Self-custodial wallet / non-custodial software in Vietnam
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is conditionally permitted in Vietnam with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must apply AML/CTF obligations as part of licensing, including internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance.
- VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000, verifying customer identities to mitigate fraud, money laundering, and terrorist financing.
- VASPs must retain data on Vietnam servers for 10 years, including transaction history, originator/beneficiary details (e.g., wallet addresses), IP/device logs, and account info.
- Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection.
- AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations.
- Systems must achieve Level 4 cybersecurity (highest standard), including encryption, intrusion detection, and continuous monitoring to support CDD.
Key Restrictions
- A non-custodial wallet publisher that does not hold, control, or access user funds may still be classified as a VASP under Vietnam's broad framework, triggering the full licensing and AML regime.
- Foreign investors require a single VND account at a licensed local bank; all transactions use VND.
- Data must be retained on Vietnam servers for 10 years.
- Systems must achieve Level 4 cybersecurity (highest standard).
- Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT.
Key Risks
- The framework is designed around custodial exchange-type VASPs; whether a pure non-custodial software publisher is in scope is legally ambiguous and untested.
- No explicit exemption for non-custodial wallets exists in the pilot licensing framework (Resolution No. 05/2025/NQ-CP).
- Enforcement precedent (ONUS platform, 2026) shows active criminal prosecution of crypto operators for fraud/money laundering, signaling high risk for unlicensed operators.
- The AML law (2022) and FATF VASP standards are being proactively adopted, which may extend obligations to software publishers that facilitate transactions.
- Practical compliance with Level 4 cybersecurity, 10-year local data retention, and VND-only banking may be structurally incompatible with a non-custodial wallet model where the publisher never touches funds or keys.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The framework mandates VASPs to apply AML/CTF obligations as part of licensing, treating crypto exchanges as market infrastructure akin to securities exchanges. This includes internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance.
VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000, verifying customer identities to mitigate fraud, money laundering, and terrorist financing.
VASPs must retain data on Vietnam servers for 10 years, including transaction history, originator/beneficiary details (e.g., wallet addresses), IP/device logs, and account info.
Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection.
No explicit STR filing mechanism is detailed in pilot docs, but AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations.
Systems must achieve Level 4 cybersecurity (highest standard), including encryption, intrusion detection, and continuous monitoring to support CDD.
Foreign investors require a single VND account at a licensed local bank; all transactions use VND.
Key reference: Resolution No. 05/2025/NQ-CP (September 9, 2025) establishes the licensing regime with AML/CTF as a core objective; Decision No. 96/QD-BTC details procedures, including AML appraisals.
Oversight involves MOF (lead), SSC (receiving applications), SBV (financial integrity), and MPS (AML, cybersecurity).
Entity Targeted: ONUS cryptocurrency platform (including tokens VNDC, ONUS, and HNG), operated by Vương Lê Vĩnh Nhân (Eric Lê/Vuong Le Vinh Nhan) and associates. Violation Type: Fraud via token price manipulation, deceptive marketing, misleading promotions, artificial trading to control supply/demand, property appropriation, and money laundering using platform infrastructure. Penalty Amount: Not yet finalized; investigation targets billions of dollars in mobilized funds and investor losses (preliminary estimates in billions of USD).
Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a non-custodial wallet publisher likely triggers VASP classification under Vietnam's 2025 pilot licensing regime, requiring a local entity, a high-burden license with AML/KYC obligations, Level 4 cybersecurity, 10-year local data retention, and VND-only banking; however, the framework is designed around custodial exchange models and no explicit exemption for non-custodial software exists, creating significant legal ambiguity.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?