There is a famous saying in the Bitcoin community:
"Not your keys, not your bitcoin".
For years, many people treated it more as a slogan, less as a warning and seldom as a reminder.
Bitcoin started out innocent, idealistic and bare.
It was magic internet money. It was a peaceful revolution. It was the way.
But over time, layers accumulated around it.
Identity checks. Banking requirements. Fraud monitoring. Reporting obligations. Consumer protection frameworks. Compliance regimes.

Most of them were driven by real-world incidents. We may not all agree on the methods, but financial crime is real. Scams are real. Consumer harm is real. We have seen it. It is painful and we would do our best to minimise it, even if there were no legal requirements whatsoever.
But consider this.
Prior to 2018, there were no mandated KYC requirements for Australian bitcoin exchanges. Buying bitcoin without identity verification was common.
Since then, more and more requirements have been introduced, to the point that by 2025, digital exchanges were expected not just to provide services, but also to profile their users, monitor their behaviour, assess their intentions and intervene when risks to them or others are detected.
The Direction of Travel
On 31 March 2026, Australia’s new Transfer of Value requirements came into effect as part of broader AML/CTF reforms.
Some of those requirements have broad implications.
One of them is the Travel Rule.
At its core, the Travel Rule is an information-sharing framework. It requires digital asset businesses to collect, retain and, where applicable, exchange identifying information relating to transfers.
In other words, exchanges are expected to share personal information about you, such as your full name, date of birth and home address, with other exchanges and custodians alongside bitcoin transactions.
So basically, we moved from KYC-free in 2018 to the Travel Rule in 2026.
How things have changed in 8 years.
A Road Paved with Good Intentions
Reasonable people may debate whether this regime is the right approach.
But one consequence is undeniable.
More personal information is being collected, stored and shared.
And every additional database creates additional privacy and security considerations for you and your family.
History is full of examples of sensitive data being leaked, breached, misconfigured, exposed or accessed for purposes far beyond those originally intended.
A recent example from earlier this year is France’s surge in kidnappings and violent attacks targeting digital asset holders and their families.
Whether those attacks originated from data breaches, public disclosures or other intelligence sources, they serve as a stark reminder that information linking identities to bitcoin ownership can create real-world risks.
Bitcoiners have understood this for a long time.
Bitcoiners minimise these risks through what we call OpSec.
But not everyone is a Bitcoiner.
And not every system is designed with privacy in mind.
The Usual Way
Globally, most exchanges and custodians confronted with the Travel Rule had two choices: comply or die.
Choosing to comply usually means connecting to Travel Rule providers, chain surveillance systems and growing networks of counterparties exchanging customer information.
So when we knew with certainty that the Travel Rule was coming, we did our research. And, on top of everything, we discovered something surprising.
Not all Travel Rule providers speak to one another.
An exchange may know exactly where a transfer is going, yet still have no standardised way to deliver the required information.
The fallback can be surprisingly low-tech.
Sometimes, it is email.
Yes, the same email channel we have all been taught not to send sensitive information, such as our debit or credit card number, through.
So we read the new rules, consulted the experts and did our own research.
And reached a decision.
Rather than building systems to support and maintain an expanding network of counterparties, surveillance, reporting and information-sharing relationships, we would do something else.
A Fork in the Road
Many Bitcoiners assume that withdrawing from an exchange to their own self-custody wallet means there are no Travel Rule obligations.
That is not entirely accurate.
Australia’s new framework introduces an important distinction between verified and unverified self-hosted wallets.
In simple terms, withdrawing bitcoin to a wallet you control is treated differently depending on whether ownership of that wallet has been verified by the exchange.
That distinction matters.
More than you might think.
Because verified self-hosted wallets attract significantly fewer obligations than unverified self-hosted wallets and offer much greater privacy and security.
Remember OpSec?
Privacy matters.
So instead of connecting to global and centralised Travel Rule providers, and instead of subscribing to third-party chain surveillance tools, and instead of automatically reporting your transactions and personal details to third parties, we built a Bitcoin-style solution. We built our very own Self-Hosted Address Zenith Attestation Module, or as we like to call it: SHAZAM.
This is the Way
Bitaroo's SHAZAM is a cryptographic wallet ownership verification system.
Its purpose is simple.
To cryptographically prove that an address or a wallet is actually controlled by the customer using it.
It is what allowed us to opt out of the information-sharing infrastructure emerging around the Travel Rule while remaining compliant.
To that end, before bitcoin can be sent or received, SHAZAM cryptographically verifies that the counterparty wallet is actually controlled by the user.
Users can prove control through message signing, extended public key verification or a proof-of-control mechanism designed specifically for self-hosted bitcoin wallets, commonly known as the Satoshi Test.
Each method has its pros and cons, but the end result is the same.
A strong attestation that the wallet is controlled by the user.
Put simply, SHAZAM, through cryptographic proof, removes the automatic need for Bitaroo to share information about you.
You’re welcome.
SHAZAM ensures self-custody on both sides of transactions, helping verify ownership for withdrawals and helping resolve incoming deposits without defaulting to third-party custodial workflows.
Every Road Has Obstacles
Yes, this means that there are additional steps involved when sending bitcoin to, or receiving bitcoin from, Bitaroo.
At first glance, this can look like friction.
In reality, it is.
But it also reflects a choice.
Verified self-custody over convenience that attracts additional reporting.
Maintaining privacy and security over commercial considerations.
This is the way.
All Roads Lead to Self-Custody
Regulations will change.
Compliance frameworks will evolve.
New reporting obligations will emerge.
That is unlikely to stop.
But none of those changes alter the fundamental promise of Bitcoin.
Bitcoin gives individuals the ability to actually own and control hard money.
Not an IOU from a bank.
Not a currency that can be inflated.
No chain of intermediaries.
Direct ownership.
The ability to send value from anywhere to anywhere, from anyone to anyone.
That capability is extraordinary.
Exchanges were never meant to be long-term custodians.
We are honoured that our users trust us with their bitcoin and we continuously upgrade our systems and defences.
But self-custody was always the way.
It is what Bitcoin is about and it is worth building for.
It is worth fighting for.
It is worth defending.
Bitaroo always believed in self-custody and always encouraged it.
It is ironic that regulation was the force that ultimately pushed Bitaroo from encouraging self-custody to effectively enforcing it, yet here we are.
The Road Ahead
Bitaroo will continue to fight the good fight.
We thank you for your support and look forward to travelling this road together.
The future is bright and orange.
The future is Bitcoin.
