An earlier analysis of Malta’s first Travel Rule ruling discussed the Arbiter for Financial Services’ finding that a customer’s declaration of wallet ownership could not replace the verification required of a crypto-asset service provider. The same issue arises in VI v Foris DAX MT Limited (ASF 310/2025), decided on 15 June 2026. The decision applies that approach to another investment scam complaint, examining both the evidence of compliance and the connection between inadequate verification and the customer’s loss.
The complainant was persuaded to invest through a fraudulent platform. Between March and May 2025, he transferred €32,273 to his account with the service provider. The funds were converted into USDC and sent, on his instructions, to an external wallet controlled by the fraudsters. During the whitelisting process, he had declared that he owned the wallet address.
The service provider relied on that declaration and maintained that it had executed transfers authorised by the complainant. It also referred to its contractual terms and scam warnings. The central question for the Arbiter was whether these steps met the provider’s regulatory obligations and, if they did not, whether the failure had contributed to the loss.
The regulatory starting point remains Regulation (EU) 2023/1113, the Transfer of Funds Regulation Recast, applicable from 30 December 2024 (the “TFR”). Its Travel Rule requirements extend to crypto-asset transfers to improve traceability and combat money laundering and terrorist financing. Similar to the previous Arbiter Travel Rule ruling, the Arbiter examined whether a failure to meet those requirements had also prejudiced a financial consumer.
Article 14(5) of the TFR requires the originator’s crypto-asset service provider (“CASP”), for transfers exceeding €1,000 to a self-hosted address, to take adequate measures to assess whether that address is owned or controlled by the originator. A self-hosted address is, broadly, an address outside a CASP’s custody. The required assessment goes beyond collecting information about the parties to the transfer.
The EBA Travel Rule Guidelines (the “Guidelines”) explain that assessment. It provides for verification through methods including remote verification, a predefined small transfer commonly called a Satoshi test, a digital signature using the relevant wallet key, and other suitable technical means. A combination is required where one method does not provide a sufficiently reliable assessment.
The service provider’s reliance on paragraph 78 of the Guidelines raised the same distinction identified in the earlier analysis. It permits information to be obtained directly from the customer where technical means cannot establish whether an address is self-hosted. The Arbiter distinguished this information-gathering step from the further assessment of ownership or control. A customer’s declaration did not dispense with the verification required under Article 14(5) and the Guidelines.
In applying those requirements, the Arbiter emphasised the standard of being “fully satisfied” as to ownership or control. The provider had produced no evidence of using the specified verification methods, and a simple tick-box declaration was found insufficient. The absence of an internal fraud alert did not remove that obligation. Paragraph 86 allows an earlier documented assessment to support subsequent transfers involving the same whitelisted address, subject to controls for changes in risk or ownership or control; whitelisting itself does not replace the assessment.
The documentation provided also fell short. Despite a specific request, the service provider did not produce its internal Travel Rule policies and procedures, instead supplying a website FAQ, screenshots and a blank declaration form. The Arbiter found these insufficient to demonstrate the required procedures or that adequate verification had actually taken place.
That finding did not conclude the assessment of liability. The Arbiter separately considered causation, taking account of the provider’s duty of care and fiduciary obligations, alongside Article 66(1) of MiCA, which requires CASPs to act honestly, fairly and professionally in clients’ best interests. This examination of consumer loss was distinguished from the FIAU’s enforcement of AML/CFT obligations.
In the Arbiter’s view, proper verification would likely have revealed that the complainant did not own or control the wallet. In the circumstances of this case, that discovery would have prompted suspension of the transfers, further enquiries and their prohibition. A causal link was therefore established between the verification failure and the loss.
The complainant’s own conduct nevertheless substantially contributed to the loss. The Arbiter considered the lack of basic checks, inaccurate ownership declaration and continued transfers despite warnings. Applying the statutory mandate to decide complaints by reference to what is fair, equitable and reasonable, the Arbiter ordered the service provider to pay 40% of the losses with interest at 2.40% per annum from the decision date until payment.
The decision’s significance lies in the application of the same verification standard to another complaint. As in the case covered in the earlier article, the provider was ordered to bear 40% of the loss. That matching percentage does not establish a fixed allocation for future complaints: the award followed an assessment of the regulatory failure, its connection to the loss and the complainant’s contribution. Read together, the decisions illustrate how Travel Rule compliance can affect consumer claims as well as regulatory enforcement, while the outcome remains dependent on the evidence in each case.
For any other information or assistance, please contact us at info@gtg.com.mt
Author: Dr Neil Gauci