# Malaysia

> Malaysia (Securities Commission Malaysia): A categorical ban written by definition, not by coin name. Region: Asia-Pacific. Attribution required: A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Asia-Pacific
- Subject: A categorical ban written by definition, not by coin name
- Authority: Securities Commission Malaysia
- Stance on on-chain confidentiality: Attribution required. A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
- Tags: privacy token ban, paragraph 15.24, definition-based, self-listing
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-malaysia

## What it actually says

The most explicit categorical ban in the Asia-Pacific set, and notable for how it is drafted. Malaysia does not list forbidden coins. It prohibits exchange operators from permitting a privacy token to be offered for trading, then defines a privacy token by purpose: one intended to enhance user anonymity and transaction confidentiality. That catches the technique wherever it appears, including designs that did not exist when the rule was written, and it applies regardless of whether an asset is otherwise reputable. The same revision liberalised elsewhere, moving listing decisions to the exchange's own board under documented criteria. So Malaysia loosened its grip on what may be listed while tightening it specifically around confidentiality.

## The instruments that matter

- **Guidelines on Recognized Markets, revised 20 May 2026**: paragraph 15.24 provides that a digital asset exchange operator must not permit a privacy token to be offered for trading on its platforms
- **The definition is the mechanism**: guidance defines a privacy token as a digital token intended to enhance user anonymity and transaction confidentiality, so the ban catches technique rather than any named asset
- **Restricted, not prohibited**: meme tokens, exchange tokens, nascent utility tokens, initial exchange offering tokens and stablecoins are tradable only under enhanced risk policies
- **Listing criteria at paragraph 15.21**: include identifiable rights or utility, at least a year of trading on a FATF-compliant provider, sufficient liquidity, sound ledger security and a security audit

## Sources

- [Guidelines on Recognized Markets](https://www.sc.com.my/api/documentms/download.ashx?id=9e4d86cb-889d-412d-94ec-a19b8ac5f7d7)
- [SC media release on the revised guidelines](https://www.sc.com.my/resources/media/media-release/sc-issues-revised-guidelines-on-recognized-markets-for-digital-asset-exchange)

## Related entries

- [Bangladesh](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bangladesh): Barred through exchange control, not a crypto law
- [China](https://www.sodalabs.xyz/privacy-hub/regulation/jur-china): Crypto banned, and a state currency designed for anonymity
- [India](https://www.sodalabs.xyz/privacy-hub/regulation/jur-india): No crypto statute, regulated through AML and tax
- [Japan](https://www.sodalabs.xyz/privacy-hub/regulation/jur-japan): Untraceability barred by self-regulation, now moving into ordinance
- [South Korea](https://www.sodalabs.xyz/privacy-hub/regulation/jur-south-korea): Identity-maximalist, and exporting the model
- [Thailand](https://www.sodalabs.xyz/privacy-hub/regulation/jur-thailand): Closed by whitelist, not by prohibition
