"Programmable cryptography meets decentralisation" - Panel // ECC#2 - Buenos Aires 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Panel with : ... Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] This panel is focused on programmable cryptography and really I think a lot of what we'll end up talking about is applications and the systems that we'll build above the cryptographic primitives in support of privacy. So thinking about great you've got these uh underlying building blocks that that are a lot of what we think of in privacy but then there's a large systems layer to make it effective. Uh and so we've got a a set of uh projects represented here that have uh you know a set of problems each that they're that they'll be able to describe of how we can leverage these privacy primitives into useful programmatic and and eventually scalable uh systems. So uh with that why don't we go down and do brief under a minute introductions of each other and then uh we'll get into some conversation.
Okay. So my name is Sandy. I'm an engineer by way background. I started my careers at companies like Google and Facebook. Uh joined web 3 in 2017.
Worked on a shard at layer 1. And a few years ago I started my own project which is essentially Calimero. Um a peer-to-peer like local first peer-to-peer uh general purpose framework for developers. Thank you. Um hey I'm Sip.
I'm the lead at Stadis Network. uh status network is incubated within the status ecosystem. So we've been around since 2017. Um and right now we focusing on building u vertically integrated stack uh that puts privacy forward uh meaning private chat private messaging but also uh what uh I'm building specifically which is a gasless L2. So natively gasless there's no gas on the L2.
It's replaced by reputation. Um and that unlocks a new type of anonymity sets that is not based on um gas linkage. So there is no way to link the gas usage of an address with another one. Um and so uh that enables us to have kind of a composible privacy layer at on top of the L2. Um so we are currently on test net.
We have our spam prediction um coming out next week uh on the test net uh which is based on ZK proof um to prove that you're not spamming the network and uh mainet early next year.
Hi everybody. Uh I'm Zach. I am the co-founder of the Aztec network. Um I'm also a uh software engineer and a cryptographer. Um and at Aztec we are a privacy first layer 2 on Ethereum.
We're building a uh programmable private world computer. Basically take everything that makes Ethereum great, everything we love about it and add privacy by default.
Hello, I'm Suji. I'm the founder of Mass Network. We are about the same time with status enter social when there's no web three word around 2017. At first it's called math book. Then Facebook really angry.
They want to sue us. Then then we just go find Twitter. Twitter was very friendly that time under Dorsy and we did many crazy thing um encryption you know sending over message and if you remember J dossy's FT um sale in 21 that's also one of our like platform company now it's under us um but it's just like again it's very small I mean every web three privacy thing is still very small um especially social uh so we're just here to keep building for like just now it's the nice year for me to enter crypto. So soon it's going to be a decade. So you know, hope some good thing happen.
Thank you. Um I think we actually have sort of a an interesting progression up the stack that we can talk through in some sense where we can go from the networking peer-to-peer layer up through how do we deal with chain metadata leakage onto the actual cryptographic and decentralization issues and then into the application layer and how do we make these social apps and so forth. uh and and how does that behavior translate all the way back down? So, um with that structure, maybe the first um prompt that I'll throw out is we've got a lot of different places to be thinking about privacy from IP addresses and network to onchain where all of these messages are now having some metadata to the application layer, you know, who can see it, decisions that we're making. How do we reason through this and what are we most like afraid of uh as we're approaching these systems?
Okay. Um yeah, I I have to I have to worry about this uh dayto-day for the last seven years. Um so I guess the question is what do you worry about the most changes? Uh because for a very long time it's not been possible technologically to build uh like featurerich privacy layers. Um Zcash uh really broke ground when they launched in 2015.
Um but for for many years afterwards um kind of private shielded transfers was basically the best that you could do. Uh and the goal of full programmability was uh not really like not really on the cards. Um and you can see this with all the all the ZK L2 ZK EVMs being um growing up over the years. None of them were really thinking about privacy because it's just it's it's too hard. I can explain a few reasons why.
um things like uh well if it's private you got to if you're if you're hiding data and encrypting it and just proving statements about the encrypted data on chain then you need to make those proofs locally um which means you can't just scale um your your hardware to deal with intractable problems with proof uh proof times your memory resources are extremely finite um and uh you know back in the day when when I got started you know you also had problems like well back then snarks all needed trusted setups uh per application and and that doesn't scale either. So, so there was a technological feasibility issue which I think now today has largely been solvedish um with networks like Aztec networks like um like Miden um but it's still very immature right like it's still like throughputs are not as good as they are on transparent networks asn't launched yet uh Miden still has a lot of centralization um issues um so for me I'm still much I'm still very much focused on the technical feasibility part um once that's been cracked Network level privacy is a huge deal um that has um we've not put any effort into solving uh because others are you know um things like NIM network um is anybody here doing network level privacy
what
is anyone here doing network level privacy
network level
yeah as in like
yeah to get your transaction into a meool
yeah making that
RBC
yeah pardon
RPC
yeah yeah
so private RPC
yeah private RPC even things like we're dealing with like for example states like syncing to the network, right? If you have private information um that you need to you need to download from the network, it's not feasible for a user like running like you know if they're interacting with a DAP on a website on their phone, they're not going to run a full node. So they need to ask somebody for their information which leaks a bit of data, right? And and you can solve that with things like trustes like tees um but that's not a perfect solution. You can do it with oblivious message retrieval but then that's way that's not efficient enough.
There are problems all over the stack that need a lot of people to work on them to solve. So I I think yeah you you hit the nail on the head here um on in terms of the stack. So the way at Stadus on how we thinking about that it's we want every level of the stack to be asparate as possible. Meaning that uh the basic level really is communication. So like how do you send and receive messages and make sure that those messages are as shielded or as encrypted as possible.
um so that the recipient doesn't is not able to obtain a lot of metadata around who you are, where you based and so on. Um, so that's why we built Waku, uh, which is kind of the successor to Whisper in the, uh, original Ethereum white paper where it's peer-to-peer and to an encrypted messaging system, uh, that is used by Real Gun actually um, and and a bunch of other uh, companies in the space and um, the way we see the interaction with the end user for privacy focused protocols is through an app. Ultimately, people are going to go through apps. Um, and so we want those apps to be as seamless as possible while integrating the highest level of privacy possible, which of course is always kind of a trade-off, right? It's like, oh, I want to use a like a private RPC.
Cool. A private RPC, you will have probably like a one or two second latency on that. And suddenly that's a whole block that you just passed by asking the chain to give you some information. So how do we make privacy actually fast and usable and seamless? Um it's and that's kind of how we thinking like the philosophy we have at Status is by integrating it vertically then we are able to have a faster uh access and a more seamless access for end users.
Yeah. Uh I think people downstairs like here is more eastern like crypto align people downstairs especially I mean I respect them but like you know people like EFF all these folks are good friends of mine but I think people downstairs don't like us for a reason that we are adding a lot of complexity um that I should not necessarily war like you know I've been we've been in decentralized social for almost 10 years right and the first time I was invited by Dan for caster and he said hey pay $2 I'm like, "Okay, I can pay $2 fee for register, but I just let you know if you only support OP and base chain, which means you're all your social network guys or KYC FYI. I'm not sure they done that or not." And and there's no there's no enough um programmability to just add different layers. We can definitely use like ZK money like Aztec to just, you know, as a as a middle one to just make sure the gas fee you pay for registry social network is not KYC, but there's no one doing that.
So it's safe to say whoever use crypto social network it's fully KYC and it doesn't need a quot order. It's just very easy to get your KYC data. There's no um we don't have any mindset for you know application level of privacy and how to program that to make it work. So that's why people downstairs don't like us. [laughter]
Sorry to hog the mic but on that topic um Aztec has actually launched really like I think what I could argue is the first application level permissionless KYC ever. um with our token with our token sale and Zika passport. Yeah. Um B. Thank you.
Um with Zeke because you know we're with Aztec we're not doing a token sale and we need because we're doing it all first party. We're doing it decentralized. It's all happening through UNISOP and their continuous clearing auction. We do need an understanding that somebody's not on the effect list. Um so how do you do that without getting them to fork over all your data?
Well, you use the zero launch passport proof. Um where all where what they're proving is I'm not on an effect list. Uh and um like yeah, a lot of what Aztec was built for is that kind of application level privacy where you can code up your own specific criteria and credentials for what you need. Um and we want Aztec to become effectively the cononical home of credentials on web 3 where you can bridge into and out of Aztec from any other chain A network um and privately query uh about whether somebody or some account has a credential that you need.
Yeah. from my side like I see it in like two categories right like one category is the financial privacy right so we have Zcash Aztec all of these other protocols but like what I'm like you know personally passionate about is like all the other stuff right so every day use Slack your data is stored on a server you use Facebook your data is stored on like some random server right um and they have like full access to all end user customer data and like we don't really have like mass adopted applications maybe like signal is the only application which is like used by privacy folks which is you know massively adopted and you know governments and regular people like what I would love to see is just you know these types of applications which have you know first nice user experience that they don't cost you know insane amount of money and then to the third thing is that developers can actually build privacy solutions without thinking you know how do I build encryption how do I build this how do I build that like it should be very very simple and like once you get to that point that you know it's like we had you internet was decentralized like SMTP you know we had it for many many years it's a decentralized protocol by nature but like we just gave it away to Google to host SMTCP servers for us um and like now they control the email right um so like the question is like how do we get back from how do we go back in the future uh to you know having self-hosted stuff u yeah
totally let me let me do one more round and I think the the next prompt I want to ask is what is the thing you're most excited about in the coming year? So, so what what feature or privacy uh update are you sort of excited to see on the horizon?
I mean like I am very into federated systems. So hopefully I would love to see like more applications like Fileverse. Fileverse is a really good example of like an end consumer application which is peer-to-peer which is you know encrypted. Uh I don't know if it's encrypted. I know I said a bold statement.
I hope so. I assume I assume uh but uh I would really love to see more more stuff like this um and yeah I mean if like protocols which are peer-to-peer like you know we had many tries like tried gun protocol tried like many people tried and I think it's like one part of the web which we kind of um you know left uh behind just because money was more interesting um and I hopefully like now I see more and more protocols who are like local first who use like CRDTS who use all of these technologies which in my opinion are like amazing and awesome and I think we're going to see a decentralized internet hopefully again in next 10 years.
Um so actually I wanted to kind of go back to what you said just before around like financial applications and I think one of the biggest uh friction of privacy right now is that uh it's not composible. Most of the privacy solutions are just you deposit and you just leave it there and that's it. So you don't have your money working for you. it's not composable with other D5 protocols. So the financial incentive to be part of an anonymity set is actually very low and I think this is also what explains the low adoption in the space is that there was up until now no real financial incentives to do it.
Um I think this is changing like privacy pool added some uh SUSDS support. So you can have like staked uh USD uh like kind of uh earning yield. You can have ST I think they support now but it's still like very early and it's not composable. So you can borrow on that deposit for example you can like you just use it for collateral. This is actually one of the things that we are building on the L2 is to make it as composable with normal D5 applications.
So, what I want to do is I want to be able to have my main address deposit into um uh lending markets just like pure ETH and then from a fresh new wallet that has nothing to do with anything start borrowing USD on that and this is where the real privacy uh benefits will come from because suddenly you have private money that you can use anywhere and that is just earning yield on the other side. Um I think this is kind of my first answer on the financial part. On the end user part and this is very linked of course. Um the way we initially thought about status network was for a gaming uh layer too because it's gasless so it's very easy to on on board people. They don't have to think about gas but also because um we have that kind of optional privacy.
So you can have fog of war and like all the kind of non-disclosed uh uh secret stuff in games and I actually believe that games are going to be the thing that push privacy forward just because people will want to use them and by the use case we'll be forced to have like faster block times. We'll have be forced to have like faster proof generation. Um, and so like adoption will come from the increased usage and not us trying to like push like super deep cipher punk difficult cryptography to people.
Yeah, good answer. I mean, composible privacy hits the nail on the head and it's also what I'm excited about. I'm uh obviously I'm biased. got my own self-interests here, but uh next year Aztec is launching um and it's going to be the first fully decentralized holistic full stack composable private blockchain.
Are you as stup?
Yeah, stage two rollup. Um and uh the um it has full code privacy. People don't know what transa what transactions you're executing. It has user privacy. They don't know who you are, your counterparties.
And as data privacy, they don't see the values. And the reason why I think this is so powerful is because I think privacy is going to eat the world much in the same way that software at the world where we saw from 2000 to 2010 all of these um existing like brick and mortar activities moved into the cloud moved into software but where you had data custodians and you had things like Facebook, Google taking your user data, monetizing it, treating as their property and now we're going to be able to build financial systems and products and services and games and coordination mechanisms where that data stays with the user and and we're going to be able to rebuild a huge amount of like our existing software ecosystem. Um the the reason why I'm so excited about Aztec is because it makes things so easy uh and composable. You can write a contract with private information, private state, private functions. You just write it in a programming language.
No. You don't need to know cryptography. And then your contract can call other contracts to have their own private functions and their own private state and their own private functionalities. And then you can bridge out into the wider ecosystem of L1's and L2s or bridge back in and use Aztec as your privacy shield. Um and you can build things like information um asymmetric games.
You can build um like uh regulated like regulated instruments where you can perform your KYC uh in a decentralized manner and then inject that those assets into into DeFi protocols as liquidity. Um it's it's really is going to be a completely new world that's that's opening up. Yeah, I'm like super bullish on you guys like you know um Aztecs you guys like status. So um as I start from ziki money if I remember correctly right so I hope next year we not only have lei finance zi money privacy we have like ziki porn please because like last cycle 21 I was living in Japan I start to teach my like normie web two Japanese friend to use like you know ziki money and all this privacy thing okay after a week they finish the sit up then they ask me okay where's the porn where's the content Dude, like I started all these cryptography. Where's the content?
Like what's the purpose? Like drug there's not even drugs. Okay. So what's the content? So I think the next year will be good is for the alternative um entry point alternative u way to get the content.
For example like poly poly market um they cannot have an app non KYC for for betting because the you know regulation. They can have a website because like web is still relatively open. You can do all the crazy thing with VPM. But like if you have like American App Store, it never go get you like non KYC version. But there's um there's O store in Europe and Japan.
Uh if you heard the news like um Apple lose a lawsuit. So they have to you know and also in the in the US they has a lawsuit with Fortnite. So they might have open app a lot of places actually allow like alternative front end alternative stores which have the alternative poly market right alternative like version of poly market for iOS app. It can be also applied for someone smart enough to engineer like gas zk status into one like super big only fan. Again it's doable just no one doing that and if you really um spend a million on only fan you actually the web experience is not good enough.
Um so I actually encourage people like developer here is to make more only fan friends. So one of my friend I mean real world friend Hong Kong Doll. She's like one of largest only fan creator um and a top Chinese um lady uh in in the adult industry ever and her annual income in 2122 was like 10 million. It's like quite an adventure for her to get money and pay tax all the things and quite adventure for audience to to learn all these. I I'm pretty sure that's more complicated than learning cryptographic.
So I think it's the problem of the content. We are almost there. I think now actually learning ZK is like at least using ZK is not that hard. Um it's actually easier than just you know go on portab and just turn off all the you know ads. Yeah.
So I think we are looking for more content and more alternative entry point into these content next year. No matter it's like AI browser, alternative app store or like alternative front end. If you don't have these we just always stuck in money. That's not cool. I I can agree that um ZK is more interesting at least than doing taxes.
So um so I think we got a a great like there there's still a lot of excitement here and a lot of of lot of you know building and attempts to to really get to users which is exciting uh and I think is like a a maturing of this ecosystem from okay we need to like have a solution to identifying these problems and identifying um you know the things that we can really uh solve. I guess maybe as a final thing, can you relate sort of this programmable crypto and this this thought of we've got these these primitives that we're using as this differentiator. We've got users that we're trying to like really attach through different problems like social media or so forth. How do we think about bridging that intermediate application layer? Because I think we've all got like sort of specific applications.
Are you coming at it from the top? Are you coming at it from the bottom up? And how are you testing? How are you feeling like you've you're you're addressing that that need and matching it?
It's a good question. For for for me, it's all about accessibility. You know, when I started this uh when I started Aztec, you know, crypto was you needed like you needed to be an academic to understand it. You know, read through papers and like write like programming. It was a nightmare.
Um, so I want to make it so that I want to make it as easy to develop privacy applications on chain as it is writing a smart cartridge on Ethereum. As in it's just code and yes, there are some semantics you need to understand, but it's just code. I mean, it just works out of the box, right? You have you have your node that you run and it syncs to the network and it gets you your private state and you just don't have to worry about it. And obviously, like this is always a work in progress.
I'm not going to claim mastic is right now as easy as writing on Ethereum, but it's a hell of a lot closer to writing on Ethereum than it is writing a custom ZK circuit. That's for sure. Um, and for me it's it's about accessibility as you said like the demand is here. There is so much latent demand. is what I've been telling people talk when I've been talking about privacy you know in 2018 2019 and they're like well why why do we need privacy on chain right like you know and I'm saying this is sampling bias if you were in web 3 by definition you cannot care about privacy because everything's transparent and so there is a universe of voices and opinions that are not in the room that are not telling you that their needs are that are not advocating for their interests and now that we're seeing privacy technology mature we're starting to see them come into the room and starting to talk and now people are like wow it's privacy season privacy is a big deal and I'm like I told you I told you 7 years ago that's what I've been building.
Um uh so yeah the demands there we just need to make it accessible. We need to make it easy. We it just needs to work and people will build.
Uh yeah 100%. So that's that's actually one of the the philosophies between uh like behind the the stack that the whole stack that we're building. Um you talked about like the entry point, right? Um we have a wallet. So wallets right now are the kind of most basic entry point to crypto.
And what we've been seeing um and actually to to your point um during the memecoin mania you had people watching only fans from their um uh rabbi wallets or like their uh Phantom on Phantom. They they were they were watching porn on their Phantom wallets and I was like I never thought that people would use their wallet as a browser for this kind of stuff but actually they do. So cool. That means that they just used the browser as a normal browser. That's perfect.
This is what we want. We want to make it as seamless as just using a browser, using the internet, except that now with a bunch of super cool cryptographic tools, we're able to have private interactions with public and private data. And I think ZKTLS is something that is also bringing a lots of new uh powerful tools to the to the space. Um, one of the main uh challenge that we have right now at at um at Stadus is to be able to do the whole the whole customer um acquisition, onboarding, on-ramping yields, literally like the whole crypto thing without touching a QC, without touching a uh identifiable information from public companies. Um so ZK peer-to-peer um like all those kind of solutions are going in that direction where you can be onboarded to crypto in two clicks without revealing any information and that's kind of the ultimate goal
from on my side like I have a web two approach to it. Um so like all the companies I worked at we would usually like dog food the stuff. So like eat your own dog food right? So if essentially you're building a product and launching a product, you should be able to use the product yourself, right? Um and if if you're not doing that, then we have a problem, right?
So like we have to address this problem at its core. And like essentially what we do at Calimero, we like open sourced everything. So we used Slack, we decided let's kill Slack, let's build a peer-to-peer solution which replaces Slack and start using it. So like we found drawbacks in the system, we find where are the protocol issues um and essentially improve iteratively. And then we're like okay we use notion right so can we build a you know CRDT backed uh notion replacement which is fully peer-to-peer and then like use it internally and essentially like doing this internally and like getting some friends and family to use it like we improved you know the product the developer experience itself like we're all developers so like we can you know see what what are the like shortcomings uh of the system and essentially like that's kind of like iteratively we are doing this and doing this and hopefully like we want to launch uh you know this stuff every like currently It's open source so you can see the code and run it yourselves but like we never like launched it as a product.
Uh but the idea is like I really believe like you should you know put the time and effort into using the products you're building because like if you're not you doing it nobody else will. So I kind of kills the point and like yeah
agree.
Yeah. I think um more important is like we should not fight. there's no meaning for us to fight. And then no matter downstairs, upstairs, here or there, like like last the last whole year was like okay OP people hate like aron people like base people hate base people hate binance people but dude you're the same scene you know like that's a I don't see any difference besides like wine's white wine is like yellow it's different no difference and but compared to what we're building like it's actually just not good enough it's actually it's very important to remind to to to remind everyone here like actually is a salana guy first integrate hyperlid phone phantom it's not any like EVM Ethereum wallet I don't know why because hyperlqu is EVM it's on arbitrage why why what's what's the reason and I mean when we start mask you know we're the first one you know just trying to bridge like mass like you know um Twitter and Facebook what's good but now in web3 social there's no one bridging like lens and faster and like blue sky so that's why we do the spin-off called Firefly and then we saw might be someone going to do that we just don't do that like so hard and figure out actually no one doing at all. Um just you know welcome to download firefighter.
social. you can find out actually is a stony app actually support like both all these social network again it's crazy I think just less fight um and more building and more entry point and we just need to program all these like good you know cryptographic encryption AK stuff together to make it usable uh no matter the user want to do 100% leverage trade or porn I mean it's their freedom but we have to provide the good usability and the holistic you know um application level yeah so that's something I think very important.
Awesome. Thank you. So, I think that's our time. So, let's thank all of our panel members once more. [applause] [screaming]
Automatic transcript — names and jargon may be misspelled.