"Public Address Parity" by Alan Scott // Ethereum Cypherpunk Congress 2
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] All right. Sick. Yeah. So, I'm Allan. Uh, I've been a contributor to Rail Gun for about 5 years.
Uh, for people who don't know, um, we're going to kind of go through the TLDDR of what the hell rail gun is anyway. So, just, uh, hang tight for that. Right. So, um, rail gun research started in early 21. Um and the whole goal for it was to pave a path forward for a more feature complete privacy mechanism uh for DeFi.
Uh at the time there wasn't a lot of really good privacy features uh outside of mixers and centralized exchanges at the time. Um and further the reality of the time was that decentralized solutions really lacked uh features uh and this made them really unappealing um to people who wanted to use them. And so ultimately sexes sort of became the uh deacto mixers of the space. So, uh I guess beyond that, um one of the uh the goals was to make a privacy mechanism that didn't compromise on security and didn't require you to leave the ecosystem that is the chain uh that you're already using to m or uh maintain some sort of esoteric note mechanism uh by yourself. And uh the reality at that time right is a lot of situations were were just that right a lot of protocols were and are still doing this to this day right so tornado cache uh very famously uh back in 21 came up with tornado cache nova which was for arbitrary deposit sizes and uh mechanically what that did was uh require you to bridge to xdi via omni brbridge uh which raises a lot of security questions at least for people like me uh because bridge security and livveness is kind of a big trouble in the space and has been uh since 21, right?
So, we didn't want to do any of that [ __ ] Uh, it would also have uh the protocol have like proper key structure, right? It wouldn't have some notes uh generated in adap front end that you would try to store in Evernote or something like this and hope you didn't lose them. Um, and so rail gun deployed and uh it was okay. Uh, but it wasn't great. Uh, in fact, this is a rail gun transaction right here.
And in 2021, a rail gun transaction, anybody want to guess how much it was because I'm sure you can't see it. He has like $180 to 250 bucks when gas was 45 GU. Uh it was extremely high. Uh and this is a transaction right here from today. It's 16 cents.
Uh and this is all on chain. So uh this isn't all uh we won't take all the credit for this. Uh 1155 came out. That was a blessing. Uh and there's been a lot of work on Ethereum to make this stuff cheaper.
But we did a lot of work on circuits. Uh there was a beta contract, a V1, a V2, maybe a V3 eventually. We've been hardening this ever since and trying to make it cheaper, right? [snorts] Um you know, but ultimately uh the gas efficiency race was off and uh we sort of chasing this uh this so-called like public address par uh which is what we were calling it. So what the [ __ ] does that mean, right?
Public address par just means like anything that you could do in a public address, you should be able to do from a privacy mechanism. uh and have that privacy mechanism be somewhere where you can live with funds for an extended period of time, right? You don't have to take them out to deploy capital, right? Which is a huge drawback of of privacy systems, right? Because it u well the privacy of these systems is based on liquidity and piggyback off of each other.
So the larger the TVL, the better. And the only way for the TVL to go up is for there to be great features that people can use to deploy capital, right? And so public addresses can do things also uh mechanically beyond what privacy mechanisms have been able to do in the past, right? So things like uh multisig uh hardware signing right and like true access to defy and cross contract calls. So one of the first things that we talked about there was hardware uh excuse me multisig support.
Uh and rail gun architecture is pretty unique for uh a smart contract system uh that does this sort of privacy stuff. Uh one of the big key features of rail gun and the way it's architected is that the keys uh do not have to be there uh don't have to be present for snark proof generation. Right? So a lot of mechanisms uh require you to have some sort of secret present and put that into uh proof generation and that's not great. Um and so um this kind of like unique feature of rail gun makes it really great for NPC uh and uh gives you a lot of flexibility in the uh signature schemes.
And so we're just going to go back here. Sorry. And so we we've actually done this already with rail gun. We have a PC that we're going to be showing off at Dev Connect. uh and maybe here today if you guys want me to whip out the laptop uh but for the sake of time we won't do it but the way the rail gun hardware wall excuse me multisig support works is uh it leverages frost uh which if you aren't a cryptographer is flexible round optimized threshold signatures and uh it works pretty similarly to uh a regular old multisig right you have an initial uh DKG uh we do this really tricky is there anybody here from waku right now yes so we do the DKG over Waku, we gossip that uh so it's private uh which is really cool.
Some user initiates a transaction uh and then gossips that around again through Waku uh to other signers. They sign it once you get the amount of signers you execute the transaction. So uh when it comes to par it's pretty uh it's pretty damn close. So hardware wallet support also again um the uh the way that the the signing mechanism works in real gun uh keys are separate from snark proof. So this again allows you to do cool hardware support.
Uh I won't uh pre-rug people who are going to talk about this later. I think uh the guys at ZK Knox are here somewhere. Going to give a presentation and talk about the research that they did for hardware wallet support for rail guns. So go check that out, I guess. Um but suffice it to say this is uh this is pretty cool.
Uh I've used it myself uh on my hardware. It's pretty cool. Um and I see it being uh something really interesting and unique where you could have it be in a u a multi-IG. So you could do a one of three multisig for example and have uh two pieces of hardware that you hide somewhere around the world. So if you ever lose your keys you can go back and get them.
Uh I think this is a pretty cool feature. Uh and the last little bit here is on the uh on the DeFi side of things and this is actually the thing that we spent the most amount of time on uh and the most amount of brain damage. So three years ago, uh it sort of started out as like integration by integration, right? Um and so swaps were really cool at the time. And so we figured out a way to take an integrate swaps uh against the 0x router.
So you could from a private address take and swap from a uh uh swap against 0x and they'd route your transaction and shield the results back. Uh that was really really sick. Uh we also did yield by way of beefy which was really really cool. So you can take and get yield on your private address. Uh, and then we did uh LP through uh unis swap v3 uh which is actually a weird amount of work because uh the positions are NFTs and making sure that like u that was secure was kind of fun but naturally the the devil's in the details but uh we sort of noticed like an overarching theme right in that um DeFi at the time atomic DeFi anyway was approve tokens for spending spend the tokens and get the results right and uh the SC came out to be a nice little recipe builder.
Wish my glasses weren't falling off as the blazes of hell up here, but um suffice it to say um we did a nice little recipe builder uh and put that together into the SDK and uh we went to market and shield, right? We said, "Hey, you could build privacy into your DeFi application." That's really cool, right? That's a great feature ad for your DAP. Uh, we also went to like wallet providers and said, "Hey, wallet provider, you could have like an incognito mode on your wallet.
See, we have this cool wallet that did it called Railway. There was this one called Terminal. Um, you can do really sick [ __ ] like that, right?" And, uh, the reality of the situation was is it didn't go great. Uh, it didn't get a lot of integrations, not a lot of traction.
The reality of the situation is, uh, builders are [ __ ] busy, right? People don't want to add extra stuff on top of what they're doing already. And rail gun's really really complicated. And so if you're like raising capital and doing some weird stuff and you got some VCs you're trying to impress, trying to figure out the half a million line code uh SDK for rail gun was a bit of a nightmare at that time, right? Um and so it was a really hard pitch, right?
Uh but I would say that it was kind of a blessing in disguise because the reality of the situation was that this isn't a really good way to go about DeFi. Um because it works at this build like it works at the speed of a builder, right? So every new integration, every new D5 primitive would require somebody to write some code, deploy something, get it into an app, submit it to an app store, whatever. There's a huge there's a huge delay, right? And there's some like really cool new [ __ ] farming activity like every other week that you want to take advantage of, right?
So um it's it's actually kind of cool that it didn't work out because it caused us to do a little bit of uh different research, right? So we said yeah, we said to oursel uh what are we going to do? Well, we're going to stop asking for permission and asking people to integrate stuff and we're going to find out a way to do it in an automated fashion, right? So, we came up with this thing called um Connect, right? Which the uh the TLDDR on uh connect is it's a it's an extension uh that records and spooks local transactions uh against a DAP front end and uh packages those up into a nice multi call and puts those in a snark proof and it does it all automated, right?
So we basically pretend like we're a really good RPC and we um instead grab all that stuff locally, bundle it and then put it in the snark proof. So what this allows us to do is leverage transaction simulation uh instead of like trying to go out and do integrations. Now there's definitely limits to that and I'd probably need another 20 minutes to talk about where the challenges are for that kind of stuff, but I'll I'll save you guys the brain space. And so Oh, sick. That's great.
So where does that leave us? Right. So, Multisig is gonna come out. We're going to drop a really sick SDK for it. You guys should check it out.
Uh hardware wall support is pretty cool. It seems to be working really well. Uh that's going to drop pretty soon. Uh and we're working on this really cool thing, Connect. And so, I hope this is like a really interesting history lesson, but really what this is is a um an appeal to people who work want to work on really cool weird nerdy privacy stuff with us.
Uh because the DeFi stuff is pretty cool. And if you want to like get in on Connect, uh come and build it with us. Uh I'm hanging out. There's also Kai of Kai, raise your hand, another rail gun contributor here. So if you guys want to talk about this stuff in some of detail over coffee, uh come and [ __ ] find us.
Thanks. [applause]
Automatic transcript — names and jargon may be misspelled.