Zero-knowledge proofs are finally useful for something other than impressing people at conferences. I say this as someone who has spent the last five years watching people misuse the term "zero knowledge" to describe anything mildly private.
Here's what actually happened. For years, the compliance problem looked impossible. You need to prove you're not on a sanctions list. You need to prove you passed KYC. But you absolutely cannot hand over your government ID, your address, your biometric data, your transaction history, or anything else that would let a financial platform or a blockchain spy on you. Privacy and regulatory compliance seemed fundamentally at odds. They're not.
Think of it like a card game. Someone hands you a sealed envelope. Inside that envelope is a certificate signed by a trusted authority saying you passed KYC screening. You can prove to anyone that the envelope is real and the signature is genuine without ever opening it in front of them. Better, you can prove a specific fact about what's inside without revealing anything else. You can prove "I am not on the sanctions list" without revealing your name, country, or PEP status.
That's the magic. That's what makes zero-knowledge proofs different from just encrypting everything.
The first working system at scale was Zcash. But Zcash had a problem. It solved privacy. It didn't solve compliance. Zcash proved you weren't double-spending coins without revealing who you were. But regulators needed something more. They needed proof that money wasn't flowing to bad actors.
Then came the harder problem. Tornado Cash happened. It worked too well. It provided genuine anonymity. Regulators responded by sanctioning it. And here's where things got interesting. You cannot sanction an open-source piece of software. You can sanction specific wallet addresses. So the system got updated. Code got frozen. Addresses got blocked. But the underlying idea remained. What if you could prove you weren't on a sanctions list without revealing your identity?
Privacy pools solved this. The idea is deceptively simple. Instead of one big mixer that everyone uses, you have a mixing pool where people opt in together and prove they're not sanctioned. Everyone in the pool proved they passed the same compliance check. So the pool is compliant. But nobody outside the pool knows who is in it or who sent what to whom.
Practically speaking, here's what this enables right now in 2026.
You're a stablecoin issuer. Someone sends you a deposit from a wallet address you don't recognize. With traditional KYC, you demand a video call, an ID scan, proof of funds, utility bills. It takes three days. You lose the customer. With ZK compliance, that wallet holder generates a proof that they passed KYC with an approved provider. They submit the proof. You verify it cryptographically. Transaction approved. Thirty seconds.
You're an NGO doing cross-border payments. You need to send money to a partner in a sanctioned country. But the people you're sending to are not on any list. The traditional system gums up. Banks deny the wire. You switch to a stablecoin rail. Everyone using that rail proves they passed screening. No individual identities revealed. No chilling effect on legitimate commerce.
You're an exchange operator. Someone wants to withdraw to a private wallet address. You need proof they're not a terrorist organization or a sanctioned entity. You don't need their name or address or employment history. You need proof they passed screening. ZK gives you exactly that.
The technical hurdle is real but shrinking. You need a trusted authority to issue the initial credential. That authority verifies identity the old way, which is slow and privacy-invasive. But they issue a signed certificate. That certificate can be used millions of times without the authority ever learning who used it or where.
The certificate itself is just a cryptographic proof. It's not blockchain-specific. It can live in a wallet, in a database, in a hardware key. It's portable. You can move between platforms without re-proving everything.
Where this gets complicated is in the details. What does "passed KYC" actually mean? Different jurisdictions have different rules. Some countries require ongoing monitoring. Others require proof of source of funds. Some require beneficial ownership. So the credential itself needs to encode not just "approved" or "denied" but which specific rules were checked and what the results were.
This is where selective disclosure comes in. The credential includes multiple facts. You've passed identity verification. You've passed PEP screening. You've passed source of funds verification. Your transaction limit is €100,000 per day. You can prove any subset of these facts without revealing the others.
So when you're trying to move money, you prove what's necessary and nothing more. For a small transaction, you prove identity and PEP. For a large wire transfer, you prove everything. For a transaction to a neighbor country, you prove you're not on their specific sanctions list.
In two years, I expect the infrastructure to mature considerably. Right now, issuing a credential requires interaction with a centralized provider. By 2028, look for decentralized credential networks. Multiple providers issuing proofs for the same person. Aggregation protocols. Reputation systems. Insurance pools that backstop compliance claims.
The other shift will be in speed. ZK proof generation currently takes a few seconds. For Ethereum mainnet transactions, that's fine. For high-frequency trading or real-time settlement, it's not. The cryptography is improving fast. New proof systems like STARKs run faster than SNARKs. Hardware acceleration is coming.
And yes, people will still misuse the term. Someone will call their basic encryption scheme a "zero-knowledge proof." Someone else will claim their centralized server provides "zero knowledge" because they promise not to look at data. Ignore them. Real ZK proofs have mathematical properties. They're verifiable. They're public. You don't have to trust the issuer after the credential is issued.
The compliance problem is not solved. Regulators still demand human judgment in edge cases. Fraud is not stopped by math alone. But for the routine, high-volume checks, ZK changes the equation. You get privacy. You get speed. You get regulatory coverage. You get something that actually works.
And that makes compliance the first problem where zero-knowledge proofs were not just clever but necessary.