Skip to content
Insights

The wallet is the last thing to scope.

On an embedded-crypto build the time goes to counterparty status, the ledger bridge, the travel rule and reporting, and all four sit underneath the wallet.

  • Bogdan Stoishych
  • Engineering
  • Jun 15, 2026

Every embedded-crypto brief opens with the wallet. Which chains, which assets, custodial or not, and what the screens look like. That part is rarely what runs long.

Four things sit underneath it, and each hands the wallet a requirement it has to meet. A scope that starts at the wallet gets rewritten as they land.

Three ways to be a counterparty

The MiCA transitional period for existing crypto firms ended in every EU member state by July 1, 2026 at the latest. Crypto-asset services in the EU can now be provided three ways, and which one a counterparty operates under is a fact the system has to carry.

  • With CASP authorization under Article 59.
  • By notification under Article 60, a route open to credit institutions and certain other regulated financial entities.
  • By a third-country firm under the narrow reverse solicitation exemption in Article 61.

Authorized and notified entities are listed in the ESMA register. A counterparty model carrying one boolean field for regulated collapses all three into a single value. They are not interchangeable: which one applies decides whether a transfer goes out, goes out with data attached, or does not go at all. That decision surfaces in the wallet as a destination the customer can or cannot send to.

Two ledgers with a bridge

A core banking system treats a payment as a single event. An on-chain transaction can be dropped, replaced or reorganized until it is final, and the mechanism that makes it final differs by chain. Bitcoin relies on the number of confirmations. Ethereum finalizes through checkpoints, usually inside about two epochs, though it can take longer. BFT chains such as those on CometBFT treat a committed block as final.

Crediting a customer on first sight of a transaction means occasionally crediting funds that never arrive. The model that holds through a reorg keeps two ledgers with a bridge between them:

  • The chain-side ledger records observations: transaction hash, block, finality status.
  • The bank-side ledger records customer entitlements.
  • The bridge moves a transaction across once it meets a finality threshold set per asset.

The two reconcile on transaction hash plus output index on UTXO chains, or log index for EVM tokens, because one transaction can carry several transfers. A reconciliation keyed on the hash alone will silently merge them.

The travel rule data has no threshold

Under Regulation (EU) 2023/1113, originator and beneficiary information must accompany every crypto-asset transfer in the EU, whatever the amount. The FATF threshold of USD or EUR 1,000 does not apply. The data can travel inside the transaction or over a separate channel, and it has to be sent no later than the moment the transfer is initiated.

  • Address attribution, to work out whether a destination address belongs to a service provider and which one.
  • Travel rule protocol integration with counterparty providers. An outbound transfer cannot execute until the data has been transmitted, so a transfer to an unreachable counterparty is held or rejected.
  • Self-hosted address handling. The CASP collects the information from its own customer, and above EUR 1,000, the one threshold anywhere in this regime, it has to assess whether that customer owns or controls the address, by having them sign a message with the address key, or send a small test amount from it.
  • A procedure for incoming transfers arriving with data missing: execute, reject, return, suspend, or ask for what is missing before releasing the assets.
  • Five-year retention of everything sent and received.

The held state is visible to the customer. That is one of these four requirements landing in the most visible place there is: a transfer waiting on a counterparty to answer needs a status, a screen and a piece of copy, and the compliance integration decides all three.

Reports come from the bank-side ledger

MiCA requires a custodian to keep a register of positions per client and to send each client a statement at least quarterly. Client assets usually sit in omnibus addresses, so the chain cannot show an individual position. The reports come from the bank-side ledger.

The chain-side ledger is what makes that answerable. Because it stores observations against block heights, any past date can be reconciled again, which is the difference between answering an auditor and rebuilding a quarter from scratch.

What to scope first

  • Counterparty status data.
  • Finality thresholds, and the bridge between the two ledgers.
  • Travel rule integration, including the hold logic.
  • The reporting data model.

The wallet is then scoped against requirements that already exist.