A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
What South Korea actually says
The most identity-maximalist regime covered here, and the only one actively trying to export it. Untraceable assets have been barred from Korean platforms since 2021, layered on top of a real-name bank account requirement that makes the won on-ramp a chokepoint. The August 2026 amendments go further than anything else in this section: the travel rule threshold is abolished outright so it applies to transfers of any size, and transfers to personal wallets are permitted only where the destination is low-risk or the two ends are confirmed to be the same person, with outright prohibition where the counterparty is high-risk. Accommodation exists but sits entirely on the institutional access axis (corporate accounts, tokenised securities) and not on confidentiality.
The instruments that matter
- Dark coin restriction
- the FSC announced in November 2020 that virtual assets whose transaction records are hard to trace could not be handled, with enforcement from March 2021; exchanges had already delisted Monero, Zcash, Dash and Zcoin in September 2019 citing FATF
- Virtual Asset User Protection Act, from 19 July 2024
- deposit custody at banks, asset segregation, mandatory surveillance systems and unfair-trading reporting to the FSS
- Cabinet approval, 11 August 2026
- abolishes the travel rule threshold entirely, so it applies to transfers of all sizes; transfers of KRW 10m or more to overseas providers must be reported to KoFIU
- Unhosted wallet transfers restricted
- permitted only where the destination is low-risk or sender and recipient are confirmed to be the same person, and prohibited outright where the counterparty is high-risk
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- SingaporeAsia-Pacific · Regulates anonymity by risk assessment, not prohibition
- Monetary Authority of SingaporeAsia-Pacific · The regulator that priced the risk instead of banning it
- BangladeshAsia-Pacific · Barred through exchange control, not a crypto law
- BermudaAmericas · A travel rule with no minimum, reaching self-hosted wallets
- ChinaAsia-Pacific · Crypto banned, and a state currency designed for anonymity
- IndiaAsia-Pacific · No crypto statute, regulated through AML and tax
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.