Longtime User Says Verification Requirement Is Driving Them Away
Kraken is facing criticism from some customers over biometric identity checks that can restrict access to crypto transfers until users submit a live facial image and, in some cases, another copy of a government-issued ID.
The issue surfaced in a recent complaint from a longtime Kraken customer who said they were asked to scan a driver’s license and complete a 360-degree facial photo or video before being allowed to move or receive cryptocurrency.
The user said Kraken already held extensive personal information collected through earlier verification, including identity documents, Social Security information, banking details and transaction records.
The additional facial verification became a breaking point.
The customer said they intended to remove their crypto, stocks and cash from Kraken, cancel their paid services and close the account once they regained unrestricted access to their assets.
Kraken Support responded publicly that when additional verification is requested on an account, the process must be completed before the affected features can be used. The support team said it could not bypass the requirement or make an exception.
The exchange does not appear to be requiring an identical biometric check from every customer every time cryptocurrency is deposited or withdrawn.
Instead, Kraken describes the process as a form of step-up authentication that can be triggered when a customer attempts a sensitive action or when the exchange decides stronger identity confirmation is necessary.
Its current support documentation says a liveness check can involve taking a real-time selfie and may sometimes require the customer to photograph a government-issued ID alongside it.
The company says the process is intended to confirm that the person attempting the transaction is the genuine account holder rather than someone who has obtained access to the account or device.
Kraken can also restrict accounts or funding capabilities when it detects potential security problems, suspected malicious activity or transfers involving wallets associated with scams or prohibited activity. Additional identity information may then be required before normal access is restored.
For U.S. customers, facial verification is already part of Kraken’s broader identity framework. Its verification documentation says U.S. residents may be required to provide a face photo in addition to a valid ID, Social Security number or tax identification number and other personal information.
The latest complaints therefore appear to concern repeated or additional verification of customers who have already passed the exchange’s standard know-your-customer checks, rather than biometric verification being introduced for the first time.
Other Kraken users responding to the complaint described separate difficulties involving locked or restricted accounts.
One customer said their account had remained locked while they waited for the company’s security team to review the case, despite repeated attempts to contact support. Another said they had been asked to provide identity documents and a photograph of their face but had struggled to complete the process and obtain assistance.
Those reports are anecdotal and do not establish that Kraken is experiencing a widespread account-locking problem. They do, however, illustrate the frustration that can develop when additional security checks prevent customers from accessing financial products while the review process remains unresolved.
Kraken says most additional verification checks are completed within minutes, although some cases require further review by its support or security teams.
The privacy implications extend beyond whether a user is comfortable taking a selfie.
Kraken defines biometric data as information generated from electronic measurements of biological characteristics, including facial geometry, that can be used to identify an individual.
Under a biometrics policy updated in July, Kraken says the biometric information is processed by third-party identity-verification providers working on its behalf. Those providers are required to permanently delete the biometric data within six months of collection, unless a legal or investigative requirement prevents deletion.
There is an important distinction, however, between the biometric template generated from a facial scan and the original material used during verification.
Kraken says photographs of passports or driver’s licenses, selfies and records of verification outcomes are not treated as biometric data under that retention rule. Those records can be kept for much longer, including for around five years after the customer relationship ends when required by anti-money-laundering and know-your-customer regulations.
The company says its verification providers use encryption and security controls and that it does not sell, lease or trade customers’ biometric data.
For customers objecting to facial verification on principle, however, those safeguards may not resolve the central problem: refusing the check can mean losing access to the function that triggered it.
Security Becomes a Problem When the Customer Has No Alternative
Kraken has a legitimate security argument.
Crypto withdrawals are unusually difficult to reverse. If an attacker gains control of an exchange account and transfers bitcoin to an external wallet, there is no card network capable of reversing the transaction and no receiving bank that can simply return the funds.
Confirming that a real person is present before approving a suspicious withdrawal can therefore prevent a catastrophic account takeover.
Passwords are no longer enough. SMS authentication can be compromised. Email accounts can be hijacked. Even conventional two-factor authentication can fail when attackers obtain session cookies, compromise devices or manipulate users through social engineering.
A live facial check creates another barrier.
The problem is that this stronger security measure changes character when it becomes mandatory after the customer has already deposited assets.
A user opening a new account can review the verification requirements and decide whether they are comfortable providing facial data before transferring money to the platform.
A customer who has held assets at Kraken for years faces a different decision when a new identity check suddenly appears during a withdrawal. At that point, consent becomes much less meaningful.
The choice is effectively: provide the requested information or lose access to the affected feature.
That is why the complaint resonates beyond one unhappy customer.
Financial platforms increasingly use biometrics because the technology solves a genuine problem, but biometrics are fundamentally different from passwords. A password can be changed after a breach. A person cannot replace their face.
Kraken’s six-month deletion policy for generated biometric data is therefore important, but it does not completely eliminate the privacy concern. The selfie and identification records from which the biometric verification was performed can remain available for much longer because financial regulations impose separate recordkeeping obligations.
There is also a broader trade-off between fraud prevention and customer control.
Centralized crypto exchanges have spent years telling users that additional compliance is the price of gaining banking relationships, regulatory licenses and mainstream financial products. As exchanges expand into stocks, payments, cards and other services, their compliance systems increasingly resemble those of conventional financial institutions.
But crypto customers often entered the market precisely because they wanted greater control over their assets.
That creates an uncomfortable contradiction. A customer may legally own bitcoin held through an exchange but still be unable to transfer it until the intermediary is satisfied with another identity check.
Kraken could reduce the friction by giving users more transparency before restrictions occur. Customers should know which actions can trigger biometric verification, whether an alternative verification method is available and what happens if they decline.
Support speed also becomes critical.
An automated security check that takes two minutes is an inconvenience. The same check followed by days or weeks of restricted access can become a serious financial problem, particularly when volatile assets are involved.
Kraken is therefore balancing two risks that pull in opposite directions.
If its verification requirements are too weak, stolen accounts can be emptied. If the requirements become too intrusive or unpredictable, legitimate customers may decide that the security system itself is a reason to leave.
For the customer who raised the latest complaint, that line has already been crossed.
