---
title: "Brazil's self-custody wallet rule: COAF reporting for transfers of US$10,000 or more"
seoTitle: "Brazil self-custody wallet rule: COAF reporting explained"
description: "Since October 1, 2026, Brazil requires reports to COAF on transfers of US$10,000+ to or from self-custodied wallets. What counts, who reports, what to do."
date: "2026-10-03"
updated: "2026-10-03"
category: "compliance"
author: "BlindPay Team"
faq:
  - q: "What is Brazil's self-custody wallet reporting rule?"
    a: "It is an amendment to Circular 3.978, the Central Bank of Brazil's anti-money laundering rule. Since October 1, 2026, institutions authorized by the Central Bank must report to COAF every transfer of virtual assets to or from a self-custodied wallet worth US$10,000 or more. Resolution 588 introduced it on September 23, 2026, and Resolution 591 replaced it a week later with the same threshold."
  - q: "Is self-custody banned or restricted in Brazil?"
    a: "No. Brazilians can still hold stablecoins and other virtual assets in wallets they control, and can still move them to and from regulated providers. The rule adds a report to COAF above US$10,000. A separate rule, Resolution 584, adds a 24-hour precautionary hold on some large outgoing transfers to self-custodied wallets from January 1, 2027."
  - q: "When do the first reports have to be filed?"
    a: "Normally, a report under Article 49 of Circular 3.978 is due by the next business day after the transfer. Resolution 591 made an exception for the start: transfers made between October 1 and December 31, 2026 are reported on the first business day of January 2027. The obligation to identify and record those transfers still applies from October 1."
  - q: "Does a wallet at an exchange count as self-custodied?"
    a: "No. A wallet is self-custodied when the owner alone controls the private key and can move funds without a virtual asset service provider taking part. A deposit address at an exchange, or a wallet held by a custodian or another payment provider, is not self-custodied, because a third party can move the funds without the owner's approval."
  - q: "Does the rule apply to companies outside Brazil?"
    a: "The reporting duty sits with institutions authorized by the Central Bank of Brazil. A foreign company paying Brazilian contractors or collecting from Brazilian customers through a regulated provider usually does not file the report itself. It does feel the rule, because its provider has to ask whether each Brazilian customer's external wallet is self-custodied and may need more data on large transfers."
  - q: "What happens if a wallet's self-custody status is answered wrong?"
    a: "A wrong answer means transfers that should be reported may be missed, or transfers that should not be reported get filed. Providers usually treat the answer as a compliance record and lock it once saved. On BlindPay, a saved answer cannot be changed through the dashboard or the API; support corrects it on request with the wallet ID."
howto:
  name: "How to declare whether a Brazilian customer's wallet is self-custodied"
  steps:
    - name: "Find the affected customers"
      text: "List every customer whose country is Brazil. Individuals and businesses are both in scope. Customers in other countries are not."
    - name: "List their external wallets without an answer"
      text: "Pull each Brazilian customer's external blockchain wallets and keep the ones where the self-custody field is still empty. Provider-managed wallets are out of scope."
    - name: "Ask the customer one question"
      text: "Ask whether a third party can move funds out of the wallet without the customer's approval. If no one can, the wallet is self-custodied."
    - name: "Save the answer once"
      text: "Record yes or no on each existing wallet in the dashboard or through the API. Treat the answer as final, because it drives regulatory reporting."
    - name: "Send the field on every new wallet"
      text: "Include the self-custody answer when adding any new wallet for a Brazilian customer, so the request does not fail once the field becomes required."
---

Brazil now requires a report to COAF, its financial intelligence unit, for every transfer of virtual assets worth US$10,000 or more to or from a self-custodied wallet. The rule took effect on October 1, 2026. Self-custody is not banned. Providers must know which wallets are self-custodied, so expect to be asked.

This article is general information, not legal advice. Confirm how the rules apply to your business with qualified Brazilian counsel.

**Key takeaways**

- The rule amends Article 49 of Circular 3.978, the Central Bank's AML rule. It is an automatic report triggered by amount, not a suspicious activity report.
- The threshold is US$10,000 or the equivalent, per transfer, in either direction: into a self-custodied wallet or out of one.
- Resolution 588 (September 23, 2026) created the rule. Resolution 591 (September 30, 2026) replaced it, kept the threshold, and moved reports for October to December 2026 to the first business day of January 2027.
- A wallet counts as self-custodied when the owner alone holds the private key. Exchange deposit addresses and custodian wallets don't count.
- A second rule follows: from January 1, 2027, Resolution 584 adds a 24-hour precautionary hold on large outgoing transfers to self-custodied wallets.

## What does Brazil's self-custody wallet rule require?

Brazil's rule requires institutions authorized by the Central Bank to report to COAF every transfer of virtual assets to or from a self-custodied wallet worth US$10,000 or more.

The text is short. [Resolution BCB 591](https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=591) adds a fifth item to the list of operations that Article 49 of [Circular 3.978](https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Circular&numero=3978) says must always be reported. The other four are large cash operations: deposits, withdrawals, and payments in cash of R$50,000 or more, and foreign exchange with physical currency of US$10,000 or more.

That neighbor list tells you how the Central Bank sees self-custody. It treats a large transfer to a wallet nobody else controls the way it treats a large cash withdrawal: money leaving the part of the system where a regulated institution can see where it goes next.

Three details matter in practice:

- **It's automatic.** The report is triggered by the amount and the wallet type. Nobody has to suspect anything.
- **It runs both ways.** Stablecoins sent from a provider to a self-custodied wallet count. So do stablecoins arriving from one.
- **It's silent.** Article 50 of Circular 3.978 says these reports are made without telling the people involved. Your customer won't get a notice for each one.

## How did Resolutions 588 and 591 get here?

The Central Bank issued the rule twice in one week, and only the second version is in force.

| Date | Rule | What it did |
| --- | --- | --- |
| November 10, 2025 | Resolution BCB 521 | Defined a self-custodied wallet and required providers to identify its owner |
| August 7, 2026 | Resolution BCB 584 | Added a 24-hour precautionary hold on some transfers to self-custodied wallets, effective January 1, 2027 |
| September 23, 2026 | Resolution BCB 588 | Added the US$10,000 self-custody report to Circular 3.978, effective October 1, 2026 |
| September 30, 2026 | Resolution BCB 591 | Revoked 588, restated the same rule, and deferred reports for October to December 2026 to January 2027 |
| October 1, 2026 | Reporting rule in force | Transfers from this date are in scope |
| First business day of January 2027 | First filing date | Reports for the October to December 2026 transfers are due |

After January 2027, the normal deadline applies again. Article 49 reports are due by the next business day after the operation.

Two things to take from the deferral. First, the transfers are in scope now, so providers have to identify and record them from October 1 even though nothing is filed until January. Second, many documents written in late September still cite Resolution 588. The rule is the same, but the citation is to a revoked resolution.

## What counts as a self-custodied wallet?

A self-custodied wallet is one whose owner holds the private key and can move funds without a virtual asset service provider taking part. That's the definition in [Resolution BCB 521](https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=521), Brazil's rule for virtual asset transfers and foreign exchange.

| Self-custodied | Not self-custodied |
| --- | --- |
| A browser or mobile wallet app where the user holds the seed phrase | A deposit address at an exchange |
| A hardware wallet | A wallet held by a custodian or regulated custody provider |
| A multisig or smart-account wallet the customer controls | A wallet at another payment provider that holds the keys |

The test that works in a support conversation is one question: "Can a third party move funds out of this wallet without your approval?" If the answer is no, the wallet is self-custodied.

Smart accounts and multisigs trip people up. If the customer's own keys control the wallet, it's self-custodied, even when the wallet is a smart contract. If a service provider holds a key that can move funds alone, it isn't.

The broader trade-offs between these models are in [custodial vs non-custodial vs MPC wallets](/resources/more/custodial-vs-non-custodial-vs-mpc-wallets).

## Who files the report, and who has to change something?

The report is filed by institutions authorized by the Central Bank of Brazil. Since the [PSAV regime](/resources/more/psav-brazil-explained) took effect, that group includes licensed virtual asset service providers.

Everyone else in the chain changes something, even if they never touch COAF:

| Who | What changes |
| --- | --- |
| Brazilian individuals and businesses with their own wallets | They get asked, once per wallet, whether they control it. Large transfers to or from those wallets are reported |
| Fintechs and platforms whose Brazilian users connect external wallets | Your onboarding flow needs the self-custody question, and your provider will need the answer per wallet |
| Foreign companies paying Brazilian contractors in stablecoins | If contractors receive to wallets they control, those wallets fall in scope through the provider's records |
| Companies paying Brazil in reais over Pix | No wallet sits on the Brazilian side of a Pix payout, so this rule doesn't apply to that leg |

That last row matters for the most common corridor. If a US company sends USDC to a provider that pays out reais over Pix, the recipient never touches a wallet. The [USDC to Brazil payout guide](/resources/more/how-to-send-usdc-to-bank-account-brazil) walks through that flow.

## What changes from January 2027 under Resolution 584?

From January 1, 2027, [Resolution BCB 584](https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=584) requires a 24-hour precautionary hold on some outgoing transfers to self-custodied wallets, and to virtual asset businesses set up abroad.

The hold counts 24 hours from when the funds arrived at the provider. It applies to transfers above US$10,000, measured per operation or as the customer's total for the day, and to smaller ones the provider's risk policy flags. Stablecoins are explicitly included.

The hold is not a freeze. The customer must be told it was applied, why, and for how long. The provider can release early with a documented, reasoned decision. At the end, it either releases the transfer or rejects it.

For product teams, this is the bigger change. The October rule adds a report nobody sees. The January rule adds a day of latency to a large withdrawal unless the provider releases it early. Build that into the timing you show users.

## How should a business prepare?

Collect the self-custody answer once per wallet, store it as a compliance record, and plan for the January hold.

1. **Map where Brazilian wallets enter your product.** Onboarding, withdrawal settings, payout destinations. Every place a Brazilian user adds an external address needs the question.
2. **Ask in plain language.** Use the third-party question above, not "is this self-custodied?" Most users don't know the term.
3. **Store the answer next to the address.** Keep who answered and when. Treat it as final, and route corrections through a reviewed process, not a settings toggle.
4. **Backfill existing wallets.** Find every Brazilian user's saved wallet without an answer and ask before the field becomes mandatory with your provider.
5. **Update customer-facing copy.** Say plainly that large transfers to or from personal wallets are reported to Brazilian authorities under Central Bank rules. Don't promise anything about specific reports, since those are silent by law.
6. **Model the January hold.** For outgoing transfers above US$10,000 to personal wallets, show "up to 24 hours" instead of "minutes" from January 1, 2027.
7. **Check your other wallet controls.** Self-custody status overlaps with [Travel Rule checks](/resources/more/travel-rule-stablecoin-off-ramps) on unhosted wallets. One wallet record can serve both.

## How does BlindPay handle the self-custody declaration?

BlindPay asks for the answer on each external blockchain wallet added for a customer whose country is Brazil, individuals and businesses alike. Managed wallets, which BlindPay creates and custodies, are out of scope, and the field is optional for customers in other countries.

Two dates apply:

- **October 1, 2026:** the `is_self_custody` field on blockchain wallets and the matching dashboard question became available. Requests without it still succeed.
- **October 10, 2026:** the field becomes required for Brazilian customers. Adding a wallet without it fails with `400 self_custody_required`.

Existing wallets without an answer return `is_self_custody: null` and keep working. Each one can be answered once, in the dashboard or with a `PATCH` on the wallet, and a second attempt returns `409 self_custody_already_set`. The [self-custody wallets guide](/docs/kb/self-custody-wallets) in BlindPay's docs has the requests and errors.

New to how wallets, payouts, and on-ramps fit together? The [types of stablecoin APIs](/resources/more/types-of-stablecoin-apis) guide maps who holds the funds in each model.

## What to do next

List your Brazilian customers' external wallets today, ask the one-question test for each, and save the answers before October 10. Then put "up to 24 hours" on large outgoing transfers to personal wallets in your January 2027 release notes.
