New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Keyvan Kambakhsh - Get private, in private

ETHCluj MeetupTue, Jun 9, 2026, 12:00 AM

I’m going to explain why depositing your ETH into a privacy protocol doesn’t actually keep you safe in a world where users of these protocols are being flagged, and why the very act of entering a privacy protocol should itself be kept confidential.

Transcript

Okay, uh First of all, uh I would like to thank Simona uh for arranging all of this because uh I know that it's not typical to have a online presentation than uh and conferences like this. Uh But uh she did her best to make this happen, and I'm very thankful. And I'm very uh I'm also very proud to be be with you guys today. And uh today I'm going to talk about the concept of plausible deniability. And uh I'll tell you that it's important to keep the fact that you're using a privacy protocol private.

You might wonder why am I uh putting this mask on me? Uh it's kind of Personally, I think it's uh you might think that it's pretentious. Uh you might think it's cringe, but I'm doing this to like uh make a point. Like you see I I I could be be be with you guys uh at the same room sitting besides you, but you wouldn't recognize me because I'm not a famous person, but as soon as I put this mask on me, uh I will get the attention of everyone. So, in order to get even more private, I have decide decided to remove this mask.

So, hello everyone. Uh hello again. My name is Key One, and uh let's begin. I'm going to share my screen. All right.

So, this is the Ethereum blockchain. And we can say that every single mainstream blockchain in the world is like this. There are a lot of people, a lot of wallets and addresses doing different kinds of stuff here. And uh it's just naturally hard to find people uh find certain people here because it's pseudo-anonymous. But uh let's say we have this guy named Waldo, the famous Waldo, and for some reason, maybe he's an activist, uh people are looking for him.

They don't know where he's uh where is Waldo in this picture, but they're looking for him. And Waldo is the is the guy who uh like decided to use a privacy protocol in like Ethereum blockchain. For example, he could use a Tornado Cash or Railgun or whatever. As soon as Waldo uses these protocols, this is what the outsiders will see from the Ethereum blockchain. They will see that some people are wearing these masks.

And I think you've got the point like uh when I see this, I will instantly realize that I don't need to brute force all of the people, all of the addresses here anymore. If I just check out who were these guys, who were these guys who put these masks, I can find them. Like I will just see the previous frame and I will I will find Waldo, as you can see. Waldo here. And the guest team.

Okay. So, now I think you um we all agree that the mere act of entering a privacy protocol must remain private. And the formal uh phrase for this concept is plausible deniability. The ability to deny that you have been using a privacy protocol. But I think we can describe describe it in other ways too, like privacy in wanting privacy, like meta privacy or privacy squared.

And it's not limited to crypto, like crypto is not the only place you want to have privacy. For the internet, for example, uh there was a project called Tor Network, which helps people to hide the websites that they are visiting. It's a very useful privacy But uh if you use the Tor Network directly and someone from the outside, some bad guy like watching the network, they can easily tell who is using this Tor Network. And it is just like putting that mask on yourself, which uh not only gives you privacy, but takes your privacy. So, in order to fix that, they uh like added this concept of plausible deniability to your to Tor Network.

They introduced bridges. Bridges are Tor relayers that are not publicly listed. They are like you can get them privately and connect to the Tor Network through them. And if you do that, you will your use of Tor Network will get plausibly deniable. You can deny that you're using the Tor Network.

Or uh there are also disk encryption software that provide this plausible deniability. So, like, you can have some files on your disk, but if for some reason your the like someone get access to your disk, they can't tell that you have installed these software. They they encrypt your data in a way that uh a person from outside, a person that has access to all the bytes in your disk can't tell you have been using uh this plausibly deniable in- encryption software. So, I I I was working uh on privacy and researching on privacy protocols uh for the past few years, and we had this idea of having plausibly deniable pri- privacy on Ethereum, too. We We already have privacy projects.

We already have Tornado Cash. We already have Railgun another. But, uh they they don't give you plausible deniability. As soon as you interact with these smart contracts, uh everyone from the outside can see that you're using them. So, we introduced this new EIP, EIP-7503, uh also known as zero knowledge burn holes.

I don't want to explain all of the technical details, but the TLDR version is that we want to enable re-minting of secretly burned ethers. So, what do I mean by actively uh send my Ethereum to an address that is pseudo random and it's provable because I can prove that this address is the result of a hash function. And uh we can also use the power of ZK- SNARKs, uh zero knowledge proofs, to hide the value of our Like, imagine we have a Merkle tree that records all the Ethereum transfers that are happening on the Ethereum blockchain. If if you have the Merkle roots of that tree, we can like make proofs on on top of that. We can prove that uh there is there is some amount of Ethereum in an address, which is address is a hash of some random value.

And the EIP itself uh proposes to the Ethereum blockchain to mint re-mint that Ethereum when someone provides such a proof. So, why is it better than cryptocurrency mixers? Because it's plausibly deniable. And not only if it's plausibly deniable, it gives you a bigger anonymity set. Uh like uh So, all addresses which have zero outgoing transactions and have some Ethereum in them are included in your anonymity set from day one.

And you can always deny that you have used ever used this protocol. But, there are uh a lot of good reasons why um Ethereum can't have EIP 712 at least today. And uh part of part of that is because um zero-knowledge proof technology is very uh fresh. It's very fresh, and it's just not a good idea to embed every new cryptographic primitive that we invent every day into a blockchain as big as Ethereum. It's dangerous.

If there is a bug in the system, it will enable everyone to mint infinite amount of Ethereum. That's not good. Uh So, I we saw that uh Ethereum is not going to have this um um like native layer. But so you know what? We can implement it ourselves.

Like Ethereum has a smart contract and there are some tooling in the Ethereum virtual machine that gives us gives us ability to do to make something like that. It will be it won't be as good as if it's implemented on the L1, but it it will be cool. So, I built this warm project and it mainly consists of two ERC-20 tokens. The first token is burned Ethereum. Burned Ethereum is simply an ERC-20 token which allows you to like mint mint it in case you provide a zero knowledge proof that there exists an Ethereum account in those state Merkle tree of Ethereum blockchain with some amount of Ethereum.

Which its address is like hash of something. We are using the Poseidon hash here. And if I want to show you the code is basically just an ERC-20 token. But thanks God, the Ethereum virtual machine gives us access to block hashes. And in in the block hashes, you have access to Ethereum's uh state tree.

And the state tree is basically Merkle tree that includes all of the accounts that exist in Ethereum blockchain, their addresses, their balances. And we can take that and give it to our zero knowledge proof circuit. And the zero knowledge proof circuit can effectively verify that. And so we we we built this BETH, the burned Ethereum token. And the problem was that so it's a one-way conversion.

You can convert your Ethereum to burned Ethereum, but you can't get Ethereum back from burned Ethereum. Unless there is some demand for it. So we thought of a second token. We called it Worm. Uh inspired from the the name of the protocol, zero knowledge Wormholes.

Which is very similar to Bitcoin. It has a fixed supply. It has a mining system like Bitcoin. But instead of burning your electricity in order to mine coin, here you are burning your burned Ethereum tokens in order to mine Worm. So so our like uh our thinking was that if if we like have a secondary asset uh which has a limited supply and like limited supply, we can somehow make demand for burned Ethereum token.

It's it's it actually work, but um not very good. Uh like uh so we built this system. And uh we we published both the burned Ethereum token and Worm token. You can see that uh the chart for burned Ethereum token is something like this. Whenever you see one of this candle red candle red candles here, it means someone is using this Wormhole uh feature.

Someone is like someone has burned his Ethereum and is uh like using this protocol to migrate his Ethereum to another address. But because of because the burn burn project exists and there is a liquidity pool for both of them uh there is some demand for burned Ethereum and the the price of burned Ethereum will slowly again recover to one Ethereum. Uh the burn token itself works like this. So um in Bitcoin you you get Bitcoins uh in um 10-minute blocks. Uh like statist- statistically speaking uh like like you will as much get as much Bitcoin as you put electricity in the in the pool.

So if if like someone is um So if the total electricity consumption to uh means a Bitcoin is like some value if if you are the person who is putting half of that electricity into the pool, you will get half of the Bitcoins minted. And the burn token works exactly like that. It will track the total amount of burned Ethereums that people are putting per epoch and the total amount of burned Ethereums that each user have put in an epoch and it um like uh multiplies these values and together with like it multiplies the uh the amount a user consumed for an epoch divided by the total ETH that was put by all users and it's multiplied but by total burn that is emitted in a block. Just like how Bitcoin rewards get halved every four years, we have like this uh smooth decaying of worm tokens per block, too. Every four years, the total worm that is emitted per 10 minutes is also halved.

Haven't. We built a uh like a mining panel for that. We launched it. Uh it's working. It's the not It's not of the only way to achieve plausible deniable privacy, but uh the reason I'm putting this in this presentation is that is somehow to show you that uh although um it's not obvious how to achieve plausible deniable privacy on cryptocurrencies, it's something that that is worth uh putting efforts in.

And uh here I I would also like to mention that the Burn Ethereum token is not here to compete, but it's here to complete because Burn Ethereum token it it if you like assume that the the the BTH token is like the Tor network, then um uh sorry. If if you assume that the all of the privacy protocols like Tornado Cash or Railgun ex- that exist in the Ethereum blockchain are like the Tor network, the BTH the Burn Ethereum token is the bridge. It's It's the thing that helps you to uh migrate your Ethereum to your favorite privacy platform without anyone noticing. And I I've also put uh this uh image of how tour network works here to show you how this is very similar to uh what we are trying to do here. And yeah, thanks for um Thanks for your attention.

Privacy is a human right. Privacy is normal, and someday I wish privacy also becomes normal. Thank you.

Automatic transcript — names and jargon may be misspelled.