{"id":"2cf6cdd6-e3e0-4eb2-bda6-37e6fc02abd9","arxiv_id":"2602.23659","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"CBDC privacy designs shrink drastically between proposal and launch, with launched projects offering only basic encryption and no real anonymity.","lead":"This paper reviews how central bank digital currencies handle privacy and finds that privacy features promised in early designs rarely survive into launched systems. It proposes a formal privacy definition and a layered map of cryptographic tools, then uses 20 country case studies to explain why the gap happens.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Table 1 treats undisclosed CBDC privacy features as absent, undermining the empirical claim; the promised failure analysis is missing from the body.","rationale":"The reader's weakest assumption—Table 1 reliability—is the linchpin of the paper's empirical claim. If the classification of 'undisclosed' as 'B' is wrong for even a few launched cases, the observed pattern that launched CBDCs lack PETs could be an artifact of asymmetric information rather than a real privacy gap. The Asia cases are the weak point: eCNY and Digital Tenge advertise anonymity but provide no verifiable details, while Iran, India, and Thailand are placeholders. The paper's own use of C* and 'Not specified' flags this uncertainty, yet the conclusions treat these entries as if they reliably indicate Layer B or below. The missing 'failure analysis of abandoned privacy pilots' is a separate overreach—no such analysis appears in the body—but it would carry less weight if Table 1 were solid. Since the table is not solid, the classification issue is the most load-bearing concern. The reader's CONDITIONAL verdict is appropriate: the authors should either provide the promised failure analysis plus verified classifications, or revise the abstract and conclusions to match the strength of the evidence. No verdict change is needed.","tokens_in":24477,"tokens_out":6603,"duration_ms":61374,"concrete_test":"Re-code Table 1 using only verifiable primary-source evidence (central bank technical specifications, patent filings, open-source code, or direct statements from the issuing bank). Treat 'not specified' as 'unknown' rather than assigning Layer B; treat C* as 'unverified' rather than including it as a positive finding. Then re-run the analysis: if any launched or pilot CBDC (e.g., eCNY, Digital Tenge) can be confirmed at Layer C or above, the claim that 'privacy does not reach the launched version' is falsified; if all confirmed cases remain at Layer B, the claim survives this test. Additionally, search the manuscript for any section performing a 'failure analysis' or identifying the four root causes; if none is found, the abstract should be revised to remove that claim.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central conclusion—that privacy is designed into proposals but stripped before launch—rests on Table 1's layer assignments. For several launched/pilot cases this assignment is based on absence of evidence rather than evidence of absence. China's eCNY is marked C* ('assumed functionality') because 'the specifics of this system remain undisclosed' (Sec. 6); Kazakhstan's Digital Tenge is also C* with 'no details about how it is achieved.' Iran, India, and Thailand are listed as 'Not specified' yet are assigned Layer B. The paper's own text concedes these details 'remain undisclosed, making it difficult to verify.' This creates an asymmetric-information bias: research projects publish detailed designs, so their PETs are easy to observe, while launched systems keep internal designs proprietary or opaque, so the absence of documented PETs is interpreted as the absence of PETs. The comparison is also cross-sectional: it juxtaposes different projects at different stages rather than tracing a particular proposal from design to launch. The abstract's promised 'failure analysis of abandoned privacy pilots' that would supply such longitudinal evidence does not appear anywhere in the body. If, for example, eCNY's managed anonymity or Digital Tenge's customisable anonymity turns out to be real PETs, two of the seven launched cases would shift from B/C* to at least C, and the headline claim would be weakened substantially.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript uses a Design Science Research Methodology to combine a 67-paper literature review with grey-literature case studies on CBDC privacy. It proposes a three-perspective definition of privacy (legal, technological, transactional) and maps this definition onto a five-layer cryptographic stack that connects privacy requirements to specific PETs. The paper then classifies 20 launched, pilot, proof-of-concept, and research-stage CBDCs against this stack in Table 1, and argues that comprehensive privacy is achievable in research designs but does not survive to launched systems. The abstract additionally promises a 'failure analysis of abandoned privacy pilots' that identifies four root causes of this research-to-launch gap.","tokens_in":24735,"tokens_out":5458,"duration_ms":52645,"significance":"If the empirical claim is accepted, the paper offers a policy-relevant and falsifiable benchmark: it specifies a concrete set of cryptographic capabilities and shows that currently deployed CBDCs generally do not exhibit them. The systematic literature counts, the layered stack in Fig. 7, and the source-documented case-study table are useful contributions for CBDC designers, regulators, and researchers. The paper is weaker as a causal study because the promised failure analysis is absent from the body and because the empirical comparison is based on an asymmetric and cross-sectional evidence base. With revision, the paper could serve as a reference synthesis; as submitted, its central claims outrun the evidence presented.","major_comments":[{"comment":"The abstract promises a 'failure analysis of abandoned privacy pilots' identifying four root causes: regulatory visibility requirements, computational overhead, liability allocation, and institutional incentives. The body does not contain this analysis, and these four root causes are never defined or evidenced. Section 6 presents case studies, and Section 7 discusses why Japan, Denmark, Kenya, and Canada shelved their CBDC plans, but that discussion concerns adoption, cash preferences, and market dynamics, not abandoned privacy pilots. This is a missing contribution, not a wording issue. The authors should either add a dedicated subsection that defines the relevant pilots, provides evidence for each root cause, and links them to the case-study data, or remove this claim from the abstract and reframe the paper's contribution accordingly.","section":"Abstract and §7"},{"comment":"The empirical conclusion is built on an asymmetric treatment of public information. Rows for Iran, India, and Thailand list 'Not specified' but are assigned Layer B; eCNY and Digital Tenge are rated C* because their anonymity mechanisms are undisclosed, and the text admits these details 'remain undisclosed, making it difficult to verify.' Treating non-disclosure as absence of PETs is not evidence of absence, especially because research projects are incentivized to publish detailed designs while deployed systems are not. Concretely, if eCNY's managed anonymity or Digital Tenge's customisable anonymity is later found to rest on real PETs, two of the seven launched cases would move from B/C* to at least Layer C, materially weakening the headline claim. The paper should either restrict layer assignments to features with positive documentary evidence or explicitly state that the conclusion is","section":"Table 1 and §6"},{"comment":"The claim that privacy can be designed in the proposal stage but does not reach the launched version is longitudinal, but the evidence is cross-sectional. The paper compares current research-stage projects (Japan, UK, Switzerland) with launched projects that were designed and launched earlier under different constraints. This design cannot establish what will happen to today's proposals when they are launched. The only within-project trajectory reported is Brazil's Drex, where ZKP was tested and then abandoned in the pilot for AML-compliance reasons (§6). Without a systematic same-project before/after comparison, the causal reading of the conclusion is not supported. At minimum, this limitation should be acknowledged in the Discussion; better, the paper should present the available longitudinal evidence (e.g., Drex, and any other project whose privacy features changed between design and","section":"Table 1 and §7"}],"minor_comments":[{"comment":"Affiliation contains a typo: 'Univeristy' should be 'University'.","section":"Title page"},{"comment":"The phrase 'the design of CDBCs' appears to be a typo for 'CBDCs'.","section":"§2.2"},{"comment":"The figure shows counts of cryptographic techniques but lacks axis labels; adding 'Number of mentions' on the y-axis and a clearer x-axis label would improve readability.","section":"Fig. 6"},{"comment":"The reference for Ben-Sasson et al. on succinct non-interactive zero knowledge appears to cite the LISA 2003 proceedings; the underlying paper is 'Succinct Non-Interactive Zero Knowledge for a von Neumann Architecture', USENIX Security 2014. The citation should be corrected.","section":"Reference [78]"},{"comment":"The sentence on Groth signatures and VRFs says 'although this is in the context of permissioned blockchains and not CBDCs [69].' The citation [69] is Androulaki et al., which is a permissioned-token paper; the reference placement makes it unclear whether [69] supports the whole sentence or only the latter clause. Please clarify.","section":"§4.2.5"},{"comment":"The caption contains a typo: 'Hyperledger imlplementations' should be 'Hyperledger implementations'.","section":"Table 1 caption"}],"recommendation":"major_revision","confidential_remarks":"The paper has a useful survey contribution and a plausible empirical pattern, but the abstract overclaims relative to the body. The missing failure analysis is a structural issue, and the empirical asymmetry in Table 1 is the main technical risk. Both are fixable within the manuscript's scope, so I recommend major revision rather than rejection."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague —\n\nWorth a look, but keep the abstract and the body on separate accounts. What is genuinely useful: the authors synthesise 67 papers, propose an integrated privacy definition and a layered PET stack (encryption, signatures, anonymity, access control, regulatory compliance), and apply both to 20 CBDC case studies. The observation that launched systems cluster at Layer B while proofs of concept reach Layers C–E is credible and policy-relevant. They also deserve credit for marking China and Kazakhstan as C* rather than pretending undisclosed details are known, and for identifying which projects (Project Hamilton, Brazil's Drex) publish source code.\n\nTwo real soft spots. First, the abstract promises \"a failure analysis of abandoned privacy pilots\" identifying four root causes: regulatory visibility requirements, computational overhead, liability allocation, and institutional incentives. That analysis does not appear in the body. The relevant empirical material is one sentence on Brazil's Drex abandoning ZKPs over AML compliance, plus some general discussion of regulatory constraints. The four root causes are asserted, not derived. That mismatch needs fixing in either direction.\n\nSecond, the empirical core rests on Table 1, and some of its classifications are absence-of-evidence rather than evidence-of-absence. For eCNY and Digital Tenge, the paper says the technical details are undisclosed; India, Iran, and Thailand are \"not specified\" yet appear at Layer B. The conclusion holds if read as \"no launched CBDC has verifiable advanced privacy,\" but the stronger version—privacy is systematically stripped between proposal and launch—needs longitudinal traces of the same project, not a cross-sectional comparison of different projects at different stages. Minor inconsistency: the footnote counts India, Thailand, and Solomon Islands as CBDCs available to citizens, while Table 1 lists them as pilots.\n\nThe definition and stack are author-defined artefacts, and the case studies are rated against them, so there is some framing circularity. That is mildly problematic but not fatal; the underlying observation about the gap is not manufactured.\n\nWho gets value: central bank technologists, policy analysts, and researchers wanting a compact map of PETs and a snapshot of twenty projects. I would not cite it for the headline result without the missing failure analysis. I would send it to peer review, but with major revision required, primarily to align the abstract with the delivered content and to soften or re-evidence the systematic-stripping claim.","headline":"Worth reading as a survey and a plausible research-to-launch privacy gap, but the abstract promises a failure analysis the body never delivers and Table 1 leans on unverifiable classifications.","tokens_in":25267,"tokens_out":3611,"would_cite":false,"duration_ms":37335,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"CBDC privacy can be designed in, but launched versions strip it out","keywords":["CBDC","privacy","anonymity","privacy-enhancing technologies","cryptography","zero-knowledge proofs","digital signatures","central bank digital currency"],"falsifier":"A reader could falsify the central claim by obtaining the technical specifications of any launched CBDC and showing that its production system uses a verifiable anonymity-enhancing technology—such as zero-knowledge proofs, blind signatures, ring signatures, or per-transaction UTXO addresses. For example, if China's eCNY 'managed anonymity' turned out to be implemented with blind signatures or zero-knowledge proofs rather than an internal firewall, the paper's Table 1 classification and its conclusion would be wrong.","tokens_in":24291,"feed_emoji":"🔐","tokens_out":7177,"duration_ms":58127,"temperature":0.7,"pith_summary":"This paper asks why central bank digital currencies, despite strong public demand for privacy, ship without meaningful anonymity. It argues that full privacy—user control over transaction data, anonymity, and regulatory compliance—can be built with known cryptographic tools, and indeed appears in proof-of-concept and research designs. Yet across seven launched CBDCs and six pilots, the authors find only standard encryption and digital signatures, with no verifiable anonymity features. They attribute the gap between research and launch to four root causes: regulatory visibility requirements, computational overhead, liability allocation, and institutional incentives. The claim matters because it locates the obstacle to private digital cash in institutional choices, not missing technology.","feed_headline":"CBDC privacy vanishes between design and launch","feed_subtitle":"All seven launched digital currencies stop at basic encryption; pilots show stronger tools exist.","key_machinery":"The paper builds two artefacts: a multi-stakeholder privacy definition (legal/regulatory, technological, transactional) and a five-layer cryptographic stack. Layer A protects personal data with standard encryption; Layer B protects transaction data with digital signatures; Layer C supports user anonymity via ring, blind, or Schnorr signatures, zero-knowledge proofs, homomorphic encryption, and multi-party computation; Layer D gives users control over transaction data; Layer E ensures regulatory compliance via BBS+ signatures, Pedersen commitments, and privacy pools. The stack maps every PET to a privacy layer and serves as the yardstick for evaluating the 20 case studies, yielding the Table","core_discovery":"The paper's central discovery is a consistent pattern: every launched CBDC examined sits at Layer B of the authors' five-layer cryptographic privacy stack—basic encryption and digital signatures—while proof-of-concept and research projects reach Layers C through E by using zero-knowledge proofs, blind signatures, UTXO models, secure multi-party computation, or homomorphic encryption. The authors conclude that comprehensive privacy is technically achievable at the proposal stage but is systematically pared back or eliminated by the time a CBDC launches, and they name four root causes: regulatory visibility requirements, computational overhead, liability allocation, and institutional incentive","pith_inferences":["If the four root causes are right, the most direct policy lever is not better cryptography but a mandate that forces privacy criteria into the design stage—for example, requiring launched CBDCs to reach at least Layer C.","The systems whose anonymity features the paper marks as 'assumed' are a testable pressure point: if either of those systems ever publishes technical details showing real privacy-enhancing technology, the paper's generalisation would need revision.","Editorial note: the abstract frames the four root causes as a 'failure analysis of abandoned privacy pilots,' but the body does not contain a dedicated failure-analysis section; a reader should treat the root-cause list as a synthesis of the case studies rather than a formally derived result.","A natural next study would track the next cohort of CBDCs from proposal to launch, measuring which of the four root causes predicts privacy loss, and whether any jurisdiction that completes a privacy-focused pilot actually retains those technologies."],"forward_implications":["If the pattern holds, citizens in countries with launched CBDCs get digital payments with no verifiable anonymity, despite public surveys ranking privacy as a top concern.","The gap between proof-of-concept and production suggests central banks are not stopped by technical feasibility; the same PETs that work in pilots could be deployed if trade-offs were accepted.","Two-tier models that separate identity data from payment data shift data custody to commercial banks without giving users transactional privacy.","The paper's definition and stack give regulators and designers a common language to specify privacy requirements before procurement, not after launch.","Existing proof-of-concept experiments show that cash-like anonymity can be implemented; the question is whether any central bank chooses to keep it in a live system."],"fun_headline_variants":["Launched CBDCs strip privacy down to basics","CBDC privacy: designed strong, launched weak","Seven live CBDCs settle for basic encryption","CBDC pilots out-privacy the real products","Privacy gap: CBDC design vs launch reality"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The conclusion rests on Table 1's classification of each CBDC's privacy features from public documents, and the paper itself admits that key details—including the 'managed anonymity' and 'customisable anonymity' claims—remain undisclosed; if any of those assumed entries actually contains verifiable privacy-enhancing technology, the central claim collapses.","fun_headline_variants_meta":{"raw":{"variants":["Launched CBDCs strip privacy down to basics","CBDC privacy: designed strong, launched weak","Seven live CBDCs settle for basic encryption","CBDC pilots out-privacy the real products","Privacy gap: CBDC design vs launch reality"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00014,"raw_usage":{"total_tokens":984,"prompt_tokens":714,"completion_tokens":270,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":458,"completion_tokens_details":{"reasoning_tokens":200}},"tokens_in":458,"tokens_out":270,"duration_ms":3042,"temperature":1.0,"reasoning_tokens":200,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-02T20:13:36.456608+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A reader could falsify the central claim by obtaining the technical specifications of any launched CBDC and showing that its production system uses a verifiable anonymity-enhancing technology—such as zero-knowledge proofs, blind signatures, ring signatures, or per-transaction UTXO addresses. For example, if China's eCNY 'managed anonymity' turned out to be implemented with blind signatures or zero-knowledge proofs rather than an internal firewall, the paper's Table 1 classification and its conclusion would be wrong.","supporting_citations":[],"review_version":1}