There is a comfortable version of this story. Privacy tools are niche products for paranoid technical users. The Telegram situation was a one-off. Monero is for people buying things they should not be buying.

That version has become very difficult to defend.

Pavel Durov was arrested in France in August 2024 over alleged moderation failures, and Telegram subsequently updated its terms to allow sharing of user IP addresses and phone numbers with authorities. The EU's Chat Control regulation had 19 of 27 member states backing a proposal that would have required platforms to scan every message before encryption, on-device, before sending. The mandatory scanning clause was eventually dropped, but the legal framework keeps advancing. Sweden is considering forcing Signal and WhatsApp to build in law enforcement access. France's Senate passed an encryption backdoor bill before the National Assembly rejected it. Tornado Cash developers were prosecuted. Samourai Wallet developers were arrested.


At EthCC, we sat down with Chris McCabe from Session and Seth from Cake Wallet. They are working on different layers of the same problem.

Chris made the clearest possible case for why architecture matters more than policy. When asked what Session hands over to regulators demanding user data, the answer is that it genuinely has nothing to hand over. No phone numbers, no message history, no central server. A company can be raided and forced to comply, but if the design contains nothing, the architecture has done the work that legal promises cannot. Session has 1.7 million monthly active users across 1,500 nodes in 50-plus countries, built without airdrops or token incentives.

Seth's framing at Cake Wallet started from a different place. Financial privacy is not a feature. It is the foundation everything else rests on. Cake launched in 2018 as the first usable Monero wallet for iOS because the cryptography was excellent and the experience was genuinely terrible. That gap was the product. What they learned since is that privacy tools fail not because the cryptography breaks but because normal people cannot use them.

The "nothing to hide" framing is worth addressing directly. Everyone uses privacy constantly. The populations with the most urgent need are often in places where financial surveillance is a genuine physical risk, where the wrong transaction flags the wrong authority. For those users, Monero and Session are not niche tools. They are infrastructure.


The regulatory direction is not neutral and it is not slowing down. The response is not to build privacy tools that satisfy regulators, which defeats the purpose entirely. The response is architecture with no single point of failure. No server to seize. No data to surrender. No company to threaten into compliance.

That infrastructure exists. Whether enough people reach it before the window closes further is mostly a product problem, not a policy one.