Loading summary
A
I don't consider it a leader in the privacy space any more than I would consider JP Morgan a leader in the privacy space, which is to say that those guarantees in terms of privacy that you would get, which is just trusting your counterparty, are totally achievable without using crypto in the way that they've done it. And so I don't see any reason why I would want to expose myself to that, like why I would want bank level guarantees. I would just use a bank.
B
Hi everyone. Welcome to Unchained, your no hype resource for all things crypto. I'm your host, Laura Shin. Thanks for joining this live stream and we will first take a quick word from the sponsors who make the show possible. This episode is brought to you by Kape, America's privacy first mobile carrier. Same premium service you'd expect from any other carrier, but designed so your number, your location and your data actually stay yours get 33% off. Six months after at Cape Co Unchained today's topic is privacy. Here to discuss are Joe Andrews, CEO of Aztec Labs, Jared Hope, founder of Lagos, and Mert Mumtaz, co founder and CEO of Helios. Welcome Joe, Jared and Mert.
A
Good to be here.
B
Hi.
C
Thanks.
D
Faros.
C
Hey, thanks. Thanks for having us.
B
We're facing a moment in crypto when it just feels like privacy is going to start mattering a lot more. It's already starting to matter a lot, lot more and more chains are going to be adopting it in various ways and they already are working on that. Obviously zcash saw a huge renaissance in the last year. Monero also got a boost. Ethereum announced this privacy roadmap near had or has confidential transactions, Canton is drawing institutions to its private chain and more. But before we get into all the details on that, let's just start with each of you explaining your interest in privacy and why you think this is the moment that this direction direction is gaining momentum. Now why don't we start with Jared?
D
Sure. I guess like, you know, I got into like the space through the sort of BBS and piracy scene and found cipher punks and like crypto anarchy. So in the 90s I was already pretty naturally inclined towards these ideas. But and I've argued, you know, for privacy on a civil liberty standpoint as well as, you know, against the sort of surveillance state, particularly after 9 11. But I think what's interesting to me about it now is like how my thoughts have developed a lot more and I started to realize that it's privacy is actually a property that's required to unblock privacy, new market activity, as well as creating stronger institutional quality. I don't know if you want me to go into that in more detail now, but it requires a little bit of understanding of token, sorry, transaction cost economics and institutional economics.
B
Sure, go ahead.
D
Maybe I'll let the other. Oh, yeah, okay. So I guess, like, it's when you think about, like, what a blockchain is actually selling, right? It's not really selling, just block space, right? We have all of these mechanisms in place to effectively create what's called credible commitments. Credible commitments is like this notion behind an institution and what makes an institution pretty high quality. So for example, a state can be very powerful, but he who giveth can taketh away, right? So what actually matters in terms of an institution is its ability to be able to hold its promises, right? Hold in such way. So these promises are effectively called credible commitments. And there's two types, right? There's motivational commitments. This is like, trust me, bro, I've got it. Don't worry about it. I'll honor my agreements. And then there's imperative commitments, which are a lot stronger. And we started to see an example of this is like in medieval times, right? A king might have some kind of deal with another king and leave their firstborn son with that other king as kind of collateral. Williamson basically talks about the sort of ideal version of this, which is the ugly princess, right? It's a lot of high value to the father, maybe not so much value to the other king, but if the other king does not honor his agreement, then maybe there's a beheading involved, right? So this is an example of an imperative commitment. So in blockchains, we do this with cryptography, we do this with game theory, mechanism design, and even decentralization. These are all things that basically make the commitments that are made on chain much, much stronger. Now the other side of this is like a lot of people think of a transaction when it happens on chain is like. And that's basically the only thing that's happening on a transaction, right? But in transaction cost economics, there's like seven steps that are involved in a transaction. You can view this as a life cycle or a process or even a supply chain. And the blockchain is really only doing the settlement and some of the other ones, right? So think about it like when you do a transaction, you actually have to discover your counterparty. You have to communicate with them. You then have to, you know, negotiate or come into contract with them. And there's a few Things that happen after the fact as well. Now, the problem is pretty much the reason why crypto has kind of a bad reputation these days is because a lot of people are making these motivational commitments outside of the chain itself, right? Whether it's a centralized exchange that goes bad or a scam and so on. And each one of these steps effectively has a sort of hazard quality to it, right? You have basically two people who can prevent you from doing a transaction, any of these steps, right? One is your counterparty, right? They might have some self interest and try to undermine the transaction or, you know, scam you in some sense. But then there's also the class of actors who are not directly involved in the transaction. So this might be, you know, you know, a hacker, this might be the states, it might be a competitor, and so on. And their capacity to influence the transaction that you're making is really determined by, let's say, three things, right? Its capacity for coercion, both you and your counterparty, its impunity, like what its estimate of its recourse is, as well as the information of that transaction, right? And that information is really important because we can't really modify this predator's or this other actor's ability to. We can't change the coercion really easily unless maybe we get violent in some sense. We can't really do much about impunity unless we're relying on a very strong legal system as an example. But we can control information within these systems, and if we can reduce that information down to zero, then the capacity for influencing a transaction also drops. And so this is kind of where privacy comes into play, right? If you can secure privacy at each of these steps in the transaction and provide not only privacy but also integrity to those steps in the transaction, you start to understand why we cared about decentralized file storage systems. For example, the Bybit hack could have maybe been prevented by having a higher sort of integrity over the content hash, over accessing its front end, for example, rather than being served through the motivational commitment of running a server on Amazon or wherever it was. So that's what I really care about, because as you do this, you reduce the hazards that are involved in any kind of contracting, which then allows or unblocks market behavior. And this means, like institutions can come on. It means that people who are not transacting because they got hurt by some other system or actor can come on. You can quantify this, right? You could even look at blockchain forensics as a how many billion dollar industry it Is right. But they are looking at this information, and that's preventing a lot of other market activity from happening on chain. So that's a nutshell of why I
B
care about these things. What comes to mind is almost. I know it's like a funny analogy, but when there's a party and let's say it's a more formal, ish party, and the music starts and the dance floor is empty, it's like, who will go on the dance floor first? And it's sort of like that when you have these public transactions. Right. That everybody can see, everybody can watch it, like, just exposes you in different ways. So that makes a lot of sense. Mer, do you want to explain what your interest is in privacy and why you think this is the moment it's gaining traction?
C
Sure.
A
So I have two main interests in privacy in crypto, specifically. Obviously, there's privacy and trust outside of crypto, but I'll reduce the scope. One is in the frame of zcash, and there, what I'm interested in is the original ethos and idea of Bitcoin, which is to say an alternative monetary currency that has a shot at being a safe haven or being able to separate money from the state in some capacity for some segment of the market. Right. I think that's primarily why a lot of people, at least back in the day, got into crypto and why it's still clearly the number one asset in crypto by several orders of magnitude. And there's a lot of problems. There's a lot of unfinished sort of paths that bitcoin sort of left, in my view. Right. So the way I tell the story is generally something like, first we had to prove that cryptographic money could work and that was Bitcoin, and had to gain legitimacy and traction, and we had to just prove out the concept. And then Vitala came and said, well, actually, it's sort of weird that this isn't programmable. And then Ethereum came, and then perhaps Solana came and said, this also has to be scalable. But then the concept of privacy, which ironically is implicitly assumed when you're talking about Bitcoin to anybody outside of the industry. Right. So, for example, if you ever watch a TV show, something like a blacklist, and the context in which bitcoin comes around is generally some criminal is asking another person for ransom. And every time I watch something like that, I'm like, what are you doing? That is way more traceable than cash. It makes absolutely no sense. And so it's this deep sort of belief that you think, oh, it's cryptographic money, obviously it must be private, right? And so it's not even really understood that actually, no, it is traceable Digital gold as the official Bitcoin account, which I'm not even sure who owns that on Twitter, literally says in their bio, right? And there's all sorts of supporting anecdotes here. So, for example, when Hal Finney was alive, he would tweet about wanting to add anonymity to Bitcoin. And you can see the early Bitcoin forums where Satoshi himself says something like, if this was possible, referring to using zk, this would make for a better, more efficient implementation of Bitcoin. But I don't know how to solve the double spend problem. And naturally that was because ZK was super early in its. I mean, zcash didn't exist. There was no production deployment of ZK snarks at that time. But now we have the tech, right? And so now it feels like, especially at a time where all sorts of liberties and let's say things that you took for granted are being attacked, whether it's age verification, whether it's AI being able to make sense of unstructured data, or whether it's the institutionalization of crypto, there remains that last branch, which is. Or the last frontier, in my view, which is not only in terms of market cap and price, but also in terms of impact and clear market gap, right? Which is adding privacy to this Internet currency. The second part is, let's say, slightly more boring, but it is sort of a prerequisite for being able to do finance at scale, right? Nobody really thinks of privacy as a scaling technology, but it actually is a scaling technology because without it, a very large group of actors physically cannot come on chain, right? So what's been most ironic in this past cycle since we've had Trump as president, and perhaps there's been some regulatory clarity, is that while your average user might not care too much, perhaps due to a lack of education or some other thing, the institutions that are coming on chain absolutely care for OPSEC reasons, regulatory reasons, legal reasons, all sorts of other reasons, right? Like if they physically cannot come on chain in a meaningful capacity beyond some newspaper headline for a very basic poc, it's very hard for them to actually move a significant portion of their business when you can see, well, here's all the people who have this token. Here are all the loan parameters and it. So within the context of privacy security, that's a complete non starter for any serious financial institution. And so on the other side of this, where I'm building on Solana with Helios, we're building a ZK privacy protocol to help alleviate a lot of those gaps. So basically to answer your question, twofold, one is the currency and then two is the scaling of finance.
B
I love it. So interesting. All right, Joe, what about you? Why are you interested in privacy and why do you think it's gaining momentum now?
C
Yeah, I think maybe again two parts. The first part, I think just following on from what Mert said, we got into this with Aztec for exactly that reason of trying to bring institutions on chain. Aztec was actually created 2017, 2018 to try and put bank grade loans on Ethereum. And we kind of ran into that scaling problem of institutions can't move onto these chains without at least the level of privacy that they get from intermediaries that they, they transact with in, in Web2. And so we kind of were trying to build these, these loan origination products and loan trading products and we, we realized that Ethereum as it stood was not like kind of the right tool for the job. And we had to go down a many year rabbit hole to, to build out a lot of the underlying zero knowledge proof technology to make that possible, which has culminated in Aztec, which is a layer two on Ethereum. And I agree with a lot of what's been said previously. Like now having privacy on these layers means you can build much stronger commitments about who you are, whether that's in the real world, tying into kind of like existing trust anchors or kind of just putting information that you don't want to be broadcast publicly inside a transaction and getting a blockchain to attest to it, which has been our mission for the last kind of eight years or so. So I think that that side of things just excites me, seeing blockchains reach more into the real world with this, with this new kind of capability. And I think that's why a lot of traction is happening at the moment, because the tech has kind of met use cases at a really interesting kind of intersection. The second kind of reason that I'm interested is just about thinking about impact on the world and where the world's going to be. And people talk a lot about leveling the playing field or financial playing field. And if you look at the current public blockchains, I just think we have a moral obligation to not let people use those because it's a worse form of money than most people on this podcast deal with in their daily lives. And so we are Going to onboard lots and lots of people to these new layers. I think we have an obligation to at least give people the level of privacy we have in our bank accounts. And I think we can do a lot better than that with kind of ZKPS and other tools. So those two kind of things kind of are a bit yin and yang, but they keep me motivated to kind of work on this. And I think the kind of end human at the end of the day has a right to this privacy. And also it's very cool to see what we can do now with institutions on chain because we have privacy.
B
All right, so in a moment, we're going to talk a little bit more about who benefits from privacy on chain. But first we'll take a quick word from the sponsors who make the show possible. If you hold crypto on your phone, your biggest vulnerability isn't your wallet, it's your carrier. AT&T Verizon and T Mobile have been breached again and again, and SIM swaps are still one of the easiest ways for attackers to drain accounts. That's where Kape comes in. America's privacy first mobile carrier, same premium service, but Kape rotates the identifier on Your Sim every 24 hours, deletes your call and text metadata after a day, and protects against SIM swaps with a 24 word recovery phrase that only you control. You also get two middle to end encrypted secondary numbers for banking and signups. So you stop handing your real number to every app that asks go to Cape co unchained and use code unchained for 33% off your first six months. Back to my conversation with Joe, Jared and Mert. So let's talk about, like, different constituencies who would benefit from privacy on chain. Like, you know, what are some of the reasons that people would want this? And like, who do you feel would benefit most? And any one of you can talk,
C
maybe just to start. I think it's helpful to lay out the different types of privacy on chain because there are two very clear camps and I think maybe this call is more in one camp, but there's a lot of people trying to get privacy on chain through intermediaries, which is kind of replicating what we had in Web two, which is kind of you have a permission blockchain or a blockchain where not everyone is a node. So you get some kind of privacy because there's a lack of global consensus. And to me, that's kind of not a very good form of privacy. The very interesting form of privacy is Privacy through cryptography. And so I think when thinking about who benefits from that, it's important to look at the different types, because some types of privacy are kind of just institutions trying to fit their way into kind of a crypto world by replicating what they have. But that's not that that interesting because I don't think it breaks down the barriers and it doesn't let us live up to the promise of this technology. So, yeah, I'm much more interested in the cryptographic type of privacy. But maybe just to say that, to start,
A
I would say yeah, to answer your question of who would benefit. So the obvious answer is everybody. And the way to frame that is to think of privacy as having an option, right? So I believe the very first line of the Cypherpunk manifesto by Eric Hughes is that privacy is not secrecy, rather it is the ability to selectively disclose oneself. And the frame to think about here is something like, your thoughts by default are private, and then you can choose to publish your thoughts on, through secure messaging, through social media, through writing a book, whatever it might be. Same with your photos on Instagram, same with your files. Right? You always, in most things in life, you have a choice in what you publish publicly versus privately versus in crypto. Today you physically do not have that choice, depending obviously on which system you use. But for example, on Bitcoin, you don't actually have that choice. And so there is nothing iron besides ironing out some technical details, of course, because the tech does need to improve somewhat from here, and I believe it certainly will. But besides that, there is basically no benefit to be gained by not having the option. Right? So it's something that must be built
D
in
A
similar to the structural integrity of a bridge, so to speak, that is taken for granted, but that you only notice when it's not there.
C
Right.
A
And so basically the answer, in my view, the only correct answer, is that everybody.
B
I love it, Jared.
D
I mean, I ducked. Don't have much more to add other than everybody.
C
Of course.
D
It's a little hard to do that. I mean, there's some spicier takes in, in there. Of course, you know, I'm certainly concerned of, you know, people who are under, you know, tyrannical regimes, for example, you know, their ability to, to transact economically, I, I feel is a right, you know, a lot of civil liberties sort of arguments come up here, right? To associate, associate freedom of speech and so on. So that's definitely one case, I think, just to kind of be a little bit spicy, perhaps another way to say Everybody as well is when you start to understand costs of compliance around KYC and AML or more broadly like follow the money methods. Right. And I think that when we start implementing these kind of tools, it's going to require smarter approaches to those regulatory challenges. But the reason why I say that is because those compliance costs, they don't get paid by like a bank. That gets paid down to the individuals. Right. Like the general public. And the main sort of perpetrators or people who benefit from avoiding KYC are typically the sort of political and financial elites. Right. And they don't need the privacy in the same way they do because they're effectively writing the rules. So there's a power issue here. And this kind of goes back to the sort of cypherpunk motto, privacy for the weak and transparency for the powerful. So I think that our public institutions should be public and everyone else should be able to selectively reveal themselves.
B
Yeah, yeah, that makes a lot of sense. It feels like anybody who's in some kind of situation where they cannot enact their own agency, like they, you know, have some sort of restriction on what they want to do with their life, that they would benefit from privacy. And, you know, there's so many examples throughout history of people being in that situation. And, you know, you could imagine that being able to have your own private money would be super helpful. All right, so now let's get into the nitty gritty part about what's actually happening on Chain, which is, I'm sure going to be a little bit contentious. I'd love to hear you guys argue a little bit. But so let's actually, so let's break this down. Let's talk about all the different ways privacy can come on Chain. I'm going to just list a few based on, you know, how Ethereum kind of described its privacy roadmap, but reads and writes, proving identities, experience, like the user experience, and then wallets, things like that. I don't know if there's anything else he would want to mention, but feel free to do so. But just generally, you know, talk about, like, the different methods or applications you're seeing for privacy, you know, that are coming on chain or that are being rolled out soon that you're most excited about.
C
I think a lot of the fundamental kind of tech behind privacy is obviously zero knowledge proofs. There are new technologies coming out that, you know, may, may kind of improve on that baseline. But the most exciting thing that, that I feel that all of these technologies are trying to, to do, and especially in the Ethereum roadmap is you have a program and you prove that program locally on your device and as a result of that program being verified successfully, some encrypted state is updated somewhere. And you know, you can take the basic kind of zcash program which is like UTXO in utxos in utxo is out and you know, you verify that no money's not been double spent and you can kind of extend that in lots of different ways to make things much more complicated. But the basic way that this is kind of happening at the moment is two things have changed that have made this possible. One is we can prove a lot more in a program. So there's very exciting use cases that can now be built that just weren't possible before because they couldn't be proven on consumer devices. And the second is the capacity to kind of do state reads and state rights is growing just based on Moore's Law. Like the amount of kind of scaling we have in, in these systems and the different data structures that exist to store private state, there's a lot, lot more technology there. So I think when whether you're talking about on Ethereum or on zcash or, or any of these layers, the, the I think the basic tenant is still the same. It's, there's a program that's proven usually in, in a zero knowledge proof and then some state is written as a result. And yeah, I think that the possibilities that enables are pretty vast. Where it gets kind of interesting is how do these things talk to each other? Is there a universal language for privacy? Can zcash talk to Ethereum? Can Privacy network on Solana talk to one on Ethereum? And there's some tools that have been developed there to make that easier. Kind of like shared languages, shared libraries, but that's kind of where we are today. So I think the Ethereum roadmap is a huge step in the right direction because it's trying to create a lot more of those standards and maybe it's a force that helps actually get people to adopt them.
B
Jared or mert, the privacy technologies or applications you're excited about.
A
Sure, I'll talk my own book. Well, I'm pretty excited about obviously timely topic of formal verification applied to ZK circuits. 2 so one, let's reduce scope to talk only about Zcash. For example, one trade off, historically speaking in privacy has been in the case of a monetary policy asset, it's been about the supply of that asset.
C
Right?
A
So for example, if you have perfect privacy, then you technically have to make some trade offs in terms of the auditability of that supply. Right. And we saw this when there was a counterfeit vulnerability discovered a few months ago at this point in zcash's orchard pool, and a lot of people weren't aware of this, that if you are using ZK to encrypt literally everything, then there has to be some trade off in observability of, for example, who holds what and the summation of those to add up to the total supply. And so you'll have things like turnstiles that limit the total supply or ensure the total integrity of the supply, but you'll still have some trade offs, for example, if one of the pools is insolvent. And I think a lot of this comes from I wrote a piece on this called Crypto is Entering the Space Age. But a lot of this comes from crypto oriented code being written in a very floppy sort of Facebook ish way, where, for example, in centralized systems, if you write code, and it's a given that all software engineers will write bugs or cause bugs they didn't intend to, you can generally speaking just release a patch right away and everything is fine again.
C
Right.
A
But in the case of crypto, when you were securing billions in assets, it's more akin to like a pacemaker or a spaceship in that, first of all, you can't really roll it back in most cases. And if it blows up, then there's a catastrophic event of billions of dollars lost. Right. And so, and obviously a lot of this is due to the new cyber capabilities of AI in being able to really break security of many things that we took for granted before. But the flip side of that, of course, is that AI also helps one perform formal verification easier and more scalably without requiring many months and years to actually be able to translate the spec into code and then mathematically verify that it does everything you thought it would do. And so what I'm most excited about in the case of ZK and privacy specifically is the formal verification of the ZK circuits, such that this trade off that we always treat it as some fundamental thing, it'll always still be there to be clear, but the risk will be reduced by orders of magnitude.
C
Right.
A
As you get the ZK circuits simpler in what they do and what they claim to do, and you have all these machines literally writing out theorems and formally verifying the actual properties of it and ensuring integrity, then basically I believe that you're going to get a 10x improvement in the risk reduction that is required for People to actually feel comfortable encrypting their money, so to speak. So that's what I'm most interested in these days.
C
I would just second that. I think just especially with AI and the rate of progress, people see kind of, I guess the negative externalities here where there's a crypto hack or crypto bug, but for a system that's fixed and the code is not changing, and with an ever advancing kind of level of AI intelligence, the capacity to find all the bugs in that system is getting much, much better. Which means that we can kind of pull from the future a state of security that we kind of could only dream of a few years ago. And I think whether that's fuzzing or more verification or just AI audits, the kind of security of these systems is getting much, much, much more secure, even though bugs are being discovered in that process. But it's much better that that happens today than kind of in, in a few years time. So I think I'm just excited that the hardening of the technology is getting to a point where it can actually power the world's financial rails because of the advancements.
B
Jared, do you want to name some of the either technologies or apps you're most excited about?
D
Yeah, I mean, I think I'm still concerned, I'm still living in the past, right? I'm still concerned about the fallout after tornado cash, right? Like if you go to like mevwatch.info you know, it's, we're having, you know, block relays self censoring at like 43.7% as of today, right. That's a huge threat to everything that happens on chain, right? Like if the, if the blockchain is not able to maintain its integrity, then it basically loses all value, right? And so like you can kind of break. So just accessing these networks is important, right? And so this is like where anonymous communication protocols come into play. And really we need to do two things here, right? We need to protect users who want to transact with the network. We also need to protect people, the validators or miners, people who are actually securing the nodes that are securing the network. And that's not quite a trivial thing to do, right? Like what I see a lot of is people think you can just sort of slap Tor or maybe a mixnet onto it and you know, you're done. The thing is that doesn't really work. That might work for users, but it doesn't really work for validators and miners. And the reason for that is because of the nature of the traffic. Say, like when you're participating in consensus, what you're actually doing is creating this sort of deterministic wall of traffic, right? And it's hitting on a regular heartbeat, right? Everyone's basically communicating every time there's a new block being produced or proposed, and that's a huge challenge. So in lupic style mixnets, they effectively get their anonymity delays, you can say, and if you start getting so many people do like so many nodes doing this, you actually start blowing out those delays. So you can't actually progress the chain if you know you need to have a block coming out every 30 seconds or whatever. Right. And the same thing is similar with onion routing, right? Like this deterministic wall of traffic can be identified really easily. So we've had to work at logos on effectively a hybrid between a mixed net and flooding routing sort of network. It's a bit weird, right? But what's great about it is that we can guarantee, you know, a certain amount of like, basically everyone who's participating will get the messages. You know, they're doing mixnet, like pass the parcel of the envelopes around. And we're treating that as a form of routing within it. But we can guarantee that we can get the block proposal unlinked. And under an active adversary threat model, we can kind of raise the cost to about seven years to try and figure out who actually did that, which is plenty of time for you to take your bags and put it into another account. Right? And that's what I'm really excited about because that allows us to really strengthen these systems and maintain their autonomy.
B
All right, so let's actually now talk a little bit more about zcash. Like MER kind of started this, but I have a few questions about this. So first of all, this is a coin that is focused on being either private digital coals or some form of currency, however you want to look at it. And yet I am not really sure how it achieves either of those places in the world. Bitcoin is claiming the digital gold. I'm not sure how we see a transition from Bitcoin having that spot to zcash having it. And then Bitcoin's original purpose, or whatever you want to call it based on the white paper, was peer to peer electronic cash system. So I'm not sure if zcash is going for that. But I'm just wondering if you guys see a way for it to achieve either of those routes or. Or something completely different.
A
Well, certainly I'll kick it off but so, well, so let's look at the facts. Right? So you actually, I think the first question you asked a few questions ago was what kicked off this sudden interest in privacy, so to speak. And certainly Zcash going from the top 100 to top 10, I think played a quite a large role in that because again, it is crypto attention, liquidity equals, you know, price action, which then leads to opportunities and more people sort of trying to use that attention. But also it helps teams who were always kind of sort of doing that to begin with. And so that's why I call it the last PvE. It's obviously a meme, but it is one of the things left in finance that is player versus environment, so to speak, rather than player versus player. Right. Because if I have privacy and Laura, you have privacy, that's good for both of us, and we don't necessarily have to cannibalize each other against that. Right. And so that's sort of how I would say even how we ended up on this podcast today. I'm not sure if we would have if zcash hadn't sort of really gotten attention back to the sector starting last year. So in terms of whether. So you mentioned, well, can it be bitcoin? Can it be digital gold? Can it be a currency? So first of all, I don't think there's room, I don't think it's a winner takes all. And there's all sorts of anecdotes I might give for this from traditional analogies from, for example, there never just being one store of value in the world to never one market being 100% dominated by any single player. Right? And so there will always be certain people who like the idea of Bitcoin, so to speak, but really require that additional privacy. So like in zcash's case, the privacy isn't privacy for its own sake, it's to enable a better monetary property for that asset.
C
Right.
A
It's sort of a. For example, one. One thing you might think of is fungibility, right? In the digital realm, if a coin has a history, for example, maybe I'll refer to the Canadian trucker protests. If a coin has history and you can see its providence, then there is a case in which you will not be allowed to use that coin because of its history. And so you actually sacrifice somewhat on the true fungibility of that asset. Whereas cash, for example, is devoid of all information. If I give you a five dollar bill, you don't see anything about where that cash bill has been in the past. There's, of course, other parts of this. Right. So zcash isn't just about the privacy, but sort of the holistic asset. And so one thing people might have missed in the Ironwood upgrade is that it is now quantum recoverable. Right. So you probably heard at some point about all sorts of panic about Bitcoin's quantum readiness. Well, zcash is actually quantum recoverable today, and then it'll be quantum proof towards the end of autumn.
C
Right.
A
And so that's another thing that's kind of checked off the list because a store of value fundamentally requires one to have a low entropy channel, so to speak. And entropy is defined as surprise, meaning you don't want to be surprised, you want to be able to just store it somewhere. And that's sort of that.
C
Right.
A
And then of course, there's other lesser known things. For example, zcash is actually scaling in terms of. Compared to Bitcoin, right. It's going from 75 second block times to 20 second block times. The TPS target is a few thousand TPS, which is obviously not the case for Bitcoin. I'm not sure. It's not on me. It's for the market to decide in terms of, you know, who buys it or who treats it as what. But for a specific set of users, me included, it feels to me it. It solves my needs better than Bitcoin would. That is not to say I don't hold Bitcoin, of course, but that does mean that it is a clear, viable alternative for some sets of uses that I care about personally.
B
And I'm curious to hear Jared's and Joe's take on, you know, what you think the trajectory of zcash is. But I also just want to ask in the same breath whether or not that bug that Mert talked about earlier, you know, in the orchard pool, if that gave you any pause or. Or what. And just for the audience, you know, to be clear, that was the one where an attacker could have created an unlimited number of counterfeit tokens. Most likely they did not, you know, just from the way the market activity has looked. But that bug was there for four years and nobody had detected it. So it's another fact that's a little alarming. But yeah, I'd be curious to hear Jared and Joe's take on, you know, where you think zcash could go.
C
I'm happy to start, I think.
B
Yeah.
C
Two things I agree with the kind of more of the digital gold thesis. I think, you know, wealth and net worth is is kind of something that a lot of people are just sensitive about. Like people wouldn't say on this call like what they're worth and, and like privacy and net worth have always been kind of like fairly hand in hand. So I do think that that is a kind of this, a product market fit there. I also think if you think about zcash as a payment instrument, there's UX friction there. You know, every time, you know, in the real world someone wants to pay with something, there's a spread against their local currency. And so it's not the best last mile payment instrument. And so yeah, I think it just, it makes more natural sense for it to be digital gold and other technologies, you know, private stable coins that are actually decentralized on, on different chains are probably a better payment instrument for, for that. I also think that you know, as soon as you start thinking about payment instruments, you start talking about payment volumes and payment fees rather than, you know, the, the asset as something that you want to buy and hold. And so the valuation metrics get a little bit, a little bit strange here. So I'm definitely more in the digital gold camp and kind of let, let other networks deal with privacy and privacy and kind of like crypto assets in the real world. And, and yeah, that's kind of my take on the, on the bug. I think it's a little surprising that kind of it, it was like that undiscovered for, for that long. But I, I think it's more just a testament to, and how far like AI audits have come and the tools we have today. So yeah, I think it's the same point as before where you know, things that we took for granted as being secure, not just on crypto Rails are definitely not secure under the current threat models. And it's actually what makes me more kind of more bullish on the digital gold thesis because if you, you know, if you keep your wealth in a broker account and these other kind of Web two things. We haven't had an AI led attack vector on Web two infrastructure that's kind of been systemic yet. But I do think that that will happen at some point. And the crypto rails have already been hardened by that because they're kind of the ones that are easiest to attack first. So I think this is actually going to be a positive thing in the long run as we see the effects of kind of more, more adversarial environments play out.
D
Yeah, I mean I'm not too, firstly, like, I mean I have a sort of libertarian streak to Me, right. So I really like the idea of sound money. And of course, fungibility to me is a very important property and that's kind of why I use that cash shielded transactions, so on, on the sort of bug, I mean, like, yeah, I mean, it's unfortunate, it's a little bit of an eyebrow, eyebrow raise. But at the same time, like, you have to realize that most cryptographers would warn against using any kind of cryptography that's new for like, you know, five or even 10 years, perhaps even more. And those who are daring enough to implement that and to, to take it to market, you know, should really deserve the sort of praise that they get. And you know, these systems do run in an adversarial environment. They are antifragile by nature and they get fixed as a result of this. So I'm just glad it's fixed.
B
All right, so to wrap up this little zcash section, I do have to ask Merc because we just had a big upgrade in zcash, Ironwood, which he alluded to earlier. But Merc, why don't you explain, you know, what happened in this upgrade, why you're excited about it.
D
Sure.
A
So as we just discussed, there was a bug or a vulnerability found in specifically the Orchard pool. So zcash has several shielded pools and Ironwood was the latest one up until Iron or Orchard was the latest one up until Ironwood. And Taylor from Shielded Labs, who by the way is a very advanced high domain knowledge person, it wasn't sort of just vibe coded. He had access to some pretty lit frontier AI tools and, and found, disclosed and patched with the coordination of other teams, of course, this, this, this bug. And obviously so some people have the same reservation lore that you have, which is like, okay, well could they have done anything with that? And while all the signs and heuristics point towards no, there wasn't. So for example, in terms of the shielded pool activity going up over time rather than going down, the price action, the fact that it was announced that there would be a fix and so the hacker would in theory would want to get out before sort of, they lost that window. You can point to all sorts of these things as heuristics, but fundamentally it's in, it's crypto, so you have to be able to verify it. And so to do that, a new shielded pool called Ironwood was released. And it's similar to Orchard, except it also has quantum recoverability. And by the way, a few days after this was found, the old Orchard pool and Ironwood were both formally verified on three separate occasions, actually, and audited in all sorts of different ways. And so what the formerly. And you can see Sean Bow on Twitter, he has a few posts on where he goes into detail, because I'm sure I'll butcher the technicalities here, but basically the claim that there can be no undetectable counterfeiting bugs going forward has been formally verified. Right. Of course, there could be other types of bugs, just as in any software system, but the specific set of bugs has been rendered mathematically not feasible. Like that's. Anyways, you can sort of look at that blog post to confirm. But anyway, so how do you confirm the supply actually is like, how do you confirm that there was no new notes in Orchard pool specifically? Right. So you said, for example, and I think a lot of people have this confusion where people think it's just an unlimited amount of Zcash, but it's actually just an unlimited amount of Zcash in the Orchard pool, which is about 28% of the supply.
C
Right.
A
And so to confirm that, what you have to do is you have to migrate from that pool to so the Orchard pool to the Ironwood pool. And if there was an attack, what would happen is this thing called a turnstile would trigger. And all a turnstile does is it ensures that what goes out can't be more than what went in. Right, because you know what went in and you know what's going out in terms of aggregate amounts. And so imagine, for example, the pool orchard had a billion dollars worth in it. And imagine that 500 million has left it now. And then the turnstile triggers. Well then that 500 million remaining would be technically insolvent because you don't know who owns what notes in that pool.
C
Right.
A
And so the idea here is that as the funds migrate from Orchard to Ironwood, they would tend from a billion to 500 million to 5 million until basically it approaches zero. Now, of course, it'll never actually be zero because I'm sure some people have died and lost their keys or lost their devices or whatever. And so it'll be a probabilistic bound in terms of what supply is for sure. Certainly not counterfeit. And then what supply still might be insolvent. And so that already went live two days ago. There's no hiccups so far. They're trying to make the migration such that it has built in privacy when you migrate, such that you don't expose who owns what notes. And so the app teams are also working on that. But basically, so to Summarize. What you get with Ironwood is you get mathematical deterministic guarantees that no undetectable counterfeiting bugs like this one can exist in the future. You get a mechanism for verifying the supply wasn't in Orchard, it wasn't counterfeited. You get quantum recoverability. But then also there's a few other goodies smuggled in there about faster sync times and faster signing and just a general performance upgrade.
B
Great. Okay, so now let's switch to Ethereum because Ethereum has a really extensive privacy roadmap and it covers a number of different areas. You know, they're, they announced this big push as I mentioned and as I also mentioned earlier, there's a number of initiatives that, you know, range from, you know, everything including like R and D to UX ui. So it really covers the gamut. What about, you know, Ethereum's privacy roadmap? Like which segments of it are most exciting to you and which do you think will really move the needle?
C
I'm happy to start with this one, I think. Yeah, Ethereum's privacy roadmap is very good to see. I think there's also like a lot of ways to get privacy on Ethereum today that don't need this. So Aztec's obviously one of those and just general like verifying zero knowledge proofs work today on Ethereum. So I think it's important to just state that the things that are exciting to me are some of the things that zcash has already achieved. The kind of upgrades talk about like having a post quantum kind of proving system and just new state types that make existing privacy apps much easier to build. Aztec exists as the layer 2 because Ethereum isn't that easy to build privacy apps on. You have to put a roll up, you have to build all of these additional metrics and functionality to enable privacy in a few years. Once this roadmap is kind of fully built, the job of teams like Aztec gets a lot easier because there's kind of parts of Ethereum that just do things kind of for free. So I think it should see a lot more teams building in the space. You won't need to raise as much kind of money to bring privacy to Ethereum and you can kind of get started a lot quicker. My only kind of complaints about it are it's quite far out. And so we're dealing with privacy today ON Ethereum. Our v5 network went live last week and so it's kind of like there's a trade off between the shiny city on the Hill where everything could be perfect and what can you actually do today? And I think the only risk I see is that the battle is being fought today for cryptographic privacy on blockchains and there's a chance that the roadmap comes too late. The only type of privacy that is legally allowed is privacy through intermediaries and that obviously brings us on to tornado cash and other things. But yeah, my only concern with it is like it could be too late to actually show that there's meaningful demand for this privacy. And so I'd like to see more done like today on what's possible kind of on Ethereum and kind of embracing those privacy solutions that exist today.
B
But I mean you must also think that if it comes to fruition then in a way it's almost competitive with what you're doing and could siphon like TVL or whatever. Am I right?
C
Not really.
D
I think
C
the way to think about it is like there's a bunch of things in the EVM today that enable Aztec to exist and we're about to get even more, which means that we can build a, a better Aztec. I think Ethereum is at the protocol level, is building features into the network that enable people to build privacy applications and so it just makes our job easier. The network effect is still going to accrue to some application on Aztec that makes use of those. And the way to think about Aztec is just it's a very generic execution environment for writing private applications. And the privacy roadmap is not necessarily around that. It's about making the job of teams like us, teams like privacy pools easier so that we have more private applications. So I think that the two are kind of very compatible. The only place it's maybe kind of competing is like, you know, if ETH has native private transfers is probably better if those occur on Ethereum L1 than, than on Aztec. But we're more focused about, about kind of like real world use cases of privacy and like programmable money like dollars and, and, and kind of decentralized stable coins. So I think yeah, I don't see it as fully competitive.
B
Jared.
D
I agree. Actually like Ethereum's privacy roadmap, it is very ecosystem focused, right. And I think that's for the right play for them because they have such a dominant ecosys, you know, DAP developers, people building on Ethereum. So that's a huge part of their focus and I think that's probably the fastest way that they, they can achieve those kind of goals. As for the rest of the roadmap it's very ambitious, particularly for a system that's live, that's already got a lot of value. Right. It's kind of a, it's very challenging to retrofit an existing system with some of these technologies and have everything go really well. Having that said, like, you know, I've been around the Ethereum community for a very long time now and I've had to raise eyebrows a couple of times and it's a huge testament to that community that they have pulled off some of the things that they've pulled off, particularly a transition to Ethereum too. So if anyone can do it, they can definitely do is ambitious and I guess we'll see.
B
All right, so in the interest of time, even though I'm sure Mert would probably have some thoughts, we're going to talk about Canton, because I think that will take up the rest of the time. And this obviously is a chain that sort of came out of nowhere and there are private transactions on it, even private stablecoin transactions. And I wondered what you think about it and how do you consider it like a, a leader in the privacy space on chain or how do you think about what they're doing and how it relates to privacy?
A
I don't consider a leader in the privacy space any more than I would consider JP Morgan a leader in the privacy space. Which is to say that those guarantees in terms of privacy that you would get, which is just trusting your counterparty, are totally achievable without using crypto in the way that they've done it. And so I don't see any reason why I would want to expose myself to that. I like why I would want bank level guarantees. I would just use a bank.
C
Yeah, I second that is what I touched on earlier with privacy through intermediaries versus cryptographic privacy and the way that they achieve their private stable coins or private transactions is exactly the. Trust me, bro, there's a sequencer who has a reputation and you send all your transactions to that sequencer and you, you trust with a non credible commitment that they're not going to monetize that data or sell that data to anyone. And so whilst it kind of, you know, it jumps on the privacy band wagon, it's, it's basically a bunch of banks trying to adopt a different tech stack. And yeah, I think that it should come out in the wash for kind of at least these, these use cases that require strong credible commitments and actual privacy that's backed by kind of cryptographic guarantees.
B
So Jared, I'm assuming you Agree. So I want to switch up the question a little bit. Like, what do you think then happens. So we have a bunch of financial, financial institutions that are transacting on this chain. Like, what do you think happens to Canton? Do you think that eventually goes away and that they end up using ones that have actual, you know, technologically secure privacy or. Yeah. Where does this go? How does it play out?
D
Yeah, well, I mean, I don't have a crystal ball, right. So I think, you know, one way you could view that in a positive light is that you could get the sort of early market adoption or, you know, bringing these other sort of institutions this way and then hopefully they recognize the risks that are associated with that approach. And then once they have that sort of market, they can transition to want something that has much stronger imperative or credible commitments or imperative commitments, cryptographic commitments. So that's what I would hope to see from them. Whether that's the case or not is a little unclear. I think that you have to be thinking about this pretty early on for similar reasons. Why? I think that it's difficult to retrofit an existing chain with some of these technologies. It's possible, but if you're an engineer, you work on these things and you accumulate tech debt and people say something is temporary and then you find out that five years later this piece of software is still operating in the same way because business interests go in different directions at the same time. Like, I, I think that it's great to see more and more chains, more different approaches because it is still pretty early. Like, you know, crypto as an industry is still relatively quite small and we have a lot of blocked market activity to unlock. You know, if we want to see, you know, real world assets and, you know, more stablecoins, you know, more value, whatever, whatever your heart desires to be on chain. So more approaches, more surface area, bring more people in and then, you know, hopefully the use of these technologies make good judgments over time.
B
All right, well, this is all the time we have. There were a few other topics, but we'll have to touch upon them another time. Thank you guys so much for coming on Unchained and sharing your thoughts on privacy.
D
Thank you so much.
C
See you.
B
All right, thanks for. Thanks everyone for joining this live stream. We will catch you next week. Bye now. Nothing you hear on Unchained is investment advice. This show is for informational and entertainment purposes only and my guest and I may hold assets discussed on the show. For more disclosures, visit Unchained Crypto.com. Sa.
C
Sam.
Episode Title: Zcash, Ethereum, Aztec, Canton and More: Which Chain Will Win the Privacy Race?
Host: Laura Shin
Date: July 31, 2026
In this high-profile roundtable, Laura Shin gathers three pioneers in blockchain privacy technology: Joe Andrews (CEO, Aztec Labs), Jared Hope (Founder, Lagos), and Mert Mumtaz (CEO, Helios). The panel explores the rapidly evolving role of privacy on blockchains, evaluating both cryptographic and intermediary-driven approaches. They delve into specific projects like Zcash, Ethereum’s privacy roadmap, new advancements in formal verification and zero-knowledge proofs (ZKPs), and institutional adoption — culminating in a candid critique of the Canton chain’s approach. Listeners receive a comprehensive, sometimes provocative look at the privacy arms race shaping the future of Web3, institutional finance, and personal autonomy.
[02:04 – 18:06]
[19:26 – 24:15]
[25:40 – 36:33]
[36:33 – 46:52]
[51:45 – 57:38]
[57:38 – 62:04]
"Privacy is not secrecy, rather it is the ability to selectively disclose oneself."
– Mert Mumtaz, quoting the Cypherpunk Manifesto ([20:38])
"Privacy for the weak and transparency for the powerful."
– Jared Hope ([23:18])
On interoperability: “Can Zcash talk to Ethereum...Privacy network on Solana talk to one on Ethereum?” (Joe, [27:13])
On privacy’s business impact: “The blockchains...have a moral obligation to not let people use those because it’s a worse form of money than most people...deal with in their daily lives.” (Joe, [17:43])
| Segment | Speaker | Timestamp | |---------------------------------------|--------------|--------------| | Opening theme & privacy’s resurgence | Laura Shin | 01:17 | | Jared: Theory and Transaction Steps | Jared Hope | 03:08-09:21 | | Mert: Privacy as scaling, Zcash/BTC | Mert Mumtaz | 10:02-15:06 | | Joe: Institutions, trust, obligation | Joe Andrews | 15:15-18:06 | | Who benefits (everyone!) | All | 19:26-24:15 | | ZK tech, formal verification & AI | All | 25:40-36:33 | | Zcash’s “PvE”, bug, Ironwood upgrade | All | 36:33-51:45 | | Ethereum’s privacy roadmap | Joe, Jared | 51:45-57:38 | | Canton’s intermediary “privacy” | All | 57:38-62:04 |
This episode offers a sophisticated, multifaceted primer on the state and future of privacy in crypto, highlighting not only the technical arms race but the social, philosophical, and economic stakes at play.