Ethereum Privacy Ecosystem Mapping - Panel || Ethereum Privacy Stack, Devconnect 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Panel discussion with Mykola Siusko, (W3PN) Antonio Seveso (Fluidkey), Cyp (Status), Kasandra (Kohaku) and Alpeh V focusing on mapped ecosystem of Ethereum and everything privacy focused on it. Exploring privacy, cryptography and all relating to people first. Ethereum Privacy Ecosystem Map: https://x.com/web3privacy/status/1989058742294344060 Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/
Transcript
[applause] Hey, hey, hello. Hello. Happy to see privacy on the main stage of the connect and many people interested in like how we proceed forward as an ecosystem. Uh today we would talk about how complex and beautiful this privacy world is and how it it's a coexistence of many different actors that complement to each other on moving forward. And I would love these people introduce themselves but through the lens of their relations personal to Ethereum and the privacy ecosystem as a whole.
Uh hi everyone, thanks for being here. I'm Antonio. I work on Fluki. That's a privacy preserving uh wallet.
Uh hello everyone. My name is Alvie. I work on um cryptography and security and I work with a number of projects on their cryptography designs across the ecosystem and uh in privacy more generally.
Hi, I'm uh Cassandra. That's my moniker on the internet. You can also call me Cass or KZgeth or just K. Um I work on a number of different things. So intersectionally um I work with the Ethereum Foundation as a grantee on this Kohaku wallet initiative looking to push privacy uh deeper into the wallet stack uh and get wallets to uh experiment with onchain privacy as soon as possible.
I'm also part of the uh Silva culture society with uh Violet here. Um so uh we are uh an informal group giving advisorship to Ethereum Foundation leadership in a confidential manner on topics such as censorship resistance, open source, privacy and security. Uh and I'm also just generally uh interested in cipher punk culture and the ways that we can opt out uh in different ways uh like uh anarchist collectivist thinking uh activism all of these things are I would say the intersectional relations that put me here today. Uh and I think I try to put all those things working in the same direction if possible.
Cool. Um, hey, I'm Sip. Um, I I'm work I'm working [clears throat] on status network and as you can see, I've been talking the whole week. So, um, yeah, we're building a fully gasless L2 uh with a privacy layer uh that is native to the chain. Um, and my relationship uh to Ethereum at large, um, I've been around since 2015.
I started in Bitcoin originally. Uh but uh yeah, you know, solo staking like really pushing. Uh I think the decentralization part uh you mentioned cyher punk is also like something I I really want to see happening more. Um uh there's Oscar did a great talk about how we need to have cypher punk in the room when decisions are made for financial instruments. So I we hope to be to be here for that.
Great. Great. uh can we put a slide with the system on the background? So we were doing a research uh for granted by Ethereum foundation on how privacy ecosystem would even look alike and what kind of different actors um contribute to this bigger vision of privacy. Also if I look around I see many uh developers, researchers, thinkers, builders, activists um who have so versatile skills but they they are a part of the bigger game.
Um I would ask you how you would describe uh in your own terms uh how does Ethereum privacy ecosystem look alike? What are the key actors uh for now? in any order.
Are we going to list all the privacy solutions because there's a lot now? [laughter]
Yeah, I think interestingly I I feel we shouldn't, right? I mean, I think the the harder part is uh not to make a list but to make a schema or to make a uh
taxonomy.
Yes, exactly. to try to slice in a certain way which I guess now we see that uh we uh you've done some of this work to do this slicing uh but to try to put in my own words to start maybe somewhere I see uh a couple of major initiatives or verticals one that I'm extremely passionate about is the bread and butter of onchain privacy so onchain solutions that obfiscate the uh the participants in financial transactions when you look at public blockchains. So, uh this is things like fluid key and stealth addresses. It's things like what we're working on at Kohaku and a number of other uh uh parallel initiatives. All of the uh shielded pool solutions which we make use of.
Um I believe this is sort of the core or the heart at least from the Ethereum perspective of privacy uh uh of what we might be calling web 3 privacy. Um but this is not everything. So this is the one which I see as like the somehow at the center but uh my question maybe for the rest would be okay so how do we connect what or and or push back on this as the core if you if you don't believe but like how do you connect these other types these other pieces and and what how might we define them and and how are they connected to this core central facet. uh probably the best thing to connect them my answer is always uh through user experience. Okay.
So in a way that uh I think the e the ecosystem has a lot of building pieces now uh sometimes uh it's hard to use one or or the other together in the right order. It's not just using them because it's fine. It's using the right way in the right order. This sometimes goes back to a question that a lot of people ask me is like uh how much private you are and it's like is there like a scale from 0 to 10? How does it work?
No, it's alo very confusing because what's private for me might not be private enough for you and vice versa. And I think that UX is the mean to connect the the the different pieces so that I can sh can share decide you know to go from like a a very easy flow sometimes not as the top privacy flow but easy and sometimes maybe some more complex but if you work around even good privacy must flow into a very easy UX flow. I 100% agree with that and I think what we've seen in the DeFi world is something that we've going are going to see in the privacy world where we're going to have more composible solutions across different type of uh privacy preserving solutions such as privacy pools can work also with stealth addresses um but we need to have the proper flow so that it makes sense to have both of them working together and um I mean as you said it's like it's down to the apps to surface that to the users in a way that is not confusing and that doesn't require a PhD in cryptography to understand what's going on behind the scene. But when people can actually get the sense that hey my money is private now or that interaction with that specific app is going to be done in a privacy preserving manner and being able to communicate that in clear worlds words to the users. Um, and actually I'm I'm talking about clear words here because um I learned something this week um uh through all the panels is words matter and when we hear um so like words like obfuscate and shield and so on the these are words that I've been using all the time and now with you know a regulation that is starting to kind of pick around and then be like okay what are you guys doing exactly?
Um I think we need to have a very normative way of talking about privacy. Um so privacy confidentiality uh have meaning that for the regulator is uh is good. Um versus the moment we said hey we're going to do like shady things with the money. Yeah. Uh so I think the user experience is super important because this is the words that people are going to be looking at and explaining the flows in a way that makes user understand that now it's private now it's confidential but we don't do shitty things then this is what we we need to go for.
Do you want something to add to that? Um, I think often the framing of privacy is kind of as a defensive technology and in some ways I think that the Ethereum ecosystem needs to expand beyond this framing of defensive technology. Like many of the projects are like focused quite a lot on defense and this kind of narrative I think actually holds back the privacy product. I think we should be thinking about privacy as a sort of collaborative community effort and by thinking about it in this way we can actually expand the map of privacy that we're seeing in the ecosystem because most of the most of the narratives that you're saying to users are oh now someone can't look at your transactions with the emphasis on the you I think this will like in in many of the services we actually need to be thinking more about what this can actually unlock for the user in a more like broad sense, what it can unlock for their community and this will help it like uh will help the engagement quite a lot with these tools. Uh I would also say that our goal for for a while is to break from echo chamber of like technical view on the privacy from Ethereum view on the privacy and go outside world talk with like electronic frontier foundation talk talk with tour talk with brave and get a feedback loop on like so what's the real state of not just privacy but a collaborative effort when brave is integrating crypto while tour as you hear today will get way more adoption with Ethereum.
Um or for example coin center is actually defending dev rights and there are many builders in scene that needs uh such strong protection and alignment um beyond uh whatever tribalism you're a part of. That's one bit and the second bit also to understand we keep talking about community but what do we really mean by community for example in fluid key uh history I guess hackathons is a part of the communal effort that helps to get test product testing feedback loop jury at the hackathon who are like suggesting where this product should evolve maybe even potential mentors partners are also does also represent community in that bigger sense but then it's all the people who are using you your product who are trying to promote it uh being becoming an advocates for privacy and stuff like that. So I would also you to reflect like what are the bigger pieces of the ecosystem we are missing in terms of the actors or like bodies uh that would really help us to kind of proceed faster or have a bigger impact these things not necessarily should go together.
Yeah. Um Fluki started as a hackathon project under the hood. No. So for us it's always been like super crucial uh uh getting feedback and uh develop what our users uh want. You know I think that the AATON part is probably on one of the best part that the web three has in terms of how project start what are the feedback collect and so on.
Now looking always at the privacy the part that uh again this is not my point is a feedback I receive a lot from our users that kind of is missing. you were saying is regular the rules the law the compliance no because we have a lot of question what if one day flute key is considered like tornado cache okay or something like that and I think that the missing part probably is that again I don't want rules seen as a bad uh actor I mean we we need to live now if you if you do things that you don't they're not shitty I mean it's okay to have but in a way that are clear and that are clear to us the user want to adopt this type of technology that might be scarce somehow.
Very quickly on that um we actually did some user research when started to think about the chain and one of the ideas were to make it fully private and I immediately got push back that was like two years ago so before the new administration and it was like as an American I will never touch it. Okay fine all right so what do we do now? So now we have like the option you can go private or you can go public but we need to define ways so that people can understand that hey hold on now you're doing something a bit different than usual. So are you okay with it? Um and and on the kind of fully other side of the spectrum uh having the technology so that we can't do something and I think this is super important to fix limits that the technology will be able to do in the sense of can the government query the viewing keys for all the users well if they can probably it's not a private system.
Um so for us building we need to make sure that the way we think about the systems has boundaries that make it easy for us to be compliance roughly but not just giving the keys to the government be like you can do whatever you want with it. I I think this is a super important point and it's it's very subtle and of course very sensitive uh topic for everyone who's working on privacy but I do think uh it's extremely important. I think it's personally totally naive to uh build uh build with compliance in mind with such a framework that will allow uh the governments in the future to have strong lever points to completely deanonymize the system. Uh you need to create some sort of surface potentially for engagement. Uh but my view is that um we can't allow the uh the jurisdictions and regulatory apparatuses inside of them to uh sigh up us into believing that uh these systems must be a certain way by default from the start.
This is how they have uh they have pressed their thumb on the digital landscape and why we're in the place where we are now. So it's absolutely imperative in my view that we both uh we create this possible surface of conversation about compliance with regulators but that these are strictly set up in a way that's strictly enforced so that there is a possibility for some privacy because if not there's uh we're not doing anything here. We don't have to talk about privacy.
Yeah, I will I will echo and agree with Cassandra on this. uh building for compliance I think is kind of a misnomer because compliance where you know there are hundreds of jurisdictions each with their own rules and if you'd like to build a global product you cannot necessarily say I am going to build a completely compliant product in every jurisdiction I think it is much better to build a globally accessible product so that everyone can have the same type of infrastructure in the sense of the internet or these other largecale projects that the entire world uses is and then to say if you need something special you can do it potentially in your jurisdiction you can find a way to work around it instead of saying oh we're going to think about the com the privacy regulations of the United States this is very different than the privacy regulations where I live like in fact some of the data collection that might be required by the United States might actually be illegal under German data pro protection laws this type of behavior of building for compliance I is going to be firstly a big distraction and ultimately feudal. Um, not that it should be ignored, not that we should give these systems over to criminals, but ultimately if you're building something for the general public, you're building an open source tool or a protocol, you simply cannot practically engineer this to work in every jurisdiction, for every law enforcement, for every regulatory body in every comp and every country. Instead, you have to build something that is flexible and generic and that can meet the needs of everyone.
I just w want to jump in really fast as well. Finally, just to say one thing, the way I would think as a builder in privacy stack about compliance is actually from the reverse direction. We know that jurisdictions will try to coers citizens for that. That's their job and that's great. They should do their job and they should have a job to do.
It shouldn't just be transparent. they have to go and they have to ask you. And so things like viewing keys for protocols are I think of them actually as a way to protect users. Give them a way to comply but with a a a small surface so that they have the ability to comply exactly in the way that they need. They can give you fine grain information instead of having to give over you know the spending keys let's say to these protocols.
And so I think we should think about these things from from the view of how can we protect our users, give them a good surface to engage with these um with these actors who are uh trying to coersse information out of you. Um and uh this I believe is like the the right approach and still it's not against uh jurisdictions existing. It's about uh helping us create the right conversation between individuals and their jurisdictions
and scaling this narrative web privacy lore that sometimes when we go beyond the crypto like reaching out to me from signal or Eva Galperin from EFF we're trying to say we're not crypto we're cryptography we're human rights with digital rights come to us and then explore decentralization and like connection points but then maybe someone would talk about crypto but from the technological perspective not from financial one or over financial one and it's a way of kind of like attracting and building the different storytelling for the actors who have skepticism with whom we need to build trust first and that's an interesting like mouse game another example is cyber punk retreat we made this protocol apps when we thought what if there will be no separation to blue sky whizf on one stage uh lots of messengers all together uh no separation and it worked fine. People can't talk to each other beyond the internal tribalism. Maybe some ending notes because time runs out.
Well, on my side, uh um make sure to talk to the project you use and share feedback because that will shape how products are made because if you don't do someone else will do for you. Um, my note is that if you're looking to get into privacy, you're looking to promote it, just pick one thing to be incredibly extra about in all of your social circles. If it's your calendar, it's your messenger, just one thing and this will do far more than you trying to be perfect.
Uh, my my final note would be Yeah, for sure. Agreed. My final note would be um that we should really focus on user experience and practical concrete applications in production. It's great to be sitting here talking about privacy and I think there's an amazing advocacy going on but it's time to move on from the talking stage and to put experiments in the hands of real users and we have all the tools we need already. What we need to do is stitch them together in palatable user experiences.
So let's do that together.
[applause]
I I'll echo that. And um my personal feeling is that we need to stop making privacy uh hackery, criminally, dark, hoodie type of thing. We need to make it something that is normal, social, uh easy, even maybe fun and u even rewarding with, you know, incentives. We are good with incentive in crypto. I don't see with I don't see us being as good as we should be in privacy in terms of incentivization and in terms of like giving people real reason to go private.
Uh as you see privacy can be fun and this is also the element of just being fun because we are humans and we want to connect with each other in a nice human way. Thank fake uh wonderful people.
Thank you. [applause]
[screaming]
Automatic transcript — names and jargon may be misspelled.