What Sanctions screening on a confidential ledger actually says
Worth stating plainly rather than glossing: this is the weakest part of the case for confidential ledgers. Sanctions liability under the US regime attaches without knowledge or intent, so any design that leaves a regulated intermediary unable to determine whether it dealt with a designated party hands that intermediary unmanaged legal risk. That mechanism, more than any explicit prohibition, is what drives delisting. The architectural answer is that screening does not require public amounts and parties, only that somebody with the duty can screen: at the on-ramp and off-ramp where identity already exists, inside the state machine as issuer policy, or through authorised disclosure. The unsolved parts are real. Designations are retroactive while proofs are historical, and a shielded transfer between two self-custodied parties has no intermediary at all. We found no regulator guidance and no enforcement precedent on any of it.
The instruments that matter
- Strict liability
- OFAC liability attaches without knowledge or intent, so a design that leaves an intermediary unable to tell whom it dealt with transfers unmanaged legal risk to that intermediary
- Where screening can still happen
- at the regulated on-ramp and off-ramp where identity already exists, inside the confidential state machine as issuer policy, or by disclosure to the obliged entity
- What has no clean answer
- designations are retroactive while proofs are historical, and a shielded peer-to-peer transfer has no intermediary to do the screening
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- Anonymity is not the same thing as confidentialityGlobal · Why two privacy designs get treated differently
- Central banks are building confidentiality themselvesGlobal · What the people writing the rules do when they design money
- Erasure against an append-only ledgerGlobal · The one collision with no clean answer yet
- Proving where funds did not come fromGlobal · Association sets, and the Tornado Cash aftermath
- Selective disclosure as a compliance primitiveGlobal · Bilateral disclosure versus publishing to everyone
- The travel rule binds institutions, not ledgersGlobal · The rule everyone assumes ends on-chain confidentiality
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.