私密 DeFi 即将到来:为什么隐私是 Ethereum 的下一个前沿 | Lean Ethereum
- Ethereum 基金会研究员 Thomas Thierry 表示,如果在 Hegotá 中落地,FOCIL(EIP-7805)、frame transactions(EIP-8141)、keyed nonces(EIP-8250)和 recent roots(EIP-8272)这4个 EIP 的组合,有望在 Ethereum 上实现原生、无需信任且抗审查的隐私交易。 短期隐私模型会隐藏交易背后的人,以及资产和余额,但金额与操作仍然公开:“你会看到一堆金额和一堆操作……但你无法知道背后是谁。” Thierry 表示,Hegotá 应以2027年落地为目标。
- 真正有差异化的命题是私密 DeFi,而不是私密转账。 现金等价只是入场券;Ethereum 的可编程性意味着“私密借贷、借款和兑换会变成令人兴奋且切实可行的东西”。这也是他与 Zcash 的区别:后者的内置资金池很强,但面向的是私密转账,而不是可组合的货币乐高。
- Frame transactions 可以消除当下隐私协议的一大瓶颈:受信任的中继者。 今天使用 Railgun、Privacy Pools 或 Tornado Cash,都需要通过第三方广播者;如果对方“离线,或者不喜欢你的交易”,结果就是“你实际上根本无法进行隐私交易”。Frame transactions 可以移除这一依赖,也能支持后量子安全签名等用途。
- FOCIL 是抗审查的最后一道防线,而机构端的价值主张也很清晰。 Ethereum 的大部分区块由2或3家构建者生产,它们可以让交易“几乎永远”无法确认;Thierry 表示,Tornado Cash 交易一度无法通过,延迟也非常严重。他举例说:“你不会希望竞争对手能找到2或3个人,说,嘿,你们能不能把我竞争对手的交易速度放慢10x?”
- 时间表方面,Glamsterdam 是一次扩容分叉,预计将 gas 从目前的6000万提升至“2亿或3亿”,可能在9月、10月或11月落地,大概率早于下一届 Devcon;Hegotá 的目标则是2027年。 通过 Kohaku 钱包 SDK 改善终端用户体验后,用户只需“勾一个选项……我想让这笔交易保持私密”,实验中已经实现了资产 shield 和原子兑换。
- 机构往往需要的是“保密性加可审计性”,而不是最大程度的匿名:对竞争对手和公众隐藏信息,同时选择性向审计师和监管机构披露。 Thierry 表示,Ethereum 的模式非常适合这一需求;他的策略是利用机构对隐私的需求,“同时推动个人权利向前发展”。
- 需要计入估值的风险在于,隐私会在最薄弱的环节失守,Thierry 点出了这些漏洞。 DeFi Dad 通过50–60个钱包、甚至可能超过100个钱包进行分散操作,“极其、极其、极其容易被追踪”;钱包可能暴露网络元数据,RPC 状态调用也会泄露交易意图,而钱包通常会记录数据,并可能将订单流发送给或出售给构建者。真正的私有共享状态——例如私有 Uniswap 或暗池——目前并不可行,因为密码学效率还不够高。Aztec 通过私有执行隐藏更多信息,但作为 L2,它需要的信任多于具备合适属性的 L1 隐私 dApp。
1. 隐私是“只增不减”监控的镜像,而 Ethereum 的第一个目标是隐藏交易背后的“谁”
- Thierry 的开场框架是:隐私正在“甚至超出加密行业的范围”恶化——“线上监控基本只增不减,如今借助 AI 也更容易实施”。现金有利于金融隐私,但“在这个时代不算特别方便”,因此最低门槛是数字现金;Ethereum 的吸引力则在于,在可编程货币乐高之上继续搭建私密借贷、借款和兑换。
- 被问及什么应该保持私密时,他的回答是绝对的——“一切:你是谁、你的余额、你的资产、你交互过的合约”——但实际落地的模型更窄:隐藏交易背后的人,以及资产和余额,同时保留金额与操作的可见性。一笔 Uniswap 兑换仍会被公开发布;“只是没人能知道是谁在做这件事。”
- 他指出的前提是用户规模。参与交易的人越多、金额越分散,匿名集就越大——“参与交易的人越多……你能观察网络、猜测谁在做什么的空间就越小。”
- 针对“隐私就是在隐藏坏事”的污名,他给出两个理由。其一是家庭类比——“你不会希望有人一直待在你家里”;其二是安全问题:“你希望全世界都知道你是 X 先生,持有价值1万亿美元的 ETH,而且你的地址就是这个吗?可能不希望。这看起来并不安全。” 他还补充说,“关你什么事”本身就是一个很有力的理由。
2. 多钱包“自救”行不通,置顶推文里的 EIP 组合才管用
- DeFi Dad 分享了自己的做法——50–60个钱包,“可能还不止”,甚至可能超过100个——Thierry 对此进行了纠正:“创建很多钱包不是保护隐私的好办法……任何老练的参与者都能追踪你发送到其他地址的 gas。” 即便通过交易所中转,一个完成 KYC 的交易所仍然知道他是谁。
- 真正的解决方案是 Thierry 置顶推文中的组合:在 Hegotá 中落地 FOCIL(EIP-7805)、frame transactions(EIP-8141)、keyed nonces(EIP-8250)和 recent roots(EIP-8272),这样“到明年,我们就能在 Ethereum 上获得原生、无需信任且抗审查的隐私交易”。Thierry 后来表示,Hegotá 应以2027年落地为目标,但具体范围尚未最终确定。
- Frame transactions 是隐私方案的核心支柱——“我把它们看作最后一种交易类型”,它提供了一种模块化方式,让用户自行编写交易,包括用后量子安全签名取代 ECDSA。更关键的是,它可以移除中继者或广播者:今天 Railgun、Privacy Pools 或 Tornado Cash 的用户必须通过第三方路由交易;如果对方“离线,或者不喜欢你的交易”,用户就无法进行隐私交易。Keyed nonces 和 recent roots 则是让整个流程运转起来的协议层组件。
3. FOCIL:中立性是 Ethereum 的护城河,异见者和机构都需要
- FOCIL,即 fork-choice enforced inclusion lists——“这个缩写有点牵强,但能用”——是 Thierry 倡导了约1年半的机制,要求构建者纳入由验证者集合监控的交易。没有 FOCIL,“2或3家大型构建者”就可能让一笔交易几乎永远无法确认;Thierry 表示,Tornado Cash 交易一度无法通过,延迟也非常严重。
- 对机构而言,威胁同样直接:构建者是“规模相对较小的公司”,竞争对手今天完全可能找到2或3家,要求它们把另一家竞争对手的交易速度放慢10x;Thierry 认为这并不难。FOCIL 把交易纳入从任意决策变成协议规则。
- DeFi Dad 的宏观判断是:在 VC 支持的新一代 L1 浪潮中,抗审查曾被“轻视”,但连续运行10年是“Ethereum 最终极的护城河”。将资产代币化的机构需要一个确定会持续存在、并能按可预期方式纳入交易的结算层。Thierry 的补充是:“网络本身无法被审查,也不会被阻断。”
4. 时间表与用户体验:Glamsterdam 预计在9月至11月落地,Hegotá 于2027年上线,用户只需勾选一个选项
- Glamsterdam “能让我们大幅扩容,远超很多人的想象”——将 gas 从目前的6000万提升至“2亿或3亿”。Thierry 估计它大概率会在下一届 Devcon 前落地,9月、10月或11月都是合理预期。至于 Hegotá,他表示2027年落地的可能性很高,或者说这就应该是目标,但提案仍在制定中。
- Ethereum 基金会正在通过 Kohaku 推进协议与钱包工作。Kohaku 是任何钱包都可以接入的钱包 SDK,目标是让协议、隐私应用和钱包共同提供端到端的私密流程;早期 devnet 已经在运行。理想的用户体验是:“我们可能还是得勾一个选项,说‘我想让这笔交易保持私密’,但理想情况下,这就是你要做的全部。” 实验已经实现了将交易 shield 起来,并原子兑换为 DAI 或其他代币。
5. 先别写入协议:让隐私应用竞争,关注 Aztec,并在后量子密码学上与 Zcash 汇合
- 将类似 Railgun 的资金池写入协议是可行的,但短期内大概率不会发生。写入协议意味着在 Ethereum 同时迁移至后量子密码学之际,锁定某一种特定密码学方案,几乎没有犯错空间。Thierry 也希望隐私 dApp 在不同设计、货币选项和 DeFi 应用之间展开竞争。未来可能会有一个主导方案被写入协议,但现在还太早。
- 目前划定的边界是:让应用自由发展,同时让来自任何应用的每笔隐私交易都获得“完整的协议保障”——完全无需信任且抗审查,只有协议本身和数千名验证者能够将其纳入区块。
- Aztec “更进一步,隐藏更多信息”——包括涉及的代码或合约,通过私有执行实现;Ethereum 未来可能也希望达到这一模式。但作为 L2,它需要的信任多于具备适当不可变性和无需信任属性的 L1 隐私 dApp。真正的私有共享状态——例如私有 Uniswap 或暗池——目前还没有人接近终局,因为密码学效率不足;今天要实现它,需要规模巨大的节点,而节点运营者必须被信任。
- 对于 Zcash,主持人提到,当前一轮由 KOL 推动的上涨,部分参与者可能并不在乎隐私;Thierry 则认为,其协议、团队和密码学“都非常强”,但 Ethereum 与 Zcash 处于光谱两端,同时也在一些问题上逐渐 converging。他听说 Zcash 可能会在现有的工作量证明系统上增加权益证明。Zcash 的内置资金池面向私密转账,而非 DeFi、可组合性或可编程货币乐高。双方共同推进的方向是后量子密码学,因为两个协议都需要完成迁移。
6. 隐私会在最薄弱的环节失守:元数据、钱包和受信任的第三方
- Thierry 坚持要补充的一点是:“隐私非常复杂,因为你必须堵住所有漏洞。” 使用隐私协议却不配合 Tor、VPN 或其他解决方案,可能会暴露网络元数据;钱包的 RPC 调用也可能泄露构建交易所需的状态,从而暴露用户意图。
- 如今的钱包通常会记录数据,并可能将订单流发送给或出售给构建者;WalletBeat 会分析钱包的属性。Kohaku 是 Ethereum 基金会推动的钱包 SDK,目标正是堵住这些泄漏点。Thierry 期待应用具备不可变性,避免可能削弱隐私的治理或升级路径,同时审查合规层:它如何判断用户不是坏人,以及需要用户提供多少数据。
- 另一个并行目标是尽量减少受信任的中间人,因为“如果你完全处于隐私状态,却必须经过那一个人,而那个人不喜欢你,你依然无法进行隐私交易。”
- 机构端的突破口是“保密性加可审计性”:对竞争对手和公众隐藏可见链上操作背后的人,同时自行选择向审计师和监管机构披露什么。“隐私对个人非常有益……我的看法是,利用机构对隐私的重视,同时推动个人权利向前发展。这是双向的。”
- 他最后呼吁参与 Ethereum 治理:公开电话会议已经开放,Forkcast 会追踪相关讨论。“分享你为什么认为隐私重要……通常会给我们带来非常有价值的反馈。”
完整逐字稿
Privacy generally is not doing great. Even beyond Ethereum and beyond crypto, I feel like we are slowly—not even slowly, but sometimes quite rapidly—losing this fundamental right. Online surveillance is basically up only, and now it is also much easier to do with AI.
For financial privacy, cash is great, but it is not super convenient in this day and age. So I think, for me, we at least need to get the equivalent of cash, but in a digital form. What is very exciting about Ethereum specifically—and maybe we will talk about this later—is that you can actually build on top of this digital primitive and do private DeFi. That goes beyond what you can do with simple transfers and also beyond what you can do with cash generally.
Private lending, borrowing, and swapping become something exciting and tangible. I think we need to get there.
This is part two in a Lean Ethereum series we are producing. This one will focus more on how Ethereum is leaning into privacy. We just did an episode with your colleague, also named Toma, all about making Ethereum quantum-safe, so hopefully this will be a great follow-up for folks on privacy.
We want to talk about what is currently broken with privacy, what needs to be fixed, and what privacy will actually look like for us as end users. We are going to talk a bit about why wallets are so important to privacy, and about the importance of privacy for further institutional adoption.
1. Why Ethereum?
On that note, why do not we talk first a bit about your background? I would love to learn more about why you chose to work on Ethereum.
I am very good. Thanks a lot for having me. I am very excited to be here.
I am Thomas. I work at the Ethereum Foundation. My background is very different. I did my PhD in computational neuroscience. At the time, I was working on the neural correlates of decision-making in humans, so quite different.
It was actually fascinating, and it turns out it is taking off these days as well, with BCI and what people are doing. That field is great, but I think I wanted to try something different. Academia was all I ever knew, and I was attracted to finding out what industry looked like, I guess.
I had been interested in crypto for a while, but when I finished my PhD, I said, “Okay, I am going to try it out and go full-time.” So I worked for Dune Analytics—I do not know if you know it—for about a year, and it was a really great team. It was at the beginning, so it was very startup-minded, and I really loved the pace, but I was missing the research aspect of it.
At the end of that year, I thought, “Okay, so either I go back to academia, or I actually do research in the space,” because I really liked it. That is when I joined the Ethereum Foundation.
For me, why Ethereum? It is an opportunity to work on a project that is both technically fascinating and mission-driven. That is very unique. Working on this is very exciting for me because it feels like we are living in this AI world now, and we have an opportunity to be as ambitious and technically driven in projects and cryptography that actually protect the end user and their privacy, and that are censorship-resistant.
For me, working on this is a perfect combination of being very passionate about the technical side of things and being fully committed to the actual mission of Ethereum and what it stands for.
2. What is broken with privacy today?
Before we get into how Ethereum solves privacy, let us set the table for us. What is actually broken in public blockchains today? Maybe just run through what actually needs to be fixed.
Privacy generally is not doing great. Even beyond Ethereum and beyond crypto, I feel like we are slowly—not even slowly, but sometimes quite rapidly—losing this fundamental right. Online surveillance is basically up only, and now it is also much easier to do with AI.
For financial privacy, cash is great, but it is not super convenient in this day and age. So I think, for me, we at least need to get the equivalent of cash, but in a digital form. What is very exciting about Ethereum specifically—and maybe we will talk about this later—is that you can actually build on top of this digital primitive and do private DeFi. You have private money legos, and that goes beyond what you can do with simple transfers and also beyond what you can do with cash generally.
Private lending, borrowing, and swapping become something exciting and tangible. I think we need to get there.
3. What should be private in DeFi?
What exactly do you think needs to become private for us as DeFi users? I think I am so in the trenches, having been in the space for about 10 years, that it has become normal to me that every transaction I make is trackable on-chain. You can basically see exactly what I am doing.
If you know my wallet, that is the whole thing here. Do you know a wallet because it has been labeled with an ENS handle? Are you a centralized exchange? Are you some analytics platform that is tagging certain wallets?
Most of us have gotten pretty accustomed to knowing that whatever we are doing on-chain, it is more than likely that someone out there—at least the centralized exchange that might be our partner for getting fiat in and out of the system—always knows what we are doing. So I guess I am trying to get to what the end state looks like. When we say that Ethereum is going to be able to achieve privacy for us as DeFi users, what does that actually mean?
If the question is what I think should be private, I would say everything: who you are, your balances, your assets, and the contracts you interact with—basically everything.
The question of what is possible today is a bit different, and we do have to go step by step. There are different models of privacy, and it is much more nuanced than just being private or not.
On Ethereum, I think what we are going for, at least in the short to midterm, is really protecting who you are. Who is behind the transaction is what we are really trying to hide. We are also trying to hide your assets and your balances.
Some things are public, though. The amounts, at the end of the day, will be public. If you are using Uniswap, the pools and the swaps will be published. It will just be impossible to know who was doing that.
You will have a bunch of amounts and a bunch of actions, and the actions will be visible, but you cannot tell who is behind them. That is where we want to go first. That is the near-term goal.
People have to be a bit careful in how they use private protocols, because we also need a lot of people to use them. That increases what we call the anonymity set. The more people you have transacting, with a bunch of different amounts and actions, the less you can observe the network and try to guess who is doing what.
That is the first step. The nice thing is that you can already do DeFi and things like that while completely breaking the link between who is behind it and what the action is, which I think is very nice.
4. The call for privacy runs deep in Ethereum
Thomas, is there a lot of pushback with the research and work that you do? It seems like privacy is still demonized. Outside of crypto, but especially within crypto, there seems to be this association that if you want to transact privately or if you want that privacy, you must be doing something wrong. It’s been a real challenge for me to explain to friends or colleagues why we need private transactions.
Thankfully, I think in the Ethereum community it’s not demonized. I’m rarely hearing people have a ton of pushback within the community.
But there is this general sense that privacy is to hide things that we don’t want people to know. I think the best answer I always have is that generally, you don’t want someone in your house at all times. You don’t want someone following you and knowing your every gesture and whatever you do privately in your home. I think it’s basically the same thing: some things are fine and can be public, and some things are better kept private.
At the end of the day, a really good argument for me that also speaks to a lot of people is security, especially when it comes to financial use cases and your assets. Do you want the world to know that you are Mr. X, that you hold a million million dollars in ETH, and that your address is this? Probably not. It doesn’t seem very safe.
I think that argument usually hits home for a lot of people. There is an actual security argument behind privacy, plus the “it’s none of your business” argument, which is also quite strong.
Yeah, I totally resonate with the idea that you wouldn’t want a random stranger in your home. What I’ve personally been forced into for UX, for my user experience, is creating so many wallets. There are some where I just don’t care if people see what I’m doing. I’m not doing anything nefarious, but if given the option, I’d rather people not know.
My way of doing this so far has been cumbersome. It’s been awful. You have to send ETH for gas to your wallet, and I probably have 50 to 60 wallets, maybe even more than that. I haven’t done a thorough accounting of it recently, but it could even be upwards of 100 wallets. Again, over time, you’ve just created wallets for certain reasons.
5. How Ethereum gets native private transactions by next year
So, I’m really hoping what you’re working on can change some of that. Personally, I want to get to a pinned tweet that you have. There’s a lot of— I would say it’s a bit of a word-salad tweet for me personally, and I don’t want to unpack everything technically in this, but there are some key components that I think are really important.
I’m just going to read this. You say, “If we ship FOCIL, which is EIP-7805; frame transactions, which is EIP-8141; keyed nonces, which is EIP-8250; and recent roots, EIP-8272, in Hegotá, we get native, trustless, censorship-resistant private transactions on Ethereum by next year.”
6. The importance of FOCIL for Ethereum
It’s that last sentence that I want to dive into a bit, because after just running through that mess of wallets, I see something like this and I’m like, “Wow, this is great.” It’s on the horizon; it’s not 5 years away. Can you speak at a high level, maybe less technically, about when this impact is coming for us and when we can expect it? Even if you have a good insight into when Hegotá might be coming, or when Glamsterdam might be coming as well.
Before that, I do want to note that creating many wallets is not a good way to protect your privacy. It’s very, very, very easily trackable. Any sophisticated actor will just track the gas you sent to other addresses to fund them and then track the other actions online. It is something a lot of people use, but it’s only marginally better.
Just to be clear, I never send gas between the wallets. I usually use an exchange as an intermediary, which I think is easier to obfuscate. Again, I don’t think it’s perfect, but—
Yeah, that makes sense. Once you get into it, it’s a bit annoying, but if you use that intermediary and they’ve done KYC, it’s easy for them, at least, to know who you are.
In any case, I think it’s way better than just having everything in one wallet that is very public and that everyone knows is associated with you. But it doesn’t give you the privacy guarantees we could get in the long term by, hopefully, next year.
I can get into this now. I’m not going to go into the technical details, but at a high level, FOCIL is also very close to my heart because I’m championing it, and I’ve been doing that for about a year and a half. It’s really about censorship resistance.
Right now, you have 2 or 3 big builders on Ethereum that are building most of the blocks. The problem is that if they don’t want your transaction to land on Ethereum and to be included, they can quite easily censor you. FOCIL is a mechanism that basically forces those builders to include the transactions that the whole set of validators monitors.
It’s a very efficient way to make sure that transactions submitted to the public mempool are forced into blocks. It’s really good for censorship resistance for general transactions, not just private ones. The goal is for private transactions to benefit from FOCIL and these strong guarantees.
Frame transactions are very important. They’re nice because they’re way more general than privacy. I think of them as the last transaction type. We have blobs and regular transactions; this is a modular way of coding your own transaction, which is very cool.
You can do things for security. Instead of ECDSA, you can use a post-quantum-secure signature, for example, so it’s very important for a lot of other things. For privacy, it’s really cool because it allows you to get rid of one of the bigger pain points in privacy, which is the use of trusted third parties called relayers or broadcasters.
When you use a private protocol on Ethereum today, like Railgun, Privacy Pools, or Tornado Cash, you have to send the transaction to get it to your address. You don’t want to do that because it obviously doxes you, so you have to send it to an actual third party that will do the transaction on your behalf. That’s terrible for censorship resistance as well, because if that trusted third party is offline or doesn’t like your transaction, you literally can’t transact privately. It’s a big bottleneck.
The modularity of frame transactions allows you to get rid of it. That gets rid of one of the bigger choke points in privacy protocols today. Keyed nonces and recent roots are basically things on top of frame transactions that make it all work. We don’t really need to worry about the technical details, but if you just shipped frame transactions, you would still have a couple of things you’d need to deal with at the protocol level, and keyed nonces and recent roots sort all of that out.
7. When will private DeFi be ready on Ethereum?
Thomas, I want to walk through some real-life examples related to the points you’re making here. FOCIL—remind us, what does that stand for, and why is it so important? You’ve been a champion of this. I’m always hearing our buddy Lex Node, or whatever name he’s going by, talk about why this is such an important upgrade to the Ethereum network.
If you can, give us more of a real-life example of how this is going to better improve Ethereum from a privacy standpoint.
For sure. I think FOCIL is larger than just privacy. It’s censorship resistance for all transactions. The goal is to have FOCIL guarantees for private transactions. FOCIL stands for fork-choice enforced inclusion lists. The acronym is a bit of a stretch, but it works.
The general, high-level view is that we don’t want outside parties to be able to just go into a room—you have 2 or 3 builders—and decide what transactions actually get into blocks. We don’t want them to choose arbitrarily which transaction gets included and gets to actually be part of the Ethereum chain or not.
Today, that’s basically what could happen. You can have 3 builders delay your transaction almost forever if they just got into a room and said, “Yeah, we don’t like this type of transaction.”
It matters for transactions that are actually linked to privacy. For example, at some point, Tornado Cash transactions were not getting through and were delayed very significantly.
It can happen from a regulatory perspective, but it can also happen for institutions. You don't want your competitor to be able to go to 2 or 3 guys and say, “Hey, can you slow down my competitor's transactions by 10x?” That could be quite easy because builders have a lot of influence today, but they're relatively small companies.
Being able to have them in control of what transactions go in or out of Ethereum is huge. It applies to users in different countries with different regulations, and to different companies and businesses that want to settle on something neutral and not heavily influenced by a few builders who get to decide whether their business is going to make it or not.
It's important for most people, I would say, because it allows you to get very strong guarantees that when you submit your transactions on the network, they will be included as long as they're valid. It's based on protocol rules, not just some random rules that people decide are arbitrary.
I think this goes back to making Ethereum truly censorship-resistant, meaning it is reliable. That benefit, feature, and value were disrespected and not fully understood for many years, as there were all these new L1s, next-generation L1s, and high-throughput L1s being brought to market and pumped up by VC investments.
What we've seen after 10 years of track record is that Ethereum hasn't gone down. It's been live continuously and has been this reliable world ledger. That remains the ultimate moat for Ethereum right now. Continually enhancing that uptime and reliability is huge.
The fact that institutions are looking into this space now and wanting to tokenize assets and bring them on-chain means they ultimately have to have a settlement layer that they know will be there tomorrow and that they know will have transactions predictably included. They can't be screwing around with some sort of funny business with a network.
To me, the work that you all have been doing is very, very important.
Thanks. I think it's exactly this. On the user end, it's more about the unstoppable aspect. It's great that I can't be stopped, and that's a very unique property. Even outside of crypto, I don't think many products or networks are censorship-resistant. It's kind of crazy; it's a really amazing property.
Of course, apps can do their own thing and filter things out, but the network itself is not censorable and is unstoppable. I think it's a pretty amazing feature. For institutions, we hear it a lot: they want to settle on something that doesn't involve counterparty risk, and that's why Ethereum is a really good place to do it.
I want to talk more about what institutions are thinking about this privacy movement within Ethereum. But before we get there, I'm also curious about the timing of all this. When is this rolling out? We mentioned that pinned tweet earlier. Hegotá sounds like it's going to be big for what you're doing.
If you were to attach a rough timeline to it, as best you can—I know it's always a moving target—and also, what does this look like for a user? Do they have to opt in? Is this going to feel invisible to users? Give us a sense of what that might feel like, too.
In terms of timelines, Glamsterdam is progressing quite well. It is a big fork, so there's a lot of work involved. Glamsterdam basically allows us to scale a ton—way more than people think. We're at 60 million gas today, and we're going to get to 200 or 300 million gas, so it's a major scaling upgrade.
It will probably happen before the next Devcon. I would say September, October, or November is a reasonable estimate. If it comes earlier, that's great, but we'll see. I think it's very likely, or at least it should be our goal, to ship Hegotá in 2027. We haven't exactly scoped it yet; we're at the end of the proposal phase, and now we have to debate what's going to be included. That also affects the timeline, but everyone is very conscious about shipping it as fast as possible and making it real in 2027. I think that's a reasonable estimate.
As for what it will feel like, what's very nice is that we have the protocol changes, which I'm mostly working on. The protocol is what I like doing and what I know, but we also have people working on Kohaku, which is a wallet SDK.
The nice thing is that we're integrating all our work. We want to make sure that by the time we actually ship the hard fork, we have privacy protocols that benefit from what we ship at the Ethereum protocol level, as well as wallets that completely integrate with them. We want to have the end-to-end private transaction flow completely figured out with Kohaku, privacy protocols, and the Ethereum protocol.
We're already working on devnets. It's early days because it's still a year away, but we're working on this full flow. I think invisible would be ideal. We'll probably still have to tick a box and say, “I want this transaction to be private,” but ideally that's all you have to do. Everything else will happen in the background.
We already have experiments that are pretty cool. You submit a transaction, shield it, and it's private; then it atomically swaps to get DAI or another token. We have this composable thing already working, and the goal is to make the UX really good now that we have an SDK and a wallet and can make sure that happens on that end.
8. Network-based privacy vs protocol-based vs wallet-based privacy
Okay. Thomas, I want to get some clarification on the difference between what I'm thinking of as network-based privacy, which I feel like you and the team—or Ethereum—are working toward, and privacy protocols like Railgun, which is one that comes to mind. I probably should define exactly what that means.
Then there's wallet-based privacy, which I believe you're referring to with Kohaku, if I'm saying that correctly. Can you help us understand the differences between these? What I'm trying to get to is: is there network-enforced or network-based privacy through Ethereum that we eventually get to that supersedes all of this?
Is something like Railgun or even Kohaku a short-term solution, or is this building toward the more complex solution that is privacy on Ethereum over the long term?
That's a really good question because it's also a debate in the community. Some people are advocating for completely enshrining a privacy pool—something like a Railgun, but perhaps with different properties—into the protocol, so that it's fully protocol-owned.
That's a viable way forward, but in the short term, it's probably not going to happen for a couple of reasons. The first is how risky it is. We're also moving to post-quantum cryptography, so we already have to migrate all our cryptography. Enshrining a privacy pool within the protocol means we have to commit to a particular kind of cryptography, and we can't make any mistakes.
Another argument of mine is that I like the fact that you can have different apps compete. I want privacy apps to compete and offer different designs, different money options, and different DeFi applications. I think it's healthy to have that competition.
Maybe in a few years we'll see that there's one dominant option for all use cases, and we end up enshrining it. But I think it's too early.
The approach we're taking now is to give private transactions that come from any privacy app or privacy protocol, like Railgun and others, the full guarantees that the protocol can give them. That means being fully trustless and fully censorship-resistant, with only the protocol and its thousands of validators able to include them.
The boundary is more about letting privacy apps flourish.
But every private transaction that comes out of one of them gets the full protocol guarantees, which I think is very important.
9. What is unique about Aztec’s approach to privacy on Ethereum?
So, for all the detail we've covered so far in terms of different approaches to privacy, one that we haven't covered is the approach that a team like Aztec is taking as a layer 2. Can you just dumb that down for us? What is interesting or unique about the approach that Aztec is taking to privacy on Ethereum?
Yes. Definitely, I think they are doing a really good job. I think I've said that the approach Ethereum is taking right now is to hide the who—who's behind a transaction and everything. Aztec goes a bit further and hides more, so it hides the code or the contracts you interact with, and it's basically private execution, which is very cool and very interesting. I think Ethereum might eventually want to get there.
I think it's great to be able to observe the new use cases this unlocks, in particular. So if you just hide the code, or hide the code plus the contracts, what does it actually change? If it changes a lot, we could also adopt it on L1 later down the road, even though it will take quite a bit of work and time.
I think one thing that's important still to note is that Aztec covers more in terms of the privacy model and surface, but it is more trusted, right? It's an additional layer—literally, it's a layer 2—and so you do have a bit more trust than what you will have on Ethereum L1 if you have private dApps with the right properties, ones that are immutable and trustless and everything.
But I think their approach is very interesting. I think no one is even close to the endgame, which is everything is private and you have what we call private shared states. So, like, a private Uniswap, dark pools—all of this completely private. I think for that you need cryptography that is just not there in terms of efficiency.
I think everyone is looking at this with new cryptography, but we all know it's not going to happen now. I don't think anyone has achieved anywhere close to this kind of privacy. Or rather, to get there, you need a fully trusted thing: you need huge, beefy nodes to actually do this, and you need to trust them that they are doing the right thing. So, yeah, the privacy spectrum is quite large, and hopefully cryptography will get a bit more efficient and we can increase what we hide.
One thing I want to talk about is that I feel like privacy has created a massive tailwind narrative behind it. All of a sudden, we've seen a lot of KOLs really rally behind privacy, and I kind of find it funny because I almost feel like—would these same KOLs be as excited about decentralization? Probably not. But all of a sudden, they've rallied behind privacy, and this is coming, in part, from some people that I don't think could care less about privacy.
The question I want to get to is Zcash versus where you're going with Ethereum. One thing I'm curious about is, could Ethereum reach feature parity on the privacy side with Zcash, or could it go beyond it? Or is that even a comparison that you're thinking of internally at the EF? Are they even on your radar? Are you drawing from anything that they've done in the space? What do you make of that?
Yeah, I think it's a very interesting question. I think the Zcash protocol itself is very strong. The team and the cryptography behind it are strong. I think Ethereum and Zcash are at very different, opposite ends of the spectrum, but are sort of converging on a few things.
I mean, Ethereum is proof-of-stake, right? I think it just has way better economic properties than proof-of-work. But now I hear Zcash wants to maybe add proof-of-stake to its already existing proof-of-work system, so they're working on this.
Zcash has an enshrined pool. I talked about completely enshrining something—they did—but it's just for private transfers, right? So it's great, but it's not about DeFi, composability, money legos, or different things you can build on top of it. It's transfers.
With Ethereum, I think we have this sort of private DeFi in mind. Ethereum is programmable, and I think there are so many use cases that are unlocked by this that we can go way beyond simple transfers. I think that will probably be the difference.
I think one thing we are converging on, which is reshuffling the cards for a lot of things—and we are sometimes in touch as well—is post-quantum cryptography, because we all need to transition. Every protocol will need to transition to post-quantum cryptography, and so we're looking into ways to achieve that and what's the best technology there. That's something I think we do share: the need to transition to post-quantum cryptography.
10. What will privacy mean for institutional investors?
Thomas, finance is clearly Ethereum's biggest product-market fit: DeFi. What does privacy unlock for the next wave of institutional adoption, based on your research? What are some of the conversations you're having behind the scenes? What will privacy unlock for these institutional-type investors who want to tokenize and bring their assets on-chain?
I said that, short-term at least, we're going for hiding who is behind a transaction and what the assets and balances are. I think that's very important for institutional confidentiality. That's actually very well suited for institutional confidentiality because oftentimes what institutions want is—they don't want to just maximize pure anonymity. They want confidentiality plus auditability.
They want to hide from competitors or maybe the general public, but still be able to disclose to auditors and regulators and everything. I feel like this—you don't know who's behind it, but you have a public layer of what actually happened—is very useful for institutions because it allows them to make the distinction between what you want to reveal, which is what you did and you can choose to reveal it if you want, and what you choose to hide.
That is, you just don't reveal to anyone who was behind the actions that are visible on-chain. So, yeah, I would say privacy is very good for individuals. I think it's also very good for institutions. My view is maybe just taking advantage of how much institutions care about privacy to also help advance individual rights. But it goes both ways, right? I feel like we can do both at the same time, which is really cool.
11. The challenge with network meta data and privacy
Thomas, we're getting close to the end here. Is there anything you think we missed that you wanted to go back to and talk about more?
12. How will private DeFi on Ethereum compare to Zcash?
One thing that I need to maybe talk about is the whole network metadata problem, because you can use all these cool protocols, but at the end of the day, if your wallet leaks your IP, it's worth nothing. What I want to actually send as a message is that privacy is very complex because you have to plug all the holes, and there are very many different holes. That's why you need a full integration between the wallet, the app, and the protocol, and you need to make sure that everything meshes together and there's no leak.
Network metadata is sometimes forgotten. People are like, “Oh, great. I'm using a privacy protocol, so I'm private now.” It's like, well, no, because you didn't use a VPN or anything, and it's very public. Or your wallet had RPC calls to ask for some state you needed to build the transaction, and that actually reveals the state you needed to build the transaction, so it leaks your privacy as well.
For me, it's really about trying to think comprehensively about what the full privacy experience looks like. Then the next step is to make it completely invisible to the user. I don't want the user to have to care about it. I want them to click a private button, and I want it to work. So there's this whole mentality behind it: we plug it all, we make sure it's very secure, and then we ship a really cool UX so that users are fine.
13. Lack of privacy today vs future private UX on Ethereum
Again, I want to bring back all of the conversation here—or all of the benefits that we've discussed—to what this is going to look like for us as users. I think there's a huge misunderstanding out there around just how little privacy we have today, whether we're talking about Web2 and legacy finance, or if we're just talking strictly about blockchain-based, on-chain-type finance.
If I were to go and download a wallet today—I like Rabby a lot; it's great for using with hardware wallets—can you just start to talk me through what some of the gaps are in terms of my own privacy there today, and what this might look like tomorrow with all of the work that you guys are doing on privacy?
Yes.
I think the wallet component is the first touchpoint to the user. That's the direct way users interact with wallets, and already a lot of privacy is lost. When you interact with Rabby—or just any other wallet, really—they usually log all your data. They also usually send or sell your order flow to builders, which is not great. They do a bunch of things that are very nontransparent.
There's a product called WalletBeat that looks at all the wallets and sort of all their properties. You have a lot of holes. I think Kohaku is an initiative by the Ethereum Foundation to build a wallet SDK that any wallet could use, and it's really about plugging the leaks everywhere and trying to plug the holes on the wallet side.
I think on the wallet side, there are 2 big holes today. The first is network metadata, or IP addresses and everything, that are completely transparent if you don't use Tor, a VPN, or some custom solution yourself. We want this to be embedded in the wallet so users don't have to think about it. Then there's another issue: your wallet calls RPC providers to ask for state to build transactions, and that also leaks exactly what piece of state you need to build your transaction. That reveals your intent and what you want to do with the transaction.
The other important part—I talked a lot about the protocol, but the less important part is the privacy app itself. It can leak, too. I think there are some properties I really like that not all privacy apps have. I like when a privacy application is immutable, so you don't have governance and tokens that people can use to upgrade it in a certain way and actually degrade privacy for one reason or another, or ship something that goes against what people want.
I think we can also talk about the compliance layer. What compliance layer are people using? How are they determining that you're not a bad actor, and how much data do they need from you to know that? That's quite an important point, I think. There are a bunch of properties that we would ideally want privacy applications to have.
Then there's the protocol that we already talked about. The amount of back-and-forth and the signals shared between the wallets, the apps, and the protocol is a lot. You have to take care of every individual signal and make sure it doesn't result in any sort of privacy leak.
One thing I really want to talk about is that privacy is good, but there's another extremely big attack surface, which is trusted third parties everywhere. If you use rollups, or even if you use privacy apps today, you have to go through trusted intermediaries for your transaction to actually land. The goal is not only to plug all the holes and get maximum privacy. It's also to reduce the number of trusted people you have to go through to execute your transaction.
At the end of the day, if you're fully private but you have to go through that one guy, and that guy doesn't like you, then you still can't transact privately. I think it's really about maxing the privacy and minimizing the trust in third parties.
14. Closing
Guys, I think this is a great place for us to start wrapping up. Thomas, thank you so much for coming on with us. We're so grateful for the work that you and the team are doing there. We so badly want privacy as a default on Ethereum, and it seems like we're getting closer to that future. I want to give you the final word here before we go, and we would love to have you back in the future.
Thanks a lot. It was very fun. Thanks for having me. If I had a last word, it would be to tell people to contribute to Ethereum's governance generally. All the public calls are completely open, and you can chime in.
We have websites like Forkcast that are very well done and allow you to track all the conversations and discussions, maybe at a higher level. Come in and share why you think privacy is important, or censorship resistance, or why Ethereum should really focus on and ship a particular feature because you care. That is usually extremely good feedback for us.
It's just an invitation for people to contribute and participate.