← Regulations / Luxembourg / Operating Models / Self-custodial wallet

Self-custodial wallet / non-custodial software in Luxembourg

Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.

Conditional AI-Generated · Unreviewed

Self-custodial wallet is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • No AML obligations attach directly to the non-custodial wallet software publisher under Luxembourg law, because the publisher never holds, controls, or has access to user private keys or funds — this activity does not constitute 'custodian wallet services' under the Law of 12 November 2004 AML Law.
  • If the publisher were to engage in any custodial, exchange, or transfer activities (e.g., an integrated swap feature where the publisher controls keys temporarily), it would trigger VASP registration and full AML/CFT obligations under the AML Law including: customer due diligence (CDD), beneficial ownership identification, ongoing transaction monitoring, suspicious transaction reporting (STRs) to the CSSF, and enhanced due diligence (EDD) for PEPs, high-risk jurisdictions, or complex transactions.
  • The CSSF's Circulars 20/747, 22/811, and 23/843 provide detailed AML/CFT guidance for registered VASPs; these do not apply to pure non-custodial software publishers.

Key Restrictions

  • Pure non-custodial wallet software publishing does not meet the legal definition of 'custodian wallet services' under Luxembourg law (which requires safeguarding private cryptographic keys on behalf of customers), so no VASP registration is required solely for publishing such software.
  • The publisher must not, at any point, hold, store, or control user private keys or funds — any incidental custody (e.g., temporary key holding during a swap) would trigger VASP classification.
  • There is no explicit consumer-protection or disclosure regime for non-custodial wallet software under current Luxembourg law; however, general consumer protection laws (e.g., Luxembourg Consumer Code) may apply to software-as-a-product distribution.

Key Risks

  • Regulatory ambiguity risk: The line between 'custodial' and 'non-custodial' may be tested by the CSSF if the software includes integrated features (swaps, fiat on-ramps, staking) where the provider exercises any control over keys or funds.
  • MiCA's upcoming full authorization regime (Regulation (EU) 2023/1114) may broaden the definition of 'custody and administration of crypto-assets' — future guidance could capture some non-custodial services if the provider's software interacts with third-party custodians or manages protocol-level custody.
  • Enforcement risk is low for pure software publishers today, but the CSSF maintains a proactive stance and could issue warnings or cease-and-desist orders if it determines an integrated feature crosses into VASP activity.
  • No confirmed enforcement precedent for non-custodial software publishers in Luxembourg — lack of public enforcement does not guarantee immunity from future regulatory scrutiny.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.

licensing 60% confidence

The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.

licensing 60% confidence

Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.

licensing 60% confidence

Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (Loi du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme, telle que modifiée): While a specific URL to the consolidated law is hard to pinpoint, it's the primary legal basis. The key amendments are from 2018 and later.

licensing 60% confidence

CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.

aml 60% confidence

Directive (EU) 2018/843 (5th AML Directive): Critically, this directive extended the scope of AML/CFT rules to include virtual asset service providers, bringing them under the regulatory purview.

aml 60% confidence

Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.

aml 60% confidence

Custodial wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store and transfer virtual assets.

aml 60% confidence

CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.

aml 60% confidence

Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:

enforcement 60% confidence

CSSF VASP Register (Information Page): This page explains the registration requirements and provides access to the list of registered VASPs.

licensing 60% confidence

Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.

licensing 60% confidence

Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):

enforcement 60% confidence

CSSF Warnings for Unlicensed Entities: The CSSF frequently issues warnings against entities that purport to offer financial services in Luxembourg without proper authorization, including those related to crypto. These are general warnings rather than specific enforcement actions against a regulated VASP.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — A non-custodial wallet software publisher that never holds or controls user private keys is not classified as a VASP under Luxembourg law and faces no AML registration obligations, but must ensure no incidental custody occurs and should monitor MiCA's evolving scope for custodial-like services.

Questions this verdict aims to answer

  • Does software publishing trigger VASP / MSB classification?
  • Do AML obligations attach when no custody exists?
  • What disclosure or consumer-protection rules apply?