Brazil's Central Bank Orders Self-Custody Reporting at $10K
Brazil's central bank issued Resolutions 588 and 589 on September 24, requiring licensed exchanges to report all self-custody wallet transfers at or above $10,000 to the country's AML watchdog. The rules take effect October 1.

Brazil's BCB just turned every licensed exchange into a mandatory informant on users who move their own bitcoin.
Key takeaways
- Brazil's Central Bank issued Resolutions 588 and 589 on September 24, 2026, requiring BCB-authorized exchanges to report all self-custody wallet transfers at or above $10,000 to COAF, Brazil's AML watchdog, effective October 1.
- COAF could compile the reported data into a self-custody address database, mapping which Brazilian exchange customers hold bitcoin on-chain by treating each withdrawal report as a building block.
- With only 5 of an estimated 120 active crypto providers having filed for a BCB license (one already denied), the Brazilian on-ramp market is consolidating into a handful of regulated choke points, concentrating the surveillance surface.
The Central Bank of Brazil (Banco Central do Brasil) issued Resolution 588 and Resolution 589 on September 24, 2026, establishing mandatory reporting requirements for self-custody wallet activity and cutting licensed institutions off from any counterparty not authorized to operate in Brazil. Both rules take effect October 1. The BCB framed self-custody wallets as an information gap, stating directly in Resolution 588 that they "can reduce the availability of information for monitoring and risk assessment purposes, unlike cases in which assets are held in custody in an institution authorized by the Central Bank." That framing is not ambiguous about the goal.
Two Rules That Work as One System
Resolution 588 requires BCB-authorized institutions to file reports with COAF (Conselho de Controle de Atividades Financeiras, Brazil's national financial intelligence unit) on any transfer of virtual assets to or from a self-custodial wallet valued at or above the equivalent of $10,000. The resolution text describes a single-transfer threshold; whether the rule also aggregates smaller same-day transfers is not confirmed in the public resolution text available at publish time. At $10,000 or above, reporting is automatic.
Resolution 589 closes the other exit. It bans licensed VASPs from transacting with any entity providing virtual asset services that is not BCB-authorized. No unlicensed foreign exchange, no peer-to-peer desk that hasn't cleared Brazilian regulators.
Together, the two rules function as a gate-and-camera system. Resolution 589 ensures that any Brazilian who wants to use a regulated on-ramp must go through a BCB-authorized institution. Resolution 588 installs the reporting obligation at the moment that user moves funds to self-custody. The exchange becomes the informant. The user does not need to do anything wrong.
What COAF Does With the Data
COAF is Brazil's equivalent of FinCEN. It receives reports from financial institutions and can compile them into investigative databases. The BCB's own resolution language raises the explicit possibility that COAF could organize these transaction reports into a self-custody address registry, linking exchange KYC identities to on-chain wallet addresses, transaction by transaction, over time.
No individual transaction needs to be flagged as suspicious. The $10,000 threshold is not calibrated to criminal behavior. It sweeps in routine sovereign-individual activity: moving savings to cold storage, consolidating UTXOs, dollar-cost averaging out of an exchange. What the rule builds, mechanically, is a potential government ledger of which Brazilians own self-custody wallets and roughly what they hold.
The market context sharpens the risk. According to a CertiK intelligence report, approximately 120 crypto providers operate in Brazil. According to Valor Econômico, only 5 have applied for a BCB license. One application has already been denied, reportedly for failing to prove prior operational activity and insufficient capital. Minimum capital requirements under the BCB's VASP framework run from R$10.8 million to R$37.2 million depending on business model. That means the entire Brazilian on-ramp market is collapsing into a handful of BCB-controlled institutions, all of which are now legally required to report their users' self-custody activity to COAF. Fewer exchanges, all of them reporting, all of them walled off from unlicensed counterparties. The surveillance surface concentrates exactly as the number of licensed players shrinks.
This is not an isolated regulatory experiment. Brazil is a G20 economy and a FATF member state. FATF's 2021 updated guidance already pushed VASPs to identify and report on "unhosted wallet" counterparties. Brazil is now operationalizing that guidance at scale, building the compliance and data infrastructure the framework always implied. The EU's MiCA regime and the UK's FCA have comparable language under active development. Brazil gives those regulators a live case study and a legitimizing precedent. The Russia digital ruble rollout and Brazil's move are different mechanisms toward the same outcome: full state visibility into who holds what outside the banking system.
What to Watch
The falsifiable version of this thesis: if COAF publicly commits to using Resolution 588 data exclusively for targeted criminal investigations, with judicial oversight, clear data retention limits, and no passive address-mapping program, and Brazil's legislature follows with a statutory right to self-custody backed by privacy protections, then this is standard AML hygiene. Watch for those commitments before October 1. The BCB's own language about self-custody "reducing information availability" suggests the agency views comprehensive informational parity, not targeted investigation, as the goal. The trigger that would disprove that reading hasn't appeared.
Sources
Frequently Asked Questions
Does Resolution 588 ban self-custody in Brazil?
No. The BCB preserved the right to hold one's own keys. Resolution 588 places the reporting obligation on the licensed exchange, not the user. A Brazilian can still withdraw to a self-custody wallet. The exchange is simply required to file a report with COAF whenever that withdrawal equals or exceeds $10,000. The surveillance is at the gate, not in the wallet.
What is COAF and what can it do with the reported data?
COAF is Brazil's financial intelligence unit, analogous to FinCEN in the United States. It receives reports from regulated financial institutions and can compile them into investigative databases. The concern documented in Resolution 588 itself is that COAF could passively accumulate a registry of self-custody wallet addresses linked to exchange KYC identities, without any individual transaction needing to be classified as suspicious activity.
How does this connect to FATF's travel rule and what countries might follow?
FATF's travel rule already requires VASPs to pass sender and receiver information on transfers above threshold between custodial institutions. Resolution 588 extends that logic to self-hosted wallets, requiring the licensed exchange to identify and report the self-custody address even when no licensed VASP counterparty exists on the other side. That is the direction FATF guidance has been pointing since 2021. Brazil operationalizing it gives regulators in the EU, UK, Southeast Asia, and eventually the United States a working template.


