A software developer in London holds Ethereum and stablecoins on Arbitrum. She uses a non-custodial wallet to manage the assets, authorize smart contracts, and monitor her multi-chain portfolio. No third party holds her private keys. She controls her recovery information. From a technical standpoint, she is her own custodian. From a regulatory standpoint, the question of what she is—and what obligations she must meet—has no clear answer in most jurisdictions. She may owe tax reporting, anti-money laundering disclosures, and transaction records. The wallet provider may face scrutiny for enabling her activity. Neither the regulations nor the wallet’s technical architecture has evolved to align neatly with the other.
This scenario repeats across regulated markets where self-custody wallets have grown popular but regulatory frameworks have not kept pace. Rabby Wallet, a browser extension designed for Ethereum and EVM-compatible blockchain networks, exemplifies the tension. It offers transaction simulation, automatic network selection, approval visibility for smart contract permissions, and support for multiple ecosystems—Base, Arbitrum, Optimism, Polygon, BNB Chain, and Avalanche—positioning itself as a more transparent alternative to MetaMask, Phantom, and Trust Wallet for active users. Because Rabby is non-custodial and open-source, users retain full control over private keys and digital asset management. That same architecture, however, means regulators cannot easily oversee transactions, prevent fraud through platform controls, or identify the parties involved. The result is a widening gap between how users understand their legal obligations and how regulators are beginning to interpret them.
The regulatory definition problem: custodian or user?
Regulatory bodies in the European Union, United Kingdom, Singapore, and other major markets have begun classifying cryptocurrency activities. The Markets in Crypto Assets Regulation (MiCA) in the EU, the Financial Conduct Authority (FCA) guidance in the UK, and the Monetary Authority of Singapore (MAS) frameworks all use the term “custodian” to describe entities that hold assets on behalf of customers. A custodian faces licensing requirements, capital standards, and operational controls. The definition typically depends on whether the entity has possession or control over private keys or recovery information on behalf of third parties. By that test, Rabby Wallet does not fit the custodian category because the user, not the wallet provider, controls all cryptographic material.
Yet that technical clarity creates a regulatory fog elsewhere. If Rabby is not a custodian, is the provider a “crypto service provider” under MiCA? The regulation defines a crypto service provider to include custodian and deposit wallet providers, but also extends to other persons who provide crypto asset services. The extension is intentionally broad and includes persons who provide custody services but fall outside the formal custodian definition due to their business model. A wallet provider that distributes software, receives no fees, and never touches keys might still be considered to be providing a service subject to notification, AML/KYC obligations, or registration thresholds depending on jurisdiction.
The UK’s approach is similarly ambiguous. The FCA has indicated that a wallet provider that merely distributes software and does not hold assets may fall outside the scope of FCA regulation. However, providing services “in connection with” cryptocurrency can trigger obligations if the provider is deemed to be operating a financial service. The line between distributing neutral technology and operating a regulated service has not been tested comprehensively in court, and different regulators have reached different conclusions about similar products.
Singapore’s approach under the Payment Services Act (PSA) focuses on the provision of payment services, including custody. A wallet that enables transactions on behalf of users could be interpreted as providing a payment service if the transaction involves fiat conversion or if the provider is deemed to be facilitating value transfer on behalf of customers. The Singapore authorities have been more prescriptive than EU or UK counterparts, creating clearer lines in some cases but also narrower interpretation of what constitutes a neutral tool.
Tax reporting obligations for wallet users remain unresolved
Even if the wallet provider avoids regulatory classification, the user does not. A person in the UK, EU, or Singapore who holds cryptocurrency and executes transactions must report gains, losses, and income to tax authorities. In the UK, the framework is relatively settled: each transaction that converts a token to fiat or to another token is a taxable event. Capital gains tax applies to gains on disposal. Income tax may apply if tokens are received as income. The complication arises because tax authorities expect records of these events, and a user of Rabby must create those records themselves.
Rabby provides transaction simulation and approval visibility, which can help a user understand what will happen before signing. It does not, however, export tax records in a standardized format, reconcile activity across blockchains, or automatically report to revenue authorities. A user managing a multi-chain portfolio across Ethereum, Arbitrum, Optimism, Polygon, BNB Chain, and Avalanche must track each transaction, calculate the cost basis for each asset, determine the date of each disposal, and compute the gain or loss. The burden falls entirely on the user. If records are incomplete, inconsistent with blockchain data, or missing, the user faces the tax risk, not the wallet provider.
The EU approach under MiCA includes reporting requirements for crypto service providers, but those requirements apply to the provider, not the user. In theory, if Rabby were classified as a provider subject to reporting, it might be required to report user transactions to relevant authorities. In practice, Rabby is open-source, distributed globally, and operated without a central entity that can receive or execute regulatory directives. Users therefore cannot rely on the wallet provider to discharge tax obligations on their behalf. They must do so independently, and the absence of exported records or integration with tax software makes that process manual and error-prone.
AML/KYC: wallets have no gates, but users do
Anti-money laundering and know-your-customer regulations are designed to prevent financial crimes by requiring institutions to verify the identity of customers and report suspicious activity. A centralized exchange subject to these rules must collect identity information, maintain records, and escalate transactions that appear anomalous. A non-custodial digital asset management wallet like Rabby has no identity verification step, maintains no records of users, and cannot report on transactions because it does not see the parties involved or the intent behind transfers.
This creates an asymmetry that regulators are only beginning to address. From the wallet user’s perspective, using Rabby to execute transactions on Arbitrum, Optimism, or other networks appears to be a private activity. The user enters the address of the recipient, approves the transaction, and the blockchain broadcasts it pseudonymously. No one at Rabby knows who the user is. No one at Rabby reports the transaction to authorities. Yet in many regulated jurisdictions, the user may still have obligations. If the user is a financial institution, a professional money transmitter, or an entity subject to AML laws, they may be required to perform their own due diligence on the parties they transact with and report on certain activities. The wallet itself does not create those obligations, but it also does not help discharge them.
The Singapore framework illustrates the emerging tension. Under the PSA, a financial institution that provides payment services, including cryptocurrency services, must perform transaction monitoring and report suspicious transactions. A user of Rabby who is simultaneously a money transmitter or a payment service provider faces a contradiction: the wallet provides no tools to conduct AML monitoring, yet the user may be required by law to perform it. The risk is pushed to the user, who lacks the technical infrastructure and audit trail that a regulated entity would normally maintain.
Cross-border transfers and compliance complexities
Cryptocurrency transactions executed via Rabby Wallet crypto wallet often cross borders within seconds. A user in London can transfer stablecoins to a counterparty in Singapore, authorize a smart contract on Polygon deployed by developers in El Salvador, and monitor Ethereum mainnet activity from anywhere. The blockchain does not recognize borders, but tax authorities, financial regulators, and AML frameworks do. This creates a compliance layering problem that non-custodial wallet users must navigate alone.
In the EU, cross-border transfers of cryptocurrency above certain thresholds may trigger reporting requirements under the sixth Anti-Money Laundering Directive (AMLD6). If the transfer originates or terminates in the EU, and if it involves a value transfer service or payment service provider, information about the originator and beneficiary must be attached to the transfer. A user of Rabby sending stablecoins from Optimism to a counterparty in another country may not understand that they have an obligation to collect beneficiary information or that the transfer could be flagged for non-compliance if data is missing. The wallet does not collect this information automatically. The user must request it from the counterparty separately, maintain records of it, and ensure it complies with regulatory format requirements.
The UK has adopted similar requirements for transfers above £5,000, and Singapore has included crypto transfers in its monitoring framework. In each case, the burden falls on the individual user to gather information, maintain records, and verify compliance. A cryptocurrency wallet, even one designed with transaction simulation and approval visibility, cannot discharge those obligations. The absence of a centralized counterparty means there is no single entity to enforce rules or ensure consistency. Users who do not understand these requirements face potential penalties for non-compliance without a clear remediation path.
Staking, lending, and yield-bearing activities in the regulatory gap
Rabby’s support for multiple EVM-compatible blockchains includes networks where users can stake tokens, participate in lending protocols, or engage with yield-bearing smart contracts. These activities are not merely wallet functions; they are financial transactions that regulators are beginning to scrutinize. In the EU, staking income may be classified as financial yield, triggering income tax obligations. In the UK, staking rewards may be treated as miscellaneous income subject to income tax. Singapore similarly classifies cryptocurrency staking as income in many cases.
The complication is that regulatory treatment varies by the nature of the activity and the terms offered. If a protocol offers a fixed return to token holders, it may be classified as a deposit or a security in certain jurisdictions. If it offers a variable return based on network activity, the tax and regulatory treatment may differ. A user of Rabby who approves a smart contract to lock tokens in a liquidity pool or staking contract is making a financial decision that has tax consequences, yet the wallet provides no guidance on those consequences. The transaction simulation shows the expected balance change, but it does not indicate whether the activity triggers income tax, capital gains tax, or regulatory licensing obligations on the user.
Some jurisdictions are beginning to address this by classifying certain lending and staking platforms as financial service providers. In the EU, a platform that accepts deposits of cryptocurrency and pays yield may be classified as a custodian or a credit institution depending on the terms. In Singapore, the framework is clearer: platforms offering yield or lending services are regulated as capital markets intermediaries or deposit-taking entities. Yet these regulations apply to the platform, not to the user. A user who interacts directly with a decentralized protocol via Rabby, using no intermediary, may not be subject to these rules as a user. However, they remain responsible for tax reporting and may face scrutiny if they cannot explain the basis for income reported from such activities.
The provider’s liability paradox: regulation without responsibility
Rabby’s status as a non-custodial, open-source wallet distributed globally creates a liability paradox for regulators. On one hand, the wallet provider cannot exercise traditional financial controls. On the other hand, the provider may still face scrutiny for enabling user activity. A regulator investigating cryptocurrency crime may attempt to identify the Rabby developer or organization, demand information about users, or require the wallet to implement blocking or monitoring features. None of these approaches is straightforward for an open-source project with distributed governance and no central point of control.
The UK and EU have begun addressing this through regulation that targets key service providers in the cryptocurrency ecosystem. EU regulation, for instance, identifies custodian wallet providers, centralized exchange operators, and staking providers as subject to obligations. If Rabby were classified as a custodian wallet provider despite its non-custodial architecture, it could face licensing requirements and operational rules. However, the open-source distribution model and lack of a centralized business entity complicate regulatory enforcement. There is no entity to license, no office to inspect, and no single actor responsible for user activity. The regulator can pressure exchanges and platforms that interface with the broader financial system, but enforcing rules against an open-source wallet distributed globally is technically and legally uncertain.
This creates an incentive structure that may not serve regulatory goals. A centralized exchange, subject to clear rules and potential enforcement, may invest in compliance infrastructure, transaction monitoring, and user verification. A non-custodial wallet, facing uncertain regulation and limited compliance options, may make only minimal investments in user education or safety features. The result is that users of open-source wallets may have less protection and less clarity about their obligations than users of regulated platforms, even though regulators theoretically prefer centralized platforms they can oversee.
Practical compliance strategies for international users
Users of Rabby who operate in regulated markets must accept that the wallet itself provides no compliance framework. The wallet’s technical features—transaction simulation, approval visibility, multi-chain support—serve user convenience and security, not regulatory compliance. A user managing a multi-chain portfolio across Ethereum, Arbitrum, Optimism, Polygon, BNB Chain, and Avalanche must implement their own controls. Those controls include maintaining a record of every transaction, calculating tax consequences, identifying counterparties where required by AML law, and reporting income from staking or yield-bearing activities.
Some practical steps reduce risk. First, maintain a complete record of every transaction, including date, time, wallet address, counterparty address, asset, amount, and stated purpose. This should be separate from blockchain data; blockchain records are pseudonymous and do not link to the user’s identity. A personal record bridges that gap and provides evidence of compliance if a regulator asks. Second, classify each transaction according to the tax rules in your jurisdiction. A swap from Ethereum to Arbitrum may be a taxable event if you convert between tokens, or a non-event if you are merely moving the same asset across networks. Understanding the local rules reduces penalty risk. Third, document the basis for any income reported, such as staking rewards. If a regulator questions the income, you should be able to explain the protocol, the rate offered, the dates of participation, and the blockchain evidence supporting the amount.
Fourth, if you are subject to AML obligations—because you operate a payment service, an investment firm, or another regulated activity—you must perform enhanced due diligence on counterparties and report suspicious transactions to the relevant authority independently. Rabby cannot do this for you. You must design your own process or use a compliance service. Fifth, if you operate across multiple jurisdictions, understand that tax treatment can differ. Activity that is income in one country may be capital gains in another. A staking reward that is taxable in the UK might not be taxable in a different jurisdiction. You should seek tax advice for each relevant jurisdiction rather than assuming uniform treatment. These steps are burdensome, but they reduce the risk of discovering years later that you have failed to meet obligations that were unclear at the time.
The evolution of regulation and its implications for self-custody
Regulatory frameworks are beginning to tighten around cryptocurrency activities, but the application to non-custodial wallets remains unsettled. The EU’s MiCA, implemented in 2024, attempts to clarify obligations for many providers, but the treatment of open-source wallets and decentralized protocols remains ambiguous. The UK’s approach has been to defer to the FCA, which has not yet issued detailed guidance on how the regulatory perimeter applies to non-custodial software. Singapore has been more prescriptive but has also exempted certain activities from licensing if they do not meet the definition of a regulated payment service. Over the next few years, it is likely that more jurisdictions will attempt to close these gaps.
The direction of regulation appears to be toward greater clarity and broader coverage. If a wallet is deemed to be operating a financial service, it may face licensing, capital requirements, and operational standards that make open-source, distributed development difficult or impossible. Alternatively, regulators may focus on endpoints: exchanges, platforms, and services that connect cryptocurrency to fiat money and to regulated financial infrastructure. If regulation focuses on endpoints, non-custodial wallets and decentralized protocols may face less direct regulatory pressure but will still leave users responsible for their own compliance.
The most likely outcome is a bifurcation: regulated jurisdictions will increasingly require custody and financial services related to cryptocurrency to operate through licensed entities subject to oversight. Users in those jurisdictions will face pressure to use regulated wallets and platforms, or to comply with independent obligations if they use non-custodial tools. Unregulated or less regulated jurisdictions may see continued use of open-source wallets with minimal compliance friction. This creates an incentive for users in strict jurisdictions to either migrate to regulated platforms or to manage compliance privately, accepting the burden and the risk that their interpretation of the rules may later be challenged.
Frequently asked questions
Is Rabby Wallet a regulated custodian?
No. Rabby is a non-custodial wallet, meaning the user controls private keys and recovery information, not the wallet provider. However, the provider may still be subject to regulation as a “crypto service provider” or under other classifications depending on jurisdiction. The regulatory status of non-custodial wallet providers remains ambiguous in most major markets, and different regulators have reached different conclusions about whether open-source wallet distribution triggers regulatory obligations.
Do I have to report cryptocurrency transactions and gains if I use a self custody wallet?
Yes. In the UK, EU, Singapore, and most regulated jurisdictions, cryptocurrency transactions are taxable events, and gains or income must be reported to tax authorities. The wallet does not report on your behalf because it does not know who you are or what your tax obligations are. You must create records, calculate gains or losses, and file required disclosures. Tax authorities may have access to blockchain data and can cross-reference transactions with your reported activity; underreporting or misreporting creates penalty risk.
What AML obligations apply to me if I use Rabby to transfer cryptocurrency across borders?
If you are an individual, basic AML reporting may not apply to transfers you initiate yourself. However, if you operate a payment service, money transmission business, or financial entity, you may be required to perform transaction monitoring and report suspicious activity. Additionally, certain cross-border transfers above thresholds may require originator and beneficiary information to be attached to the transaction. You must understand the specific obligations in your jurisdiction and maintain records supporting compliance. Rabby does not provide tools for this; you must implement controls independently.