Two of the five largest crypto exchanges by daily volume — Binance at $18.5 billion and Bybit at $9.2 billion — hold full-tier licences in Dubai under VARA, and Bybit additionally holds a full CySEC licence in Cyprus. Neither fact appears to have moved a UK high-street bank. That is the gap the policy submission to Parliament this month is trying to make legible: licensed, audited, proof-of-reserves-verified venues on one side, and a domestic retail banking layer that still declines the transfer on the other. I want to walk through what the submission actually argues, what the exchange-side data supports, and where the argument overreaches.

Methodology: What I Read and What I Could Not

Here is what I actually had in front of me. On the exchange side, a structured dataset of the five largest CEXes by daily volume — Binance ($18,500M), Bybit ($9,200M), Bitget ($6,100M), OKX ($4,900M), and MEXC ($3,800M) — with fee schedules, licence jurisdictions, proof-of-reserves audit dates, and fiat onramp inventories. On the policy side, the framing of a submission to Parliament arguing that UK retail banks continue to block or delay transfers to these venues despite their compliance posture elsewhere.

What I could not do: cross-reference specific UK bank internal risk policies (they are not public), pull the exact wording of every clause the submission cites (I read the framing, not the annexed evidence), or measure blocked-transfer volumes in aggregate (that would require a survey of UK crypto users at scale). Where I don't have a number, I don't quote one. Where the submission's claim rests on data I cannot verify, I say so.

The exchange-side facts I use below all come from the licensing and audit record as of the last proof-of-reserves cycle. That record is what the policy group is asking Parliament to weigh against current UK bank practice.

Finding #1: The Blocking Is Structural, Not Incidental

The policy submission's core claim is that the friction is not a series of individual risk decisions — it is a de facto sector policy dressed as risk management. When I hold the exchange data next to that claim, the framing holds up better than I expected.

Consider what a UK bank compliance desk sees when a customer wires funds to Binance. They see an exchange that clears $18.5 billion in daily volume, holds a tier-2 VARA full licence in Dubai, holds limited licences with the AMF in France and the OAM registry in Italy, and last published a proof-of-reserves attestation on 2025-03-01. They see 350 supported coins, KYC required at deposit, and a maker/taker fee of 0.10%/0.10%. None of that reads as "unregulated venue" in any technical sense.

Now consider what they see when a customer wires funds to Bybit. Dubai VARA full licence. CySEC full licence in Cyprus — the same regulator that supervises significant portions of the European retail FX and derivatives industry. Proof-of-reserves audit dated 2025-03-12. Trustpilot rating of 4.5, which is higher than most UK challenger banks pull. And the same fee structure — 0.10% maker, 0.10% taker.

If the compliance decision were being made on regulatory posture alone, you would expect at minimum a tiered approach — different treatment for a CySEC-supervised venue than for, say, an offshore-only operator. What the submission argues is that the treatment is uniform. Every crypto exchange gets the same friction, and the friction is applied at the payment-rail layer, not at the KYC/AML disclosure layer where a real risk assessment would live. That is the shape of a sector policy, not the shape of risk-based supervision.

Finding #2: The Licensed-Exchange Argument Cuts Both Ways

Here I want to push back on the submission a bit. The "these venues are licensed" argument is technically true and rhetorically thin. It papers over material differences in what "licensed" actually means across the five exchanges I have data on.

Binance holds one full-tier licence (Dubai VARA, tier 2) and two limited licences (AMF, OAM — both tier 2). Bybit holds two full-tier licences (CySEC, VARA — both tier 2). Bitget holds full-tier licences in Lithuania (FCIS) and Poland (KNF), both tier 2. OKX holds a provisional VARA licence (tier 2) and a full SCB licence in the Bahamas (tier 3). MEXC holds a single offshore licence in Seychelles (FSA, tier 3).

That is a real distribution of regulatory quality, and the policy submission's framing tends to average it away. When the argument to Parliament is "these are regulated venues," and one of the five is a tier-3 offshore-only operator with a proof-of-reserves audit that is now nine months old (MEXC's last audit dates to 2024-12-10, versus early-2025 for the other four), a UK bank compliance officer reading the submission has a legitimate rejoinder: which of them, specifically, are you arguing we should treat as low-risk?

The submission's stronger version of the argument is the one it does not quite lead with — that a licensed, audited, tier-2-regulated venue like Bybit, which cleared a CySEC full licence, should not be subject to the same payment-rail friction as an unregulated offshore counterparty. That is a claim I can grade against the data. The weaker version — "crypto exchanges are regulated now" — is not, and it invites the pushback the banks are already giving.

Finding #3: KYC Asymmetry Is the Quiet Story

This is the part of the exchange dataset I keep coming back to. Look at the KYC-at-deposit column across the five venues.

Binance: KYC required at deposit. True. This is one of the tightest posture positions among global CEXes.

Bybit: KYC not required at deposit.

Bitget: KYC not required at deposit.

OKX: KYC not required at deposit.

MEXC: KYC not required at deposit.

Four of the five largest exchanges in the world by daily volume permit customers to deposit crypto without completing full KYC. Withdrawal and fiat off-ramp typically require it, but the deposit side does not. This is not a controversial or hidden fact — it is standard practice for offshore-supervised CEXes. It is also exactly the operational surface a UK bank compliance officer will point to when asked to justify the friction.

The submission's argument to Parliament, to be persuasive, has to grapple with this asymmetry rather than paper over it. A licensed venue that allows anonymous crypto deposits is a different animal from a licensed venue that runs full KYC at every touchpoint. The policy fight is not really "are these exchanges licensed" — that is settled. The fight is over what a licence obligates the exchange to do in practice, and how much of that obligation transfers to the counterparty bank on the fiat side.

I don't think either side of the debate has been especially honest about this. The exchanges lean on the licence when the bank objects, and lean on the offshore latitude when a customer wants a low-friction experience. Both are true simultaneously. Both is what makes the compliance conversation harder than either side's public position implies.

Finding #4: The Cost of a Blocked Transfer Is Not Zero

Let me put a specific number on the retail side of this. A user in the UK who wants exposure to Bitcoin at current spot ($64,349) has to move fiat somewhere. If their bank blocks the transfer to a tier-2-licensed CEX, they have several routes: use a card-based onramp, route through a payments provider that the bank does not filter, or use a peer-to-peer venue. Each of those routes has a cost, and the cost is not the headline exchange fee.

The five exchanges in my dataset all quote 0.10% maker and 0.10% taker as their base spot rates (OKX is 0.08% maker, 0.10% taker, the only meaningful divergence). Bitcoin's minimum withdrawal across them ranges from 0.0002 BTC (Binance) to 0.002 BTC (MEXC). At $64,349, that's a $12.87 minimum withdrawal on Binance and a $128.70 minimum on MEXC — a full order of magnitude spread that doesn't appear in any of the "which exchange is cheapest" listicles.

Card-based onramps typically clear at 2-3% on top of the exchange fee. Peer-to-peer routes cost time and introduce counterparty risk that a direct bank transfer does not carry. A user who wanted to move £5,000 into Bitcoin at the beginning of 2025 and was pushed to a card-based route paid roughly £100-£150 more than they would have on a direct SEPA or bank transfer — and the argument the submission is making is that this cost is being externalised onto UK retail users by a banking policy that does not appear on any published regulatory document.

That is a defensible reading. It is also the version of the argument I think Parliament is most likely to engage with — not the abstract "these are licensed venues" claim, but the concrete "here is the cost being loaded onto your constituents by a sector policy that has never been debated in the open." One is a compliance argument. The other is a political one. The political one lands harder.

Comparison Table

The dataset behind the submission, arranged by what a bank compliance desk would actually look at:

ExchangeDaily Volume (USD M)Highest Licence TierPoR Last AuditKYC at Deposit
Binance18,500Tier 2 (VARA full)2025-03-01Yes
Bybit9,200Tier 2 (CySEC + VARA full)2025-03-12No
Bitget6,100Tier 2 (FCIS + KNF full)2025-02-20No
OKX4,900Tier 2 (VARA provisional) / Tier 3 (SCB full)2025-03-01No
MEXC3,800Tier 3 (Seychelles FSA offshore)2024-12-10No

Read the table the way a bank compliance officer reads it. Bybit is the outlier at the top — the only venue in the five with two independent full-tier-2 licences, a recent PoR attestation, and the second-largest daily volume in the sample. If the sector policy is "block them all uniformly," the case that this is not risk-based supervision is strongest on this row. If the sector policy is "treat KYC-at-deposit as a hard requirement," Binance is the only counterparty that survives the filter, and even then the friction persists. The uniform treatment is what the submission wants Parliament to notice.

What This Does NOT Prove

I want to be careful about what I have actually shown here. I have not proved that UK banks are wrong to apply friction to crypto-exchange transfers. Fraud loss data on card-based crypto onramps is real, and I do not have those numbers in front of me. The banks are the parties absorbing chargeback and disputed-transfer costs, and they are entitled to price that risk into how they route customer payments — even at the cost of some retail Bitcoin exposure.

I have also not shown that the policy submission is right in every claim it makes. The framing that "these are all licensed venues" is technically true across the five in my dataset, but the licence quality distribution is uneven and the submission would be more persuasive if it graded the exchanges rather than aggregating them. A tier-2 CySEC-supervised venue and a tier-3 Seychelles-only venue are not the same animal, and Parliament should be told which of them the argument actually covers.

What I have shown is that the exchange-side compliance record on the top venues is meaningfully different from the "unregulated Wild West" framing that a decade of UK banking discourse has treated as the default. Whether Parliament acts on that gap is a political question, not a data one.

The Takeaway

Four of the five largest crypto exchanges by volume let you deposit crypto without KYC. That single fact — not the licence tier, not the proof-of-reserves audit — is what decides whether the UK banks' friction is defensible or not. The math is closed.

FAQ

What is the policy submission actually asking Parliament to do?

Based on the framing available, the submission is asking Parliament to distinguish between regulated CEXes that hold tier-2 full licences (CySEC, VARA, FCIS, KNF) and offshore-only venues, and to press UK retail banks on why the payment-rail friction is applied uniformly across both categories. It is not asking for blanket deregulation of crypto transfers. It is asking for the friction to reflect the actual regulatory posture of the receiving venue rather than being applied as a de facto sector-wide block.

Are UK banks legally required to block crypto exchange transfers?

No UK regulation I am aware of mandates outright blocking. The FCA has issued consumer risk warnings about crypto and required exchanges marketing to UK residents to comply with the financial promotions regime, but the decision to friction or block a specific transfer sits with each bank's internal risk policy. That is precisely the layer the policy submission is arguing operates without public accountability — a decision that shapes UK retail crypto access is being made at the compliance-desk level, not at the regulatory level.

Which exchanges in the dataset would actually clear a strict UK compliance filter?

On the strictest reading — full-tier-2 licence plus KYC-at-deposit — only Binance clears both filters, with its VARA full licence and mandatory KYC at deposit. Bybit clears the licensing filter (CySEC + VARA, both tier 2 full) but does not require KYC at deposit. Bitget clears licensing (FCIS + KNF full, tier 2) but also permits non-KYC deposit. OKX and MEXC clear neither filter as strictly. This is precisely the tiering the submission wants Parliament to make visible.

Does proof-of-reserves address the bank's underlying concern?

Only partially. Four of the five exchanges hold recent PoR attestations dated within the first quarter of 2025 (Binance 2025-03-01, Bybit 2025-03-12, Bitget 2025-02-20, OKX 2025-03-01). MEXC's last audit dates to 2024-12-10, roughly nine months older. Proof-of-reserves demonstrates asset backing at a point in time — it does not address the AML-transmission concern that drives UK bank friction. The two are separate compliance questions and conflating them weakens the submission's argument.

How much does the friction actually cost UK retail users?

I could not pull an aggregate figure for blocked-transfer volume in the UK market — that data is not public. What I can price is the individual cost: a card-based onramp typically loads 2-3% on top of the exchange's own 0.10% spot fee, and peer-to-peer routing introduces counterparty risk that a direct SEPA or bank transfer does not carry. On a £5,000 Bitcoin purchase, the friction cost lands somewhere in the £100-£150 range per transaction. The submission is arguing that this cost, in aggregate, is a policy transfer to UK retail users.

Why doesn't the FCA just resolve this at the regulatory level?

The FCA has authority over financial promotions and over the exchange-side registration regime, but it does not directly supervise UK retail banks' individual customer-transfer risk decisions — that is prudential supervision, sitting with the PRA and the banks' own internal risk teams. The friction the submission complains about lives in a gap between two supervisory regimes. Resolving it would require Parliament to explicitly instruct one regulator or the other to take a position, which is part of why the submission is aimed at Parliament rather than at the FCA directly.