New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Kohaku Updates | Kassandra (Berlin Ethereum Day, June 2026)

Berlin Ethereum MeetupWed, Sep 9, 2026, 12:00 AM

Kassandra (Ethereum Foundation) walked through what privacy by default on Ethereum means. The Berlin Ethereum Day was a one-day event held on June 15, 2026, during the Berlin Blockchain Week, bringing together speakers from the Ethereum Foundation and the broader FOSS, privacy, and security ecosystems to explore the future of Ethereum and self-sovereign technologies - from technical direction and core values to the challenges and opportunities ahead. Future Meetups and Events: https://www.meetup.com/berlin-ethereum-meetup/ More information on the speakers and the agenda: https://berlinethereumday.com/

Transcript

I'm cassandra.eth, kzg.eth, anything with a K you can call me Cass. Um and uh I work on this Kohaku initiative inside the EF. This is something uh group inside the EF as well as well as a bunch of uh grantees uh all working together on um improving R&D around the access layer to make sure that privacy is a first-class citizen for for users in current Ethereum and of course in the future Ethereum.

So making sure that it's possible to have a private user experience on Ethereum. Um so we want privacy by default on Ethereum and that's what this talk is about. I'm going to try to move through my slides. In the age of AI I decided to have the most ugly possible slides and most boring slides ever instead of making them pretty for you. Um and I'm hoping to move through this pretty fast so I can do some live demo here cuz the real goal is to show you guys how you can actually get privacy on Eth L1 as soon as possible.

Um we'll see if that works. Okay. Um So Kohaku wants to bring privacy by default for Ethereum users um specifically at the wallet layer, right? Users using their wallet um just naturally get transaction privacy. This is what we want, but how can we do it?

And of course it's really important to remember uh most of you here already know I imagine you have context you've used Ethereum wallets met most people. Um there's almost no transaction privacy on Ethereum today. Certainly none of it is embedded by default in any of the classical wallets you might use. Um the users who do go above and beyond to use the tools that the infrastructure we have deployed for privacy um to to actually achieve some transaction privacy themselves is an extremely small group um something less than 1% of all transactions are actually private on Ethereum today. So, how can we improve this?

Um what we need to do is we need to innovate on the Ethereum wallet and its de facto standards. So, um we have some enshrined standards and some that are more kind of implied by the user experience of the of current wallets and some of these really need to shake up and we need to change them. For instance, most wallets today we actually think of a wallet almost as an address or a wallet is maybe like a bag of addresses, but uh when you when you interact uh with Ethereum, you usually have some sort of toggle where you toggle between addresses and then at each address you see balances and you take actions and you think of this address as something like um a name space for you as a user. And to me, this is one of the biggest things that we need to disrupt because um address space can be thought of actually as something very low level in Ethereum now. And even on Bitcoin, you have the idea of a wallet is some aggregation over address space.

You have UTXOs in many different addresses, but you see the aggregate balance and you just operate on your wallet. We need something similar like that in Ethereum today and we can have it. So, um uh yeah, we need to shake up the Ethereum wallet de facto standards and we need to enshrine some new standards that make privacy something more general, something more standard, something that all the wallets are implementing. So, it's a big job. We're working on it.

I want to talk about um three things today quickly that that that we're working on and I want to mention um privacy on Ethereum, we recently have decided to think about it in three core pieces and we're going to focus on one piece today. But just to name them, there is privacy of rights. So, the actual data that gets written on the Ethereum blockchain, we want to make sure that that uh has some obfuscation. It uh doesn't uh doesn't necessarily link uh certain users to to their activity and link their activity across different transactions and so forth. So, this is the privacy of the stuff that's actually written on the chain.

This is what we're going to focus on mostly today, but there are two other categories that are very important for the Kohaku initiative as well. This is privacy of reads. So, this is the idea that when you ask for data from the blockchain, just not writing but just reading, seeing different balances of different addresses and so forth, seeing the state of different smart contracts, that this can be done privately. So, that when you ask an RPC, um is there a way that the RPC can serve you that data without knowing what they've served you? Um or uh uh things of this nature.

So, privacy of reads is also uh equally as important as privacy of writes. And then finally, something similar to writes but not exactly the same, it's a it's a third um let's say a third branch of privacy on Ethereum, would be privacy of let's say um network-level privacy or um private propagation. So, this is about when you actually try to communicate, when you send the transaction you want to write, or when you send the data that you uh your request to read some data from Ethereum, can you stay private? Are you leaking your IP? Are you are you deanonymizing yourself in this process?

So, all three of these layers are really important for privacy, but today we're going to focus mostly on privacy of writes. And in my view, this is like a solved problem from a technical level. We just need to patch together the UX to make it legible for users. So, I want to show you uh how how we can uh the little bits of standards we can uh organize around so that so that we can have this and then talk a little bit about how we make it legible. Okay.

So, three things I'm going to focus on, key derivation, transactions themselves, and then this question of legibility. So, key derivation. The one very simple thing, one piece of infrastructure we have on Ethereum that we want to leverage as much as possible, are these quote and quote shielded pools or uh mixing protocols. So, these are protocols like Tornado Cash, Railgun, privacy pools, and they allow you to anonymize your funds, any tokens you might be holding, by placing them uh into a shared pool. Lots of people make deposits into them, and then you break the link between the deposits and the withdrawals with a uh zero knowledge cryptography.

So, you can withdraw from this pool in such a way that nobody knows which of the deposits this withdrawal is linked to. So, these protocols are awesome, and you can already use them on Ethereum today, but very few users are using them because you have to stitch this together yourself. This is not baked into your wallet. So, the main work we're doing at Kohaku, we're building the Kohaku SDK, um and this tries to make it really easy for wallets to integrate these protocols. And alongside this, we want it to be a standard to be able to find the assets that you have inside of these privacy protocols.

So, one one piece of friction today is if you want to use something like Tornado Cash, you need to actually hold onto these secret notes yourself, and you have to deal with the manage these secrets on your own separate to any other wallet infrastructure you might be using. You also have to make sure when you withdraw, you withdraw to a fresh unlinked account, and that you never, you know, uh uh deanonymize this account by linking it back to your other more public accounts. All of this is something you as a user have to do by yourself. Um so, one key simple thing we can do is when you have a wallet seed phrase, already a standard on Ethereum, we just need a standard path on the derivation path to find the secret material for the different privacy protocols. So, that if the the main goal of standardizing something around key derivation for privacy protocols is the idea that let's say you are using this wallet, it integrates Railgun and Tornado Cash.

Um you anonymize some funds, you have some funds in there, you have some ETH and other tokens inside of these protocols. Well, then you I don't know, lose access to your wallet, you start up on a new machine, you take your seed phrase for your wallet, and you plug it into a completely different, let's say, wallet client, and still that wallet can open, uh you know, take the seed randomness, derive the secret information from there, and voila, find all your privatized funds in Tornado and Railgun right when you sync up your wallet on a new on a new piece of software. So we want um the the secret data for these different privacy protocols to be enshrined in such a way that every wallet, when they take a seed phrase and they know where to look to find your public funds, to find the different addresses you might use uh as uh just like public addresses, it'll also find all your private funds, all your notes and UTXOs inside these protocols. Okay, I'm going way too slow, so the demo's probably going to be off. Let's see.

Um Key derivation, that was the first piece. Next piece, and this is what I think uh what got me involved in this Kohaku project was um the uh I got really excited after the release of 7702. Um this is an upgrade that allows you to make EOAs act like smart accounts on the fly, and this is what made it possible for us to have to dream of an Ethereum UX similar in simplicity to the one you have today, and just as general. When you use some browser wallet, you go to a front end, you decide you want to interact with some protocol, and then your wallet simply, you know, figures out uh the payload and the signing and the gas for you, and you just do the interactions you want to do. That you can have this exact same feeling on Ethereum, but actually you can do it in a way more private way.

Uh and this is now possible with uh with the types of tools we have available. So, I want to talk about how you can have like fully private transactions, but still do generalistic things like swap and mint NFTs and stake your tokens and I don't know bridge to another network, um but do this in a much more privatized way. So, the main idea is to use the 4337 standard. So, we use the um uh we don't have fully in-trying to account abstraction on Ethereum, but we have 4337, which is uh basically something close, let's say. Um and we want to build user operations so that you as a user, you just want to swap some tokens on Uniswap.

You want to take some ETH and you want to swap it to buy some get some DAI, I don't know. Um when you do this, if you already have some funds, let's say you have some ETH shielded in one of these shielded pools like Railgun or Privacy Pools or Tornado Cash, you can instead construct a user operation where you will remove the funds from the privacy protocol into a fresh address also where this where the secret to unlock that address is also derived from your basic seed phrase. You will then synchronously after that be able to append arbitrary calls like the swap you want to do on Uniswap. So, the funds will flow from the privacy protocol into the fresh address, and then you'll do the swap on Uniswap, swap your the ETH that falls in there for DAI, and then finally, you'll pay the gas, you'll you'll pay the fees for gas back to the relayer with some privatized funds inside of uh Tornado Cash, let's say. And so, all All this can happen synchronously under the hood, so you just feel like you're swapping on Uniswap.

You could now dream of a UX where you're using a browser extension wallet, you say swap on Uniswap, it says, "Do you want to use private tokens for this?" You click yes, you click swap, the thing happens, and then when you look at your balances for your wallet, you see that you have some die and a little less ETH. Um but under the hood, you have like fully anonymized what you've done, and the only thing that happens is there's this new account that uh the only public link is that some account received some ETH and swapped it for die, and paid for that uh with Tornado Cash. So, this is all completely possible now. So exciting.

Um nothing stops us from doing this today on Ethereum, but we don't have it. And the reason is because we need to shake up a little bit this user experience. You have to now imagine, right? Ev- if you want to truly be private, now every interaction you're going to do with one of these dapps is going to come through a fresh account. Or maybe a few times if you're doing something long-lived, um you might have to reuse an account to uh let's say keep topping up a certain position if you have a collateralized debt position on MakerDAO.

Um so uh but you're going to have funds scattered across many, many different accounts, and so we no longer are going to be having this model where you're going to have a drop-down and think about each address as an account that you operate from specifically. Instead, we're going to have to think about a a more uh robust uh um a a a wider wallet abstraction, right? Where uh where you just see the funds in your wallet, and if you want to know about this low-level address details, you can, but this is now considered very technical detail. But of course, if you were to take your seed phrase and, you know, go to a different wallet, you'll still find all your funds, right? This is the idea.

This is possible. Um nothing stops us from doing it, but we need to make it legible for users, right? There's a lot of technical detail here, so we need to wrap it up in a way that makes it simple and achievable for users, but we also need to expose enough data for users that they understand what they're doing. They know about the different trade-offs that are being made. For instance, how private are the funds that you're about to use when you do this swap?

For the longer you sit inside of these shielded pools, the the more anonymized your funds are. They're almost trivially de-anonymized if you were to simply put them in the privacy protocol and then 1 minute later pull them out, right? So, things like this are going to be really difficult user experience challenges to figure out. So, yeah, how much how anyone tell me how long it has been so far? Okay, yeah, okay.

So, um now I want to show you how we're we need to do this today, right? So, let's just start doing it right now. So, I'm building a CLI tool. It's just a personal project that consumes the Kohaku SDK to show you that it's real, that you can use it to build these user experiences with these privacy protocols and make it simple and possible. So, here we go.

I'm going to use my CLI a little bit and show you what's up. So, I was going to show you first that you can Okay, you can just create a new wallet. So, let's um create. Okay, we're just creating this wallet new wallet. I'll make a password.

I would save this seed phrase. And there you go. You've got your wallet new wallet. It's created. Um we are not going to sync this wallet right now because uh it would take a few minutes.

The first time you sync with privacy protocols, it takes a few minutes. So, instead, we are going to use another wallet that I just created a few minutes ago. Um so, let's check out the balances of this wallet first. Okay, cool. So, I can see my different wallets.

I'm going to select ETH demo day wallet. Put in my password. Okay, cool. So, we've got this CLI based wallet. It's based on just a single seed phrase that you need to back up.

Um we've got some errors in here. This is a fresh demo by the way, right? I'm working on this as we speak. So, here we go. We're looking at our balances.

So we can see just like the total aggregate in our in our wallet in our public in public funds. And we have 4.2 ETH. We've got 125 USDC. We don't have any money in Railgun.

We don't have any money in Tornado Cash. And then if we want to see a breakdown address by address, we can see that if you put the remote verbose flag. Okay, let's deposit some funds into let's shield some funds. Let's put some funds in a privacy protocol. What are we going to use first?

Someone call it out. Which who what do you want?

Tornado.

Okay, so we just say shield. Okay, great. So, now we are shielding some funds. We're shielding some ETH, but if you wanted to shield a different token, you just pass like a token argument. Uh opening up the wallet.

It's going to ask me how much do I want to shield? I'll shield Let's shield 0.2 ETH just to show you how this works. Um and it's I need to pick like the source account to do this from. I only have one, so I'll do it from there.

Okay, now I'm going to have to do this in two parts. The log is a little actually a little bit wrong a little bad because we're going to do two deposits into Tornado into the 0.1 uh Tornado pool. So we'll do the first one. Okay.

It's going to take a second with the chain. Um So, yes, the goal here is to as quickly as possible show people that you can actually interoperate with these privacy protocols. You don't have to be a cryptographer yourself. You don't need to stitch too many front ends and and different like uh things on onus on the user themselves to figure out how to use these privacy protocols correctly. Um okay, we want to do the second one.

Um and just trying to make it a little simpler to see how you'd really use Ethereum in in a private way. Um because everyone knows about how you could do this, right? But how many people actually are doing this? A raise Raise your hand, how many of you are interacting with Tornado or Railgun with for your for Okay. Pretty cool.

Nice. You guys are cool. Um All right. So, we shielded some funds. Let's just check out our balances again.

Let's Yeah. This. You can kick me off the stage whenever cuz I could go forever, too, but uh Yeah, you got to be done almost? Okay. Uh Cool.

This is going to take a second again. We're going to see the error again. Yeah, I got to fix that. Um okay, great. And we can see Oh, nice.

Now I have a little bit less ETH. I got some money in Tornado.

[applause]

That Nick guy. Come on. It's not too important. We're not done. We're not done.

This is We got to at least do a round trip, right? Um so, uh also note that up here we could have checked out the transactions. You can see, you know, this is actually happening on Sepolia right now. Um but let's just move on. We're almost done.

So, unshield, right? Now we want to take some funds. Okay. All right. Mhm.

I spelled broadcast wrong. It's cool. So, this is the part I'm really proud of. Um so, first of all, it asks, uh we just want to unseal some some funds we have in tornado, and where are we going to send them? Well, it just right away says, "Well, do you just want to generate the next public address on your account?"

Yes, I do. So, let's let's unshield there. Okay, we have to sync a little bit with tornado cash to make sure we can do the make the zero knowledge proofs. We got Um let's unshield 0.1 ETH.

All right. So, we've done a lot of work at Kohaku to make sure that you can utilize all these privacy protocols without relying on their relaying infrastructure. So, most people use privacy protocols, but in order to relay withdrawals, you use some relayers that are run actually by somehow by people specific to that protocol. And if that infrastructure goes away, then uh so uh then so does your ability to transact privately. So, we're making sure that you can use all of these protocols with the classical 4337 mempool instead.

So, as far as I know, this is like first of its kind. We're the only ones relaying tornado cash transactions in this way. And the other thing that's awesome about this is that then you can append arbitrary calls after your unshield and do things like I was saying, swap, bridge atomically after unshielding, and we pay for we pay gas to the relayer uh directly with privatized as well. So, this is all really cool. Um All right, we're building the proof.

Taking long. What's going on, bro? Um So, as I was saying, we are making that possible on all three protocols. So, this is like the the dream is to eliminate one of these uh potential choke points or points of failure or uh or or censorship, which are like the proprietary layers. Um Okay.

There we go. Yes, I would like to broadcast this. So, now I am sending a 4337 user op bundle to Pimlico, who is then going to bundle my transaction and and do the withdrawal on my behalf. And we should end up with not exactly 0.1 ETH in in the fresh account.

Maybe just slightly less. We'll see when we check out our balances um because we have to also pay for the gas. So, okay, cool. So, I want to show you that it worked. So, first thing, let's let's open up this transaction link.

You can see that it's a account abstracted transaction. There we go. I know I got to go. All right. Supposedly Oh, okay, here we go.

You can see we've done this AA transaction, right? So, we've done something through the 4337 mem pool. And we have Let's see if we can find the Yeah. And we have 0.097 in this new fresh address.

So, as we can see, now we can see the totals, public totals. We have some USDC, we have some ETH. We have a little more public ETH now because in this fresh address in the index one on my wallet, I now have received a little bit of ETH. And we can check out that address here. And see that the it has no transactions it's ever done.

The only interaction it has is this interaction with this 4337 bundle. And now it's holding ETH and could do some transactions privately. So, this is where I'm at. I'm working hard to make this more private private Ethereum transactions is possible. You should all be experimenting with it.

We all will be soon. Thank you for your time. Goodbye.

[applause]

Automatic transcript — names and jargon may be misspelled.