Ethereum Institutional Privacy Now - Panel || Ethereum Privacy Stack, Devconncet 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Here Oskar Thorin [IPTF/EF] opens the panel about Ethereum Institutional Privacy and work of IPTF. Discussion features Zach Obront (Etherealize), Amzah Moelah (ABN AMRO), Eugenio Reggianini (European Blockchain Association), Francois Garillot (Miden) and touches several important topics from developing and building, technology growth and much more. Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/
Transcript
[applause] Hello.
Hello. Hello.
Yeah.
Can you guys hear me? All right. Cool. Uh yeah. So we'll first do like a very very short uh talk here.
I do like a 3 to five minute intro talk and then that will lead into the panel just mentioned. Uh this is an abbreviated talk. Uh the previous panel talked a lot about compliance and privacy and so on. Uh I give a previous talk at Cyban Congress that also touched on this and there will be a longer version of this talk at D5 today later today. But what I want to talk about is institutional privacy on Ethereum.
Uh my name is Oscar and I'm the IPF lead at Ethereum Foundation together with Mo and it stands for institutional privacy task force. Uh and why does institutional privacy matters? It matters for a few reasons. I think one big reason is that if you look at these massive massive uh sort of financial uh institutions that exist, we're talking about trillions of dollars in monetary flow and and it used to be that institutions that regulation was the biggest blocker for them moving on chain. But what what's happened in the last few years now actually privacy [clears throat] is the biggest blocker for them.
So what's the leverage and impact here? I think even just moving uh 1% of traditional finance funds to Ethereum would have like massive impact in terms of the impact Ethereum can have on on privacy and so on. Uh and just having a single institution um onboarded here um also touches on like millions of users, right? Uh this is not hypothetical. There are institutions that are already on chain and there's multiple things happening um over the next uh year or so here.
there's like massive leverage and the time for this is now in terms of institutions moving on chain with privacy built in uh and a single institution large institution here can have a massive impact uh compared to in terms of which ecosystem eventually win is if it's Ethereum or if it's sort of more private versions it matters a lot how sort of we enable these type of use cases uh why do they want Ethereum uh there's a few reasons things like liquidity uh sensor persistence like 10ear uptime and being like a sort of a selling point in terms of settlement there are other alternatives as well But they have different limitations. Uh but in order for Ethereum to sort of onboard onboard these institutions, they need sort of address these privacy concerns they have. So what are those and this leads IPF and why we started stands for institutional privacy task force. What we're trying to do is onboard institutions onto Ethereum and making sure the privacy goals are met and we do things like workshops and so on and trying to kind of demystify the space and make sure that we can uh address institutional needs when it comes to privacy spec specifically. Uh the first artifact we have is this institutional privacy map where basically we we we talk to these massive institutions.
We try to understand what are their business use cases and requirements and then uh we open source as much of that as possible and then we talk to various vendors in the space and sort of specification experts and basically try to connect these two things both the institutions on one side and then the solution space on the other side and it's very much a work in progress. Uh, I'm going to skip all of this and here's a QR code to to the map uh if you're interested in knowing more about this. But now let's move on to the panel.
Impressive.
That was impressive speed.
All right. Uh
quite impressive I'd say. Yeah.
Sorry.
Quite impressive for speed.
Sorry it was a bit fast but hopefully understandable. So uh this panel has lot of a lot of experts across of uh research and policy and engineering and so on and we'll talk about institutional privacy. So just a brief introduction. So we have Eugino uh who's the head of growth at the European blockchain association and Italy's ICO credited expert at TC 307. He engages with EU institutions, regulators and industry to align decentralized identity, privacy serving infrastructure and blockchain governance with emerging international standards.
And then we have Zack H. Uh Zagarun is a CEO of Epherise uh where he's building institutional products and the underlying primacy privacy primitives needed to support them. He previously worked as a security researcher uh securing tens of billions in TVL and and serving as a steward for EF's trillion dollar security initiative. And then we have Amsa who spent most of his career in uh financial risk management before getting deeply involved in Ethereum and crypto space. And now he's bridging traditional controls with Ethereum native markets to advance tokenized assets and resilient institutional frameworks.
And finally we have Francois who's a se senior staff protocol engineer at Polygon Maiden who is focused on ser knowledge proofs uh systems and fought for privacy uh with private ro private roles as executive and co-contributor across blue chip web three uh teams. He leverages experience working on enterprise software to design compliance workflows of web 3. And as I mentioned, I'm leading this IPF uh institutional privacy task force at the Ethereum Foundation. So I think maybe to get started like in one sentence or maybe a few sentences, what institutional problems are you working on that actually requires privacy on public rails rather than just a traditional database or or private chain? Uh maybe we can start with uh Franis.
Yeah. So um yeah, of course you you you can always build on on a private blockchain, but today we believe that institutions want to access global liquidity that is offered by Ethereum while at the same time retaining what they have from the traditional finance world, which is a degree of privacy um that allows them to trade with global liquidity but while not making the entirety of their their trade trades public. Um for us that's why it's important both to build privacy in but also to build on Ethereum.
Well um uh maybe I can take this from a more different perspective from standard perspective. I think institution uh and in the standard process there is a very important concept for institution which is the trust anchor essentially every institution has a big let's say let's call it offchain environment to which toward which they anchor liability into the society uh to everybody's using their services. So one part of the big problem on creating let's say blockchain based services for institution is how to create an efficient system to bridge the trust anchor into the onchain world and then on the other side one the data is actually can be triggered onchain how to embed different cryptographic techniques to ensure that data is actually processed in a minimal way but still in auditable and verifiable manner. Cool. Uh yeah, so at Etherealize we're focused on upgrading some of the like deep inner workings of the financial markets, specifically credit markets.
Uh so I'll tackle it from two directions. One is why privacy. Right now all of these markets run on bilateral agreements. So there are two parties. They are very used to the idea that the exact information that needs to leak leaks and nothing else.
And so the only way they would consider public blockchains is with that level of privacy met. Um, from the other direction, why be on a public blockchain? These are complex markets with parties who don't necessarily trust each other and are needing to rely on regulation sometimes across countries. And so to have a source of truth at the center of those markets is a huge advantage that they can't do without public blockchain. So right now they're kind of at a standstill saying there's this upgrade potential.
We can't do it without the privacy we need. And so we're trying to bring those things together.
Yeah. So I work for ABN Ambrose. That's a big Dutch bank. uh we have 5 million retail customers. So we're not actually building something right now specifically in privacy, but what's coming up now is for example a digital identity wallet.
And usually how that works is uh data is stored in a centralized database and then you connect with some kind of uh uh yeah outside provider or a third party. But that's of course not really safe. So we already starting to think how can we use ZK uh proofs for example uh so we could have selective disclosure with outside parties and in that sense we can then uh protect uh our customer information and also let them connect with the broader web free uh environment. Okay, great. Uh, so this is a question that this was sack of Frano, but I'm saying feel free to jump in as well.
Like if you pick uh one concrete flow that you you might care about like maybe some bond issues or trade or some treasure payment or whatnot like who can see what exactly and what step and like what is stored onchain versus offchain maybe starting. Yeah, Fran go ahead.
Yeah, thanks for the question. Super happy to have the occasion to answer it. So one great way of approaching this is to approach it this from the point of view of wanting to trade with a DXR unis swap. Um the nice thing is that we can offer on maiden something that offers the full anonymity that is we have anonymous accounts that trade with each other through nodes. So it's a mix of the account model in the UTXO model.
If you're trading with a venue, that venue will want to be public because as a DEX, you want to p republish the prices every time you've uh interacted with with somebody. So, you are emitting notes into a batch that the the as the the user there's nothing on chain except for um what the the venue might might be able to decrypt. The venue performs your trade, emits note on the ex notes on the exit. Those notes can then be claimed by accounts that can be fully private. So you retain full anonymity when it comes to the users and from this B to the users with the exception of that venue that unis swap trader that has decided to reveal some information publicly on your account which is always something you can do.
On top of that we build compliance flows. Now those compliance lures are not based um on on the on the um at the pro baked on the protocol level but we will definitely help you put them in your app. That is of course you can have proofs of your transfer policy whatever the hell that happens to be. Um plus um and we are definitely working on the hell um and plus uh the the view key policies that you might implement on top of this which means market engineering at the local level. that includes auditability workflows, that includes compliance workflows, and that includes proof um of whatever it is that you need to make that market safe and threat resistant is really important to us.
Well, maybe I can take it more from functional perspective. I would say that generally every issuance or distribution flow has at least for institutional service has three key pillars. Let's say the first one is identity and trust which is connected to on boarding flow for investors KYC and everything for issuers KYB process and so on. Um the second one which is tied to actually the blockchain account model is probably what we call the policy enforcement. So essentially the account uh collect all the information from this offchain environment and generate uh a a trigger to a statement of executions on on the blockchain.
Uh that can be done in different ways that of course resemble the characteristic of the underlying financial uh in that sense offer that has been triggered. And in this context, of course, privacy preserving techniques can make uh an efficient distribution of peer-to-peer between, for instance, offering that can only be distributed to certain types of investors that are associated to certain types of accounts and so on. And um and then you have the third pillar which is probably reporting associated to the which is associated to the first one to the on boarding but also to the second one which triggers the the trade operations on chain. This of course uh it I think a glue of all these services how you we can make uh let's say we can extract uh from onchain data testation the data points that we uh actually need offchain to uh provide uh traditional reporting for our clients at the end.
Cool.
So yeah the answer to this is very different depending on which flow right there's there and this I think is one of the challenges in this space is like it's hard to have general principles from how different things are. So like one example of a flow is there's a big loan, an interest payment is made, there's a ton of lenders that has to get split out. The expectation is like no one should know about that. There's no regulation around it. This is this is uh allowed to be totally private and so we we want to be able to support that end of the spectrum.
On the other end, maybe there's a trade of positions in in being lenders there and there's expectations that certain administrative parties could see that the trade happened but not the price. Maybe others can see all the details. Uh and so we've built everything around this kind of flexible model similar to what Alec was saying in the last talk around uh we don't want to be hard coding these compliance rules. We want to be saying a user or an application can determine that for themselves. Uh, and so we've got the ability within that application or user flow to either only see that data themselves or to to kind of enforce additional rules around regulators being able to see things or administrative bodies or even uh giving that data kind of in an aggregated form to associations that aggregate more industry statistics.
Yeah. So I mostly agree with what uh Zach said. So in in the past there so you saw like mostly when institutions were thinking about privacy they just start a private chain and then only maybe let's say 20 banks they uh participate and and then it's just uh let's say uh no only them they are able to see what's in there but actually it's indeed much more nuance. It depends on the use case what type of flows and and what the regulator needs to uh know for example and I can imagine if you put something uh like like a balance uh balance information on chain then it's sort of more on the aggregated form and you use proof of reserves for example.
Yeah. Uh so I guess I'll give you a second to I just also want to add another question Eugene and AMSA for you guys like from banks and venues and regulators like what are some non-negotiable requirements that you keep hearing over and over again like when it comes to for example audit trail or edgibility or KYC rules uh things like that reporting requirements latency cut off times
uh well maybe I can I can start but maybe think is the right fit for that I would say accountability then it comes to on boarding process standardize on boarding process and so on. And then I would say compliance associated to reporting which um for me then it's about uh if you ask my personal opinion it's about framing concrete uh business requirements into uh let's say um technical structures like then the devil is is in the details who is your user an application or the investor that's different that create a different let's say process flow and interaction for your or ecosystem but also I would say that the the goal should be to build this system in uh an efficient way because otherwise that we will have block uh from adoption perspective and this is why I think account infrastructure the way in which are evolving in Ethereum is very cool because they support this operational orchestration that facilitate actually to get us closer to our institution needs.
Yeah. No, no real addition. So, it's sort of like
Yeah. I mean, so and this is not something that being an engineer I lead personally, but there's our co-founder that is an absolute machine spending time over and over over weeks um with customers in the in institutional space. And the top level um demand that comes up is control. who sees what, when, and for what reason. And then you devolve those conversations into details and then they become insanely customized.
You have the green variant of that, the blue variant of that and the the black variant of that. And they all are very specific about that control. And to us this is um great because the traditional finance world uh has spent decades building the GIAPS the the generally accepted accounting practices the AFRS the their AML and CTF flows and they have been created through discussions and through networks they are not global and so they validate our thesis that okay there's a lot of diversities in what people want exactly but the capabilities the control they're kind of all the the same. So we're building with those capabilities at the protocol layer and then supporting customers in de in um through their journey for what their particular favorite color of control is.
I think also this is a consequence of how technology evolves, right? So in communities like Ethereum, technology and innovation grow so fast. Then of course is uh a take on experts like us to try to digest this into an institutional level. And I think the way in which we we saw blockchain networks evolving from like setting governance rules for just private permission access in 2016 or 2017 and now having full comp composibility like you were describing is a great progress that we see.
I want to talk about trade-offs. So what are the main trade-offs that you're currently living with? I'm talking about like for example performance versus privacy or global liquidity versus type controls or onchain transparency versus offchain records. Maybe starting with sack.
Yeah, there I mean for us the biggest thing is fortunately we're in a market where speed is not the biggest priority. These things a lot of the credit markets settle in weeks so seconds is not the biggest biggest thing on their minds. Um but the UX of privacy is very difficult, right? And especially the UX of privacy as people have different priorities. Uh and so and and especially kind of blockchains are very good at maintaining this concept of like cued state that is coming and how do we handle if things change and making sure that transactions are ordered correctly and like there's a lot of infrastructure that we've come to rely on from blockchains and as we start queuing up private transactions things get get complicated.
There's obviously like Miden's doing a lot of this kind of work on their end, that's that's really great.
Um, but trying to figure out kind of the best user experience that meshes with privacy when the bar for people who are used to non-blockchain systems with a lot of trust assumptions is this stuff is private and it's easy. So, we got to meet meet that bar where they expect it.
Yeah. France about 30 seconds or so like
Yeah. I mean, so so I wanted to highlight first uh uh trade-offs that we don't have uh thanks to Ethereum. uh institutions really want to only enter markets if it's worth their time entering which really means they want a global market with network effects a lot of counterparties deep liquidity and we're a roll up on Ethereum um being a rollup on Ethereum rather than a private chain or yet another L1 gives us that differentiator and that access to that deep market now that's the good part of course there's plenty of other things that are quite complex for us we care a lot about that white glove experience for an institutions entering that market so that they can have their own conditions. Um and one of those challenges of course that we might talk about this um is the the challenge between privacy and threat resistance. There's a bunch of thread actors that ex exist in the web3 world today and we really want to get a better handle of that to offer a f a fantastic experience.
And so we are less approaching that from the um let's build in decentralization right away and more from okay we we know how to do that part. Let's do it at the moment where it's what serves the customers the best. Uh Eugina, I'm curious like how would you think about because we're talking about these various approaches and so on and they can be formally compliant and all these things but what would it actually take to make these solutions trusted and usable both sort of institutions and governments? Um okay I think that everything start from uh maybe trying to consider uh institutional services like integrated system where every part of the system does its own uh specific access rule and provide at the end uh data origination from apps and so on. data compression and um and posting from rollups layer three layer two and data decentralization and privacy or independency into the layer one.
Um so I think that um if we combine this system where you have of course an offchain environment where the trust assumption is given to the institution then we can allocate to apps layer two layer one uh different process in uh the issuance and distribution and settlement generally which uh associate which is associated with for instance financial services. so that each part of this process is associated to an a stakeholder that's that match this capability at its best.
Uh AMSA, how do you look at things like in terms of not just being formally compliant, but what would it take for these systems actually be trusted and usable by institutions? What do you think is the main?
Yeah. So for for us it's really important that that it's customizable. So in the beginning you had like blockchain is just one use case or everything is public or everything is private. So that that's that's not like uh one sizefits all. So for each use case you need a certain kind of tradeoffs a certain kind of uh uh changes you can make.
Uh and what's also most important for us is to be uh regulatory compliant. So uh unfortunately uh the banking sector is one of the most heavily uh regulated uh areas and especially in Europe where we are situated that's yeah if if something is is not really correct regarding privacy for example then yeah it doesn't fly with with the regulator and you cannot go further on and you have a lot of like issues and maybe fines etc.
All right we're almost towards the end. Uh I want to give you each sort of a minute each to sort of talk briefly sort of what what what is like one building block if it's like if it's technical operational policy wise that you think would like meaningfully accelerate institutional adoption and like if we meet again in like 2026 what do you wish what do you think is realistic that would have happened this year? So try to keep it to like a minute each uh maybe talking starting with Zack.
Sure. Um I think right now we kind of mentioned this before like the what we mean when we say institutional very broad what we mean when we say privacy very broad intersection of those extremely different in different use cases right um even to the point of like Franis's point before of like oh they care a lot about plugging into liquidity there are use cases we're focused on that are more about building the infrastructure underneath things where they don't care that the rest of the world exists at all right it's just about that this is a better way to do things and So um I think I think it would move us forward a lot to get clarity into the specific situations that we're trying to solve for and how different they are. Um and part of that is on the technical kind of blockchain and privacy side of this. Part of this is also from institutions right in the I don't think there's been the need for what compliance things are required to be categorized and made concrete as much as we would like them to be. Uh and so the push on that side to really map and be clear about the different requirements and how they fit together and how these could start to turn into a protocol that can support them would level up our ability to build something towards that versus kind of the fragmented world more run by lawyers that has not been made as hardened as we would we would want it to be.
AMSA.
Yeah. So the good thing is is the past seven years since I'm active in this space uh the tech came a long way. So zero knowledge proves it's uh a lot of development on the full polyomorphic encryption. Uh I think one of the most uh yeah important things to to improve is the education to regulators also institutions because um now they probably heard about zero knowledge proof incremential but they don't really know how that works. So you can say oh yeah it's really safe and uh it's a real proof but they don't understand why it's a correct proof and why they should trust that and how they still think uh for a for majority from the regulators is also still from uh legal point of view uh something written in contracts uh when something goes wrong who can we call and uh if something breaks who who will fix it and if there's nothing to no one to to call then uh that's a bit a difficult perception for them.
Cool. Uh yeah. Uh you know one minute.
Yeah. Uh um maybe okay I'd like to pick three small things for each. Well on the technological side I think it's probably what of the one of the thing that we it will benefit most is uh zk proving real time proving aggregation because this actually enable to tackle an operational problem that we have is to build complex use case which serve financial or institutional clients which can combine apps uh institutional clients and layer one and then on the policy side I like to support uh the statement on on the education because I uh as a community especially in engaging institutional clients I think again it will matter a lot to start thinking about Ethereum as integrated ecosystem and integrated system itself. Uh I wish for the 26 uh probably from the business perspective we have seen this year a lot of starting initially activity. I would like to uh see more engaging collaboration between projects so that uh application in the market can really start having access to global liquidity global network.
Yeah. So if we met in a year I would like to uh have as we plan launched the the mainet of Maiden in the spring. So we're going to have celebrated that. Beyond this and my my um my particular view, I would like us to be on on our way to to full decentralization have all the the offering those privacy flow but roughly the idea is that this will take a village right so the core thing I want to see happen is really more engagement that is we have those ideas at the moment that privacy is at odd with compliance that's not really true but the the the the truth is that it will take a lot of work towards marrying the two together. That is first before even compliance u let's agree we would like to not have so many terrorists involved in the place where we trade right so the actual threat threat resistance and what uh um compromises we need to make to actually build extremely secure protocols needs to go a little bit further.
More importantly, we also want institutions that help us shape the kind of markets they want to see because we know this is going to be messy. This is going to be peculiar to their particular needs. And we're completely fine with that. Um we want to offer at the protocol level the control that they will um install between their apps, their uh endpoints and their counterparts.
Okay, thank you. We're almost at the very end. I just want to give each of you like 10 to 20 seconds to mention something maybe something that's happened this week or just plug something everybody mentioned just like very briefly so people are interested can find out more 10 to 10 20 seconds starting with AMSA
yeah so I found it interesting so three years ago I was a volunteer helping one of one of the first dev connects or that actually the first one and uh regarding how people look at institutions compared to now that's Yeah, improved. Yeah,
I mean it's just amazing how much privacy is in the air this year and uh my background is in the security space and it has been a recurring theme how re security researchers who understand this stuff are lacking. So anyone who's at that intersection encourage you to go all in.
Uh I'll pick uh probably data regulatory organization. I think there is much hope for TKP in a compliant data main and um probably also the Ethereum interoperability layer that I think will help a lot bringing institution on chain.
Oh my uh it's very difficult as an engineer when you ask me what I'm excited about you usually hear about an extremely niche subject. We've landed pre-ompiles on Maidon recently and the really cool thing to me is that this opens the verification of flows that involves machine learning of any kind, right? Um, so we've been talking about looking at transactions. We've been talking about all listing, blacklisting, which amounts, the travel rule, etc. That's cool.
If you're an extreme nerd like me, you really want to do machine learning and then proofs of m machine learning. Um, that's now a thing we can do.
I want to thank all the panelists. We heard like some very interesting perspectives all the like technology and and policy and institution engineering and so on. And we just scratched the surface, but I recommend you guys to come up to these people and talk more if you're interested in this topic. And that's it for us. Thank you.
Thanks.
Automatic transcript — names and jargon may be misspelled.