"Kohaku: Wallet privacy on Ethereum" by Vitalik Buterin, Consigny & Kassandra // ECC#2 - BA 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Speaker
Ethereum Foundation · 24 talks
Ethereum's Vitalik Buterin together with Kassandra and Nick Consigny presents new set of primitives called Kohaku. Vitalik also shares more about what will Ethereum implement for improving their privacy and Kassandra and Nick Consigny goes more into Kohaku. Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] Okay. Well, thank you so much for the kind introduction, Cassandra. So I will uh start off with uh some of the background basically why Kohaku why we're doing Kohaku and uh you know why it makes sense to really start something like Kohaku now. So Ethereum I think first we need to appreciate it has led the way on privacy research and development over the past 10 years in all kinds of ways right so Ethereum added the elliptic curve pre-mpiles ECD ec pairing back in 2018 tornado cache rail gun all the privacy protocols are based on that uh we have funded a lot of academic research on all these uh topics uh privac the PSE uh did a lot of really important work on Ziggy Stark protocols, developer tooling, even a lot of pioneering application layer stuff and Ethereum L2s including Aztec including INMAX on the enterprise side also Nightfall and likewise on security right I think uh the DAO hack in 2016 who remembers the Dow hack who lost money in the Dow hack um so it really catalyzed the ecos system and we've got a much stronger smart contract auditing ecosystem. You know, we got Seal, you know, a group that's been uh doing all kinds of work around security this past decade.
A lot of improvements to languages, both Solidity and Viper, to make them more and more secure over time. Also, multi-IG wallets that were sort of mostly a dream back in 2015 and then now very mainstream today. Who here uses a multiig wallet on Ethereum? Amazing. So, but on real world privacy and security delivered to users, we're still behind where we could be and that is the thing that could change and that is the thing that this year can change.
So, using privacy protocols in 2025. The good part is the the base layer technology. It's all great. You can sign a pro generate a proof within like one less than one second on a laptop, two seconds on a phone. It's easy to develop.
It's uh very well understood. There's a lot of well- tested circuits. But from a UI side, right, using a privacy protocol requires a separate seed phrase. There's no multisig option. So if you have your coins in a private pool, your coins have to be controlled by one single key.
It requires opening a separate privacy wallet. It takes like five clicks to do private send and withdraw. The public broadcaster mechanisms are brittle. Last week I had to, you know, fight against public broadcasters and uh it took about 10 tries until eventually I figured out that uh it works after you turn turn on a VPN. So we're in this like very last mile stage, right?
And it's exactly at that last mile stage where we need to put a lot of really concerted effort into doing better. Same on the security side. A lot of layer one security work much better. Safe wallet much better. But this year safe UI not yet much better right also usability of security.
Uh so there's this article here basically asking why you know in the era of everyone knowing about mount go and fdx do people use centralized exchanges and one big part of the answer is basically convenience right and uh a lot of people don't understand how well how to work with things like private keys on all of these fronts we can do better privacy is important so this is an excerpt from a particle an article I wrote in April why I support privacy. Privacy is freedom. Privacy gives us space to live our lives in the way the ways that meet our needs without us having to constantly worry about how our actions will be perceived by all kinds of centralized and decentralized uh coercive and otherwise political and social games. Privacy is order. A lot of the most basic mechanisms in our society depend on the assumption that not everyone can constantly see what everyone else is doing.
And uh privacy is progress. There's a lot of value that we can uh unlock by using data for things like medicine and science that could become a dystopian nightmare if it is done in a way that uh is not designed to be privacy first. And with newer cryptography, it can be designed to be privacy first. Privacy is not an abstraction. It is a concrete benefit to users.
We can show that we have now security is important. So here I think I'll let the meme speak for me, right? But basically, you know, you have you could do a lot of things with your assets. If you put them into DeFi, you get some APY. If you do nothing, you get 0% APY.
Can anyone shout out what your APY is if you lose your private keys? minus 100. Uh, what your APY is if Lazarus discovers your private keys, minus 100. And what your APY is if the wrong people discover how much money you have, who you donate to, and where you live, dead. So now, privacy is a lot of things, right?
I think historically we have at least within the in the Ethereum world thought about privacy as basically just being what can you zk prove on chain but privacy is much more than what happens on chain. It's also UX work. It's making it easier for people to have different wallets for different applications and not accidentally screw up and link their identities to each other when they do that. Privacy is privacy of reads. being able to read data from the chain without compromising everything about yourself.
This can be done either with uh uh techniques that take RPCs and make them better. So things like either TE plus OAM or the really cryptographically pure approach P or by making it easier to have full notes which uh block level access list and ZKVMs will do. Also making sure you don't reveal everything about yourself from um at the network level. So looking at mix nets also looking at operations other than finance all of these things are important security is more than any one thing. So risk based access control you should have to press more buttons and get more authorization to move $100,000 than to move $10.
This is something that traditional security has uh recognized for over a decade and something that our space needs to work around as well. recovery, better options for people to recover their accounts uh if they lose a device, if they lose a key. Um security at the user interface level, onchain version control, both of software dependencies and of UIs. We should have a world where UIs live onchain and the DAO itself sends an onchain transaction to update the UI. So you can't hack into a server and make people dependency minimization and security of the dependencies.
So, Ethereum in 2025, it has strong security and privacy research. It has strong security on the L1. There is constantly improving privacy tooling that has improved by miles since Zcash, the very first version of Zcash launched and it took two minutes to sign a transaction. So, so much improvement has happened, but we still need to level up the last mile. We need to level up the application and wallet layer, the parts of this whole problem that are closest to the user.
And that is exactly what Nico will talk to us about.
Thank you, V.
It's me again, Cassandra, and I want to show you the demo of our Kohaku wallet we've been working on. So, this I've been working on this in collaboration with the EF, a bunch of EF grantees. Shout out especially to uh the Wonderland team who's been doing a lot of work on this alongside me. So let's check it out. So here we are in my browser and we are going to try and open the Kohaku wallet.
So it's a pretty traditional browser extension wallet. This is a fork of the Amire wallet where we just have tried to embed these privacy features directly in a classical browser wallet user experience. So yeah, everything looks pretty traditional so far, right? We've got this account. We've got ETH and USDC on Sapoleia in our public account here.
We've got a number of different accounts we can derive from our seed phrase. But maybe the first big difference is we have this thing called the private account. So let's check that out. And as you can see, this uh already has some ETH in it. But this is ETH we've already deposited into privacy pools into a privacy protocol which helps anonymize our funds.
So uh the private account is actually aggregating balances across both privacy pools and rail gun. So any tokens or ETH that we've deposited into either of those protocols would show up in our private account. Okay, cool. So what can we do with the Kohaku wallet? Well, we have all these funds in our public uh address here.
So one thing we can do is we can take public funds we have and we can shield them. We can deposit them into these privacy protocols on Ethereum. So let's start with uh privacy pools and uh let's deposit some ETH into privacy pools. Why not, right? So, we click privacy pools and uh let's do 0.
2 ETH and uh we pay a small fee. This is part of the privacy pools protocol. Click deposit and sign send this transaction off. Wait for it to be included. Okay, cool.
Uh we have deposited some ETH into privacy pools and we can see now uh we see this pending uh message since in privacy pools you actually have a delay on on deposits. uh they have to be checked for uh the ability to be whitelisted to make sure it's not bad actors trying to use the protocol. So that's why we already had some privacy pools ETH pre-deposited so we can use it later and we don't have to wait this pending period. But uh we can also use the rail gun protocol as another privacy protocol. So our Kohaku SDK is agnostic to the different privacy solutions on Ethereum.
We want to support all of them. And one cool thing about rail gun is it uh supports all ERC20s out of the box. Unlike some other privacy protocols that maybe have to bootstrap each asset individually, rail gun supports all the ERC20. So let's maybe deposit this ERC20. We have some of Onspolia into Rail gun.
So we just change the privacy provider to Rail Gun. Okay, cool. And we switch the token to USDC. And let's deposit, I don't know, 500 USDC into uh rail gun. So just click deposit here and sign and send the transaction.
One interesting thing that's happening here uh is uh under the hood with the Kohaku wallet is we didn't have to first do an approval and then do the deposit even though we're utilizing the RC20. That's because we're using 7702 under the hood so that we can bundle these together into one action. So, it's one click to do this deposit. Awesome. So, as you can see, we uh our USDC balance went down.
And if we check out our private account, we can see we have a bunch of USDC deposited into rail gun. We can see it in our private balances here. So, great. So, that's what deposits look like when you want to take uh public funds and anonymize them directly inside the Kohaku wallet. But, uh what else can we do?
Another feature I want to show you is using a DAP, right? So people want to also interact on the chain, use the daps they like. So here I have as an example unis swap open and um we can connect our kohaku wallet here it's a fork of empire empire but one new user experience is instead of connecting the currently active account in the wallet um we promote privacy hygiene by nudging the user to actually create a new account whenever they connect to a. So this way um we can try to always use fresh accounts and uh have much better privacy hygiene. So okay, let's uh connect our fresh account here.
Copy it. Cool. And then I'm also going to make sure we're on the testnet. Great. Awesome.
Cool. So we connected our fresh account. This is great because uh unis swap doesn't learn anything about our identity or any links of our accounts. The only thing that UniS swap learns is we've connected this absolutely unlin account, but it doesn't have any funds in it, right? So, what do we do?
Well, we can just open our wallet, navigate to the private account, and from here when things load, uh, cool. Um, what we can do is let's, uh, let's withdraw some of the privacy pools ETH directly into our fresh account so we can swap on unis swap but anonymously. So, we just click send from the private account, pick privacy pools. We'll input our fresh address that we want to receive the funds. And I don't know, let's withdraw 0.
4 ETH. Why not? Okay. So now we're going to click send. And we do some client side proving here interestingly so that we can create the zero knowledge proof to withdraw the funds from privacy pools.
And this is broadcasted by a relayer so that uh whoever is paying the transaction fees for this does not in no way linked to our identity. So the relayer is going to broadcast this transaction. The funds are going to leave privacy pools and hit our completely unlin account connected to unis swap. And when that's transaction is included we can uh move on. Cool.
So, looks like we've been included. And if we check out the unis swap application, there we are. We can see we've got some ETH. So, why don't we try to buy some token on Spoia? I don't know.
Uh, cool. So, we can spend a little bit of ETH. And the Kohaku wallet functions like any other browser wallet. We can interact with all the DAPs uh same way we always could. It's not noticing my balance just yet.
See? Great. So, we're swapping some ETH for Uni, but we're doing this uh much more privately thanks to the Kohaku wallet. Just wait one more time for this transaction to be included. Okay, it's been included.
Great. So, what have we done? We have deposited funds into a privacy protocol. We've withdrawn from a privacy protocol into a fresh account to use a DAP in a more anonymous way. And uh the last feature I want to show you guys is um one thing we can do with rail gun which is if we have funds inside of rail gun like we do here we have almost 500 USDC we can do a private internal transfer.
That means uh if someone else has a zero zk rail gun address um instead of withdrawing from rail gun we can without ever leaving the rail gun shielded pool just uh send them some funds completely anonymously. So we get privacy for both sender and receiver. So, uh, yeah, I'm going to try to send my friend Nico some, uh, USDC. So, here I [clears throat] go. And I want to give my ZK address to Cass.
So, I'm going to simply open my Kohaku wallet and go to my private account. And here you go. I don't have a balance yet, but that's absolutely normal. And then I copy my zero zero ZK address. And I will give it to C right now.
All right. I just got a notification on Signal. Nico sent me his Zero ZK address. So, open up my wallet, navigate to send here, clicking rail gun USDC, pick up the address, and let's send 100 USDC to Nico privately uh for both sender and receiver. Uh wait for it to be included.
Looks like it has been. If I refresh my account, we can see I have 100 less USDC. Let's see if NA received response. And so I'm going to go to my private account, fetch my balance, and here we go. I got a $100.
Thank you, Cass. So, uh, that's pretty much it. Uh, thanks for, uh, your time and for watching. We're really excited about the privacy features we can bring to traditional browser wallets with the Kohaku SDK. Um, so if you're building a wallet or you already are uh working on a wallet and you want some of these features, definitely reach out to us.
Again, thanks so much and hope you enjoyed. See you. Thank you for the hardware, Cass. This was a very nice demo. So, as you can see, uh, Kohaku is a set of primitives that can power wallets.
uh we have three main goals. So an SDK that exposes strong privacy and security features, a power user uh oriented reference implementation that you've just seen and uh collaborating with existing wallets. So we don't want to be a wallet oursel. We don't want to maintain a consumer product. So we want uh you guys that are building wallets to use us uh to use the SDK.
So reach out to us. I'm going to walk you through quickly the features that we've been working on for this first version. Uh so everything you've seen here uh when we fetch the data you you might have noticed that it takes a little bit more time than usual. Uh this is because we're using Ilios like client. So basically when you use Ilios you remove the trust from the RPC.
So this is a very nice and cool feature. We are also working on a minimal uh execution client with an oblivious server which would allow um for the RPC calls to actually be private. Uh so not only they're trustlessly verified but they're also private. Uh once we will have this uh this server currently it's being developed by Oblivious Lab. Shout out to them.
Uh we have the private end that you've just seen. So we're using privacy uh pool that has been developed by uh Wonderland. Shout out to them. They are doing an amazing work on this wallet. Cass, our one and only Cass did the reggon integration.
We did the private receive and private payment requests. Uh again an amazing work from Wonderland. Uh so we have the aggregated uh aggregated view of the privacy uh tokens. Uh we have uh we are working on preventing IP leakage. So we are working on a to library that we found.
We have one account per DAP as you've just seen. Uh we are also working on a new wallet connection kit that is a privacy first protocol for uh JSON RPC connectivity. This one will be uh showcased to you during the week. We are also working on a social recovery kit uh that is being developed by the PSC team. Uh it will use uh ZKGWT in the beginning but also ZK email, ZK passport and anon ADAR in the future.
Uh we're working on a postquantum kill switch with the zenox team where you will be able to deploy a pass postquantum account. Um so in case uh we reach postquantum um computing you will be ready. Uh we are also working on a universal ethereum application for hardware uh that we hope to be able to showcase this week. This this is an application that will be able to run on uh multiple hardware. Um, we are working on ZK hardware signers that are almost ready.
Uh, allowing you to use privacy protocols directly from your hardware wallets and unlocking u unlocking the security of hardware wallets for privacy protocols. Again, shout out to the ZK Knox team for this amazing work. Uh, and we are also developing spending policies. So we will be working with the 4237 team to have spending policies so that you can uh have different signers assigned to different spending policies. And last but not least we are also looking into broadcasting transaction directly through the peer-to-peer network uh without even relying on on RPCs and future direction that we're exploring a native Ethereum browser.
So we're bringing back Mist all over again. Um we are also working yo shout out to mist um and developing a local AI uh transaction scoring to improve the security and the privacy so it can warn you if you're leaking your privacy through this next transaction and we are also collaborating uh to make native account obstruction happen on Ethereum. Uh thanks a lot for the time. Sorry for the little demo effects. Uh hope to see you all during Defcon and that you enjoyed the presentation.
See you soon. [applause]
Automatic transcript — names and jargon may be misspelled.