The study says privacy tools serve growing security needs while enforcement is more effective at fiat conversion points, citing fraud, extortion and trafficking-related crypto activity.
ChangeNOW and CoinRabbit have jointly released “Financial Privacy in the Digital Age,” a report arguing that crypto regulation is focused on the wrong part of the transaction stack and that enforcement should concentrate on fiat off-ramps rather than upstream privacy infrastructure. Drawing on data from TRM Labs, Chainalysis, the RAND Corporation, the United Nations Office on Drugs and Crime (UNODC) (U.N. crime agency), Statista and U.S. Treasury Department disclosures, the report examines both illicit use of privacy-preserving crypto tools and their legitimate role in protecting users. The report says on-chain privacy has shifted from a niche preference to a practical safeguard for high-net-worth individuals facing extortion risks, businesses seeking to shield treasury activity and deal flow, and humanitarian operations supporting civilians, journalists and activists in conflict zones and sanctioned regions. Its central argument is that privacy and compliance are not inherently at odds because the main enforcement weakness appears where crypto is converted into spendable fiat currency. Among the findings, pig-butchering fraud generated an estimated USD 75 billion in cumulative losses between 2020 and 2024, while CertiK data showed USD 124.1 million in cryptocurrency was targeted in 52 verified physical “wrench attacks” in the first half of 2026. That represented a 33% increase in incidents and a nearly elevenfold jump in financial exposure from H1 2025. The report also says crypto payments tied to human trafficking networks in Southeast Asia rose 85% in 2025, and that 36% of corporate board members see public exposure of internal financial data as a top governance concern as the average data breach cost reaches USD 4.44 million. The publication highlights ChangeNOW’s Private Crypto Transfers and CoinRabbit’s custodial model as examples of privacy architecture intended to preserve AML (anti-money laundering) compliance. It concludes with five recommendations for regulators, industry, analytics firms and policymakers, including directing more resources toward fiat off-ramps and cross-jurisdictional intelligence sharing.