"Cypherpunk x Institutional Privacy" by Oskarth // Ethereum Cypherpunk Congress 2
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] All right. Uh, hi everyone. My name is Oscar. I'm from IPF, so it stands for institutional privacy task force at the Ethe Foundation. I help co-lead it with MO.
And today I'm going to talk about cypher punk and institutional privacy. And these are two words you don't usually see in the same sentence. And I thought it would be interesting to sort of explore a little bit of the overlap as well as the tension between these two very different groups of people. So we'll cover three things. So the first is looking at sort of the tension overlap between cyer punks and enterprise.
H and then we look a little bit about like what institutions care about when it comes to privacy and this leads into the work we're doing in terms of creating like institutional privacy map and sort of exposing what institutions actually need in a private space and what solutions are available in the Ethereum ecosystem. And finally, we look at sort of how these different worlds can coexist on neutral rails and in terms of specific patterns that you might use or how you might solve specific use cases as well as how you can contribute to this effort. So first of all, tension overlap. Uh I think there's a few questions that naturally come to mind like one is do cyber punks and it users actually want the same thing when we talk about privacy and like what's the overlap versus the opposition here in terms of like culture and social norms and technology. uh can both of them sort of exist on credibly neutral uh rails like for example Ethereum and more generally is it possible to sort of onboard institutions onto public blockchains without losing the reason we're here in the first place uh and finally like what is like a plural approach uh look like?
So why this room and like why why are we talking about this now? So if you look at public rails uh this sort of aggregate things like users and tooling and liquidity and it's like massive network effects if you look at bitcoin ethereum in terms of real world adoption uh institutions are right now exploring privacy on public rails alongside with alternative solutions like private and consorial mail ones and I guess one thesis is that if we don't shape this then what ends up happening is that you have worse defaults that's going to impact you anyway so basically it's going to happen either with us or without us and I think we have a real opportunity here to impact things and move things into a better um direction. So why Ethereum? Why do institutions care about Ethereum? They're actively exploring and and building on Ethereum.
There's a few reasons. One is in terms of uh liquidity and sensor resistance and being like incredibly incredibly neutral settlement layer. So Ethereum has like 10ear uptime and it's kind of the selling point if you will for various D5 protocols and stable coins and whatnot. Um and in terms of various other institutions looking into it, it's kind of becoming a little bit of a selling point in that regard. Um if you look at statistics around stable coins, real world assets and DeFi, a lot of that is on Ethereum.
Uh but I think usage of this is kind of nient and it's it's the kind of thing where we don't know yet how things will play out in the future and a single large institution can really flip the scale here uh in terms of if what these systems look like on a decade long timeline. to specific institutions start on bonding onto a another alternative then that could have consequences that we don't necessarily like in sort of the more cyber punk part of the space. Uh and I guess one key question is like how can we onboard institutions and make sure they sort of build on sound technology and it's very kind of honest about sort of how the systems work and they cryptographically secured and so on. So what do what does privacy mean for users? Why do they want it?
So one difference with the cipher punks is that it's not a philosophical or moral question right it's very much kind of bottom line profit and and impacts when it comes to things like pricing or execution as well as counterparty risk. Uh another reason is that they sort of want it for compliance reasons um and sort of operational certainty familiarity. So, a lot of these institutions, especially financial institutions, but also governments, they have a certain way that they want to do things legally and business-wise, and they want to be able to basically port that onto public blockchains. Um, and they want to be able to reason about things in a similar way, even though the specifics might differ a little bit. And finally, like a big reason in terms of strategic confidentiality.
So, in terms of positions, flows or intentions. So, how does institutional privacy differ from individual privacy? One big difference is that there are many actors. Uh so it's not just Alice sending some money to to Bob. It's it's more the fact that once one institution is onboarded that will have privacy implications for many many people and there also end to end interactions when we talk about like private trades and stuff like that.
If you imagine like a NASDAQ running on public blockchains u another big reason that is difference is that there's a very high cost for violations. So if you buy a cup of coffee, you might care about s of privacy and not connecting things, but empirically people actually care less about that, at least most normal people, if you will, compared to institutions because if you're sending transaction for millions of dollars, then what ends up happening is that the bottom line impact is much higher, right? Another thing is that audibility is also kind of uh mandatory because they are operating in this kind of more um regulatory framework, right? uh when they think about privacy, it's not the same thing as opacity. It's more about sort of having scoped visibility of who learns what and when and under what specific circumstances.
A big thing here is that jurisdictions sort of shape behavior as well. Uh so as I mentioned where cyber punks sort of live completely in in cyerspace and self- sovereign and that's kind of the power center when we're talking about institutions they live usually in some specific legal framework and that could either be something like if it's US or UK or Cayman Islands or or whatnot or Singapore and this sort of shapes the kind of specific requirements they might have and they have different um requirements for disclosures. Uh this is also relevant when you're talking about like things like crossber flows like who must verify which claims and where. Uh and there also things like institution specific alignment when talking about like risk and brand brand and regulatory relationships. So in certain uh legal regulatory environments it's a case that institutions can actually help co-write the laws and that will also impact the design and I think generally what we can expect when we talk about institutions moving on chain is there will be various types of arbitrage and it's already happening.
If you look at some of the biggest multinationals in the world, they often try to find sort of what's the best venue that they can sort of best achieve their business use cases. Uh and what we want to do is when we have patterns that work on public blockchains to achieve privacy, we want to make sure that they can accommodate these various constraints. Uh I think it's very easy in the space that you have this kind of cage match with like well it's us versus them and you can do that. But I think potentially a more useful way to look at it is that there are similarity. There are a lot of differences but also some similarities here.
So cy punks care about self sovereignty and no back doors and kind of more this crypto anarchy uh sort of way of looking at the world and nation states and so on. Uh whereas enterprise what they value is usually things like operational privacy or having verifiable processes or predictable operations. And fundamentally if you will the systems right uh there's the same kind of math and cryptographic building blocks that use for this. is just like different constraints in terms of what they care about and there's a kind of minimal shared baseline here when it comes to like authenticity and privacy and verifiability. That's something that both cyber punks and and users value just in slightly different scenarios.
Uh also I want to touch briefly on plarity here. Uh I think you can have multiple sort of legitimate choices that can coexist. So if it's like privacy L1's, private ledgers as well as public L1's and L2s. And what I think we want to do is we keep some kind of public composible verifiable option open and in general I would say that coexistence is better than uniformity and interoperability is better than monoculture and the ecosystem here in order to sort of onboard these institutions they must sort of satisfy the the privacy requirements that they have on public infrastructure and I think if we don't do this what ends up happening is that we get these closed surveiled insecure rails that will ultimately impact everyone and sort of make things worse in terms of not being having like permissionless systems or self-serving systems where you can sort of move money in and out and so on. But in order to do that, we must understand exactly what are the institutional privacy requirements.
And this leads into work we've been doing in terms of an institutional uh privacy map. Uh and just briefly about us IPDF uh institutional privacy task force. Uh so it's a new team at EF only been on for two months and we're trying to help institutions build on top of Ethereum. It's a small focused team. has uh business leads, technical architects and researchers and we do things like workshops and deep dives and collaborative collaborative drafts with uh institutions and vendors.
And what we're trying to do is to some extent like surfacing truths and demystifying the space because what ends up happening is that these institutions they get approached by some BD function from a very very wellunded uh product and they may tell them something but it's not necessarily accurately reflect duality. So we're trying to sort of show them uh what the space and what is what is possible today and give them a little bit more more neutral guidance and the goal here is that we want to provide privacy that's like performance securable secure usable accessible with a specific focus on institutions uh and how we work. So a big thing is that we work sort of from real world valid use cases. So these are not like some blog posts of ideas of how institutions can move on chain. are some of the biggest institutions in the world telling us specifically this is what we want and here are the constraints we have and the constraints might be things like business constraints or legal constraints or operational constraints uh and what we're trying to do is kind of distill uh patterns and these kind of reusable uh building blocks so that could be specifications ERC's or specific ways of of achieving certain privacy guarantees and then approaches which are kind of endto-end uh combin compositions of specific patterns or vendors and we do deliver things like privacy specs and playbooks and validation PC's and what we're trying to do is we have like a public reference that's open and try to push as much thing as possible open source but then we sort of keep certain sensitive engagements uh detail in order to sort of allow these users to tell us more in detail about what they actually need.
Uh so what we're doing with this dig privacy map is we're trying to frame the problem and like what where the leak is actually occurs and then we're trying to connect that to specific solutions whether that's patterns approaches or vendor options and we're starting from these like validated uh use cases from big institutions uh which constrains a specific set of requirements whether that's sort of in terms of transaction per second exactly what they want to keep private what systems to compose with what regulatory constraints there are and so on and the ultimate goal is to provide these playbooks and guidance to help in his users make better decisions and kind of surface areas of work where the ecosystem needs to do more in order to be a credible alternative. It's very much a work in progress both in terms of coverage and depth and this is something where we need you guys' help uh in terms of how we structure it. So we have use cases like uh specific business problems and requirements and then we have patterns so kind of specifications and reusable technical building blocks and then approaches are kind of combinations or of patterns and vendors how to sort of recommendations of how you should build these endto-end solutions to target a specific use case and then we also have documentation on jurisdictions and regulatory frameworks and compliance because this we are not legal experts but what we want is when I have like a TDR of how some specific like the stable coin act or whatnot how that impacts things uh how impedance design and so on and then we also have documentation from vendors which are kind of neutral tool and documentation. So there's various vendors in space that provide these kind of wholesale solutions and we try to sort of uh surface that uh so people institutions in the space know what's available to them in terms of how to approach these problem and you might we try to design it for different types of personas. Uh so if you're sort of a business persona you might start with use cases look at specific jurisdiction you care about and then look at approaches or how you would solve it.
But if you're more on the technical side, you might start looking at sort of some specific uh specifications and patterns and then see how that composes up into approaches and see if any vendors attacking this or if this is maybe an open opportunity. If you're more on the legal side, you maybe start with some specific jurisdictions or regulation and see that it's like actually captures uh your understanding and then move up to sort of use case requirements and so on. And the idea is that we want to make this map as useful as possible for different types of personas which are actually impacting uh where this technology is heading. Uh in terms of life cycle you can think of leakage happening at multiple uh parts right so one thing is like pre-trade uh leaking intent or sort of orderflow exposure uh when it comes to settlement there's like things like linkage between who and and some specific asset as well as principal risk and there's some technical things there's like DVP versus or PVP so DVP stands for deliver versus payment and this is has a specific uh meaning in sort of a business and uh legal world where if you pay for a specific asset the deliver of asset has to happen at the exact same time in time. It has to be atomic, but it's not just like a smart contract.
It's the case it has to happen across different networks. So you might have a clearing house that's like a completely different networks and you need protocols to sort of deal with this because it's both a legal requirement and a sort of business way of of minimizing risk. And this is like a strictly higher requirement than you might see when it comes to bridges in the crypto native space. And then when you talk about post trade uh there's things like positions and notes that you don't want you you don't want to leak but at the same time you sort of need to meet certain auditory requirements and this this depends again this depends again on the specific jurisdiction you're operating in the current status we have a few hand cases uh we have a few use cases that are documented we are aware of more but we are very careful in terms of only adding the ones that multiple institutions have told us directly about. So we are make making sure we focus on solving the real world problems that that the institutions actually have.
Approaches we have a few set in place and patterns as well. We have basics in place but there's more to do there. Uh vendor documentations we're working with ecosystem and it's uh we have like 30 or so there including contributions from multiple people and different products. Uh we're trying to keep like a neutral scope here. Uh so not sort of picking favorites but at least showing uh the ecosystem like what options are available and what the trade-offs are.
And it's something where we definitely appreciate you guys' feedback and contributions. And then finally of coexistence on neutral rails because this is a cyber punk congress right and you might think well this is like very much compliance tech and so on. Uh and I think it's interesting to think about keeping sort of two contradictory models in your mind at the same time and I think it's possible to sort of accommodate both of these users. Um so when we're talking about patterns these are kind of reusable building blocks and these are very fundamental primitives like it's commitments or the atomic DVP I was talking about or scope viewing and these patterns are useful no matter what type of use case you are designing for. So even if it's the most sort of cyber bankank use case you can imagine which is no nation state can touch it under no conditions or also uh designing for institutions these are still like the building blocks that you would use to to solve for it.
And then we'll talk about approaches sort of how to compose how we compose these specific patterns to solve specific use cases. Uh we'll we don't have a lot of time but we'll talk a little bit about some specific topics here. So private broadcasting, private bonds, payments and then trade settlement just to give you an idea. So when it comes to private transaction broadcasting the goal is that we're trying to reduce uh pre-trade leakage and this is things like front running and MV and and leaking strategies and the way we do it is for example like encrypt having encrypted or private lanes and doing OTC submission and potentially having things like private rollup execution and it matters because uh institutions often want like uh better execution quality but still having composibility with for example D5 uh when it come to something like private bonds there's multiple structured products but bonds is something There's quite a lot of demand for this applies both to issuance and trading. And the problem here is that you want to have sort of confidential bond deals but having some a short settlement because these are absolutely massive monetary flows we're talking about.
So that's very important to them. Uh and this composes multiple patterns of patterns. So for example, shielded transfers, atomic DVP and safety disclosure. And the outcome that we want here is having kind of compliant confidentiality and deterministic finality private payments. Uh here you want sort of stakeholder visibility.
And I would say that private payments it sounds like a simple problem but if you actually look into how payment infrastructure works it's extremely complex and there's all kinds of things with different cost providers or treasury management and so on and different networks. Um, you also want to have kind of regulatory and auditor access when required. And this again depends on specific regulation about what that looks like, what that looks like. And here you want to have things like sealer balances and transfers, scoped viewing, and potentially sort of optional uh DVP or PVP. So, payment versus payment if you're doing things like crossboard transactions and being able to deal with with how the how that looks across countries.
Uh, and this matters a lot because you want to have operational privacy without sort of blackbox accounting. So you want to be able to sort of show uh to a regulator what is needed and also when I say that private payments it depends a lot on specific use case here. So for example one use case is a set of institutions doing like multi-million dollar transfers uh with each other. That's very different in terms of constraints compared to for example a bank issuing a retail stable coin with with like 10 million users or whatever. Uh and that also influences a lot the design.
So it's not just as simple as your private payments. There's like a lot of subtlety to it. uh private trade settlement. Uh so the goal here is again sort of minimize leakage and reduce operational friction and this this applies to like a lot of structured products. So it's a bonds or real world assets generally like auto tokenization and things like derivatives and securities in general.
And here you can do things like you can batch proofs and commitment and having some kind of neutral settlement venue because this is something again where institutions they care a lot about like where does actually settle what's the risk especially if you're going to put billions of dollars on chain uh as well as having auditable dogs logs and here again you want to have sort of predictable cycles and sort of cleaner reconilization because that has an impact on things like liquidity so how you move uh money around. Um and you can think of this map a little bit like a decision path. So you would start by like identifying what's the specific use case like what's the business problem you have and then applying some jurisdictional constraints like what are the regulation that matters here and then you would select specific patterns and approaches uh like what are the building blocks that make up the solution and then you would evaluate v vendors sort of what tools exist and what's the majority of them what's the performance and then have like a create like a feedback cycle here uh where we headed so we're trying to sort of get a broader coverage because multiple domains this is just like scratching the surface and go sort of even deeper on deeper patterns and approach runbooks and having like being able to provide these uh playbooks which kind of shows the best practice for how to do this uh in terms of getting privacy on Ethereum for institutions. So just summary cyber bunk institutions they have different goals but it's still like a lot of shared technology math. Uh I would say different systems can coexist on the same credibly neutral foundations and we want to make sure we have this public composible verifiable option open to everyone and I think also very important here is that we need cyber punks in the room when these specs are written because that will sort of fundamentally impact the design and we can move things in the right direction.
Uh and when it comes to institutional privacy, institutions want privacy on Ethereum and we are building an open shared privacy map of the space and you can contribute PR and issues and you can as well come talk to me. I'm here and Mo over there is also working at the PDF and here are some links. Uh we have the GitHub uh X I don't know how much you can see it but you can see of the if you scan the QR code that leads us to um the IP the the privacy map and yeah bring real constraints as feedback and so on. Uh and that's it for me. I want to uh make sure because this is like a little bit different from the cyber bunkers.
I want to if someone has a really spicy question raise your hand and I'll answer it. Spiciest question. Go for it.
Okay. So Ethereum is basically a selling point because it has loads of liquidity that could be easily accessible. But like with the cyber point values and current solutions out there, is there like any potential privacy project that currently exists and operates that could possibly accommodate these institutional demands because it seems like it goes against our entire eos.
Uh I think that's a good question. So I think there's like there's a bunch of privacy product. I mean there's obviously alternative L1 but on top of Ethereum specifically there's a bunch of them. There's things like privacy pools, there's there's rail gun, there's also things like Aztec common online and so on. So in terms of meeting the requirements, a lot of that is more when it comes to scale and throughput and so on.
I would say that you can have different networks, right? So let's say you have some default protocol or whatever on L1 and then cyber punks would use it in a permissionless way on their own, no constraints. And then you also in addition to that you maybe have like an L2 that's like imagine like you have a bank account or you have like some stock exchange or whatever h and that operates the same way and then you have it had interrupt with sort of the L1 and so on. So that's how you can sort of accommodate both of these users.
But then the liquidity is fragmented, right? So
uh not necessarily because if it's cryptographically secure, there's various things you can do. But it's it's not the trivial problem, but it's better than the alternative where you have two completely divorced uh rules because what you can do is you can have like proofs that make sure that you can have certain guarantees that you're not on a sanctions list or whatever and then you can use that to sort of compose liquidity. So that's better than having a completely separate ecosystem where you can't c cryptographically connect the two dots basically. But it's not a trivial problem. But there are various ways you can approach that.
Any other spicy questions? All right. Uh thank you. That's it. [applause]
Automatic transcript — names and jargon may be misspelled.