Late night digging through Dusk's Rust code, I stumbled on a struct called ComplianceProof. Thought it was the "bridge" they market. Then I read what it actually does—or rather, what it doesn't.

Moonlight generates a ZK-proof for privacy, plus a recoverable key for regulators. The validator checks the proof format, nods, and finalizes the block. That's it. It never verifies if that recovery key actually works. The decryption handshake happens off-chain—email, phone call, carrier pigeon—after the transaction is already cemented. A malicious actor could feed a junk key, the chain accepts it, and the regulator later gets gibberish with zero on-chain recourse. The privacy stays intact, the compliance bridge silently burns.

I checked the testnet data myself—Phase 2, current. ~210,000 blocks processed, but only ~1,470 transactions triggered the full Moonlight circuit. That's 0.7%. The flagship institutional feature is practically dormant. Most activity is just validators staking in circles.

And the Regulatory Decryption Keys? Held by the foundation and vaguely named "external partners." No on-chain governance for rotation, no time-lock. If that off-chain key handshake gets compromised, the attacker doesn't break the cryptography—they just own the metadata.

So $DUSK built a trust-minimized privacy layer that re-introduces a trust assumption at the exact point of regulatory proof. If the compliance feature barely runs and the keys rely on human goodwill, are we really buying a blockchain—or a very expensive legal wrapper with a PLONK sticker on it?
@Dusk #dusk #DUSK $DUSK