Chaum's original digicash worked something like that. It could only be transferred anonymously once. It could only be converted to and from regular cash at regulated entities like banks. So you'd buy some coins at the bank. You could then use the one anonymous transfer to send them to some youtuber. Neither the youtuber nor the government would have any way to learn who sent these coins. But, the youtuber would have no way to send them to a third random person. The only thing he or she could do with them would be bring them to a bank and convert them back to normal currency--along with doing any required tax reporting that is required when you bring cash to a bank. All this was mathematically enforced by the crypto protocol (blinded RSA signatures). It wasn't that great for libertarian madness like Bitcoin supposedly was, but we've since seen how that turned out.
Maybe it's time to revisit Digicash, especially since the patents have expired.