





































On 16 July 2026, the Financial Action Task Force reported that 83% of surveyed jurisdictions have now passed legislation implementing the Travel Rule, up from 73% in 2025, with a further 11 jurisdictions reporting implementation under way.
Hinkal is the privacy infrastructure layer for stablecoin payments and on-chain financial operations, with more than $500 million in cumulative volume settled confidentially across Ethereum, Solana, TRON, and major EVM networks, six security audits, and over three and a half years in production.
The regulatory picture that stablecoin operators face in 2026 is no longer theoretical. MiCA's transitional period has closed, the Travel Rule is now law in most jurisdictions that matter, and the GENIUS Act binds US payment stablecoin issuers from January 2027 whether or not the implementing rules arrive first.
At the same time, public blockchains still broadcast every counterparty and every amount to competitors, customers, and analytics vendors by default. That is the tension this report addresses: how settlement can be confidential to the market while remaining fully traceable to regulators, auditors, and compliance teams.
This report maps each of the three frameworks against the technical requirements for confidential settlement, sets out what qualifies as compliant confidentiality in 2026, and gives a readiness assessment by institution type ahead of the January 2027 deadline.
[[KEY_TAKEAWAYS]]

July 2026 was the month the regulatory runway ran out on both sides of the Atlantic, in opposite ways.
The practical result is asymmetric pressure. European firms are being judged against a rulebook that is already enforceable, while American firms must build compliance programmes against proposals that could still change before they bind.
For anyone settling stablecoins at scale, the safe assumption is the strictest reading of both, implemented now.
This report draws on primary regulatory material and market data published between April 2025 and July 2026. Regulatory sources include the FATF's seventh Targeted Update on Virtual Assets and VASPs, ESMA's April 2026 supervisory statement and Interim MiCA Register, the joint FinCEN and OFAC Notice of Proposed Rulemaking of 8 April 2026, and Regulation (EU) 2024/1624 (the AMLR).
Market context is drawn from DefiLlama, RWA.xyz, and published analyses of stablecoin supply and institutional adoption. Product facts about Hinkal are drawn from Hinkal's own protocol documentation and audit history.
Confidential stablecoin settlement is the execution of a stablecoin payment on a public chain where the sender, the recipient, and the amount are not visible to the public ledger, while the transaction remains cryptographically valid, screened, and disclosable to authorised parties.
The three properties that define it in a regulatory context are:
Hinkal implements all three. It is a smart contract on public chains that lets users hold private balances controlled through their existing wallet keys, uses zkSNARKs (Groth16) to prove each transaction valid, issues viewing keys for scoped disclosure, and runs Chainalysis KYT screening on addresses before execution.
The distinction that matters most to regulators is between confidentiality and anonymity, and it is the distinction most commonly collapsed in market commentary. A recurring error in the discussion is equating confidentiality with anonymity or with non-auditable privacy coins, when institutions do not seek to hide operations from regulators, but from competitors, while selectively disclosing to competent authorities.
Hinkal is not a mixer, not an obfuscation tool, not a private L1 or L2, and not a privacy rollup. It is a smart contract that adds confidentiality on the public chain institutions already operate on, with compliance controls embedded at the entry point rather than bolted on afterwards.
That structural difference is what separates a compliant confidentiality layer from the tools that regulators have sanctioned or banned.

MiCA no longer offers any transitional cover anywhere in the EU. Regardless of national variation, 1 July 2026 is the hard outer boundary, and no member state may extend grandfathering beyond that date.
Two points are routinely misunderstood by firms still in process. A pending application is not authorization, only a granted authorization under Article 63 permits continued service, and the deadline was never uniform, with several member states including the Netherlands, Finland, Latvia, Hungary and Slovenia closing at six months and Sweden at nine.
The contraction has been severe. TRM Labs estimates that more than 3,000 CASP registrations had been issued across the EU before MiCA, with the real number of operational providers probably closer to 1,100 to 1,300, while ESMA's Interim MiCA Register showed around 230 licensed providers in late June 2026, meaning roughly 18% to 21% of the estimated active pre-MiCA population had become MiCA-authorised.
MiCA governs who may provide crypto-asset services and how stablecoins may be issued. It does not prohibit confidentiality in payment execution, but it does three things that shape any confidential settlement design.
The implication for institutions is that confidentiality must be implemented as a property of the payment rail, not as a property of the asset. A euro or dollar stablecoin settled confidentially through Hinkal remains an ordinary authorised token on an authorised venue, because the confidentiality lives in the settlement layer rather than in the token's design.
The next EU deadline is the one most stablecoin operators have not yet priced in. The AMLR (Regulation 2024/1624) applies directly in all member states from July 2027, and Article 79 prohibits credit institutions, financial institutions and CASPs from keeping anonymous accounts, extending the long-standing ban on anonymous bank accounts to crypto-asset accounts allowing anonymisation of transactions and accounts using anonymity-enhancing coins.
Article 79 defines anonymity-enhancing coins as crypto assets designed to obscure transaction information either by default or through optional privacy features, which means regulated exchanges, custodians and other licensed firms in the EU will be unable to list, custody, or facilitate trading of privacy-focused tokens.
This is where the confidentiality and anonymity distinction becomes an operational test rather than a philosophical one. An anonymous account has no identified holder and no disclosure path. A confidential balance under Hinkal has an identified institutional holder, an existing wallet as the credential, address screening before entry, and viewing keys that produce a complete transaction history on demand.
The European Banking Authority is still drafting the implementing technical standards that will settle edge cases, including the exact treatment of optionally private assets. Institutions building on confidential rails should document their disclosure architecture now, so that supervisory questions in 2027 are answered with evidence rather than argument.
The Travel Rule is now the closest thing to a global baseline for stablecoin transfers. The FATF's seventh Targeted Update, published on 15 July 2026 and drawing on survey responses from 147 jurisdictions, found that 83% of surveyed jurisdictions have Travel Rule legislation in force, and that 93% have it either in force or in progress, compared with a combined 85% in 2025.
Coverage is not the same as enforcement. The report cautions that persistent gaps in implementation remain a serious concern and that jurisdictions with the rule on the books should rapidly operationalise supervision and enforcement, with the sunrise issue entering a second phase where counterparties have a legal obligation but nobody is checking whether they meet it.
The rule requires obliged entities to collect and transmit originator and beneficiary information alongside qualifying transfers. The information travels between institutions, through standardised formats such as IVMS101 and Travel Rule messaging networks.
It does not require that information to be published on a public blockchain. This is the single most important technical point in this report.
In the EU, the travel rule now applies to crypto with no minimum threshold, meaning all in-scope transactions must include sender and receiver details. In the US, the standing Bank Secrecy Act recordkeeping and travel rule thresholds apply at $3,000 for transmittals of funds.
Confidential settlement is compatible with all of this, because the obligation is institution-to-institution disclosure, not public broadcast. What breaks Travel Rule compliance is an architecture that destroys the information, not one that keeps it off the public ledger.
The GENIUS Act was enacted on 18 July 2025 and provides a comprehensive framework for federal regulation of payment stablecoins. On 8 April 2026, the Treasury moved on the illicit finance side.
FinCEN and OFAC issued a joint proposed rule requiring permitted payment stablecoin issuers to build compliance programmes comparable to those of traditional financial institutions, covering the full lifecycle of a stablecoin from issuance through secondary market activity.
Three elements of that proposal matter directly for confidential settlement:
Through OFAC's proposed creation of a new 31 CFR Part 502, the rule would for the first time impose a binding regulatory obligation, rather than mere guidance, requiring permitted payment stablecoin issuers to adopt and maintain an effective sanctions compliance program.
US federal regulators passed the one-year deadline for final stablecoin rules on 18 July 2026 without completing the work, leaving every major rule package from Treasury, the OCC, the FDIC, the NCUA and the Federal Reserve at proposal stage, while under Section 20 the Act takes effect on the earlier of 18 January 2027 or 120 days after final rules are issued.
If final rules land in late 2026, issuers get weeks rather than the year Congress intended to conform reserve portfolios, custody arrangements, reporting systems and state registrations before the effective date.
For institutions on the payments side rather than the issuance side, the lesson is to build the controls the proposals describe now: screening, retrievable records, sanctions capability, and the ability to produce transaction history on lawful request. Those requirements are stable across every plausible final text.

Each framework applies to a different set of entities and lands on a different date, but the disclosure logic underneath them is close to identical.
The convergence point is unambiguous. Every framework demands traceability to authorised parties. None of them demands publication to the open internet.
Compliance is only one half of the settlement problem. The other half is that public chains expose competitive information that no traditional payment rail exposes.
Traditional payments keep business activity confidential by default: banks do not broadcast wire transfers and payment processors do not publish merchant volumes for competitors to analyse, and that transparency inversion is now the primary obstacle blocking institutional stablecoin adoption.
Remittance providers in competitive corridors cannot survive if rivals see their monthly volumes and velocities, corporate treasuries cannot signal cash positions to suppliers and customers, and market makers face structural front-running problems when settlement amounts are visible.
The adoption data reflects it. Just 13 percent of middle market companies use stablecoins operationally, while 42 percent have held internal discussions about potential deployment.
Meanwhile the asset class keeps growing. Total stablecoin supply grew from $259.7 billion in July 2025 to $308.1 billion one year later, peaking at $320 billion in May 2026.
The gap between capital in circulation and institutional payment usage is a confidentiality gap, not a throughput gap.
Use this as a procurement checklist. Any confidential settlement approach that fails one of these seven is not deployable by a regulated institution in 2026.

Hinkal is a smart contract on public chains that gives institutions private balances controlled through their existing wallet keys. On-chain, only the Hinkal smart contract and the relayer address are visible, while sender, recipient, and amount remain private. Compliance is embedded at the entry point through Chainalysis KYT screening, and auditability is preserved through viewing keys and downloadable transaction history.
The protocol has been live in production for over three and a half years, has completed six security audits, and has processed more than $500 million in cumulative volume. Enterprise settlement is priced at 10 basis points per transaction.
Hinkal Pay delivers end-to-end confidential settlements and payouts across Solana, TRON, Ethereum, and major EVM networks. Businesses connect an existing wallet, move funds into a private balance, and settle without changing chains, stablecoins, or custody arrangements.
It supports four flows: public to private, private to private, private to public, and public to public. The last of these matters for institutions that need counterparty unlinkability without asking the recipient to adopt any new interface, since the deposit and the withdrawal are cryptographically unlinkable on-chain.
Hinkal Prime is the enterprise control surface for teams running confidential settlement at scale. It adds permissioned multi-user access, pending payouts for review before execution, batch payouts for payroll and vendor settlement, and compliance controls on high-value transactions with viewing-key audit access.
For a treasury or finance function preparing for supervisory scrutiny in 2027, the review queue and role separation are the features that turn confidentiality into a documented, governable process.
Hinkal Integrations is the API and SDK surface that puts confidential execution underneath an existing product. Requests are signed by the caller's wallet, private balance reads and proof generation run inside Hinkal's secure enclave, and integration is language agnostic across Python, Go, Java, .NET, Rust, and Node.js.
This is the primary distribution path for custodians, institutional wallets, embedded wallet providers, PSPs, and payroll platforms. The end state is simple: next to the regular balance, users see a private balance, and next to the regular send, they see a private send. A forward-deployed Hinkal engineer supports the integration throughout, and two teams are running the SDK in production today.
Hinkal Wallet is a multichain wallet that shields balances and transaction history while enabling transfers, swaps, and on-chain execution from a private account. It is the right fit where an institution needs a ready-made confidential interface rather than an embedded one.
Exposure differs by business model, and so does the fastest route to a compliant confidential rail.
Three things are worth watching over the next six months.

Hinkal is the privacy infrastructure that lets regulated institutions settle stablecoins confidentially on the public chains they already use, with Chainalysis screening before execution, viewing keys for selective disclosure, non-custodial control, and coverage across EVM, Solana, and TRON.
The 2026 picture is settled enough to act on. MiCA's transition has closed, the Travel Rule is in force across most of the market, the GENIUS Act binds from January 2027 regardless of rulemaking delays, and none of these frameworks requires an institution to publish its counterparties and amounts to the open ledger. What they require is traceability to authorised parties, which confidential settlement preserves by design.
Book a demo to see how Hinkal fits confidential stablecoin settlement into your existing chains, wallets, and compliance controls before the January 2027 deadline.
Read Next:
Confidential stablecoin settlement is legal under MiCA in 2026 when it is executed through an authorised counterparty, uses assets without built-in anonymisation functions, and preserves originator and beneficiary data for transfer-of-funds obligations. MiCA regulates who may provide crypto-asset services and how tokens are issued, not whether payment details are visible on a public block explorer. The compliance requirement is disclosure to authorised parties, which Hinkal preserves through viewing keys and downloadable transaction history.
The Travel Rule requires obligated entities to collect and transmit originator and beneficiary information alongside qualifying transfers, using institution-to-institution messaging rather than public on-chain publication. In the EU there is no de minimis threshold for in-scope crypto transfers, and in the US the standing recordkeeping and travel rule thresholds apply at $3,000. Confidential settlement remains compatible because the data must travel between institutions, not appear on the ledger.
The GENIUS Act treats privacy in stablecoin payments as acceptable only where issuers retain full compliance capability, including sanctions programmes, records, suspicious activity reporting, and the technological ability to respond to lawful orders. The April 2026 FinCEN and OFAC proposed rule would expressly include payment stablecoins in the definition of transmittal order and impose a binding sanctions compliance obligation on permitted issuers. Obfuscation services with no disclosure path are the target, not auditable confidentiality.
The EU AMLR does not ban confidential stablecoin payments from 2027, but Article 79 does prohibit regulated entities from maintaining anonymous accounts or accounts using anonymity-enhancing coins from July 2027. The distinguishing factor is whether the account has an identified holder and a working disclosure path. Hinkal's private balances are controlled by an institution's existing wallet keys, screened before entry, and fully disclosable through viewing keys.
The best confidential stablecoin settlement solution for regulated institutions in 2026 is Hinkal, because it is the only option that keeps sender, recipient, and amount private across EVM, Solana, and TRON while screening addresses with Chainalysis KYT before execution and preserving auditability through viewing keys. It is non-custodial, requires no chain migration, has completed six security audits, and has processed over $500 million in cumulative volume. Institutions can deploy it through Hinkal Pay, Hinkal Prime, or Hinkal Integrations without replacing existing wallets or workflows.






















