
As a title, "The Compatibility of Permissionless Networks and Financial Integrity" doesn't exactly get the blood racing.
But, as blockchain legal theory, the paper is momentous.
Released last week on SSRN, it was written by Rebecca Rettig, Michael Mosier and Omid Malekan.
Each has standing. Mosier ran FinCEN as acting director and served as an associate director at OFAC. Rettig is chief legal officer at Jito Labs. Malekan teaches at Columbia Business School.
It's momentous because it takes aim at a sacred cow: namely, that institutions are, more or less, legally obliged to transact on permissioned networks.
Infrastructure run by pseudonymous validators cannot be squared with AML and sanctions obligations, it is often said. So, in the end, serious players will graduate to gated systems.
The authors think that’s wrong legally-speaking, and say so frankly.
Their argument goes like this: Institutions worry about coming into contact with bad actors they can't see. On an open network, the fee you pay to process a transaction goes to a validator you didn't pick and can't identify. That validator might be in Iran or North Korea. The same validator might, in the same block, process a transaction for a sanctioned wallet.
Doesn't that put a bank in breach? No, say the authors, for two reasons.
First, the law has never demanded zero risk. The Bank Secrecy Act and the sanctions rules ask for programs that are reasonably designed to manage it. When FinCEN and OFAC bring enforcement actions, they go after firms that controlled customers and money and ignored their obligations for years. Nobody has ever been penalized because a validator they never chose processed a block that happened to contain a sanctioned transaction.
Second, more fundamentally, the bank isn't really dealing with validators at all. The protocol sets the fee and assigns the validator by lottery. The bank has no say in either. That looks a lot like sending an email whose packets pass through a router in a sanctioned country. The router isn't your counterparty. It's plumbing. The sanctions laws prohibit buying from, selling to, financing or brokering for a designated party, and paying a code-determined fee to a code-selected machine is none of those things.
So where do the obligations sit? Where they always have: with the institution's own customers and the assets it holds. The OCC has already said banks may run nodes, pay network fees and hold the tokens needed to do so. The GENIUS Act puts stablecoin compliance on the issuer, with nothing running to the network underneath.
What does this mean for privacy? (This is a privacy newsletter after all). The early case for public ledgers rested on transparency. The authors say that financial integrity requires something more circumscribed: that necessary facts be verifiable by the institution, its counterparty and its supervisor.
Zero-knowledge proofs, provenance proofs and viewing keys can deliver that without exposing positions to competitors, they say.
All of which is good for permissionless networks that provide privacy….
Miden is a permissionless network with privacy at the protocol level, built on exactly the premise the paper describes: provable, selective disclosure, safeguarding everything non-material as the user’s.
The paper's significance is potentially wide because it makes a legal statement about reality. The choice between Canton-style permissioned systems and open networks has been litigated as a compliance question. The authors say it should be seen more as a business choice framed in legalese. Institutions can pick gated rails if they want them. But the law isn’t there to assist this time.
Every era of the internet has been a fight between open and closed systems. In the early years it was the web versus AOL. In 2017-19, the same fight played out in blockchains: Ethereum against the "enterprise chains" that wanted the automation and verification of a blockchain with none of the permissionless ethos. Ethereum won. The enterprise chains are mostly gone.
Any reasonable reading of that history says openness tends to win in the end. The cumulative gains of an open network outgun anything a central operator can offer, and the operator's advantages (control, recourse, familiar governance) turn out to be the very things that stop the network from growing.
The current round of permissioned enthusiasm has a plausible excuse the earlier rounds lacked: privacy. Institutions cannot broadcast their positions, and until recently a public ledger gave them no alternative.
That excuse is expiring too. If the necessary facts can be proved to the right parties without being published to everyone, then the last real argument for a gatekeeper falls away, and the fight goes the way it always has.
We hope to have one of the authors on the Privacy Podcast in the coming weeks.
Privacy Roundup
Primus launched a Confidential Vault on BNB Chain for earning yield on encrypted stablecoins, using fully homomorphic encryption to convert $U into $eU while keeping individual deposits and vault positions confidential.
Hinkal showed how existing wallets including Privy, Turnkey, and DFNS can support confidential payments, using zero-knowledge proofs and a relayer to hide the sender, recipient and amount from public view.
The Ethereum Foundation is sponsoring a Privacy-Preserving Technologies workshop affiliated with Asiacrypt 2026 in Hong Kong, covering zero-knowledge proofs, multiparty computation, fully homomorphic encryption, private information retrieval, private identity and deployed privacy systems.
Paul Keating on Privacy Podcast
Ben speaks with Paul Keating, one of the creators of Hummingbird: The Bitcoin Jungle Story, about what Bitcoin looks like when it moves from X (formerly known as Twitter) into everyday life.
Paul describes living almost entirely on Bitcoin in Costa Rica, where a growing local community has made it possible to spend and move between Bitcoin and local currency when needed. The conversation is a reminder that adoption does not always begin with people understanding every argument for Bitcoin. Sometimes it starts because the technology is simply useful.
The episode also explores Paul’s work with Primal and Nostr, and the idea that the same principles of ownership and sovereignty can extend beyond money to identity, content, and online social platforms.
Thanks for reading this edition of Privacy Dispatch. Please subscribe to receive this newsletter every Tuesday.
Till next time.
