An SEC commissioner said something almost no regulator dares to say out loud: KYC, as it works today, is creating a security problem, not solving one.
Hester Peirce gave a speech on September 23rd, in her second-to-last week as commissioner, and didn't hold back.
Her comparison was simple but sharp: collecting names, addresses, birth dates, and financial data on millions of honest people is like building an ever-growing haystack. Not only does that make it harder to find the actual "needles," the real criminals, it also puts every innocent person whose data ends up in that pile at risk.
Her exact words: "every additional piece of information the government collects and stores increases the risk that someone, inside or outside government, ends up misusing it."
What's interesting is she's not calling for identity verification to disappear. She's calling for separating two things that currently get bundled together: the raw data itself, and the specific fact that actually needs verifying.
Her proposal: use cryptographic proofs, zero-knowledge proofs, to confirm specific things without handing over everything behind them. Prove you're over 18. Prove you're a citizen of a certain country. Prove you're not on a sanctions list. All without disclosing your birth date, your address, or your income.
She also floated something pretty logical: let companies rely on verification another regulated entity already did, instead of making you hand over the same documents over and over. Fewer copies of the same data floating around means fewer places for that data to leak from.
Here's the part that hits close to home for anyone holding Bitcoin.
This data is already leaking, and it's not theoretical. Chainalysis found that in 2025, violent "wrench attacks" led to roughly $58 million stolen from crypto holders, the highest figure ever recorded. So far in 2026, there are already 46 documented cases and over $30 million stolen.
France is the starkest example right now: 30 physical attacks just through mid-year. Why? An employee at the French tax agency stole and sold information on wealthy crypto investors, names, addresses, holdings, all of it. On top of that, a separate leak hit 50,000 users of the French crypto tax service Waltio.
This isn't just a France problem either. Similar incidents already hit Pocket Bitcoin and 21bitcoin in the German-speaking world.
And while Peirce is pushing the US to collect less data, Europe is moving in exactly the opposite direction. The DAC8 directive requires exchanges to collect detailed user information and share it across borders.
Bull Bitcoin already sued France over this. Its CEO, Francis Pouliot, put it bluntly: DAC8 turns "Know Your Customer" into "Kill Your Customer."
And now Bull Bitcoin is also going after CARF, the similar framework the OECD is pushing globally.
Bottom line: one SEC commissioner is saying "we're collecting too much data, and it's putting people in danger," while Europe keeps building massive databases that someone, sooner or later, is going to hack, leak, or sell.