Remote VASP serving residents in Hungary
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Hungary with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including foreign entities serving Hungarian residents) must register with/l be licensed by the Magyar Nemzeti Bank (MNB) for AML/CTF purposes under Act CXXXVI of 2013 (Pmtv.) (hu.aml.vasp-registration-under-the-transposition, hu.aml.obligation-vasps-including-those-offering, hu.aml.act-cxxxvi-of-2013-on)
- Customer due diligence (KYC), transaction monitoring, and suspicious activity reporting obligations apply (hu.aml.purpose-of-registration-this-registration)
- Travel Rule obligations under EU Regulation 2023/1113 (TFR): for all VASP-to-VASP transfers, originator and beneficiary data must be collected and shared with no de minimis threshold; for unhosted wallet transfers above €1,000, enhanced information collection applies; below €1,000 simplified due diligence may apply under risk-based controls (hu.travel-rule.no-de-minimis-threshold-for, hu.travel-rule.above-1000-when-a-transfer, hu.travel-rule.below-1000-below-this-threshold)
- Information must be stored securely for 5 years (extensible to 10) (hu.travel-rule.store-the-information-securely-and)
- Significant monetary fines for non-compliance, including up to 10% of annual turnover or at least €5 million for legal persons (hu.travel-rule.fines-significant-monetary-fines-which)
- Under MiCA (applicable phases from 2024-2025), CASPs providing custody must separate client crypto-assets and funds from own assets, maintain records allowing immediate segregation, return client assets on request (hu.aml.explicit-mandate-mica-explicitly-requires, hu.aml.key-requirements-article-67, hu.aml.keep-client-crypto-assets-and-funds, hu.aml.maintain-records-and-accounts-that, hu.aml.return-client-crypto-assets-and-funds)
Key Restrictions
- Foreign-incorporated entities serving Hungarian residents must register with the MNB as a VASP under Hungarian AML law — operating without registration is unlawful (hu.aml.obligation-vasps-including-those-offering)
- Under MiCA, a CASP authorization (comprehensive operational/prudential authorization beyond AML registration) will be required for custody services, requiring a local entity and prior authorization by the MNB (hu.aml.authorization-as-a-casp-under, hu.aml.scope-this-authorization-is-comprehensive)
- No specific statutory rules on segregation of client crypto assets under current Hungarian law, though MiCA will mandate this by 2025 (hu.aml.there-are-no-specific-explicit, hu.aml.however-general-civil-law-principles)
- No specific statutory insurance/bonding or cold storage mandates under current Hungarian law (hu.aml.no-specific-explicit-statutory-insurancebonding, hu.aml.no-specific-explicit-mandates-for)
Key Risks
- The MNB actively issues warnings against unlicensed foreign operators and prohibits them from offering services to Hungarian residents; criminal complaints may be filed (hu.enforcement.issuing-warnings-against-unlicensed-service, hu.enforcement.entity-targeted-xifra-lifestyle-also, hu.enforcement.outcome-the-mnb-prohibited-xifra)
- Police and tax authority (NAV) investigations into crypto fraud and money laundering create enforcement exposure (hu.enforcement.police-investigations-hungarian-police-frequently, hu.enforcement.tax-authority-nav-the-national)
- MiCA transition: entities operating under current AML-only registration may need to upgrade to full CASP authorization, creating regulatory uncertainty and re-application risk (hu.aml.authorization-as-a-casp-under)
- General civil law principles and fiduciary duties around asset segregation create ambiguity — no bright-line statutory rule exists (hu.aml.however-general-civil-law-principles)
- Public censure and significant fines (up to 10% turnover) for Travel Rule non-compliance (hu.travel-rule.fines-significant-monetary-fines-which, hu.travel-rule.public-censure-publication-of-a)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP Registration: Under the transposition of the EU's 5th and 6th Anti-Money Laundering Directives (AMLD5/AMLD6), custodial wallet providers are classified as Virtual Asset Service Providers (VASPs).
Obligation: VASPs, including those offering custodial services, are required to register with, or be licensed by, the Hungarian Financial Supervisory Authority (primarily the Magyar Nemzeti Bank - MNB, the Central Bank of Hungary, which oversees financial market supervision) for AML/CTF purposes.
Purpose of Registration: This registration primarily obliges the entity to comply with AML/CTF requirements, such as customer due diligence (KYC), transaction monitoring, and suspicious activity reporting, rather than specific operational custody rules.
Act CXXXVI of 2013 on the prevention and combating of money laundering and terrorist financing (Pmtv.) – This is Hungary's primary AML law, amended to include virtual asset service providers.
There are no specific, explicit statutory rules under current Hungarian law specifically for the segregation of client crypto assets from the custodian's own assets.
However, general civil law principles, fiduciary duties, and good business practices would strongly suggest and often require such segregation to protect client interests in case of insolvency or operational issues.
No specific, explicit statutory insurance/bonding requirements for crypto custodians beyond general business insurance that any company would hold.
No specific, explicit mandates for the use of cold storage (offline storage of private keys) under current Hungarian law.
Authorization as a CASP: Under MiCA, any entity providing "custody and administration of crypto-assets on behalf of third parties" will be classified as a Crypto-Asset Service Provider (CASP) and will require prior authorization by a national competent authority (in Hungary, this will be the MNB).
Scope: This authorization is comprehensive and covers specific operational, organizational, and prudential requirements, going far beyond mere AML registration.
Explicit Mandate: MiCA explicitly requires CASPs providing custody services to make adequate arrangements to safeguard the ownership rights of clients, particularly in the event of the CASP's insolvency.
Key Requirements (Article 67):
Keep client crypto-assets and funds separate from their own crypto-assets and funds.
Maintain records and accounts that allow for the immediate segregation of client crypto-assets and funds from own assets and from those of other clients.
Return client crypto-assets and funds without undue delay upon their request.
No de minimis threshold. For any amount, the originating VASP must obtain and submit specific information about the originator and beneficiary, and the beneficiary VASP must receive and store this information.
Above €1,000: When a transfer from an unhosted wallet to a VASP, or from a VASP to an unhosted wallet, exceeds €1,000, the VASP must collect and verify information about the originator or beneficiary, respectively.
Below €1,000: Below this threshold, simplified due diligence may apply, but VASPs are still expected to implement risk-based controls.
Store the information securely and for the legally required period (typically 5 years, extensible to 10 years).
Fines: Significant monetary fines, which can be substantial, especially for legal entities (up to a certain percentage of turnover or a fixed high amount, whichever is greater). The EU TFR itself mandates that penalties for legal persons should be at least €5 million or 10% of annual turnover, and for natural persons at least €5 million.
Public Censure: Publication of a statement indicating the responsible natural or legal person and the nature of the breach.
Issuing warnings against unlicensed service providers (often foreign entities).
Entity Targeted: Xifra Lifestyle (also known as Xifra Global, Xifra LLC). Violation Type: Unlicensed financial service provision (offering investment services related to cryptocurrency trading without the necessary MNB authorization) and operating a scheme with characteristics of a pyramid scheme. Penalty Amount: The MNB issued a public warning and a cease-and-desist order. While no specific administrative fine amount was publicly disclosed by the MNB in its initial announcement, the action effectively prohibited the entity from operating in Hungary and referred the case to law enforcement for potential criminal proceedings.
Outcome: The MNB prohibited Xifra Lifestyle from offering its services to Hungarian residents. The MNB also filed a criminal complaint against the unknown perpetrators. The platform subsequently largely ceased operations in Hungary.
Police Investigations: Hungarian police frequently conduct investigations and make arrests related to cryptocurrency fraud, scams, and money laundering. However, these are criminal proceedings targeting individuals or criminal groups, rather than administrative enforcement actions by a financial regulator against a formal "entity" with a specific "penalty amount" in the same way the MNB acts. The outcomes are typically arrests, charges, and eventual court sentences, which are distinct from regulatory fines.
Tax Authority (NAV): The National Tax and Customs Administration (NAV) enforces tax laws on crypto income and transactions, but these are typically individual or corporate audits and assessments rather than publicly announced "enforcement actions" against specific crypto platforms with a universal "penalty."
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Hungarian residents from abroad must register with the MNB under AML law, and from MiCA's phased application (2024–2025) will require full CASP authorization with a local entity, comprehensive operational requirements, and client asset segregation.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?