Brazil’s central bank digital currency pilot, Drex, is running into renewed pressure as development slows and major external participants reduce their commitment to privacy-focused workstreams. According to local outlet Valor Economico, companies involved in building privacy solutions for the project, including Microsoft and EY, have cut the number of employees assigned to Drex-related initiatives after the central bank closed the second phase of the pilot without approving any of the proposals submitted by participants.
The reported pullback underscores a central problem that has hovered over the Drex initiative for months: no tested privacy model has yet met the standards required by Brazil’s central bank. That impasse has left the project in a holding pattern, with the market still waiting for a clearer signal on what comes next for one of Latin America’s most closely watched CBDC experiments.
Privacy Remains the Core Technical Challenge
At the heart of the Drex delay is a difficult design requirement. The central bank wants a system capable of preserving the confidentiality of user transactions while still enabling regulators to inspect and supervise activity when necessary. In practical terms, that means privacy cannot come at the expense of oversight, and regulatory visibility cannot completely erase transactional secrecy.
That balance has proven difficult to achieve. Earlier reporting in February had already indicated that none of the privacy solutions presented by vendors had satisfied the central bank’s demanding criteria. Since then, there have been no major public institutional updates laying out a revised roadmap, a new testing framework, or an approval path for proposals that failed to pass the previous stage.
As a result, Drex appears to be in a technical and strategic pause. The absence of an accepted privacy architecture is not a minor implementation issue; it is a foundational requirement for the broader viability of the pilot. Without a workable model, progress toward deployment becomes harder to justify, especially for private-sector partners that must continue allocating specialized staff and budget to a project with uncertain timing.
Microsoft and EY Reduce Staffing
Valor Economico reported that EY, which is leading the Starlight privacy project, lost three team members involved in the development of that solution. The reduction is a concrete sign that companies are reassessing resource commitments after the central bank declined to advance any of the proposals submitted during the second phase.
Microsoft has also reportedly reduced its direct involvement in ZKP Nova, its privacy proposal for Drex. That comes after the company invested significant resources in the initiative last year. Even so, the proposal is not being abandoned entirely. Testing and support for ZKP Nova are expected to continue through Hamsa, a Microsoft partner, which will remain involved in the effort.
The staffing changes do not necessarily mean that participating companies have lost all interest in Drex. However, they do suggest that uncertainty around regulatory acceptance is starting to affect commercial decision-making. For external partners, especially those building technically complex compliance-sensitive infrastructure, prolonged ambiguity can raise the cost of staying fully engaged.
No Approved Proposal, No Clear Timeline
The lack of public guidance since the February update has amplified questions around the project’s direction. Market observers and industry participants have been looking for signs of whether the central bank will revise its standards, open a new phase of testing, or narrow the field toward a smaller set of privacy models. So far, none of those steps has been publicly confirmed.
Rogerio Lucca, executive secretary of Brazil’s central bank, recently said that the Drex team is still evaluating the project’s future. According to his comments, technical teams are discussing possible next steps based on the results of ongoing tests. However, he did not disclose the results themselves, leaving the market without additional clarity on which solutions, if any, are closest to meeting the bank’s requirements.
That cautious messaging reflects the complexity of the challenge. If the central bank moves too quickly without a robust privacy framework, the credibility of the pilot could suffer. If it moves too slowly, the project risks losing momentum among private partners and technology providers that were expected to help shape the ecosystem around Drex.
Why the Resource Pullback Matters
The decision by large firms to scale back staffing matters because CBDC pilots often depend on sustained collaboration between regulators, technology vendors, consulting firms, and infrastructure partners. When those participants begin to reduce manpower, it can affect not only development speed but also experimentation breadth, technical support, and the institutional confidence surrounding the pilot.
In Drex’s case, the issue is especially important because privacy is not a side feature. It is one of the core conditions for the project to move from testing toward broader implementation. If key providers conclude that the approval pathway is too uncertain, they may continue supporting the effort in a narrower or more selective way rather than committing large teams for an open-ended period.
The situation also highlights a broader challenge facing CBDC programs globally. Central banks want systems that are secure, auditable, compliant, and privacy-aware all at once. But designing infrastructure that satisfies every one of those objectives at institutional scale remains difficult. Drex is now another example of how privacy architecture can become a decisive bottleneck in state-backed digital currency development.
What Comes Next for Drex
For now, Drex remains in a wait-and-see phase. The central bank has not formally closed the door on the project, and ongoing tests suggest that technical evaluation is continuing behind the scenes. But until there is a clearer policy signal or a privacy solution that meets the required threshold, the pilot is likely to remain constrained by uncertainty.
The next major development will likely depend on whether Brazil’s central bank can identify a path that preserves both transaction confidentiality and supervisory access. If such a model emerges, confidence in the pilot could recover quickly. If not, further reductions in private-sector participation may become harder to avoid.
At this stage, the immediate takeaway is clear: Drex has not been canceled, but its progress has slowed materially. With no privacy proposal approved and major partners reducing staffing, the future of Brazil’s CBDC pilot now hinges on whether the central bank’s technical review can produce a viable next step.

