Skip to content

Crypto KYC in India: Meaning, Process, Documents, Rejections and Privacy Risks

Author: EDITORIAL TEAM Last updated: July 18, 2026

Last updated: 2026
Author: EDITORIAL TEAM
Regulatory sources checked: July 2026

Affiliate disclosure: This article may contain links to cryptocurrency platforms or related services. We may receive a commission if a reader registers or completes an eligible action through one of those links. Commercial relationships do not determine how we describe a platform’s KYC process, privacy practices, compliance claims or risks. An affiliate relationship must never be treated as proof that an exchange is safe, solvent or suitable for a particular user.

Responsible trading: Cryptocurrency prices can move sharply, and losses may exceed what a new trader expects. KYC verification does not reduce market volatility, prevent an exchange failure or guarantee that withdrawals will always be available. Use only money you can afford to lose, review fees and withdrawal rules before depositing, protect your account with independent security controls, and seek professional advice for personal legal or tax questions.

Important: This guide provides general educational information. It is not financial, investment, tax or legal advice.


Quick Answer: What Is Crypto KYC in India?

Crypto KYC in India is the process through which a cryptocurrency exchange or other Virtual Digital Asset service provider confirms a customer’s identity.

The process commonly involves:

  • Verifying a PAN and date of birth.
  • Confirming an identity or address document.
  • Completing a live selfie or liveness check.
  • Matching the customer’s name with a bank account.
  • Collecting declarations about occupation, income or source of funds.
  • Screening the customer and transactions under anti-money-laundering controls.
  • Requesting additional information when a profile presents a higher compliance risk.

KYC primarily answers one question: Is the account being operated by the person whose identity has been submitted?

It does not answer several other important questions:

  • Is the exchange financially solvent?
  • Does it protect customer assets adequately?
  • Will it process every withdrawal without delay?
  • Is its FIU-IND registration currently in good standing?
  • Does it maintain sufficient reserves?
  • Can it recover from a major cyberattack?
  • Does it provide legal protection comparable to a regulated bank deposit?

Those checks must be made separately.

Under India’s anti-money-laundering framework, businesses providing specified VDA services are subject to reporting, customer-due-diligence and record-keeping obligations. FIU-IND’s January 2026 guidance states that registration with FIU-IND is a mandatory prerequisite for VDA service providers carrying on the activities covered by the March 2023 notification.


KYC Is a Compliance Control, Not a Platform Safety Certificate

A common misunderstanding is that an exchange must be safe because it asks users to complete KYC.

That conclusion does not follow.

KYC helps a platform identify customers, build an audit trail, monitor transactions and respond to lawful requests. It may make anonymous misuse more difficult, but it does not eliminate:

  • Exchange insolvency.
  • Fraud by employees or executives.
  • Poor custody controls.
  • Cybersecurity breaches.
  • Account takeover.
  • Operational outages.
  • Withdrawal restrictions.
  • Token price collapses.
  • Smart-contract failures.
  • Inadequate customer support.
  • Changes to banking access or regulations.

A platform could operate a detailed KYC process and still have weak financial controls. Conversely, a technically secure wallet service might not provide the same compliance framework as an Indian reporting entity.

Think of KYC as an identity checkpoint. It identifies the person entering the system; it does not certify the condition of everything inside that system.


Why Crypto Platforms Ask for KYC in India

Indian crypto KYC is connected to three broad areas: anti-money-laundering compliance, account integrity and financial reporting.

Anti-Money-Laundering Compliance

The Central Government’s March 2023 notification brought specified VDA activities within the relevant PMLA framework. Covered activities include exchanges between VDAs and fiat currencies, exchanges between different VDAs, VDA transfers, custody or administration of VDAs, and certain financial services connected with a VDA issuer’s offer or sale.

FIU-IND guidance requires covered service providers to implement customer due diligence, internal controls, risk assessment, transaction monitoring, suspicious-transaction reporting and record-keeping processes.

KYC gives a service provider a verified identity against which account activity can be assessed.

Preventing Third-Party Account Use

A verified identity makes it harder to operate accounts under fake names or to route money through unrelated bank accounts.

This is why exchanges may reject:

  • Deposits from bank accounts belonging to someone else.
  • Withdrawals to an account with a different beneficiary name.
  • Multiple accounts created using the same identity.
  • Profiles with inconsistent PAN, identity and bank details.
  • Accounts showing activity inconsistent with the information supplied during onboarding.

These controls are designed partly to reduce money-mule activity, impersonation and unauthorised use.

Tax and Transaction Records

PAN information also connects an account to Indian tax reporting.

Income from the transfer of VDAs is generally subject to the special tax framework under Section 115BBH. The Income Tax Department states that qualifying VDA income is taxed at 30%, plus applicable surcharge and cess, and that the computation generally does not permit deductions other than acquisition cost or the set-off of VDA losses. Section 194S also provides for 1% TDS on covered VDA transfer consideration, subject to the law’s conditions and thresholds.

KYC itself does not calculate a user’s final tax liability, but verified PAN information helps connect transactions, TDS records and tax reporting.


KYC, CDD, AML and EDD: What Is the Difference?

These terms are related but do not mean the same thing.

KYC: Know Your Customer

KYC is the identity-verification part of onboarding and periodic account review.

It may confirm:

  • Legal name.
  • Date of birth.
  • PAN.
  • Residential address.
  • Photograph or live presence.
  • Bank-account ownership.
  • Contact information.

CDD: Customer Due Diligence

Customer Due Diligence goes beyond collecting a document.

CDD may involve:

  • Understanding the purpose of an account.
  • Assessing the customer’s expected activity.
  • Determining whether the customer is acting for someone else.
  • Checking beneficial ownership for business accounts.
  • Screening against sanctions or risk databases.
  • Reviewing whether transactions match the customer profile.

AML: Anti-Money Laundering

AML is the wider system of policies and controls used to detect and report potentially suspicious financial activity.

It continues after onboarding and can include:

  • Transaction monitoring.
  • Wallet-risk screening.
  • Sanctions checks.
  • Unusual-pattern detection.
  • Suspicious Transaction Reports.
  • Account restrictions pending investigation.
  • Reviews of transfers involving unhosted wallets.

EDD: Enhanced Due Diligence

Enhanced Due Diligence is a deeper review applied when the risk is considered higher.

FIU guidance explains that EDD should be more rigorous than ordinary KYC and may include more frequent profile reviews, additional information from credible sources, and reasonable enquiries into a customer’s source of funds. It also identifies higher-risk relationships and Politically Exposed Persons as situations requiring enhanced attention.


Which Documents Are Commonly Requested?

There is no single document flow used by every Indian crypto platform. Requirements can vary according to the platform, customer type, verification provider and available government-document integrations.

A typical retail process may request the following.

Information or documentCommon purpose
PAN number and date of birthTax identity and identity validation
Aadhaar through DigiLockerIdentity or address verification where this route is supported
Passport or Voter IDAlternative identity or address proof on some platforms
Live selfieConfirms that a present person is completing the process
Bank account number and IFSCLinks INR deposits and withdrawals to the verified customer
Occupation or income rangeSupports customer-risk assessment
Source-of-funds evidenceMay be requested during enhanced review
Mobile number and emailAccount contact, authentication and alerts

For example, CoinDCX’s published support flow describes PAN verification, Aadhaar verification through DigiLocker or an alternative passport-upload route, followed by a selfie. ZebPay’s published onboarding material similarly describes PAN verification, DigiLocker-based address verification or supported alternatives, a selfie and income-related declarations. These examples illustrate common workflows, but they should not be interpreted as a universal document list for every exchange.

Is Aadhaar Always Mandatory?

Do not assume that every platform must use exactly the same Aadhaar process.

Some exchanges use DigiLocker-based Aadhaar verification. Others may provide an alternative route using a passport, Voter ID or another officially accepted document. The available route may also depend on whether the customer is an Indian resident, non-resident, business or institutional user.

Follow only the document instructions displayed inside the platform’s official app or verified website. Do not send Aadhaar images to an individual who contacts you through social media, messaging apps or an unsolicited phone call.

Can You Use a Masked Aadhaar?

UIDAI defines a Masked Aadhaar as a version in which the first eight digits are replaced while only the last four digits remain visible. It can reduce unnecessary exposure of the full Aadhaar number.

However, a masked copy should be used only when the platform’s official process accepts it. A DigiLocker consent flow may work differently from manual document upload. Do not alter, obscure or edit a document in a way the official verification process does not permit.


How the Crypto KYC Data Flow Usually Works

KYC is often described as though an exchange manually looks at a photograph and approves the account. Modern verification is usually a combination of automated checks and human review.

The precise technical architecture is not public for every platform, but a typical process can be understood in seven stages.

1. Account Registration

The user creates an account using a mobile number, email address or both.

The platform may collect:

  • Device information.
  • IP address.
  • Browser or app version.
  • Approximate location signals.
  • Login history.
  • Consent records.

These signals can be used for account security and fraud-risk assessment. A change in device or location does not automatically mean wrongdoing, but unusual combinations can lead to additional checks.

2. PAN Verification

The user enters a PAN and date of birth. The submitted details are checked using an authorised verification process or verification provider.

The main purpose is to confirm that:

  • The PAN format is valid.
  • The PAN record is active or usable.
  • The date of birth corresponds to the record.
  • The supplied name is consistent with the verified identity.

A user should enter their name exactly as it appears in the official record. Adding a nickname, shortening a surname or rearranging names can create a mismatch.

3. Identity or Address Verification

The platform may redirect the customer to DigiLocker or request an accepted document upload.

With a DigiLocker flow, the user signs in, completes the required authentication and grants consent for specified documents or information to be shared. DigiLocker is a Government of India digital-document platform that allows issued documents to be accessed, shared and verified.

With manual upload, the system may use Optical Character Recognition to extract text from the document. OCR can read fields such as:

  • Name.
  • Date of birth.
  • Document number.
  • Expiry date.
  • Address.

OCR is not infallible. Glare, compression, a damaged card, unusual typography or poor focus can cause incorrect extraction.

4. Selfie or Liveness Check

The user may be asked to take a live photograph or complete a liveness step.

The purpose is generally to establish that:

  • A real person is present.
  • The capture is not simply a photograph of a photograph.
  • The person resembles the holder of the submitted identity.
  • The session has not been completed using an obviously substituted face.

Depending on the provider, the check may be passive or may ask the user to move, blink, turn their face or follow an on-screen instruction.

Do not assume that an exchange obtains or compares your face against a government biometric database. In many workflows, the comparison is performed between the live capture and the photograph available in the document or document-verification flow. The exact process should be explained in the platform’s privacy and KYC notices.

5. Cross-Document Matching

The platform compares the information across the supplied records.

Typical comparison fields include:

  • PAN name against identity-document name.
  • Date of birth across records.
  • Address against the declared address.
  • Selfie against the document photograph.
  • Bank beneficiary name against the KYC identity.

Minor variations may be accepted by one system and rejected by another. Platforms use different matching rules and third-party verification providers.

6. Bank Verification

The user submits bank-account details or completes a supported UPI verification flow.

The platform may check:

  • Account number.
  • IFSC.
  • Account status.
  • Beneficiary name.
  • Whether the account type is supported.
  • Whether the user is the primary account holder.
  • Whether the bank account is already linked to another profile.

Some verification systems use an automated account-validation service or a small test transaction. Others use UPI-based verification or require supporting evidence if automation fails.

CoinDCX’s support material identifies name mismatch, incorrect bank information, unsupported NRE or NRO accounts, verification timeouts and the customer being only the secondary holder of a joint account as possible reasons for bank-verification failure. ZebPay’s published rules provide a different example, stating that the registered bank account must be in the customer’s name and that certain joint or non-resident account types are not accepted. Platform policies therefore need to be checked individually.

7. Risk Review and Account Decision

If all automated checks pass, the profile may be approved without manual intervention.

A case may instead be referred for review when:

  • Details do not match.
  • A document is unreadable.
  • The selfie confidence is insufficient.
  • The account is linked to previous registrations.
  • A sanctions or PEP screening result needs clarification.
  • The platform needs more information about occupation or funding.
  • The customer’s activity differs from the expected profile.
  • A transfer involves a wallet or counterparty presenting higher AML risk.

The final result may appear as verified, pending, processing, rejected, action required or enhanced review.


Why PAN, Identity and Bank Names Must Match

Name mismatch is one of the most common causes of crypto verification problems in India.

Consider this example:

  • PAN: Rakesh Kumar Sharma
  • Aadhaar or passport: Rakesh K Sharma
  • Bank account: R K Sharma
  • Crypto account profile: Rakesh Sharma

A human reader may understand that these names probably refer to one person. An automated matching system may not.

The system might interpret the variations as:

  • A missing middle name.
  • An unsupported abbreviation.
  • A different legal identity.
  • An incomplete bank record.
  • A possible third-party bank account.

Common Sources of Name Mismatch

Name differences can arise from:

  • Initials being used on one document and full names on another.
  • A surname appearing before the given name.
  • Marriage-related name changes.
  • A missing middle name.
  • Spelling differences.
  • Extra spaces or punctuation.
  • Transliteration between regional scripts and English.
  • Bank records not being updated after a legal name change.
  • Joint-account holder details.
  • A business bank account being submitted for a personal profile.

What Should You Do?

Use the exact name shown in the authoritative record requested by the platform. Do not invent a variation simply because it is used socially.

When the official records themselves disagree:

  1. Check which document contains the outdated or incomplete information.
  2. Update the record through the bank or relevant official authority.
  3. Retain the acknowledgement or proof of the correction.
  4. Wait until the corrected record is reflected in the relevant system.
  5. Retry through the official exchange interface.
  6. Request manual review when the platform expressly supports it.

Do not create a second exchange account to escape a mismatch. Multiple-account attempts may create an additional fraud flag.


Common Crypto KYC Rejection Reasons

A rejection does not always mean the user is ineligible. It often means the system could not verify one or more fields confidently.

Rejection reasonWhat may have happenedPractical response
PAN name mismatchAccount profile does not match the PAN recordEnter the full name exactly as recorded
Incorrect date of birthPAN or identity record has a different dateCheck the official record before resubmitting
Blurry imageOCR cannot read the documentRetake it using stable, even lighting
Cropped documentOne or more edges are missingShow the full document and all four corners
Glare or reflectionSecurity laminate hides text or photographTurn off flash and change the angle
Screenshot rejectedPlatform requires a camera capture or issued digital documentUse the permitted capture method
Unsupported documentThe selected document type is not acceptedChoose an option listed in the official flow
Expired documentPassport or other document is no longer validRenew it or use a valid alternative
Selfie failureFace is obscured or lighting is poorRemove sunglasses or mask and face the light
Address mismatchDeclared address differs from the proofEnter the current address exactly as supported
DigiLocker interruptionConsent, OTP or session was not completedRestart through the official app
Bank name mismatchBeneficiary name differs from KYC recordsUse a bank account in the verified legal name
Unsupported bank typePlatform does not accept the account categoryReview the platform’s bank rules
Secondary joint holderThe verification result returns the primary holder’s nameUse an accepted account where permitted
Duplicate profileThe identity or device is associated with another accountContact official support rather than registering again
Manual review requiredAutomation could not resolve an edge caseSupply only the documents requested through the secure channel
EDD initiatedAdditional source-of-funds or risk information is requiredRespond accurately and retain copies of submissions

How to Retake a Document Image Properly

Document quality is a simple issue, but repeated poor submissions can exhaust the number of permitted attempts.

Use the following approach:

  1. Clean the camera lens.
  2. Place the document on a plain, contrasting background.
  3. Use bright, even light without direct flash.
  4. Keep the camera parallel to the document.
  5. Show all four corners.
  6. Avoid fingers covering the document.
  7. Make sure the name, number and photograph are readable.
  8. Do not use beauty filters, editing tools or scanning effects.
  9. Upload the original capture rather than a compressed messaging-app copy.
  10. Confirm that the document is current and supported.

Never digitally replace, sharpen, erase or alter a field. Even an innocent edit intended to improve readability can cause the document to appear manipulated.


How to Complete a Selfie or Liveness Check

For a better chance of a successful liveness check:

  • Face a soft light source.
  • Avoid a bright window behind you.
  • Remove sunglasses, masks and hats.
  • Keep your entire face inside the on-screen frame.
  • Hold the phone still.
  • Follow the movement instructions slowly.
  • Do not use a photograph displayed on another device.
  • Disable filters and portrait effects.
  • Use the official application rather than a screen-recorded or remote session.
  • Allow camera permission only for the genuine app or verified website.

If your appearance has changed substantially from the identity photograph, the case may need manual review. This can occur after significant weight changes, medical treatment, ageing, facial hair changes or an old document photograph.

Do not attempt to defeat the liveness system. Repeated suspicious attempts can lead to stronger restrictions.


Bank Verification and the “Penny Drop” Question

Some financial platforms validate accounts by initiating a small credit and reading the beneficiary information returned through banking infrastructure. This is often described as a penny-drop check. Other platforms may use UPI verification, bank-account verification APIs or manual documents.

Do not assume that every exchange deposits exactly ₹1 or uses the same method. The amount, timing and verification provider can differ.

The important result is the beneficiary-name match.

Why Bank Verification Fails

A bank check may fail because:

  • The account number is wrong.
  • The IFSC has changed.
  • The bank is experiencing an outage.
  • The account is inactive.
  • The beneficiary name differs from the PAN record.
  • The account is a joint account and the user is not returned as the primary holder.
  • The account type is not supported.
  • The UPI verification request expires.
  • The same bank account is already connected to another exchange profile.
  • The bank returns an abbreviated or outdated name.
  • The platform imposes a cooling-off period after bank changes.

Do Not Use Another Person’s Bank Account

Using a parent’s, spouse’s, friend’s, employee’s or employer’s bank account can trigger third-party funding controls.

Even when the money genuinely belongs to you, the transaction can resemble:

  • Account renting.
  • Money-mule activity.
  • Layering of funds.
  • Unauthorised account use.
  • An attempt to avoid tax or identity controls.

Use only an account permitted by the platform and matching your verified identity.


What Is Enhanced Due Diligence?

Enhanced Due Diligence is not simply “KYC again.” It is a deeper review designed for profiles or transactions presenting higher risk.

FIU guidance describes EDD as measures that are more rigorous than ordinary KYC. These can include more frequent profile reviews, additional information gathering, source-of-funds enquiries and greater monitoring.

Possible EDD Triggers

The precise risk rules are generally confidential, but enhanced review may be associated with:

  • Large or rapidly increasing transaction volumes.
  • Activity inconsistent with the declared occupation or income.
  • Politically Exposed Person status.
  • A potential sanctions or watchlist match.
  • Transfers connected with higher-risk jurisdictions.
  • Repeated rapid deposit-and-withdrawal patterns.
  • Transfers involving wallets associated with illicit activity.
  • Use of an unhosted wallet presenting additional verification concerns.
  • Multiple linked accounts or devices.
  • Unclear source of funds.
  • Institutional or corporate beneficial-ownership complexity.

There is no universal public amount at which every user automatically enters EDD. Platforms apply risk-based controls.

Documents That May Be Requested

Depending on the case, a compliance team might ask for:

  • Recent bank statements.
  • Salary slips.
  • Income Tax Returns or acknowledgements.
  • Business-income records.
  • Sale agreements.
  • Proof of an inheritance or gift.
  • Evidence of the source of crypto assets.
  • Wallet transaction records.
  • Employer or business details.
  • A live video call.
  • An explanation of specific transactions.

Provide only documents specifically requested through the platform’s secure process.

Never send financial records to a Telegram “agent,” WhatsApp contact or personal email address merely because the sender knows your name or account details.


Re-KYC and Ongoing Monitoring

KYC is not always a one-time event.

A platform may require re-verification when:

  • A document expires.
  • The customer’s address changes.
  • The bank account is replaced.
  • Regulatory requirements change.
  • A periodic review becomes due.
  • Account activity changes materially.
  • A security incident affects the profile.
  • A transaction requires updated information.
  • Earlier verification data becomes incomplete.

CoinDCX and ZebPay both publish re-KYC information in their support materials, although the timing, restrictions and documents differ by platform and account.

A re-KYC notice should be checked inside the official app. Do not click an unexpected link merely because a message threatens an immediate account closure.


What Happens to Your Data After KYC?

KYC creates a concentrated set of valuable identity information.

Depending on the platform and verification route, the data involved may include:

  • Legal name.
  • Date of birth.
  • PAN.
  • Identity-document details.
  • Residential address.
  • Mobile number.
  • Email address.
  • Photograph or video capture.
  • Bank-account information.
  • Device and IP information.
  • Occupation and income declarations.
  • Transaction history.
  • Wallet addresses.
  • Source-of-funds records.

This data may be processed by the exchange and by third-party providers that supply document verification, liveness, sanctions screening, cloud hosting, analytics, customer support or payment services.

Regulatory Retention

Financial-compliance records may have to be retained for legally prescribed periods, including after a customer closes an account.

FIU guidance includes record-keeping requirements and, in the VDA transfer context, refers to certain required information being retained for at least five years. This means account closure may not result in the immediate deletion of all KYC and transaction records.

A platform should explain:

  • Which information it collects.
  • Why it collects it.
  • Which service providers receive it.
  • Where it is processed.
  • How long it is kept.
  • Which requests a customer can make.
  • How to contact the grievance or privacy team.
  • What happens after account closure.

Data Protection Does Not Eliminate Breach Risk

India’s Digital Personal Data Protection Act establishes a framework for lawful processing and protection of digital personal data. It does not make a platform immune from attack or automatically guarantee that every processor follows strong security practices.

Be cautious when an exchange makes vague claims such as “military-grade security” without explaining:

  • Security governance.
  • Access controls.
  • Breach-response procedures.
  • Independent audits.
  • Vendor management.
  • Account-protection options.
  • Data-retention practices.

Do not assume that a particular encryption standard is legally required unless the platform or applicable official rule specifically states it.


Privacy Questions to Ask Before Uploading KYC Documents

Before submitting sensitive identity information, check the following.

Is the Domain or App Genuine?

Confirm the website address independently. Search advertisements, sponsored links and lookalike domains can lead to phishing pages.

For an app:

  • Check the developer name.
  • Review the official website’s app link.
  • Avoid APK files from messaging channels or mirror sites.
  • Examine the requested permissions.
  • Do not disable device security merely to install a crypto app.

Is the Privacy Policy Specific?

A useful privacy policy should identify:

  • The legal entity operating the platform.
  • The categories of personal data collected.
  • The reasons for processing.
  • Third-party recipients or processor categories.
  • Retention practices.
  • Security and grievance contacts.
  • Cross-border processing where applicable.

A policy consisting only of general statements such as “we may use your data to improve services” provides limited practical information.

Does the Platform Explain the KYC Provider?

Some exchanges use specialised external verification companies.

Check whether the policy explains:

  • That a third party performs verification.
  • What data the verifier receives.
  • Whether selfie or video data is retained.
  • Whether data is used to improve facial-recognition systems.
  • Whether the information is transferred outside India.
  • How a complaint can be raised.

Is There an Official Grievance Channel?

Look for:

  • A grievance officer.
  • A privacy contact.
  • A support portal within the account.
  • A documented escalation process.
  • An official regulatory or law-enforcement contact.

Do not rely exclusively on a public social-media account for identity-related disputes.


The KYC Data “Honeypot” Risk

A database containing PAN information, addresses, bank details, identity images and facial captures can be highly valuable to criminals.

If exposed, such information may support:

  • Identity theft.
  • Loan or account fraud.
  • SIM-swap attempts.
  • Targeted phishing.
  • Fake customer-support calls.
  • Credential-recovery attacks.
  • Extortion.
  • Social engineering against family members.
  • Fraudulent account openings.

The risk is not limited to an external hacker. Poor access controls, excessive employee permissions, insecure vendors or careless document handling can also expose customer data.

This is why KYC should be completed only when necessary and only through a platform whose legal identity, compliance status, privacy policy and support process can be checked.


Fake Crypto KYC Scams in India

KYC language gives scammers an effective pretext. It sounds official, urgent and connected to financial compliance.

A fraudulent message might claim:

  • Your KYC has expired.
  • Your account will be permanently blocked.
  • A withdrawal is waiting for verification.
  • Your PAN is linked to an illegal wallet.
  • A compliance officer needs to speak with you.
  • You must pay a KYC release fee.
  • You need to install software for video verification.
  • You must share an OTP to cancel a transaction.
  • Your assets will be transferred unless you act immediately.

The criminal then directs the victim to a fake page, malicious app, screen-sharing session or personal messaging account.

CERT-In has specifically warned about scams involving unverified support contacts and screen-sharing applications through which criminals can view OTPs or carry out unauthorised transfers. India’s National Cyber Crime Reporting Portal also provides facilities for reporting suspicious identifiers and financial fraud.

Legitimate KYC Versus a Scam Request

Legitimate processWarning sign
Initiated within the official app or verified siteInitiated through an unsolicited Telegram or WhatsApp message
Uses a documented upload or consent flowAsks you to send documents to a personal account
Does not need your account passwordRequests your password “for verification”
Does not require your seed phraseClaims the seed phrase is needed for wallet compliance
Does not ask you to reveal an OTP to an agentRequests an OTP over a call
Does not require remote control of your deviceAsks you to install AnyDesk, TeamViewer or similar software
Clearly identifies the legal entityUses only a first name or generic “KYC department” identity
Explains why information is requiredThreatens immediate loss without explanation
Does not require an unlock paymentDemands a processing, tax, release or verification fee

The Never-Share List

Never provide any of the following to a person claiming to be an exchange representative, KYC officer, recovery expert, bank employee or law-enforcement officer:

One-Time Passwords

An OTP confirms an action being performed in your account. It should be entered only into the genuine interface that you intentionally opened.

Do not read it aloud. Do not forward a screenshot.

Account Passwords

Support staff should not need your password to review an account issue.

Two-Factor Authentication Codes

Never disclose:

  • Authenticator-app codes.
  • Backup codes.
  • 2FA recovery keys.
  • QR setup secrets.

Seed Phrases and Private Keys

A seed phrase or private key provides control over a self-custody wallet. It is not a KYC document.

No exchange, police officer, tax authority or wallet-support agent needs your seed phrase to verify your identity.

UPI PIN, Card PIN or CVV

A UPI PIN authorises a payment. It is not required to receive money or complete identity verification.

Remote Access or Screen Sharing

Do not install or open remote-control software at the direction of a person who contacts you about KYC.

A remote-access session can expose:

  • OTP notifications.
  • Banking applications.
  • Password managers.
  • Email accounts.
  • Seed phrases.
  • Exchange balances.
  • Authenticator codes.

Unrequested Document Bundles

Do not email a full package containing PAN, Aadhaar, bank statements and a selfie unless the request has been independently confirmed through the platform’s authenticated support system.

A scammer obtaining that bundle may have enough information to impersonate you elsewhere.


Does KYC Mean an Exchange Is FIU-Registered?

No.

Completing KYC means the platform has performed an identity-verification process. It does not, by itself, prove that its FIU-IND registration is current.

FIU registration and customer KYC are separate facts.

FIU-IND’s updated guidance explains that registration is a mandatory prerequisite for covered VDA service providers and that a system-generated reference identifier alone is not necessarily equivalent to completed registration approval.

Before using a platform:

  1. Identify the legal company operating it.
  2. Look for its claimed FIU-IND status.
  3. Check recent official FIU material rather than relying only on a logo.
  4. Note the date on which the status was checked.
  5. Confirm that the legal entity name matches the platform.
  6. Treat missing or unclear evidence as unresolved.

Registration is an important compliance check, but it is still not a guarantee of solvency, custody quality or investment safety.


Is “No-KYC Crypto” Safe for Indian Users?

A platform advertising no-KYC trading may operate outside the Indian reporting framework or restrict the services available to Indian customers.

Risks can include:

  • No reliable local grievance process.
  • Sudden restrictions based on location.
  • Delayed withdrawals when retrospective KYC is demanded.
  • Limited clarity about the operating company.
  • Weak recovery options after account compromise.
  • Inconsistent tax records.
  • Funds being frozen after risk screening.
  • Exposure to sanctions or illicit-wallet counterparties.
  • Platform closure or domain blocking.
  • Greater impersonation and fraud risk.

Do not interpret “no KYC” as “private and safe.” It often means that identity checks are deferred, incomplete or handled under a different jurisdiction.

This article does not provide instructions for bypassing KYC, using false documents, hiding account ownership or circumventing location controls.


What to Do When KYC Is Rejected

Follow a controlled process instead of repeatedly resubmitting random documents.

Step 1: Read the Exact Status

Look for a reason such as:

  • Name mismatch.
  • Unclear document.
  • Unsupported ID.
  • Selfie mismatch.
  • Duplicate PAN.
  • Bank verification failed.
  • Manual review required.

Step 2: Check Your Official Records

Compare:

  • PAN name and date of birth.
  • Identity-document details.
  • Declared address.
  • Bank beneficiary name.
  • Exchange-profile name.

Step 3: Correct the Root Problem

Retaking a photograph will not solve a bank-name mismatch. Updating a bank account will not solve an incorrect PAN date of birth.

Address the field causing the failure.

Step 4: Use Authenticated Support

Open support from inside the account or through the verified website.

State:

  • The KYC stage that failed.
  • The displayed error.
  • The date of the attempt.
  • The type of document used.
  • Whether official records contain a known variation.

Do not send more personal information than support requests.

Step 5: Preserve Evidence

Keep:

  • Ticket numbers.
  • In-app messages.
  • Submission dates.
  • Rejection notices.
  • Copies of non-sensitive correspondence.
  • Bank-verification reference numbers.

Do not publicly post unredacted identity documents while asking for help.


What to Do If an Account Is Restricted After KYC

A restriction after verification does not necessarily mean the original KYC failed.

Possible reasons include:

  • Re-KYC becoming due.
  • Bank details changing.
  • Enhanced due diligence.
  • A suspicious-login alert.
  • A transfer undergoing wallet screening.
  • A sanctions false positive.
  • A source-of-funds request.
  • A court, tax or law-enforcement instruction.
  • Platform-wide withdrawal maintenance.
  • A security hold after password or 2FA changes.

Ask the platform to clarify:

  1. Which feature is restricted?
  2. Is the restriction security-related or compliance-related?
  3. What document or explanation is required?
  4. Where must it be submitted?
  5. Is a reference or ticket number available?
  6. Can unaffected assets or functions still be accessed?
  7. What is the formal grievance route?

Do not pay an unofficial “release fee” to remove a hold.


KYC and Crypto Tax: What Users Should Understand

KYC does not mean taxes have been fully calculated or paid.

A platform may deduct TDS while the user remains responsible for:

  • Calculating taxable VDA income.
  • Reconciling purchases and disposals.
  • Reviewing TDS records.
  • Reporting transactions in the appropriate return.
  • Completing Schedule VDA where applicable.
  • Maintaining supporting records.
  • Seeking professional advice for complex activity.

The Income Tax Department’s 2026 material continues to provide for transaction-wise VDA reporting and the special 30% framework, subject to applicable surcharge and cess. Section 194S governs TDS on covered transfers.

Do not assume that:

  • TDS is the final tax.
  • A loss on one token will automatically cancel a gain on another.
  • The exchange’s profit screen equals taxable income.
  • Moving between platforms removes reporting obligations.
  • A no-KYC platform makes transactions invisible.
  • Closing an exchange account removes historical records.

Consult a Chartered Accountant for personal calculations.


Pre-KYC Safety Checklist

Before uploading any identity document, confirm the following:

  • The website address is correct.
  • The app came from the official publisher.
  • The legal company operating the platform is disclosed.
  • Current FIU-IND status has been checked.
  • The privacy policy explains KYC data use.
  • The platform provides a grievance channel.
  • The requested document is listed in the official process.
  • No person is asking you to send documents over Telegram or WhatsApp.
  • No payment is required to “unlock” KYC.
  • No one is asking for your OTP, password, 2FA code or seed phrase.
  • Remote-access software is not involved.
  • You understand which account features require verification.
  • Your PAN, identity and bank names are consistent.
  • You are prepared for tax and record-keeping obligations.
  • You understand that verification is not proof of platform safety.

Post-KYC Account Security Checklist

After approval:

  • Create a unique password.
  • Enable app-based two-factor authentication where supported.
  • Save recovery codes offline.
  • Secure the email account connected to the exchange.
  • Activate withdrawal alerts.
  • Review active sessions and devices.
  • Use an anti-phishing code when available.
  • Avoid public Wi-Fi for financial activity.
  • Keep the operating system and app updated.
  • Never approve an unexpected login or withdrawal.
  • Verify wallet addresses independently.
  • Consider whether long-term assets should remain in exchange custody.
  • Retain tax records and transaction exports.
  • Review privacy and security notices periodically.
  • Treat unexpected KYC messages as potential phishing attempts.

Frequently Asked Questions

Is crypto KYC compulsory in India?

Covered VDA service providers operating under the Indian PMLA and FIU-IND framework are expected to perform customer due diligence. In practice, users should expect KYC before receiving full access to compliant exchange services. The exact point at which deposits, trading or withdrawals become available can differ between platforms.

Can I trade crypto without KYC?

Some offshore or decentralised services may offer limited access without conventional onboarding. That does not mean they comply with Indian reporting requirements or provide comparable customer protection. A platform may also demand identity verification later when a withdrawal or risk review occurs.

Does KYC approval mean the exchange is safe?

No. KYC confirms customer identity. It does not certify reserves, solvency, cybersecurity, custody quality or withdrawal reliability.

Does KYC mean the government has approved the exchange?

No. A platform’s customer-verification process is not proof of government approval. FIU registration must be checked separately and recently.

Which documents are required for crypto KYC?

PAN is commonly requested for Indian customers. Depending on the platform, identity or address verification may use Aadhaar through DigiLocker, a passport, Voter ID or another accepted document. A live selfie and bank verification may also be required.

Can I send my documents to customer support by WhatsApp?

Do not do so unless the platform’s independently verified policy expressly establishes that channel, which would be unusual for sensitive KYC material. Use the secure in-app or website upload process.

Why is my PAN verified but my bank account rejected?

PAN verification and bank verification are separate steps. The bank check may fail because the beneficiary name, account type, primary-holder status, IFSC or account number does not satisfy the platform’s rules.

Can I use a family member’s bank account?

Usually not. Platforms generally expect fiat deposits and withdrawals to use an account belonging to the verified customer. Third-party accounts can trigger compliance restrictions.

Can I use a joint account?

It depends on the platform. Some accept a joint account only when the exchange user is the primary holder; others may reject joint accounts entirely. Check the platform’s official rules before submitting one.

How long does crypto KYC take?

There is no reliable universal approval time. A straightforward automated check may finish quickly, while mismatches, system outages or manual review may take longer. Ignore any article promising an absolute approval time for every user.

Why has the exchange asked for my income?

Occupation, income range and source-of-funds information can form part of customer-risk assessment. More detailed evidence may be requested during EDD.

Is an EDD request proof that I did something wrong?

No. EDD is a risk-based review. It can be triggered by transaction size, account patterns, PEP status, wallet-risk information or other compliance factors. A request should still be verified through the official support channel before documents are submitted.

Why am I being asked to complete KYC again?

A platform may require re-KYC after a periodic review, document expiry, address change, bank update, change in account behaviour or regulatory update.

Is Aadhaar safe to upload?

No online submission can be described as risk-free. Use only the platform’s verified process, review its privacy policy and use a masked Aadhaar when the official workflow accepts it. DigiLocker consent flows should be completed only through the genuine DigiLocker and platform interfaces.

Does the exchange have direct access to my Aadhaar biometrics?

Do not assume this. A platform may receive authorised document information through DigiLocker and may perform its own selfie or liveness comparison. That is different from having unrestricted access to UIDAI biometric databases.

Can support ask for my OTP during KYC?

No support agent should ask you to disclose an OTP over a call or message. Enter OTPs only into the genuine interface you intentionally opened.

Can a KYC officer ask for my seed phrase?

No. A seed phrase has no legitimate role in identity verification. Anyone requesting it is attempting to obtain control of the wallet.

Is there a KYC processing fee?

A demand for a special KYC payment, verification deposit or withdrawal-unlock fee is a major warning sign. Check the fee schedule and contact official support independently.

What should I do after sharing an OTP or remote access?

Immediately disconnect remote access, change affected passwords from a safe device, contact the bank and exchange, revoke suspicious sessions, secure the email account and report financial cyber fraud promptly. India’s National Cyber Crime Reporting Portal identifies 1930 as the helpline for online financial fraud.

Can I bypass a KYC rejection by making another account?

Do not attempt this. Duplicate profiles can violate platform terms and create additional fraud or AML concerns. Resolve the original mismatch through official support.

Is KYC data deleted when I close my account?

Not necessarily. Compliance and transaction records may be subject to legal retention requirements. Review the platform’s privacy and account-closure policies for the applicable process.


Final Takeaway

Crypto KYC in India is an identity and compliance process. It connects an exchange account to a verified person, supports transaction monitoring and helps reporting entities meet their anti-money-laundering obligations.

For users, the most important points are straightforward:

  • Keep PAN, identity and bank records consistent.
  • Submit documents only through an official interface.
  • Expect automated checks to be followed by manual review in some cases.
  • Do not assume a fixed approval time.
  • Understand that EDD may require source-of-funds evidence.
  • Review how the platform handles and retains personal data.
  • Never reveal OTPs, passwords, 2FA codes, private keys or seed phrases.
  • Never permit remote access for KYC support.
  • Verify FIU-IND status independently.
  • Do not treat completed KYC as proof that an exchange or investment is safe.

KYC can make an account identifiable and improve compliance controls. It cannot remove the financial, custody, privacy and cybersecurity risks associated with cryptocurrency.


Official References

  • Financial Intelligence Unit – India: Updated AML and CFT guidance for VDA service providers and registration requirements.
  • Income Tax Department: VDA tax, Schedule VDA and Section 194S guidance.
  • UIDAI: Masked Aadhaar and Aadhaar security services.
  • DigiLocker: Official digital-document access and verification services.
  • MeitY: Digital Personal Data Protection Act and related framework.
  • CERT-In and National Cyber Crime Reporting Portal: Phishing, remote-access and financial-fraud guidance.
  • Published exchange help centres: Examples of DigiLocker, selfie, bank-verification and re-KYC workflows.

Reviewed by the Editorial Team

This page provides general educational information about cryptocurrency trading. It does not provide personalised financial, investment, legal or tax advice. Platform features, fees and requirements may change, so important details should be verified directly.