Self-custodial wallet / non-custodial software in Slovakia
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is permitted in Slovakia with no licensing burden.
Verdict Details
- Permitted
- yes
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- No AML obligations attach to a pure software publisher of a non-custodial/self-custodial wallet, because the publisher never holds, controls, or has access to private keys or customer funds.
- Slovak law (sk.aml.custodian-wallet-providers-entities-that) defines obliged entities as those safeguarding private keys 'on behalf of their customers'. A self-custodial wallet publisher does not safekeep keys on behalf of clients.
- sk.aml.providers-of-other-services-related is a catch-all but is interpreted in the context of services involving custody, exchange, or transfer — not software publishing.
- If the wallet included remote key-management features or a hosted component, CDD, transaction monitoring, SAR filing, and PEP screening under Act No. 297/2008 Coll. would apply.
Key Restrictions
- The wallet must genuinely be non-custodial: the publisher cannot hold, store, or control private keys at any point.
- No Slovak-specific geofencing or consumer-protection rules apply to pure software publishers; general EU consumer-protection and software-liability rules (e.g., Civil Code, Consumer Protection Act) may still apply to the distribution of software in Slovakia.
- If the wallet is marketed as a 'financial service' or implies custodial features, the regulator (NBS) may reclassify it under the CASP framework.
Key Risks
- Regulatory reclassification risk: If the wallet offers integrated swaps, staking, or other services where the publisher facilitates transactions (even via third-party APIs), Slovak authorities may treat the publisher as a custodian wallet provider or VASP.
- Enforcement precedent: NBS has issued repeated warnings (May 2022, September 2023, March 2021) about unlicensed crypto and investment services — a self-custodial wallet publisher with ancillary features could attract scrutiny.
- MiCA alignment from December 30, 2024: Under MiCA Title V, 'custody and administration of crypto-assets on behalf of clients' (Article 68) will require CASP authorization if the service crosses into custody; pure non-custodial software remains outside scope, but the line is thin.
- Consumer-protection exposure: Slovak consumers could bring claims under general product-liability/software-quality law if the wallet has defects that cause loss of funds, even if the publisher is not a financial institution.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Custodial License Requirements (Current - AML Focus):
Registration, not a dedicated license: Currently, there isn't a specific "crypto custody license" in the traditional financial sense. However, entities providing services related to virtual assets, including custodian wallet providers, are considered "obliged entities" under Slovak AML law.
AML Obligations: This means they must comply with AML/CFT requirements, such as customer due diligence (CDD), transaction monitoring, suspicious activity reporting (SARs), and implementing internal risk management systems.
National Legislation: These obligations stem from Act No. 297/2008 Coll. on measures against the legalization of proceeds of crime and the financing of terrorism (Zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu). This Act has been amended multiple times to transpose the 4th, 5th, and 6th EU AML Directives.
Competent Authorities: For AML purposes, the Financial Intelligence Unit (FIU) within the Ministry of Interior is key, but the National Bank of Slovakia (Národná banka Slovenska - NBS) supervises financial institutions, which could include certain crypto-related activities if deemed financial services.
Act No. 297/2008 Coll. (AML Act): Link to Slov-Lex, the Slovak legislative database (in Slovak) (Search for the consolidated version to include amendments).
National Bank of Slovakia (NBS) general information on Virtual Assets (in Slovak): https://www.nbs.sk/sk/dohlad-nad-financnym-trhom/dohlad-nad-virtualnymi-aktivami (This page confirms the application of AML rules and highlights upcoming MiCA).
Segregation of Client Assets Rules (Current):
Insurance/Bonding Requirements (Current):
None specific to crypto custody: There are no national insurance or bonding mandates specifically for crypto custody providers under current Slovak law.
Cold Storage Mandates (Current):
No specific mandate: Slovak law does not currently mandate the use of cold storage for crypto assets. Custodians are expected to implement robust security measures, but the specific technology is not prescribed.
Qualified Custodian Definitions (Current):
Not explicitly defined for crypto: The concept of a "qualified custodian" as a specifically regulated entity for crypto assets does not exist under current Slovak law. Entities performing custody are primarily defined by their AML obligations.
Publication: MiCA was published in the Official Journal of the European Union on June 9, 2023.
Titles III (asset-referenced tokens) and IV (e-money tokens) will apply from June 30, 2024.
All other titles, including those related to CASPs and custody, will apply from December 30, 2024.
MiCA Text (Official Journal of the European Union): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114
Custodial License Requirements (Future - MiCA):
Mandatory Authorization: Under MiCA (Title V), any entity providing "custody and administration of crypto-assets on behalf of clients" (Article 68) will be considered a Crypto-Asset Service Provider (CASP) and will need to be authorized by the national competent authority. In Slovakia, this will most likely be the National Bank of Slovakia (NBS).
Application Process: CASPs will need to apply for authorization, demonstrating compliance with various organizational, operational, and prudential requirements.
Passporting: Once authorized in Slovakia, a CASP can "passport" its services across the entire EU.
Segregation of Client Assets Rules (Current):
Strict Segregation Mandate: MiCA explicitly requires CASPs providing custody services to:
"Enter into a client agreement to specify their duties and responsibilities, and to ensure that clients’ rights are clearly established, including those relating to the ownership of the crypto-assets." (Article 68(2)(b))
Act No. 297/2008 Coll. on Protection Against Legalisation of Proceeds of Crime and Against Financing of Terrorism (AML Act): This is the primary legislation in Slovakia governing AML/CFT. It has been amended multiple times, most notably by Act No. 397/2019 Coll., which transposed the 5AMLD and extended its scope to virtual assets and VASPs.
Directive (EU) 2018/843 (5th Anti-Money Laundering Directive - 5AMLD): This directive extended AML/CFT obligations to VASPs for the first time.
Directive (EU) 2015/849 (4th Anti-Money Laundering Directive - 4AMLD): The foundational directive.
Directive (EU) 2018/1673 (6th Anti-Money Laundering Directive - 6AMLD): Further harmonized criminal offenses and penalties for money laundering.
Virtual currency exchange services: Providers exchanging virtual currencies for fiat currencies, or vice versa, or between one or more forms of virtual assets.
Custodian wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store, and transfer virtual assets.
Providers of other services related to virtual assets: This can be broadly interpreted to include other services like issuance, transfer, or administration of virtual assets.
Identification of the Customer and Verification of Identity:
Natural Persons: Full name, date of birth, place of birth, permanent address, nationality, type and number of identity document, and the issuing authority. Identity must be verified using reliable, independent sources (e.g., government-issued ID).
Legal Entities: Company name, registered address, registration number, identification of directors/management, and verification of their authority.
Identification of the Ultimate Beneficial Owner (UBO):
Understanding the Purpose and Nature of the Business Relationship/Transaction:
Continuously scrutinize transactions throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Politically Exposed Persons (PEPs): Customers who are or have been entrusted with prominent public functions, their family members, or close associates.
High-risk jurisdictions: Customers or transactions involving countries identified as having strategic AML/CFT deficiencies by FATF or the European Commission.
Complex or unusually large transactions: Or transactions with an unusual pattern, without an apparent economic or lawful purpose.
New or developing technologies: Including virtual assets, where the risks may not be fully understood.
Non-face-to-face business relationships: Where there is no physical meeting with the customer.
Source of Funds (SoF) and Source of Wealth (SoW): VASPs must take reasonable measures to establish the source of funds and wealth involved in high-risk relationships or transactions.
Obligation to Report: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that funds are proceeds of criminal activity or are linked to terrorist financing.
Regulator Name: National Criminal Agency (NAKA) – specifically the National Unit for Combating Financial Crime.
Entity Targeted: An organized criminal group involving multiple individuals suspected of operating a sophisticated investment fraud scheme and subsequent money laundering using cryptocurrencies. Violation Type: Investment fraud, money laundering, unauthorized business activities, establishment, masterminding, and support of a criminal group. The scheme involved luring victims into fake crypto investment platforms.
Criminal charges filed against multiple individuals.
Seizure of assets: During the operation, authorities seized financial assets, movable property, and real estate worth approximately €15 million. This includes accounts, cryptocurrencies, and other assets believed to be proceeds of crime.
Date: Raids and arrests occurred in late 2023 (e.g., December 2023), with investigations ongoing since prior to that.
Outcome: Multiple individuals arrested and charged. Assets seized. Criminal proceedings are ongoing. This represents one of the largest financial crime operations in Slovakia involving cryptocurrencies.
Polícia SR (Official Police Statement): https://www.facebook.com/policiaslovakia/posts/pfbid0251iGk2rK4y9W8Wz2o76qF8RCHWpYwQdD71k8GvV1wL5GjQz1P4wK4yJgW2p8l/ (Link to Facebook post by Polícia SR, official channel, dated 18.12.2023)
TASR (News Agency): https://www.teraz.sk/slovensko/naka-zasahovala-pri-rozsiahlej-tres/761168-clanok.html (News article from 18.12.2023)
Entity Targeted: Individuals involved in an international scheme impersonating banks and investment companies to defraud victims, often directing them to fake crypto investment platforms or phishing for personal data to access their crypto wallets. Violation Type: Internet fraud, unauthorized access to computer systems, data theft, and potential money laundering.
Arrests and charges against suspects.
Seizures: Specific amounts are difficult to quantify publicly as investigations are often international and involve multiple victims. However, reports indicate damages in the hundreds of thousands to millions of euros across various victims.
Date: Ongoing investigations and arrests have been reported throughout 2022 and 2023. For instance, an arrest in Slovakia linked to a larger international phishing operation was reported in March 2023.
Outcome: Suspects identified and apprehended. International cooperation between law enforcement agencies (e.g., Europol, Eurojust) is common in these cases. Criminal proceedings are underway.
Europol (General cooperation for cybercrime, relevant to Slovak context): While not a specific Slovak action, Europol often assists NAKA in such international cases. https://www.europol.europa.eu/media-press/newsroom/news/romanian-criminal-gang-dismantled-involved-in-cryptocurrency-fraud-worth-eur-2-million (Example of a related Europol case in Romania from October 2023, illustrating the type of regional cooperation NAKA engages in).
Regulator Name: National Bank of Slovakia (Národná banka Slovenska - NBS).
Entity Targeted: General public, but implicitly targets any unlicensed entities or scammers operating without proper authorization or misrepresenting their services. Violation Type: Operating without required licenses (e.g., for investment services or financial advisory), offering fraudulent investment opportunities, misrepresentation of crypto products, or not adhering to AML/CFT obligations (though the latter is harder for the NBS to enforce directly against unlicensed foreign entities). Penalty Amount: No direct monetary penalty specified for the warning itself. The "penalty" is more in the form of reputational damage for entities named (if any) and increased public awareness leading to fewer victims.
Date: NBS has issued numerous warnings throughout the last 3 years, for example:
September 2023: Warning about financial services without NBS authorization.
May 2022: General warning regarding cryptocurrency risks.
March 2021: Warning against specific entities offering unlicensed services.
Outcome: Increased public awareness, reduced risk for consumers (if warnings are heeded), and a clear signal from the regulator regarding unauthorized activities. These warnings often precede or accompany police investigations.
NBS Official Website (Example of an investor warning from 2023): https://www.nbs.sk/sk/informacie-pre-media/tlacove-spravy/2023/investicne-sluzby-bez-povolenia-nbs (Dated 22.09.2023, focuses on unlicensed investment services, often linked to crypto)
NBS Official Website (General warning about virtual currencies from 2022): https://www.nbs.sk/sk/informacie-pre-media/tlacove-spravy/2022/virtulne-meny-vynimocne-rizikove (Dated 09.05.2022, highlights risks)
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Yes — a publisher of purely non-custodial/self-custodial wallet software for Slovakia does not trigger VASP/MSB classification, does not require licensing, and has no AML obligations under current Slovak law, because the publisher never holds or controls private keys on behalf of users; the key risk is reclassification if the wallet adds integrated swap/staking/transfer-facilitation features.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?