A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
What Bermuda actually says
Bermuda restricts no asset by name and still runs the most comprehensive transaction surveillance requirement found in the Americas. There is no minimum value: every virtual asset transfer carries originator and beneficiary information. More unusually, the obligation expressly reaches transfers to self-hosted wallets, where most regimes either carve out an exemption or say nothing at all. Set against that, the regulator has published no position whatsoever on anonymity-enhancing assets, mixers or tumblers, treating everything under the single heading of digital assets. It is a clean illustration of the pattern running through this section: the binding constraint on confidentiality is the transfer rule, not a list of forbidden coins.
The instruments that matter
- Digital Asset Business Act 2018
- the licensing framework, with proceeds of crime regulations and 2021 sector-specific guidance carrying the transfer obligations
- No de minimis at all
- the obligation to transmit transaction information applies to all virtual asset transfers regardless of amount, the strictest threshold located anywhere in this section
- Self-hosted wallets are expressly in scope
- providers must obtain and record originator and beneficiary information for transfers to self-hosted wallets, which most regimes either exempt or leave unaddressed
- No position on anonymity-enhancing assets
- the regulator's own digital assets pages contain no mention of privacy coins, mixers or tumblers, and treat all coins and tokens under the single term digital assets
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- BahamasAmericas · Issuance of privacy tokens barred, trading not
- BrazilAmericas · A named anonymity rule, and a CBDC that could not solve privacy
- MexicoAmericas · Anonymity named as the reason to exclude the asset class
- South AfricaMiddle East & Africa · A travel rule that starts at any value above zero
- South KoreaAsia-Pacific · Identity-maximalist, and exporting the model
- ArgentinaAmericas · Self-custody providers written out of the regime
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.