · Unreviewed

Self-custodial wallet is conditionally permitted in Estonia with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • No AML obligations attach to the software publisher itself because it does not provide custody, exchange, or transfer services — the user controls private keys and funds directly.
  • However, if the publisher also offers any ancillary service (e.g. fiat on-ramp, swap aggregator, or hosted recovery) that touches virtual currency custody or exchange, AML obligations under the MLTFPA and MiCA/CMA would apply.
  • If AML obligations were triggered (not applicable for pure non-custodial software): mandatory customer identification/verification, transaction monitoring, source-of-funds checks, and suspicious activity reporting to the FIU.
  • Anti-money laundering and terrorist financing prevention obligations are governed by the Money Laundering and Terrorist Financing Prevention Act (MLTFPA), which treats VASPs as financial institutions — but only if they provide regulated services.

Key Restrictions

  • Publishing non-custodial wallet software does not, by itself, constitute a regulated crypto-asset service under Estonia's Crypto Asset Market Act (CMA) or MiCA — provided the publisher never holds, controls, or has access to user private keys or funds.
  • If the software is distributed with any integrated service that involves custody, exchange, or transfer (e.g. an embedded swap feature routed through the publisher's liquidity), it would trigger CASP licensing requirements.
  • No geofencing or local-entity requirement applies to the software publisher as long as it is purely a software developer and not a service provider under MiCA/CMA.

Key Risks

  • Regulatory boundary risk: Estonian authorities (EFSA/FSA) may interpret integrated features (e.g., in-app swaps, staking, or recovery services) as constituting a 'crypto-asset service,' subjecting the publisher to full CASP licensing, capital requirements (€100k–€250k), and AML obligations.
  • Transition risk: Legacy FIU-registered VASPs must transition to FSA/EFSA licensing by July 1, 2026; a publisher claiming pure software status may be scrutinized if its product blurs the line between software and service.
  • Consumer-protection exposure: Even if unregulated, the publisher may face civil liability or regulator pressure if wallet users suffer losses (e.g., from code vulnerabilities or phishing) and Estonian authorities deem the publisher to have a duty of care.
  • MiCA scope creep: Under MiCA Article 3(1)(16), 'crypto-asset service' includes 'custody and administration of crypto-assets on behalf of clients' — publishing software alone is excluded, but any service layer added to the software could bring the operator into scope.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Crypto Asset Market Act (CMA): National implementation of MiCA (via )

licensing 60% confidence

EU MiCA Regulation (2023/1114): https://eur-lex.europa.eu/eli/reg/2023/1114/oj (via )

licensing 60% confidence

Money Laundering and Terrorist Financing Prevention Act (MLTFPA): https://www.riigiteataja.ee/en/eli/ee/Riigikogu/act/520062020002/consolide (via )

licensing 50% confidence

CASP License: Mandatory for all providers of crypto-asset services, including exchanges, wallets, and transfers; covers virtual currency exchange and transfer services under the single license regime (previously separate).

custody 20% confidence

Primary Estonian Laws: Crypto Asset Market Act (CMA); Money Laundering and Terrorist Financing Prevention Act (MLTFPA).

custody 20% confidence

EU Framework: MiCA Regulation (EU) 2023/1114.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — publishing self-custodial wallet software alone does not trigger VASP/CASP classification or AML obligations under Estonian law (CMA/MiCA) because the publisher never holds, controls, or has access to user funds or private keys; however, any integrated service layer (swap, custody, fiat on-ramp) would bring the operator into full CASP licensing scope with a local entity, €100k–€250k capital, and AML obligations under the MLTFPA.

Questions this verdict aims to answer

  • Does software publishing trigger VASP / MSB classification?
  • Do AML obligations attach when no custody exists?
  • What disclosure or consumer-protection rules apply?