Wallet with a lock and five verification icons: identity document, Satoshi test transfer, liveness check, secure chip and signed message
Hardware Wallet

What is a Satoshi test — and the four other ways to prove you control a self-hosted wallet

If an exchange has asked you to prove that you control a wallet address before it will send funds there, it is following a specific rule with a specific list of accepted methods. Here is that list, what each method actually proves, and the one thing four of the five leave out.

Published 2 September 2026 · Cryptnox SA, Geneva

Key takeaways
  • Since 30 December 2024, EU crypto-asset service providers must assess whether a self-hosted address is owned or controlled by their customer before transfers above EUR 1,000 (Regulation (EU) 2023/1113, Article 14(5)).
  • The EBA Travel Rule Guidelines (EBA/GL/2024/11, paragraph 83) list five accepted methods. A Satoshi test is method (c); signing a message with the wallet's key is method (d).
  • Methods (a) to (d) each prove either identity or key control, never both, and none of the five proves legal ownership or continuing control.
  • The Cryptnox Wallet identity flow performs method (d) and binds the signature to a government-ID check, with no funds moved.

Why you are being asked at all

Since 30 December 2024, crypto-asset service providers in the EU have operated under the Transfer of Funds Regulation (Regulation (EU) 2023/1113, the European implementation of the FATF "travel rule"). Article 14(5) covers transfers to and from self-hosted addresses — wallets you control yourself, rather than an account held for you by an exchange. You will also see these called unhosted wallets; the two terms mean the same thing, and older guidance tends to use the latter.

Above a threshold of EUR 1 000, the provider must take adequate measures to establish whether the self-hosted address is actually owned or controlled by its customer. A simple declaration from the customer is not one of the methods the guidelines list.

The European Banking Authority set out how in its Travel Rule Guidelines (EBA/GL/2024/11). Paragraph 83 gives providers five methods, and says they should use at least one.

The five methods

MethodWhat it isWhat it actually proves
(a)Unattended identity verification that displays the addressWho you are — and that the address was shown during your session
(b)Attended (human-supervised) identity verificationThe same, with a person reviewing it
(c)Sending a predefined amount, set by the provider, from and to the address — the Satoshi testThat someone can move funds from the address
(d)Digitally signing a specific message with the key corresponding to the addressThat someone holds the private key
(e)Other suitable technical means, provided the assessment is reliable and secureWhatever the provider is satisfied it establishes

Sources: EBA/GL/2024/11, Travel Rule Guidelines (final report, PDF), paragraph 83, and Regulation (EU) 2023/1113 on EUR-Lex. Summarised; the guidelines give the authoritative wording.

What is a Satoshi test?

A Satoshi test is a wallet verification in which a crypto-asset service provider asks you to send a small, exactly specified amount from the self-hosted address you are claiming, so that the confirmed on-chain transaction shows you can spend from it. It is method (c) on the EBA list. The amount is often close to the smallest unit the asset supports, which is where the name comes from, and some providers send it to the address and ask for it back. When the transaction confirms on-chain, the provider treats that as evidence you control the address.

It is simple and it needs no special software, which is why exchanges reached for it first. It also has real costs:

  • Funds actually move. A test transfer is a live transaction, not a simulation.
  • You pay a network fee, which on a congested chain can exceed the test amount by a wide margin.
  • It takes as long as the chain takes. Confirmation time is not yours to control.
  • It leaves dust behind — small unspendable balances and extra UTXOs that complicate later accounting.
  • It fails for addresses you cannot spend from, such as certain contract or custody arrangements.
The limitation that matters

A Satoshi test shows that somebody was able to send from the address. It does not show who. If your keys were copied, coerced or shared, the test passes exactly the same way.

Which exchanges ask for a Satoshi test?

Any EU crypto-asset service provider can use one, and several large platforms document it under their own names. The details below come from each provider's help centre at the time of writing; the provider's current page is authoritative.

  • Kraken offers a Satoshi test to EU clients when withdrawing to a new private wallet or depositing from an unverified one, for transfers above EUR 1,000. You send the exact amount from the exact address being verified within 180 minutes, and network fees are credited back as Kraken fee credits, subject to limits (Kraken: What is a Satoshi test).
  • Crypto.com describes it as a one-time verification that confirms you control a non-custodial wallet address, required in the EU once cumulative transfers to that wallet exceed EUR 1,000, with 90 minutes to complete it (Crypto.com: How to perform a Satoshi test).
  • Coinbase verifies a self-hosted wallet with a small test deposit sent from that wallet within a set time (Coinbase: self-hosted wallet verification).
  • BISON (Börse Stuttgart) lists three options for the same check: a Satoshi test, a digital signature, or what it calls an Automated Ownership Proof (BISON: Transfer of Funds Regulation).

Two things follow. The method is the provider's choice, not yours, so a signed message is only available where the provider offers it, as BISON does. And a provider that accepts a digital signature is accepting method (d), which is exactly what the Cryptnox certificate carries, with a verified identity attached.

Message signing — method (d)

Method (d) asks for something different: take a message the provider specifies, sign it with the private key corresponding to the address, and hand back the signature. Anyone can then verify that the signature matches the address, without the key ever being revealed.

Compared with a Satoshi test this is strictly cheaper and cleaner. No funds move, no fee is paid, there is nothing to wait for on-chain, and no dust is created. It is also more precise: a spend proves control over funds, while a signature proves possession of the key itself.

But it shares the same blind spot. A valid signature proves that whoever produced it held the key at that moment. It says nothing at all about their identity.

The gap four of the five share

Read paragraph 83(e) closely and the EBA's actual standard becomes visible. A method qualifies where it allows a reliable and secure assessment and the provider is "fully satisfied that it knows who owns or controls the address".

Measured against that sentence, the methods split into two groups that each solve half the problem:

(a) and (b) — identity, weakly bound

These establish who you are to a documented standard, then display an address during the session. The link between the person and the key rests on the address being shown, not on it being cryptographically demonstrated.

(c) and (d) — key control, no identity

These prove cryptographically that someone controls the address. Neither carries any statement about who that someone is.

This is why paragraph 85 exists: where one method on its own is not sufficiently reliable, the provider should use a combination. In practice that means pairing an identity check with a cryptographic one — which is more onboarding steps, more evidence to store, and more for the customer to get through.

Where Cryptnox fits

The Cryptnox Wallet identity flow performs method (d) — you sign a Cryptnox challenge with the key held on your Cryptnox hardware wallet card, and no funds move — and binds that signature to a government-issued identity document check and a liveness check in the same operation. How the identity flow works, step by step.

The output is a single sealed PDF, a Blockchain Public Key / Address Control Attestation Certificate, naming the address, the verified identity and the time. Whether it satisfies any particular provider's process remains that provider's decision; the certificate states its own scope and reliance is theirs to assess.

Three practical points people miss

Every method is a snapshot. Control of a key can change, lapse or be compromised the moment after verification. None of the five establishes continuing control, and none is evidence of legal ownership — only of what was demonstrated at a recorded time.

Verification can be reused. Under paragraph 86, once a provider is satisfied an address belongs to its customer it may record that and skip re-verification for later transfers to the same address — commonly called whitelisting. It must still watch for changes in risk or control.

The threshold is not a safe harbour. EUR 1 000 is where the obligation bites, but providers apply risk-based procedures to self-hosted transfers generally, so you may be asked below it.

Frequently asked questions

What does a Satoshi test mean?

A Satoshi test is a wallet verification in which an exchange asks you to send a small, exact amount from your self-hosted address. A satoshi is the smallest unit of bitcoin, which is where the name comes from. A confirmed transaction shows that you can spend from the address. In the EU it is method (c) in the EBA Travel Rule Guidelines (EBA/GL/2024/11, paragraph 83).

Why did my exchange ask me for a Satoshi test?

Since 30 December 2024, EU crypto-asset service providers must assess whether a self-hosted address is owned or controlled by their customer before transfers above EUR 1,000 (Regulation (EU) 2023/1113, Article 14(5)). A Satoshi test is one of five accepted ways to do that, and the provider chooses the method. Kraken, Crypto.com, Coinbase and BISON all document it in their help centres.

How much does a Satoshi test cost, and how long does it take?

The test amount is small, and some providers credit the network fee back afterwards, but you pay that fee up front and it varies with the chain and how busy it is. The time is set by on-chain confirmation plus the provider's window: Kraken allows 180 minutes and Crypto.com 90 minutes to complete the transfer.

Is a Satoshi test the same as signing a message?

No. Both appear on the EBA list, but they are different methods. A Satoshi test (method (c)) moves funds on-chain and costs a network fee. Signing a provider-specified message with the wallet's private key (method (d)) proves control of the key with no transaction and no fee. Each shows that someone controls the key; neither, on its own, shows who.

Can I prove I control a self-hosted wallet without sending any crypto?

Yes. Digitally signing a specific message with the key corresponding to the address is method (d) in EBA/GL/2024/11 and involves no transfer. The Cryptnox Wallet identity flow performs that signature on the card, binds it to a government-ID check and a liveness check, and issues a Blockchain Public Key / Address Control Attestation Certificate. Whether a given provider accepts it is that provider's decision.

Does a Satoshi test prove who owns the wallet?

No. A confirmed test transaction shows that somebody was able to spend from the address at that moment. It does not identify that person, and it is not evidence of legal ownership or of continuing control. That is why the guidelines allow providers to combine methods (paragraph 85) and why identity-bound proofs exist.

Prove control without moving funds

The Cryptnox Wallet identity flow takes about five minutes and produces a sealed certificate you can hand to whoever asked for it.

Sources: Regulation (EU) 2023/1113, Article 14(5) · EBA Guidelines EBA/GL/2024/11 (Travel Rule Guidelines), paragraphs 83–86, applicable from 30 December 2024. This article is general information about the verification methods regulators recognise, not legal or compliance advice.