Fire, Silence, and the Global Rollout of Mandatory Digital Identity
Cryptocurrency was conceived as a way to move value without gatekeepers - a parallel financial rail for people unwilling to depend on institutions they never voted for. Thirty-two years after Eric Hughes wrote that "Cypherpunks write code," the underlying tools once built to remove trusted intermediaries are increasingly being retrofitted to require biometric sign-off, and contracts once designed to run without asking permission may soon check identity documents before executing. A large share of DeFi projects are now actively pursuing compliance credentials, positioning themselves as institution-ready and interoperable with the very systems crypto set out to bypass.
September 2025 offered two contrasting illustrations of where this is heading: one country burned down the apparatus of control within days, the other absorbed a much larger restriction with barely a murmur. Nepal's government banned major social media platforms, triggering unrest severe enough that the prime minister resigned soon after. Around the same time, Vietnam deactivated roughly 86 million bank accounts that lacked biometric verification, and the response was largely silence. No riots, just a population adapting to a new baseline of compliance.

Nepal: confrontation
On September 4, 2025, Nepal's government banned 26 social media platforms - among them Facebook, Instagram, WhatsApp, YouTube and X - after the companies failed to register with the Ministry of Communication, a process that would have required local representatives, government oversight and content monitoring. Most platforms declined to comply.
Prime Minister KP Sharma Oli, who had built a personality-driven public image around life-size cutouts and slogans like "KP Ba (father), we love you," appears to have miscalculated the reaction of a generation raised almost entirely online. By September 8, thousands of students had gathered in Kathmandu, many still in school uniforms, carrying signs reading "no shutdown of social networks" and "democracy hacked, authoritarianism back."
Gen Z, which makes up roughly 40 percent of Nepal's population, turned to TikTok - one of the few registered platforms still functioning - to organize gatherings and spread the word. For a cohort that grew up expecting a connected, federal, prosperous Nepal, losing digital infrastructure read as an attack on the generation itself.
Police responded with force. Nineteen people were killed. The following day, protesters stormed and set fire to the prime minister's residence, along with the homes and offices of other senior political figures. Footage circulated showing demonstrators smashing property amid the flames, and the prime minister resigned shortly afterward. The social media ban was reversed within 24 hours. From the initial ban to the prime minister's resignation, the entire episode played out in five days.
Vietnam: acquiescence
Vietnam's path toward mandatory digital identity was slower and far less visible. Project 06 launched in 2022 as a government initiative to build a unified digital ID system, with full rollout targeted for 2025 and a longer-term vision stretching to 2030. The stated goals were to build a cashless economy, cut down on fraud, and bring the country in line with standards set by the OECD and the Bank for International Settlements.
Implementation arrived in stages. On January 1, 2025, unverified accounts were quietly frozen - no transfers, no QR payments, no visible activity. On July 1, corporate accounts were told their legal representatives needed to submit biometric data or face suspension of service. By September 1, full deactivations were underway.
Vietnam had approximately 200 million bank accounts before the biometric requirement took effect. Afterward, 113 million remained active, meaning 86 million accounts were deactivated for lacking a face scan, fingerprint record, or chip-based ID card linked to the national database. The State Bank of Vietnam described the move as "data-cleansing," framed as a way to eliminate fraudulent accounts, laundering vehicles, and dormant clutter in the banking system.
Under the new rules, transfers above 10 million dong (about $379) require biometric authentication, and daily transaction totals above 20 million dong (about $806) trigger a biometric approval step. For citizens living in Vietnam, reactivation meant visiting a bank branch in person to scan a face and fingerprints. Foreign nationals who had already left the country were required to fly back, since no remote verification, video call, or one-time-password alternative was offered. Affected funds remain locked - not confiscated, but inaccessible until the account holder appears in person. There was no Nepal-style backlash, no burned buildings, no resignation - just tens of millions of frozen accounts and a public that adjusted through sheer inconvenience rather than protest.
The two cases sit at opposite ends of the same spectrum: Nepal's youth mobilized and reversed a restriction within days, while Vietnam's population absorbed a much larger and more permanent change with little visible resistance. One explanation is pacing - Nepal's ban arrived overnight and was immediately visible, while Vietnam's rollout was staged gradually enough, and framed reasonably enough (fraud prevention, international standards), that no single moment galvanized opposition.
The UK's middle path
Britain offers a third model, one still in progress. The country already has roughly one CCTV camera for every 13 people according to 2024 estimates, and an estimated 21 million cameras nationwide. March 2024's Spring Budget committed £230 million to drone and facial-recognition technology, and Live Facial Recognition has since been deployed in London, South Wales, and Essex, with Essex planning routine use by the end of 2024.
In August 2024, Prime Minister Keir Starmer announced an expansion of facial-recognition deployment as a response to "violent disorder" following that summer's riots. A coalition of civil-rights groups has since argued that police have expanded Live Facial Recognition use without adequate scrutiny or a clear statutory basis, and the Equality and Human Rights Commission intervened in a September 2025 judicial review to argue the Metropolitan Police's use of the technology is "likely unlawful." Separately, £55.5 million has been earmarked for retail facial recognition aimed at shoplifting, including £4 million for mobile units that can be sent to high streets.
Public opposition to a national digital ID has been substantial: a petition against mandatory digital ID cards has drawn more than 2.84 million signatures. The government has continued development regardless, and in September 2025 Starmer confirmed digital ID would become mandatory for Right to Work checks before the end of this Parliament, even though the scheme was absent from Labour's election manifesto. The UK case is effectively an open question: whether a Western democracy can push through comparable surveillance infrastructure without triggering the kind of backlash seen in Nepal.
Brussels, CBDCs, and the legal scaffolding for compliance
While individual countries wrestle with cameras and bank freezes, the European Union has been building a more comprehensive framework on a fixed timetable. eIDAS 2.0 entered into force in May 2024, and by September 2026 every EU member state must offer citizens a Digital Identity Wallet capable of holding civil-status records, diplomas, payment credentials and medical data under a common standard, marketed under the principle of user control.
In July 2025, Identyum's ID Wallet received certification at the EU's highest assurance tier, incorporating face biometrics, liveness detection, document scanning and video verification, all built to ETSI standards. The wallet is designed to allow selective disclosure - proving, for instance, that a user is over 18 without revealing their exact birthdate. In practice, this still means centralized, government-issued credentials sitting at the protocol layer, capable of being mandated or monitored regardless of the selective-disclosure marketing.
Financial infrastructure is moving in parallel. JPMorgan's internal work with JPM Coin and its JPMD token already demonstrates that smart contracts can enforce compliance checks before releasing funds on private networks - and much of DeFi already runs on admin keys, whitelists and upgrade mechanisms that could be switched toward the same purpose. Central bank digital currencies extend the same logic to national money supplies: 137 countries are currently exploring CBDC frameworks, and three have already launched fully operational systems.
China's digital yuan is the furthest along. It is programmable money that can be set to expire, forcing holders to spend it by a deadline rather than save it - a mechanism for controlling velocity, not just tracking transactions. It also sits alongside an upgraded social credit system that links financial activity, court records and social media behavior into a single database used to determine access to services.
In the United States, the trajectory has been more contested. Trump's executive order halted federal work on a retail CBDC, and the proposed CBDC Anti-Surveillance State Act would bar the Federal Reserve from issuing one, with sponsors citing the surveillance risk of "government-controlled programmable money". That legislative effort remains unresolved, however, and existing law already provides a separate route: the REAL ID Act defines its official purpose to include "any other purposes that the Secretary shall determine," meaning the Department of Homeland Security can broaden its use without new congressional action. In effect, the legal groundwork for mandatory digital ID and programmable-money enforcement already exists in the US even with retail CBDCs paused - a mechanism that today enforces sanctions compliance, and could as easily be pointed at carbon accounting or social-credit-style scoring tomorrow.
The cypherpunk countercurrent
Against this backdrop, the movement that originally produced the technology behind crypto has been showing renewed signs of life. On March 9, 1993, Eric Hughes published "A Cypherpunk's Manifesto," arguing that "privacy is necessary for an open society in the electronic age," that the cypherpunks were "dedicated to building anonymous systems," and, in its most quoted line, that "cypherpunks write code." Thirty-two years on, that code is seeing fresh momentum even as eIDAS 2.0 and CBDC frameworks advance.
Zcash's price rose roughly 400 percent, moving from about $34 to $180 and breaking an eight-year downtrend, while DarkFi shipped its alpha release built around fully anonymous infrastructure.
Several figures associated with the original cypherpunk milieu are directly tied to this resurgence. Zooko Wilcox, who moved from David Chaum's cypherpunk mailing list through DigiCash to founding Zcash, watched DigiCash collapse under regulatory pressure before building what became Zcash. The project's NU7 upgrade is targeted at quantum-resistant encryption, and more than 23 percent of the ZEC supply currently sits in shielded pools.
Adam Back wrote Hashcash in 1997, a proof-of-work scheme cited in Satoshi Nakamoto's Bitcoin whitepaper, and protested US cryptography export controls by wearing an "RSA Munitions T-shirt." He now runs Blockstream, working on the Lightning Network and Bitcoin satellite infrastructure, and still maintains the site cypherspace.org. A rough technical lineage runs from Chaum to Back to Satoshi to today's privacy-focused protocols.
Jameson Lopp, who describes himself as a "Professional Cypherpunk," is Casa's Chief Security Officer and previously worked in online advertising, where he saw firsthand how poorly the industry treated user privacy. He was swatted in 2017, after which he overhauled his personal operational security, helped track down the person responsible, and shifted his focus from key-management practices to broader personal-safety training - teaching crypto holders how to avoid doxxing, "wrench attacks," and kidnapping attempts.

Amir Taaki, a British bitcoin developer and co-creator of DarkWallet, fought against ISIS in Syria before returning to software development. In February 2025, his project DarkFi launched its alpha, offering a fully anonymous DAO, IRC-based chat, peer-to-peer messaging, and cross-chain swaps, which he has described as "the strongest anonymity you can get." He has argued that cryptocurrencies were captured by institutions partly because they lacked real anonymity, and compares the movement to a Hydra: "you cut a head off, another pops up."
Monero has faced direct commercial pressure - delisted by Binance and Kraken, and set to be banned outright in the EU by 2027 - yet it currently holds a market capitalization of about $6.1 billion. In January 2026, MyMonero will shut down its light-wallet service and delete its server-held view keys a month later, pushing its users toward self-hosted nodes. As Sam Bent has argued, running a full or pruned node locally is the only setup that keeps a third party from ever seeing a user's IP address, sync activity, or transaction timing - convenience and privacy, in his view, pull in opposite directions.
Other privacy infrastructure has continued to grow. RAILGUN has processed $3.5 billion in private transaction volume, $2.5 billion of it in the past 18 months. Aztec now has more than 23,000 validators bringing private smart-contract execution to Ethereum, including a low-memory mode aimed at mobile devices. zkSync applies privacy across users, data, metadata and transactions, and saw daily transaction counts rise 276 percent in the first quarter of 2025, now holding more than $2 billion in tokenized real-world assets. On the device side, GrapheneOS, CalyxOS and SimpleX Chat are stripping out trackers and building privacy-by-default as a baseline rather than an add-on.
Where privacy meets accountability
None of this resolves the underlying tension between privacy and enforcement. The same mixing tools that shield dissidents' funds can shield ransomware payouts; the same zero-knowledge proofs that protect whistleblowers can protect traffickers. Regulators have responded by targeting the people who build these tools rather than the tools themselves: Tornado Cash developer Alexey Pertsev was convicted of money laundering, and the founders and CEO of Samourai Wallet were arrested and charged on similar grounds - even as the underlying software kept running.
Eric Hughes's 1993 manifesto put the underlying argument plainly: "We cannot expect governments, corporations, or other large, faceless organizations to grant us privacy. We must defend our own privacy if we expect to have any." Amir Taaki made a similar point in 2014 while discussing Dark Wallet, framing privacy and censorship-resistance as the core of liberty - an ethos he has carried into DarkFi. Jameson Lopp has framed the same idea in more technical terms, describing cryptographic tools as giving ordinary people "asymmetric defense capabilities" that shift the balance of power between authorities and the public.
The current state of play
By late 2025, the contrast between Nepal and Vietnam captures two very different outcomes for the same underlying pressure: a five-day uprising that reversed a social-media ban versus tens of millions of bank accounts frozen with no comparable protest. The UK sits somewhere in between, still deciding how far facial recognition and mandatory digital ID can go before provoking real resistance. Meanwhile, the EU's eIDAS 2.0 deadline in September 2026 and the broader spread of CBDC frameworks across the 137 countries currently exploring them suggest the infrastructure for programmable, identity-linked money is arriving regardless of any single country's reaction - with tools like Worldcoin's iris-scanning Orbs having already tested public willingness to trade biometric data for tokens.
At the same time, privacy-preserving technology has not disappeared - Zcash and Monero have seen renewed market interest, DarkFi's anonymous infrastructure is live, and RAILGUN continues to process billions in shielded transfers, even as developers behind these tools face growing legal risk. The open question, more than three decades after Hughes's manifesto, is which pattern becomes the default: rapid, visible resistance to new surveillance measures, or gradual, low-friction acceptance of them.
Get new scam files the moment we publish them — usually 2–3 emails a week.