Public-Private Hybrid Rollups by Adam Domurad | Devcon SEA
Devcon·Thu, Oct 9, 2025, 12:00 AM
Speaker
We posit that it is a best practice that rollups have privacy capabilities. We'll focus on zero-knowledge and its role in enhancing privacy and how to deal with the need for public state for shared use cases. We'll delve into the interaction between public and private execution environments, detailing how such disparate execution environments can be combined. Speaker(s): Adam Domurad Skill level: Intermediate Track: Layer 2 Keywords: Zk Rollups, Token bridging, Privacy, best, practice Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[Music] [Music] hello everyone um yeah as was mentioned I'm Adam dad from ASC I'm a Staff engineer uh Sal at deap as we say in Thailand or others say in Thailand and the talk today is public private hybrid rollups what I think a lot of people consider the next ethereum Frontier here I don't think this is just people working on privacy I think a lot of projects realize that privacy is a real problem in the ethereum space and that in order to protect users in order to attract more real world use cases privacy is absolutely critical and there's sort of a story to be told here um back in the day steam was using Bitcoin for transactions and a lot of the problems that they had were related to gas fee spiking the volatility of the price of Bitcoin and we at here at ethereum have done a lot of work to try to get a good user experience on ethereum I would say the current Frontier of ethereum is very much scaling and we're almost at the stage where we can say hey organizations look over here we solved scaling e theorem is great but basically what I would say would happen is that they kind of do the same toy experiments that they've always done done real business stays where there's real privacy I think the difference between the Steam Bitcoin story and today is that back in the day Bitcoin was kind of considered private you have pseudonyms you don't have you don't have all the things like chain analysis that collect all these touch points and I would say that today it would be a real risk to do Mass business on chain and you know you think of v and he buys a silly game and then you know suddenly it pops up on Twitter that's like an annoying use case or annoying situation but you can think of much more dangerous situations where people's entire net worth is being tracked so at Aztec we kind of have this definition Mike at azte came up with it I really like it it's ethereum is an open system so in an open system you are broadcasting to people there's a minimum Mark you could say that you are at the very least singling an intent to do something and our gold standard at Aztec is that is all you're revealing about your intent when someone looks at the blockchain and all that they see is that someone did something in some state in some function of some contract I would say that's the highest level of privacy that we could hope for in ethereum and I I'd say ethereum needs privacy I I think I wouldn't disagree with our current focus on ux and scaling but I think it's kind of known that privacy is a big problem that if we want people to work on ethereum do real things you know for the average person you could every so often withdraw to coinbase get yourself in a new EA and that gives you enough privacy but that that's not a great situation to be in and ethereum ethereum has its tradeoffs in terms of priorities it has to balance Innovation speed and scope and basically where Innovation Happ s right now is with layer twos or rollups which we've got a great talk on the definition of but I'm just going to stick with the term rollups and we need to lead the way with private rollups and just a quick caveat privacy is a very large topic and we do consider it holistically at Aztec but I won't be talking about for example which jurisdiction to about uh when you're deploying your app and you need to have compliant privacy we actually have our amazing Crypton native legal team here they they're big privacy Advocates and privacy Advocates very rooted in reality they uh they have some very exciting meetings with governments um talking about privacy in ZK and they're happy to talk about real world deployments I'm going to be focusing on the technical matters and uh sort of the journey we had at Aztec is um well Aztec started with wanting to do bonds on chain and quickly realized that no one wants to do bonds where all of their moves are tracked and that sort of led us to needing privacy and doing privacy on ethereum and there's sort of like the evm model doesn't necessarily work nicely with privacy uh what does work nicely with privacy this is sort of the zexi model and I think all private chains essentially use a model like this and this is sort of taking a step back because ethereum originally moved away from this these Bitcoin style notes or utxos and moved to um you know an account model an account model makes a lot of sense for public State because um if you're there sort of uh a race condition if you're trying to work on a note and your intent signals a certain note while things are happening in a shared matter and sort of these These Chains that have public state with notes kind of have limitations on what you can do in the same block um essentially because because of the limitations of using notes for public state but actually for private state turns out Bitcoin has has near the right model uh the missing pieces are I mean I say nullifiers in ZK it's basically ZK uh you can't really have nullifiers without ZK so the idea of a nullifier is that okay we have our chunks of money that's maybe a very easy way of looking at what a note is or a utxo and you want to use in some way a chunk of money it could be data but just for an easy example say it's chunk of money and you can only use it if a nullifier doesn't already exist and what is a nullifier it's essentially a relationship mathematical through a hash function and only you really see whether a nullifier exists for your note if and you provide a ZK proof um so sort of ZK in the sense of actual zero knowledge because you want to prove in your transaction that um you have emitted a nullifier maybe for a note you're using and that also that nullifier uh corresponds to your note but you don't want to reveal anything actually about your note the way that this um this bar of something happened is achieved is through the fact that actually no one looking at the system knows which notes are active which ones have been nullified so to someone looking in it's just hey this note was created here you don't know who owns it this nullifier was emitted here you don't know which for which note and this is sort of the underpinning I would say of private uh smart contracts and computation and for a you know practical example that isn't money um we have a example in our repo at a Tec with a card game and we kind of have like this cute strength and point system and that's sort of the user data and then everything else I would summarize as being uh important for the protocol and then this um then this is encrypted only you can see it as a user and on your own device you can't compute with it okay so the the premise is public private hybrid rollups and really we would love everything to be um done privately as you know as much as makes sense sometimes you do want to reveal stuff truly to everyone but we're going to for this talk we'll use a narrow definition that anything that doesn't fit into this idea of something happened you're revealing the amounts of transactions that we're calling public that means any other information that's not just you know the parties transacting if you send someone a note you're encrypting it in a way that they can see it but any anyone not part of the peer-to-peer transaction gleans information and can everything be private I I think there's there's you know there's answers on both sides um so if you talk about it very strictly I alluded that ethereum when moving to uh smart contract computation there's a reason they move to the account model and what we're talking about is taking a step back to more of a note model so kind of but by definition we are undoing some of the benefits of what enables multi-party uh systems like Unis Swap and and it's for a good reason because privacy the only real way to do a privacy is that the users execute and prove their own transactions and um particularly I'm going to focus on ZK here I think it's the most mature Sol privacy Solution that's can really take the world's transactions okay but uh so at Aztec actually we have both we have uh we also have public State and sort of this butt is okay something happened we considered the gold standard but it's often okay to say okay someone did the specific trade but we don't know who there's plenty of times that's not okay if you're trading in such size that well maybe you tip off the market or maybe you're the only person who could trade such size so actually you've revealed your identity then it's not okay but we take a very practical standpoint we have a a public um part of our chain on Aztec because it is we definitely believe in the gradients of privacy and then you can say you can make an argument for actually yes that you can get privacy until the last M Mile and do public shared State I think the easiest way you can consider um okay you may maybe you can't do something like Unis swap like a fixed function Market maker but you could have a signal chat and you could post prices on that and at least from the chain the the chain still has the something happen property and only your peers that you're advertising to know the details and then there's obviously other privacy Technologies there's T's FH on the horizon although still very slow that can get us to this property um i' say mostly because there there's always a trade-off here when you're when you're dealing with multiple parties and you want privacy okay so what would a hard no world be I mean a hard no world really is sort of the status quo right now like or the chain is being tracked more than ever and there there's little incentive for a business to do stuff that reveals their business Edge on chain right now because and we see cases where user safety is compromised because their actions are onchain really the good news is really there's no hard no for holistic privacy on any chain ethereum did not start out as a private chain but here we are at Aztec building a a system for holistic privacy but that being said that there's many of these rollups even the ones that co-opted the term ZK I mean they use ZK technology but really they're just validity proofs and especially looking at you looking at Z ZK sync I I I mean I love the company but their their marketing is muddling things by using the term private and associating that with ZK which is private but really they're just a validity rollup and these chains make basic privacy hard and holistic privacy very hard still and okay so what's the middle ground and mostly the middle ground that this is largely the way you can think of the public part of Aztec is that you have some private identity you have portion of your transaction that come from the private World namely you have private account abstraction you have um you know you can start something like in a card game example you may unilaterally work on your deck in hand and you're able to do that privately that information is private and then you want to kick off a public event which would be you know revealing your card so other people can work on um can play the game and um so yeah as I said identity is always private on Aztec and I think that's that is something that any chain can have private account abstraction as long as you're comfortable with users doing client side proofs which is something we take very seriously we like having we like to build things that actually work on commodity Hardware we go through pains to make sure that our proving system is practical for the people that are using stuff like phones because the reality is that that is the only way to do real privacy is that you know not only is there the ability to privately uh approve your transaction but that you're able to do this in a way that works for everyone and another important thing we do attec is that we have the same smart contract framework that works in public and priv private land and we do nice things like being able to share States being able to use the same semantics being able to as cohesively as possible work through what are very different execution environments because um the we we try as much as possible to abstract the fact that these are just running on very different devices the public part is proven by code by B code and it work works on secret ERS whereas the private State can only really exist on users devices and transactions can be a mix they typically just if you think about it logically they kick off from private State because well that is the user to just encode their event they have to execute everything that is going to happen in private State the sequencer can't execute that and the whole thing either succeeds or revers so so if you start something out in private State and you call something in public even though you executed you're the only one who can execute that state luckily to just revert that state is to just pretend your transaction didn't come in and the way we execute this so we had a very successful noiron we had V there it was super energetic I'm super happy about it uh we have the language no which sort of you can think of it as I like the term circom Plus+ it has everything that circom can do in terms of create circuits um I think uniquely we also uh translate to a more of a zkv m b code as well and it looks like rust so it's code that developers are used to you can kind of think like targeting commodity developers uh the and um and on top of that it integrates with a variety of proving systems so you could we have the rollup itself we in inir and I think this is sort of the the main way we're making sure this is ready for complicated use cases other rollups other other people in web too uh we're very much making Noir as a public good and so this is sort of the the proving scheme in a diagram for the client side where we we kind of just verifi we have this folding scheme it compromises like it has a bigger proof size but it tries to be the the fastest thing possible um proving systems are getting faster and faster but still we have we want to work hard to make sure this works on commodity hardware and then the folding is recursively verified in the rollup circuit also with Noir which actually uses a different proving scheme we call Mega honk okay so just the last bit um I don't have as much to say here I think this is sort of I I would say that you get a lot from the scheme I described but there is that last Model I think we do want to get to the point where okay you want to use something like a DEX it should be as private as possible and I think we can do even better by combining Technologies and sort of having multiple layers here the gold standard is to do everything with privacy Primitives uh all of them have trade-offs but using them together I think you you can get as far as possible to The Last Mile result and here we have stuff like multi-party computation uh definitely we have people in the Aztec space building um building stuff like a multi-art party order book and we have fully homomorphic encryption which has caveats it's slow right now but some something definitely to look out in the long term we have T's and I think I would just lump in the same category uh you know app specific rollups like this Bank diagram here I think they're kind of the same thing like once you have um if you're willing to have someone centralized doing the matching and you could St that in a te I mean that has good trade-offs because you're no worse if the tea is broken um then you can certainly kind of keep working in the private model and then you also have uh you know just like okay you could use signal and you can find peer-to-peer people to work with um and that is completely offchain um so yeah thank you for listening that's sort of um the point of the talk I guess is to just let you know about the different techniques that um can bring privacy to ethereum and it's sort of Mission critical I would say um I think it's the next big thing everyone should be worried about thank you so Adam I'm just going to direct you over here okay all right cool so we do have some live questions coming in um oh there we go we will be able to see that so I can tell public state from private but can I also do the reverse Shield to private do you want to take an answer for this oh yeah sure so yeah as I was saying the um so you have to think about the mall here the private state is operating locally so what you're able to your intent also encapsulates everything executing in private so doing the reverse kicking off something from public well you can certainly do that but what the usual pattern is that in public State you give yourself something like a permission that's going to be privately uh verified because to operate privately you have to react to that and do stuff Bas on your own device the sequencer can't do it for you all right cool so if anyone have any live questions feel free to scan the QR code over here and the question will pop up on this side I think we can give it another 20 seconds to see if there's any more questions oh there's yeah the uh so the word hybrid the reason I'm using the word hybrid in the presentation title is because we have a we have a well first of all describing a rollup that has both private and public parts and and how we can cohesively work those together and then also sort of um stradling the gradients of different privacy techniques and kind of varieties of um full privacy and I think you can combine these techniques you can have client side proving uh client side proving is sort of the the main part of privacy you don't need you know you could have privacy without a ZK validity rollup you can just have um for example like the ZK apps on ethereum and the idea is that there's any any chain that has public State and uses privacy is a hybrid um but there's sort of more and less fistic ways to do that
Automatic transcript — names and jargon may be misspelled.