[{"data":1,"prerenderedAt":663},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Fbrazil-self-custody-wallet-declaration":3,"resources-category-brazil-self-custody-wallet-declaration":535},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":484,"categoryType":6,"compare":6,"contributors":6,"date":485,"description":486,"extension":487,"faq":488,"howto":507,"isBlog":525,"isChangelog":525,"meta":526,"navigation":528,"path":529,"pillar":525,"products":6,"rawbody":530,"role":6,"seo":531,"seoTitle":532,"stem":533,"thumbnail":6,"updated":485,"__hash__":534},"content\u002Fresources\u002Fmore\u002Fbrazil-self-custody-wallet-declaration.md","Brazil's self-custody wallet rule: COAF reporting for transfers of US$10,000 or more",null,{"type":8,"value":9,"toc":472},"minimark",[10,14,17,23,42,47,50,67,70,73,93,97,100,188,191,194,198,206,244,247,250,258,262,270,273,319,327,331,339,342,345,348,352,355,405,409,412,415,437,457,465,469],[11,12,13],"p",{},"Brazil now requires a report to COAF, its financial intelligence unit, for every transfer of virtual assets worth US$10,000 or more to or from a self-custodied wallet. The rule took effect on October 1, 2026. Self-custody is not banned. Providers must know which wallets are self-custodied, so expect to be asked.",[11,15,16],{},"This article is general information, not legal advice. Confirm how the rules apply to your business with qualified Brazilian counsel.",[11,18,19],{},[20,21,22],"strong",{},"Key takeaways",[24,25,26,30,33,36,39],"ul",{},[27,28,29],"li",{},"The rule amends Article 49 of Circular 3.978, the Central Bank's AML rule. It is an automatic report triggered by amount, not a suspicious activity report.",[27,31,32],{},"The threshold is US$10,000 or the equivalent, per transfer, in either direction: into a self-custodied wallet or out of one.",[27,34,35],{},"Resolution 588 (September 23, 2026) created the rule. Resolution 591 (September 30, 2026) replaced it, kept the threshold, and moved reports for October to December 2026 to the first business day of January 2027.",[27,37,38],{},"A wallet counts as self-custodied when the owner alone holds the private key. Exchange deposit addresses and custodian wallets don't count.",[27,40,41],{},"A second rule follows: from January 1, 2027, Resolution 584 adds a 24-hour precautionary hold on large outgoing transfers to self-custodied wallets.",[43,44,46],"h2",{"id":45},"what-does-brazils-self-custody-wallet-rule-require","What does Brazil's self-custody wallet rule require?",[11,48,49],{},"Brazil's rule requires institutions authorized by the Central Bank to report to COAF every transfer of virtual assets to or from a self-custodied wallet worth US$10,000 or more.",[11,51,52,53,60,61,66],{},"The text is short. ",[54,55,59],"a",{"href":56,"rel":57},"https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=591",[58],"nofollow","Resolution BCB 591"," adds a fifth item to the list of operations that Article 49 of ",[54,62,65],{"href":63,"rel":64},"https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Circular&numero=3978",[58],"Circular 3.978"," says must always be reported. The other four are large cash operations: deposits, withdrawals, and payments in cash of R$50,000 or more, and foreign exchange with physical currency of US$10,000 or more.",[11,68,69],{},"That neighbor list tells you how the Central Bank sees self-custody. It treats a large transfer to a wallet nobody else controls the way it treats a large cash withdrawal: money leaving the part of the system where a regulated institution can see where it goes next.",[11,71,72],{},"Three details matter in practice:",[24,74,75,81,87],{},[27,76,77,80],{},[20,78,79],{},"It's automatic."," The report is triggered by the amount and the wallet type. Nobody has to suspect anything.",[27,82,83,86],{},[20,84,85],{},"It runs both ways."," Stablecoins sent from a provider to a self-custodied wallet count. So do stablecoins arriving from one.",[27,88,89,92],{},[20,90,91],{},"It's silent."," Article 50 of Circular 3.978 says these reports are made without telling the people involved. Your customer won't get a notice for each one.",[43,94,96],{"id":95},"how-did-resolutions-588-and-591-get-here","How did Resolutions 588 and 591 get here?",[11,98,99],{},"The Central Bank issued the rule twice in one week, and only the second version is in force.",[101,102,103,119],"table",{},[104,105,106],"thead",{},[107,108,109,113,116],"tr",{},[110,111,112],"th",{},"Date",[110,114,115],{},"Rule",[110,117,118],{},"What it did",[120,121,122,134,145,156,166,177],"tbody",{},[107,123,124,128,131],{},[125,126,127],"td",{},"November 10, 2025",[125,129,130],{},"Resolution BCB 521",[125,132,133],{},"Defined a self-custodied wallet and required providers to identify its owner",[107,135,136,139,142],{},[125,137,138],{},"August 7, 2026",[125,140,141],{},"Resolution BCB 584",[125,143,144],{},"Added a 24-hour precautionary hold on some transfers to self-custodied wallets, effective January 1, 2027",[107,146,147,150,153],{},[125,148,149],{},"September 23, 2026",[125,151,152],{},"Resolution BCB 588",[125,154,155],{},"Added the US$10,000 self-custody report to Circular 3.978, effective October 1, 2026",[107,157,158,161,163],{},[125,159,160],{},"September 30, 2026",[125,162,59],{},[125,164,165],{},"Revoked 588, restated the same rule, and deferred reports for October to December 2026 to January 2027",[107,167,168,171,174],{},[125,169,170],{},"October 1, 2026",[125,172,173],{},"Reporting rule in force",[125,175,176],{},"Transfers from this date are in scope",[107,178,179,182,185],{},[125,180,181],{},"First business day of January 2027",[125,183,184],{},"First filing date",[125,186,187],{},"Reports for the October to December 2026 transfers are due",[11,189,190],{},"After January 2027, the normal deadline applies again. Article 49 reports are due by the next business day after the operation.",[11,192,193],{},"Two things to take from the deferral. First, the transfers are in scope now, so providers have to identify and record them from October 1 even though nothing is filed until January. Second, many documents written in late September still cite Resolution 588. The rule is the same, but the citation is to a revoked resolution.",[43,195,197],{"id":196},"what-counts-as-a-self-custodied-wallet","What counts as a self-custodied wallet?",[11,199,200,201,205],{},"A self-custodied wallet is one whose owner holds the private key and can move funds without a virtual asset service provider taking part. That's the definition in ",[54,202,130],{"href":203,"rel":204},"https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=521",[58],", Brazil's rule for virtual asset transfers and foreign exchange.",[101,207,208,218],{},[104,209,210],{},[107,211,212,215],{},[110,213,214],{},"Self-custodied",[110,216,217],{},"Not self-custodied",[120,219,220,228,236],{},[107,221,222,225],{},[125,223,224],{},"A browser or mobile wallet app where the user holds the seed phrase",[125,226,227],{},"A deposit address at an exchange",[107,229,230,233],{},[125,231,232],{},"A hardware wallet",[125,234,235],{},"A wallet held by a custodian or regulated custody provider",[107,237,238,241],{},[125,239,240],{},"A multisig or smart-account wallet the customer controls",[125,242,243],{},"A wallet at another payment provider that holds the keys",[11,245,246],{},"The test that works in a support conversation is one question: \"Can a third party move funds out of this wallet without your approval?\" If the answer is no, the wallet is self-custodied.",[11,248,249],{},"Smart accounts and multisigs trip people up. If the customer's own keys control the wallet, it's self-custodied, even when the wallet is a smart contract. If a service provider holds a key that can move funds alone, it isn't.",[11,251,252,253,257],{},"The broader trade-offs between these models are in ",[54,254,256],{"href":255},"\u002Fresources\u002Fmore\u002Fcustodial-vs-non-custodial-vs-mpc-wallets","custodial vs non-custodial vs MPC wallets",".",[43,259,261],{"id":260},"who-files-the-report-and-who-has-to-change-something","Who files the report, and who has to change something?",[11,263,264,265,269],{},"The report is filed by institutions authorized by the Central Bank of Brazil. Since the ",[54,266,268],{"href":267},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","PSAV regime"," took effect, that group includes licensed virtual asset service providers.",[11,271,272],{},"Everyone else in the chain changes something, even if they never touch COAF:",[101,274,275,285],{},[104,276,277],{},[107,278,279,282],{},[110,280,281],{},"Who",[110,283,284],{},"What changes",[120,286,287,295,303,311],{},[107,288,289,292],{},[125,290,291],{},"Brazilian individuals and businesses with their own wallets",[125,293,294],{},"They get asked, once per wallet, whether they control it. Large transfers to or from those wallets are reported",[107,296,297,300],{},[125,298,299],{},"Fintechs and platforms whose Brazilian users connect external wallets",[125,301,302],{},"Your onboarding flow needs the self-custody question, and your provider will need the answer per wallet",[107,304,305,308],{},[125,306,307],{},"Foreign companies paying Brazilian contractors in stablecoins",[125,309,310],{},"If contractors receive to wallets they control, those wallets fall in scope through the provider's records",[107,312,313,316],{},[125,314,315],{},"Companies paying Brazil in reais over Pix",[125,317,318],{},"No wallet sits on the Brazilian side of a Pix payout, so this rule doesn't apply to that leg",[11,320,321,322,326],{},"That last row matters for the most common corridor. If a US company sends USDC to a provider that pays out reais over Pix, the recipient never touches a wallet. The ",[54,323,325],{"href":324},"\u002Fresources\u002Fmore\u002Fhow-to-send-usdc-to-bank-account-brazil","USDC to Brazil payout guide"," walks through that flow.",[43,328,330],{"id":329},"what-changes-from-january-2027-under-resolution-584","What changes from January 2027 under Resolution 584?",[11,332,333,334,338],{},"From January 1, 2027, ",[54,335,141],{"href":336,"rel":337},"https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=584",[58]," requires a 24-hour precautionary hold on some outgoing transfers to self-custodied wallets, and to virtual asset businesses set up abroad.",[11,340,341],{},"The hold counts 24 hours from when the funds arrived at the provider. It applies to transfers above US$10,000, measured per operation or as the customer's total for the day, and to smaller ones the provider's risk policy flags. Stablecoins are explicitly included.",[11,343,344],{},"The hold is not a freeze. The customer must be told it was applied, why, and for how long. The provider can release early with a documented, reasoned decision. At the end, it either releases the transfer or rejects it.",[11,346,347],{},"For product teams, this is the bigger change. The October rule adds a report nobody sees. The January rule adds a day of latency to a large withdrawal unless the provider releases it early. Build that into the timing you show users.",[43,349,351],{"id":350},"how-should-a-business-prepare","How should a business prepare?",[11,353,354],{},"Collect the self-custody answer once per wallet, store it as a compliance record, and plan for the January hold.",[356,357,358,364,370,376,382,388,394],"ol",{},[27,359,360,363],{},[20,361,362],{},"Map where Brazilian wallets enter your product."," Onboarding, withdrawal settings, payout destinations. Every place a Brazilian user adds an external address needs the question.",[27,365,366,369],{},[20,367,368],{},"Ask in plain language."," Use the third-party question above, not \"is this self-custodied?\" Most users don't know the term.",[27,371,372,375],{},[20,373,374],{},"Store the answer next to the address."," Keep who answered and when. Treat it as final, and route corrections through a reviewed process, not a settings toggle.",[27,377,378,381],{},[20,379,380],{},"Backfill existing wallets."," Find every Brazilian user's saved wallet without an answer and ask before the field becomes mandatory with your provider.",[27,383,384,387],{},[20,385,386],{},"Update customer-facing copy."," Say plainly that large transfers to or from personal wallets are reported to Brazilian authorities under Central Bank rules. Don't promise anything about specific reports, since those are silent by law.",[27,389,390,393],{},[20,391,392],{},"Model the January hold."," For outgoing transfers above US$10,000 to personal wallets, show \"up to 24 hours\" instead of \"minutes\" from January 1, 2027.",[27,395,396,399,400,404],{},[20,397,398],{},"Check your other wallet controls."," Self-custody status overlaps with ",[54,401,403],{"href":402},"\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps","Travel Rule checks"," on unhosted wallets. One wallet record can serve both.",[43,406,408],{"id":407},"how-does-blindpay-handle-the-self-custody-declaration","How does BlindPay handle the self-custody declaration?",[11,410,411],{},"BlindPay asks for the answer on each external blockchain wallet added for a customer whose country is Brazil, individuals and businesses alike. Managed wallets, which BlindPay creates and custodies, are out of scope, and the field is optional for customers in other countries.",[11,413,414],{},"Two dates apply:",[24,416,417,428],{},[27,418,419,422,423,427],{},[20,420,421],{},"October 1, 2026:"," the ",[424,425,426],"code",{},"is_self_custody"," field on blockchain wallets and the matching dashboard question became available. Requests without it still succeed.",[27,429,430,433,434,257],{},[20,431,432],{},"October 10, 2026:"," the field becomes required for Brazilian customers. Adding a wallet without it fails with ",[424,435,436],{},"400 self_custody_required",[11,438,439,440,443,444,447,448,451,452,456],{},"Existing wallets without an answer return ",[424,441,442],{},"is_self_custody: null"," and keep working. Each one can be answered once, in the dashboard or with a ",[424,445,446],{},"PATCH"," on the wallet, and a second attempt returns ",[424,449,450],{},"409 self_custody_already_set",". The ",[54,453,455],{"href":454},"\u002Fdocs\u002Fkb\u002Fself-custody-wallets","self-custody wallets guide"," in BlindPay's docs has the requests and errors.",[11,458,459,460,464],{},"New to how wallets, payouts, and on-ramps fit together? The ",[54,461,463],{"href":462},"\u002Fresources\u002Fmore\u002Ftypes-of-stablecoin-apis","types of stablecoin APIs"," guide maps who holds the funds in each model.",[43,466,468],{"id":467},"what-to-do-next","What to do next",[11,470,471],{},"List your Brazilian customers' external wallets today, ask the one-question test for each, and save the answers before October 10. Then put \"up to 24 hours\" on large outgoing transfers to personal wallets in your January 2027 release notes.",{"title":473,"searchDepth":474,"depth":474,"links":475},"",2,[476,477,478,479,480,481,482,483],{"id":45,"depth":474,"text":46},{"id":95,"depth":474,"text":96},{"id":196,"depth":474,"text":197},{"id":260,"depth":474,"text":261},{"id":329,"depth":474,"text":330},{"id":350,"depth":474,"text":351},{"id":407,"depth":474,"text":408},{"id":467,"depth":474,"text":468},"compliance","2026-10-03","Since October 1, 2026, Brazil requires reports to COAF on transfers of US$10,000+ to or from self-custodied wallets. What counts, who reports, what to do.","md",[489,492,495,498,501,504],{"q":490,"a":491},"What is Brazil's self-custody wallet reporting rule?","It is an amendment to Circular 3.978, the Central Bank of Brazil's anti-money laundering rule. Since October 1, 2026, institutions authorized by the Central Bank must report to COAF every transfer of virtual assets to or from a self-custodied wallet worth US$10,000 or more. Resolution 588 introduced it on September 23, 2026, and Resolution 591 replaced it a week later with the same threshold.",{"q":493,"a":494},"Is self-custody banned or restricted in Brazil?","No. Brazilians can still hold stablecoins and other virtual assets in wallets they control, and can still move them to and from regulated providers. The rule adds a report to COAF above US$10,000. A separate rule, Resolution 584, adds a 24-hour precautionary hold on some large outgoing transfers to self-custodied wallets from January 1, 2027.",{"q":496,"a":497},"When do the first reports have to be filed?","Normally, a report under Article 49 of Circular 3.978 is due by the next business day after the transfer. Resolution 591 made an exception for the start: transfers made between October 1 and December 31, 2026 are reported on the first business day of January 2027. The obligation to identify and record those transfers still applies from October 1.",{"q":499,"a":500},"Does a wallet at an exchange count as self-custodied?","No. A wallet is self-custodied when the owner alone controls the private key and can move funds without a virtual asset service provider taking part. A deposit address at an exchange, or a wallet held by a custodian or another payment provider, is not self-custodied, because a third party can move the funds without the owner's approval.",{"q":502,"a":503},"Does the rule apply to companies outside Brazil?","The reporting duty sits with institutions authorized by the Central Bank of Brazil. A foreign company paying Brazilian contractors or collecting from Brazilian customers through a regulated provider usually does not file the report itself. It does feel the rule, because its provider has to ask whether each Brazilian customer's external wallet is self-custodied and may need more data on large transfers.",{"q":505,"a":506},"What happens if a wallet's self-custody status is answered wrong?","A wrong answer means transfers that should be reported may be missed, or transfers that should not be reported get filed. Providers usually treat the answer as a compliance record and lock it once saved. On BlindPay, a saved answer cannot be changed through the dashboard or the API; support corrects it on request with the wallet ID.",{"name":508,"steps":509},"How to declare whether a Brazilian customer's wallet is self-custodied",[510,513,516,519,522],{"name":511,"text":512},"Find the affected customers","List every customer whose country is Brazil. Individuals and businesses are both in scope. Customers in other countries are not.",{"name":514,"text":515},"List their external wallets without an answer","Pull each Brazilian customer's external blockchain wallets and keep the ones where the self-custody field is still empty. Provider-managed wallets are out of scope.",{"name":517,"text":518},"Ask the customer one question","Ask whether a third party can move funds out of the wallet without the customer's approval. If no one can, the wallet is self-custodied.",{"name":520,"text":521},"Save the answer once","Record yes or no on each existing wallet in the dashboard or through the API. Treat the answer as final, because it drives regulatory reporting.",{"name":523,"text":524},"Send the field on every new wallet","Include the self-custody answer when adding any new wallet for a Brazilian customer, so the request does not fail once the field becomes required.",false,{"author":527},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Fbrazil-self-custody-wallet-declaration","---\ntitle: \"Brazil's self-custody wallet rule: COAF reporting for transfers of US$10,000 or more\"\nseoTitle: \"Brazil self-custody wallet rule: COAF reporting explained\"\ndescription: \"Since October 1, 2026, Brazil requires reports to COAF on transfers of US$10,000+ to or from self-custodied wallets. What counts, who reports, what to do.\"\ndate: \"2026-10-03\"\nupdated: \"2026-10-03\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"What is Brazil's self-custody wallet reporting rule?\"\n    a: \"It is an amendment to Circular 3.978, the Central Bank of Brazil's anti-money laundering rule. Since October 1, 2026, institutions authorized by the Central Bank must report to COAF every transfer of virtual assets to or from a self-custodied wallet worth US$10,000 or more. Resolution 588 introduced it on September 23, 2026, and Resolution 591 replaced it a week later with the same threshold.\"\n  - q: \"Is self-custody banned or restricted in Brazil?\"\n    a: \"No. Brazilians can still hold stablecoins and other virtual assets in wallets they control, and can still move them to and from regulated providers. The rule adds a report to COAF above US$10,000. A separate rule, Resolution 584, adds a 24-hour precautionary hold on some large outgoing transfers to self-custodied wallets from January 1, 2027.\"\n  - q: \"When do the first reports have to be filed?\"\n    a: \"Normally, a report under Article 49 of Circular 3.978 is due by the next business day after the transfer. Resolution 591 made an exception for the start: transfers made between October 1 and December 31, 2026 are reported on the first business day of January 2027. The obligation to identify and record those transfers still applies from October 1.\"\n  - q: \"Does a wallet at an exchange count as self-custodied?\"\n    a: \"No. A wallet is self-custodied when the owner alone controls the private key and can move funds without a virtual asset service provider taking part. A deposit address at an exchange, or a wallet held by a custodian or another payment provider, is not self-custodied, because a third party can move the funds without the owner's approval.\"\n  - q: \"Does the rule apply to companies outside Brazil?\"\n    a: \"The reporting duty sits with institutions authorized by the Central Bank of Brazil. A foreign company paying Brazilian contractors or collecting from Brazilian customers through a regulated provider usually does not file the report itself. It does feel the rule, because its provider has to ask whether each Brazilian customer's external wallet is self-custodied and may need more data on large transfers.\"\n  - q: \"What happens if a wallet's self-custody status is answered wrong?\"\n    a: \"A wrong answer means transfers that should be reported may be missed, or transfers that should not be reported get filed. Providers usually treat the answer as a compliance record and lock it once saved. On BlindPay, a saved answer cannot be changed through the dashboard or the API; support corrects it on request with the wallet ID.\"\nhowto:\n  name: \"How to declare whether a Brazilian customer's wallet is self-custodied\"\n  steps:\n    - name: \"Find the affected customers\"\n      text: \"List every customer whose country is Brazil. Individuals and businesses are both in scope. Customers in other countries are not.\"\n    - name: \"List their external wallets without an answer\"\n      text: \"Pull each Brazilian customer's external blockchain wallets and keep the ones where the self-custody field is still empty. Provider-managed wallets are out of scope.\"\n    - name: \"Ask the customer one question\"\n      text: \"Ask whether a third party can move funds out of the wallet without the customer's approval. If no one can, the wallet is self-custodied.\"\n    - name: \"Save the answer once\"\n      text: \"Record yes or no on each existing wallet in the dashboard or through the API. Treat the answer as final, because it drives regulatory reporting.\"\n    - name: \"Send the field on every new wallet\"\n      text: \"Include the self-custody answer when adding any new wallet for a Brazilian customer, so the request does not fail once the field becomes required.\"\n---\n\nBrazil now requires a report to COAF, its financial intelligence unit, for every transfer of virtual assets worth US$10,000 or more to or from a self-custodied wallet. The rule took effect on October 1, 2026. Self-custody is not banned. Providers must know which wallets are self-custodied, so expect to be asked.\n\nThis article is general information, not legal advice. Confirm how the rules apply to your business with qualified Brazilian counsel.\n\n**Key takeaways**\n\n- The rule amends Article 49 of Circular 3.978, the Central Bank's AML rule. It is an automatic report triggered by amount, not a suspicious activity report.\n- The threshold is US$10,000 or the equivalent, per transfer, in either direction: into a self-custodied wallet or out of one.\n- Resolution 588 (September 23, 2026) created the rule. Resolution 591 (September 30, 2026) replaced it, kept the threshold, and moved reports for October to December 2026 to the first business day of January 2027.\n- A wallet counts as self-custodied when the owner alone holds the private key. Exchange deposit addresses and custodian wallets don't count.\n- A second rule follows: from January 1, 2027, Resolution 584 adds a 24-hour precautionary hold on large outgoing transfers to self-custodied wallets.\n\n## What does Brazil's self-custody wallet rule require?\n\nBrazil's rule requires institutions authorized by the Central Bank to report to COAF every transfer of virtual assets to or from a self-custodied wallet worth US$10,000 or more.\n\nThe text is short. [Resolution BCB 591](https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=591) adds a fifth item to the list of operations that Article 49 of [Circular 3.978](https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Circular&numero=3978) says must always be reported. The other four are large cash operations: deposits, withdrawals, and payments in cash of R$50,000 or more, and foreign exchange with physical currency of US$10,000 or more.\n\nThat neighbor list tells you how the Central Bank sees self-custody. It treats a large transfer to a wallet nobody else controls the way it treats a large cash withdrawal: money leaving the part of the system where a regulated institution can see where it goes next.\n\nThree details matter in practice:\n\n- **It's automatic.** The report is triggered by the amount and the wallet type. Nobody has to suspect anything.\n- **It runs both ways.** Stablecoins sent from a provider to a self-custodied wallet count. So do stablecoins arriving from one.\n- **It's silent.** Article 50 of Circular 3.978 says these reports are made without telling the people involved. Your customer won't get a notice for each one.\n\n## How did Resolutions 588 and 591 get here?\n\nThe Central Bank issued the rule twice in one week, and only the second version is in force.\n\n| Date | Rule | What it did |\n| --- | --- | --- |\n| November 10, 2025 | Resolution BCB 521 | Defined a self-custodied wallet and required providers to identify its owner |\n| August 7, 2026 | Resolution BCB 584 | Added a 24-hour precautionary hold on some transfers to self-custodied wallets, effective January 1, 2027 |\n| September 23, 2026 | Resolution BCB 588 | Added the US$10,000 self-custody report to Circular 3.978, effective October 1, 2026 |\n| September 30, 2026 | Resolution BCB 591 | Revoked 588, restated the same rule, and deferred reports for October to December 2026 to January 2027 |\n| October 1, 2026 | Reporting rule in force | Transfers from this date are in scope |\n| First business day of January 2027 | First filing date | Reports for the October to December 2026 transfers are due |\n\nAfter January 2027, the normal deadline applies again. Article 49 reports are due by the next business day after the operation.\n\nTwo things to take from the deferral. First, the transfers are in scope now, so providers have to identify and record them from October 1 even though nothing is filed until January. Second, many documents written in late September still cite Resolution 588. The rule is the same, but the citation is to a revoked resolution.\n\n## What counts as a self-custodied wallet?\n\nA self-custodied wallet is one whose owner holds the private key and can move funds without a virtual asset service provider taking part. That's the definition in [Resolution BCB 521](https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=521), Brazil's rule for virtual asset transfers and foreign exchange.\n\n| Self-custodied | Not self-custodied |\n| --- | --- |\n| A browser or mobile wallet app where the user holds the seed phrase | A deposit address at an exchange |\n| A hardware wallet | A wallet held by a custodian or regulated custody provider |\n| A multisig or smart-account wallet the customer controls | A wallet at another payment provider that holds the keys |\n\nThe test that works in a support conversation is one question: \"Can a third party move funds out of this wallet without your approval?\" If the answer is no, the wallet is self-custodied.\n\nSmart accounts and multisigs trip people up. If the customer's own keys control the wallet, it's self-custodied, even when the wallet is a smart contract. If a service provider holds a key that can move funds alone, it isn't.\n\nThe broader trade-offs between these models are in [custodial vs non-custodial vs MPC wallets](\u002Fresources\u002Fmore\u002Fcustodial-vs-non-custodial-vs-mpc-wallets).\n\n## Who files the report, and who has to change something?\n\nThe report is filed by institutions authorized by the Central Bank of Brazil. Since the [PSAV regime](\u002Fresources\u002Fmore\u002Fpsav-brazil-explained) took effect, that group includes licensed virtual asset service providers.\n\nEveryone else in the chain changes something, even if they never touch COAF:\n\n| Who | What changes |\n| --- | --- |\n| Brazilian individuals and businesses with their own wallets | They get asked, once per wallet, whether they control it. Large transfers to or from those wallets are reported |\n| Fintechs and platforms whose Brazilian users connect external wallets | Your onboarding flow needs the self-custody question, and your provider will need the answer per wallet |\n| Foreign companies paying Brazilian contractors in stablecoins | If contractors receive to wallets they control, those wallets fall in scope through the provider's records |\n| Companies paying Brazil in reais over Pix | No wallet sits on the Brazilian side of a Pix payout, so this rule doesn't apply to that leg |\n\nThat last row matters for the most common corridor. If a US company sends USDC to a provider that pays out reais over Pix, the recipient never touches a wallet. The [USDC to Brazil payout guide](\u002Fresources\u002Fmore\u002Fhow-to-send-usdc-to-bank-account-brazil) walks through that flow.\n\n## What changes from January 2027 under Resolution 584?\n\nFrom January 1, 2027, [Resolution BCB 584](https:\u002F\u002Fwww.bcb.gov.br\u002Festabilidadefinanceira\u002Fexibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=584) requires a 24-hour precautionary hold on some outgoing transfers to self-custodied wallets, and to virtual asset businesses set up abroad.\n\nThe hold counts 24 hours from when the funds arrived at the provider. It applies to transfers above US$10,000, measured per operation or as the customer's total for the day, and to smaller ones the provider's risk policy flags. Stablecoins are explicitly included.\n\nThe hold is not a freeze. The customer must be told it was applied, why, and for how long. The provider can release early with a documented, reasoned decision. At the end, it either releases the transfer or rejects it.\n\nFor product teams, this is the bigger change. The October rule adds a report nobody sees. The January rule adds a day of latency to a large withdrawal unless the provider releases it early. Build that into the timing you show users.\n\n## How should a business prepare?\n\nCollect the self-custody answer once per wallet, store it as a compliance record, and plan for the January hold.\n\n1. **Map where Brazilian wallets enter your product.** Onboarding, withdrawal settings, payout destinations. Every place a Brazilian user adds an external address needs the question.\n2. **Ask in plain language.** Use the third-party question above, not \"is this self-custodied?\" Most users don't know the term.\n3. **Store the answer next to the address.** Keep who answered and when. Treat it as final, and route corrections through a reviewed process, not a settings toggle.\n4. **Backfill existing wallets.** Find every Brazilian user's saved wallet without an answer and ask before the field becomes mandatory with your provider.\n5. **Update customer-facing copy.** Say plainly that large transfers to or from personal wallets are reported to Brazilian authorities under Central Bank rules. Don't promise anything about specific reports, since those are silent by law.\n6. **Model the January hold.** For outgoing transfers above US$10,000 to personal wallets, show \"up to 24 hours\" instead of \"minutes\" from January 1, 2027.\n7. **Check your other wallet controls.** Self-custody status overlaps with [Travel Rule checks](\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps) on unhosted wallets. One wallet record can serve both.\n\n## How does BlindPay handle the self-custody declaration?\n\nBlindPay asks for the answer on each external blockchain wallet added for a customer whose country is Brazil, individuals and businesses alike. Managed wallets, which BlindPay creates and custodies, are out of scope, and the field is optional for customers in other countries.\n\nTwo dates apply:\n\n- **October 1, 2026:** the `is_self_custody` field on blockchain wallets and the matching dashboard question became available. Requests without it still succeed.\n- **October 10, 2026:** the field becomes required for Brazilian customers. Adding a wallet without it fails with `400 self_custody_required`.\n\nExisting wallets without an answer return `is_self_custody: null` and keep working. Each one can be answered once, in the dashboard or with a `PATCH` on the wallet, and a second attempt returns `409 self_custody_already_set`. The [self-custody wallets guide](\u002Fdocs\u002Fkb\u002Fself-custody-wallets) in BlindPay's docs has the requests and errors.\n\nNew to how wallets, payouts, and on-ramps fit together? The [types of stablecoin APIs](\u002Fresources\u002Fmore\u002Ftypes-of-stablecoin-apis) guide maps who holds the funds in each model.\n\n## What to do next\n\nList your Brazilian customers' external wallets today, ask the one-question test for each, and save the answers before October 10. Then put \"up to 24 hours\" on large outgoing transfers to personal wallets in your January 2027 release notes.\n",{"title":5,"description":486},"Brazil self-custody wallet rule: COAF reporting explained","resources\u002Fmore\u002Fbrazil-self-custody-wallet-declaration","xe-kcd0LvkYIg4PIgljmZvY_OlT9XkKO2Oozlq6Gzi8",[536,540,544,548,552,553,557,561,565,569,573,577,581,585,589,593,597,600,604,608,612,616,620,624,628,632,636,640,644,648,651,655,659],{"path":537,"title":538,"description":539},"\u002Fresources\u002Fmore\u002Faml-audit-readiness-risk-monitoring","AML audit readiness: what regulators ask for and how to prove your risk monitoring works","The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan.",{"path":541,"title":542,"description":543},"\u002Fresources\u002Fmore\u002Fare-blockchain-payments-legal","Are blockchain payments legal? Rules in the US, EU, UK, Brazil, and Mexico","Blockchain payments are legal for businesses in the US, EU, UK, Brazil, and Mexico, under different rules. What each country regulates, as of October 2026.",{"path":545,"title":546,"description":547},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","Are stablecoin payments reversible? Finality, custody, and fraud explained","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",{"path":549,"title":550,"description":551},"\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","Automated KYC\u002FKYB vs. manual onboarding: what actually changes","A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.",{"path":529,"title":5,"description":486},{"path":554,"title":555,"description":556},"\u002Fresources\u002Fmore\u002Fbuild-vs-buy-automated-risk-monitoring","Build vs. buy automated risk monitoring: a decision framework and 15 provider questions","Build, buy point solutions, or use an integrated provider? Compare three ways to run automated risk monitoring, who stays responsible, and 15 questions.",{"path":558,"title":559,"description":560},"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","Compliance agents for cross-border stablecoin payments: a global regulatory guide","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.",{"path":562,"title":563,"description":564},"\u002Fresources\u002Fmore\u002Fcrypto-wallet-compliance-checklist","Crypto wallet compliance checklist: KYC, KYT, and Travel Rule","The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks.",{"path":566,"title":567,"description":568},"\u002Fresources\u002Fmore\u002Fdirect-vs-indirect-stablecoin-exchange","Direct vs indirect stablecoin exchange: who holds the stablecoin, and who carries compliance","In direct exchange, both parties hold stablecoins and own compliance. In indirect exchange, a provider settles in stablecoins behind a normal bank payment.",{"path":570,"title":571,"description":572},"\u002Fresources\u002Fmore\u002Fdo-merchants-need-a-license-to-accept-stablecoins","Do merchants need a license to accept stablecoin payments? KYC, KYB, and compliance explained","Usually no: the license sits with the provider that moves the funds. What merchants still owe on KYB, sanctions, tax, and records in the US, EU, Brazil.",{"path":574,"title":575,"description":576},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","How to automate KYC and KYB for stablecoin payments","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",{"path":578,"title":579,"description":580},"\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","How to choose an automated risk monitoring vendor for a fintech startup","A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.",{"path":582,"title":583,"description":584},"\u002Fresources\u002Fmore\u002Freduce-false-positives-transaction-monitoring","How to reduce false positives in transaction monitoring without missing real risk","Cut AML alert noise without losing real cases: a 7-step tuning process, the levers that work, the metrics to watch, and what automation should never close.",{"path":586,"title":587,"description":588},"\u002Fresources\u002Fmore\u002Fstablecoin-payment-licenses-msb-mtl-vasp-emi","MSB vs money transmitter license vs VASP vs EMI: which license does a stablecoin payment flow need?","MSB registration, state money transmitter licenses, VASP, EMI, and PSAV compared: who needs each, what triggers it, and when your provider covers you.",{"path":590,"title":591,"description":592},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA stablecoin rules explained for payment companies","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",{"path":594,"title":595,"description":596},"\u002Fresources\u002Fmore\u002Fongoing-sanctions-screening-how-often-to-rescreen","Ongoing sanctions screening: how often to rescreen and what to screen","How often to rescreen customers against sanctions lists, what to screen beyond names, and a cadence that holds up under OFAC strict liability.",{"path":267,"title":598,"description":599},"PSAV in Brazil: the Central Bank's virtual asset license explained","PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",{"path":601,"title":602,"description":603},"\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","Real-time transaction monitoring for cross-border stablecoin payments","Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.",{"path":605,"title":606,"description":607},"\u002Fresources\u002Fmore\u002Fstablecoin-card-issuing-compliance","Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained","What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.",{"path":609,"title":610,"description":611},"\u002Fresources\u002Fmore\u002Fstablecoin-off-ramp-limits","Stablecoin off-ramp limits: per-transaction, daily, and monthly caps explained","Why off-ramps cap how much you can convert per transaction, day, and month, how the caps map to KYC and KYB tiers, and the documents that raise them.",{"path":613,"title":614,"description":615},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan","Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",{"path":617,"title":618,"description":619},"\u002Fresources\u002Fmore\u002Fgenius-act-for-businesses","The GENIUS Act explained for businesses that use stablecoins","What the GENIUS Act means if your business sends, receives, or holds stablecoins: who it regulates, the dates that matter, and what to do before 2027.",{"path":621,"title":622,"description":623},"\u002Fresources\u002Fmore\u002Ftravel-rule-workflow-hold-return-reject","The Travel Rule in an automated workflow: what to collect, when to hold, when to return","How to automate Travel Rule compliance for stablecoin transfers: what data to collect, the checks before release, and when to hold, reject, or return.",{"path":625,"title":626,"description":627},"\u002Fresources\u002Fmore\u002Ftransaction-monitoring-red-flags-stablecoin-payments","Transaction monitoring red flags for stablecoin payments: 12 rules to automate","The 12 red flags automated transaction monitoring should catch in stablecoin and cross-border payments, with rule logic, actions, and the data each needs.",{"path":629,"title":630,"description":631},"\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb","Virtual account requirements: KYC, KYB, and what the bank reviews before it says yes","What you need to open a virtual account: KYC or KYB, the extra fields and source of funds documents the bank reviews, who owns each step, and timelines.",{"path":633,"title":634,"description":635},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","What are compliance agents in fintech? How they work and what they do for payments","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",{"path":637,"title":638,"description":639},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","What is KYB? Know Your Business verification explained","KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",{"path":641,"title":642,"description":643},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","What is a VASP? Virtual asset service provider explained","A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",{"path":645,"title":646,"description":647},"\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","What is automated risk monitoring in fintech?","A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.",{"path":402,"title":649,"description":650},"What is the travel rule for stablecoin off-ramps? Thresholds, data, and failed checks","The travel rule makes off-ramps pass sender and receiver data with transfers. Thresholds by country, required data, and what happens when checks fail.",{"path":652,"title":653,"description":654},"\u002Fresources\u002Fmore\u002Fgenius-act-usdt-foreign-stablecoin-issuers","What the GENIUS Act means for USDT and other foreign-issued stablecoins","Can USDT stay available in the US under the GENIUS Act? The foreign issuer path, the 2027 and 2028 deadlines, and what payment companies should ask now.",{"path":656,"title":657,"description":658},"\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what","Who owns compliance when you integrate a crypto on-ramp API? KYC, KYB, KYT, and holds","An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.",{"path":660,"title":661,"description":662},"\u002Fresources\u002Fmore\u002Fsource-of-funds-crypto-off-ramps","Why do crypto off-ramps ask for source of funds? Documents, triggers, and on-chain proof","Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.",1791398900006]