Kentucky House Bill 380, introduced by Representatives Aaron Thompson and Tom Smith, includes a provision requiring hardware wallet manufacturers to provide mechanisms for users to recover seed phrases and private keys—a requirement that industry experts say is technically impossible and risks creating security vulnerabilities.
The Bitcoin Policy Institute and other crypto advocates argue the rule contradicts how non-custodial wallets are designed to function, while lawmakers frame it as consumer protection. The bill was amended late in the legislative process, limiting technical consultation.
Kentucky crypto bill proposes mandatory wallet recovery mechanisms
At the center of the controversy is a clause in the Kentucky crypto bill requiring wallet providers to assist users in recovering access credentials. According to the bill’s language, manufacturers “shall provide a mechanism for and assist any person who owns a hardware wallet” in resetting a “password, PIN, seed phrase, or other similar information.”
This provision effectively mandates that companies design systems capable of restoring access to wwallets something that challenges the foundational design of non-custodial crypto storage. The Kentucky crypto bill also introduces identity verification requirements for users requesting such recovery services, adding another layer of compliance for providers.
The timing of the amendment has raised additional questions, as it was introduced late in the legislative process, limiting broader technical consultation. Observers note that the Kentucky crypto bill reflects a growing effort by regulators to balance consumer protection with emerging digital asset technologies.
Industry experts warn of technical and security risks
The Bitcoin Policy Institute has been among the most vocal critics of the Kentucky crypto bill, stating that the requirement is incompatible with how non-custodial wallets operate.
“This is technologically impossible for non custodial wallets,” — Bitcoin Policy Institute, in a statement.
The group further emphasized that no manufacturer can access or recover a user’s seed phrase without fundamentally redesigning the architecture of such wallets. By design, non-custodial wallets ensure that only the user has control over private keys, a principle widely regarded as central to cryptocurrency ownership.
Critics argue that enforcing such a requirement under the Kentucky crypto bill could introduce vulnerabilities similar to a “backdoor,” potentially exposing users to hacking or unauthorized access. It may also push users toward custodial solutions, where third parties manage private keys, thereby reducing individual control.
The organization added:
“Kentucky legislators should be protecting their constituents’ right to secure their own property. We urge the Senate to strip this provision before the bill reaches a vote,” — Bitcoin Policy Institute.
Kentucky crypto bill reignites self-custody debate
The controversy surrounding the Kentucky crypto bill has revived broader discussions about self-custody in the crypto ecosystem. Advocates argue that self-custody the ability for individuals to control their own private keys is a fundamental principle of digital asset ownership.
Some regulators have expressed support for this position. Paul Atkins noted that he is “in favor” of self-custody options, particularly in situations where intermediaries create financial or operational burdens for users.
At the same time, policymakers in other jurisdictions have taken steps to protect these rights. For instance, Avelino Valencia introduced amendments to a separate bill to explicitly safeguard self-custody protections.
However, regulators have also highlighted the risks associated with self-managed wallets. The U.S. Securities and Exchange Commission previously warned that losing a private key results in permanent loss of access to funds, while custodial services carry risks such as hacks or insolvency.
These contrasting pconsumer protection and technological integrity.
Balancing regulation and innovation
The Kentucky crypto bill reflects a broader trend of increasing state-level involvement in crypto regulation across the United States. While policymakers aim to address user protection concerns, industry stakeholders caution that poorly designed requirements could have unintended consequences.
For hardware wallet manufacturers, compliance with the Kentucky crypto bill could require significant redesigns or even render certain products unviable within the state. For users, the implications are equally significant, potentially affecting how securely they can store and access their digital assets.
As debate continues, the outcome of the Kentucky crypto bill may set an important precedent for how other jurisdictions approach similar issues. Whether the controversial provision remains or is removed could shape the future of self-custody rights and wallet design standards in the broader crypto ecosystem.