
Canton
Institutional
web3 infrastructure
Privacy Is Not Secrecy: The Case for Confidential-but-Traceable Blockchains
Privacy controls who sees transaction data, while secrecy hides it from everyone including lawful oversight. Confidential-but-traceable blockchains keep contents private from the network yet expose auditable records to regulators and auditors holding a viewing key.
AUG 12, 2026
Last updated AUG 12, 2026 · V1
TL;DR
- Privacy controls who sees your data. Secrecy hides it from everyone, including legitimate oversight.
- Strong encryption was once classified as a weapon. The crypto wars of the 1990s ended by normalizing privacy as regulated infrastructure.
- Fully transparent chains like Ethereum expose every transaction to every node, which disqualifies them for institutions holding fiduciary or regulated data.
- The CLARITY Act asks for accountable participants and preserved law-enforcement reach. It does not mandate public transparency or ban privacy, and it passed the House and is pending in the Senate as of August 2026.
- Confidential-but-traceable architecture keeps transaction substance private while making auditable data available to authorized parties.
- Systems like Canton Network and zero-knowledge disclosure models already run this way in production.
- The strongest objection is that on-chain privacy enables laundering: OFAC sanctioned the Tornado Cash mixer in 2022 over funds tied to North Korea’s Lazarus Group. Selective disclosure addresses it, and the courts are still drawing the line.
- A mixer hides from everyone permanently. Institutional confidentiality gives way when a legitimate authority invokes the right to see, and that is what distinguishes lawful privacy from criminal concealment.
Why Was Strong Encryption Once Treated as a Weapon?
Strong cryptography was once regulated by the US government as a munition. Under Cold War export-control rules, encryption above a set strength was on the US Munitions List, the schedule that governed tanks and missiles.
The logic was that unbreakable encryption in hostile hands could shield foreign military communications from US intelligence. Exporting strong encryption could therefore be treated as arms trafficking.
The clashes that followed became known as the crypto wars.
When Phil Zimmermann released PGP (Pretty Good Privacy) in 1991 and it spread internationally, he became the subject of a federal criminal investigation into export violations. That case ran for years before the government dropped it without charges.
Washington also pushed alternatives that preserved surveillance access. The Clipper Chip, introduced in 1993, was an encryption device with a government-held key-escrow system built in, meaning the state kept a spare key that could decrypt any message on demand.
The Clipper Chip offered privacy for citizens, with a backdoor reserved for the state. It collapsed under technical criticism and public resistance.
A privacy-enabling technology was treated as guilty by default, because bad actors might use it.
What Ended the Crypto Wars, and What It Teaches Us
Export controls on strong encryption were liberalized around the late 1990s and early 2000s, and criminals had not disappeared. Suppression stopped being worth its cost.
Strong encryption existed overseas regardless of US rules, and secure commerce on the emerging internet depended on it. The resolution took a durable form.
Strong privacy became normalized as legitimate, regulated infrastructure. Encryption moved from the munitions list into the mechanics of ordinary commerce, where it still protects logins, payments, and messages today.
So, the workable response to a privacy technology that bad actors can misuse is to define the terms under which it operates legitimately.

Encryption and blockchain privacy raise the identical dilemma, where a tool that protects legitimate users also shields bad ones, so the resolution that worked once may be worth applying again.
What Is the Difference Between Privacy and Secrecy?
Privacy is controlling who sees what for legitimate reasons, while secrecy is concealment designed to evade accountability. That single sentence carries the weight of this whole article.
The two words describe opposite intentions. Privacy protects specific things in everyday finance:
- a medical payment,
- a supplier’s negotiated price,
- a trading position,
- a company payroll.
None of these are hidden because someone is doing wrong. They are shielded because broadcasting them harms patients, businesses, and employees.
Traditional finance is private and still accountable. Your bank balance is not published to the world, yet it is far from concealed.
Auditors, need-to-know counterparties, tax authorities, and regulators all see what they are entitled to see. Oversight stays intact while exposure stays limited.
The design goal is hiding from the wrong observers. A competitor is the wrong observer, and a regulator with a warrant is the right one.
Why Is a Fully Transparent Blockchain a Problem for Regulated Finance?
On Ethereum and similar public chains, every transaction is visible to every node by design. A node is any computer helping run the network, so in practice the data is open to the public and to competitors.
That radical transparency works for consumer crypto, where openness builds trust between strangers.
For regulated institutions handling client and market data, the same property is disqualifying. The failure modes are concrete:
- Strategy leakage. Competitors can reverse-engineer a firm’s approach by watching its transactions unfold on-chain in real time.
- Position exposure. Counterparties can see trading positions and, with analysis, map an entire portfolio.
- Client and settlement data. Sensitive client information and settlement records become visible network-wide, breaching confidentiality duties.
For anyone holding regulated or fiduciary data, transparency-by-default is a confidentiality failure baked into the base layer. An institution cannot opt out of it on a chain built to expose everything.
What Does the CLARITY Act Ask of On-Chain Finance?
The CLARITY Act (H.R. 3633) is a market-structure bill. Its core job is to sort digital assets between SEC and CFTC jurisdiction, creating a new “digital commodity” category for tokens whose value comes from a functioning blockchain.
The distinction decides which rulebook a token lives under: the SEC‘s stricter securities regime, or the CFTC‘s lighter commodities one, which is why issuers fight over the category.
The bill also builds provisional registration so exchanges and brokers can operate while detailed rules are written. It defines a “maturity” path for issuers to exit securities treatment.
The key point for this argument is what the bill requires. It does not demand transparency-by-default, and it does not ban privacy.
What it demands is accountable participants:
- registered intermediaries,
- disclosure obligations,
- preserved law-enforcement reach.
Those three requirements ask for traceability and oversight. It stops short of exposing every transaction to the public.
The legislative status should be stated precisely. The House passed H.R. 3633 on July 17, 2025, by a 294-134 vote.
The Senate Banking Committee advanced its own version on May 14, 2026, by 15-9, and the bill sits on the Senate Legislative Calendar as Calendar No. 423. A cloture motion was filed on August 8, 2026, and no final Senate floor vote had occurred as of August 10, 2026.
| Milestone | Date | Result |
| House passage | July 17, 2025 | Passed 294-134 |
| Senate Banking Committee markup | May 14, 2026 | Advanced 15-9 |
| Placed on Senate calendar | June 1, 2026 | Calendar No. 423 |
| Cloture motion filed | August 8, 2026 | No final floor vote yet |
Note: This section is analysis, not legal advice. Anyone acting on the bill’s provisions should confirm the current floor status and seek legal review, since the text and timeline remain in motion.
So Is Regulation Asking for Transparency, or for Accountability?
Regulators are asking ledgers to be auditable by the right parties, not public to all. That is the privacy-and-accountability principle written into law.
The demand is for a ledger that authorized observers can inspect. The same logic runs through other frameworks.
US market-structure rules and EU regimes alike target anonymity that cannot be selectively lifted. Their concern is concealment that no lawful authority can ever penetrate.
This reframes the technical challenge.
The design goal is selective, provable disclosure: keep data confidential from the network, while keeping it available to those with a legitimate right to see it.
Can a Blockchain Be Private and Accountable at the Same Time?
A blockchain can keep transactions confidential while still exposing the auditable data that regulators and participants legitimately need. This is the confidential-but-traceable model, and it exists as a category of design.
The substance of a transaction stays private while the accountability trail remains. Several tools make this possible, and they are usually combined:
- Need-to-know data distribution. Only the parties to a transaction, plus designated observers, receive its details. Other validators handle ordering without seeing contents.
- Selective disclosure and viewing keys. A participant can grant a specific party, such as an auditor or regulator, scoped read access to particular records.
- Zero-knowledge validity proofs. A transaction can be proven valid, correctly formed and properly funded, without revealing its contents to verifiers. This is like proving you are over 18 without showing your birthdate, where the check passes while the underlying data stays hidden.
The emphasis throughout is engineered disclosure. These systems are built so the right observer can be admitted deliberately, which is the capability regulation is looking for.
What Do Real Confidential-but-Traceable Systems Look Like?
Confidential-but-traceable design runs in production today, across more than one architecture. Two approaches reach the same principle by different routes.

The first is institutional settlement infrastructure, illustrated by Canton Network. On Canton, privacy is the default: only named parties and their designated observers can see a given contract, while super validators handle encrypted data and transaction ordering rather than readable contents.
Super validators order transactions and confirm the ledger without being able to read what the transactions contain.
The accountability layer is deliberately public. Reward distributions and burn-and-mint fee data are visible, and regulators can be granted scoped read access to what they are entitled to see.
Canton scale suggests production reality. Reporting indicates the network processes more than $9 trillion in monthly on-chain transaction volume, with over 600 institutions participating.
Named Canton participants include DTCC, BNY, Goldman Sachs, and Franklin Templeton. In August 2025, an industry group completed one of the first real-time, fully on-chain settlements of US Treasuries against USDC, executed on a weekend when traditional markets sit idle.
Figures like these change over time and should be reconfirmed before republishing. The second family is zero-knowledge and shielded-with-disclosure systems.
Approaches here include Zcash-style viewing keys, ZK rollups, and compliance-oriented privacy layers. They deliver validity without exposure: a proof confirms a transaction is legitimate while its contents stay hidden, and opt-in selective disclosure lets a user reveal specific records to a specific party.
| Design family | How privacy works | How accountability works |
| Institutional settlement (Canton) | Only named parties and observers see a contract | Public reward and fee data; scoped regulator read access |
| Zero-knowledge / shielded (Zcash-style, ZK rollups) | Validity proofs hide transaction contents | Viewing keys enable opt-in selective disclosure |
Multiple architectures now deliver the same principle: confidential to the network, traceable to the authorized.
Doesn’t Confidential Settlement Just Enable Sanctions Evasion?
The strongest objection to on-chain privacy is that it becomes a laundering tool, and it deserves a fair hearing. The clearest example is the mixer episode.
In August 2022, OFAC (the US Treasury’s sanctions enforcer) sanctioned Tornado Cash, an Ethereum-based mixing protocol, adding it to the SDN List (the register of parties US persons are barred from dealing with). It was the first time OFAC targeted an autonomous on-chain protocol rather than a person or company.
A smart contract of this kind places many users’ funds together and redistributes them, breaking the on-chain link between sender and receiver so the money trail goes cold.
OFAC alleged the protocol had been used to launder large sums, including funds tied to North Korea’s Lazarus Group. Estimates cited in litigation referenced billions of dollars moved through the service.
The designation did not survive judicial review. In November 2024, the Fifth Circuit ruled in Van Loon v. Department of the Treasury that Tornado Cash’s immutable smart contracts are not “property” under the International Emergency Economic Powers Act, and that OFAC had exceeded its statutory authority in sanctioning them.
On March 21, 2025, OFAC formally removed Tornado Cash from the SDN List. The delisting covered the protocol’s smart contracts; separate matters, including the criminal case against co-founder Roman Storm, proceeded on their own track.
The episode demonstrates that if confidential settlement means no lawful authority can ever trace an illicit flow, then privacy becomes a shield for sanctioned actors, and the concern is real regardless of how the Tornado Cash litigation is resolved.
What is vital for the industry is whether a system can stay confidential to the network while remaining traceable to authorized parties.
How Does Selective, Auditable Disclosure Answer the Evasion Critique?
The regulatory target is irreversible anonymity. In both US and EU thinking, the problem with a mixer is that its privacy can never be lifted by any lawful authority.
Confidential-but-traceable systems toolkit is built for exactly this purpose:
- scoped read access for regulators,
- viewing keys a participant can hand to an auditor,
- provable transaction validity,
- a public economic layer that cannot be manipulated.
Oversight is designed in from the start. A mixer is built so no one can ever lift the veil, often by immutable code. Institutional confidentiality lifts when a legitimate party invokes the right to see.
However, the legal landscape underneath remains unsettled and the Tornado Cash founder has a pending motion for acquittal.
Even unresolved, currently the courts have shielded the immutable code itself from sanctions while leaving open whether a person can be held accountable for operating a financial service around it. The boundary between publishing code and operating that service is still being drawn.
Why Confidential-but-Traceable Is the Future of On-Chain Settlement
Normalizing strong encryption unlocked secure commerce while keeping oversight intact, and confidential-but-traceable architecture extends that model to institutional finance. The crypto wars ended by treating privacy and accountability as compatible.
A CLARITY-era framework asks for accountable participants and reachable records. Confidential-but-traceable systems meet that request in architecture, while keeping privacy intact.
Reliable infrastructure carries the same weight as reliable design. As a staking and validation provider, Everstake supports networks across this landscape, giving institutions a dependable route to participate in confidential and accountable on-chain systems.
Everstake has historically operated 130+ networks to date. The landing point is clear.
Institutions want the privacy they already have in traditional finance, where balances are shielded but auditors and regulators see what they are owed. Selective, auditable disclosure is how a public ledger, under a real regulatory regime, delivers that.
It is the design the CLARITY-era market has been waiting for.
FAQ
Is privacy the same as secrecy on a blockchain?
Privacy and secrecy are different. Privacy means controlling who sees what for legitimate reasons, with oversight preserved, while secrecy means concealment designed to escape accountability.
Does the CLARITY Act ban private crypto transactions?
The CLARITY Act (H.R. 3633) does not ban private transactions. It is a market-structure bill that sorts assets between the SEC and CFTC and requires accountable, registered participants. The bill remained pending in the Senate as of August 10, 2026, not yet law.
Why can’t institutions just use Ethereum?
On Ethereum, every transaction is visible to every node. That exposes trading positions, client data, and settlement records network-wide, breaching the confidentiality duties regulated institutions carry.
What does “confidential-but-traceable” mean?
Confidential-but-traceable systems keep transaction contents private from the network while making auditable data available to authorized parties. Tools include selective disclosure, viewing keys, and zero-knowledge validity proofs.
Does blockchain privacy enable sanctions evasion?
The regulatory concern is irreversible anonymity, such as a mixer whose privacy can never be lifted. Confidential-but-traceable systems differ because their disclosure lifts on authority, letting regulators and auditors access records when legitimately entitled.
Disclaimer:
This article is for general informational purposes only and does not constitute legal, regulatory, tax, or financial advice. It does not represent the official position or opinion of Everstake or its affiliates. References to laws, regulatory actions, and court decisions reflect the authors’ understanding as of the publication date and may change or be inaccurate. Do not act on this content without seeking independent professional advice. Everstake accepts no liability for reliance on it.
Share with your network