Bridging Regulation and Decentralization: Tech Stacks for Compliant Adoption | Ryan | ETHTaipei 2026
ETHTaipei·Sat, Oct 3, 2026, 12:00 AM
Bridging Regulation and Decentralization: Tech Stacks for Compliant Adoption | Ryan, Independent | ETHTaipei 2026
Transcript
[music] Hi everyone. Um so today I'm going to talk about like how to really um bridging regulation into the um the the world that is familiar with us the decentralization world and what kind of um product or what kind of tech stack we need to integrate into our existing decentralized product to make it regularized. So I think at this point we all agree that the next major wave of customers and the fund the money um the user will be coming from the enterprise world which is a normal world that we feel discussed about which is the trafi world but now we are welcoming everyone to on board to this um onchain decentralized world that we are familiar with um and now with all the regulators in each different continent like in the EU the Mika and Dora regular and also the the reason um travel rule regulation is also applying and also the basil framework a lot of basically I'm trying to say is a lot of each continent each country they are applying new rules and new um policy uh into the financial product that um we hope that we can make everything safer and protect the end user I think capacity angle that we're all um trying to align here and also make sure that uh the interest is also aligned between the new player which is the decentralized product player and all the treadfi institution player in this space. So I think there are two different things that in the in different fields that we care about from the institution side they need to know uh what kind of user is using the product and how can they use it um what kind of rules they need to follow and after that um after they use the product uh how do we keep back keep track of all the trades uh with all the auditing uh with all the accounting and make sure that everything is being documented and on the Ethereum side we care about permissionless assets and censorship resistant cred uh credible neutral neutrality and um global and always onchain settlement. So we hope that um everything can still always going back on onchain but the end user can be abstracted of interacting uh with the stuff onchain and still can be protected by the government and everything is safe um in their manner.
um no matter it's really self-custodial or not. Maybe there's some trade-off here. So I think the the whole thing about regulation is trying to find a middle ground to integrate um the user into a safe onchain interaction means so I think it's not a fight between the cryptonatives and the institution player. So I think crypton natives people can still interact with the all the onchain protocols that we're familiar with. There's no um unaligned interest here.
And for the chat via institution they can on board their existing user with simpler UX maybe sacrifice on self-custodial but with simpler UX um everything can be abstracted and can interact by the um user that um we are very hard to educate with our parents or grandparents. they can easily just using uh the existing banking um applications to interact with all the onchain apps. So there are a couple different layers of um the compliance stack when we're talking about this. Um so when user is interacting with the actual DAB, I think this is one layer. um like unis swap and all the other players are doing this.
They're using geo fencing and gated pools to make sure that the user that is interacting with their protocols are um what we'll say is not terrorist or they are um eligible to use their app safely. So that's the first like um end interface for the user and then there's the travel rule rails. The travel rules is trying to manage how the fund goes between different um virtual asset providers um to make sure that all the fund is being traced um safely and the travel rules rails came recently because the previous method is called the AML screening which is the anti-money laundering screening. Um the way that they do this is using a lot of um like monitoring to track the transactions to make sure that um to identify and categorize which players are belongs to each account and how are they using the onchain apps and interact with different protocols to try to label the user and find out who they actually are without really knowing who they are. And the travel rule is kind of the bottom up method.
is like um understanding who's a user exactly and track where their money are going to. So these are kind of two like alternatives for each other. And then there's the policy engines. Policy engines is more like protecting the user and to manage how what are the permissions that the user are allowed to use to interact with um different protocols or onchains or what kind of no matter what kind of apps will be um will be restricted through policy engines. And then there's the um the the infrastructure that's underneath the money which is the keys and the custody um management tools like all the custodial wallets that we're talking about or even like safe like multisake wallets are also talking about this is how the money is being managed safely and then after that is to trying to understand who the how the actual user is which is the identity and attestations um using KYC tools and like um the the things that we're familiar with like uploading all our documents um running our information previous like nakedly on on on all the centralized server.
So these are the different layers of compliance stack when we're trying to build a regulated um product. So the first layer the identity and attestation uh registries um it's pretty much KYC. I'll say pretty much everyone would know um have used KYC before and are familiar with this. Um I think there's different players in this field. Um I'll say KYC is one and the other will be onchain attestation.
That's kind of a different method um in this field like um this is also what like base app though they kind of like sunset it down but this is what base app is trying to test to through onchain attestation issuing onchain identity to have a profile for a user onchain and to issue um the the the authenticators and to issue like the identity on chain to allow to track the user uh interact with which or what um application or decentralized application onchain. So that's another method, but that method is kind of dead I would say because it's still really hard to be regulated and to track who the actual user is through documents. Um so but but that's more decentralization and that's the kind of the experiments that been testing uh in the previous couple years. And then the ZK credential is the reason method that's coming up um this two or three years and it's also what my previous company is is trying to build. I can talk about more of this um about ZKYC stuff um at the end of the talk but um these are the I'll say the three different kind of method that people are trying to tackle KYC.
So the simple centralized pure storagebased KYC which is what sums up and persona is trying to do and the onchain attestation is through EAS the Ethereum attestation service and coinbased verification and human passport. They're kind of the three different players in the space. So, human passport will be the onchain profile and coinbased verification will be the verify verifier on their uh base app or base chain and EAS is the um sorry and the ES will be Oh, okay. Uh thank you. Um the ES will be the attestation infrastructure to issue all the uh reusable identity onchain.
And um the reason why people are trying to build ZK credential is related to how PII which is the personal information identity is being managed. Um I'll talk about why I think privacy is really uh important in KYC later. And then there's the second layer which is the keys and custody. I'll say this is a rather mature space and the product and the solution is quite mature as well in the space. So multisig um the safe um built by Nosis I would say is the most familiar by everyone.
Um they host everything onchain and manage everything onchain. Everything is aggregated through um account uh signature and sign everything through onchain um smart contract verification and then there's MPC which is a single account onchain but everything is aggregated offchain um so it's chain agnostic so it's it will be more easily to be transferred through different ecosystem um but it's more centralized and it's more permissioned and Um these are the two different kind of solution. Uh when we talk about keys management and then um about MPC there are two different kind of ways to manage the key. One is TE and one is S HSM. Um it's it's more like cryptography related um terms.
So you don't necessarily need to understand them. Um but um to talk about this I I want to point out is that um Fireblocks and Bitco are the most uh two biggest player in the MPC custody wallets um theme and Fireblocks is using TE and bigo is using HSM which have different trade-offs um if you're interested uh we can dive into this later um and safe is using multisig right now. So these are the different players um that's doing keys and custody management. And then there's the automated policy engines um which is how user are allowed to interact with different applications. These are pretty much tied to the wallet connect uh the the wallet provider because it's pretty much the same thing um to manage your fund and to move your fund in and out of your in and out of your um in and out of your wallet.
So it's pretty much the same thing. I I my time is pretty high. So um I'm going to try to jump faster. But uh these are different kinds of um wallets that's doing um uh to to manage fund for the user. And then there's ML.
ML also rather trivial. It's just management transaction. So I'll also jump this. And then travel rules I will say is pretty interesting because travel rules are pretty recent um regulation and these are the couple big players in the team. Um and I'll say um the TRP which is from the um 21 analytics is I'll say pretty interesting because they are pretty creating open standard for travel rules management.
So it can abstract um the travel rules alliance in the future and then finally is the compliant D5 front end uh which um these are the couple like regulated uh players in the field. I want to point out Limino is quite interesting because they are the ninth um regulated um virtual asset service provider in Taiwan. So they are the newest and the latest um custodial wallet legal player in Taiwan. I'll say that's pretty much interesting to watch uh to to keep an eye on. And Bigo and Fireblocks is also trying to come to Taiwan but but they are not licensed yet.
And I'll talk about this like real quick because I think this is really interesting. So these are the regulation tag um field that people are trying to build. And so depending on what kind of service you want to provide to your end user, you'll need to uh put the different pieces of the puzzle together to build a um system that's well defined for your user. And so just to quickly sum up, these are the uh a fully compliant uh transaction. what a fully compliant transaction will look like.
We'll go through all the previous part that we talked about and yeah so um just to quickly summarize I think there are two things that I I think is really interesting for a takeaway. One is that um Taiwan is not uh licensed yet for the custodial wallets besides Liino. So like big go and far the box are not uh regulated yet. Um so what they're trying to do now I I think people will be curious about then how do they uh actually work with Taiwan company. So the solution they're going to write going for right now is that they have license in USA and in Singapore and UAE.
So if your banks have um a uh a client uh company or a sub company in these country they can work together in these are the com country first and to integrate the system together and then in the future they can apply to Taiwan uh once the regulation of custodial wallets is being managed. That's one thing. And the last thing I want to talk about is why KYC is important is because a lot of the information and PII leak is through KYC uh process like Discord and Coinbase and I think privacy is important because it can be protected through encrypted um cryptography way to better manage uh user information. Uh if you guys are interested in privacy and interesting in custodial wallets, feel free to reach out to me. I can talk more and deep dive this into more um topic in the future.
Thank you.
Thank you, Ryan. [music]
Automatic transcript — names and jargon may be misspelled.