Centralized exchange in Hungary
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Hungary with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP registration with the Magyar Nemzeti Bank (MNB) under AMLD5/AMLD6 transposition (hu.aml.vasp-registration-under-the-transposition)
- Customer due diligence (KYC) at onboarding and ongoing, per Act CXXXVI of 2013 on AML/CTF (Pmtv.) (hu.aml.act-cxxxvi-of-2013-on)
- Transaction monitoring and suspicious activity reporting to MNB (hu.aml.purpose-of-registration-this-registration)
- Travel Rule compliance: for VASP-to-VASP transfers of any amount, collect and transmit originator/beneficiary information; for VASP-to-unhosted/unhosted-to-VASP transfers > €1,000, collect and verify originator/beneficiary info (hu.travel-rule.no-de-minimis-threshold-for, hu.travel-rule.above-1000-when-a-transfer)
- Storage of travel-rule data for at least 5 years, extensible to 10 years (hu.travel-rule.store-the-information-securely-and)
- Policies and procedures to detect missing/incomplete transfer information; ability to reject, suspend, or report (hu.travel-rule.detect-missing-or-incomplete-information)
- Post-MiCA (Regulation EU 2023/1114): CASP authorization required from MNB, covering prudential, organizational, and operational requirements far beyond AML registration (hu.aml.authorization-as-a-casp-under, hu.aml.scope-this-authorization-is-comprehensive)
Key Restrictions
- Under MiCA (Articles 59-67), CASPs providing custody must segregate client crypto-assets and funds from own assets (hu.aml.key-requirements-article-67)
- Client crypto-assets and funds must be separately recordable and immediately identifiable (hu.aml.maintain-records-and-accounts-that)
- CASP must return client crypto-assets/funds without undue delay upon request (hu.aml.return-client-crypto-assets-and-funds)
- No specific Hungarian statutory rules on cold storage or minimum insurance/bonding currently exist, but MiCA prudential requirements will apply (hu.aml.no-specific-explicit-mandates-for, hu.aml.no-specific-explicit-statutory-insurancebonding)
- No de minimis threshold for VASP-to-VASP travel rule — all transfers require data sharing (hu.travel-rule.no-de-minimis-threshold-for)
Key Risks
- Regulatory transition: The current regime is AML-registration based; MiCA (applying from December 2024/2025) will impose a full CASP authorization with significantly higher prudential requirements — operators must plan for the transition (hu.aml.authorization-as-a-casp-under)
- No explicit statutory segregation rules pre-MiCA — only general civil law/fiduciary principles apply, creating asset-protection ambiguity for client funds (hu.aml.there-are-no-specific-explicit, hu.aml.however-general-civil-law-principles)
- MNB enforcement precedent: MNB has issued prohibitions and criminal referrals (e.g., Xifra Lifestyle, 2022) against unlicensed crypto service providers (hu.enforcement.outcome-the-mnb-prohibited-xifra)
- Travel-rule/GDPR tension: sharing originator/beneficiary data across borders raises privacy law conflicts (hu.travel-rule.technical-requirements-vasps-must-ensure)
- Fines under EU TFR up to €5 million or 10% of annual turnover for legal persons (hu.travel-rule.fines-significant-monetary-fines-which)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP Registration: Under the transposition of the EU's 5th and 6th Anti-Money Laundering Directives (AMLD5/AMLD6), custodial wallet providers are classified as Virtual Asset Service Providers (VASPs).
Obligation: VASPs, including those offering custodial services, are required to register with, or be licensed by, the Hungarian Financial Supervisory Authority (primarily the Magyar Nemzeti Bank - MNB, the Central Bank of Hungary, which oversees financial market supervision) for AML/CTF purposes.
Purpose of Registration: This registration primarily obliges the entity to comply with AML/CTF requirements, such as customer due diligence (KYC), transaction monitoring, and suspicious activity reporting, rather than specific operational custody rules.
Act CXXXVI of 2013 on the prevention and combating of money laundering and terrorist financing (Pmtv.) – This is Hungary's primary AML law, amended to include virtual asset service providers.
There are no specific, explicit statutory rules under current Hungarian law specifically for the segregation of client crypto assets from the custodian's own assets.
However, general civil law principles, fiduciary duties, and good business practices would strongly suggest and often require such segregation to protect client interests in case of insolvency or operational issues.
No specific, explicit statutory insurance/bonding requirements for crypto custodians beyond general business insurance that any company would hold.
No specific, explicit mandates for the use of cold storage (offline storage of private keys) under current Hungarian law.
Authorization as a CASP: Under MiCA, any entity providing "custody and administration of crypto-assets on behalf of third parties" will be classified as a Crypto-Asset Service Provider (CASP) and will require prior authorization by a national competent authority (in Hungary, this will be the MNB).
Scope: This authorization is comprehensive and covers specific operational, organizational, and prudential requirements, going far beyond mere AML registration.
Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 (MiCA).
Explicit Mandate: MiCA explicitly requires CASPs providing custody services to make adequate arrangements to safeguard the ownership rights of clients, particularly in the event of the CASP's insolvency.
Key Requirements (Article 67):
Maintain records and accounts that allow for the immediate segregation of client crypto-assets and funds from own assets and from those of other clients.
Return client crypto-assets and funds without undue delay upon their request.
No de minimis threshold. For any amount, the originating VASP must obtain and submit specific information about the originator and beneficiary, and the beneficiary VASP must receive and store this information.
Above €1,000: When a transfer from an unhosted wallet to a VASP, or from a VASP to an unhosted wallet, exceeds €1,000, the VASP must collect and verify information about the originator or beneficiary, respectively.
Store the information securely and for the legally required period (typically 5 years, extensible to 10 years).
Detect missing or incomplete information and have procedures for handling such cases (e.g., rejecting or suspending transfers, reporting to authorities).
Fines: Significant monetary fines, which can be substantial, especially for legal entities (up to a certain percentage of turnover or a fixed high amount, whichever is greater). The EU TFR itself mandates that penalties for legal persons should be at least €5 million or 10% of annual turnover, and for natural persons at least €5 million.
Technical requirements: VASPs must ensure data "travels" with transactions for AML/CFT traceability, using interoperable systems compliant with MiCA; no Hungary-specific protocols detailed beyond EU standards and FATF Recommendation 16, facing challenges like GDPR privacy integration.
Outcome: The MNB prohibited Xifra Lifestyle from offering its services to Hungarian residents. The MNB also filed a criminal complaint against the unknown perpetrators. The platform subsequently largely ceased operations in Hungary.
Entity Targeted: Xifra Lifestyle (also known as Xifra Global, Xifra LLC). Violation Type: Unlicensed financial service provision (offering investment services related to cryptocurrency trading without the necessary MNB authorization) and operating a scheme with characteristics of a pyramid scheme. Penalty Amount: The MNB issued a public warning and a cease-and-desist order. While no specific administrative fine amount was publicly disclosed by the MNB in its initial announcement, the action effectively prohibited the entity from operating in Hungary and referred the case to law enforcement for potential criminal proceedings.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange may operate in Hungary under the current AML-VASP registration regime, but must transition to a full MiCA CASP authorization (with mandatory asset segregation and prudential requirements) once MiCA applies, and must comply with the EU Travel Rule (no de minimis for VASP-to-VASP transfers, €1,000 threshold for unhosted wallet transfers).
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?