KYC data is an irresistible honeypot for hackers, and we must change how it is collected
Laz Pieper of Coin Center argues that the way firms collect Know Your Customer (KYC) data creates concentrated targets for hackers and needs to be rethought. He suggests privacy-preserving identity verification systems that let people prove only required attributes while retaining control over their underlying personal information.

Why It Matters
KYC repositories hold sensitive personal data and therefore become attractive targets for cyberattacks; shifting to verification methods that minimize stored data could reduce breach risk and give individuals more control over their information, Pieper argues.
Key Facts
- Author: Laz Pieper
- Organization: Coin Center
- Main claim: KYC data is an irresistible honeypot for hackers
- Proposed approach: Privacy-preserving identity verification systems
- Proposed benefit: Allow individuals to prove only what a service needs to know while keeping underlying information under their control
Laz Pieper of the policy organization Coin Center warns that current approaches to Know Your Customer (KYC) data collection create concentrated stores of sensitive personal information that are highly attractive to hackers. Under today’s model, businesses routinely collect and retain full identity records from users, producing centralized targets that, if breached, can expose large volumes of private data.
Pieper proposes replacing that paradigm with privacy-preserving identity verification systems. Such systems would enable people to demonstrate only the specific attributes a service requires — for example, that they are over a certain age or that an identity is genuine — without handing over or allowing the service to store the underlying documents or full identity data.
Adopting verification methods that limit what information is disclosed and retained could reduce the incentives for attackers and shrink the fallout when breaches do occur. By keeping raw identity details under individuals’ control, these approaches aim to lower the risk posed by large centralized repositories and to align data practices more closely with user privacy.
Pieper’s argument frames this shift as a necessary change in how identity information is collected and handled. Moving toward selective, privacy-preserving verification would require rethinking industry practices and deploying new technical and policy solutions so that services get what they need without creating irresistible honeypots for cybercriminals.
Keep Reading

Algorand names former Chainlink executive William Herkelrath as CEO

Hunter Biden's new LAPTOP token lost 98% of its value in under an hour after $1.6 billion debut

PayPal expands stablecoin rails with custom token issuance platform
