Published by Capital Insight Ltd · Nicosia Herausgegeben von Capital Insight Ltd · Nikosia
The Banking Dossier
Compliance

A travel rule needs two supervised ends. The 83 per cent is 91 jurisdictions out of the 109 that were asked.

Eine Travel Rule braucht zwei beaufsichtigte Enden. Die 83 Prozent sind 91 von 109 befragten Ländern.

The Financial Action Task Force published its seventh targeted update on virtual assets on 16 July 2026, and the headline number is that 83 per cent of jurisdictions have now passed travel-rule legislation, up from 73 per cent a year earlier. The body of the report gives the fraction: 91 of 109. The survey went to the FATF’s global network of 205 jurisdictions; 147 answered; and because the questionnaire used skip logic, jurisdictions that had not yet decided whether to prohibit or regulate crypto firms were never shown the travel-rule questions at all. So 91 of 205 jurisdictions have the law — 44 per cent, our own arithmetic on the FATF’s own figures — and the report itself says it “infers that jurisdictions (58 out of 205) that did not respond to the survey have not made progress on R.15, including Travel Rule implementation”. A rule that only works when both ends of a transfer have it is being scored on the end that answered the questionnaire.

What the rule assumes before it says anything

The travel rule began as a banking measure. FATF Recommendation 16 requires that identifying information about the originator and the beneficiary travel with a payment. In 2019 the FATF extended it to virtual assets and to the firms that handle them, and the 2026 update restates the obligation: providers must “obtain, hold, and transmit specific originator and beneficiary information immediately and securely when engaging in payments or value transfers, including VAs and hybrid payment chains”.

Read that sentence for what it takes for granted. There is a firm at the sending end that is licensed, supervised and reachable. There is a firm at the receiving end with the same properties. There is a channel between them. And there is a supervisor with authority over at least one of them who will notice if the message does not arrive. In a correspondent banking chain all four hold, most of the time, because the payment instruction and the identifying data are the same object: the message is the payment, and a bank that will not send the data does not send the money.

In a crypto transfer none of the four is automatic. The value moves on a public ledger that settles without reference to any compliance message. The identifying data moves, if it moves at all, over a separate arrangement the two firms have to find. Either end may be a wallet with no firm behind it. And the supervisor at one end has no jurisdiction over the other. The rule was not redesigned for any of this; it was extended to it.

The denominator moved more than the numerator

The FATF’s own figures repay a second look. In 2025 the answer was 85 of 117 jurisdictions, which is 73 per cent. In 2026 it is 91 of 109, which is 83 per cent. Six more jurisdictions passed legislation; the base of respondents fell by eight.

Our own arithmetic, flagged as such: express the 2026 numerator on the 2025 base and 91 of 117 is 77.8 per cent. Of the roughly eleven-point headline improvement, about five points are new law and about six are the smaller denominator. Slightly more than half of the progress reported this year is the set of jurisdictions being asked, not the set of jurisdictions complying.

This is not a hidden number. The FATF prints the fractions, prints the response rate, prints the skip logic, and prints the inference that non-responders have made no progress. It also states plainly that “responses were self-reported and have not been independently verified”. Everything needed to do the division is on the page. It is simply that the percentage is what gets quoted, and the percentage has a denominator that the measured parties select themselves by choosing whether to answer.

The law exists. The supervision mostly does not.

Passing legislation is the first of at least three steps, and the FATF measures the second. Of the 91 jurisdictions with travel-rule law, 55 — 60 per cent — “have not yet issued findings or directives or taken enforcement or other supervisory actions against VASPs focused on Travel Rule compliance”.

Something worth noting sits between the two halves of the same document. The executive summary describes this as “almost half of jurisdictions that have introduced Travel Rule legislation not yet having taken Travel Rule-related supervisory or enforcement action”. Section 2.5 gives it as “slightly more than half of the 91 jurisdictions (60%; 55 of 91)”. Both sentences describe the same 55 firms-worth of nothing. One rounds towards the encouraging side of a half, the other towards the discouraging side, and the summary is the part that travels. We would not read intent into it. We would note that the summary of a report is a different document from the report, and that this is why the fraction matters more than the adjective.

The FATF offers a fair explanation: many jurisdictions have only recently enacted the legislation and are building supervisory frameworks in a new area; others may have engagement or ongoing cases that produce no published action. That is plausible and probably right for a large share of the 55. It does not change what the number means for a firm on the other side of a transfer, which is that in most places with the rule, nobody has yet checked whether anyone follows it. The pattern is familiar from an entirely different corner of European payments law, where the rule binds one party while the supervisory duty points at another, and the result is a prohibition that almost nobody enforces.

The message has no post office

In the European Union the rule is Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, which brought crypto-asset service providers inside the same obligation as banks. The European Banking Authority issued the implementing guidelines on 4 July 2024, applying from 30 December 2024, and they repeal the 2017 joint guidelines that had covered funds transfers alone.

The guidelines are worth reading for what they concede. They set out, in the EBA’s words, “the steps CASPs and ICASPs should take if the full information cannot be transmitted due to technical limitations”, and they require firms to have “alternative mechanisms for collecting, holding and making available to the receiving CASP or ICASP in the transfer chain the information that cannot be transmitted due to technical limitations”. Where a bank wire has one message format and one network, the guidelines describe the crypto transport as a choice among arrangements “between CASPs, application programming interfaces (APIs), code solution running on top of the blockchain and other third-party solutions”. The regulation says what must travel. It does not say how, and there is no equivalent of the banking network that would make the question moot.

The EBA also allowed a transitional period to 31 July 2025 for providers “while systems are being adjusted”. A transitional period is an honest instrument and it is the right one when an obligation lands ahead of the plumbing. It is also an admission about the plumbing.

When the far end is not a firm

The hardest case is the one the banking rule never had to consider: a transfer to or from an address that no licensed entity controls. The EBA guidelines address it directly. A provider must obtain and hold the information on the self-hosted address, must ensure the transfer can be individually identified, and must “assess whether that address is owned or controlled by the CASP customer where the transfer amount exceeds EUR 1 000”.

Look at what the third obligation asks. It does not ask who the beneficiary is. It asks whether the address belongs to the provider’s own customer. That is a different question, and it is the only one that can be answered, because there is nobody else to ask. The guidelines make this explicit: “Requests for missing information or clarification with respect to transfers from or to self-hosted addresses should be sent directly to the CASP’s customer.” The rule’s information-gathering mechanism, faced with an unidentifiable counterparty, folds back onto the one party already identified.

That is not a drafting failure; it is the only available design. But it means the travel rule delivers two different things depending on the far end. Between two supervised firms it produces an independent statement about the counterparty. Between a firm and a self-hosted wallet it produces a statement by the customer about themselves, corroborated by whatever ownership proof the provider can construct. Both are recorded as travel-rule compliance.

The only sanction is exclusion

What happens when the other firm simply does not send the data? A supervisor cannot fine a provider in a jurisdiction where it has no authority, which in the FATF’s counting is most jurisdictions. The guidelines therefore reach for the tool that is available. Where a counterparty fails, the receiving provider should decide whether to reject, return, suspend or execute the transfer, and in addition should “consider the future treatment of the prior CASP or ICASP in the transfer chain for AML/CFT compliance purposes, including rejecting any future transfers from or to the prior CASP or ICASP or self-hosted address in the transfer chain, or restricting or terminating its business relationship with it”.

That is de-risking written into guidance, and it is a rational response to an enforcement gap. It is also a mechanism whose costs land somewhere specific. A provider in a jurisdiction that has not yet legislated does not get fined; it gets cut off, and so do its customers, including the ones who did nothing. The border of the compliant system becomes the operative sanction, which is a different and heavier thing than a penalty — much as the real cost of a payments licence turns out to be time and standing rather than capital.

There is a second consequence. Decisions of this kind are made on evidence of a counterparty’s failures, and the standard for that evidence is set by the firm making the decision. The guidelines list among risk-increasing factors any provider “identified as repeatedly failing to provide required information without a justified reason”, and also one that “has previously been known to fail to provide required information on a number of occasions without good reason, even if it did not repeatedly fail to do so”. Two thresholds, one exclusion list, and no appeal named in the text — a shape we have seen before in fraud data sharing, where two different standards of proof led to the same shared file.

What the money did while the rule was being passed

The same FATF report describes what the gaps were used for, and the cases are not small. It reports a Cambodia-based financial services conglomerate that “laundered at least USD 4 billion in illicit proceeds between 2021 and 2025”, serving both organised-crime fraud schemes and state-linked cyber theft through the same infrastructure. It reports that in June 2025 the Spanish Guardia Civil dismantled a crypto investment fraud network that allegedly laundered around EUR 460 million from more than 5,000 victims.

It also reports a shift in instrument: most identified on-chain illicit activity now involves stablecoins, and the FATF flags “an emerging risk of a financial services conglomerate with links to criminal networks developing a proprietary stablecoin designed to resist freezing and asset seizure”. That is worth holding next to the travel rule debate, because it points at a different control. The travel rule produces information. Freezing produces an outcome. An issuer that engineers away the freeze is not attacking the message; it is attacking the only step that ever recovers anything.

The case for the rule as it was built

The strongest argument for the current design is coverage weighted by where the activity is, and the FATF makes it. Its annex lists the jurisdictions with materially important virtual-asset activity, and those jurisdictions constitute “approximately 97% of the global VA market”. A count of jurisdictions is close to the worst way to measure a rule whose subject is concentrated in a few dozen places. Ninety-one of 205 sounds thin; the same 91 measured by market share would sound very different, and the FATF is explicit that this group is where implementation matters.

The trajectory supports it too. The report’s own series runs 35 jurisdictions with travel-rule legislation in 2023, 65 in 2024, 85 in 2025, 91 in 2026. Expressed as shares of respondents that is 39 per cent in 2023 against 83 per cent now, and a rule that moves that far in three years is not a dead letter, whatever the denominator does.

And the alternative designs are worse in specific ways. A de-minimis threshold would be trivially defeated by splitting transfers, which is why the European rules push the threshold onto the self-hosted ownership check rather than onto the transmission duty. A prescribed single message channel would have required a standard-setter to pick a winner among competing protocols in a market that did not yet exist. Delaying the obligation until the plumbing was ready would have meant no obligation at all during the years the FATF is now documenting. The travel rule is also the mechanism that makes chain analysis attributable: a blockchain shows addresses, and the rule is what occasionally attaches a name to one. Without it the ledger is transparent and anonymous at the same time.

What this does not tell you

It does not show that the rule fails to work. We have no measure of how many transfers carry complete information, how many messages arrive, or how many investigations turned on data the rule produced. The FATF counts laws and supervisory actions because those are countable; the operational compliance rate is not published by anyone we found.

It does not establish that the 58 non-responding jurisdictions lack the rule. The FATF assumes they have made no progress, and says it is an inference. Some may have legislated and not answered a survey. The direction of the assumption is conservative, which is defensible, but it is an assumption in both the FATF’s presentation and in ours.

And it says nothing about causation between the gaps and the cases. The USD 4 billion and the EUR 460 million are real and sourced, but no document we read attributes them to the absence of a travel rule in a particular jurisdiction. Serious laundering operations exist in places with the rule as well. Showing that a control is unevenly implemented is not the same as showing that even implementation would have stopped a given crime.

The rule that has to be two rules

The general point is not about crypto. It is that some obligations are single-party and some are pairwise, and the two cannot be monitored the same way.

A capital requirement, a licensing condition, a disclosure duty — those bind one firm, and counting the firms that comply tells you most of what you need. A travel rule is different in kind. It is an obligation on a relationship. Its value to the sending firm depends entirely on the receiving firm, and a jurisdiction that implements it perfectly gains only as much as its counterparties allow. For that class of rule the meaningful measure is not the share of jurisdictions with the law but the share of transfers with both ends inside it, weighted by value — and nobody publishes that, because doing so would require the flow data that the very opacity being regulated withholds.

So the scoreboard defaults to the countable thing. Held firmly: 91 of 205 jurisdictions in the FATF’s network have travel-rule legislation, and in 55 of those 91 no supervisory or enforcement action has yet been taken. With reasonable confidence: the market-weighted picture is substantially better than the jurisdiction count, because activity concentrates where the rules are. Cautiously: the gap between those two statements is exactly the space in which an offshore provider chooses where to be registered, and it will not close through better measurement — only through supervision in places that have so far written the law and stopped there.

Am 16. Juli 2026 hat die Financial Action Task Force ihren siebten Lagebericht zu Kryptowerten veröffentlicht, und die Schlagzeile lautet: 83 Prozent der Staaten haben inzwischen ein Gesetz zur Travel Rule — der Pflicht, Angaben zu Auftraggeber und Begünstigtem mit dem Transfer mitzuschicken. Ein Jahr zuvor waren es 73 Prozent. Im Fließtext steht der Bruch: 91 von 109. Befragt wurde das globale Netzwerk der FATF mit 205 Staaten; 147 antworteten; und weil der Fragebogen mit Filterführung arbeitete, bekamen Staaten, die noch nicht entschieden hatten, ob sie Kryptodienstleister verbieten oder regulieren, die Fragen zur Travel Rule gar nicht erst zu sehen. Damit haben 91 von 205 Staaten das Gesetz — 44 Prozent, eigene Rechnung auf den Zahlen der FATF —, und der Bericht selbst schreibt, er unterstelle, dass die 58 Staaten ohne Antwort keine Fortschritte gemacht hätten. Eine Regel, die nur wirkt, wenn beide Enden eines Transfers sie haben, wird an dem Ende gemessen, das den Fragebogen ausgefüllt hat.

Was die Regel voraussetzt, bevor sie etwas sagt

Die Travel Rule begann als Bankenvorschrift. Die FATF-Empfehlung 16 verlangt, dass Angaben zu Auftraggeber und Begünstigtem mit der Zahlung mitreisen. 2019 hat die FATF sie auf Kryptowerte und die Unternehmen ausgedehnt, die damit handeln; der Bericht von 2026 formuliert die Pflicht so: Anbieter müssen bestimmte Angaben zu Auftraggeber und Begünstigtem „unverzüglich und sicher” erheben, vorhalten und übermitteln.

Man lese den Satz auf das hin, was er stillschweigend annimmt. Am Sendeende steht ein Unternehmen, das zugelassen, beaufsichtigt und erreichbar ist. Am Empfangsende steht eines mit denselben Eigenschaften. Zwischen beiden gibt es einen Kanal. Und es gibt eine Aufsicht über mindestens eines von beiden, der auffällt, wenn die Nachricht ausbleibt. In einer Korrespondenzbankkette trifft das meistens zu, weil Zahlungsauftrag und Angaben dasselbe Objekt sind: Die Nachricht ist die Zahlung, und eine Bank, die die Daten nicht schickt, schickt auch das Geld nicht.

Bei einem Kryptotransfer gilt keine dieser vier Annahmen von selbst. Der Wert bewegt sich über ein öffentliches Register, das ohne Rücksicht auf irgendeine Compliance-Nachricht endgültig wird. Die Angaben bewegen sich — wenn überhaupt — über eine getrennte Absprache, die beide Unternehmen erst finden müssen. Jedes der beiden Enden kann eine Adresse sein, hinter der kein Unternehmen steht. Und die Aufsicht am einen Ende hat über das andere keine Befugnis. Die Regel wurde dafür nicht neu entworfen, sondern darauf ausgedehnt.

Der Nenner hat sich stärker bewegt als der Zähler

Die Zahlen der FATF lohnen einen zweiten Blick. 2025 lautete die Antwort 85 von 117 Staaten, also 73 Prozent. 2026 sind es 91 von 109, also 83 Prozent. Sechs Staaten mehr haben ein Gesetz erlassen; die Zahl der Befragten ist um acht gesunken.

Eigene Rechnung, als solche gekennzeichnet: Rechnet man den Zähler von 2026 auf die Basis von 2025, ergibt 91 von 117 genau 77,8 Prozent. Von den rund elf Punkten Verbesserung entfallen etwa fünf auf neue Gesetze und etwa sechs auf den kleineren Nenner. Etwas mehr als die Hälfte des gemeldeten Fortschritts liegt in der Menge der Befragten, nicht in der Menge derer, die die Regel umsetzen.

Versteckt ist daran nichts. Die FATF druckt die Brüche, die Rücklaufquote, die Filterführung und die Unterstellung über die Nichtantworter. Sie schreibt außerdem ausdrücklich, die Antworten seien Selbstauskünfte und „nicht unabhängig überprüft”. Alles, was man zum Nachrechnen braucht, steht da. Nur wird eben der Prozentsatz zitiert — und dessen Nenner bestimmen die Gemessenen selbst, indem sie entscheiden, ob sie antworten.

Das Gesetz gibt es. Die Aufsicht meistens nicht.

Ein Gesetz zu erlassen ist der erste von mindestens drei Schritten, und die FATF misst den zweiten. Von den 91 Staaten mit Travel-Rule-Gesetz haben 55 — 60 Prozent — bislang keine Feststellungen, Anordnungen, Sanktionen oder sonstigen Aufsichtsmaßnahmen gegenüber Kryptodienstleistern getroffen, die sich auf die Travel Rule beziehen.

Zwischen den beiden Hälften desselben Dokuments steht etwas Bemerkenswertes. Die Zusammenfassung beschreibt das als „fast die Hälfte” der Staaten mit Travel-Rule-Gesetz. Abschnitt 2.5 formuliert dieselbe Tatsache als „etwas mehr als die Hälfte der 91 Staaten (60 %; 55 von 91)”. Beide Sätze meinen dieselben 55. Der eine rundet auf die ermutigende Seite einer Hälfte, der andere auf die entmutigende — und die Zusammenfassung ist der Teil, der weiterwandert. Eine Absicht lesen wir darin nicht. Wir halten fest, dass die Zusammenfassung eines Berichts ein anderes Dokument ist als der Bericht, und dass deshalb der Bruch mehr zählt als das Adjektiv.

Die FATF liefert eine faire Erklärung: Viele Staaten haben die Gesetze erst kürzlich erlassen und bauen gerade erst Aufsichtsstrukturen in einem neuen Feld auf; andere führen laufende Verfahren, die zu keiner veröffentlichten Maßnahme führen. Das ist plausibel und für einen großen Teil der 55 vermutlich zutreffend. An dem, was die Zahl für ein Unternehmen am anderen Ende eines Transfers bedeutet, ändert es nichts: In den meisten Staaten mit der Regel hat bisher niemand nachgesehen, ob sich jemand daran hält. Das Muster kennt man aus einer ganz anderen Ecke des europäischen Zahlungsrechts, wo die Verbotsnorm die eine Partei bindet und die Aufsichtsnorm auf eine andere zeigt — mit dem Ergebnis eines Verbots, das kaum jemand durchsetzt.

Die Nachricht hat kein Postamt

In der Europäischen Union heißt die Regel Verordnung (EU) 2023/1113, die neu gefasste Geldtransferverordnung, die Anbieter von Kryptowerte-Dienstleistungen derselben Pflicht unterwirft wie Banken. Die Europäische Bankenaufsichtsbehörde hat die Leitlinien dazu am 4. Juli 2024 erlassen; sie gelten seit dem 30. Dezember 2024 und heben die Gemeinsamen Leitlinien von 2017 auf, die nur Geldtransfers erfassten.

Interessant ist, was die Leitlinien einräumen. Sie beschreiben, welche Schritte Anbieter unternehmen sollen, „wenn die vollständigen Angaben aus technischen Gründen nicht übermittelt werden können”, und verlangen „alternative Mechanismen”, um die nicht übermittelbaren Angaben dem empfangenden Anbieter in der Kette dennoch verfügbar zu machen. Wo eine Banküberweisung ein Nachrichtenformat und ein Netz hat, beschreiben die Leitlinien den Transportweg im Kryptobereich als Auswahl zwischen Absprachen „zwischen Anbietern, Programmierschnittstellen (APIs), auf der Blockchain aufsetzenden Codelösungen und anderen Lösungen Dritter”. Die Verordnung sagt, was mitreisen muss. Wie, sagt sie nicht — und ein Gegenstück zum Bankennetz, das die Frage erübrigen würde, gibt es nicht.

Die Aufsichtsbehörde hat den Anbietern außerdem eine Übergangsfrist bis zum 31. Juli 2025 eingeräumt, „während die Systeme angepasst werden”. Eine Übergangsfrist ist ein ehrliches Instrument und das richtige, wenn eine Pflicht vor der Technik da ist. Sie ist zugleich ein Eingeständnis über die Technik.

Wenn am anderen Ende kein Unternehmen steht

Der schwierigste Fall ist der, den die Bankenregel nie kannte: ein Transfer von oder zu einer Adresse, die kein zugelassenes Unternehmen kontrolliert. Die Leitlinien behandeln ihn ausdrücklich. Ein Anbieter muss die Angaben zur selbst gehosteten Adresse erheben und vorhalten, muss sicherstellen, dass sich der Transfer einzeln identifizieren lässt, und muss „beurteilen, ob diese Adresse dem Kunden des Anbieters gehört oder von ihm kontrolliert wird, sofern der Transferbetrag 1 000 EUR übersteigt”.

Man sehe sich die dritte Pflicht an. Sie fragt nicht, wer der Begünstigte ist. Sie fragt, ob die Adresse dem eigenen Kunden gehört. Das ist eine andere Frage, und es ist die einzige, die sich beantworten lässt, weil es niemand anderen zu fragen gibt. Die Leitlinien sagen das offen: Anfragen nach fehlenden Angaben oder Klarstellungen zu Transfers von oder zu selbst gehosteten Adressen sollen „unmittelbar an den Kunden des Anbieters” gerichtet werden. Der Erkenntnisapparat der Regel fällt, wenn die Gegenseite nicht identifizierbar ist, auf die eine Partei zurück, die ohnehin schon identifiziert war.

Das ist kein handwerklicher Fehler, sondern der einzig mögliche Entwurf. Aber es bedeutet, dass die Travel Rule je nach Gegenseite zwei verschiedene Dinge liefert. Zwischen zwei beaufsichtigten Unternehmen erzeugt sie eine unabhängige Aussage über die Gegenpartei. Zwischen einem Unternehmen und einer selbst verwalteten Adresse erzeugt sie eine Aussage des Kunden über sich selbst, gestützt auf den Eigentumsnachweis, den der Anbieter beibringen kann. Beides wird als Erfüllung der Travel Rule verbucht.

Die einzige Sanktion ist der Ausschluss

Was geschieht, wenn das andere Unternehmen die Daten schlicht nicht schickt? Eine Aufsicht kann keinen Anbieter in einem Staat sanktionieren, über den sie keine Befugnis hat — und das sind nach der Zählung der FATF die meisten Staaten. Die Leitlinien greifen deshalb zu dem Werkzeug, das zur Verfügung steht. Versagt eine Gegenpartei, soll der empfangende Anbieter über Zurückweisung, Rückgabe, Aussetzung oder Ausführung entscheiden und zusätzlich erwägen, wie er den vorangehenden Anbieter künftig behandelt — bis hin dazu, „künftige Transfers von oder zu dem vorangehenden Anbieter oder der selbst gehosteten Adresse in der Transferkette zurückzuweisen oder die Geschäftsbeziehung einzuschränken oder zu beenden”.

Das ist Risikovermeidung als Leitlinientext, und es ist eine vernünftige Antwort auf eine Durchsetzungslücke. Es ist zugleich ein Mechanismus, dessen Kosten an einer bestimmten Stelle anfallen. Ein Anbieter in einem Staat ohne Gesetz zahlt keine Geldbuße; er wird abgeklemmt, und seine Kunden mit ihm, auch die, die nichts getan haben. Die Grenze des regelkonformen Systems wird zur eigentlichen Sanktion — etwas anderes und Schwereres als eine Strafe, ähnlich wie der wahre Preis einer Zahlungslizenz sich als Zeit und Stellung statt als Kapital erweist.

Eine zweite Folge kommt hinzu. Solche Entscheidungen beruhen auf Belegen über das Versagen einer Gegenpartei, und den Maßstab dafür setzt das entscheidende Unternehmen selbst. Die Leitlinien führen als risikoerhöhenden Umstand jeden Anbieter auf, der „wiederholt ohne gerechtfertigten Grund” die erforderlichen Angaben nicht liefert — und ebenso einen, von dem bekannt ist, dass er das „bei einer Reihe von Gelegenheiten ohne guten Grund” getan hat, „auch wenn er es nicht wiederholt getan hat”. Zwei Schwellen, eine Ausschlussliste, und kein im Text benannter Rechtsbehelf — eine Form, die wir bei Betrugsdaten schon einmal gesehen haben, wo zwei verschiedene Beweismaßstäbe in dieselbe gemeinsame Datei führten.

Was das Geld tat, während die Gesetze entstanden

Derselbe FATF-Bericht beschreibt, wozu die Lücken genutzt wurden, und die Fälle sind nicht klein. Ein in Kambodscha ansässiger Finanzkonzern habe zwischen 2021 und 2025 „mindestens 4 Milliarden US-Dollar” an Erlösen gewaschen und dabei über dieselbe Infrastruktur sowohl Betrugsnetzwerke der organisierten Kriminalität als auch staatlich verbundenen Cyberdiebstahl bedient. Im Juni 2025 zerschlug die spanische Guardia Civil ein Netzwerk des Kryptoanlagebetrugs, das rund 460 Millionen Euro von mehr als 5 000 Geschädigten gewaschen haben soll.

Der Bericht beschreibt auch eine Verschiebung beim Instrument: Der größte Teil der erkannten illegalen Aktivität auf der Kette laufe inzwischen über wertstabile Kryptowerte, und die FATF warnt vor einem Finanzkonzern mit Verbindungen zu kriminellen Netzwerken, der einen eigenen wertstabilen Kryptowert entwickle, „der dem Einfrieren und der Beschlagnahme widerstehen soll”. Das gehört neben die Debatte über die Travel Rule, weil es auf eine andere Kontrolle zeigt. Die Travel Rule erzeugt Informationen. Das Einfrieren erzeugt ein Ergebnis. Wer die Einfrierbarkeit wegkonstruiert, greift nicht die Nachricht an, sondern den einzigen Schritt, der je etwas zurückholt.

Was für die Regel spricht, wie sie gebaut ist

Das stärkste Argument für den heutigen Entwurf ist die nach Aktivität gewichtete Abdeckung, und die FATF trägt es selbst vor. Ihr Anhang listet die Staaten mit erheblicher Kryptodienstleistungstätigkeit; auf sie entfallen „rund 97 % des weltweiten Marktes”. Eine Zählung von Staaten ist so ziemlich der schlechteste Maßstab für eine Regel, deren Gegenstand sich auf wenige Dutzend Orte konzentriert. 91 von 205 klingt dünn; dieselben 91 nach Marktanteil klängen ganz anders, und die FATF sagt ausdrücklich, dass es auf diese Gruppe ankommt.

Auch die Kurve spricht dafür. Die eigene Reihe des Berichts lautet 35 Staaten mit Travel-Rule-Gesetz 2023, 65 im Jahr 2024, 85 im Jahr 2025 und 91 im Jahr 2026. In Anteilen der Befragten sind das 39 Prozent im Jahr 2023 gegen heute 83 Prozent — eine Regel, die sich binnen drei Jahren so weit bewegt, ist kein toter Buchstabe, was auch immer der Nenner tut.

Und die Gegenentwürfe sind in bestimmter Hinsicht schlechter. Ein Bagatellbetrag ließe sich durch Stückelung mühelos umgehen — deshalb legt das europäische Recht die Schwelle auf die Eigentumsprüfung bei selbst gehosteten Adressen und nicht auf die Übermittlungspflicht. Ein vorgeschriebener einheitlicher Nachrichtenkanal hätte verlangt, dass eine Standardsetzerin in einem Markt, den es noch nicht gab, einen Sieger unter konkurrierenden Protokollen kürt. Und hätte man die Pflicht bis zur Reife der Technik aufgeschoben, hätte es in genau den Jahren, die die FATF jetzt dokumentiert, gar keine Pflicht gegeben. Die Travel Rule ist überdies das, was Kettenanalyse überhaupt zuordenbar macht: Eine Blockchain zeigt Adressen, und die Regel ist das, was gelegentlich einen Namen an eine davon heftet. Ohne sie ist das Register transparent und anonym zugleich.

Was daraus nicht folgt

Es folgt nicht, dass die Regel nicht wirkt. Wie viele Transfers vollständige Angaben tragen, wie viele Nachrichten ankommen und wie viele Ermittlungen an solchen Daten hingen, wissen wir nicht. Die FATF zählt Gesetze und Aufsichtsmaßnahmen, weil das zählbar ist; eine Quote der tatsächlichen Erfüllung veröffentlicht, soweit auffindbar, niemand.

Es folgt nicht, dass den 58 nicht antwortenden Staaten die Regel fehlt. Die FATF unterstellt, sie hätten keine Fortschritte gemacht, und nennt es eine Unterstellung. Manche mögen Gesetze haben und keinen Fragebogen. Die Richtung der Annahme ist vorsichtig, was vertretbar ist — eine Annahme bleibt es, bei der FATF wie bei uns.

Und über eine Ursache sagt es nichts. Die 4 Milliarden Dollar und die 460 Millionen Euro sind belegt, aber in keinem gelesenen Dokument werden sie dem Fehlen einer Travel Rule in einem bestimmten Staat zugeschrieben. Große Wäscheoperationen gibt es auch dort, wo die Regel gilt. Zu zeigen, dass eine Kontrolle ungleich umgesetzt wird, ist nicht dasselbe wie zu zeigen, dass gleichmäßige Umsetzung eine bestimmte Tat verhindert hätte.

Die Regel, die zwei Regeln sein muss

Der allgemeine Punkt handelt nicht von Kryptowerten. Er lautet: Manche Pflichten binden eine Partei, andere binden ein Paar — und beide lassen sich nicht auf dieselbe Weise überwachen.

Eine Eigenmittelanforderung, eine Zulassungsbedingung, eine Offenlegungspflicht binden ein Unternehmen, und die Unternehmen zu zählen, die sie erfüllen, sagt das meiste. Eine Travel Rule ist von anderer Art. Sie ist eine Pflicht an einer Beziehung. Ihr Wert für das sendende Unternehmen hängt vollständig vom empfangenden ab, und ein Staat, der sie tadellos umsetzt, gewinnt nur so viel, wie seine Gegenparteien zulassen. Für diese Klasse von Regeln wäre der aussagekräftige Maßstab nicht der Anteil der Staaten mit Gesetz, sondern der wertgewichtete Anteil der Transfers mit beiden Enden innerhalb der Regel — und den veröffentlicht niemand, weil er genau die Flussdaten verlangte, die die regulierte Undurchsichtigkeit vorenthält.

Also fällt die Anzeigetafel auf das Zählbare zurück. Fest vertreten: 91 von 205 Staaten im Netzwerk der FATF haben ein Travel-Rule-Gesetz, und in 55 dieser 91 ist bisher keine Aufsichts- oder Durchsetzungsmaßnahme ergriffen worden. Mit vernünftiger Sicherheit: Das marktgewichtete Bild ist deutlich besser als die Länderzählung, weil sich die Aktivität dort ballt, wo die Regeln gelten. Vorsichtig: Der Abstand zwischen diesen beiden Sätzen ist genau der Raum, in dem ein Anbieter entscheidet, wo er sich registrieren lässt — und er schließt sich nicht durch besseres Messen, sondern nur durch Aufsicht in jenen Staaten, die es bisher beim Gesetz belassen haben.