Ethereum Privacy Roadmap by Andy Guzman || Ethereum Privacy Stack, Devconnect 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Speaker
Andy Guzman showcases what they were doing with PSE in regards to navigating through Ethereum and its privacy as well as going into presumptions how its future will look like. Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/
Transcript
Cool. How's everyone doing? Thanks for holding on this week and last presentation of the day. So, um, today I'm going to just share some thoughts about where we're going, where have we coming through and and also like some thoughts about perhaps some areas where we will need some help from this audience. So, along this week, especially in this event, we have seen great speakers, great technology, great progress.
Um I did wanted to talk something a little bit different to start. So in 1840s u there was a gentleman uh Justin von Levink I don't know how to pronounce it well who noticed something interesting in agriculture which said that basically even though he could put more water or more fertilizers or more sun some things some didn't yield more and he discovered a law called the law of the minimum which is really great to understand how does growth in an ecosystem whether that's agriculture or even the privacy ecosystem happens and it requires The the key idea is that the growth of the ecosystem would only happen with the scarcest resource that exists. So in this case, things like you can add more calcium, more sun, more water, but if there's not enough potassium, things wouldn't grow. So this is a good analogy on how can we grow our space, but also a good analogy when I try to think about how can we think about privacy. So privacy is a leakage.
You leak information that might relate back to you. And similar to this analogy of the weaker the weakest point in the chain which is like what it end and end ends up breaking. Similarly we need to think about privacy in a very holistic way. So there's layers and every layer we'll need to think about how can we lock them and make them private so that users can feel comfortable and feel under control without leaking their information. And during the our research we have seen these are just some of the layers that we have identified.
This is not an academic classification, but we do see that we leak information everywhere. If we're interacting with the DAP, we leak information in the front ends with a browser fingerprinting with uh our like our operating system and our IP. We leak information whenever we want to broadcast whenever we try to connect to an HTTP request or broadcasting. We leak information with RPCs whenever you know information flow through it. uh on relayers on mempos even our own validators.
Sometimes if we just even run our own infrastructure we could be leaking information about the address and our IP and this is frankly you know a tough problem to to crack. So within PSSE which is a team part of the Ethereum foundation called privacy stewards of Ethereum we have simplified our mental model and how can we think of this and try to divide the ecosystem and the space and how to try to make meaningful contributions to it. So we divide it very simply in three buckets. So private reads what I like to think about metadata privacy, networking privacy is whenever you want to query the state of the blockchain and you want to query your balance or whatever the price of a token. Um, private rights is whenever you want to do onchain actions, whether that's voting or transactions.
And private voting is whenever you want to port data, whether that be from like web two world to the web 3 world or whenever you want to make this data useful in in in your client devices. So, browsers, phones, uh, etc. And there's just some actions that you typically do, right? So, actually, we'll need to think through first what is the use case? what are the things that people want to do that our users want to do and then how what are the layers that it interacts and how can we lock all of them so these are just some things that within the PSC team would have been doing things like Tor if we want to query the balance without disclosing to a server what information we're trying to query things like P as well other types of techniques things like um integrating or supporting teams integrating sock 5 connections and exposing on onion domain.
So it's easier to to tackle, it's easier to have hidden services and the ecosystem can even access it without leaking information and defeating censorship and that is all online private reads but things like postquant exploring new systems to do plus quantum foldable client side layer 2s. Things like um state of private voting that was discussed earlier today. things like a beginnings of a comparison of methodology to compare like the different technologies that we have on the private transaction space and there's all these other side like benchmarking CKVMs you might have heard that CKVMs are great for scaling and they are but are they great for privacy not that many right we'll need to think and and and think through and build all these tool chains so we can have GPU acceleration CPU acceleration but on your phones uh that is mobile native and a lot of other things or primitive like CQTLS, CKPDF and many other things. So we can port over and have much richness of data uh and identity that we can then you know have a complete private flow at the upper layers of the stack. So it's a big challenge and we're just a few people so it's great to see like just great teams happening and growing and building a lot of these tooling on the ecosystem as well.
Now when people talk about privacy typically they think of of of two things right what is the 8020 what is like the biggest the 20% of effort which will bring the 80% of value at least from a perspective from a user and most of the time they think of two two things right private transactions sending ETH or ERC20s or private DeFi whenever want to do like loans and and um borrowing and swaps etc. I'm going to talk now about a little bit about networking method data privacy and then a little bit about private transactions some learnings. So one of the things that is scary or hard to wrap our heads around is how do we measure privacy and how can we reason about it? Is there a way in which we can flatten the levels of privacy into simple numbers the same way that in a layer two landscapes people were able to do stages of like stage zero, stage one, stage two? I think it's hard but I think it's doable and just there's been some attempts on Twitter of different people uh for example trying to say stage one is just a transparent transactions uh stage two is something that I hide the content of that transaction the asset or the amount and that and we will call this confidential stage three it's something that is an anonymous which I had I hide the sender on that receiver and stage four will be I hide everything right so this in itself is just a good mental model to start thinking and reasoning about privacy onchain privacy.
Vitalik as well in one of these you know interactions with people mentioned that trust assumptions are also important understanding how many people need to collude in order to take away my privacy right like rockpull your privacy and the best things are if if if there's no way right that somebody you know can take away from privacy but there are many models that are very valid the specific situations where a committee or trust operator or just a hardware um are valid argumentations just to to build the privacy protocol on top of it. So we need a way to reason about all these technologies so we can be better, you know, more intentionally build build the systems. So within the privacy landscape in the in the networking levels, this is a picture about Bitcoin nodes from bit nodes.io or so. So you can see how many Bitcoin nodes are discovered by public IP addresses and how the onion addresses have been growing from zero to almost 64%.
So this is just a an interesting observation about how other ecosystems are approaching and I wonder do we have data on the Ethereum ecosystem? Do we know how many validators or full nodes are accessed only through onion services or mixnets? I'm not sure we do and I think we should spend a little bit more of time here and this is an effort that um Igor Baronov um helping us in the in the privacy cluster has been doing which is compiling and helping other teams and organizations and and services to add for example onionized support tour. So Cake wallet, Hinkle wallet, Broom, Ampire, Luncape and and many others are adding sucks 5 or snowflake support so they can bypass censorship and not track or not know the origin of the request. And this in itself adds a lot of value to the privacy ecosystem.
There's also RPC nodes like the RPC and and public nodes and lambda nodes uh explorers like block scout frontends like tornado cache front end and load balancers and SDKs. This list needs to grow right across the Ethereum ecosystem. We still need to be adding more and more onionize and mixet support if we want to get into a a a place in which like all this networking metadata privacy is actually happening on our space. So not only onchain privacy which is extremely important and many great teams are building it but also this metadata networking level privacy and shout out as well for NIM uh Nosis teams. them recently this week announced about you know how to have a reverse proxy before your transactions reach the RPC and so they can grow through mixets right so this is roughly what we are trying to achieve we want the properties of confidentiality which is hiding um the content of the request and anonymity which is hiding the origin and a destination and these are just like increasingly we can do it it's it's it's a lot easier for example doing PI and TR and and ORAM and FH with index data but as we try to move into more complex data structures like the raw Ethereum history in Merkel Patricia trees um it's a lot harder right but there are intermediate steps that we can do like transform Ethereum data into something that is more easily querable and all of these are things that we're exploring and trying to push forward so like it's easier for you and me just to use your wallet and there's magic behind it and we you query data without leaking all your information and all your your bags Okay, let's talk briefly about private transfers.
So, what do we mean? Again, just send ETH or ERC20s from me to you. And I will say like there is a real need to understand what is the ideal private transfer mechanism. So, I just took the liberty of putting these six ideas here. There's a lot of discussion and consensus that needs to happen.
Well, let's imagine a private transfer mechanism that is subsent or at least just roughly twice the gas for a transparent transfer. Uh private transfer mechanism that is just one click. So no additional seeds, no additional approvals is just one click. The latency just one block. The privacy I can decide.
It could be fully transparent or I just hide the amount or I hide the origin or a destination or everything. The compliance the same. I can decide to just be a 100% permissionless privacy or I want to adhere to a specific jurisdiction where they can either see uh my transactions with a viewing key with my permission or they just I don't know I I I prove that I'm not part of a specific list and trust assumptions hopefully additionally we can build something that does not require any additional trust assumption besides just using the Ethereum network. Does this exist yet? No.
But we need to move forward and move towards this direction and we can explore and evaluate different prim primitives and protocols and evaluate them in these different criteria like from one to five. How good is this protocol in cost in UX in latency and the good thing is that these different protocols will serve different markets. So the emojis here didn't didn't work. But the top should have been like a retail person. They're just someone who they today wants to have great UX, great cost, perhaps don't need to have like a lot of um privacy guarantees because it's very low amount of numbers.
But for an institution, it will look very different, right? It needs good be compliant. It needs to have top amount of privacy because it's probably going to be like high prices um sorry high high amounts and it's okay to have you know a bit more of trust assumptions in their infrastructure and we'll have different type of um user personas and different type of segments. So how privacy looks a privacy solution looks to you and to me it might be different from different organizations and users. Um during this exploration we found out like at least 12 13 different technical approaches from mixers and shielded pools like many of the projects that we saw here from stealth addresses as well that we have in the in in the privacy district from previdiums to IO or just general roll-ups that are programmable with CK things that are programmable with MPC is like a very expansive design space about how can we build privacy and just in this use case right just in private transfers there's like about 13 different technical approaches and of course they combine and they're not perfect classifications but this is just an initial map and from there we identified 35 teams great teams trying to add some sort of these combinations of privacy right so what I can say is that there's a very rich ecosystem that is trying to solve this problem and I'm yeah and basically it's like following many different type of approaches from things that are with different trade-offs that have better UX, better speed, better privacy uh or better costs.
And this is just a picture about you know these 30 time 35 teams um or wallets or you know protocols that exist. So I'm going to say some predictions and I hope you bear with me and check these predictions in 12 months in one year. So the first one is we will solve private transfers by November of 2026. So by next Devcon I will stand up in the stage and say like we have solved this problem. It will be be already done and I'm very hopeful and I'm you know extremely convinced about the richness of the design space and the richness of these you know teams and like you know proficiency of just executing.
The other one is we will have endtoend UX integrations. Right now these protocols have very different strengths and weaknesses but if you combine several of them you can actually achieve a really great um really great UX really great privacy with all the like you know combining the strengths of each one and I will see I imagine there will be more consolidation of teams next year. However, I do also see some challenges. One is like we'll need still scalable privacy and the good thing is like scalability is one of like main Ethereum, you know, roadmaps uh goals, but also some of these systems do introduce some considerations that perhaps won't scale to a thousand transactions per second, 10,000, you know, and things in in the in the web two institutional world. You know, these are some of the numbers that we will need.
The other one is we will need uh more interoperable privacy. That does mean that these all these protocols are easier to plug and play between each other. We'll still need that. And the one that I'm more worried is we'll need unified liquidity. So this is moving slightly away from just pure transactions.
But when we're starting talk to talk about uh private DeFi, it is true that current systems can provide some level of privacy but by segmenting or compartmentalizing different type of technologies into their own subsystems. So a big challenge for our community by next year is how do we give privacy without fragmenting liquidity. So this is all nice and good but we'll get used and I think I always like to remind this to people and teams es especially like highly technical highly proficient teams is like the best technical solution or technology not always wins uh but rather it also has to be adopted by its users and its you know developers and and its you know ecosystem. So a key idea here is super simple but I have to remind everyone it's like adoption would always happen if the benefits outweighs the cost. So a user would only adopt this if they see more benefits by using the privacy solution instead of like transparent without with no privacy guarantees and the same case for developers of wallets and of websites etc.
So what are the costs for a user is the UX the latency the actual you know money that people pay for their private version of whatever they want to do and for a developer is the integration cost the infrastructure to run it the stability and the risk. So this is why I think for example an initiative like Kohaku makes a lot of sense because it helps ship privacy much cheaper for just wallets or anyone who wants to adopt it because it's an SDK that you can just plug and play and reduces the cost of development and adoption. So keep keep this in mind um when we're building tools uh to build this end toend Ethereum privacy stack. Now just lastly some words about compliance because I think this is also going to be it is a big topic now and is going to be continue to be a big topic next year is like I do see this compliance as a spectrum and culturally this room and all these people who came for defcon um we we we could be within this spectrum in one way or another. So on the left side uh we have permissionless privacy or the cipher punk privacy right these early initial ideals where I don't need to use anyone for permission in order to have privacy this you know human rights perspective on the right side we have the compliant privacy or the responsible and the practical and we see teams like saying like hey I don't want these privacy protocols to be used by bad actors or by this jurisdiction or whatn not right and this is actually a need from institutions and governments and many people who prefer to do And you can see this on Twitter right uh from the left things like Hanyabu or Pava Versace or Ethereum engine they're like no no no I don't don't add any compliance to my privacy protocols and on the other side we have things like Amin and way that who were around here or other protocols which is like no no we need to build privacy but we need to do it responsibly and I will continue to see this play out kind of like this diff difference of perspectives and I will say like either extreme carries risk If we do all compliant privacy, we might risk a capture on our chain of on Ethereum because basically regulators will decide who can use privacy, who cannot.
But if we do all the cipher pump with no consideration about the other great amount of users that are institutions and governments and just people who want to be compliant within their jurisdiction, then we might alienate a lot of part of the world. So either extreme carries risk and I think at least from my perspective I will try to be a counterbalance of whatever is the you know most um famous or like you know the big mindset of of people within a specific amount of time. Another big one that will happen next year is like privacy at the core protocol. So these different perspectives might start a civil war in our in our ecosystem in a sense of like should we embed privacy to the core layer one or should we keep it at the app layer. I want to start the discussion.
I want this to be like a very open transparent for the Ethereum ecosystem because there are pros and cons with either. Uh but I want us to spark it as a group of of privacy advocates. And finally, I just want to finish by saying the the Foundation continues to share its commitment to privacy by having a huge group of researchers, engineers, um, coordinators and great thinkers and advocates who wants to propose and and keep pushing these ideals forward not only because of an adoption and because it makes sense, but also because of our values and our origins and just keep pushing uh, human freedom. So, thank you and Ethereum is for privacy. Okay, we only have one question at the moment, so I I will I will answer this.
We don't have the QR code, but maybe I'll have a little walk you around the uh the audience. So, the the question we have is, I'm a developer who wants to contribute. Which area do you need most help with? All of them depends on your skill set, right? If you're like a person who likes and cares and and you know breathes like networking or RPC or infrastructure perhaps you know the the things that we call private reads makes a lot of sense or private broadcasting if you have touch kind of like the core protocol validators as well.
If you are someone who is just like an appdev or a CK circuit engineer or something perhaps it makes sense a lot on the private read private rights like onchain privacy. Um yeah and the same right if you are like more on GPU hardware like it just depends on your skill sets I guess and what interests you the most. I will say in all of them we need help and in all of them there's like good open issues uh work to be done for sure.
Automatic transcript — names and jargon may be misspelled.