Soda Labs

The third-party doctrine

Why chain analysis needs no warrant

Regulator or standard-setterAmericasRestricts anonymity

Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.

What The third-party doctrine actually says

Any account of US financial privacy that stops at statutes misses the layer that actually decides things. Because records handed to a third party carry no constitutional protection, chain analysis combined with a subpoena to the exchange is a lawful warrantless route from an address to a name. The Fifth Circuit blessed exactly that sequence in 2020, noting that agents used a commercial clustering vendor and then served a grand jury subpoena on Coinbase rather than seeking a warrant. The First Circuit followed in 2024, and the Supreme Court declined to hear the appeal in June 2025. The 2018 cell-site decision narrowed the doctrine for location data while leaving the financial records line untouched. This floor has not moved.

The instruments that matter

United States v. Miller (1976) and Smith v. Maryland (1979)
information voluntarily conveyed to a third party carries no reasonable expectation of privacy, the foundation for subpoenaing exchange records
United States v. Gratkowski (5th Cir., 30 June 2020)
no reasonable expectation of privacy in Bitcoin blockchain records or in Coinbase account records; agents used clustering analysis plus a grand jury subpoena rather than a warrant
Carpenter v. United States (2018)
narrowed the doctrine for historical cell-site location data as qualitatively different, while expressly preserving Miller
Harper v. Werfel (1st Cir., 24 September 2024)
Coinbase account information falls squarely within the third-party doctrine; certiorari denied 30 June 2025

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.