From Tornado Cash to future developers protection - Panel || Ethereum Privacy Stack, Devconncet 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Fatemeh Fannisadeh, Marina Markezic (EUCI), Ayanfeoluwa Olajide (Base West-Africa), Joan Arús (Sentinel Alliance), Beth McCarthy (Web3Privacy Now) goes through lessons from Catalangate in relation to state regulation, Tornado Cash case and how to protect the developers the best. Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/
Transcript
[applause] Okay. Doing some uh interior design. [laughter] Okay. So, I'm Beth McCarthy, program director at Web3 Privacy, and um I'm really excited to host um some people I really admire. uh brilliant legal minds thinking about um regulatory and compliance in um yeah a really uh inspiring way.
So, uh, I will have everybody introduce yourselves starting at the end and then we'll go into, uh, a discussion that, uh, will end up in a call to action and how we can get involved with, uh, fighting against weaponizing, surveillance, mercenary, spyw wear, and all of the, uh, ways the government is trying to crack down on uh, yeah, some threats to privacy. So, Yeah. Um hello everyone. My name is Ay Oliday and um I'm a web 3 lawyer. I'm a lawyer who I work with a lot of web 3 projects and companies do um basically in Africa and um basically helping them to scale their projects on the right side of the law.
Um I'm into um regulatory compliance, you know, policy and then legal advisory. And it's a pleasure to be on this panel with um other amazing legal experts.
Hi everyone.
Hello. Hello. Yeah. Okay. Um thanks for being here.
Thanks for having me on the panel. Um my name is Fatimized. I'm a crypto lawyer working in privacy for the past couple of years. Um I'm also part of the Sylvia Culture Society. I'm qualified in Switzerland and uh yeah excited to be part of this conversation.
Hi everyone, my name is Marina and I work in the EU and policy in the EU including work on privacy. We work within the European crypto initiative which is an association that is uh working on all things related to blockchain and crypto in the European Union and part of it is privacy as well and we'll talk later more about what that means and what's happening at the moment in the EU. Hello, my name is Joan Arus and I am the co-founder of Sentinel Alliance which is a nonprofit association of mercenary spyware victims founded mostly by uh developers and technologist with the objective to basically defend actively defend victims through strategic litigation, raise awareness across key stakeholders and try to achieve effective change through regulation. And I guess I will be starting the conversation with um a little bit a personal story and then we will connect with the topic. Um before founding Sentinel Alliance I was executive director at Aragon project.
Uh before that I co-ounded Bogdani which uh both of them were speaking before. Uh basically I spent my career in technology building censorship resistant and um anonymous um protocols for governance and identity in 2019 and for two years uh because of that work we uh were targeted at Bogdoni with mercenary spyware Pegasus and Candido which I don't know if raise your hand if you know what mercenary spyware is. Wow. Okay. So, just for those who did not raise their hands, mercenary spyware is basically a capability.
It's more than a piece of software. It's the capability of turning your phone into a spy in your pocket. It can basically read encrypted messages. What? Read your messages before they are transmitted and encrypted.
It can retrieve files, photos, contacts, absolutely everything. It has root access on your device. You don't need to click on any link to get infected. They can target you with your phone number or your iCloud account. And um it is multi multiplatform meaning that it's not restricted to phone.
It can also get you on iOS, Mac OS, Windows uh terminals. And what I wanted to to to this is highly unknown in the industry. Not everyone knows. Among the targets was Jordi Vina who was an advisor. Not only they targeted our team of developers.
They targeted our investors or advisors. Jordi Valina being one of them. He alone received 32 attacks which costed millions to the attackers. And um we were simply building open-source code. We were not trafficking weapons.
We were not planning an attack uh on a on a marketplace or bump uh a train. They considered that to be a national security threat because of the potential use of the protocols we were building. I I repeat for the potential future use. I hope you you you see how this new playbook um increases exponentially the risk surface and the vectors of attacks against open source developers. Um we've moved from a framework of requiring to arrest a developer to retrieve the messages for example in tornado cash that was the case they had to gain physical access.
We have moved from that from any government in the world being able to target your device and that's really uh that's really really worrying and the other obvious uh challenge is from prosecuting past usage which you can get into the details whether you know money laundering or AML rules whether they breach or not but it's past actions
and this is a new playbook prosecuting future actions. H how do you know who targeted you and why they targeted you?
So I'll start with the why. Uh we were targeted because they were the the Spanish authorities were very scared that Catalan politicians could use the censorship resistant boarding protocol that we were building. And that that was enough to basically prosecute us under the terrorism offense which is by the way uh a key enabler here in terms of regulation. If you check in most countries including Europe, terrorism includes any action with the objective to subvert the constitutional order or seriously destabilize the economic or social structures. Okay.
who here is building tools that could fit that definition. I see some hands. You get my point. Um, this is this is highly highly worrying and the weaponization of this serious offense is being used increasingly against developers.
Oh. Oh, okay. All right. Um so as a you know legal professional in the space I think that what I'll be able to contribute to that is um the fact that the regulators are concerned with very few things right um and the fact that the concept or the definition of terrorism is so broad that innocent open-source developers and protocols could be found liable under the definition of terrorism and so um I think that it's um a call to action or something that we need to look at in the space um especially for those of us in policym or who are trying to develop the policy legal landscape and it is simply that perhaps it's high time that we come to redefine certain concepts right to be able to either we expand or we subtract from what we've always known to be what so now in this context what we've always known to be terrorism I think that um a way that developers could be protected is if we advocate for the expansion or otherwise of certain terminologies and in this context it will mean terrorism right Yeah.
So, so you mean ex expanding the definition of terrorism or like refining it so that it doesn't Okay. Um, well, I mean
it's such a bad word terrorism. It's used and abused and and like I'm even afraid of mentioning it on stage somehow like I like to like I'm on the right side what whatever that is. But um I think it's it's really a battle that is very difficult like who gets to tell how like the United States how to define terrorism like Spain how to define like who gets to lobby there like it's usually designed in the legal system in a way where um it kind of encompasses everything and it's really difficult to fall outside of it. So if nothing else works, you can always fall back to terrorism or sanctions in the case of tornado cash um which then like was proved to be illegitimate sanctions because you cannot sanction a software but still like these are the ultimate tools that they will use and that whether or not it's legitimate, it doesn't matter because they're going to still sanction it and people will suffer as a result whether it's the developers directly or the users. and then a few years later you realize that they weren't even allowed to do this.
So I don't think that I'm a lawyer like maybe I shouldn't say this but I don't think that going past the bureaucratic route is necessarily um kind of like the first response we must have because it takes a long time to build the culture.
I agree.
Yeah, I agree. And I I think that the technologies that privacy enables and censorship resistant protocols, if you think about it, they represent a direct challenge to the monopolies that nation states have had for over 300 years or more. You think about identity, self-signing identity, voting, finances. If you look at that definition of terrorism, it will be used that playbook will be used again and again unless we achieve some sort of protection or increased pro protection for those who are building those tools. for everyone here who is building central decentralized technologies and privacycentric technologies.
The same way we considered lawyers are needed for maintaining your right to have a proper defense in court or the same way we've got journalists protected with freedom of speech protection. We need in my opinion we need uh increased protections for the work of open source developers because we increasingly live in a digital society and they are building the primitives that will allow society to upgrade to digital governance digital finances etc and I don't know what what is your opinion on the chances of uh achieving that increased protection uh towards open source developers do you think it's actually feasible. What's the way to get there?
I mean, this is what we discussed before in preparation to this panel. There's so many things that in a way we work on at least from a policy perspective that is kind of reactionary to what's happening and the new laws being proposed and the changes being proposed that could affect one part of let's say what we understand as privacy. that doing something that is like again proactive like changing a law that is not even meant to be changed because you see that is affecting you in some way that you think should not. It's even you know putting even more work into that and trying to activate us more. So it's really like I would say this panel it's kind of a call for activation from this industry.
I know that like most of you are builders but I think that a part of the industry is also thinking about what how to help builders in way build in a more secure way but at the same time at least um you know preventing some future regulations from happening that could be limiting privacy in many different ways. It can be financial privacy. It can be like just digital privacy in terms of like communication. It can be also when it comes to building Yeah. And um to add to this discussion um when we talk about um how developers I'm sure many developers here are interested and about how they can be you know legally protected right how do I do what I want to do without um looking behind me you know every two minutes so that the how do I yeah okay so I mean we are we're curious to know how we can operate you know freely and fairly without having to look behind us to see if the regulators you know are coming to clamp down on us.
And about that I think that um it will be interesting for us to um look at um the you know layer 2 protocols and first of all I think we have to actually define what kind of privacy we're offering as developers and to what extent right um for for me I kind of understand privacy at four levels there is um pseudonymity there is confidentiality then there is anonymity and then there's full stack privacy Right? Privacy in the sense that oh nobody can see what I'm doing, where I'm doing it, who I'm sending the message to, how much I sent, when I sent it, how I sent it. Right? Um if you first of all determine what kind of privacy you're offering. I mean in context what degree of privacy you're offering.
And I think that that would be simply that you are um it's not full dark mode privacy but something that um you can some privacy that you offer such that you can disclose certain information but no more than is required right so how do I um you know when I'm building my privacy stack how do I maintain disclosure or how do I create disclosure and at the same time give out information that I need to give to the regulators yet no more than is required right um we see how that in the the blockchain space is in direct conflict for example with the provisions of the GDPR if we're looking at data privacy the blockchain is in is um naturally by default the blockchain is transparent and one of the things that the regulators will require of you as a developer is that um they require you to be in full compliance with article 17 of the GDPR that states that you and I have a fundamental human right for our data to one not be disclosed but more importantly for our data to be erased and to be forgotten at will. However, this the the um cryptographic measure through which you're building your project is the blockchain and the blockchain is inherently transparent. So, how do we how do we merge the two, right? Um I think uh from my perspective and especially from the perspective um of the law I I understand that there are zk there zk zero knowledge proofs where zero knowledge proofs require you I mean make it possible for you to be able to prove that a transaction is true without revealing the details of the transaction right um however in practice we see that although that is possible But the at the end of the day the transaction that you have proven to be true can still be tied to a personally identifiable information. it can still be tied to um at the end of the day a wallet address or you know it's your sequentials you know have the trails are there right so there's that to look at right and at the and at some point I think that in the legal and regulatory space we would be looking at whether or not um zero knowledge proofs provide for true anonymity do they truly provide anonymity like we are like we claim they do or do they just provide some form of advanced pseudonymization because um what the regulators want from you is that um apart from the fact that they they want data to be erased whenever and you know whenever it calls for it, they also want data to be as anonymized as possible.
I I mean they want data to be as anonymized as possible. And um the current level where ZKS operate do not provide for full anonymity because again while you can prove that a transaction is true without necessarily revealing the content the trails can still it can still be traced you know to a transaction ash. So some people some developers are trying to um toy with the idea of creating like a two layered um step where the commitment I mean the content of the transaction is private you can't see it however the proof of that transaction which is the transaction ash in this case it is um recorded and uploaded on a public ledger right and so the regulators will still ask since I can see proof that the transaction is on chain. Have you truly anonymized the data? Because um anonymity is the fact that um there's an actor but I can't identify the actor and pseudonymity is there is an actor but the actor is operating under a consistent but artificial identifier.
So what I'm just basically trying to say we're just exploring concept here and um it's a way of intermitting all of us in this room especially as we do one or two things in advancing for privacy especially in the Ethereum ecosystem. So we have to determine what we really want. Do we want advanced pseudonymity? Do we want confidentiality? The information is there however it's private.
Do we want anonymity? Anonymity where the actor we know that there is an actor. We know that there is something but it is unidentifiable or do we want full dark mode privacy?
Let me stop there.
May I ask a question?
Um I I
No, I just wanted to mention that uh I think that a key change we need to be doing is we are treated as uh like that we need to prove that we're not criminals, you know, and we constantly speak about how we can be compliant with regulators. the the hugest like the hypocrisy of this is that while they do all these privacy protecting uh regulations like GDPR it's supposed to save us from from the bodies then they deploy mercenary spy which basically breaks privacy and makes it impossible and breaks the pillars of democracy among other things so I think that we it's very important that we don't fall in on on that trap of let's please the regulators like we are not criminal like people building open source software and coding and publishing code were not criminals. Those who weaponize the surveillance apparatus of the state and the different pillars of the democracy against developers are the real criminals and they should be held accountable. And I think that all this conversation regarding uh compliance we we are constantly falling in that defensive trap that you were mentioning right Marina and um and I'm wondering how we can step up our game and and become more offensive and because the battle is fought in our minds in everyone's minds you know uh uh in terms of
switching that paradigm you know from potential criminals to basically freedom fighters which is what everyone who's doing this are Um, so yeah, I don't know if you've got any ideas on that.
You want to react?
Okay. Well, um, off the top of my head,
show closer.
Off the Can you hear me?
Yeah.
Uhhuh. Okay. Thank you. So, off the top of my head, like, yes. You know, you you're making me feel like you're putting me on the spot as though I'm the prosecutor.
Yeah.
Or as though I'm being controversial. [laughter] you know, I mean, we're all on the same side. You know, I think that that was why I mentioned in the beginning about the fact that um
like you said, call to action and we're no more reacting and first is advocacy like we're doing here. This is like one of the very first steps talking about it talking about it. Second is that I already mentioned earlier I think that we also need to come together in our advocacy to begin to redefine certain terminologies. is very very important because I could go on and on and on. The the concept of personal data for example, it it puts privacy developers at risk.
But if we through advocacy, you know, begin to clamor for, you know, old more perhaps events, conferences, roundt discussions, you know, that would that would um help. And but on the technical side, what I think I can quickly add is that um layer 2 protocols um especially at the sequential a sequencer level, sorry, at the sequencer um level, the regulators are very very quick to clamp down if they see that um the developers or the validators or the sequencer nodes are they have this um it's a it's like a centralized setting where an a particular entity or a particular sequencer has the power to perhaps edit or upgrade or to you know make modifications to the sequencer node that is those are some of the things that will attract regulations. So if um L2 protocols or you know privacy developers we can get past the stage of actually really decentralizing you know sequencer node such that it is difficult for a regulator to say oh you are the data controller like it is you that is running this thing and so we're holding you accountable. So the more we have a lot of um decentralized nodes who are running things independently albeit simultaneously. Yeah.
So um what I would maybe uh comment here on is a message that I think would be great that that you get from this panel is that we're discussing here some of the situations that happened some to to some of our colleagues but why it happened was because we had some laws that were in way finalized at that moment they were applied in a specific way. The message that I want to share is that those laws are changing like in a good and a bad way. So they can change in a way where we would like them to change and it goes into the direction that you know we in a way advocate for and they can also change in a way where we get additional laws or we have you know laws that are somehow acceptable or good for us changing in a in a in a better way and that's where we do need to be active on an advocacy level. uh in a way we as EUCI we chose to be the one wearing the suit and going to the room and talking to the regulators but we do know that there's like very different ways of like being active and in way advocating for for privacy it is uh you know organizing events like that it's meeting discussing topics uh you know doing activities like like you do and I think all of those are needed but uh another thing that I would say is important from why we are speaking here and why discussing from a EU perspective is um my my question was like where are you practicing law which country
Africa but like it's global as well like I work with a lot of projects from outside of Africa
so basically lawyers from all over the world know about GDPR and it was decided in the EU and it will change in the EU as well and um there's some very I think interesting updates that are happening and they happened just two years two days ago go. Um, there was a draft proposal for GDPR to be reopened, change in specific ways where it could actually be pretty positive for our industry like indirectly recognizing that the privacy preserving technologies could be even used as a tool for um, I would say even making blockchain a little bit closer to the GDPR framework as we had like a very nice explanation how GDPR works And where is the I would say conflict with GDPR and the blockchain. We had um I would say something like as a surprise this year the European data protection board issued this guidance where they analyze the compliance of blockchain when it comes to GDPR and you know again we have builders here in the room our um product road map is very uncertain. We react to what's happening in Brussels. So that's something that we we didn't uh in way plan to work on this year but we got this this guidance the first draft of a guidance responded as well uh as an as an association and now we're waiting for the final guidance but the guidance was not very positive as it was described that even mentioned if the data cannot be deleted uh from the blockchain the blockchain itself should be deleted so that's not very I would say constructive um as well but those are just like drafts so it's it's not final Yet what is amazing is that with all the activities that the associations did uh I would say us as well and and of course others uh the European Commission has taken this into consideration and they have written a proposal to change the existing text of the GDPR in a way where it would be much easier for the blockchain to be compliant within GDPR.
um and it goes also against some of the topics that were written in the guidance from this uh European data protection board. So changes are happening and I I have to say like it's not many times that I have this opportunity to talk about uh you know positive achievements that are happening in the space and I'm very happy that we can share that our contribution was significant to these changes as well. Of course, it's not only our association, but it was a very very important step that we did this year. So, you know, a little bit hopeful because every time people speak to me, they're like, "Oh, Marina, you're always like, you know, depressing me. [laughter] There's so many like non non-positive changes, but they could be also good ones."
And as a last note, uh you know, some people are solar banks here. They believe that there will be you know a bright future where you know nation states will basically realize the benefits of using this technology for a greater good and there's the lunar banks who are preparing for the crackdown. It doesn't matter who is right. We need to protect the work of open source developers and the only way we can do that is if we become stronger so that if they touch one of us they they touch everyone right and in my opinion that the work that uh associations like the European uh crypto initiative uh web3 privacy and everyone who's working on advocacy I have a specific ask for the industry I see lots of projects uh very well capitalized billions of dollars moving lots of money, making cool parties, that's really good. That's that's that's great.
But without putting their money where their mouth is, we will see many more developers getting prosecuted or getting their ass in jail. And the moment you are having to defend yourself against 5 years, 12 years imprisonment, that that's it. Damage is done. We need a protective framework. And in order to do that, we're up against nation states, governments who have virtually access to unlimited uh amount of funds.
Um we're way smaller. So I think as a key call to action, we need to unite, stop trivialisms. we're all in the same boat and uh support the organizations that are actually raising awareness on the importance of this of these technologies and who are doing excellent policy uh work and legal defense and that
want to add
um no it was very interesting I mostly listen that part I agree like we need to support organization like the UCI um but also I mean somehow devs are now forced to be like activists because of this reaction and it's really hard to plan and to foresee the risk. So I think where I stand and what I usually tell devs is just trying to have basically ethical behavior. You know, putting question trying to behave like close to what they believe is right within their own moral framework so that then it's coherent and defensible because at some point if you have to defend yourself, you all of a sudden are put in the spot of uh someone who is doing civil disobedience almost. So like you need to have a strong moral framework to be able to bring in your defense and argue why you think that like what you were working on is legitimate and positive for society.
Wow, perfect timing. And yeah, if anyone you want to share just a final word and yeah, I'm ready to go join the fight
with you guys. So
yes,
final words.
Oh, final words. Oh. Oh, okay. Okay. Final words.
Final words. final words. Um well I think that my final words would be that um when you hear legal and regulatory please do not think that it's the end of the world or someone has come to kill your dream and you know like the positive developments that have been happening you know in the space especially with the you know um European crypto initiative um there's a bright light at the end of the tunnel but I think I'll very quickly want to intimate all of us in this room that um as a first step or one of the first steps to in your um building a privacy stack journey is that you should have a legal mapping. a legal mapping by that I mean um having taking notes of all that will be required of you in the jurisdiction that you plan to you know set up your project because when you understand that or when you have that you'll be able to know how to navigate and then if you ever have or work with third party sequencers you would be um you'll be protecting yourself by having what I like to call like a a a framework like a written agreement between any third-party service you'll be having. So if your project is going to be using a third party sequential for example, it would be nice to have an agreement between you and that third party service so that when liability comes knocking, you can protect yourself and yeah that's it.
Um just one last actual final.
Yes, one sentence. Uh there is no such a thing as compliant privacy. There is either privacy or no privacy. Okay, mic drop on that one. Cool.
Thank you guys so much.
Thank you. Bye.
Automatic transcript — names and jargon may be misspelled.