Privacy Coins vs Regulators: The Battle for Anonymous Ledgers
- One design choice drives nearly every regulatory outcome: whether privacy is mandatory, as with Monero, or optional, as with Zcash.
- MiCA itself does not ban privacy coins. The binding pressure comes from the accompanying AMLR, which phases in a custodial ban for licensed providers by 2027.
- Almost nowhere has banned ownership. Restrictions target intermediaries, but because most people access assets through intermediaries, the practical effect resembles a ban.
- For institutions, custody availability and banking relationships are the real constraints, and both move faster than formal regulation.
- The supervisory case and the privacy case are each internally coherent, and serious institutions should understand both rather than dismiss either.
- Demand for financial privacy has proven fairly inelastic to venue availability, which reveals a lot about who the marginal buyer now is.
- The pivotal open question is institutional, not technical: whether regulators will ever accept cryptographic proof of compliance in place of raw transaction data.
Why This Is a Classification Problem, Not an Ideological One
Consider the compliance officer who now has to write a one line policy on Monero before the next board meeting. For that person, privacy coins are not a moral debate. They are a risk classification question with an unusually short decision window, because the regulatory ground is shifting month by month rather than year by year. For regulators, the same assets pose a different question: whether transaction monitoring obligations can meaningfully be applied to instruments designed specifically to defeat transaction monitoring.
This analysis works through what the rules actually say, how Monero and Zcash diverge in regulatory treatment, what the delisting data reveals, and which unresolved questions sit ahead of the 2027 deadline. Throughout, the aim is to give a treasury team or compliance officer something they can act on, not a slogan they can repeat.
The Distinction That Drives Everything
Privacy coins are not a single category, and treating them as one is the first mistake institutions make. The regulatory outcomes diverge sharply depending on a single design choice: whether privacy is mandatory or optional.
Monero and Zcash Took Opposite Paths
Monero applies privacy by default to every transaction. Ring signatures obscure the sender, stealth addresses obscure the recipient, and confidential transactions obscure the amount. There is no transparent mode, because the protocol simply does not offer one. Zcash, by contrast, uses zk-SNARKs to enable shielded transactions, but shielding is optional. The network supports transparent addresses that behave much like Bitcoin addresses, fully visible on a public ledger, and users choose per transaction whether to shield.
Why That Difference Decides Everything Else
That single difference determines almost everything about how the two assets are treated. A regulated exchange operating under FATF travel rule guidance must be able to demonstrate that it can monitor and report on transaction data.
With Monero, that demonstration is impossible by construction, because the data is hidden by default and cannot be revealed. Compliance teams that refuse to list it are not being obstructive; they are being asked to certify something the protocol makes unverifiable. With Zcash, an exchange can restrict itself to transparent addresses, refuse shielded deposits, and produce the same audit trail it produces for Bitcoin. That gives compliance a defensible, documentable argument, even if it is not a complete one.
The Spectrum Behind the Binary
Framing the market as Monero versus Zcash is a useful simplification, but the category is really a spectrum, and where a coin sits on it predicts its regulatory fate more reliably than its name or its market capitalization. At the mandatory end sits Monero, joined by the Mimblewimble coins Grin and Beam, which conceal amounts and structure by default and, in Grin’s case, dispense with conventional addresses altogether. These assets share Monero’s structural problem exactly: there is no compliant mode to offer a supervisor, because none was ever built.
In the middle sit the optional privacy designs. Firo, formerly Zcoin, lets users burn and redeem coins through its Lelantus Spark protocol, shedding transaction history on demand, while Zcash’s shielded pool is the best known example of privacy a user switches on rather than inherits. Further along again is Dash, which many analysts no longer treat as a privacy coin at all. Its PrivateSend feature is optional CoinJoin mixing layered on an otherwise transparent chain, closer to Bitcoin with a tumbler attached than to anything Monero does.
A different axis entirely is occupied by Secret Network, whose value proposition is private computation rather than private payment. Its encrypted smart contracts aim at confidential decentralised applications, which raises questions that anti money laundering frameworks written for payments were never designed to answer.
The Privacy Delisting Wave
The delisting wave has not respected these distinctions. When exchanges cut privacy exposure, they decided to clear the whole shelf at once. Gate.io’s December 2024 phase-out swept up Monero, Dash, Zcash, Horizen and Verge together, and earlier compliance-driven removals bundled Decred and Firo alongside them.
For an institution, the lesson is that market infrastructure often classifies by label and category risk even where the underlying designs, and therefore the actual compliance arguments, differ sharply. Your internal policy can afford the nuance; the exchange that has just delisted your custody venue will not.
The Privacy Coin Regulatory Landscape in 2026
| Jurisdiction | Legal to hold | Exchange availability | Key instrument | Direction of travel |
| European Union | Yes | Narrowing sharply | AMLR alongside MiCA | Custodial ban on anonymity enhancing assets phasing in by 2027 |
| United States | Yes | Very limited on regulated venues | BSA obligations, FinCEN guidance | Pressure via banking and licensing rather than direct prohibition |
| Japan | Restricted | Effectively none | FSA exchange rules | Long standing prohibition on listing, unchanged |
| South Korea | Restricted | Effectively none | Real name banking rules | Sustained exclusion from licensed venues |
| United Kingdom | Yes | Limited | FCA registration regime | Compliance burden discourages listing |
| Switzerland and UAE | Yes | Case by case | Local VASP frameworks | More permissive, subject to enhanced due diligence |
Two patterns jump out. First, almost nowhere has actually banned ownership, since the restrictions target intermediaries rather than individuals. Second, and this is the part institutions underestimate, the practical effect of intermediary restrictions closely resembles a ban, because most people and firms access these assets through intermediaries in the first place. Legality and accessibility have quietly come apart.
The Rule Beneath the Rules: Fatf and the Travel Rule
Behind every national measure in the table above sits one international standard. The Financial Action Task Force’s Recommendation 16, the so-called travel rule, requires virtual asset service providers to collect and pass on identifying information about the originator and beneficiary of a transfer, mirroring an obligation that has governed bank wires for decades. FATF has separately flagged anonymity enhancing coins as a category warranting heightened scrutiny. The two positions combine into a simple bind: a provider cannot transmit originator and beneficiary data for an asset engineered to conceal exactly that, so listing such an asset and satisfying the travel rule are close to mutually exclusive.
This is why delisting behaviour looks coordinated without any single regulator ordering it. FATF standards are not themselves law, but member jurisdictions implement them, and exchanges operating across borders tend to adopt the strictest applicable standard globally rather than maintain a patchwork. The pattern is visible in the numbers: the count of exchanges that had removed privacy coins rose from roughly 51 in 2023 to more than 70 by late 2025, with pressure clustered in the European Union, the United Arab Emirates and parts of Asia. For an institution, the travel rule is the mechanism that turns a soft international recommendation into a hard commercial fact, and it consistently moves ahead of formal national legislation.
How MiCA and AMLR Actually Work Here
One point deserves precision, because it is widely misreported. MiCA itself does not explicitly ban privacy coins. The binding pressure comes from the Anti Money Laundering Regulation that accompanies MiCA, which imposes obligations on custodians, payment processors and banks regarding anonymity enhancing assets, with a custodial ban phasing in by 2027. The mechanism is indirect but effective: rather than prohibiting the asset, the rule makes it unworkable for licensed entities to hold or service it.
Why the Pressure Arrives Before the Deadline
For an institution, the consequences arrive earlier than the 2027 date suggests. Custody becomes the first constraint, because regulated custodians are withdrawing support ahead of the deadline rather than at it, and an institution that cannot obtain qualified custody cannot hold the asset regardless of what the rule technically permits. Fiat off ramps close next, as banks decline to process flows connected to privacy assets, which renders any remaining exchange listing academic. Finally, audit and reporting obligations do not scale down with position size, so a fund holding even a small privacy coin position still carries the full compliance overhead. That disproportion pushes rational allocators toward zero well before the formal cutoff.
Beyond Coins: Mixers, Protocols and the Developer Question
Privacy is not only a property of coins. It is increasingly delivered by protocols that sit on top of transparent chains, and this is where the most consequential legal fights of the past two years have played out. Mixers such as Tornado Cash pool and re-emit funds to break the visible chain of custody on Ethereum, achieving through software what Monero achieves through protocol design. Regulators treated the distinction as immaterial, and the results reshaped the landscape for everyone building or holding privacy technology.
The sequence is worth setting out precisely, because it is widely misremembered. In August 2022 the US Treasury’s OFAC added Tornado Cash to its sanctions list, an unprecedented step against autonomous code rather than against a person or a company. In November 2024, in Van Loon v. Department of the Treasury, the Fifth Circuit held that Tornado Cash’s immutable smart contracts are not the “property” of any foreign national, because no one controls them once deployed, and ruled that OFAC had exceeded its statutory authority. In March 2025 OFAC removed Tornado Cash from the sanctions list, though it kept the individual developer Roman Semenov designated.
The Criminal Shadow Behind Privacy Coins
The criminal thread runs separately and remains live. In August 2025 a New York jury convicted co-founder Roman Storm of conspiracy to operate an unlicensed money transmitting business, while deadlocking on the graver money laundering and sanctions counts, producing a partial mistrial. In March 2026 prosecutors signalled they would retry the two unresolved counts, with proceedings slated for late 2026, leaving the central question unsettled: whether writing and publishing privacy software can expose its author to criminal liability for how strangers later use it.
For institutions the practical takeaway is sharper than the constitutional drama suggests. The sanctions relief applies to the tool, not necessarily to the people around it, and the money transmitting conviction stands regardless of it. Any privacy service that can be characterised as receiving and forwarding value invites the same theory of liability, whatever its decentralisation claims. Treasury teams assessing exposure to privacy protocols, not merely to privacy coins, should assume that “we only wrote code” is not, on current US precedent, a complete answer.
The Delisting Record of Monero
The market data through 2026 points to more than 70 delistings affecting Monero since 2024, with pressure strongest in Europe and parts of Asia. The figure below shows how that pressure tracks directly with asset design rather than with any single regulator’s whim.

Here is an important nuance that complicates the simple story. Delisting has not correlated cleanly with price collapse. Privacy tokens outperformed through 2025, and researchers expected that strength to continue into 2026 despite the regulatory headwinds. In other words, demand for financial privacy has proven fairly inelastic to the availability of regulated venues. That resilience tells you something meaningful about who the marginal buyer has become, and it is a detail institutions should not overlook when they model liquidity risk.
The Zcash Reversal in 2025 and 2026
The point above, that price did not follow the delistings, understates what happened next. Beginning in September 2025, Zcash staged a rally variously reported at several hundred per cent, and by mid 2026 it had, on some measures, overtaken Monero as the largest privacy coin by market capitalisation. Price alone would be easy to dismiss as speculation, but a structural metric moved alongside it: the share of ZEC held in shielded addresses climbed from roughly 8 per cent in early 2024 to above 30 per cent by May 2026. The privacy features were being used, in other words, not merely traded around.
The institutional plumbing shifted too. Grayscale filed to convert its Zcash Trust into a US-listed spot ETF, the first such filing for a privacy asset, and Robinhood added ZEC for eligible users, restoring a mainstream retail on-ramp. Commentators began describing a “privacy is normal” narrative, in which selective disclosure and corporate confidentiality reframe privacy as a compliance-compatible feature rather than an evasion tool.
Two cautions keep this from overturning the article’s thesis. First, the reversal is concentrated in the optional-privacy design; the mandatory-privacy squeeze on Monero has not eased, which is exactly what a design-determines-outcome argument predicts. Second, a regulated ETF wrapper and a self-custodied shielded transaction are different products serving different demand, and the former does nothing to widen custodial access to the underlying asset for the licensed European entities facing the 2027 deadline. The Zcash reversal is best read not as regulators relenting, but as capital routing around them toward the one privacy design that can still present a compliance story.
The Regulator’s Case on Privacy Coins
The supervisory position is coherent, and it deserves to be presented on its own terms rather than as a mere obstacle. Anti money laundering frameworks depend on financial intermediaries being able to identify counterparties, monitor patterns and report suspicious activity. That architecture has been built over decades and now underpins sanctions enforcement, terrorist financing controls and tax administration alike.
Why Supervisors See a Hole
From that vantage point, an asset that renders counterparty identification technically impossible does not create a small gap in the architecture. It creates a hole through which the entire architecture can be bypassed. Permitting regulated institutions to service such an asset would mean accepting an unmonitored channel inside a monitored system. Sanctions enforcement sharpens the concern further, because effectiveness there depends on the ability to trace and freeze flows, and an untraceable settlement asset is not a neutral technology in that context. Regulators also note, fairly, that they are not objecting to privacy as such. Bank transfers are private from the public while remaining visible to supervisors, so the real objection is to privacy that extends to the supervisor, not privacy that extends to competitors or neighbours.
The Counterargument by Privacy Advocates
Privacy advocates make a case that is equally coherent, and institutions assessing this space should weigh it seriously. Transparent ledgers create a permanent, public, searchable record of every transaction a person or company ever makes. That is not the status quo being preserved; it is a substantial reduction in financial privacy compared with cash, and arguably compared with the banking system itself.
For commercial entities, the concern is concrete rather than abstract. A company paying suppliers on a transparent chain exposes its supplier relationships, payment terms and volumes to competitors, and a trading firm exposes its positions. Privacy technology addresses a legitimate commercial need, and that need is real whatever the illicit uses may be. Advocates also point to the empirical record, noting that analyses of illicit crypto activity have consistently found the large majority occurs on transparent chains, largely because liquidity and usability matter more to criminals than theoretical untraceability. If that holds, restrictions on privacy coins impose real costs on legitimate users while displacing only a small share of illicit volume.
The Technical Middle Path
There is a technical argument layered on top. Zero knowledge proofs can demonstrate compliance without revealing underlying data, so a user could prove that funds did not originate from a sanctioned address without disclosing the entire transaction graph. Selective disclosure, viewing keys and proof of innocence schemes all point toward a middle path. Whether supervisors will accept cryptographic attestation in place of raw data access is the genuinely open question, and it is largely institutional rather than technical.
Institutions and Privacy Coins
Analysis is only useful if it converts into policy. For a treasury team, fund or corporate assessing exposure, five practical points carry the most weight.
- First, classify by design rather than by label, because mandatory privacy assets and optional privacy assets face materially different regulatory paths and your policy should distinguish them.
- Second, map custody before allocation, since custody availability is the binding constraint and it moves faster than regulation itself.
- Third, watch the banking layer, because fiat off ramp availability is the earliest reliable indicator of where an asset is heading commercially and it leads formal action by a wide margin.
- Fourth, assume the 2027 EU deadline arrives early in practice, since firms de risk ahead of deadlines rather than on them.
- Fifth, distinguish legality from accessibility, because holding remains legal in most jurisdictions yet that fact offers little comfort when no regulated venue will trade the asset and no bank will process the proceeds.
How Will Privacy Coins Be Regulated?
Looking ahead, the situation is likely to settle into one of three broad outcomes, and understanding each helps an institution plan for more than the base case.
Separation, Compliance Layer, or Absorption
The first outcome is full separation, in which privacy assets move entirely outside the regulated perimeter, trading on decentralised venues and peer to peer markets. Liquidity fragments, spreads widen, and institutional participation falls to zero, while retail and ideological demand persists. This is the current trajectory.
The second outcome is a compliance layer, in which selective disclosure and viewing key infrastructure matures enough that supervisors accept cryptographic attestation as sufficient, returning optional privacy assets to regulated venues under conditions while mandatory privacy assets stay excluded. This requires a shift in supervisory posture that has not yet appeared.
The third outcome is base layer migration, in which privacy technology is absorbed into mainstream chains as an optional feature rather than a separate asset class, dissolving the category and reframing the regulatory question around transaction types rather than tokens.
Both the second and third outcomes hinge on regulators accepting a proof based rather than data based model of compliance, which makes institutional willingness, not cryptographic capability, the pivotal variable.
Frequently Asked Questions (FAQ)
Are privacy coins illegal? +
In most jurisdictions, holding and using privacy coins for legitimate purposes is legal. What is illegal is using them to launder money, evade sanctions or finance criminal activity. Restrictions generally target exchanges and custodians rather than individual ownership.
Does MiCA ban privacy coins? +
MiCA does not explicitly ban them. The accompanying Anti Money Laundering Regulation imposes a custodial ban on anonymity enhancing assets for licensed providers, phasing in by 2027.
Why is Monero delisted more often than Zcash? +
Monero applies privacy to every transaction by default, which makes transaction monitoring impossible and prevents exchanges from demonstrating compliance. Zcash offers a transparent layer that gives exchanges a documentable compliance position.
How many exchanges have delisted Monero? +
Market data used in 2026 roundups points to 70 or more delistings since 2024, with the strongest pressure in Europe and parts of Asia.
Can institutions still gain privacy coin exposure? +
Access is narrowing quickly. The binding constraints are qualified custody and banking relationships rather than the legality of the asset itself.
What happened with Tornado Cash? +
A US appeals court found in late 2024 that OFAC could not sanction Tornado Cash's autonomous smart contracts, and the tool was removed from the sanctions list in March 2025. Separately, co-founder Roman Storm was convicted in August 2025 of operating an unlicensed money transmitting business, with a retrial on the unresolved counts expected in late 2026. The coin question and the developer question are moving in opposite directions.
Why is Zcash rising while other privacy coins struggle? +
Zcash offers optional privacy, so it can present a compliance story that mandatory-privacy coins cannot. A price rally from late 2025, real growth in shielded-pool usage, a Grayscale spot ETF filing and a Robinhood listing pulled institutional and retail attention back to it, even as pressure on Monero continued.