← Back to list

Statement of Professor J.W. Verret at the SEC Crypto Roundtable on Privacy and Surveillance

Professor Verret teaches securities law, corporate law, banking law and forensic accounting at the George Mason University Antonin Scalia…

J.W. Verret · 2025-12-02 21:33 · 0 claps · 3.9 min read
#cryptocurrency #privacy #securities-law #tokenized-equities
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 ECO · Economy · General EDU · Education & Learning 🔒 · Cybersecurity ⚖️ · Law & Justice

Statement of Professor J.W. Verret at the SEC Crypto Roundtable on Privacy and Surveillance

Professor Verret teaches securities law, corporate law, banking law and forensic accounting at the George Mason University Antonin Scalia Law School. He is the former Chief Economist and Senior Counsel for the US House Financial Services Committee. He served on the SEC’s Investor Advisory Committee and the FASB’s advisory council on the development of GAAP. He leads Veritas Financial Analytics, an expert witness and policy advisory firm, and has recently served as an expert for SDNY, for the defense in US v. Sterlingov, and for the defense in SEC v Red Rock. He is co-chair of the Blockchain Association’s Cybersecurity Working Group and is a certified cryptocurrency forensic investigator.

I am honoured to speak at an SEC led by Chairman Atkins, whose dissents as Commissioner inspired me in law school to publish work that helped obtain the teaching role I have today. I am grateful for your friendship and guidance Mr. Chairman in the 20 years since.

I filed a rulemaking petition in 2022 asking the SEC to open public comment about how to refine its approach to crypto, see https://www.sec.gov/files/rules/petitions/2022/petn4-782.pdf. These roundtables are a reasonable response to that request, and I appreciate the opportunity to participate.

Fascinating zero-knowledge proof technologies will be presented at the roundtable. I support their development. Yet I urge caution about where this conversation should, and should not, lead.

Before discussing how to implement compliance in decentralized systems, we face a foundational question: what is the perimeter beyond which government financial surveillance has no legitimate claim? The SEC should define that boundary clearly before endorsing any compliance architecture, however elegant its cryptography.

Compliance can be built into smart contracts, as presenters have shown. But there is a red line where smart contract compliance features become a tyrannical threat to financial self-sovereignty. We must define that line today, and the SEC must delineate it clearly, in writing, to serve as a North Star limiting future staff action.

Start with first principles. Why is the SEC interested in tokenized equity? If tokenized equity simply replicates traditional brokerage infrastructure on a blockchain, with the same intermediaries, the same custodial requirements, the same surveillance apparatus, we have achieved nothing.

Tokenized equity is only interesting if it delivers what blockchain uniquely offers: self-sovereignty and peer-to-peer exchange. Full personal control of assets in my own wallet. Liquid asset transfers without intermediaries. The ability to pay for coffee with fractional Tesla shares.

And the moment you have true self-custody and peer-to-peer transfer, you need privacy, privacy as anonymity. This is not optional. This is a fundamental human right and a prerequisite for genuine self-sovereignty

Privacy equals anonymity in a global blockchain. To hold otherwise means Russia, China, Venezuela become shared arbiters of our privacy rights in global blockchain assets. Privacy defined as something other than anonymity will ultimately become a national security threat.

Consider wrench attacks. This term describes how criminals bypass cryptographic security by threatening physical violence and it is very real. Kidnappings of crypto holders occur regularly. In May 2025, an Italian investor was held captive and tortured for weeks in New York. There are hundreds of similar documented horror stories.

This is an investor protection issue. Privacy directly serves investor protection when transparent ledgers create physical danger. Privacy further serves 1975 Act and NSMIA goals of fairness, efficiency, and capital formation by preventing front-running of investor trades.

Broker-dealers should be permitted, even encouraged, to offer customers privacy-enhancing tools when withdrawing digital assets to self-custody.

Tools like RAILGUN, privacy pools, or Zcash’s shielded transactions protect customers from physical violence. Regulation S-P already requires brokers to safeguard customer information. Protecting client privacy in post-withdrawal activity should be understood as part of fiduciary obligation, not a violation of the broker rulebook.

I am concerned about pressure to move in the opposite direction. Certain compliance vendors have lobbied the SEC to adopt the FATF Travel Rule and expand it for “pre-transaction risk mitigation.”

Let me be direct: the FATF Travel Rule was never adopted through the Administrative Procedures Act. It is an international guideline, not binding U.S. law.

The SEC should not implement requirements that bypass American rulemaking procedures, particularly while constitutional challenges to related Treasury reporting rules work through the courts.

The one-way ratchet of AML requirements is well documented through the history of that regime. What begins as reasonable compliance inevitably expands.

Today’s voluntary ZK-proof attestation becomes tomorrow’s mandatory disclosure regime.

Today’s blacklist becomes tomorrow’s whitelist where only pre-approved wallets can transact.

We should be deeply cautious about building infrastructure that makes expanded surveillance frictionless.

I close with a constructive proposal. The SEC and CFTC should adopt four guiding principles as a north star for every crypto rulemaking, stated on the first page of every exemption and rule.

First: privacy equals investor protection, because wrench attacks are real and transparent ledgers create physical danger, privacy directly serves the public interest.

Second: blockchain base layer neutrality matters, infrastructure layers like Ethereum or Base must remain neutral, permissionless and open.

Third: non-custodial means no KYC obligations in DeFi, consistent with FinCEN’s recognition that non-custodial actors are not money transmitters and therefore outside of their own regulatory perimeter.

Fourth: blockchain tech exists to eliminate financial intermediation and enhance asset-owner sovereignty, without that, there is no point to it.

These principles should pervade SEC staff work the same way “best execution” pervaded Regulation NMS. A clear north star focuses every examination, every enforcement action tempted to engage in regulation by enforcement, every interpretation, every no-action letter.

These four principles should be made concrete as crypto regulations “North Star” for future SEC staff action.

The alternative is a tokenized future that delivers surveillance without sovereignty, and that is no future worth building.


메타데이터
post_id
0c8ff049e43d
slug
statement-of-professor-j-w-verret-at-the-sec-crypto-roundtable-on-privacy-and-surveillance-0c8ff049e43d
url
https://medium.com/@VeritasForensics/statement-of-professor-j-w-verret-at-the-sec-crypto-roundtable-on-privacy-and-surveillance-0c8ff049e43d
canonical_url
https://medium.com/@VeritasForensics/statement-of-professor-j-w-verret-at-the-sec-crypto-roundtable-on-privacy-and-surveillance-0c8ff049e43d
author_url
https://medium.com/@VeritasForensics
status
ok
fetched_at
2026-07-30 05:45:41