In short
- The Bitcoin Policy Institute urged the Kentucky Senate to remove Section 33 of HB 380, calling it “technologically impossible” for non-custodial wallets.
- The provision was buried as a floor amendment in a kiosk regulation bill that passed the House of Representatives 85-0 and cleared the Senate within days.
- One expert told Decrypt that hardware wallet providers would likely exit the Kentucky market entirely rather than redesign products in ways that undermine self-control.
A last-minute change requiring hardware wallet providers to help reset users’ credentials, tucked into Kentucky’s sweeping crypto ATM law, is facing mounting backlash, with experts saying it’s a fundamental misunderstanding of how crypto infrastructure works.
Section 33 of House Bill 380added as a last-minute amendment during debate in the House of Representatives, would require hardware wallet providers to provide customers with a mechanism to reset “any password, PIN, seed phrase or other similar information” needed to access a wallet.
“BPI is sending a letter to the Kentucky Senate informing them of the harmfulness of this language,” the group further wrote X.
Hardware wallets are physical devices that store crypto private keys offline and ensure that only the user, not even the manufacturer, can access or recover them.
“This probably indicates a misunderstanding much more than a deliberate attempt at control,” Joe Ciccolo, founder and president of BitAML, told Decrypt.
“Policymakers often struggle with the concept of self-control,” Ciccolo said, noting that “there is no central authority capable of resetting access credentials,” unlike traditional systems where recovery is standard.
BPI described the mandate as “technologically impossible for non-custodial wallets,” noting that requiring a backdoor would Bitcoin‘s fundamental security model and pushes users to centralized administrators who are more vulnerable to hacks and failures.
“Kentucky is suddenly on the verge of banning self-determination. Tell your friends,” wrote Conner Brown, Managing Director at BPI. X.
“Requiring hardware wallet providers to restore or reset credentials would essentially force them to redesign their products in ways that undermine self-management – or exit the market altogether,” Ciccolo said.
“Most non-custodial wallet providers would likely choose not to operate in Kentucky rather than compromise their core security model,” he added, warning of “reduced consumer choice” and “reduced privacy protections.”
“The consumers the bill seeks to protect would lose access to one of the most secure ways to store digital assets,” he said.
In safer ways, Ciccolo noted that “social remediation mechanisms or multi-signature setups” can reduce risk “without introducing centralized control,” adding that “the best protection is to ensure that users understand both the benefits and responsibilities of self-control.”
He also backed BPI’s move, saying that “education is critical” and that where proposals arise from a “knowledge gap”, direct engagement with policymakers “is the most effective way forward”, noting this has “a direct impact on consumers who value financial autonomy and security”.
HB 380 was introduced in the House on January 14, favorably reported by the Banking and Insurance Committee on March 4, and passed by the full House 85-0 on March 13.
The underlying bill regulates virtual currency kiosk operators, establishes licensing requirements, and establishes transaction limits, disclosures and reimbursement rules, provisions that have broad political support and are expected to move the bill quickly through the Senate.
The bill arrived in the Senate on Monday and was referred to the Committee on Committees.
Kentucky’s move follows a broader crackdown on crypto kiosks Connecticut shuts down Bitcoin depository for compliance deficiencies and Minnesota is considering a ban on crypto ATMs.
Daily debriefing Newsletter
Start every day with today’s top news stories, plus original articles, a podcast, videos and more.