1. What she said

Speaking at SIFMA's Digital Assets Conference in New York on 23 September, in her penultimate week as an SEC commissioner, Hester Peirce said know-your-customer and anti-money-laundering rules rest on a simple theory: if institutions collect enough data on enough people, law enforcement will find the criminals among them. The approach, she said, is not working particularly well. Regulators build ever bigger "data haystacks", which make the needles harder to find. She criticised "data maximalists" who assume more collection is always better, and warned that every extra field of personal data the government collects raises the chance that it, or a private party, mishandles it by accident or on purpose.

Her alternative is cryptographic. Attribute-based credentials could attest to specific facts, such as age, citizenship, accredited-investor status or absence from sanctions lists, without revealing the data behind them. A zero-knowledge proof, she said, can tell a counterparty "Yes, this person meets your requirement" without disclosing a name, income or address. She also called for firms to be allowed to rely on another regulated entity's identity checks, instead of each one collecting and storing the same documents. The tools exist, she said; the regulatory framework does not. She stressed that her views are her own, not the SEC's.

2. Why it resonates in France

France has become the clearest illustration of what happens when data about crypto holders escapes. On 30 June, Interior Minister Laurent Nuñez said authorities had recorded 77 cases of kidnapping, sequestration, extortion or attempts linked to crypto assets since January, against 45 in all of 2025. Chainalysis counts 30 publicly documented violent attacks in France in the first half of 2026, more than any other country, against 19 in 2025, and estimates that more than 30 million dollars was stolen through physical coercion worldwide over the same period.

Chainalysis calls the alleged misuse of French tax records the likeliest driver of the surge. A tax official, Ghalia C., has been held since 30 June 2025, charged with complicity in violence against a prison officer and criminal association. According to Le Parisien's reporting, investigators say she used the tax administration's Mira system to look up targets, including crypto investors, and found Western Union transfers suggesting she was paid. She is presumed innocent. Separately, a breach at crypto tax-reporting company Waltio reportedly exposed data on about 50,000 users in January. Public evidence does not show that every 2026 victim was identified through those files.

The tax administration's own systems have also been breached this year. In August, Bercy confirmed illegitimate access to the DGFiP's information system in June and July 2026, using stolen credentials of public agents, which allowed data on individuals and professionals to be viewed and extracted. Earlier in the year, an intrusion hit FICOBA, the national bank-account register, affecting about 1.2 million accounts, according to a written question to the National Assembly. No public evidence links either breach to attacks on crypto holders.

3. What zero-knowledge proofs would change, and what they would not

The honest answer is: part of the problem. Replacing document collection with proofs of attributes would shrink the number of databases holding passports, addresses and balances, and with them the number of insiders and hackers able to reach them. That targets the exposure a KYC leak creates.

It would not have stopped a tax official from querying a tax database. That data is collected under tax rules, not KYC rules, and Europe is moving the other way: since 1 January 2026, the EU's DAC8 directive has required crypto platforms to report their users' identities and transactions to tax authorities. The principle Peirce defends, collect the fact rather than the document, applies there too. The law does not.

Watch:

• Washington. Whether the SEC and FinCEN take up attribute-based verification after Peirce leaves.

• Paris. Nuñez's promised action plan, and whether it addresses who can query tax data on crypto holders.

• The DGFiP. Whether its investigation shows that data on crypto holders was among the files extracted in June and July.