By NHI Mgmt Group Editorial TeamBased on SumSub: “Sumsub Partners With Chainlink to Power Cross-Chain Identity for On-Chain Compliance” (June 8, 2026)

TL;DR: Reusable, privacy-preserving KYC credentials across Ethereum, Arbitrum, Avalanche, Polygon and Base are being introduced through SumSub’s partnership with Chainlink, letting users prove claims on-chain without exposing raw personal data while supporting permissioned access and reusable identity across wallets. The bigger issue is that on-chain identity is becoming a governance layer, not just a verification step.


At a glance

What this is: SumSub and Chainlink are positioning cross-chain KYC credentials as reusable, privacy-preserving on-chain identity claims that can support eligibility checks across multiple blockchains.

Why it matters: IAM and governance teams should read this as a shift from one-off verification to reusable identity authority, which changes how access, consent, and data minimisation need to be controlled across ecosystems.


Context

This article is about privacy-preserving KYC credentials that can be reused across blockchain ecosystems without putting raw personal data on-chain. The core identity problem is not just verification, but how a verified claim becomes an access credential that follows the user across wallets, protocols, and chains.

For IAM teams, the important shift is that verification output is no longer a dead-end record. Once a claim can be presented repeatedly across environments, the governance question moves to credential scope, wallet binding, revocation, and who is permitted to trust the resulting assertion.


Key questions

Q: How should security teams govern reusable identity credentials across blockchains?

A: Security teams should treat reusable identity credentials as governed assets with explicit issuance, binding, revocation, and re-authorisation rules. The key is to define where the trust decision lives, how eligibility is rechecked, and how revocation propagates across every chain or protocol that accepts the credential. Without that, portability becomes a governance gap rather than a convenience.

Q: Why do privacy-preserving KYC credentials still need strong lifecycle controls?

A: Privacy-preserving KYC reduces what is exposed, but it does not remove the need to control how long a claim remains valid, who can rely on it, or when it must be withdrawn. If the credential can be reused across wallets or services, lifecycle control becomes the mechanism that keeps a valid claim from becoming permanent access.

Q: What breaks when wallet ownership is not bound to a reusable identity claim?

A: The same credential can be replayed through another wallet, which weakens accountability and can let one verified identity be trusted in the wrong context. Without strong wallet binding, the organisation is no longer governing the person and the proof together. It is only governing a portable assertion.

Q: How do organisations separate KYC verification from on-chain authorisation?

A: By assigning different owners, controls, and decision rules to each step. KYC verifies who the user is or what they are eligible for. Authorisation decides whether that claim is sufficient for a specific asset, protocol, or workflow. If the two are merged, compliance proof is likely to be overtrusted.


Technical breakdown

How cross-chain KYC credentials are issued and reused

The model described here combines an off-chain KYC flow with an on-chain credential issuance step. A user completes verification, proves wallet ownership by signing a message, and then receives a reusable credential that contains verified claims rather than raw identity data. The key architecture point is that the claim becomes portable across wallets and blockchain environments, so the trust decision shifts from one verification event to repeated acceptance of the same credential in different contexts.

Practical implication: treat the credential as a governed identity artefact, not a static proof, and define where it can be replayed.

Why privacy-preserving claims still create governance exposure

Privacy-preserving does not mean governance-free. Even when raw personal data never touches the chain, the system still creates a durable linkage between a verified person and one or more wallets. That linkage introduces lifecycle questions around consent, reuse, permissioned access, and whether an issuer or protocol can trust a claim long after the original verification context has changed. In identity terms, the control plane moves from data disclosure to assertion authority.

Practical implication: define claim validity, revocation, and re-issuance rules before allowing reusable credentials into production workflows.

What cross-chain identity means for permissioned access

Cross-chain identity credentials are effectively turning KYC into an access primitive. Rather than re-running onboarding at every protocol boundary, issuers and applications can check a reusable claim such as age or residency and then allow or deny access. That creates a new IAM boundary in which eligibility, assurance, and wallet ownership must all be evaluated together. If those checks are not aligned, the organisation may end up trusting a transferable claim more than the identity relationship behind it.

Practical implication: map each permissioned asset or workflow to the exact claim, assurance level, and wallet-binding requirement it needs.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Cross-chain KYC is becoming an identity authority layer, not just a verification step. When a verified claim can follow a user across wallets and blockchains, the control surface changes from onboarding to ongoing trust assignment. That means the programme now has to govern assertion reuse, not just proof of identity. Practitioners should treat reusable credentials as a new IAM boundary that needs explicit policy.

Privacy-preserving design does not remove the need for lifecycle governance. The article’s model avoids putting raw personal data on-chain, but it still creates persistent identity linkage and repeated trust decisions. That is a governance problem because the credential can outlive the context in which it was created. The implication is that lifecycle, revocation, and re-authentication rules matter as much as disclosure controls.

Wallet ownership is now part of the identity control, not a side check. The article shows that proving control of a wallet is part of the issuance flow, which makes the wallet itself a governed identity anchor. That matters because a reusable KYC claim without strong wallet binding can be misapplied across environments. Practitioners should evaluate wallet binding as an access control dependency, not a UX detail.

Reusable claims will pressure existing KYC programmes to separate verification from authorisation. Traditional KYC often ends at identity proofing, but cross-chain credentials turn the result into a reusable authorisation input. That collapses the old boundary between customer onboarding and downstream entitlement decisions. The practical takeaway is that teams need clearer ownership between identity, compliance, and protocol-level access governance.

Cross-chain identity creates a new form of trust portability that will not fit legacy IAM assumptions cleanly. IAM models typically assume a stable application boundary, but blockchain ecosystems distribute trust across multiple venues and wallets. The result is a credential that can be valid in one context and overtrusted in another. Practitioners should build policy around context, not just claim content.

What this signals

Reusable identity claims will force IAM programmes to think in terms of assertion governance. A claim that can travel across wallets and blockchains needs explicit scope, expiry, and revocation policy. The practical shift is from verifying a user once to governing where that verification remains trustworthy.

Cross-chain identity also exposes a familiar blind spot in access design. If the organisation cannot say which protocol, wallet, or asset is entitled to trust a specific claim, then the credential is already broader than the policy model supporting it. IAM teams should narrow trust boundaries before reusable credentials become normal.

Wallet binding is becoming a control point, not a convenience feature. A reusable KYC claim is only as strong as the identity relationship behind it, which means wallet ownership, recovery, and revalidation have to be part of the access model. That is especially true when claims are reused across multiple blockchain ecosystems.


For practitioners

  • Define claim acceptance boundaries Specify which chains, wallets, assets, and user populations can accept a reusable KYC credential, and document where a fresh verification step is still required.
  • Bind credentials to wallet control Require explicit proof of wallet ownership and record how that binding will be revalidated if the wallet changes or the user adds another wallet.
  • Separate verification from authorisation Map each downstream access decision to the exact claim it depends on, then keep compliance proof and entitlement logic under different governance owners.
  • Plan revocation and re-issuance rules Decide how reusable credentials will be withdrawn, refreshed, or superseded when user status changes, claims expire, or trust conditions shift across ecosystems.

Key takeaways

  • Reusable KYC credentials shift the governance problem from one-time identity proofing to ongoing control of claim reuse.
  • Privacy-preserving design reduces exposure of raw personal data, but it does not remove lifecycle, wallet-binding, or revocation obligations.
  • IAM teams need to separate verification from authorisation so that a portable claim does not become an uncontrolled access pass.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, and GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-08 — Environment IsolationReusable credentials cross wallet and chain boundaries, which creates isolation and trust-scope issues.
NHI-10 — Human Use of NHIThe article’s wallet-linked KYC flow turns human identity proof into a reusable non-human credential.
Recommendation — Constrain where reusable identity claims can be accepted and revalidated before broad reuse becomes policy debt. Separate human verification from machine-presented claims so downstream access does not overtrust the credential.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is governing which blockchain services may trust a reusable identity assertion.
Recommendation — Map each claim to explicit authorization rules and limit acceptance to the workflows that need it.
NIST SP 800-63SP 800-63C — FederationThe credential functions like a federated assertion that must remain valid across relying parties.
Recommendation — Treat cross-chain claim reuse as a federation problem and define relying-party trust requirements.
GDPRArt.5 — Principles relating to processing of personal dataThe article centres on privacy-preserving handling of identity claims and raw personal data minimisation.
Recommendation — Apply data minimisation and purpose limitation so reusable claims do not exceed the stated compliance need.

Key terms

  • Cross-Chain Identity: Cross-chain identity is a way of letting one verified identity or claim be recognised across multiple blockchain environments. It reduces repeated onboarding, but it also creates governance obligations around issuer trust, revocation, and policy consistency wherever the credential is accepted.
  • Wallet Binding: Wallet binding is the process of linking a verified identity claim to a specific blockchain wallet through proof of ownership. It establishes who can present the credential, but it does not by itself prove ongoing eligibility, so it still needs lifecycle and access governance.
  • Privacy-Preserving KYC: A KYC model that verifies identity or eligibility while avoiding exposure of raw personal data on-chain. The design reduces disclosure risk, but it still requires governance over reuse, revocation, and downstream authorisation.
  • Claim Reuse: The repeated presentation of a previously verified identity statement to multiple relying parties or protocols. For identity governance, reuse changes the control problem from proof collection to managing scope, validity, and acceptable trust boundaries.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org