Self-custodial wallet / non-custodial software in India
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is conditionally permitted in India without local incorporation, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- Register as a VDA Service Provider (reporting entity) with FIU-IND under the Prevention of Money Laundering Act (amended March 7, 2023).
- Implement transaction monitoring systems — risk-based, real-time, AI-powered systems to flag suspicious activities like large transfers, structuring, or high-risk patterns, tailored to customer risk levels.
- Deploy blockchain analytics tools — monitor wallets, histories, and typologies like chain-hopping or mixers.
- Comply with the FATF Travel Rule — share originator/beneficiary details (name, account, address) for virtual asset transfers via secure channels, with screening, recordkeeping, and rejection of incomplete data.
- Screen wallets, addresses, and counterparties against sanctions lists (OFAC SDN List, UN Consolidated List) and block/ freeze sanctioned cryptoassets.
- File Suspicious Activity Reports (SARs) with FIU-IND.
- Subject to PMLA penalties — fines up to 3x contravention value and 3-7 years imprisonment, plus FEMA violations up to 3x amount.
Key Restrictions
- Self-custodial wallet software publishers that never hold, control, or have access to user funds may nonetheless be classified as VDA Service Providers (VASPs) under the PMLA amendment if they facilitate transactions or provide services beyond pure software distribution.
- No specific exemption for non-custodial software publishers exists in Indian law — the scope of 'VDA Service Provider' is broad and may capture wallet publishers who integrate with exchanges, swaps, or fiat on-ramps.
- Offshore wallet publishers face enforcement risk — India blocked 9 offshore exchanges in 2024 for non-compliance, and non-compliant VASPs had websites blocked.
- RBI has historically been hostile to private crypto (attempted outright ban in 2018, reversed by Supreme Court 2020), creating regulatory uncertainty for any crypto-adjacent services.
Key Risks
- Regulatory ambiguity — India has no comprehensive crypto legislation and no specific framework for DeFi or non-custodial services, leaving self-custodial wallet publishers in a grey area.
- Enforcement risk — FIU-IND has demonstrated willingness to block offshore crypto service providers, and the broad 'VDA Service Provider' definition could be applied to wallet software publishers.
- Tax exposure — Finance Act 2022 imposes 30% flat tax on virtual digital asset transactions and 1% TDS on transactions above INR 50,000, which could create reporting obligations for the publisher if they facilitate transactions.
- Risk that FIU-IND or RBI could issue guidance explicitly including non-custodial wallet publishers within the VASP regime, creating retroactive compliance exposure.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
FIU-IND — VDA Service Provider registration, AML/CFT, blocked 9 offshore exchanges in Jan 2024
RBI — Stablecoins, payments, Digital Rupee CBDC pilot — historically hostile to private crypto
Prevention of Money Laundering Act (amended 2023) (2023) — VDA SP registration with FIU-IND — mandatory
VASP: VDA Service Provider registration with FIU-IND (1-3 months, no minimum capital). Offshore exchanges blocked in 2024 for non-compliance (Binance, KuCoin, etc.) — most subsequently registered. No comprehensive crypto legislation despite being 'upcoming' since 2021.
CUSTODY: No specific custody framework; covered under FIU registration. No framework for stablecoins, DeFi, or token issuance.
Transaction Monitoring Systems: Confirmed as a standard requirement for VASPs. Sources describe risk-based, real-time, AI-powered systems to flag suspicious activities like large transfers, structuring, or high-risk patterns, tailored to customer risk levels.
Blockchain Analytics Tools: Supported indirectly. Sources highlight blockchain monitoring (e.g., SaaS models analyzing wallets, histories, and typologies like chain-hopping or mixers) as essential for VASP compliance, often integrated with transaction monitoring.
Travel Rule Solutions: Explicitly required under FATF standards. VASPs must share originator/beneficiary details (e.g., name, account, address) for virtual asset transfers via secure channels, with screening, recordkeeping, and rejection of incomplete data.
Adopted and Effective Date: Adopted via PMLA amendment on March 7, 2023, explicitly to comply with the FATF Travel Rule by including VDA service providers (often termed VASPs) in the PMLA framework.
Threshold Amounts: No specific threshold is detailed in the provided sources for India; FATF globally recommends $1,000/€1,000, but countries like India set their own (or none), with requirements potentially applying to all transactions.
VASPs Covered: All Virtual Digital Asset Service Providers (also called VDA-SPs), now classified as reporting entities under PMLA. Several VASPs have registered with the Financial Intelligence Unit - India (FIU-IND), while non-compliant ones faced website blocks.
Technical Implementation Requirements: FIU-IND issued specific AML & CFT Guidelines for VDA-related service providers, covering transaction monitoring systems, blockchain analytics tools, and Travel Rule compliance. VASPs must adhere to these and any subsequent FIU-IND directives on implementation status.
Prevention of Money Laundering Act (PMLA), 2002 (amended March 7, 2023): Core legislation extending AML/CFT to VDAs and VASPs. https://www.ikigailaw.com/article/592/the-implementation-of-the-fatf-travel-rule-to-vasps-in-india
FIU-IND AML & CFT Guidelines for VDA Service Providers: Operational guidance post-amendment. https://fiuindia.gov.in/pdfs/downloads/VDA08012026.pdf
Screening obligations: Continuous screening of wallets, addresses, and counterparties against the Specially Designated Nationals (SDN) List (https://sanctionssearch.ofac.treas.gov), plus the 50% Rule (block entities owned ≥50% by SDN-listed persons) (https://ofac.treasury.gov/faqs/topic/1626). No crypto exceptions; includes sanctioned jurisdictions like Iran, North Korea, Syria, Cuba, Crimea/Donbas (https://ofac.treasury.gov/sanctions-programs-and-country-information).
Blocking: Immediately freeze sanctioned cryptoassets (e.g., from designated wallets/exchanges like Blender.io or SUEX) and report to OFAC; no trading/transfer allowed without license (https://www.elliptic.co/blockchain-basics/what-are-ofac-crypto-sanctions).
Penalties: Civil fines up to $1M+ per violation (e.g., Binance $3.4B in 2023 for Iran/Russia/Cuba dealings; Bittrex $24M) (https://sanctionslawyers.net/ofac-lawyers/ofac-cryptocurrency-sanctions/); criminal penalties possible. Indian VASPs risk secondary sanctions or PMLA fines up to ₹10 lakh + imprisonment.
Screening obligations: Screen against UN Consolidated List (https://www.un.org/securitycouncil/content/un-sc-consolidated-list); covers terrorists, proliferators (e.g., North Korea).
Blocking: Freeze assets and prohibit dealings.
Penalties: PMLA fines (up to 3x contravention value) + 3-7 years imprisonment; FEMA violations up to 3x amount.
Finance Act 2022 (Section 115BBH) (2022) — 30% flat tax on virtual digital assets; 1% TDS on transactions above INR 50,000
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a self-custodial wallet software publisher that does not hold user funds may be classified as a VDA Service Provider under India's PMLA amendment if it provides services beyond pure software distribution (e.g., swaps, on-ramps), requiring FIU-IND registration and AML/CFT compliance, but the scope of the VASP definition is ambiguous for pure non-custodial software publishers and India lacks a specific framework for DeFi or non-custodial services.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?