New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Vitalik Buterin on Ethereum Privacy @Web3Privacy hackathon, Berlin 2025

Ethereum Cypherpunk CongressThu, Oct 9, 2025, 12:00 AM

Speaker

Ethereum Foundation · 24 talks

Vitalik Buterin (founder of Ethereum) gave a speech + Q&A at the opening ceremony of W3PN HACKS hackathon focused on privacy, digital freedom and open-source solutions. "Using privacy protocols today requires a separate seed phrase, No multisig option, Requires opening a separate wallet, ~5 clicks to do private send / withdraw, Public broadcaster mechanism brittle, often breaks. We can do better", - Vitalik Buterin. Web3Privacy now hackathon was an anti-bounty event proposing radically different nature of web3 hackathons amplifying solution-first approach and not chasing sponsor bounties. Moreover, it enabled 28 interdisciplinary mentors shaping hackathon projects from UX/UI to privacy-open-source-fit: https://hackathon.web3privacy.info Useful links: Web3Privacy now collective: http://web3privacy.info Web3 privacy market dashboard: http://explorer.web3privacy.info Cypherpunk Congress: http://congress.web3privacy.info TIMECODES 00:00 Intro 00:17 Getting Serious about Ethereum privacy 24:44 Q&A Session Start 24:53 Do you know we have been working on offchain protocol to turn every file into a hash tree which you can sign and the test like time stamp and linking to other files as well. Is there something similar you already know which has been established? 26:45 How would you explain what a nullifier is and why can it be coerced easily? 29:00 Do you have an opinion on the EIP7503 wormholes and do you think there's like plausible deniability maybe possible? 30:59 You mentioned that you want to see our privacy tech stack formally verified. Obviously formal verification comes in many formats. Can you talk just what you would like to see under what paradigm to give you the confidence in the next? 33:25 Do you agree with the community's reaction to the ban of the Tornado Cash some years ago, and if not how do you to the and how do you uh prevent how do how do you prevent it in the future? 36:10 You showed a slide with a lot of things that could be paralized like the reads, the rights, etc. Were those use cases uh what you had in mind when uh Ethereum came out with with Whisper? And if so because you also uh said that offchain is good because it doesn't leak as much metadata. Is there a strong case for for the adoption of offchain peer-to-peer like I'm going to say Waku? Would Waku make sense for a bunch of those? 38:53 Talk about Waku again in back in 2021 I built a messaging app that was and using Waku and one of the interesting things is that because the node was running in browser, I didn't have to require the user to do some operation like run a node. So what do you think about? 41:39 Just wondering about governance and privacy. I know you mentioned the onchain voting as well as the fund transfers and kind of the important privacy elements there. Are there any other specific use cases around governance that get you excited and where you think it's crucial to enable privacy? 44:02 Any work on reintroducing interfaces to allow for encryption decryption keys which might be derived from a root key via a standardized API? 45:16 Is Railgun ever going to lower their quarter % fee? Do you know? 45:38 How do you see the synergy between B2B privacy and sort of like human privacy and where are the disconnects between them? 47:51 What is privacy endgame? 51:28 Can you share your perception of cypherpunk in two years? 54:15 Since you it's very important for you to keep your thoughts private and you run a local LLM, how do you deal with the your location privacy? 56:26 What's your opinion on the how privacy projects can reach product market fit? 58:17 What would be the low hanging fruit in terms of dev hours spending on privacy? 01:00:14 What are your thoughts about uh whistleblowing rights and how they intersect with privacy data? 01:01:20 What do you think about ZKTLS proof?

Transcript

[Music] Hello everyone. Okay, great. Um just Okay, great. Uh so topic for today uh will be first getting serious about privacy. Um and so we'll uh talk uh uh first a little bit about uh Ethereum, the approach that I've been thinking about in terms of uh how Ethereum can move forward on privacy, what kinds of things we should do, in what order, what kinds of things we should do that we have not been thinking about before so far.

Um what kinds of things we should not do. Um and then we'll be very happy to take and answer um any kind of questions from you. Uh so I think what we've seen so far is that Ethereum has led the way on privacy research and development in a lot of different ways, right? So Zcash of course was the first major production implementation of onchain privacy and I think systems on Ethereum were probably yeah either the second or close to the second. So back in 2019, we had the EC mall and EC ad and EC pairing op codes that enabled all kinds of onchain privacy solutions to start happening.

Um and then we saw tornado cache and tornado cash launched on Ethereum and Ethereum was the chain where the entire arc of that very complicated story happened. Um by the way, free Roman Storm, Roman Storm continues to need help. Um then uh PSC the privacy scaling explorations in the Ethereum foundation uh they um have worked on many kinds of ZK Snark protocols a lot of low-level protocol related research a lot of dev tooling related work a lot of implementation uh level work PSSE has been a bedrock of a lot of like very bottom level uh tooling and ideas on zero knowledge proofs for scaling and zero knowledge proofs for privacy. Um, also L2s have contributed a lot. So, Aztec in addition to releasing I think already multiple test versions and I believe mainet coming soon is also been experimenting with a lot of very innovative ideas regarding privacy.

uh but also things lower level things like the noir language also the entire plunk and plopup category of algorithms um also intmax fully snark based plasma rollup hybrid um nightfall from EY champions by Paul Brody quite a bit so Ethereum has been a home for a huge amount of valuable privacy related work right but The problem is that on real world value delivered to users we are far behind where we could be. Um so if you use actually using a privacy protocols on Ethereum today uh who here has used a privacy protocol on Ethereum in this month? Who here has used railway uh privacy pools? Uh tornado cash uh something different from all three. Shout them out.

Monero. Monero. Okay. Ba. Okay.

Partic starting to happen. But what does using a privacy protocol today look like? Right. So my experience is so one it requires you to have a separate seed phrase and so you have this like totally separate thing that you have to worry about holding and not losing and not having stolen if you want to use your assets. That's one.

Two is uh there's no multisig option. The only option is a single key um option which is like pretty scary for large amounts of funds. Three, it requires uh opening a separate wallet. So whenever you want to do a private send, you have to go and like open the thing and then it like slowly starts loading. It goes from zero to 100.

You have to wait like 30 seconds. Four, you need a total of about five clicks to private send and withdraw. So I think when I use railway, I count, you know, click one, open the railway wallet. Um, and then click two. Um, you have to click on unshield, which is like a different thing than send.

And like when I the thing that I think of as sending is actually unshielding. Sometimes I click send and then I realize that's the wrong thing and I have to do a third click of clicking on shield. But anyway, two click on shield. Then three um you know click on generate proof. Then you wait then you know four click on choosing a public broadcaster.

Um and then like when and then the proof is done you like usually like a fifth click to like actually start the whole process. Right. So it's uh like much complicated just on a raw UX level than it could be. Um and also the public broadcaster mechanism. This is something common to tornado cache and railway and any one of these systems that tries us to to actually be decentralized.

These things are brittle. These things often break. um these things, you know, within the last 6 months I've had situations where it just broke completely on one version and I had to switch versions. Um at some point it broke completely on one internet connection. I had to either turn a VPN on or turn a VPN off.

Um so very far from perfect and uh we can do better. So why now, right? Why do we want to really push for privacy now as opposed to pushing for privacy in say either 2021 or 2029 right so I think first of all at the top of all this uh privacy is important right privacy is freedom privacy is order uh privacy is progress privacy is a bedrock of a lot of things that uh we care about in this world um privacy is not just an abstraction in the same way that something like decentralization or cred credible neutrality is privacy is a concrete benefit that is directly appealing to users. It's like you can understand what it means to transact privately and uh transacting privately as opposed to transacting publicly is something that actually has meaningful differences in the kind of experience you will have during the transaction but more importantly yeah after the yeah transaction right freedom of speech is easy freedom after speech is the harder thing. Uh so the um also the technology is mature enough today.

This was not true four years ago and so today we can do it and therefore we must. So the way that I think about privacy on Ethereum is I yeah break it up into three categories. So I think of privacy of rights um on chain. So basically when you perform operations you know like things like sending uh those operations happen onchain by default everything you do on chain creates a public link between every operation and every other operation. How do we deal with these things without creating the onchain public link?

Uh then number two privacy of rights offchain. Uh so um in this case uh how do you avoid leaking information when uh when you're sending transactions like basically all the parts other than uh the blockchain itself. And number three privacy of reads right when you read the chain um then uh like reading the chain also reveals a lot of things about who you are and what you're doing. Uh and how do we actually try to minimize that? So let's start with privacy of rights.

So three categories that I think we can focus on short term. One is funds transfers, two is DeFi, three is voting. These are like basic category of operations. Um and they're strong cases uh to have privacy for each of these. So private funds transfers um I think we all know about um private DeFi.

So railway for example has private DeFi inside of it. Adding privacy to DeFi has a value in a lot of different ways. Uh so um it's uh valuable for people not to know what your investments are, what your strategies are. It's valuable for people to not know what your liquidation price is. It's uh valuable for uh people to not know everything you're doing in real time so that they can frontr run you.

There's all kinds of uh reasons why it's important to be private in DeFi in order to protect you and also having uh private DeFi increases the amount of funds that people are willing to store in a private context which in turn makes it more viable to make private transactions. Privacy in voting also super important. Projects like Macy are moving forward starting to actually get used more. Also other forms of ZK voting already exist and are already increasing in their user friendliness and their integration. So without privacy voting turns into a very toxic social game priv and so we needs to really make privacy in any kind of onchain onchain voting a reality and the default.

And then the holy grail of course is to have privacy of general computation. Privacy of general computation is hard for a bunch of reasons. One of those reasons is uh that general computation involves doing a VM and VMs involve client side proving and client side uh proving is even harder to make efficient than server side proving. Um and another reason is that privac privacy in a general purpose way requires rethinking the software development model because you don't just think about who owns what assets. You have to also think about who has access to what pieces of data and like things like what what Aztec has been doing in terms of figuring out like noir and figuring out their entire account and contract model like it's actually a pretty intricate and challenging amount of work but ultimately this is the holy grail privacy of right uh so rights offchain um okay basically yeah this one's actually the Easy one.

Uh so basically yeah the thing that matters here is send raw transaction as well as the various equivalents for ERC 4337 for intentbased transfers like 7683 for like every type of send needs to be able to happen through a mixet so that when you do these operations there is not a public link between your IP address and the transaction. We should not expect that the Ethereum network is private by default. We should expect that people who wants to see things are going to run like 30% of the nodes in the network just so that they can see everything that's going on and the demand for this to increase as uh onchain data leakage decreases and so we needs to increase the amount of network layer privacy as well. Now privacy of reads is something that I think we have not been talking about nearly enough right. So, um, who here has been using, uh, raise your hands again, has used an onchain privacy protocol this month?

Who here thinks you were private? Okay, good. So, basically, you know, you chances are you leaked everything about yourself to whatever RPC provider you're using. This is a problem and uh, this is a problem that can be fixed. So I see two tracks uh for solving this.

So one of them is keeping the form factor of a small light client connecting to a large RPC server but making that connection actually be private. So we've been thinking about making light client connections secure for a long time. I've been talking about Helios for a long time. Noah Centro has been heroically working on Helios for a long time. What Helios does not do is uh it gives you like client security.

It does not give you any kind of privacy. And actually a lot of the time the the more harmful thing that an that an RPC can do to you is not feed you bad information even though feeding you bad information can totally cause you to lose huge amounts of money in a DEX. um rather it's uh uh stealing your information and then potentially selling it off and like potentially yeah sending it out some who knows where else. And so the idea here is basically we use cryptographic technologies in order to make it possible for people to ask RPC servers for Zen for information get back responses without the RPC servers even knowing what they answered. So there's a short-term approach which uses trusted execution environments together with oblivious RAM.

Um basically using like these trusted hardware based security models uh to reduce the opportunities for data leakage and ORAM basically makes the TE problem easier because you don't have to worry about leaking memory access patterns. um instead the thing that has to be private is basically just a much smaller thing that has like basically all of one memory in it. Um but then of course hardware based security models are very imperfect and there is a more holy grail solution which is private information retrieval uh P. So the uh this thing has a lot of challenges in terms of efficiency but uh the efficiency of P has been improving more and more with every passing year and it is something that I think we actually can get to doing. So making hardened uh making hardened RPC nodes is one of these paths.

The other one of these paths is making it easier and more practical for a user to run their own node even as um Ethereum L1 scales. So, who here runs their own node or has run their own node in the last 12 months? Okay. Um someone shout out how many gigabytes it takes on your hard drive. A few hundred.

Okay. Uh someone else shout out how many gigabytes do you have on your hard drive? Anyone shout out their number? I mean, mine is like 2048, but I got a fancy laptop to play around with self-hosted LLMs. Um, okay.

Who here has uh on their on the hard drive of their laptop more than 256 gigs of disk space? Raise your hand if you have more. Okay. More than 512. Okay.

So actually see yeah now in the what the EIP over 9,000 I forget the exact number in the proposed EIP that specifies Ethereum node requirements the expected amount of disk space is 4 tab so who here has 4 tab okay one hand is up great now this is a problem right and so I think there actually is a pathway to make the yeah node running requirements decrease massively And that pathway basically is one history exp block level access list and ZKVMs. And so you basically get verified blocks and the only thing that you have to track is the state itself and then you just get fed verified deltas to the state. you can apply the deltas directly then that can reduce even today a node's storage requirements to some something like 50 to 80 gigabytes. So who here on their laptop has uh let's say at least 80 gigabytes of space who here has that on their phone? Okay, see so we like with today's numbers we can actually make state storing nodes pretty viable.

Now, of course, the argument is, well, what happens if L1 scales by 10x? Then within a few years, we expect that to increase back to the hundreds of gigabytes. And so, the solution here is partial state nodes. Basically, nodes that only store parts of the state. And we need to figure out some kind of way of like basically splitting apart parts of the state that are spam for parts of the state that are relevant to important applications.

And then you as a user can store only those parts of the state. And if you make queries that touch only those parts, then nobody outside of uh uh outside of you and your computer actually needs to find out anything about what reads you're making. So this is another piece of uh privacy of reads. A third piece of privacy of reads is uh identity and accounts, right? Um so who here has used ZK email?

Anonhar, any of the ZK rappers? Okay. Um, who here has a world ID? Okay. Um, yeah, I mean I I agree.

I hope the world goes to hell as well. Okay. Um, then I mean I I had one and I lost it. Um, then so you know hopefully they're recovery. Well, now who here has used ZK passport?

Um okay. Um I mean actually I have to right. Um so one of the uh one of the parts of this right so basically what is identity AI used for right I think identity is an an important piece in all kinds of different applications. It can be used to prove that you are the same person that previously did some action. It could be used to prove that you're not a robot.

It can be used to prove that you are a member of some community. But at the same time, identity has uh all kinds of risks if it's done incorrectly. So single global identifiers are something that could be abused for deplatforming. Um especially if they're not implemented well. Um single if you have a single global identifier, even if everything is done through nullifiers, you can still be coerced into revealing your nullifier.

Um so a lot of challenges in uh getting into this whole space space and doing it well. Um and I think this is something where uh like the world is moving forward into these kinds of things and uh I think our community might be the most well positioned uh to actually figure out a well-designed privacyfriendly and pluralistic form of identity and reduce the chance that the thing that the world standardizes on is just terrible um across multiple dimensions. Also, privacy of ID is something that directly comes into wallets themselves. Uh, so private account abstraction, right? So, right now to use railway or to use privacy pools or any of these, you need to have one single key.

Who here would feel comfortable trusting one single key with $1 million? Okay. Um, $10 million. Okay. Um, let me ask the question another way.

um more than 10% of your assets. Okay, more than 50% of your assets. Okay, see very few hands raised, right? And so basically we for privacy to be viable, we need account the underlying accounts to actually be much more secure than single keys. So the the most very basic thing you can do is of course multisync, right?

But the real long-term thing that we can do is private account abstraction, right? Basically uh whatever your normal account is, the account that you use to send normal transactions in order to spend uh from private accounts that are ZK links to that account, you have to provide a zero knowledge proof that you still control that account. And then on top of that, you have to reveal that you control some extra secret. And the point of that extra secret is just the privacy part. Um so if we do this then we we can make ZK accounts much more secure.

We can basically enable much more secure and zero knowledge ways of revealing who you are both to your onchain account and to all kinds of other onchain applications and we can make this work seamlessly with your existing accounts on Ethereum. So next yeah so this is uh kind of my general privacy mind map. are other important things to think about here, right? So, one of those things is uh when do we get into uh doing privacy on the L1? I think uh this is a topic worth exploring.

I think uh the reason to not do this literally tomorrow is basically that uh if you implement that and uh there is a bug in the privacy mechanism then someone can print infinite money and you won't even be able to tell. Uh so it's uh like pretty scary in that sense. Uh so personally I think we should wait until our privacy stack is uh and our ZK stack is like formally verified proven to a much greater extent and ideally we can do that for the ZK that we use to scale Ethereum and for the ZK that we use to make Ethereum private at the same time. Also ZK snarks by their on their own are not enough for a lot of things. There are things that require FHE.

There are um though even with FHE you need to have a like basically a multi-IG backd dooror committee uh that reveals when things get decrypted which is like scary in its own way. I mean for me the holy grail is offiscation. Maybe we actually might get offiscation in the not too long-term future. Maybe we'll see. Um and so there's uh things that are worth thinking about in terms of like the Ethereum of 2040 from that point of view.

So I think it's a a discussion that we should consider. Um my view on short-term uh things the L1 should do for privacy is basically that whatever we do in terms of L1 account abstraction and L1 fossil support should be designed with privacy protocols in mind. And I think that's like the basic uh bottom line that we should agree on in terms of what L1 does for privacy in the short and medium term at least until we were confident enough in the cryptography to actually stick privacy features into the L1 directly. So conclusion uh basically yeah privacy on Ethereum is happening and there are already things that are underway on each of the items that I talked about and I think anyone who is here can actually help build out any part any part of that map. Right?

So basically yeah go back one slide. Um so if you you know anyone for any one of these bubbles like any one of these things are things that people in this room can go and contribute to. If you are someone who is uh good at hacking around Ethereum clients you can go build a partial state node. If you're someone who is uh good at uh thing me figuring out private account abstraction and some of the like challenges around like doing onchain reads and doing the client side proving you can work on that. Working on client side proving enables a lot of these.

So client side proving work is important. Privacy preserving voting is important. Each and every one of these items here are potential hackathon projects and are potential long-term projects for people here to put a lot of effort and time in. Uh so let's uh work together. Let's make the best uh privacy preserving user experience on Ethereum possible.

So thank you and happy to take questions. We will have a Q&A session for half an hour. Uh please raise your questions if you have an urgent question please. Yeah I have a question like I think one of the best ways to preserve privacy is to do local and private first. Mhm.

And uh um like do you know like we we have been working on offchain protocol to turn every file into a hash tree which you can sign and the test like time stamp and linking to other files as well. Is there something similar you already know which has been established or sorry what use case is this for? Yeah, for example, you have private like private data like you have a self-iss and you want to attest it between friends for example. Mhm. And then you can have additional signatures which attested to a key which has some form of public reputation.

Mhm. So you can issue your own identities offchain and you can use them to sign documents for example. Yeah, I support this. Um I generally support a uh maximally off-chain approach because maximally off-chain means minimum metadata leakage and I think you it should be as easy as possible to make proofs over onchain state and then combine and then combine that together with proofs over any kind of records that you have and be able to prove things about yourself without the chain or third parties learning about it. Um I think so I mean yes I think that's super valuable.

I mean, I think in order to have like a proper integrated pipeline that delivers these kinds of things, I think the like ZK Ethereum ecosystem probably does need to be a couple of steps more mature. Like it needs to be more viable to make a state proof of your own account. It needs to be more viable to just like make proofs that go into Ethereum state in general. Uh but I'm sure these things will improve. Uh how would you explain what a nullifier is and why can it be coerced easily?

Okay, so the way that the math works right is that you have a secret and then using that secret you can like think of it as you hash the secret plus one and then you get a public number and then you hash the secret plus two and then you get your nullifier. Um, and so what you do is uh when if you have like some resource that can only be spent once, then when you receive the resource, you publish the first number and then when you spend it, you publish the second number along with a proof that there exists some first number that someone was publish someone published previously where that like basic the same secret was used to generate both, right? And because the secret always stays private to you permanently, you're the only one that's able to make the proof. You're the only one that's ever able to actually know that link. And so what this means is that essentially, yeah, you're able to make a proof that says I'm using or like I'm allowed to take this action because I have a resource of a particular type.

And this proof at the same time like the null the the nullifier being published basically prevents you from claiming uh claiming the resource twice. So it prevents you from dossing the system. Now the uh issue with coercion is basically that um like someone can always uh if they see that there is an any action and that action is uh connected to you um then which they could find out like offline or through any other way then they know that you're you are a user of this system and they can force you to reveal your secret and I mean potentially they can like torture you or lock you up until you actually reveal the secret that that maps to that nullifier. And then once you do that then that also reveals your original leaf value and then potentially that reveals your entire history. Right?

So these are the kinds of issues that like ZK by itself and like especially ZK identity because it creates this persistent object that you end up creating like many application specific nullifiers from right is like needs to solve for right because if you don't then like someone can basically kind of force you to reveal your entire identity that you use to sign everything. Um, do you have an opinion on the EIP7503 more rules and do you think there's like plausible deniability possible? Yeah, I mean I think it's cool. Um, I mean I saw there were some recent improvements uh to it. I mean things like making it work off of receipts instead of state proofs which I think really improves the the the simplicity, reduces code complexity which is good.

I think uh for me personally to feel comfortable with it, the main blocker is basically that like ZK technology needs to get mature enough. Um and like it needs to get to the point where we have really really strong assurance that this kind of thing is not going to be broken, right? Because if someone breaks it, they can like they actually can print basically an unlimited amount of money, right? like the because the size of the anonymity set like it's not even the set of all like explicit depositors. It's basically the set of all people who have transferred ETH into accounts where it has not been spent from.

And so it's uh the like someone could just like print tens of millions of ETH before we know what's going wrong, right? So like being really solid on security is like the big prerequisite for me. And there's also like smaller things like uh you know the fact like the 80 bytes uh kind of thing and like the fact that even with the grinding it only has 92 bits of collision security which is like I mean it's like you know on the boundary of like being okay. I mean I think if we're going to take time to be confident on security we should also take time to like maybe figure out how to finally move away from 20 byt addresses. Um so I think like some security related things need to be figured out.

I mean personally if the security related things were already solved like I would totally love it and uh like want it to be in ASAP but I mean I mean I think it will take time and at some point we'll get to the point where we're comfortable with things like that. You mentioned that you want to see um our our privacy text formally verified. Um obviously formal verification comes in many formats. um can you talk just to what you would like to see under what paradigm to give you the confidence in in the test? Yeah.

So I mean one analogy is like the way that we're approaching formal verification of the ZK EVM right and there there's two aspects to it. One is formally verifying the arithmetization. Uh so basically yeah this uh like pro creates a a machine verifiable proof of the mathematical statement that if you have a valid witness like valid polomial values for these for these polomials then that means that you have a valid execution of the underlying VM that's like and some implementation of that in lean that where the you know like final state is some particular value, right? And then on top of that, you can even prove other statements. So like for example, there are some ZKVMs that have already proven a property called determinism, which basically means that the ZK EVM accepts exactly one post state route.

Um, and so that's powerful because it means that like there aren't bugs that allow an attacker to just prove anything. Um so once you have and then another part of the proof is like actually proving the kind of correctness of the proof systems themselves right and like that's something that I think we've gone into less because we're still in the arc of optimizing the proof systems but at some point we need to start doing that so that's the basic thing um then uh the and then similar types of things can be done for client side proving right and So we can uh like potentially you can even mathem like convert statements like if you put one uh coin into railway then you can take one coin out into a mathematical state statement that you can actually verify ends to ends right or you can do similar things to virtual machine execution right so if we do things like that then like we can get more comfortable with the actual safety of all of this zero knowledge machinery that in the future millions of ETH will be dependent Mhm. Um, do you agree with the community with the community's reaction to the ban of cash some years ago? And if not, how do you to the and how do you uh prevent how do how do you prevent it in the future? I mean, what to to you what was the Ethereum community's reaction to the native cash ban?

So I I I thought that many nodeers have started to uh to send their transactions and also I don't know if there was public support for developers gen. Yeah. Yes. So I mean there was definitely a scare back in about 2022 to 2023 regarding block builder censorship right and this is like an intersection of the privacy legal issues and the whole like builder centralization problem. So my view on the builder centralization problem right now is that like we need Fossil um as a way of mitigating the uh mitigating it like basically what Fossil does is it creates 16 different actors per slot who have the power to force any partic a transaction to get included inside of that slot.

And so we get like very strong censorship resistance even if the entire block building market gets monopolized by one actor like not saying we should let that happen right but even if as a second layer of defense I know there are people who are working on multi-party block building technologies like basically market designs where blocks get built through the collaboration of multiple actors by default and if that happens that also helps kind of decrease the risk of single block builder dominance. So I think to me like that's strategy two and strategy three is like I think we should at least explore some kind encrypted meool ideas in parallel. Um so like to me those are the top three and I think uh if privacy is going to be first class importance for Ethereum. I think it should be then like we needs to have multiple paths toward continuing to make sure that we have it right. And also I mean in general I think uh like these things should be the responsibility of L1 right.

I think we should not require individual like well uh like identified actors including builders or even including application developers to be virtuous right and so we should really yeah ensure censorship resistance of the L1 and also we should do a version of account abstraction that is friendly to privacy protocols. So 7701 for example does this. Um and so that way privacy pools and railway and tornado cache will be able to get rid fully of the of the public broadcaster dependency. Hey uh so my question is you you showed a slide with a lot of uh things that could be paralyzed the reads the rights etc. So was were those use cases what you had in mind when Ethereum came out with with whisper and if so because you also uh said that offchain is good because it doesn't leak as much metadata.

uh is there a strong case for for the adoption of uh offchain peer-to-peer like uh I'm going to say wacu like wacu would waku make sense for a bunch of yes so I think uh like whisper and like waku is a successor to whisper so wo is very important work and I know it's already starting to be used in messengers these things are good I think wo actually is one of the things that we should explore for the uh privacy preserving send RPC transaction use case I do think that like like Waku type things are insufficient in a couple of ways and uh so like I think maybe one or two years ago the vision for how privacy would happen is basically you would have things like the portal network and so you would you which would not just cover history it would also cover state and if you wants to make a state read then you would ask the peer-to-p peer network and you connect to it through waku and then it would give you back a Merkel branch right the reason why I think this is insufficient is that I think anonymization is not enough. Right? Basic if you think about it like let's say I do a railway withdrawal and I withdraw into account X right and then right before I do this uh there is uh in the in the network a query uh that goes to account X and also a query that goes to account Y right then what's actually happened is well there is information that is out there in the public that linked X to Y it actually doesn't even matter that theoretically X and Y might have been mapped to different nodes, right? Because like even just those two accesses happening at the at the same time is still enough information to like probabilistically narrow the that user down to a very small number of participants, right? So like I think for that reason we don't just need anonymization like we actually need a mechanism that allows users to do reads without those uh the the content of the read like the index or the address that you're reading being exposed to anyone except for the user themselves.

So I I view those two technologies as as being highly complimentary for the Ethereum use case. like I think for for the for the sending uh transaction aspect like mixnet type things which includes tour and ITP which which can also include waku as indispensable uh this is also to talk about waku again in back in 2021 I built a messaging app that was and one of the interesting things is that because the node was running in browser I didn't have require the user to do some operations run a node. Mhm. So um what do you think about because I'm running also node archive so I write my own explorer my own which is self private but we have learned that people don't want to run their own so is there any way we could have something similar that says in order to access your service you have to even without knowing it I mean the challenge with the without knowing part is that even a partial state node is going to take tens of gigabytes and you can't like ask people to download tens of gigabytes in the background without telling them because like at the very least it's going to like destroy a bunch of people's phone plans, right? Um, so I think uh the anything that is like seamless and fully in the background is something that realistically is just going to require um some kind of like light client based approach.

Now what you could do potentially is you could have like an even more radical partial state node like a node that only c like stores the state of like say a privacy protocol and nothing else. And so it's obvious to the network that you're a user of the privacy protocol but not but but they don't see anything else, right? And that's interesting. Um the yeah so that would be like one uh thing that uh yeah I think is important to keep in mind. Um the right but I mean in general I mean the other challenge of course of this kind of run a node without the user even knowing it is basically that then like if the ecosystem standardizes too much over that then like users don't become aware of like what security guarantees they have.

So the type of approach that I would favor is like a type of approach where like this is related to the whole problem of embedded wallets in general, right? where like if you use an application with an embedded wallet then by default the embedded wallet does its thing but also if it detects that you have a browser wallet then it automatically yeah switches over to the browser wallet and then the browser wallet like can run the checks itself and give you a guarantee that you're being secure even if like the DAP interface has been hacked. Uh just wondering about uh governance and privacy. Uh I know you mentioned the uh onchain voting as well as the fund transfers and kind of the important privacy elements there. Are there any other specific use cases around governance that get you excited and where you think it's crucial to enable privacy?

H I mean I think for me like governance is uh it's like often one part voting and two parts communication right and so having privacy preserving coms and having privacy preserving coms with the level of UX quality that people are willing to actually adopt it and defaults to it is something that's very valuable. So I mean Signal I think has done quite a good job but also like Signal definitely lags behind other apps on at least some dimensions. Um I mean I know increasingly you've been seeing people uh migrating to Mattermost which is like self-hosted over Slack though which is like I think fine for the context of an organization for the context of something more diffuse like a Dow like you probably want people to be able to communicate in a way where the trust guaranteed doesn't even depend on the operator. Um so having like something stronger and sort of even more cipher punkish uh would would actually help a lot. Um so that's one and then for the uh voting part I mean yeah I think uh like basically every part of a governance process should be zked right and then like basically the principle is sort of only necessary transparency right so the the rules of the of the game have to be transparent and have to be very clear to everyone but in the context of the actions like only the contents of the action that need to be public would be the contents of the action that actually get made public.

And like we can think think about that as a starting principle. Um and you know apply that across all the different uh you know regular Dow voting, quadratic voting, quadratic funding sort of designs. I mean sortation is interesting also right because like you should be able to like you should have zk sortation where no like nobody else knows if you've been chosen right because if you have been chosen that's like a very easy coercion vector right so yeah think like we need to think like privacy first across all of these things is any work on reintroducing uh interfaces to allow for encryption decryption keys which might be derived from a root key via a standardized API interfaces allowing interfaces. So this is is this like the equivalent of what MetaMask did back in the day with giving you like an encryption? Yeah, I mean I think this is a good idea.

Um I think this needs to be Yeah, like this is actually not too far from some ERC's that have already been made. Like I think 5.564 is the ERC for stealth addresses and stealth addresses implicitly depend on a public key encryption technology. Right? So if you generalize that only a little bit then you can basically have a system where each account can publicly show like what its encryption key is and then you'd be able to do encrypts to an account and I think that would be super valuable.

Um, maybe as a followup, it would also be super cool to set a small defined restricted payload which can be decrypted, right? We don't need to make it big, like a very small interface, very clearly defined. Just send something in for encryption decryption. Oh, I see. So, you mean like the equivalent of a Zcash memo field?

Yeah. Yeah, I would support that. Uh, is Rail Gun ever going to lower their quarter% fee? Do you know? Um I mean that's that's a question for them.

I think uh I mean realistically for higher levels of adoption at some point they will have to uh but I think this is uh this is their choice. Lots of privacy will help to corporations. How do you see the synergy between B2B privacy and sort of like human privacy and where are the disconnects between them? So I think they share a lot on technology right and like enterprise privacy projects and uh like kind of look these sort of grassroots Ethereum ecosystem privacy projects have contributed to the same code on many occasions. Many of them are forks of each other.

There's a lot of implicit collaboration at the tech level. often one thing that's happened in practice so far is that the B2B privacy use cases they've decided uh that for their compliance needs they have to have some kind of backdoor whereas I think for these uh kind of more consumer oriented privacy protocols like there's been a strong standard of them being backdoor free and uh I mean like so things like privacy pools and real gun that basically allow one of these depositors. Like that's fine, right? Rugpulled, right? Like if you think you're private, you should stay private.

And uh this kind of guarantee is uh incompatible with the kind of approach that B2B has been taken and like the B2B comp protocols compliance needs. So that's like probably the biggest uh disconnects that we've seen so far. I mean my personal dream is of course that over time kind of norms keeps changing and the compliance needs on even the B2B side will start shifting toward more like a kind of privacy pools and rail gun style selective disclosure approach. Uh but that's uh something that of course we'll continue taking time. Um but no I mean in general I uh I do see those ecosystems as being very collaborative uh just because even if they make different decisions they use like 90% of the same code.

What radical privacy what is privacy endame? Um I mean to me privacy endgame is basically that like you should be able to have your digital life without revealing information to other people that you do not want to reveal or that you do not know you're revealing. Um, so that's uh I mean like I think privacy is also valuable in physical space and like I definitely do not appreciate all of the people that just like randomly I mean like photo me and then put me up on crypto Twitter and then there's like people talking about like oh you know like this is what Vitalic is doing now. Uh but unfortunately those kinds of problems are kind of outside of our area of expertise to solve. Um but uh no I think uh like the domains that I think will matter um over the next two uh two decades right I think are like especially as physical privacy keeps decreasing digital privacy needs to keep increasing to compensate and uh that like this involves privacy of communications this involves privacy of funds transfers this involves privacy of uh governance operations and ultimately like those three things you know They're not entirely separate categories.

They're a continuum, right? Like any funds transfer is at least in part of communication. Um and uh you know like any communication is at least in part a governance operation, right? Uh so um but then other categories that will pop up privacy of AI so AI is like increasingly becoming sort of a second brain and like chat GPT seeing all of that as something that should not happen. Um, also, uh, oh, who here, um, has a local LLM installed on their devices now?

You should, um, who here has, uh, bought a, uh, some kind of computer or GPU specifically to be able to run better localms? Okay. Um, one thing that you can do by the way that's like actually economically optimal is uh buy something powerful uh but share it between you and a group of your friends, right? So like for example like if you look at a Mac studio the if you with top end specs like the cost does go to the crazy side it's 12 $12,000 but the way the thing that the property that LLM use has is basically you're only actually using it like 1% of the time right and uh a fullsize Mac studio is actually powerful enough to run full-size deepseeek at a very good speed and so one thing you could do is uh you know you could basically take one such device and basically give you know yourself and a few a few or like or a dozen or a few dozen uh people uh that you know like you reasonably trust access to it, right? So there's uh like a lot like I think more experimentation with kind of local and even kind of going up to the larger model is a good thing.

um basically because yeah the AI is going to become more and more a part of your thought uh we're also going to get start getting BCIs very soon brain computer interfaces and so privacy of BCIs is literally privacy of your mind um basically you know privacy will go down a lot if we're not careful and if we are careful and if we do the right thing we can keep it at a similar level or even increased and I think this is a very valuable project to push for. Can you share the perception of cypher punk within two years because the first year once you published the article and I'm just taking a death talk only for center was the only one talking about the second then some big companies were exploring like how they can talk about this what would allow them to talk about and what's the state of this cultural shift and change yeah I mean I think in general kind of for the world of This is actually a very good political moment to start talking about cyberpunk and privacy topics more openly. And I think this is actually true for a couple of reasons, right? One of those reasons is that the uh just the global political environment is much more unfriendly than it was uh I mean more than two years ago, definitely more than four years ago and like way more than than 10 years ago. And so the idea that you know, oh, you can just go run one of these centralized things and it's run by like nice idealistic tech people and like they're definitely not going to do anything bad or get captured by people who will make them do anything bad.

It's just like more obviously completely false. And this is not something that like grassroots rebels care about. This is something that institutions care about. This is something that governments care about, right? Um, and so that's uh like one thing, right?

Basically, yeah, in this kind of like much less friendly and much more unstable environment, having more sovereignty over your own data at an individual level and at a group and community level is more important. And the other thing is that like there are people who have talked about the current era as being an era where you can just do things. And sometimes of course this is bad because uh just doing things sometimes involves just shooting missiles. Uh but uh at the same time from an individual point of view like you know you can just do things does mean you know you can just uh go and make privacy protocols. you know, you can just go and send people $10,000 without telling anyone.

And like you can just uh like really go much further um in asserting your digital rights than people were comfortable with a few years ago, right? And so I think uh there's uh like basically from both of those angles, right? like the need has increased and the opportunity has uh increased and supporting kind of personal and local community security and seeing privacy as being a core part of that security is uh something that is uh I think very important to I mean both talk about and make a reality right now since uh since you it's very important for you to keep your thoughts private and you run a local LLM how do you deal with the your location privacym M yeah currently not well. Um and currently yeah like I do not claim to have uh good solutions right and uh I mean one of the challenges here right is that like even if you do um you know like burner phones and literally rotate them every month like even a month of data is totally enough to uniquely fingerprint and identify you. Um, so it's a hard problem.

I think uh if you want to like really uh go further out on uh location privacy then like we will have to figure out kind of lifestyle alternatives to having your internet constantly with you on the go that provide something close to that level of quality. And like that basically means much more accessible mesh networks. That might even mean kind of more piratey stuff like something that automatically connects to Wi-Fi networks and automatically does the click through and like you know like goes through passwords or whatever. Um but uh the basically yeah you know like generally yeah you need an alternative uh some kind of alternative to that for connectivity is probably the number one thing but then even kind of beyond the the beyond that right the other thing is just like the ease of in-person surveillance and just all of the cameras that are everywhere right and uh I mean the more realistic thing to do is to just kind of continue to to to fight for laws that kind of restrict those kinds of things and like and put controls on them, right? Because uh you know, like obviously like people can get around them, but like it like every single one of those things like does uh like push the people creating the cameras to be more careful and to kind of not be as brazen in uh in data collection or in like in letting the data get leaked.

But no going further beyond that like I definitely admit it's a challenge. What's your opinion on the how privacy projects can reach product market fit because we're talking with folks on the scene and only barely a few for example for gun it took three years to hit the break even and barely any selfunded project of three people can reach this state for roy is based on the personality of let's say and there's not many people like him. So what how would you suggest privacy builders to go post in their way to find that product? I think we I I think we should learn a lot from Signal, right? Signal is like the one reasonably cippher punk project that like actually has gotten a huge amount of adoption to the point where you know famously even the US government uses it.

Um, so, uh, that's h Bitcoin. Bitcoin. Well, Bitcoin, I would not call Bitcoin a privacy project, right? Z. Yeah.

So I think uh yeah like we should uh like and I think like from from my point of view like what succeeded with Signal is like it actually does have a good enough UX that it's a kind of like maybe like 80 to 90% capable uh drop in like Skype or Telegram replacement and then like that's good enough to the point where like basically you have these spikes of adoption that happened you know Snowden revelations and then the whole paval durab situation last here and like basically every time this happens more and more people become interested. Um so but in order for that to happen your project has to be ready for it right and so to me like one of the warnings is basically just improve UX right though I mean at the same time where like even signal is uh like it's definitely not strong enough on the metadata privacy and so we do need to keep pushing harder there. We just have a few minutes and we'll run a hackathon to present lots of ideas and usually developers when they do hackathons sometimes they overcold what's possible within three days. What would be the the low hanging fruit in terms of dev hours spending on privacy. Okay.

Um so if you wants to work on like for example P then one simple thing is instead of focusing on state you focus on history. And the easy problem that you do is basically that the input is a log topic and the output is and basically the client asks the server give me what the log the one log in the previous block that is compat uh that has that log topic and then the server rep like scans over all of the logs in just that one block. So that's like a set of size 100 to like maybe between 100 and thousand then replies back with that. Like if you just have that like that already is the seed of privacy preserving history query and like that's a thing that I mean I think especially in the GPT era lots of people here are very able to go and vibe code um well or hopefully the you know like locally running deepseeek like0525 or like whatever the most recent one um era um then if you know we're talking about like ease of use then like build a wallet that like prov creates a one-click experience for privacy pools or railway operations. Um then you know if we're talking about like ZK voting like actually fork one of the some Z um you know like DAO like governance framework can like basically like rip out the backends and make it private and and otherwise make it look as close to identical as possible, right?

So like I think that's kind of roughly the the bite-sized chunk you'd want to do for the hackathon. Let's go. The last one. Um, what are your thoughts about uh whistleblowing rights and how they intersect with privacy data? Yeah, I mean in general I think uh whistleblowing is uh absolutely important and I'm generally a big believer of know Julian Assange's maximum maxim of privacy for the weak and transparency for the powerful and I generally think that like actively forcing uh powerful organizations including companies including governments to be more open than they otherwise would be is like actually one of the more important counterforces to reduce the risk of like some kind of single actor dominating the the world in in some irreversible way in the future.

Um so to me whistleblowing is uh definitely an important part of that. Um I think uh one area where ZK tech would help is it can actually make whistleblowing credible right because uh not only can you reveal information but you can reveal information attached to a zero knowledge proof of the truth of that information. What do you think about ZKTS for? Uh, yes, ZKT OS is good. Yeah, you should use it.

Thanks, D. Thank you, too. [Music]

Automatic transcript — names and jargon may be misspelled.