New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Privacy Voting in DAOs - Panel || Ethereum Privacy Stack, Devconncet 2025

Ethereum Cypherpunk CongressFri, Jan 9, 2026, 12:00 AM

Panel discussion where Lasha Antadze (Rarimo), Anthony Leuts (Aragon), Jordi Pinyana (Vocdoni), John Guilding (MACI) and Joshua Davila (Bread Coop) discuss importance of private voting in blockchain spaces, DAOs, cases of proving identities and much more. Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/

Transcript

[applause] Hello. Hello. Hola. Hola.

Hi everyone.

If you're waiting for the panel about private voting, you're in the right place. I think we're just we're just missing the last the we're just missing

one. John, one more. I think he's he's sprinting up on stage, but maybe I can already um introduce myself in the panel. My name is Joshua Davila. I am a writer and podcaster for the blockchain socialists.

Um as you can maybe tell from my name, I hope I am a democracy maximalist. I really really like democracy. I love people giving inputs and I love outputs reflecting uh the will of the people. Um, it's definitely one of the things that inspired me to get into the crypto space and it's something that I believe um, the technology crucially should be used for, not just uh, pump and dump schemes and memecoins, but also for the ability for us to express uh, our desires in ways that are not necessarily always mediated by the market. Um, and one of the things in the crypto space I think that we've been kind of missing um, when it comes to democracy is the same expectation that we expect out of any sort of national election, which is for our votes to be private.

Um, and so I'm here with um, a couple of smart dudes on the stage with me as well. Lasha from Rammo, uh, Anthony from Aragon, Jordi from Vogdoni, and John Gilding from PSSE uh, working on Macy. Um, and yeah, the way that I'm going to go about this is I'm going I have a few questions and then um, we'll have some discussion. I really dislike panels that do kind of Q&A style, so I encourage my panelists to interject with each other and um, be combative and disagree. Um, [laughter] and so yeah, maybe we can just get right into it just as a as a primer for everyone.

Whoever wants to take it, whoever wants to go first can take it. Um, why does private voting matter and why couldn't we do it before with crypto? Why is this moment interesting?

Okay. Hey everybody, uh, Anthony from Aragon here. Um, why does private voting matter? Um, simply put, um, without privacy, um, it's unlikely that the decisions that are going to be made are going to be made accurately without privacy in play. Meaning, people are not going to be as honest about their decisions um, if everybody can see what that decision is going to be going to be because there could be, you know, reprisals or whatever that might be.

Um nowhere where more do you see that than in our industry where if somebody votes um doesn't vote yes um on somebody else's proposal in a very small community then everybody gets very upset. Uh and so if you look at probably 99% of proposals out there probably 99% of people vote yes on 99% of those proposals um because nobody wants to be a party pooper. So if we had private voting, you would have much more honest decisions and thus better outcomes.

Can continue.

Hi. No. Okay, perfect. Uh so hi everyone. This is uh Jared from Vogdoni.

I would uh move a bit and I think that one of the biggest and most important things about private voting is user protection uh from the voter and from the organizer. I think it's super important because it protects the voter and organizer against retaliation. It encourages honest expression. We increase the trustworthiness of the of the systems because people can actually see that everything is kind of right and they can express themselves in a in a proper way and it also prevents vote buying. So I think these properties of protecting the user and also the organizer are really important.

Oh hello. So yeah, hi everyone. We build the private voting staff freedom tool as a kind of public good. So this is our key from the protocol. But in general like do you know like private voting was invented by Australians in general like within the ballot boxes.

It didn't exist until like 1870 or something.

So Australians.

Yeah. It was called the Australian ballot box where the first privacy was introduced and back then like Brits like the power they they were against it. They fought like like 30 years until it became a common standard. So privacy had a friction even with the physical ballot boxes and privacy and but but the like statistically like and I I I'll just have this kind of historical answer if it's okay. Statistically what it caused was like you had like a upside of like participation because like you couldn't like course and like trace who voted how and it did really bring this kind of credible neutrality right so it was not like uh I would vote and then I had to like fight for it but I could vote decide and like keep calm and chill with the results.

So I think it has all the great effects of the modern democracy we have it and private voting on chain that's like I don't know there's no alternative to it especially if we touch the real world and kind of decision making.

Yeah I think these guys covered most of it. I think the thing that I'll add is uh why couldn't we do private voting before? Um it's it's been a bit of a technical challenge. um uh being able to have all of the properties we want at like the correct cost on chain. Uh when we started Macy a few years ago, nothing really existed.

I think people have figured out like what the good designs are now where things can scale to millions of of users. We've just published a state of private voting report 2026 where we've analyzed 12 projects, projects that these guys have have contributed to and uh the the kind of state of things is is pretty optimistic. There's also some non-technical reasons why private voting has has not been adopted. I think people quite like the fact that we can vote publicly. So, there's definitely some work to be done to kind of change that narrative like we've kind of seen the the rise of the the privacy meta this year in 2025.

We need to also persuade people that voting privately is a good thing. um can go into like various reasons why people think that, but yeah, that's that's um a good non-technical reason why um people haven't adopted private voting yet.

Yeah, I think one of the things that I've been reflecting on is that um what private voting allows us to do is also avoid the kind of like uh toxic positivity I think in the crypto space is maybe one thing we can say. Like Anthony was saying, 99% of proposals are yes [laughter] because no one wants to publicly say no. Um, private voting allows some uh I guess some some ability to disscent and I think like maybe Vtonon's experience in Catalunia and um uh Rammo's exper experience in Russia are two places where you know in real terms not just on Dows or in crypto spaces where that that matters a lot. It's 8 to nine years in prison if they caught you that you participated. So

89

8 to n 8 to n

depends on the

well and and to that point like you know uh even when in the real world you have polls that are done on elections, right?

Um polls often are not super accurate because what happens is is they go to your house and they ask you publicly like what you're going to vote on, right? Uh, and most people are actually less willing to say who they're going to vote on than what they're going to actually vote in private. And so that's why you see this dissonance between actually like what the polls are saying and sometimes what actually happens in votes. So actually like often a better methodology is to ask somebody's neighbor what you think that their neighbor is going to vote on and those polls can often be more accurate. So it goes to that point though right where privacy actually allows people to make the decision that they want to make rather than the decision that they think is popular.

I think there's it I think there's there's another example uh which is more like in-house where uh woman's doesn't feel empowered enough and they vote basically in like more traditional uh scenarios what the man says and I think this is a good reason for allowing and and to in order to improve and and deliver private voting because I think we will learn a lot from women's opinions that are not like forced to vote in a specific way because of their social uh environment and also I think we are in a the best moment of history to apply this kind of voting the all the advancements in uh applied cryptography distributed systems and so on. I think that we kind of democratized this access to private voting because in the past this was like super expensive at just in the hands of nation states basically and super powerful uh organizations. I I think we need to go deeper within the private voting. So now we can vote privately, but there's still one little thing remaining where you as a voter still can can prove or like show how you voted. I think we need to remove that dependency as well because it breaks away a lot of like economical kind of back backbones that are usually used in mailing elections in real world.

So how how that works that like okay you go into a private ballot box or you voted but depending on like the proof that you like literally show that I kind of like voted and stuff uh they enforce like a certain agenda over you they repress uh people or they there's this entire technique in physical elections where they give you a um completely clean ballot they has not a clean one they already has a cross the number on the ballot and they force you to go into the ballot box and take out the clean sheet.

So you always know that you put the ballot box that they enforced you to do and uh you came out with a clean one. So there's like all these techniques that have been like evolved in terms of how people are you and this like mostly like the repressive states are using these people. So privacy is super important at every stage. So it should be like even not able to be verified for my own keys. Yeah.

I think kind people kind of forget with in-person election voting. Not only is privacy important and when you go into a voting booth, no one can see what you do, but you're also free from side games like bribery. And we kind of as mentioned take that for granted when we vote in person in a blockchain context when things are verifiable and transparent. It's very easy to provide a receipt and collusion could scale very easily because it's very simple to kind of write smart contracts that automate this this bribery that happens. We haven't seen too much in the past or too much collusion uh kind of scares with blockchain voting.

um we would we would view it like in in order to get to the the the maximum um kind of pinnacle of onchain private voting. We need these anti-ollusion properties. We've kind of seen the beginning of this this year. There's a team called Antiapture that engaged in a vote buying exercise to kind of prove that this is an attack vector a few months ago. So they bought some votes um uh as part of an arbitrum arbitum dowo and impacted the result of the vote.

So, we haven't seen too much of this kind of uh use case in the past, but uh maybe we're seeing the beginnings now and and definitely having these anti-lusion properties is like a critical critical part for private voting. It's not just being able to vote privately.

Yeah. So, I'll definitely want to get into the some stuff about anti-lusion. Um I think there's something interesting about privacy right now at the moment. you know, uh, voting in the blockchain space is really like, you know, uh, there's you can always wrap around it and put a price, right? There's always a price to someone's votes possible in in many Dows and oftentimes that's kind of like outwardly encouraged um through various systems where you can there are essentially bribe markets and that's you know because it's a financial application they kind of accept that that that happens.

Um, but that's not like uh I wouldn't call that very democratic and I wouldn't call that ideal for many many other use cases for voting. But um maybe first I wanted to talk a bit about um the differences between the protocol level of the of of voting and the application layer of voting. I'm just curious from from your guys's perspective if you guys have any thoughts on which part of the layer is maybe uh is more is more difficult perhaps. Um the protocol is something that I think we've in part been able to achieve. Um like Jordi said, we now uh not just nation states are able to facilitate even a private vote or centralized systems or what have you.

Um now we can do it and so now we can build the applications for that. But I imagine that's also like a um it's new territory um at the moment. But I'm curious if you guys think have a thought on which one is more difficult to kind of um make. Maybe I can explain about our context. So I think one of the biggest problems we we encountered is in two layers.

So the social one and the application one. So I think even that we got better and better on providing a good user experience uh to the voter. We still struggling to provide like a one-click UX for voting privately and this this stops a lot of people from from for voting not that much in those but a lot in the in the let's say real world scenarios and also in the social layer. Uh there have been a lot of attempts of doing private voting in the wild and we failed during the past 20 years. So people are a bit reluctant and they it's difficult to gain their trust to make them to trust the system because we failed so many times that now it's it's difficult.

Uh and I think this are kind of the main problems we we encountered in our context.

Yeah, I think at a pure technical level we've got all the building blocks in place, we've got the cryptography, we've got some of the protocols being built. I think 2026 will be the year that uh the the protocols that are going to production now will really come to fruition. Uh and then after these protocols have gone have gone to production, people need to do some work to implement them in all of the DAO tooling providers. So in Aragon, Tally, Snapshot, Agora. Um and I think that's when we'll see like uh the ability to plug and play private voting into Dows.

But in terms of like a technical level, I think we're there. There's definitely some interesting future potential work that we can still do. Uh just like Ethereum has to be quantum resistant, our private voting protocols will need to be quantum resistant. Uh various improvements could be made to the UX like as you mentioned, doing it in one click. Um improving the devx of using these protocols as well.

And yeah, as kind of briefly mentioned before, like um selling the fact that private voting is a good thing actually. Do you have any thoughts? U

I think like the good news I have a good news and a bad news. Good news is that the technically actually voting private voting all the primitives we pretty well build out on the level of the protocol like vote counting like how do we smart contracts everything is there. Another piece that was missing and like all of us here contributing last year and that has been like going was this addition the another layer which is like identification layer where we enabled not only kind of token based voting for whatever but the real people and real identities to be brought in like passports biometry and stuff and still maintain this full anonymity and decentralization. So systems could be couldn't be shut down. So in a way if you look from a technical package perspective it's ready it's like it's out there to destroy something but we don't know yet like how to deploy it in real world.

So what is the context like how to build out the trust that is away from the technical challenges and what works what's not like is it purely political is it more like a coordination aspect is it more like a to distinct between this uh I don't know like echo chambers of different narratives versus the truth what people believe so I think like we we we're at this moment when we should take this technology and not just like brand it as voting but more like a okay it's like a kind of truth measurement in different forms and iterate on this but that's a heck lot of a challenge and u that that that's basically the friction point in my opinion

the identity

yeah of course because like if I mean if you ask me

okay we figured out the fintech and like all this how the money should move and exchange but voting if done right is the second biggest use case for the blockchain and identity plus voting and the privacy it all comes together. So it's it's one of the largest and biggest coordination layers we never had before. It was like an exclusive function of either a government state or like some kind of like small platform for run this coordination layer and for the first time like we had an incredibly neutral infrastructure for money. We have a credibly neutral infrastructure for coordination and especially as this craziness of the AI and like narrative wars continues. This will become the only space where the genuine sentiment could be measured in different forms.

So I don't think what could be bigger than this.

I don't think the right term actually is coordination. I think that that term is overly overly used because there's no difference between coordinating offchain and onchain to be frank. But I get where you're going with it. Point is the primitive that's new is execution right offchain any form of execution requires a trusted intermediary it's the same with DeFi it's the same here with decision-m right you can actually execute on decisions without a trusted intermediary right that's extremely powerful that is a new primitive and that's why it's so and also that's why it's so complicated so yes to the question of yes okay um it's complex from a technological perspective that's true from a UX perspect perspective. That's true.

If you add any um if you add anything in the way of somebody voting or add any level of friction, you see a huge drop in participation. But way more complex than that is the fact is actually the governance which what voting helps achieve is what's built on top. Uh is the fact that governance is an infinite design space built on top of uh a large design space which is what is it governing um right which is products, protocols etc. And so when you combine those two, you get a really really really complex um problem that you need to solve and structure. Um and that's super complicated.

And so everything impacts um you know each layer is impacted um what of what you're governing and who is governing what and so it's really really really challenging and that's the problem. And then you know you get these tough requirements and then okay now you have to replicate that from a technological perspective and a UX perspective. Um and yeah, it it really snowballs from there and that's why I think to date it's been very challenging to have like um private onchain execution and governance um really become mainstream. But I think yeah so I mean definitely here execution is kind of like the new thing that we've got now for sure. I think identity is something maybe I want to dig into a little bit more and how we can solve this problem because it's kind of like a it on the surface it sounds very uh paradoxical that you need identity which is the opposite of privacy and then you have private voting like you need to always have you need to define your demos right

it depends on the the environment and the context we're using so freedom tool is purely for real world voting so the all the use cases that have been done it some kind of nationbased like digital protest or like come out to sign a petition or those type of things. So their identity in the form of the passport was super important. Unfortunately, I have to mention like the most of the people who were kind of brave enough to use this technology and like to start distributing with their context, it was highly political. I don't know. One of them is in jail and I just have to highlight like seriousness of like the stuff they were doing.

Another one is in exile is like sentenced 11 years and within this kind of terrorist list by the one of the authoritarian states. I'm not going to go into names but this was the kind of reality of the people that were trying to deploy within their societies and identity in the form of the nation identity and the genuine signal to get from their supporters was this environment it was deployed. So that's why passports played a crucial role in unlocking this type of interaction. Right.

Okay. Uh yeah I think one of the biggest problems of identity is flexibility. Not all organiz all all the organizations have the same requirements on on identification and also uh I think we cannot expect uh to have an unified crossber identity in all of the world. So I think we should be adapting to each organizations and for example even if the passport and electronic ID use case is super important and it's one of the best identification way you have then when you go to a country you see that most of the people don't have a passport or some of them don't have like an electronic digital identity. So for example here in Argentina we try to do some experiments with digital identity and the document national identity that is not electron is I mean it's not digitally signed and it's super difficult because who here have a passport maybe us because we are traveling and we require it but you don't have like this unified identity system that you can use.

I think it's really important that we take into account that we should create things on top of flexible identity systems

or we scan our eyeballs into the orb.

Oh, they won't solve the national the identification problem.

Yeah. Um proof of personhood and identity is one of the the harder problems in in crypto. We recently did like a bit of an experiment with uh human tech and human passport as we were running the Gitcoin privacy round. Um obviously like passports and ZK passport could work quite well for like national elections when you need like cross national votes or Dow votes you need proof of personhood. I think the approach that they've got is quite good.

So you can have like your ID verified. I think a recent feature that they've just released is like ZK email proofs. So you can like um use ZK email to prove you've got like five emails from Uber or Amazon and that builds up your your score. Um so so that's really good. And then I think I think one issue is like you just want to reduce the the damage that people who break into the system can do.

So like even if you have this proof of personhood score and you've got a score above 20, people can still um yeah break into the system by like farming farming face IDs a bit like what happened with Worldcoin where people in like countries where the cost to to to bribe people for their faces is very low. Like hey I'll give you $2 to scan your face and then you can just like farm farm IDs quite easily. That's quite a hard um attack vector to protect against. I think human tech have some kind of like data analytics that detect like hey like these IDs were created at the same time using the same mechanism like uh let's block those. Um and then yeah just like reducing the damage that these exploring ways to reduce the damage that these like attackers could do.

One maybe more like niche but interesting approach with the the Gitcoin privacy round that we did is like yes people could generate like fake IDs but the the voting mechanism we used was quadratic voting which incentivizes broad support rather than putting all of your eggs in one basket. So even if you successfully create 50 fake IDs, you're disincentivized to put all of your eggs in one basket and you're actually the the kind of like attack that you can pull off isn't as effective because the voting mechanism use forces you or incentivize you to spread your your vote more broadly. Maybe a more niche example, but that's that's maybe how we can think about these things and like think of ways to uh reduce the possible damage that people can do a bit like with um collusion resistance as well.

Yeah. Um, I hope some of you guys were able to take part in the in the private voting rounds that um that Macy and Privote uh ran. Um, I'm very biased. I got a little bit of money from it because people voted for me, but it was very wellrun. Um, but one of the So, we're we're nearing the end, so I kind of wanted to skip to my spicier questions.

Maybe that's a question that I have. But I think I'm noticing and hearing is that um private voting is not a it's not purely a technological problem. It's also a very political one which is I think um very interesting just because generally historically in the crypto world if you ask if you talk to a lot of crypto people they'll say no no there's no politics here. We're we're just talking technology right there's nothing or don't don't ask me who I voted for whatever. Um but in this case um it is very political and it's something that I think we need to embrace and and just think about directly or else we're just not going to solve um what we're trying to solve for.

But when thinking about this question about politics, I mean Macy it's anti-olusion. I kind of want to ask like is all collusion bad? Um I think that there's maybe there's maybe a case for collusion as uh in the case of um the creation of social movements but I'm wondering you know so a question what if whether or not collusion is bad and whether or not um uh maybe or like how you guys are thinking about collusion specifically.

Yeah I guess initial comment is collusion is just another form of coordination. You can have good coordination bad coordination. Um, an interesting example we spoke about the the other day at a workshop was um, uh, US members of of Congress and how over time uh, maybe like 200 years ago, members of US Congress didn't really coordinate with each other. And over the next like 100 years up until today, coordination is very common in in Congress. Like, hey, you've got your proposal, I'll vote for that, I've got mine, you vote for this.

And that could be good or bad. Maybe this is to um uh defeat the other party and because you think you're right, maybe it's to start factions and it it's for lobbying. So I think it's a it's I think it's for me it's 50-50 like you can have like good collusion and bad collusion. We want to stop the bad types and encourage the good types.

Yeah. Uh 100% agree. Uh I think uh what we call politics today is basically an open and transparent way of colluding. I think that collision is bad in bad examples like when there's coercive or you want to bribe someone. So then I think collision is a bad thing but not per se even though we should work on this on on the private voting realm because I mean we should be prepared for this edge bad cases.

Yeah. I mean, as a as a good Swiss person, um I'll be neutral on this on this um [clears throat] question and say yes that it's it's not good or bad, [laughter]

but that's the truth of the matter. I mean um I think the goal is about the outcome. I think the the much larger issues in our particularly in our industry um regarding voting is that voting um so far hasn't meant anything which is sort of sad. Um but voting hasn't um there's been very few um times where voting actually had you know onchain executable powers. Um and thus you see that voting has sort of decreased over time.

And I don't think privacy necessarily is going to fix that. We need to get the incentives right first to create meaningful and valuable tools and products that can be governed by by potentially voting um by whatever input that is. if it's tokens, which is very common now, that those tokens then have some value. And then I think you'll all of a sudden see that with people having skin in the game, they'll actually start to participate because they care, because they're personally affected by that. Um, and then um that's when privacy would be more important to factor in.

Um, and then one can decide if collusion is important or not at that at that aspect.

20 seconds.

Yeah, me as a fellow Eastern European, I have different problems. My problem is that like whether I'm not talking about the token, I'm talking about real life. My problem is that every 10 years a government takes over the ballot boxes and then there's a kind of a death fight until you kind of have another rotation of the power and stuff. So the system of initial democracy, institutional democracy that was given us and over years some folks in a certain time span figure out how to overtake it. So I'm looking at this technology pretty political and the idea is that to take it into a neutral hands

and us as as a community being able to operate this very simple and easy layer of holding elections or like protests or signing petitions and show the numbers because at the end of the day democracy is a numbers game. So whoever is good in mass and we can be good in mass and show that is going to win and I believe in this type of like implementation and that's what my primary problem I'm trying to solve is.

Well I think we are at the time now. So thank you guys for coming.

Can I can I drop a quick shill?

Quick shill.

Um this is highlighting the work that all of these guys have done here. If you're interested in the the state of private voting and where we are today, go to psse.dev, dev, check out our blog and we've got a 70page report that you can dig into and it covers everyone's work here um sitting at this panel. So, please check it out if you're interested.

It's a great report.

It's a good report, guys.

Excellent report.

Thank you. Thank you very much. [applause]

Automatic transcript — names and jargon may be misspelled.