Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


When a crypto exchange asks for wallet ownership proof, it wants to establish that you own or control a self-hosted address involved in a transfer. Depending on the provider, asset, wallet, and applicable law, the method may be a plain-message signature, a small test transfer, an authenticated declaration, or another documented check. Proof of control never requires your seed phrase or private key.
Key Takeaways
- Verify the request inside the exchange's official app or typed domain and match it to a real transfer.
- Confirm the exact address, asset, network, challenge text, amount, destination, expiry, and fee before acting.
- A message signature should be readable and domain-bound; a transaction or token approval is a different risk.
- A small test is an on-chain transfer with real fees and irreversible consequences, not a harmless signature.
- Stop if anyone requests recovery words, a private key, remote access, or an opaque authorization.
Secure the surrounding account and support workflow with the online security guide.
It usually signals a compliance check. Covered providers may need to classify the counterparty, meet Travel Rule obligations, apply sanctions or risk controls, or investigate a transfer. The crypto Travel Rule explainer describes the regulated-party context. The EU regulation contains specific provisions for transfers to or from self-hosted addresses and, in a defined case, a EUR 1,000 ownership-or-control check.[1] That provision is EU-specific, not a universal global rule.
Proof of control answers a narrow question: can the requester demonstrate control of the cryptographic key or transaction path associated with this address? It does not necessarily prove legal ownership, source of funds, identity, or entitlement to every asset associated with the wallet.
| Method | What it can indicate | Main risk to check |
|---|---|---|
| Plain-message signature | Control of a key for a supported address | Unreadable or reusable challenge |
| Small test transfer | Ability to send from a specified address | Wrong network, destination, amount, fee, or irreversible loss |
| Authenticated declaration | Account holder attests to relationship | False statement or wrong address |
| Wallet connection | Address access in a browser flow | Malicious transaction or token approval |
| Document or screenshot | Context about wallet or transaction | Excess personal data; weak proof of key control |
Do not begin from an email, text message, direct message, or search advertisement. Open the known exchange app or type the official domain. Locate the same request in the account, confirm the transfer reference, and use the provider's published help page. Contact authenticated support if the two do not match.
Reject any request to move all funds to a “safe” or “verification” address, install screen-sharing software, reveal an MFA code, or send recovery material. A scammer can copy the language of a real compliance process while substituting a malicious destination.
Match the full address, asset, and network. Decide whether the address belongs to your self-hosted wallet, another person's self-hosted wallet, an exchange deposit account, a smart contract, or a service. Read self-custody versus an exchange account if the custody boundary is unclear.
Do not claim ownership merely because an address appears in your history. If the recipient controls it, say so. If it is an exchange deposit address, identify the exchange rather than attempting to sign with a key you do not possess. If the address has changed, ask whether the request can be regenerated for the correct address.
A bounded message should be readable and should identify the verifier, purpose, address or account context, a nonce, and an expiry. Confirm that the wallet is signing a message, not a blockchain transaction or token approval. Compare every character displayed by the wallet with the exchange prompt.
Never paste a seed phrase or private key into a website to produce a signature. Never download an unknown signing tool. Hardware wallets and reputable software wallets keep the secret key inside the wallet while returning only the signature. If the wallet or asset does not support the requested method, ask for an official alternative.
The wallet signature request guide explains how typed data, approvals, and transactions can grant permissions beyond a plain message. Stop if the meaning is opaque, the domain differs, the challenge is open-ended, or the interface shows spending authority.
A small-transfer method proves that someone can initiate an on-chain transaction from a specified address. Coinbase documents this as one provider-specific verification option for some assets and wallets.[3] It is not supported everywhere and should not be treated as a global requirement.
Verify the destination from the authenticated exchange workflow, the exact asset and network, the required amount or range, memo or tag, deadline, and network fee. Use a test amount you can afford to have delayed, but do not improvise a different amount if the process requires an exact one. Check whether the exchange expects the funds from the same address being verified; wallet software may select a different input address.
Do not repeat a test until the first transaction state is known. Save the transaction ID and confirmation. A test transfer is irreversible and exposes an on-chain relationship, so consider its privacy and fee cost before choosing it when a safe alternative exists.
An authenticated declaration may ask you to state whether you own or control an address. Read the statement and make only a truthful claim. Save the text and submission confirmation. Do not call a custodian's deposit address self-hosted and do not attest that you control another person's wallet.
A wallet-connect prompt is not automatically a harmless attestation. Inspect the site origin, chain, account, human-readable message, contract, function, spending amount, token allowance, and expiry. If the wallet shows a transaction, approval, permit, or blind-signing warning, stop. Ask the exchange to explain the required action in plain language or offer another supported method.
Provide only the requested signature, test transaction ID, or declaration through the official case. Screenshots can expose balances, other addresses, device details, and transaction history; crop or redact unrelated information when allowed. Do not send a full wallet backup or an exported private key.
Save the challenge, signature, address, method, transfer reference, timestamp, support case, and result. If the provider later asks for source-of-funds evidence, treat that as a separate purpose and use the source-of-funds document guide. Wallet control alone does not establish where assets came from.
If verification fails, check the address, network, message encoding, wallet support, selected account, and challenge expiry. Ask the provider for the precise supported method. Do not enable blind signing globally, import keys into an unknown wallet, or transfer everything to a different address merely to pass the check.
The EBA guidelines describe multiple potential methods for assessing ownership or control in the relevant EU context.[2] Kraken also publishes jurisdiction-specific procedures that may include attestations or a Satoshi test.[4] Both are evidence of possible implementations, not a guarantee that your exchange, wallet, asset, or country follows the same method.
It can surrender complete wallet control and must never be shared. Legitimate verification uses a signature, test, declaration, or another bounded method.
No. Verify the domain and readable challenge, and confirm that the wallet is not presenting a transaction, typed authorization, or token approval.
The wrong network, asset, address, amount, memo, source address, insufficient fee, or expired request can cause failure. Check the provider's exact instructions.
No. Control of an address and the lawful origin of assets are different questions and may require separate evidence.
You usually do not control its private key. Identify the receiving provider and account relationship instead of claiming self-hosted ownership.
Not merely to satisfy a verification prompt. If the meaning is not visible and bounded, stop and request another official method.
No. The cited amount belongs to a specific EU provision. Other jurisdictions and providers can apply different conditions.
No. A VPN cannot prove identity or key control, sign a challenge, change compliance rules, or alter exchange records.
Disclaimer: This article is for general informational purposes only and is not legal, financial, investment, tax, or platform-specific advice. Verification methods and requirements vary by provider, asset, wallet, and jurisdiction.
Sources checked 12 September 2026.
Related articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





