The U.S. Treasury Department's March 2026 report to Congress, submitted under the GENIUS Act framework, formally acknowledged that crypto mixing services have legitimate privacy uses — a reversal from the enforcement posture that led to Tornado Cash sanctions in 2022. The 32-page report arrived w...
"Mixing services can serve lawful purposes on public blockchains… when paired with safeguards such as record-keeping and other compliance measures." — U.S. Department of the Treasury, GENIUS Act Report to Congress, March 2026
The U.S. Treasury Department's March 2026 report to Congress, submitted under the GENIUS Act framework, formally acknowledged that crypto mixing services have legitimate privacy uses — a reversal from the enforcement posture that led to Tornado Cash sanctions in 2022. The 32-page report arrived weeks after Zcash's development arm raised $25 million in seed funding and as Railgun's cumulative shielded volume crossed $4.5 billion.
The policy shift is not unconditional. The same report proposed a digital asset "hold law" enabling exchanges to freeze suspicious funds without court orders, and urged Congress to clarify AML obligations for DeFi protocols. North Korea-linked actors stole at least $2.8 billion in digital assets between 2024 and 2025 using mixing services, per Treasury data. Developer prosecutions continue: the DOJ requested an October 2026 retrial for Tornado Cash co-founder Roman Storm on unresolved money laundering and sanctions charges, even as the broader policy environment softens.
The result is a two-track regime: privacy infrastructure is gaining institutional and regulatory legitimacy, but the individuals who built the first generation of these tools face prison sentences. This report examines whether the emerging "compliance-compatible privacy" model creates durable economic value or merely a regulatory arbitrage window.
The U.S. Treasury submitted a 32-page report to Congress in March 2026, marking the most significant policy shift on crypto privacy since the Tornado Cash sanctions of August 2022. The report, filed under the GENIUS Act's illicit finance and innovation provisions, states that mixing services "may lawfully help shield personal, business and charitable transactions from public view."
This represents a 180-degree turn from Treasury's 2022 posture. OFAC's original Tornado Cash designation treated the protocol's immutable smart contracts as sanctionable property. The Fifth Circuit Court of Appeals reversed that determination in November 2024, ruling that OFAC had exceeded its statutory authority — immutable smart contracts "are not capable of being owned or controlled by anyone" and thus fall outside the International Emergency Economic Powers Act (IEEPA).
The March 2026 report operationalizes this legal reality. Key proposals include:
The policy acknowledges the tension directly: North Korea-linked actors stole $2.8 billion in digital assets between 2024 and 2025, frequently using mixing services. The report does not dismiss the illicit finance risk. It reframes it — from "ban the tools" to "regulate the usage."
The regulatory thaw has not reached the individuals who built first-generation privacy tools. Three cases define the current legal landscape:
Alexey Pertsev — Tornado Cash developer. Convicted by a Dutch court in May 2024 of laundering $1.2 billion through Tornado Cash. Sentenced to 64 months. Released to electronic monitoring in February 2025 while appealing.
Roman Storm — Tornado Cash co-founder. Convicted in August 2025 of conspiring to operate an unlicensed money-transmitting business by a Southern District of New York jury. The jury deadlocked on the more serious charges: money laundering conspiracy and sanctions violations conspiracy. The DOJ filed a motion on March 10, 2026, requesting an October 2026 retrial on the two unresolved counts, which carry a combined maximum sentence of 40 years. Storm remains free on bail. An oral argument on his motion for judgment of acquittal is set for April 9, 2026.
Keonne Rodriguez — Samourai Wallet co-founder. Sentenced in November 2025 to 60 months in federal prison plus a $250,000 fine for conspiracy to operate an unlicensed money-transmitting business. Samourai Wallet processed more than 80,000 BTC (over $2 billion at transaction time) through its Whirlpool mixing and Ricochet transaction-hopping services. President Trump indicated in December 2025 that he would "look into" a potential pardon.
The legal paradox is stark: the Treasury now acknowledges the tools' legitimate purposes while the DOJ continues prosecuting their creators. This creates a chilling effect on open-source development that newer protocols are attempting to design around.
A new generation of privacy protocols has emerged with compliance mechanisms embedded at the architecture level. The key players and their metrics:
Railgun — zk-SNARK-based privacy system on Ethereum. Cumulative shielded volume: $4.5 billion, doubled year-over-year. TVL: approximately $94-106 million (fluctuating). Daily shield count reached a record 326 in early 2026. Monthly shielded volume exceeds $140 million. The protocol launched Railgun Connect, enabling private wallets to interact directly with DeFi platforms like CowSwap without unshielding funds. Market cap: $57.9 million. RAIL token price: $1.01.
Privacy Pools (0xbow) — Built on Vitalik Buterin's 2023 research paper co-authored with Jacob Illum (Chainalysis), Matthias Nadler, Fabian Schär, and Ameen Soleimani. Launched on Ethereum mainnet in March 2025. The protocol uses zero-knowledge proofs to allow users to demonstrate their funds do not originate from sanctioned sources — without revealing their full transaction history. Over 17,000 transactions processed. 0xbow raised $3.5 million in seed funding in November 2025. Expanding to BNB Chain in Q1 2026 via a partnership with Brevis.
Aztec Network — Privacy-focused Layer 2 on Ethereum. TVL surpassed $1.2 billion as of mid-2026, according to industry reports. Uses zero-knowledge rollup architecture to provide private smart contract execution.
Zcash (via ZODL) — The Zcash Open Development Lab, formed by the former Electric Coin Company core team following a January 2026 governance dispute, raised over $25 million in seed funding as of March 9, 2026. Dash integrated Zcash's Orchard privacy shielded pool technology in early 2026, extending its compliance-compatible privacy model to another chain.
Monero (XMR) — The established privacy coin survived 73 exchange delistings in 2025. Market cap approximately $8.2 billion (January 2026 data). The upcoming FCMP++ (Full-Chain Membership Proofs) upgrade, scheduled for Q1 2026, moves Monero from probabilistic obfuscation to mathematically provable untraceability. Atomic swap technology has shifted liquidity to non-custodial venues after centralized exchange delistings.
The architectural divergence is clear: Railgun, Privacy Pools, and Aztec are building "selective disclosure" — users prove compliance without revealing transactions. Monero is building the opposite — deeper untraceability with no compliance hooks.
Non-custodial swap volumes surged 340% year-over-year, according to CryptoNews data, with platforms processing billions in daily volume without KYC requirements. The drivers are structural:
GhostSwap processed over $750 million in swaps across 1.5 million users without KYC. The global crypto exchange market is projected to grow from $85.75 billion in 2026 to $314 billion by 2033, with non-custodial platforms capturing an increasing share.
This migration represents a real structural shift in where crypto economic value flows. Volume moving from centralized, fee-extracting venues to non-custodial swaps reduces revenue for traditional exchange operators while distributing value to liquidity providers and protocol token holders.
The institutional side of crypto privacy operates on a different axis. Canton Network, developed by Digital Asset (CEO Yuval Rooz), provides privacy infrastructure for financial institutions. Unlike retail privacy tools, Canton enables granular data partitioning — a regulator can request the transaction amount between parties A and B without accessing the full transaction history.
The most significant institutional development: DTCC's collaboration with Digital Asset and Canton to tokenize a subset of U.S. Treasury securities custodied at DTC, supported by a SEC No-Action Letter. The minimum viable product was expected by mid-2026.
Canton's token rallied in early 2026, sparking a broader privacy-coin surge that lifted Midnight (Cardano's privacy sidechain), Zcash, and Monero. The institutional signal is unambiguous: regulated financial firms want on-chain privacy, but only with compliance guarantees.
The Ethereum Foundation itself allocated resources to privacy research, listing it as a core priority for the 2025-2026 roadmap. This institutional backing — from the world's largest smart contract platform's non-profit — validates the demand signal from both sides: retail users want protection from surveillance, and institutions want protection from competitors seeing their order flow.
Applying an economic-value-first lens to the privacy infrastructure sector reveals several dynamics:
Fee revenue is minimal. Railgun's $57.9 million market cap against $4.5 billion in cumulative volume implies thin take rates. Privacy Pools has processed 17,000 transactions with no visible fee extraction model. The value accrues to token holders through usage-driven demand rather than protocol revenue.
The compliance premium is real. Protocols with selective-disclosure mechanisms (Railgun, Privacy Pools, Aztec) are attracting institutional capital and regulatory tolerance. Protocols without compliance hooks (Monero) face exchange delistings but retain a dedicated user base willing to accept liquidity friction.
Infrastructure subsidy remains high. ZODL's $25 million raise, 0xbow's $3.5 million seed, and Aztec's previous rounds indicate that privacy infrastructure is still primarily venture-subsidized rather than self-sustaining from fees.
Regulatory arbitrage window. The current environment — Treasury acknowledging legitimate use, DOJ still prosecuting developers, Congress yet to legislate — creates uncertainty. Protocols launching now benefit from softer rhetoric but face the risk that legislation could impose obligations they cannot technically meet.
Crypto privacy is bifurcating into two distinct models: compliance-compatible and compliance-resistant. The Treasury's March 2026 report accelerates this split. Protocols building selective disclosure — proving fund legitimacy without exposing transaction graphs — are positioned to capture institutional demand. Protocols building deeper untraceability will retain users who prioritize absolute privacy but face persistent liquidity friction from exchange delistings and regulatory hostility.
The unresolved tension is developer liability. Until Congress legislates clear boundaries between writing privacy software and operating a money-transmitting business, the chilling effect on open-source development will persist. The Treasury has signaled where policy is heading. The DOJ has not yet followed. That gap — between acknowledging legitimate use and prosecuting the people who enabled it — defines the current state of crypto privacy.
The economic value question remains open: whether compliance-compatible privacy generates sustainable protocol revenue or merely redistributes venture capital through a regulatory arbitrage window. The data so far — $4.5 billion in Railgun volume against a $57.9 million market cap, $1.2 billion in Aztec TVL funded by venture rounds — suggests the market is pricing usage growth, not current cash flow. That is a familiar Web3 pattern. Whether privacy is the sector where that pattern finally converts to durable economics will depend on whether the next 12 months produce legislation or merely more reports.