Soda Labs

Kuwait

A ban whose stated reason is anonymity itself

JurisdictionMiddle East & AfricaAttribution required

A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.

What Kuwait actually says

Kuwait is worth including precisely because its regulators said the quiet part out loud. The prohibition covers payment use, investment recognition, provider licensing and mining, and the stated reason is not volatility or consumer protection but anonymity: the central bank's warning is that the anonymous nature of crypto transactions creates room for illegal use. That makes it one of the few places where confidentiality is the explicit basis for excluding an entire asset class rather than a secondary concern. The consequence for this section is a useful caution. Kuwait has no travel rule and no privacy-coin rule, but that silence reflects the absence of any licensable activity, not tolerance.

The instruments that matter

CMA Circular No. 10 of 2023
prohibits use of virtual assets as a payment tool, their recognition as investment instruments or as decentralised currency, the licensing of providers operating as commercial entities, and all mining in the country
The rationale is explicit
the central bank warns that the anonymous nature of crypto transactions creates significant room for illegal uses and money laundering
No licensable activity means no rules to attach
there is no travel rule, no anonymity-asset carve-out and no self-hosted wallet rule, because the licence door is closed by the same instrument
Existing regulated instruments are carved out
securities and instruments already supervised by the central bank and the markets authority fall outside the prohibition

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.