Self-custodial wallet / non-custodial software in Timor-Leste
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is conditionally permitted in Timor-Leste without local incorporation, subject to AML obligations and none licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- No specific AML obligations attach to a self-custodial wallet publisher because the publisher never holds, controls, or accesses user funds — the activity does not trigger any financial-services or VASP classification under current TL law.
- If the software publisher's activities were interpreted by a court as 'blurring the lines' with traditional financial services, general AML/CFT obligations under Law No. 2/2011 (and its successor Law No. 7/2021) could apply, including: customer due diligence (identifying and verifying customers), transaction monitoring for suspicious activity, and reporting suspicious transactions to the Unidade de Informação Financeira (UIF).
- However, with no custody and no fiat handling, the likelihood of such reclassification is low under current TL law.
Key Restrictions
- No crypto-specific licensing or registration regime exists, so no license is required solely for publishing non-custodial wallet software.
- General business registration laws apply if a physical presence (branch/office) is established in Timor-Leste, but pure software publishing from abroad does not trigger this.
- If the software publisher does anything beyond publishing code — e.g., offering hosted wallet recovery, fiat on-ramp intermediation, or any custodial-like service — the activity could be reclassified as a financial service subject to BCTL oversight.
Key Risks
- Regulatory ambiguity: TL has no clear definition of 'virtual asset' or 'VASP' in law, creating uncertainty about whether non-custodial software constitutes a financial service.
- FATF interpretation risk: The FATF's Travel Rule and VASP guidance technically apply to 'transfer' facilitators. If TL adopts FATF Recommendations more aggressively, non-custodial wallet publishers could face retroactive obligations.
- Enforcement precedent risk: The BCTL has issued public warnings about crypto risks, signaling skepticism. A future enforcement action could reinterpret the law expansively.
- Tax/PR exposure: Even if unregulated, publishing a wallet accessible in TL could attract scrutiny; the BCTL may issue advisories or takedown requests.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Lack of Specific Regulation is Not the Same as Legality or Full Freedom: While there are no crypto-specific licenses, any entity operating within Timor-Leste would still be subject to general business laws, tax laws, and potentially, if their activities could be interpreted as traditional financial services, existing financial sector legislation overseen by the Banco Central de Timor-Leste (BCTL).
No specific licenses are currently required for crypto-specific activities.
Neither a specific registration nor a licensing regime exists for VASPs.
If a service provider's activities blur the lines with traditional financial services (e.g., holding fiat currency deposits, facilitating fiat-to-fiat transfers through crypto, or providing lending services in fiat backed by crypto), they might inadvertently fall under existing financial services laws and require a license as a financial institution, payment service provider, or money service business from the BCTL. However, for pure crypto-to-crypto activities or non-custodial wallets, there is no direct precedent or requirement.
AML/CFT Obligations: Even without specific VASP regulation, Timor-Leste, as a member of the international community, is subject to the recommendations of the Financial Action Task Force (FATF). Its existing Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) laws (such as Law No. 2/2011 on the Prevention and Combat of Money Laundering and Financing of Terrorism, and any subsequent updates) would apply to financial institutions and designated non-financial businesses and professions (DNFBPs). The BCTL and other relevant authorities would expect any entity involved in financial transactions, even those involving virtual assets, to have robust AML/KYC controls in place to prevent illicit activities.
The general AML/CFT laws of Timor-Leste (e.g., Law No. 2/2011) would be the guiding principles. Failure to comply with these general obligations could lead to criminal charges if illicit activities are facilitated.
There are no specific licensing requirements for cryptocurrency custodians or digital asset service providers in Timor-Leste.
Issuing Warnings and Advisories: The BCTL has previously issued statements cautioning the public about the risks associated with cryptocurrencies, highlighting their volatile nature, lack of regulatory oversight, and potential for use in illicit activities. These are general advisories rather than enforcement actions against specific entities.
Prioritization: Enforcement efforts in smaller, developing economies often prioritize more traditional forms of financial crime due to limited resources and the nascent stage of crypto adoption.
Law No. 3/2011 on Prevention and Combat of Money Laundering and Financing of Terrorism (Lei N.º 3/2011 de Prevenção e Combate ao Branqueamento de Capitais e ao Financiamento do Terrorismo): This is the foundational law that establishes the framework for AML/CFT in Timor-Leste. It defines money laundering and terrorist financing offenses, sets out reporting obligations for financial institutions and designated non-financial businesses and professions (DNFBPs), and establishes the Financial Intelligence Unit (FIU).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — publishing a self-custodial wallet does not trigger VASP classification or AML obligations under current TL law because the publisher never holds user funds, but regulatory ambiguity exists and general business laws apply if a local presence is established.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?