SEC Commissioner Hester Peirce used one of her final public addresses to deliver a pointed critique of Know Your Customer regulations, calling on regulators to dismantle what she described as a surveillance "panopticon" that puts ordinary citizens at risk.
A Parting Warning on Surveillance
Peirce, whose term as a commissioner is drawing to a close, argued that the vast troves of personal information collected under KYC rules do more harm than good. Rather than protecting consumers, she contended, these "data haystacks" expose them to real dangers when the information is inevitably breached.
The commissioner framed current identity-verification requirements as a mass surveillance apparatus, borrowing the concept of the panopticon—a prison design in which inmates can be watched at all times without knowing when. In her telling, mandatory data collection subjects law-abiding people to constant monitoring while creating irresistible targets for criminals.
"The very systems built to protect people are the ones leaving them most exposed."
The Real-World Cost of Data Leaks
Peirce pointed to recent breaches of crypto customer records as evidence of the threat. When KYC databases are compromised, the leaked details can be used for phishing campaigns and, more alarmingly, to identify and physically target individuals known to hold significant crypto assets.
The crypto industry has seen a rise in so-called "wrench attacks," where criminals kidnap or assault people believed to control valuable digital holdings. Peirce suggested that the concentration of sensitive financial data in centralized systems amplifies exactly these kinds of risks.
Among the concerns she raised:
- Leaked personal data fueling targeted phishing schemes
- Physical threats against identifiable crypto holders
- Centralized databases serving as high-value targets for hackers
A Case for Privacy Technology
As an alternative, Peirce highlighted privacy-preserving tools such as zero-knowledge proofs, which allow users to verify facts about themselves—such as meeting a regulatory requirement—without surrendering the underlying personal data. Such approaches, she argued, could satisfy compliance goals while shrinking the honeypots that attract bad actors.
Peirce, long viewed as one of the SEC's most crypto-friendly voices, has consistently pushed for lighter-touch oversight of digital assets. Her closing remarks reflect a broader theme of her tenure: that regulation should not come
