← Regulations / Vietnam / Operating Models / Self-custodial wallet

Self-custodial wallet / non-custodial software in Vietnam

Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.

Conditional AI-Generated · Unreviewed

Self-custodial wallet is conditionally permitted in Vietnam with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASPs must apply AML/CTF obligations as part of licensing, including internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance.
  • VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000, verifying customer identities to mitigate fraud, money laundering, and terrorist financing.
  • VASPs must retain data on Vietnam servers for 10 years, including transaction history, originator/beneficiary details (e.g., wallet addresses), IP/device logs, and account info.
  • Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection.
  • AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations.
  • Systems must achieve Level 4 cybersecurity (highest standard), including encryption, intrusion detection, and continuous monitoring to support CDD.

Key Restrictions

  • A non-custodial wallet publisher that does not hold, control, or access user funds may still be classified as a VASP under Vietnam's broad framework, triggering the full licensing and AML regime.
  • Foreign investors require a single VND account at a licensed local bank; all transactions use VND.
  • Data must be retained on Vietnam servers for 10 years.
  • Systems must achieve Level 4 cybersecurity (highest standard).
  • Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT.

Key Risks

  • The framework is designed around custodial exchange-type VASPs; whether a pure non-custodial software publisher is in scope is legally ambiguous and untested.
  • No explicit exemption for non-custodial wallets exists in the pilot licensing framework (Resolution No. 05/2025/NQ-CP).
  • Enforcement precedent (ONUS platform, 2026) shows active criminal prosecution of crypto operators for fraud/money laundering, signaling high risk for unlicensed operators.
  • The AML law (2022) and FATF VASP standards are being proactively adopted, which may extend obligations to software publishers that facilitate transactions.
  • Practical compliance with Level 4 cybersecurity, 10-year local data retention, and VND-only banking may be structurally incompatible with a non-custodial wallet model where the publisher never touches funds or keys.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

The framework mandates VASPs to apply AML/CTF obligations as part of licensing, treating crypto exchanges as market infrastructure akin to securities exchanges. This includes internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance.

licensing 20% confidence

VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000, verifying customer identities to mitigate fraud, money laundering, and terrorist financing.

licensing 20% confidence

VASPs must retain data on Vietnam servers for 10 years, including transaction history, originator/beneficiary details (e.g., wallet addresses), IP/device logs, and account info.

licensing 20% confidence

Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection.

licensing 20% confidence

No explicit STR filing mechanism is detailed in pilot docs, but AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations.

licensing 20% confidence

Systems must achieve Level 4 cybersecurity (highest standard), including encryption, intrusion detection, and continuous monitoring to support CDD.

licensing 20% confidence

Foreign investors require a single VND account at a licensed local bank; all transactions use VND.

licensing 20% confidence

Key reference: Resolution No. 05/2025/NQ-CP (September 9, 2025) establishes the licensing regime with AML/CTF as a core objective; Decision No. 96/QD-BTC details procedures, including AML appraisals.

licensing 20% confidence

Oversight involves MOF (lead), SSC (receiving applications), SBV (financial integrity), and MPS (AML, cybersecurity).

enforcement 60% confidence

Entity Targeted: ONUS cryptocurrency platform (including tokens VNDC, ONUS, and HNG), operated by Vương Lê Vĩnh Nhân (Eric Lê/Vuong Le Vinh Nhan) and associates. Violation Type: Fraud via token price manipulation, deceptive marketing, misleading promotions, artificial trading to control supply/demand, property appropriation, and money laundering using platform infrastructure. Penalty Amount: Not yet finalized; investigation targets billions of dollars in mobilized funds and investor losses (preliminary estimates in billions of USD).

licensing 20% confidence

Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a non-custodial wallet publisher likely triggers VASP classification under Vietnam's 2025 pilot licensing regime, requiring a local entity, a high-burden license with AML/KYC obligations, Level 4 cybersecurity, 10-year local data retention, and VND-only banking; however, the framework is designed around custodial exchange models and no explicit exemption for non-custodial software exists, creating significant legal ambiguity.

Questions this verdict aims to answer

  • Does software publishing trigger VASP / MSB classification?
  • Do AML obligations attach when no custody exists?
  • What disclosure or consumer-protection rules apply?