Compliance Is About Outcomes, Not Architecture: Why We Wrote to OFAC & FinCEN

Avatar of the content author
Sign up now so you never miss an update
contributors
Avatar of the content author
Midnight
By Dr. Saj Khoshroo, Chief Legal Officer, Dr. Ben Beckmann, Chief Technology Advisor, Elkan Adler, Senior Legal Counsel, Mahesh Sashital, Solutions Manager, Cliff Koutsky, Public Sector Business Development, Midnight Foundation

Last month, the Midnight Foundation filed a formal comment with the US Treasury Department's Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC) on their joint proposed rule for permitted payment stablecoin issuers under the GENIUS Act. You can read our full submission on regulations.gov.

We wanted to share why we filed, what we said, and why we think this rulemaking matters for the future of privacy-preserving finance in the United States — not just for Midnight, but for any institution that needs both regulatory accountability and financial confidentiality.

What the proposed rule does well

First, the good news. The GENIUS Act and the proposed rule represent serious, thoughtful work. Treasury chose a risk-based, effectiveness-focused approach rather than dictating specific technical architectures. That's the right instinct. Rules that mandate particular technology tend to freeze innovation in place and age badly. Rules that measure outcomes leave room for better tools to emerge.

We support the rule's objectives without reservation: protect the U.S. financial system from illicit finance, and encourage responsible innovation in payment stablecoins. Those goals aren't in tension with what we build. They're the reason we build it.

The gap we're worried about

Here's the problem. No single line in the proposed rule bans privacy-enhancing stablecoins. But across the document, the compliance mechanisms it describes quietly assume one specific architecture: a fully transparent public ledger where every transaction — sender, recipient, amount, balance — is visible to anyone who cares to look.

The rule leans on blockchain analytics, public on-chain data, and observable secondary-market activity as the primary ways an issuer demonstrates it is meeting its obligations. That describes how stablecoins have worked in the past on networks like Ethereum, Solana, and Tron. It does not describe other ways compliant stablecoins can work.

The risk isn't a prohibition. It's an interpretive default. If the final rule's compliance tests are defined by reference to public-chain visibility — without ever acknowledging that newer architectures achieve the same results — then in practice it could become impossible to demonstrate compliance without exposing all transaction data publicly. Examiners, exchanges, and intermediaries may then treat the latest generation of privacy-enhancing chains as inherently higher-risk, even when they aren't. An entire category of compliant and in many situations, superior technology runs the risk of being squeezed out by broad and indirect implications.

Regulatory visibility is not the same as public transparency

This is the distinction at the heart of our comment, and we think it's the most important idea to take away.

The laudable policy goal is regulatory visibility (authorized parties being able to see transaction data); not public transparency (everyone being able to see it).

Public transparency is an accidental side effect of how legacy blockchains happen to be built, and it carries real costs:

  • Surveillance of lawful activity. Pay your property taxes with a transparent stablecoin and your wallet is permanently, publicly linked to that payment. Data brokers and hostile actors can aggregate this at scale.
  • Competitive exposure. No enterprise wants its payroll, treasury moves, or supplier payments visible to competitors. That's incompatible with how the existing financial system works, and it's a major barrier to institutional adoption.
  • Privacy-law tension. For state-chartered banks exploring tokenized deposits and Bank Secrecy Act (BSA) standards, full public visibility can collide with confidentiality obligations under the Gramm-Leach-Bliley Act. A rule that implicitly requires transparent public-chain deployment puts tension between bank issuers and necessary federal privacy laws.
  • National security risk. Public chains increase the attack surface, letting foreign adversaries map the financial flows of US citizens and critical-infrastructure operators. Transparency-by-default turns into a systemic intelligence vulnerability.

And here's the irony: transparent-chain monitoring is already being evaded. The rule's own evidence describes how operators of the sanctioned Garantex exchange rotated their wallets daily to dodge analytics tools. If your compliance framework depends on public observability that sophisticated bad actors already defeat, you're relying on the weakest available control.

Selective disclosure meets every obligation in the rule

Privacy-enhancing chains using selective disclosure are not "privacy coins" in the popular sense. They aren't designed to hide activity from regulators. They're designed to restore control over data to the data proprietor or issuer and shield it from the general public while preserving — and often strengthening — compliance and regulatory access.

The mechanism is cryptographic. The issuer holds viewing keys that give it full visibility into transactions involving its stablecoin. Sanctions screening can be enforced with zero-knowledge proofs: the token contract can require every transfer to prove neither party appears in a sanctions set, rejecting non-compliant transactions before settlement. That's pre-settlement prevention, which is architecturally stronger than spotting a violation after it's already been written to an immutable ledger.

Walk through the obligations one at a time and selective disclosure holds up on every one:

  • AML/CFT monitoring: the issuer sees identical or richer transaction data via viewing keys.
  • Block, freeze, reject: the same smart-contract controls work on a shielded chain. Circle's ability to freeze USDC comes from its token contract, not from Ethereum's transparency — and that capability transfers directly.
  • Lawful orders: the issuer can freeze, seize, or burn tokens and hand law enforcement a cryptographically authenticated, tamper-evident record — stronger evidence than a screenshot of a block explorer.
  • Sanctions compliance: ZK proofs block prohibited transfers pre-settlement instead of catching them after the fact.
  • Travel Rule and recordkeeping: these run off-chain, so the ledger's privacy architecture is irrelevant. It works the same way.

On a transparent chain, the issuer sees exactly what everyone else sees — including the illicit actors designing their behavior to evade detection. On a selective-disclosure chain, the issuer sees what others can't. That information asymmetry favors compliance, not crime.

What we actually asked for

Our comment is not a request to weaken any rule. Rather, we asked the Treasury to make explicit what the proposed rule already implies: that compliance is measured by what an issuer can do, not by what the public can see.

Concretely, we proposed eight targeted clarifications, including:

  • Define "technical capability to block, freeze, and reject" by compliance outcome, not by blockchain architecture — explicitly including cryptographic enforcement.
  • Acknowledge that ZK-based pre-settlement enforcement is an effective sanctions compliance program under OFAC's rules.
  • Specify that a PPSI's choice of blockchain is not itself a customer-due-diligence risk factor where equivalent regulatory visibility is demonstrated.
  • Confirm that issuer-accessible data via viewing keys satisfies any future secondary-market monitoring obligations.
  • Validate the fact that cryptographically authenticated records may satisfy lawful-order compliance without requiring public verifiability.
  • Reiterate that Travel Rule compliance is judged on off-chain data transmission, not on-chain visibility.
  • Use technology-neutral language in the preamble, such as auditable DLT (distributed ledger technology), or clarifying that "public ledger" refers to verifiability, not public visibility of transaction contents.
  • Ensure state-level regimes that recognize selective disclosure aren't penalized under the "substantial similarity" framework.

Why Congress already pointed this direction

Section 9 of the GENIUS Act directs FinCEN to research and evaluate innovative methods for detecting illicit activity — and the statutory factors it must weigh expressly include privacy risks associated with the information collected. Congress wrote privacy into the standard. A technology that improves detection and effectiveness while reducing privacy risk is precisely what the statute tells FinCEN to favor. Zero-knowledge proofs are exactly that kind of advanced tool.

This is not theoretical

Selective-disclosure architectures are already in the field. Monument Bank, a regulated UK institution, is working to tokenize £250 million in customer deposits as shielded tokens on the Midnight network — balances and histories cryptographically private, regulatory access preserved through viewing keys, and no public-chain transparency required by the UK's Financial Conduct Authority. In the U.S., the Texas Blockchain Council is working with state legislators on stablecoin legislation that contemplates privacy-enhancing designs, and Midnight ecosystem partners have responded to government RFIs at the state and federal level.

Technology has advanced to the point where data protection and compliance on public, permissionless chains can co-exist. The compliance architecture is demonstrable. What's urgently needed now is for regulators and legislators to familiarize themselves with the advantages and opportunities this technology provides, before final rules are set. Rules drafted without that familiarity risk mandating transparency standards that put every account balance, counterparty, and transaction history on public chains into permanent public view — exposing individuals to theft, extortion, and physical targeting, and institutions to systemic risk as competitors and bad actors trade against exposed positions.

Technology has advanced to the point where data protection and compliance on public, permissionless chains can fully co-exist — without retreating to private, permissioned networks that achieve confidentiality simply by restricting who may participate. The compliance architecture is demonstrable. What's urgently needed now is for regulators and legislators to familiarize themselves with the advantages and opportunities this technology provides, before final rules are set. Rules drafted without that familiarity risk mandating transparency standards that put every account balance, counterparty, and transaction history on public chains into permanent public view — exposing individuals to theft, extortion, and physical targeting, and institutions to systemic risk as competitors and bad actors trade against exposed positions.

The ask, in one sentence

We're asking FinCEN and OFAC to write a final rule whose standards are defined by outcomes rather than architectural choices — so that the clear benefits of privacy-enhancing stablecoins, which deliver the regulatory visibility government needs and the financial privacy citizens, businesses, and institutions expect, remain viable and can be accessed in the United States.

Privacy-enhancing stablecoins with selective disclosure aren't an evasion of the compliance framework. Done right, they're an advancement of it.

The Midnight Foundation is dedicated to advancing the development and adoption of the Midnight network, a privacy-enhancing blockchain for confidential smart contracts and selective disclosure. Read our full comment to FinCEN and OFAC here. Questions or interest in a technical demonstration? Contact us at info@midnight.foundation.


Share