AMLConsensus · course
Programme · Lesson 10.5
Section 10 · Lesson 10.5

Privacy Coins: Monero, Zcash and the Limits of Tracing

Almost this entire programme rests on the fact that a blockchain is transparent: addresses, amounts and links are visible forever. Privacy coins break this assumption — they are designed so that an analyst cannot trace the flow. In this lesson we unpack how Monero's and Zcash's privacy works, why tracing hits a wall here, what this changes for AML, and why the very use of a privacy coin is a signal, not a crime.

Transparent vs privacy coins

Bitcoin, Ethereum, etc.
Pseudonymous: an address is not signed with a name, but all amounts and links are public and traceable forever.
Monero (XMR), Zcash (ZEC)
Private: the sender, recipient and/or amount are cryptographically hidden at the protocol level.

The difference is fundamental. Bitcoin is a glass house: you can't see a nameplate with a surname, but you can see every movement. Monero is a house with mirrored walls: you can see that someone inside is doing something, but not who, to whom, or how much.

Why Monero is almost untraceable

Monero (XMR) is the gold standard of privacy. Confidentiality is enabled by default for everyone (you can't "accidentally" send transparently). Three mechanisms work at once:

The result: the sender, recipient and amount are hidden simultaneously. Classic blockchain analysis (following the chain, clustering addresses) does not work on Monero. This isn't "hard" — it is unavailable by design.

That is exactly why Monero is a "blind spot" for tracing tools. An analyst can see that an exchange's address sent XMR or received XMR (at the boundary where Monero touches the transparent world), but what happens inside Monero is inaccessible.

Zcash: privacy "on demand"

Zcash (ZEC) uses a different approach — zk-SNARKs (zero-knowledge proofs: you can prove that a transaction is valid without revealing the details). But with an important difference from Monero:

Practical consequence: Zcash is often partially traceable — many people move between t-addr and z-addr, and "de-shielding" at the boundaries yields clues. Monero leaves no such boundaries within itself. So in the "hardness" of privacy, Monero > Zcash from a tracing standpoint.

What this means for AML: use is a signal in itself

Since you cannot trace the flow inside Monero, compliance cannot confirm the legality of the source with the usual tools. So the logic flips: if it can't be verified, the risk is assessed conservatively.

Transparent coin
Cleanliness can be proven → the address passes the check
Privacy coin
Cleanliness cannot be proven → elevated risk by default

An important nuance to keep in mind: using Monero is not a crime and not proof of guilt. Privacy has legitimate motives: protection from surveillance, commercial confidentiality, safety in undemocratic countries, an unwillingness to reveal your balance to the whole world. But from a compliance standpoint, the impossibility of verification is in itself a risk factor. The formula: "not a suspicion of a specific crime, but the impossibility of dispelling suspicion."

How exchanges and VASPs treat privacy coins

The spectrum of reactions from regulated venues:

  1. Delisting. Many large regulated exchanges have removed Monero/privacy coins from their listings so as not to carry an unsolvable compliance risk.
  2. Jurisdictional restrictions. In some countries trading privacy coins is restricted or prohibited for licensed venues.
  3. Enhanced due diligence (EDD). Where a coin is available, depositing/withdrawing XMR may trigger an in-depth check and a request for the source of funds.
  4. A flag at the boundary. Even if nothing is visible inside Monero, the moment of exchanging XMR ↔ a transparent asset on an exchange is recorded and may be grounds for escalation.
  5. Refusal of service. Some VASPs simply don't work with privacy coins as a matter of policy.
For the analyst the takeaway is practical: if a conversion into/out of a privacy coin appears in a client's history, this is legitimate grounds to ask questions about the source of funds and, in the absence of a coherent answer, to escalate — not because "Monero = crime," but because the break in traceability has to be compensated for somehow.

The limits of tracing: where the analysis ends

An honest picture of an analyst's capabilities with privacy coins:

  • What is visible: the fact and time of contact with a privacy coin at the transparent boundary (a deposit/withdrawal on an exchange, an exchange), the amount at that boundary.
  • What is not visible (Monero): who the sender is, who the recipient is, what amount moved inside, the link between entry and exit.
  • What is sometimes visible (Zcash): the transparent parts of the chain and t↔z transitions, giving partial clues.
  • What compensates: KYC at the boundaries, analysis of the timing/amounts on entry and exit (timing correlations), information from exchanges, the client's behaviour.

In other words, the fight against the risks of privacy coins is waged not inside their blockchain, but at the boundaries — where the private world meets the regulated and transparent one. This is the "limit of tracing": the tool is powerless inside, but strong at the edges.

Lesson summary

  • Privacy coins hide the sender/recipient/amount at the protocol level.
  • Monero (ring signatures + stealth addresses + RingCT) — privacy by default, tracing inside is impossible.
  • Zcash — privacy is optional (z-addr), so it's often partially traceable.
  • For AML: the impossibility of verification = elevated risk by default, but not proof of guilt.
  • Regulated venues more often delist/restrict/enhance the check.
  • The analysis shifts from "inside the blockchain" to the "boundaries" of deposit/withdrawal and KYC.
The main idea: privacy coins are a legitimate technology with legitimate uses, but for compliance they create an irremovable break in traceability. The analyst's task is not to condemn, but to assess the risk correctly and request what the coin cannot hide: a documented source of funds.

This material is educational and does not constitute legal or tax advice.