## THE STABLECOIN BALANCING ACT

## Source details

**Canonical URL:** [THE STABLECOIN BALANCING ACT](https://www.imf.org/-/media/files/publications/fandd/article/2025/09/duffie.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/fandd/article/2025/09/duffie.pdf.md)
- [Structured JSON version](/-/media/files/publications/fandd/article/2025/09/duffie.pdf.json)

---

### Executive summary
- Compliance-by-design payment systems can simultaneously: fight crime, protect privacy, and process large-scale payments efficiently.
- The approach applies to decentralized stablecoin payment systems and could, in principle, be applied to central bank digital currencies and other digital representations of money.
- Compliance enforcement occurs as transactions occur (proactive, on-chain) rather than reactively (off-chain).

### Compliance-by-design model — how it works
- Users (example: Alice and Bob) undergo identity verification by a licensed credential issuer and obtain a hashed KYC certificate stored on the payment-system ledger.
- Transactions include zero-knowledge proofs (ZKPs) demonstrating eligibility to be inside the KYC perimeter without revealing identities or personal data.
- Smart contracts embedded in the ledger monitor transactions for risk indicators (unusual patterns, transfers exceeding thresholds, links to known high-risk wallets).
- When red flags are detected, smart contracts automatically generate suspicious activity reports (SARs); unmasking identities follows a legal process (warrants or other jurisdictional procedures).
- Layered responses:
  - White-listed routine transfers proceed seamlessly.
  - Flagged transactions may be delayed or trigger automated SARs.
  - High-risk transfers involving known offenders may be blocked.

### Technical components
- Zero-knowledge KYCs (zkKYCs) combine zero-knowledge proofs with selective disclosure; a verifiable credential (anchored to official ID) is cryptographically protected and stored in the user’s private wallet.
- During a payment, a zkKYC token is embedded on-chain proving KYC compliance without revealing user identities; underlying credentials remain off-chain with the credential issuer.
- Smart contracts analyze encrypted information in zkKYC tokens against specified SAR criteria and can be dynamically updated.
- Mentioned techniques and developments:
  - Zero-knowledge proofs (ZKPs) as the core cryptographic tool.
  - Multiparty computation as a potential aid to reduce computational burden.
  - Future cryptography improvements expected to speed ZKP implementations.

### Implementation, governance, and interoperability
- Trusted ecosystem elements:
  - Credential issuers must be licensed, transparent, and accountable.
  - Governments, banks, and certified fintech firms could serve as trusted nodes anchoring users to the compliance perimeter.
  - Uniform standards for KYC verification and cross-ledger interoperability are required.
- Cross-border enforcement requires cross-jurisdictional cooperation similar to correspondent banking.
- Project Mandala (Bank for International Settlements proposal, cited as 2024) is analogous: uses zero-knowledge proofs to coordinate compliance checks without sharing compliance-related data between banks.
- The authors do not propose mandatory adoption; alternative offshore stablecoin systems may persist even if some countries adopt compliance-by-design rules.

### Challenges and trade-offs
- Significant computational burden for large-scale payment throughput; risk of delays during peak periods.
- Risk of simplistic rule implementations producing many false positives and false negatives, overwhelming enforcement authorities.
- Potential frictional costs and delays when moving funds between different payment systems.
- System quality depends on the least rigorous credential issuer; compromised credentials must be revocable.
- Legal questions to resolve across jurisdictions:
  - What justifies triggering a SAR?
  - Under what conditions may authorities unmask a user’s identity?
  - Jurisdictions may set differing due-process thresholds (administrative subpoenas versus judicial warrants).

### Implementation options and mitigations
- Allow regulated providers to license and manage smart contracts, offering compliance-as-a-service to reduce computational burden on the ledger and provide limited access to payment data in exchange for services.
- Improve ZKP performance via advances in applied cryptography.
- Use multiparty computation to share computational load.

### Key statements and notable references (from the source)
- The compliance-by-design approach is in line with the 2023 IMF–Financial Stability Board policy framework for crypto assets.
- Project Mandala: Bank for International Settlements proposal (2024).
- Zero-knowledge KYCs (zkKYCs) referenced to Pauwels 2021.
- The authors: Darrell Duffie (Stanford), Odunayo Olowookere (York University), Andreas Veneris (University of Toronto).
- Visual/chart notation includes an example amount of "$100" associated with a transaction token in the illustrative Chart 1.

*Source: duffie*

---


_Source: https://www.imf.org/-/media/files/publications/fandd/article/2025/09/duffie.pdf_
