A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
What Malaysia actually says
The most explicit categorical ban in the Asia-Pacific set, and notable for how it is drafted. Malaysia does not list forbidden coins. It prohibits exchange operators from permitting a privacy token to be offered for trading, then defines a privacy token by purpose: one intended to enhance user anonymity and transaction confidentiality. That catches the technique wherever it appears, including designs that did not exist when the rule was written, and it applies regardless of whether an asset is otherwise reputable. The same revision liberalised elsewhere, moving listing decisions to the exchange's own board under documented criteria. So Malaysia loosened its grip on what may be listed while tightening it specifically around confidentiality.
The instruments that matter
- Guidelines on Recognized Markets, revised 20 May 2026
- paragraph 15.24 provides that a digital asset exchange operator must not permit a privacy token to be offered for trading on its platforms
- The definition is the mechanism
- guidance defines a privacy token as a digital token intended to enhance user anonymity and transaction confidentiality, so the ban catches technique rather than any named asset
- Restricted, not prohibited
- meme tokens, exchange tokens, nascent utility tokens, initial exchange offering tokens and stablecoins are tradable only under enhanced risk policies
- Listing criteria at paragraph 15.21
- include identifiable rights or utility, at least a year of trading on a FATF-compliant provider, sufficient liquidity, sound ledger security and a security audit
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- BangladeshAsia-Pacific · Barred through exchange control, not a crypto law
- ChinaAsia-Pacific · Crypto banned, and a state currency designed for anonymity
- IndiaAsia-Pacific · No crypto statute, regulated through AML and tax
- JapanAsia-Pacific · Untraceability barred by self-regulation, now moving into ordinance
- South KoreaAsia-Pacific · Identity-maximalist, and exporting the model
- ThailandAsia-Pacific · Closed by whitelist, not by prohibition
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.