Zero-knowledge proofs (ZKPs) have moved from academic cryptography to the center of a regulatory fault line. On one side, the U.S. Securities and Exchange Commission endorses ZKP-based "selective disclosure" as a viable compliance architecture. On the other, Europol warns that ZKPs "significantly...
"You cannot make society secure by making people insecure." — Vitalik Buterin, Ethereum Co-founder
Zero-knowledge proofs (ZKPs) have moved from academic cryptography to the center of a regulatory fault line. On one side, the U.S. Securities and Exchange Commission endorses ZKP-based "selective disclosure" as a viable compliance architecture. On the other, Europol warns that ZKPs "significantly complicate tracing the origins of (illicit) cryptocurrency for law enforcement." Both positions are grounded in the same technology.
The result is a jurisdictional split widening in real time. The EU is mandating ZKP-enabled digital identity wallets under eIDAS 2.0 by December 2026 while simultaneously banning privacy coins from regulated exchanges under its Anti-Money Laundering Regulation (AMLR). FinCEN has proposed record-keeping requirements for privacy coin transactions exceeding $500. Meanwhile, 73 exchanges delisted at least one privacy coin in 2025 — a 43% increase from 2023 — and Coinbase removed Monero, Zcash, Dash, and Horizen from its platform effective April 7, 2026.
The market is responding. ZK rollups collectively hold over $28 billion in total value locked (TVL). Railgun, a ZKP-based privacy protocol, has processed over $5.16 billion in cumulative shielded volume. Aztec Network launched its alpha mainnet in April 2026 — the first Ethereum L2 supporting private smart contract execution. The ZKP infrastructure market is projected to reach $7.59 billion by 2033, per Grand View Research. The technology is no longer experimental. The question is whether regulators will agree on what it means.
The divergence between the SEC and Europol on ZKP technology is not philosophical — it is operational. SEC Chair Paul S. Atkins, speaking at the Crypto Task Force Roundtable on Financial Surveillance and Privacy in December 2025, described a future where "a regulated platform can demonstrate that its users have been screened, without the ability to retain a permanent, person-by-person map of every payment, trade, or donation." He specifically cited zero-knowledge proofs and selective disclosure as tools that allow users to "prove compliance without handing over their entire financial history or personal details."
Europol's First Report on Encryption takes the opposite position. The agency flagged ZKPs as a technology that will make cryptocurrency tracing "harder" as adoption grows, noting that ZK proofs have been used in contexts like Tornado Cash withdrawals in ways that "significantly complicate tracing the origins of (illicit) cryptocurrency for law enforcement."
The European Commission is developing a Technology Roadmap on encryption, due in 2026, aimed at identifying solutions that "enable lawful access to encrypted data by law enforcement." Europol's Internet Organised Crime Threat Assessment (IOCTA) 2026, released April 28, warned of a widening "velocity gap" between law enforcement capabilities and the pace of privacy-enhancing technology deployment.
These are not abstract policy debates. They shape which protocols can operate in which jurisdictions, which exchanges can list which assets, and where capital flows.
The enforcement arm of the regulatory divide is visible in exchange delistings. In 2025, 73 exchanges worldwide delisted at least one privacy coin, up 43% from 2023, according to CoinLaw data. The trend has continued into 2026:
At least 97 countries have introduced or updated privacy coin regulations as of March 2025, up from 79 in 2023.
Despite this, Monero's market capitalization stands at approximately $6.5 billion, ranking 15th globally, with prices in the $330–$410 range through mid-2026. The asset has survived its delisting wave — but its exchange-accessible liquidity has contracted materially. Binance's 2025 removal alone shifted over $600 million in trading volume off its XMR, ZEC, and DASH pairs.
The pattern is clear: regulators are not banning privacy technology outright. They are removing privacy-by-default assets from regulated touchpoints while, in some cases, endorsing privacy-by-design systems that include compliance hooks.
The ZKP market has moved past proof-of-concept. Three categories of infrastructure are now live and scaling:
ZK Rollups: Total value locked across ZK-based rollups exceeds $28 billion, according to DeFiLlama data. zkSync Era has processed over 700 million transactions and achieves throughput of 20,000–30,000 TPS following its Atlas upgrade. Starknet processes 27 million monthly transactions. Gas cost reductions of up to 90% relative to Ethereum L1 have driven adoption across DeFi and stablecoin settlement. ZK rollups collectively settle more stablecoin volume than all optimistic rollups combined.
Privacy Protocols: Railgun has processed $5.16 billion in cumulative shielded volume across Ethereum, Arbitrum, Polygon, and BNB Chain, with TVL reaching $108.5 million — a fresh all-time high. Protocol revenue stands at $4.7 million. Ledger hardware wallet integration went live April 30, 2026. Deployment on Solana, NEAR, and Metis is scheduled for later in 2026.
Private Smart Contracts: Aztec Network launched its alpha mainnet on April 1, 2026, becoming the first Ethereum L2 to support full smart contract execution with complete privacy. The Aztec token generation event occurred February 12, 2026. A v5 network release with security fixes is planned for July 2026, and the team targets 3–4 second block times by year-end.
Grand View Research projects the global ZKP market at $1.535 billion in 2025, growing to $7.59 billion by 2033 at a 22.1% CAGR.
The concept at the center of the regulatory debate is "selective disclosure" — the ability for a user to prove a specific attribute (age verification, sanctions screening status, tax compliance) without revealing the underlying data.
Railgun implements this through its Privacy Compliance Protocol (PCP), which allows users to generate zero-knowledge proofs of transaction history for auditors or regulators without exposing transaction details. The approach is opt-in: users voluntarily disclose specific transactions to specific parties.
Aztec takes a similar approach with private-by-default smart contracts that support selective disclosure features. According to the project's roadmap, the system can be designed so that users prove compliance properties — such as tax payment verification — without revealing full transaction details.
Eli Ben-Sasson, CEO of StarkWare, has framed this as a structural rebalancing: crypto can "rebalance power in our society, taking it away from big tech and restoring it to sovereign individuals." Catherine Kirkpatrick Bos, StarkWare's General Counsel, stated that "building a world where the data about ourselves is stored and surveilled is building a panopticon."
The practical question is whether regulators will accept proof-based compliance as equivalent to data-based compliance. The SEC under Atkins appears open to this. Europol's position suggests it is not.
The EU's regulatory posture on ZKPs is internally contradictory. Two frameworks are advancing simultaneously:
eIDAS 2.0: Formally adopted in March 2024, the regulation mandates that every EU member state provide citizens with a European Digital Identity Wallet by December 31, 2026. The specification requires selective-disclosure mechanisms based on cryptographic proofs. The wallet allows users to prove specific attributes — such as age — without revealing full identity data. ETSI and the European Blockchain Services Infrastructure (EBSI) are developing standardization drafts for ZKP-based selective disclosure.
Anti-Money Laundering Regulation (AMLR): The EU's new AML package bans "crypto-asset accounts allowing anonymization of transactions" and prohibits exchanges from listing privacy coins. These rules become enforceable by mid-2027.
The contradiction: the EU is building ZKP-based selective disclosure into government-issued identity infrastructure while banning ZKP-based selective disclosure from financial markets. The distinction the EU draws is between identity verification (permitted with ZKPs) and transaction privacy (prohibited). Whether this distinction holds as ZKP infrastructure matures is an open question.
France has gone further, declaring privacy-focused cryptocurrencies and anonymizing platforms illegal within its borders. Dubai's January 2026 rules barred Tornado Cash explicitly from regulated firms.
From an economic value distribution perspective, the ZKP infrastructure stack creates multiple fee-capture layers:
Prover networks charge for proof generation. As proof generation has accelerated from minutes to milliseconds for basic proofs, the cost per proof has dropped — but aggregate volume is rising. ZK rollups generate revenue through the spread between L2 user fees and L1 settlement costs.
Privacy protocols capture value through protocol fees on shielded transactions. Railgun's $4.7 million in protocol revenue on $5.16 billion in shielded volume represents a take rate of approximately 0.09% — thin, but scaling with volume.
Compliance middleware — the selective disclosure layer — is the newest fee-capture opportunity. As regulated entities require proof-based compliance, the platforms that generate and verify these proofs sit at a tollbooth between users and regulated markets.
The economic question is whether privacy compliance becomes a cost center (regulatory overhead absorbed by platforms) or a revenue center (a service users and institutions pay for). Current evidence suggests the latter: institutional demand for privacy-preserving compliance is driving adoption of ZK infrastructure at the protocol level.
Zero-knowledge proofs are no longer a niche cryptographic tool. They are the technology on which two incompatible regulatory philosophies are converging. The SEC sees ZKPs as a solution — privacy-preserving compliance that reduces systemic surveillance risk. Europol sees them as a problem — a barrier to tracing illicit capital flows.
Both are correct within their own mandates. The result is not a debate that resolves cleanly but a jurisdictional patchwork that protocol developers, exchanges, and institutional users must navigate. Privacy coins are being removed from regulated markets. ZK-based compliance infrastructure is being built into government identity systems. The technology is the same; the regulatory treatment is not.
For the ZKP infrastructure market, this split is not necessarily negative. It creates demand for compliance-compatible privacy — systems that satisfy the SEC's selective disclosure model without triggering Europol's enforcement concerns. The protocols that solve for both constraints — privacy by default, compliance by proof — will capture the compliance middleware layer. That layer, sitting between $28 billion in ZK rollup TVL and 97 countries of regulation, is where the next phase of value accrual occurs.