Self Protocol - ZK Identity With No Compromises | Marek Olszewski | ETHWarsaw [4]
ETHWarsaw [4] 2025·ETH Warsaw·Sun, Nov 9, 2025, 12:00 AM
Speaker
Marek Olszewski from Celo dove into Self Protocol, a new production ready identity protocol that let's users privately prove their humanity without a counter party. Self piggybacks on the cryptography in Biometric Passports and EU ID cards, enabling individuals to prove that they have a valid ID document in zero knowledge. 🎥 Recorded at ETHWarsaw 2025 Follow ETHWarsaw on social media for the latest updates! X (Twitter): https://x.com/ETHWarsaw LinkedIn: https://www.linkedin.com/company/ethwarsaw Telegram chat: https://t.me/joinethwarsaw
Transcript
Hey guys, happy Friday. It's good to be here.
Yeah. You guys enjoying ETH Warso?
Yeah.
Yeah. Okay, let's wait a moment for the slides to come up. Uh if you don't know me, my name is March. I'm one of the co-founders of Self Protocol, also one of the co-founders of Cello. Uh if you're new to Self, you can uh learn more certainly after this talk by going to self.
xy XYZ and then also you can follow us at selfprotocol and then if you like my talk you can find me at on Twitter. Okay. So um self-protocol is a new ZK identity protocol um that I'm going to walk through but I want to make this fun for you guys. So I I threw in a little game. Just going to wake this thing up.
Perfect. The game is called Guess the Country. And so throughout my slides, I'm going to have a few country shapes thrown in, sprinkled at random locations. And your job is to yell out, well, first of all, recognize the country and then yell out the country name. You think you guys can do that?
Okay, I'm going to try to warm you guys up.
That is interesting. I sus that's right. Uh I suspect I need internet. Give me one second.
Accelerate.
It's okay. I'll just use my hotspot.
Okay. We're going to just imagine that none of this happened. Okay, live debugging here. Fingers crossed.
Okay, what do you guys think? Do you think it'll work this time?
Yeah.
Okay. Once again, to warm you guys up. I'm going to give you an easy one.
Yes. One point over here.
I think someone over here was first.
France. Two points over here. And the reason I'm keeping um count of points is, you know, I wanted to raise the stakes a little bit for you guys. So, uh, I am going to be giving out, um, 100 of USDT to the person who gets the most number of countries, right? I might need a volunteer to help me keep track of the points or I'm going to try my best.
Uh, and you guys can also uh, use the honor system. Um, and we're going to pay it out in Miniipe. So, Minipay is a stablecoin only wallet by the browser company Opera. You guys, anybody heard of Opera? Yeah, lots of hands.
Uh they have a really really nice stable coin wallet and they added this cash link feature uh where you can claim cash just by sending a URL. Uh and to show you uh that I'm trustworthy. Uh I'm going to give four of you 20's water right now. We'll see who can scan this the fastest.
Why does it not look safe? That's right. That I'm giving out to people in talk.
Really?
Okay. A few people are getting it. Okay. I'm going to put these up at the end as well. Um, if you do claim the money, yell out loud to motivate the others to participate in this competition.
Um, okay. So, he's got number three over here. Um, I feel like Are you moderating? Are you the MC?
Give my money away to someone else.
Okay.
Okay. I don't know if he's eligible. Um, but I don't know. Maybe you are. Um I think you get to decide since you're the MC.
I'll give it away to the community.
Perfect. Okay. So at Cello, you know, we've been focused laser focused on this kind of P2P use case uh P payments use case for for many many years now. Um and you know, we've been working with Opera um hand inand thinking about you know how are we going to onboard 1 billion people. So Opera now has 9 million people using uh mini pay.
So it's in emerging markets it's really starting to take off but you know they want to become global Venmo right so they want to hit billions of people and so we've been thinking you know how are we going to do this right and if you look back at the history of onboarding in crypto you know we've had many many waves now of onboarding yes is that one point for you okay um it's easy one but
ah okay a few people have claimed the money so you know I'm good for extra motivation to participate in this game. Um, so we've gone through many many waves of of crypto onboarding. I think the first one of course is proof of work, right? Early on, two points early on. Um, you could simply, you know, buy a GPU, participate in mining first Bitcoin, later Ethereum, and then get some rewards.
That pulled in a lot of people into crypto, right? Later on, we got proof of stake. Uh, same thing, but now instead of buying a GPU, you bought some Ethereum and you bought some Cello. You could stake it and then you could earn some rewards by helping secure the network. Later on, we had DeFi summer.
Argentina in the back is right. I think one point for you. Um, we had Defi Summer. Anybody remember DeFi summer? That was fun, right?
Um, you put your money to work. You brought money, you put it to work, and you got rewarded. That pulled in a lot of people into crypto. And you know, all of these waves had one thing in common, right? They all required people to bring capital um and put it into crypto.
PM is right. Two points for you. Or is it three now? Three points. Okay.
You're tied with Mr. MC over here who may or may not be eligible. People in the back, I know you're at a disadvantage because, you know, light does not travel infinitely fast and sound also doesn't come back to me infinitely fast. But I think you guys can still I think you can still uh get this if you step it up a notch. But all of these waves required people to bring capital, right?
The whole premise was you needed to bring capital. And the reason for that probably was that capital was a really good civil resistance mechanism. Greenland is not right.
Denmark,
Denmark is um and so that was really important, right? You Bitcoin didn't want to pay people uh if they weren't providing a service. So they wanted a system that wasn't gameable. By definition, proof of work was actually invented to solve the civil resistance problem. Um same for proof of stake.
And then likewise, DeFi summer also had this really nice property. And the reason was it didn't matter if you split up your account into multiple smaller accounts. If you only had a fixed amount of capital to begin with, if you divided it all up, you wouldn't get any additional rewards. And so capital has this really amazing civil resistance mechanism. But if we want to onboard, you know, UK is right, I think over here, two points, one point.
And you know if you want to on board the next wave of people we need to start looking beyond people who are going to bring uh you know who have disposable income that they want to put to risk in crypto, right? We want to bring people who can benefit from crypto but who may not have the capital to come and earn these rewards. And so we want to reward them because we have to incentivize them in a way that doesn't require them to bring capital to solve civil resistance. So we have to solve the civil problem without capital. And so that's one thing that self protocol is really focused on.
Uh it does actually a little bit more than this. Um but at its core it's a new identity protocol that helps you solve civil resistance uh in a productionready scalable reliable way um without requiring people to bring capital. And the way it works is it leverages what I like to call is the most trusted um Ukraine is right. Uh how many points? Four.
I think we have a leader over here. Um it leverages what I like to call is the most trusted meat space at the station of who you are, right? And that's your either your biometric passport or if you if your country issues biometric ID cards like most EU countries then uh your biometric ID card as well. Um these are pretty amazing because they're difficult to obtain. Uh they're unique to individuals and they are stored typically securely right because you need them to travel.
You're like likely going to keep them somewhere safe. Uh and the most important thing is that they're machine readable. So, they all have now these NFC chips in them, and you can take the NFC chip, tap it on your phone, and you can read the contents of these cards um without any special hardware. And what's even better is the data inside. What was that?
There's a new name for Czech Republic.
Czecha is right. Um, what's really amazing about these types of IDs is they have contents in these chips. So all of your biometric data that you see on the front page of your ID, all of that is stored electronically. But even better than that, it is actually signed cryptographically with a certificate authority chain. Multiple signatures leading up to the this countrywide certificate authority.
So if you have the public keys of every country in the world, some not that many public keys, you can verify the authenticity of any one of these passports or any one of these biometric IDs. That's really amazing. They did that, of course, to make it hard for you to forge these um documents so that when you enter a country, um if you ever see people putting down your IDs on this flat scanner and you wonder why is it taking so long, it's because it's reading the data in the NFC chip and that can take a little bit of time. and they're verifying that you didn't forge that passport. And so what's really cool is now in a world of um you know blockchains, we can actually verify the authenticity of these IDs without a counterparty, right?
Who likes giving their passport data to a third party so that they can be they can be hacked and your data can be leaked everywhere? Who likes that? One person likes it, right? Who instead would like uh KYC to be verified in a way where you can have a smart contract do the verification that your password data is authentic? Right?
Who likes that much better, right? It's better. Except it's a trick question because if we were to do that, we'd be revealing your data to everyone on chain. So, let's not do that. Instead, what we do is we verify the certificate authority chain in zero knowledge.
So, we can again do it without a counterparty but also do it privately. And so, that's what self does. And once you've done that, once you've proven, what was that? Sweden is right. Uh once you have done that, then uh you can actually start disclosing additional information about yourselves.
Uh all in zero knowledge. So you can prove that you're from some country. Um so this solves a civil resistance problem. You can prove that you're from a specific country if you're comfortable revealing that. You can prove that you're not from a set of countries without revealing which country you are from.
You can also prove that you're over a certain age or under a certain age without revealing your actual date, date of birth. Uh and you can also prove that you are not on the OFAC list without revealing your name, your passport number or your citizenship. So lots of really cool things that you can do with self once users have onboarded. So you might be wondering Canada's right. Uh, how many points do you have?
Three. You still have four. Okay, you're getting close. Looks like the speed of sound is not limiting you anymore. I like it.
Um, so you might be wondering, okay, so what does this experience look like here? Let me step to the side so you guys can see. This is what the onboarding flow looks like. Uh, I'm going to do an EU ID here, but you can also use a passport. First, you have to scan the back side of your ID.
Uh, that's required so that you can actually decrypt what's on the NFC chip. Um, we scan the NFC chip. Much easier to scan on your ID than on your passport. And then we're done. We can start generating the ZK proof.
And so, we're generating a bunch of ZK proofs to effectively register you on chain. Uh, and you are now done. You are registered. You can start using self to disclose information about yourself to third party DAPs. It's just that easy.
Pretty cool, right?
So, how does you know what's going on under the hood?
Who was first? Okay, Croatia, which means I think he's tied for four points. I don't know if you're just letting him catch up or if you're just really into the content and you stop focusing on the game, but uh I think you might want to pick it up a notch because I don't know. You're It's It's yours. It's It's You're about to lose it from this guy.
How many slides are left? There's enough there's enough for anyone here to still win. So sharpen up your your geography skills, everyone. Um okay. So what's going on in the hood?
So obviously we have to create that ZKP that proves the whole certificate authority chain is valid and the way we do this is we have a Merkel route of all of the public keys of all of the different uh country certificates on chain and we're creating a proof uh that all of the signatures in that chain is valid and then we do a Merkel inclusion proof of that final public key. Uh then we uh need to derive a nullifiers from your passport data and we do this so that you can only um register once. Uh you can't solve civil resistance if you can keep registering multiple times with the same ID and so we have this nullifier for that. Uh and then finally um we derive we users are required to create a user generated secret uh which is then used um by the passport. It's then used with the passport data to generate a commitment in a um Merkel tree that we maintain.
Chile is right. That was you. Okay. In the lead again. Um and so we use this Merkel uh tree to effectively let you register on chain.
uh so that in the future rather than having to verify or prove once again that you have a valid passport you can instead just prove that you know a secret that leads to a commitment that happens to be in the tree. So these subsequent proofs are um much cheaper to generate because we use Poseidon hashes instead of these um more complicated hash functions that these issuing countries use for their IDs. And critically, this allows you to create multiple disclosure proofs in the future that are not linkable to each other, which we wouldn't be able to do if we didn't have this dream. And so once we generate these proofs uh and these uh uh ids, uh we verify the proof on chain. We verify that the nullifier hasn't been used before.
And again, we add that commitment to this Merkel tree. And so once we've done that, Switzerland is right neck and neck 55. Um once we've done that, we can we can start disclosing things. And the way this works is DAPs can uh generate a QR code which the app can sign that encodes what the DAP is requesting. Uh in this case uh it was requesting that um someone's age was over 18 and that they were not on the OFAC list.
And then if the user feels comfortable revealing that they can press prove and they can generate an UDK proof uh that can be either verified offchain or even onchain so that it can be composed with some smart contract logic. Uh and if the DAP were to ask for very sensitive information then the wallet would would warn you. In this case this isn't really sensitive but I threw in that screen just to show you guys um how your data is protected. So if someone were to ask for your full name, your birthday, and everything, we would have been like, "Hey, are you sure you want to disclose this to the staff?" So pretty pretty pretty slick.
And so what's going on over here? Brazil is right. Who was first? 65 or maybe 76. Either way, I think you're one point ahead.
And so once we get here we verify the actual ZKP that's proving the statement that uh you want to disclose. Uh and then we are also doing a Merkel and conclusion proof that proves that you know that secret to that leads you to a commitment that is in that onchain registration tree. Uh and then optionally each DAP as we call it can also have its own nullifier. So users can only perform this step once. So, if you're using this, for example, to do a civil resistant uh airdrop, uh then you would want everyone to only be able to do their airdrop once.
And so, you can have a a per application nullifier or per action nullifier. And critically, if you look at how this nullifier is derived, it's not derived from your passport data. And that's really important because that's what guarantees that unlinkability between these different proofs. And so, you can, for example, go and prove your age to some um dating website, you can then go and den yourself uh some airdrops and no one will be able to um um link those two actions to each other. And that's really really important for your privacy.
And critically, even your issuing country won't be able to see uh what actions you're performing. They'll be able to see that you registered, but they won't be able to see what you're actually doing once you've registered. And that's really important. Okay. So, how does all of this work?
Mexico was right. Two points in the lead. Uh, I don't know. I think it's still yours for the taking. I guarantee you there are more than two countries left.
But, but you got to you got to act quick. Um, okay. So, how does all of this work? We've got the passport, of course, the the mobile application that I just showed you uh scans using the NFC reader. We've got that secret that I mentioned that's important for maintaining your privacy.
If you were to lose that secret, that would kind of suck. So, we automatically back it up for you in the cloud using uh your keys store um iCloud backup um or your Google drive per application um in a storage area which is pretty secure. Um there was a question earlier about client side proving. You know, we worked really hard to do this client side initially and sadly there are a fair amount of countries out there that use fairly expensive uh hashing functions and fairly expensive signature um schemes uh that would be that are ultimately too expensive to prove on your phone. Um and so we accelerate these proofs using a TE.
Um but everything is open source. So you can go and verify uh that the mobile application only connects to that TE if it uh verifies the atestation uh that it's running a unmodified image and then you can look at what code gets compiled into those images and you'll see that your uh sensitive data gets deleted as soon as these proofs are created and so you can have a lot of trust in this whole system uh that nobody including us can see your sensitive ID information. And so once these proofs are generated in these TEES, they uh can again be either sent onchain uh or they can be sent through an SDK um to the application that was requesting them. In the onchain case, um we maintain the registry on Cello and right now these proofs can be verified only on Cello. Uh but we're working hard to get the state route of this registry tree uh propagated out to all Ethereum chains.
Um Cell has become hell too recently and so you can actually do this trustlessly yourself but we're working on making it easier for everyone. Um because we want self to be a utility for all of Ethereum. Um and critically uh because we don't have a civil problem which is pretty neat. uh we can pay for your gas when we verify these proofs on chain and we're happy to do that because we know you can't scam us because you likely only have a small amount of IDs. Um so this is the high level architecture.
Um we have a really nice SDK as well.
Oh, is it here twice? Okay, it is Argentina. Um but you're right. We won't give you the point because it was here before.
Oh yeah.
Well, we can still subtract one and that way it'll be a tie, which makes this whole thing a lot more exciting.
I like Yeah, I like the call out that it's a civil attack. Um anyway, we have a really nice SDK. Uh and so if you have a use case, uh maybe you are doing an airdrop and you have uh issues with civil attacks. Uh maybe you want to incentivize people to join your protocol and um you don't care if they bring capital or not. You just want them to use your protocol.
Uh maybe you have bad actors uh and you want to filter out people who are uh on the OFAC list. Um, or uh, who would have thought that nowadays you have to worry about whether or not you're speaking to a human or an AI agent? How many of you are wondering how much of Twitter now is, uh, actually written by humans? Every time I log in, I'm like, I don't know anymore. Would be nice, right, if people could prove that they in fact are a human.
And ironically, I predict that it won't be just us um, worrying and thinking about this problem. AI agents soon will also want to know if they're speaking to AI agents or humans. And so they too will be interested in these proofs. And then finally, maybe you have some kind of silly fun use case. Maybe you have a memecoin and you want to reward like all the Bartks in the world uh with some coins.
Um you could do that, right? You could create an app that, you know, requests that people disclose if their first name is Bartk and if so they can get an an airdrop for free. If not, then they uh would have to go to Bartk and try to buy his memecoin. Um you know, anything you can think of uh anything that exists on your passport front page, your hair color, your height, your um city of birth, you can effectively request as zero knowledge proofs and then you could build applications perhaps fun applications around this. Um all of this uh you can learn more at docs.
self.xyz. Uh and you would be in good company uh building on top of self uh because just yesterday um a launched um what was it?
Not Ireland, not Greenland either,
not Greece,
not Albania. Okay, I'll give you guys a moment to think about it. Um but just yesterday super super exciting news. Um AI that is right. How many points for you over there?
Three. Okay. Well there still still some more slides. Um so AI now has started doing um boosted rewards for real humans. So you may have seen a world doing this with Morpho.
Now this is available with self and a uh for select pools. Um and so you can actually prove uh that you're a human uh and then earn additional rewards um for your deposits into a so something pretty cool. This was just announced and is now live uh yes as of yesterday. Uh and then a few weeks ago anybody saw this announcement?
That is right. I thought this would be the hardest one, but apparently this was the hardest one. Um, so Google Cloud announced something really, really cool. So they announced they're they're using self for three new products. Uh, one of which is, um, really exciting.
It's a mainet faucet. Who would have thought you could have a faucet that gives you mainet tokens? Um, Google thinks though. Uh, and of course, you know, you would have a big civil problem there and you have a big OFAC problem there. And so that's one reason why they're uh excited to use self for this upcoming really cool new mainet faucet.
So keep an eye out for that. I think that's all the time I have. Um yeah, thank you so much and
thank you so much for such an exciting talk. I did keep score. Um I'm more than happy to read it out before we go for questions or you'd rather do it afterwards.
No, read it out. Yeah.
Okay. So some guy at the back with one point, some guy in the front with one point. some dude in the middle. I think that guy in a cool t-shirt, uh, three points. Um, the file coin guy, some dude, uh, with five points.
And then that cool dude at the back that knows everything, eight points. So, congratulations.
Congratulations. Come find me afterwards. I'll I'll send you the cash link. And then these are the QR codes from earlier. Maybe they haven't been fully claimed, so I thought I'd put them up here.
Does anyone have any questions?
Oh, lots of questions. Um do you use the semophur library for the stuff or do you write something yourself?
Um we do not but it's very similar to semaphore in the way that we do the uh commitment tree. Yes.
Okay. And then which zik proving system do you use to prove this?
Grow 16. So we kept it very uh vanilla because we wanted to get into production uh as early as possible. This launched at ETH Denver earlier this year and it's fully audited by ZK security uh and so you have you can have a lot of confidence both the proving system is pretty robust or very robust and you know the code that's running on top of it.
What about the trusted setup?
Uh so we did a public trusted setup on potion. Anyone could participate. Um all the information is on potion.
I have a question. How is it better than worldcoin?
Good question. Uh, you know, I think Worldcoin is very interesting and, you know, I'm a fan of what they're doing. Um, the challenge with Worldcoin is getting people in front of those orbs. Um, is a scaling, you know, challenge, right? It's a lot of people in the world and there's a lot of orbs.
This allows us to piggyback on something that people already have in their pocket um and um arguably is more decentralized, right? Because rather than trusting one um company with their orbs to provide these attestations, we're instead relying on nation states. There's many nation states that have all have their own own keys. uh if one of these keys is compromised then DAPs can just choose to uh not allow people from that country to uh generate these proofs and so in a way it's a lot more decentralized in that regard as well. So I think it's it's quicker to scale to billions of people and uh arguably the federated approach is a little nicer.
Yeah. So you said you mentioned different nation states and you know there are nation states that are less trustworthy when it comes to their national documents
and I know that CO has a lot of experience in like Africa, Latin America where the corruption is a bit like higher than Switzerland for example.
So I'm wondering like how do you deal with like passports that have been issued because someone paid some amount of money or you just ignore it because it's still better than what we have today. Yeah, I mean I think maybe a bigger problem might be that there are people who have citizenship from multiple countries, right? And suddenly they might have multiple um passports. Likewise, if you have a biometric ID uh and a passport, maybe you could register twice. Uh and initially we thought, okay, this seems like a problem.
Maybe we'd want to solve it. But the more we looked at it, the more we realized, well, one, it's significantly better than what exists today. Uh for a lot of use cases, it's probably fine. someone claims an airdrop twice as long as he can't do it 10 times. And then secondly, Vitalik had this really nice post where he he talked about how he wants these systems to allow you to register more than once as long as it's not too many times.
And that is because he wants people to be able to have synonymous accounts still. So, you know, if Bartekch has another pseudonmous um um you know, account of some kind that he tweets from and he wants to use that to claim an airdrop, then he could uh if for example he registered twice with his, you know, ID card and his passport. And so, as long as it's hard for people to register 10 times, then we think that this actually provides a really nice service.
We have time for one more question. Yes. Uh you mentioned uh the offax list probably a dozen times. How does the attestation actually work? Like who who and what do I disclose to?
So that at the end I end up with a trust that no I'm not on the list. So to prove that you're not on the off list, we maintain um a a root of Merkel tree where we put the whole of effect list into. Um the effect list actually is composed of different ways to identify people. So we actually maintain three Merkel lists, some based on your names and date of birth, some based on your citizenship and passport numbers. Uh and ultimately what we're doing is we're doing a ZK exclusion proof that you're not in any three of these OFAC lists.
Um and so again the root exists on chain. You do a Merkel exclusion proof and then you can prove uh u you can then verify that proof against this route on chain. And once you do that then again you can compose with smart contracts. Say that you want to deposit money into a DEX or a lending pool and you want that pool to not allow um you know OFAC sanctioned individuals from participating then you could then verify this proof as part of the as part of the deposit logic
the root of the state. Yes.
Awesome. Thank you so much for the amazing questions. If you do have any more other questions, you can meet Mik at the other side of the stage. And let's have one more huge round of applause. Thank you very much.
Thank you.
Automatic transcript — names and jargon may be misspelled.