Travel Rule Requirements: Updates to Crypto Withdrawals Interface and API

Overview

The Travel Rule is an international anti-money-laundering (AML) standard that requires virtual-asset service providers (VASPs) to transmit key details about the originator (sender) and beneficiary (recipient) of certain blockchain transactions.

Although MiCA has officially been in force since 2023, its specific Travel Rule obligations become operative for crypto exchanges during 2024-2025. We are activating the feature on 19 May 2025, giving you a clear workflow to provide the required data, so your funds can clear with minimal delay and full MiCA compliance.

To comply with the international Travel Rule regulations, we introduce important and mandatory updates to the deposits and withdrawals process and API functionalities. Please note that this is only the first iteration of Travel Rule updates, and additional changes are expected in the near future.

Deposit confirmation

When you fund your account, we are legally required to collect basic information about the sender in accordance with the Travel Rule. If your deposit requires additional Travel Rule information, it cannot be credited to your account until you complete the verification.

You have to provide proof of deposit if your account is registered in the EU or Turkey and you receive:

  • A deposit from your own wallet;
  • An external deposit from another VASP (virtual asset service provider).

Please note: verification requirements may vary depending on the jurisdiction and applicable regulatory requirements.

To confirm your deposit, go to the “History-Deposits” section, find the required deposit and press the “Verify” button to open the confirmation form (this button appears automatically if the deposit needs additional data). The next steps depend on the source of the funds.

 

Deposit from another VASP (exchange, broker, custodial wallet)

 

To confirm a deposit from another VASP, you have to fill in the data as follows:

1. Select “Received from a VASP”.

2. Provide the sender’s wallet address (originator.walletAddress) and their residential address: country, city (originator.address, including country, city and addressLine1). The postcode (postCode) is optional.

3. Provide:

  • For an individual: first name and  last name.
  • For a company or other entity: full legal name and country of residence.

     

4. Provide the VASP information:


Please note: you must obtain the list for the relevant account, taking regional availability into account.

5. Press “Submit”.

6. Wait for WhiteBIT to review your application.

 

Please note: make sure the name and country match the information the sending exchange can confirm. Otherwise, you will receive a follow-up request.

 

Deposit from a self-hosted (non-custodial) wallet

This applies when the funds are sent from a wallet that you control, such as a hardware or software wallet.

1. Select “Received from a self-hosted wallet”.
2. The system launches an AOPP (Address Ownership Proof Protocol) check. AOPP is an open protocol that proves you control the sending address without revealing any sensitive data.
3. In your wallet, sign the message generated on the verification interface — no private keys are exposed.
4. Paste the signature into the form and click Confirm.
5. Your deposit will then be successfully confirmed.

Please note: the deposit will remain uncredited until you complete the Travel Rule steps. There are also two types of deposit status:

  • submitted: awaiting verification;
  • approved.

To check when a transaction was approved, you need to use the endpoint for checking deposit/withdrawal history: api/v4/account-wallet/get-deposit-withdraw-history.

Changes in Withdrawals Interface

For users from the EEA region, additional information will now be required when making a crypto withdrawal. The following fields must be completed:

  1. Wallet Type: Specify whether the destination wallet is a VASP-hosted wallet (hosted) or a self-custody wallet (unhosted).
  2. Receiver Type: Indicate whether the receiver is an Individual or a Legal Entity.

     
    • If Individual: Provide the receiver’s First Name, Last Name, Country of Residence and Address;
    • If Legal Entity: Provide the Full Name, Country of Residence and Address.

      3. VASP Information: If the destination wallet is hosted by a VASP, provide information about the VASP:
    • Select the VASP ID if the VASP is available in WhiteBIT’s list; or
    • Enter the VASP Name if the VASP is not available in the list.
    • For self-custody (unhosted) wallets, VASP information is not required.

These fields ensure the required information is captured during the withdrawal process, aligning with compliance standards.

Features of verification in Tron, Solana networks

In the Tron and Solana networks, verification of withdrawals/deposits is somewhat more complicated, as there is no automatic request for a signature, as in Ethereum. The process looks like this:

 

1. Enter the address. On the verification page, you need to insert the address of the wallet you plan to verify.

2. Sign the message manually.

Tron (via TronScan):

  • Go to TronScan
  • Click on Connect Wallet (mobile devices may have difficulties; in many cases, using TronLink helps).
  • Select: More → Sign & Verify
  • Next: V2 → Sign Message
  • Paste the message from the verification portal (AOPP) and click Sign Message
  • After that, we get a signature, but:

This signature is not in Base64, so you need to convert it on a third-party website.

 

Solana (via SolScan):

The process is similar, but other services are used, such as SolScan, Phantom Wallet, or Trust Wallet.

After converting the signature to Base64 format, you need to paste it into the appropriate field on the verification site and click Add Proof.

 

Please note: the platform is not responsible for failed verification attempts, as these processes depend on third-party services and wallets.

 

Not all networks have the ability to verify a Web3 wallet (for example, Polygon, Whitechain). In this case, you should specify the name of the wallet in the VASP field. If the wallet is non-custodial, there is no need to specify the wallet’s name.

 

For each network, you need to verify the wallet again. If you received a deposit in the Polygon network, verified your wallet, and then received a deposit in Ethereum, you will have to verify it again. 

 

To confirm the deposit, you will need to provide the following information:

 

  • Sender's first name
  • Surname of the sender
  • Name of the platform from which the funds were sent
  • Country of residence of the sender.

API Updates: Travel Rule Object

Verification in accordance with the Travel Rule is required if:

  • This is a cryptocurrency deposit or withdrawal.
  • The account is registered in the European Economic Area (EEA).
  • The transaction meets the regional threshold requirements.
  • The Travel Rule API is enabled for this account.


Please note: The Travel Rule API is not available for all accounts. To request access, please contact your account manager or send an email to institutional@whitebit.com.

A new “travelRule” object has been introduced for users who use the private API for deposits and withdrawals.

Here is an example of a full description for a deposit request:

  1. Individual
{
  "uniqueId": "550e8400-e29b-41d4-a716-446655440000",
  "walletType": "hosted",
  "originator": {
    "type": "individual",
    "residenceCountry": "NLD",
    "walletAddress": "0x9876543210fedcba9876543210fedcba98765432",
    "address": {
      "country": "NLD",
      "city": "Amsterdam",
      "addressLine1": "Damrak 1"
    },
    "firstName": "Alice",
    "lastName": "Johnson"
  },
  "request": "{{request}}",
  "nonce": 1594297865000,
  "vaspData": {
    "vaspId": "vasp-002"
  }
  1. Legal entity
{
  "uniqueId": "550e8400-e29b-41d4-a716-446655440000",
  "walletType": "hosted",
  "originator": {
    "type": "entity",
    "residenceCountry": "GBR",
    "walletAddress": "0xabcdef1234567890abcdef1234567890abcdef12",
    "address": {
      "country": "GBR",
      "city": "London",
      "addressLine1": "123 Finsbury Square",
      "postCode": "EC2A 4BX"
    },
    "fullName": "Acme Corporation Ltd"
  },
  "request": "{{request}}",
  "nonce": 1594297865000,
  "vaspData": {
    "vaspName": "Famous Vasp Inc"
  }

For further information on deposit confirmation, please refer to the API documentation.

An example of a withdrawal request looks as follows:
1. Individual

{
  "ticker": "BTC",
  "amount": "0.5",
  "address": "bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh",
  "uniqueId": "24529048",
  "travelRule": {
    "walletType": "hosted",
    "beneficiary": {
      "type": "individual",
      "firstName": "John",
      "lastName": "Doe",
      "residenceCountry": "DEU",
      "address": {
        "country": "DEU",
        "city": "Berlin",
        "addressLine1": "Alexanderplatz 1"
      }
    },
    "vaspData": {
      "vaspId": "vasp-001"
    }
  },
  "request": "{{request}}",
  "nonce": 1594297865000
}

2. Legal entity

{
  "ticker": "USDT",
  "amount": "10000",
  "address": "0x742d35Cc6634C0532925a3b844Bc9e7595f8a2B1",
  "network": "ERC20",
  "uniqueId": "24529049",
  "travelRule": {
    "walletType": "hosted",
    "beneficiary": {
      "type": "entity",
      "fullName": "Acme Trading Ltd",
      "residenceCountry": "GBR",
      "address": {
        "country": "GBR",
        "city": "London",
        "postCode": "EC2A 4BX",
        "addressLine1": "123 Finsbury Square"
      }
    },
    "vaspData": {
      "vaspName": "Famous Vasp Inc"
    }
  },
  "request": "{{request}}",
  "nonce": 1594297865000
}

Detailed information on confirming withdrawals is available in the API documentation.

Why These Updates Are Necessary

The Travel Rule is an international standard requiring financial institutions and exchanges to collect and share certain information about the originators and beneficiaries of transactions. These updates ensure that we remain compliant with these regulations, fostering transparency and security across the crypto ecosystem.

Frequently Asked Questions (FAQs)

  1. What happens if I don’t provide the required information? Without the mandatory details, your deposit or withdrawal request may be delayed or rejected until all necessary fields are completed.
  2. Do these changes apply to all users? Currently, these updates apply specifically to users from the EEA region.
  3. Are these changes applied to all types of deposits and withdrawals? No, these changes are applied only to crypto deposits and withdrawals. Fiat deposits and withdrawals remain unaffected.

Was this article helpful?

2 out of 2 found this helpful

Have more questions? Submit a request