New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Privacy As Infrastructure For Web3 - Panel || EPS 2025 Workshop

Ethereum Cypherpunk CongressFri, Jan 9, 2026, 12:00 AM

Panel discussion Clément Danjou (Zama), Alex Zaidelson (SCRT Labs), Lior Bondarevski (Fhenix), Laín Calvo (Crecimiento) focus on how privacy has been evolving since its beggining and sharing thoughts on current state of it as well as thinking of its future. Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/

Transcript

Thank you so much everyone for being here. So the idea for

Do you listen to me? Okay.

Yeah. But maybe raise your voice for just for me. So the idea for this panel is to explore how privacy have been evolving and since the beginning in in crypto and your ideas and your thoughts on the current statement of privacy and the future. Yes. And maybe the very first thing to do will be nice if each one of you can introduce a little bit about what do you think about privacy today and what you do.

Okay. So I'll start. Uh so a lot of people now are talking about a new privacy season. Uh we all hope it is really that and we all hope that people finally start to understand how important it is to protect your data and what you're doing on chain and uh for for all all of the use cases. So and we'll talk about this at this panel.

Now I'm Alex. I'm CEO of Secret Labs and Secret Labs is utilizing the TE trusted execution environment technology which is a hardwarebased technology. Uh we started uh in 2020 with the secret network which the confidential computing blockchain where everything is executed all the contracts are executed in in trusted execution environment and Intel SGX specifically and we have recently added to our portfolio the confidential virtual machines product based on Intel TDX and we'll soon add AMDSV as well uh where any workload can run inside this confidential VM VM with all the data being fully protected from the owner of the hardware and also the source code being verifiable. Meaning the uh owner of this virtual machine can prove to anyone what is the exact specific source code running in that machine which in my mind kind of makes any workload similar in a way to a smart contract where you can prove what exactly is the code that is running in this machine. So excited to be here.

Thanks for having me and uh let's hear the others.

Yeah. Hey, I'm Leor Leor Bonderfki. I'm leading the protocol at Phoenix. At Phoenix, we're uh bringing um high throughput privacy based on FHE to every EVM chain. Our goal is to be able to uh support any privacy solution, any privacy need on any EVM chain and it's quite easily be done.

Um yeah, happy to be here. uh my take about privacy and this uh in this era is finally happening. I think it's our job to to make it real to make it uh possible and to make it fast. We need to work fast. We need to push our products into production as soon as possible in order to be able to uh uh accommodate this uh this great uh season.

Uh and I think uh we are soon to be amazed.

Yeah. Um so I'm KMO. I'm working at Zama. So, uh I'm ahead of blockchain. Zama is a primarily like a company working on FHE.

So, it's a kind of new uh cryptographic primitive we working on for a few years now. And uh yeah I think we happy to to see uh this technology reach uh the beginning of the maturity to actually build a product and uh this is like the the right time like as as they said like basically we are like in the privacy season. I think I love this uh this term and uh this is like the right moment to push like any privacy technologies because like the the market seems to to ask for something. So uh yeah this is great

guys now it will be nice to to ask a few years ago privacy was more like a feature and now it's needed more than ever in infra all on web3 so from your point of view how was the evolution of privacy in our ecosystem since the beginning you are in the industry

okay so I I'll start so uh initially the blockchains were for creating storing and transferring value, right? That's what Bitcoin was all about. And then some people figured out that okay, Bitcoin is all public. So, let's do this store of value and transfer value. Let's do it private.

And that's how Monero and Zcash were born. Uh that's also how my first crypto project beam, which is a Mimblewimble privacy, Mimblewimble protocol based privacy coin was born. So, that was the first stage. Now the second stage started when Ethereum appeared and people said oh smart contracts by the way which are not really smart and not really contracts they're just onchain programs but it's just a nice term uh and then people said okay let's make them confidential and then you know secret network came along and uh other TE networks and ZK networks like Astack Alio and a bunch of others so people started to figure out how that would work and now actually with the advent of confidential virtual machines, people started thinking why don't we bring this privacy plus verifiability to any workload both onchain and offchain. So I see this very clear evolution from just transferring and storing coins to running those small and relatively limited onchain programs with with confidentiality and then to running any workload with full confidentiality and verifiability.

So that's that's my look at the evolution.

Yeah, Alex took uh a lot of different aspects that I wanted to mention, but I will I'll just mention like two more aspects. I think that um there are two more aspects that are really important for the maturity of cyber of of sorry of privacy in general on web 3. Um the first one is that people started to be more like open to privacy just because they're not afraid anymore. I think the new administration in the US started like the process of uh accepting privacy as a given thing without like uh the fear of being uh penalized for using for protecting your own data and I think the other governments are um continuing with the process of accepting it as well. So I think that's the first case.

I think that the maturity of the technology like imagine four years ago and go to anyone like we're here representing FHE but go to anyone and tell them like you will have an uh production grade FHE solution people will uh be probably shocked like it took like forever to do the computation there and finally we have like more mature uh solutions to be ready to uh be deployed and actually already deployed uh on uh test nets. So yeah, it's very exciting on this end as well.

Yeah. Uh and also I think like a few years ago you you you didn't have the same impression from government and banks regarding blockchain in general. And you see that like more and more government and banks try to to go to to get on on blockchain, but they quickly realized that they needed privacy to actually like move traditional finance on chain. And even like we are clearly at the beginning of that but this is like the next step for the blockchain to have like more use cases coming from tra traditional finance on chain and for that you need like more mature technology to to bring these use cases. So now we have talked about a little bit about the timeline about privacy, how it has evolved and now to to keep talking about the future and current things.

Maybe it will be really nice to get to know your your take on privacy. Why do you think this is so important and why you are working hard on this topic? Why do you decide to spend all your days working on privacy? Yeah, I I can start here. Um, I think it's fairly easy.

Uh, I would challenge everyone here to use their the the commonly used websites that they're using every day without HTTPS. Put your credit card data without HTTPS. Use everything that you are using, but just discard HTTPS. If you're willing to do so, yeah, I don't think you will agree with me. But if you're not willing to do so, try to think why are you willing to do so on web 3.

That's the sole reason I would think that privacy should matter to you. Uh uh there are many reasons but I mean think of this.

Yeah. I'll just give another example again challenging the public here. What if your bank was just publishing all your credit card statements in the open for anyone to log in and just watch them? What how how would we all feel about this? We would feel terrible.

Why though? Are we drug dealers or criminals? No. But we definitely don't know don't want other people to know how much money we have and how we spend it and where and when and so on and so forth. This is all very valuable information.

And when we are transacting on Ethereum on any or any other public chain, we get exactly this. All our dealings, all our transactions are just available for anyone to observe forever.

Forever and ever. There's even no way to to erase that. So uh so that's the the answer like why we need privacy because just the the the the opposite situation if you think it through is just unbearable. It's like it cannot be

and I think this is also like something you see already with banks like we often like think about like starting from blockchain from what we have today to say hey today everything is uh is public so which use case we would to to have it private but if you think about like traditional finance banks everything is confidential confidentiality is by default and because like we are working on blockchain we are used to have everything public we try to do the things uh in the opposite way like everything is public by default and we try to to ask what would be confidential but in reality like everything should be confidential by default and then we question like what could be public but like I think like we have like a mind like two web three oriented saying like hey what we yeah not the the right direction I guess

I think in in that point there's we need to do a shift in the paradigm where if you think that someone needs privacy it's Not because they are doing a crime, it's just for privacy of their own. In that thing, what do you think is um what is needed to do this shift in people's paragin?

Um I think this this uh shift started like because like we we have more business use case on that like uh I think many many companies like building on blockchain realize that it was needed by the market simply by that. So the shift I think comes from like a business incentive not like because people like realize they all know that from the beginning that they needed privacy but just like they managed to do business and do like address some use case in public and it was fine but now I think we we reach a threshold where all use cases public are rich and we have new use cases to unlock but we need progressive for that

and this moment it will be really nice to start talking about the main use cases is if you want to explore each one of you one that you love the most and then go deep into that.

Uh okay. So I'll start um and I'll take one particular use case of off-chain confidential computation and I'll give the public here an example of let's say everyone here is probably using open AI right and open AI has this you aren't so you're using what anthropic or something else or nothing at all okay so you are you are probably the only uh one here or one of the very few people who are not using that so Most people are using that and OpenAI has recently added this kind of a private mode, right? When they say your data will not go anywhere, but how can you trust them? I mean, of course, your data will go everywhere and they will use it and they will buy it and sell it and do whatever they want with it. Uh why is that?

Because there's no way to verify which code they're running on their back end. So the confidential VM technology actually solves that. So for instance, we have our confidential AI services where we're running several open source models and we open up the code and we prove that this is exactly the code that's running. So anyone using our AI services and and other confidential AI services that are there there's a number out there using this technology uh they can be sure and they can verify don't trust verify they can verify that their data is not going anywhere. And you know we haven't talked about AI but privacy in AI is of paramount importance because we are sharing our most uh our deepest things.

People are using AI as their psychotherapist as their business uh you know advisor as their marriage advisor whatever all the data. So, so those AI companies they not only have our data now they start getting our very soul and they can even influence us in the ways that we can't even imagine. So, so that aspect of privacy which is one probably of the newer ones out there. So, I deliberately took that one as the latest. I think that's something that also people are starting to understand and will be understanding more and more and and acting accordingly.

Yeah. The way I like to look at privacy solutions is by splitting them into like two categories. There are local privacy solutions such as Ethereum foundation that are pushing uh some local solutions and then there are application like general applica applicative solutions. Those solutions are basically like you can create every possible application that you can think of with privacy as a given thing without knowing anything about the technology behind the scenes. And I can give so many examples like can I can I can sit here for hour four hours and speak of examples but like let's go for the very common defy uh obstruction.

I want to transfer funds from my wallet to another wallet without people knowing how much money do I have nor how much money do I transfer to my friend and it's not because I'm having some criminal thoughts. It's just because I don't want anyone to know my personal balance, my personal needs of what I'm buying, uh from whom I'm buying and stuff like that. These are very important things and very achievable with uh applicational privacy.

Yeah. Um just something I I wanted to to to just like think about like is how we want to have privacy like we mentioned like privacy infrastructure and how we see things but um is a feature is like a like a new blockchain bringing the features. I think this is something also important to to have in mind that how we can like have a usability for people to to use actually these features. We saw like regal like directly integrated with SRM which is great like we you can imagine that you can directly like use a kind of part of coach. It's not like the perfect solution, but at least you have something directly on on SRAMM to to use.

And I think this also to to to think about like we have the liquidity on many chains and today we we need to to to use like to use this liquidity and add a privacy layer on top of that. And if you bring a new features like privacy, this something to have on mind in mind like you you have so much blockchain, so much liquidity across many blockchain and you you need to onboard these features. Should we like try to move the liquidity to a new network? Should we like try to add privacy directly on chain? This is an open question, but I think like this is something to to have in mind in the future.

It's a really good comment what you says and related to that you said about what we are doing now, what's good in the future and maybe it's a good point to start talking about future use cases to scale privacy and what is needed in the industry. Um sorry I didn't have a question sorry

about future use cases that you think are needed to scale in privacy in web3. Um I think for the scalability I think uh most of the technology we have today uh are good enough for to basically like launch uh fa could be f zk mpc like u of course like you have some technology with more maturity because they are in production for many years and um and other like are just starting to build test net production and so on but I think like we are at level or all technology can be used and I think for the scalability like we probably need a few uh few few months years to actually like see the the adoption but uh I think we are ready to have massive adoption of privacy. It's just a matter of engineering. There is no like a big unknown cryptographic that you're not sure what you can do. I think we are at level where we have a road map and we know that it's doable in the in the coming years.

So this is great at least like you don't have this unknown or you're not sure it will be doable at some point. You know it will be doable at some point. So now it's just like a engineering problem which is great because it's solvable just need some time but it will be done at some point.

Yeah I I totally agree with with Clemo I think that uh we are as mature as we need in order to start building start pushing and we don't need to wait. I think that the next step of majority of majority sorry is um we need to understand that um every technology every privacy technology has its own need. Uh we we are not in a fight. Uh my personal belief is that FH is great for execution but ZK for example is great for scaling and FH is not there for scaling. So obviously we will need them all.

These are are they are great for verification of the things you are running. So yeah, you have a lot of things that you can do together. Uh and once everyone will understand that it's our goal to be able to push this uh technology or all of our technologies together uh to institutions to whatever project that needs us uh I think we'll be in a very good place.

Yeah. And I would like to add so about the scalability I feel the TE technology is pretty scalable right now because the hardware is pretty widely available and the software to run the confidential VMs is there. So you know we are now offering those confidential VMs in kind of a cloud service provider fashion and you know as we get more demand we just buy or rent more and more servers. So that's pretty scalable. Um and regarding the future use case uh use cases.

So we see some of our customers working on deploying trading strategies inside tees. Uh also deploying medical applications like medical image analysis that we just did a proof of concept with fetch AI on mimography imaging. So running best of breed models inside tees to analyze mimography images and produce uh high quality medical reports uh and that for example that can make this medical care available and democratized or diagnostics available and democratized anywhere in the world also through blockchain payment rails. So um AI agent is also a very powerful use case for tees where you can deploy or use somebody else's AI agent without fearing that it would steal your data or or do something bad. So we'll see more and more cases there both onchain and offchain and hopefully some of the more uh general use cases like agents or or medical would bring in newer people into this blended web 3 environment and take the whole industry up.

So and to board these new use cases from your point of view what be would be the main challenge right now for the industry and privacy?

Uh well I think uh UX of blockchains is still a major challenge. Uh, every time I need to send a transaction on Ethereum with my ledger, I like curse because it never I mean maybe I'm doing something wrong every time, but I'm doing that for years and always is like waiting and then this and this connect. So the u the UX is first thing and everybody talks about this, everybody knows this, but it's still not great. Uh that's one and two uh I think for wider adoption it's our challenge as in as an industry to switch public perception from uh of of the web3 industry from it being a place to gamble on tokens to being a place to use services that are cheaper, faster, and better uh than elsewhere. and and that's that's really I think those two challenges are are very big challenges.

We are moving there but it's it's a long uphill battle.

Yeah, I think that I want to emphasize the UX part. I think that once the user experience will be finalized in a way that it will be super native to use privacy without any change in your contract without any change in anywhere and once blockchain will be accessible and the experience on blockchain will be super super super easy. I think that will be the case where like of course all of us wants in wants in institutions to start using blockchain for for so many reasons. either voting or money transfer and anything. Uh and I think that those are the major things we need to go through in order to be able to make it happen.

Yeah. And I would go in the the same direction but more like u I think like what something we we are missing in the integration in the ecosystem. So for example like there are like an initiative we are pushing uh with Fenix also regarding the confidential token uh um standard. So the idea is to have like a standard confidential token running on SRM to have the possibility to have like the to integrate like a transfer like your balance everything encrypted uh directly like in a wallet website everywhere but for that we need a stalization. I think this is like a big challenge to to um reach an agreement between all parties working on privacy to have like some stalization on that like this.

We've like we is a lot like the integration of this confidentiality solution in like any DAP any wallet any ecosystem could be like also like um centralized centralized exchange to basically like because otherwise nobody will use it like if it's not in your wallet it's not in your centralized exchange it would be a big issue so this is the next change I guess

now before we close it will be really nice for each one of you to explore a little bit about and what do you think about the next challenge and what do you wish for your project to succeed?

Can can you repeat the last challenge please?

Yes.

Yeah. I mean the next challenge of ours is um make uh the solutions way more mature in a way like it's it's part of the UX but make it more performant. Make the throughput real. Make the throughput not uh like I know there is a myth about FHE that's like I know I know where it comes from but it's super slow. It's hard to use.

So we already broke some of the major parts of this myth but make it like like unreal for people to actually think about FHE uh as a slow thing. uh and I think the technology actually uh becomes more and more mature and I think it's very possible uh nowadays and I think that uh that's a huge step forward for us. So uh I think for the TE industry uh one challenge is just finding the right use case and finding customers and uh explaining the value but I think it's going pretty well. That's one challenge. Another challenge is uh to prove to the world that TE's are secure.

So recently there were a couple of uh published attacks on TEES that allow an attacker to break uh the TE when they have physical access. So now we have launched an industry initiative by multiple TE players like Fala, ourselves, Oasis, AK Verify and a bunch and a bunch of other guys. uh and this initiative is called proof of cloud and the idea is that we crossverify our machines following a standard procedure and we generate a proof that those are really located in secure data centers that cannot be accessed by attackers and broken in that in that way. Uh so I think those are for for the tea industry those are the two main challenges now. Um yeah and and in general we all have the same challenge as the web3 industry as a whole.

Yeah for them I feel like we we plan to launch your mainet by the end of the year. So of course like many challenge arrive when you launch a mainet. So it will be uh uh yeah it will be a lot but I think mostly uh our current challenge is to to scale in general to because we know that we working but uh well we need to do more on that and as I said like I think it's uh to drive the adoption to more privacy oriented uh uh features on SRM and on EVM in general. So uh yeah we're working on that and uh we try to contact anyone who wants to to bring on their product to contact me or or Zama.

Thank you so much guys each one of you it has been a really good talk a great panel and well if you want to say some last words before we close you are welcome. Yeah, I just want to mention like don't be afraid to build. Don't be afraid to use. I know that's like privacy could sound really scary at first uh and hard to use and hard to build and hard to everything. Either you are a builder or a user, don't afraid to start.

Uh you will be surprised on how mature it became, how easy it's uh it is to approach uh and convince me otherwise. Uh yes and I I will add to this uh whatever you're using be it onchain or offchain just try to think which data you are now committing or or sending and who will be able to see that data and when. So if you're using blockchains the answer is anyone will be able to see your data forever and ever. If you're sending something to OpenAI, then you understand that OpenAI will be able to see your data and do whatever they want with it forever and ever. So, give it a thought and think, well, maybe there is an alternative that um that I could use and try and as Leor said, it's not scary.

It's not that difficult. Just just go there and protect yourselves and your data.

Uh yeah. Um I think like I agree with uh with you both. So yeah just like uh thank you to to be here and to uh have interest in privacy in general. I think this is something we we are looking for for many years. I mean like we are all working on in company who actually work on privacy for many years and uh so we are glad to to see so many people interested in the privacy field.

So continue like uh continue and get some interest on that. So it's great. Thank you so much.

Thank you for having us. Thank you. Thank you. Thank you. It was great.

Automatic transcript — names and jargon may be misspelled.