# Policy as Critical Infrastructure for Privacy by Nikhil Raghuveera || EPS Devconnect 2025

- Speakers: Nikhil Raghuveera
- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-02-09
- Duration: 14:51
- Topics: web3, privacy, now, crypto, cryptography, blockchain, data, security, human right, rights, tech, technology, internet, open source, free, freedom, ethereum, hackers, ethics, cypherpunk, dev, developer, dapp, decentralization, bitcoin, computer, surveillance, cyber, peer2peer, p2p, love, solidity, zk, zero knowledge, education, academy, w3pn, privacy stack, devconnect, 2025, eps25, pse, privacy stewards of ehtereum, ethereum foundation, ef
- Watch: https://streameth.org/watch/yt-5FIxhc1Lp2A
- YouTube: https://www.youtube.com/watch?v=5FIxhc1Lp2A

## Description

...

Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. 
Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration.

Ethereum Privacy Stack: 
http://eps25.web3privacy.info

Organized by 
Web3Privacy Now & Privacy Stewards of Ethereum

Web3Privacy now collective: http://web3privacy.info
Privacy Stewards of Ethereum: https://pse.dev/

## Transcript

Let's go for predicate. I need my laptop here or no slides. &gt;&gt; Oh, perfect. Okay. &gt;&gt; Um, &gt;&gt; perfect. Thank you. Hey, everyone. How are you guys doing? &gt;&gt; All right. So, first up, I think we have to define and think about the world as it is today and where it goes, right? So, I'm sure many of you guys share this view that blockchains will become the global financial settlement system. Uh, I'm this was me pulling the numbers from last night. I don't know how it's changed. I haven't looked at the markets this morning, but hopefully it's same if not a little bit higher. But the point is generally that you actually see a significant amount of growth in digital assets over the last, you know, even over the last year. uh you're seeing record amounts of from a market cap standpoint, stable coins really does seem to be the real fundamental use case for for blockchains, right? This is something we've always talked about, but you're actually seeing that adoption uh not only in crypto world, but you're seeing that happen through fintexs and financial institutions as well. And then of course you have real world assets uh and DeFi itself. So all this means that we are really going into a world where blockchains do become a global financial settlement system and privacy is critical to that right we cannot have a world in which all of our financial activity as a user is fully revealed but same for any organization they also cannot have everything be disclosed publicly for a number of reasons right from from a business execution standpoint for payroll they can't have all their employees see how much everyone is making a business can't show how much are they paying their different vendors publicly both to their other vendors as well as their competitors. You could pretty much backtrack their entire financial position through things like that. So in this case now we say privacy is critical, right? But what that also means is you are also engaging and interacting across regulated markets. users are coming in from regulated markets and businesses of course exist and operate in regulated markets. So the question then is how do you incorporate compliance into that to be able to scale in the global economy? And really the question is is why compliance, right? It's because developers and organizations that operate in regulated markets have to think about their business requirements such as you know they don't want to reveal everything but they have to ensure that they're not you know sending money to someone who's malicious or receiving money from uh a malicious actor. There's of course regulations and security. So to make this even a little bit more tangible, the re what I think about here is, you know, you and I will all go buy a pair of shoes. But when we go buy a pair of shoes, we don't go to a back alley and say, "I'm going to go and buy a pair of shoes from something that was clearly stolen, right? We actually don't want to do that. We usually go to a store and say, let me buy a pair of shoes." So again, this is where compliance does matter. And so this is really what we see, right? So this is what the purpose of predicate is is we build policy infrastructure uh for privacy solutions and core to this is that we believe that Ethereum should be credibly neutral. None of this should be enforced at the Ethereum core protocol level but rather you are building financial uh solutions that sit on top privacy solutions that sit on top. And so in that case you need policy infrastructure to be able to power that. And so really then it's that policies control how transactions flow in financial systems. That's historically how it's always worked and that's really what the view that we take as well. All right. So how does this work? Quite simp. It's not too complex actually. So you have a financial application or a privacy application. In this case uh you have a predicate API. So in this case they request the predicate API to to issue a signature saying hey this transaction that's about to go through let's say someone wants to enter into a privacy system is it compliant or not and if it is predicate issues a signature an attestation in subsecond latency basically we have an off-chain compute system that validates the transaction says does this adhere to the requirements if so yes we issue a signature then When the user is submitting the transaction, that signature is embedded in the transaction object. The user is never going to really realize this. We should not be fundamentally changing the user experience. It should be very very consistent with what they already have. So they go through, they don't realize it, but they have a signature embedded in the transaction object through predicate. So they then hit submit. The transaction only goes through the smart contract if there is a signature from predicate. If there isn't, the transaction can't go through. So what this means is we are actually creating mechanisms to have compliance enforcement at a smart contract level for f uh for various applications right. So a transaction can only go through if it has a signature from predicate. We attest to whether something is compliant or not and uh it is enforced at a smart contract level. And then lastly the signatures are validated uh on chain uh through the predicate contracts. So I'm going to have one slightly more abstract slide and then I'm going to go into like a few tangible examples of this. So the what this means is when you think about policies in this architecture is you're allowed to do you know smart contract level enforcement in which transactions only execute per defined settings uh fully observable right so you can see in real time if they're going through if they're not going through why they're going through why they're not. The other part is it's one integration. So you're going to need to incorporate when we really get into the you know the incredibly boring parts of compliance for everyone here. It actually you have to think about a number of different data points onchain and offchain. This is zero knowledge proofs. This is off-chain data. This is proprietary data. Um any of those things. It's really how do we have a unified mechanism to be able to do all of that. Uh and then lastly it should be programmable. Right? You incorporate this once you should not have to update your smart contracts every time. If something changes for your business or regulation changes, you should be able to update that. It should be programmable without having to make any dramatic changes to your infrastructure. All right. So, let's make this now even more concrete. So, IntMax is a privacy L2 uh on Ethereum. They need to ensure that you know malicious actors can't depos can't enter into their privacy system. And so, the way this works is it's in their deposit contract. So anyone who's going to go and deposit that predicate is essentially used to verify that those funds are not coming from a major exploit or coming in from you know um uh a major instance of terrorist financing or human trafficking. Uh so when a person is about to deposit this is verified by predicate and here we use a multitude of different data inputs for that. So for example, TRM which is a blockchain analytics provider. There are various custom uh other data sources that we use and these are of course all defined by INMAX. A crucial part here, right, is that you have to have a number of automated redundancies because you can say, hey, look, TRM is right there. Isn't that if there's a Cloudflare issue or an AWS outage, what happens? Are you basically stopping every transaction into inmax? And that's where this is really important in the way that this is designed is it should have auto capabilities to incorporate a number of other data pieces. TRM goes down, if there's a major outage in the world, you should have various points of input. And again, this is where you incorporate custom blacklists as well that use much more onchain infrastructure. So that's INMAX. Now, I'm going to talk about one, Alo, obviously not an Ethereum uh blockchain, but I think what they do is very interesting and their approach is very fascinating. So Alio is a layer 1 blockchain, passed a governance proposal. their ecosystem passed a governance proposal and said, "Hey, we are a privacy blockchain and so we need to define and enforce some best practices for our bridges. Not for the blockchain as a whole, but we as an ecosystem believe that bridges should be taking some certain best practices." They didn't say exactly what you have to do. They said here are some things take some set of them and do that. And so this included uh basically uh time delays 24 to 72 hours before bridging a limit in the uh amount that can be bridged in any given day or any given transaction screening against high-risisk addresses right such as sanctions and addresses involved in major exploits. Um they said if you want you could do KYC really up to you but the main thing was they said hey we have to have at least some shared view that we need some best practices for our ecosystem. uh and I think it's an really interesting approach right they as an they as an ecosystem passed a governance proposal it's a much more decentralized mechanism of doing this and so all of those bridges then use predicate to be able to enforce different requirements such as these perhaps not all of them but a subset of them then the last one is when we go to a little some of the more institutional use cases and so then we start thinking about identity right identity is tricky Because we have traditional KYC, KYB systems, but then we also have really where I think the world should be going, which is zero knowledge identity, right? Zero knowledge identity ensures that we as people have custody and control over our own personal data without it being out in the world. The challenge of course is not every institution today is comfortable with that. So we have to think about how we accelerate that forward. How can we have zero knowledge solutions sit alongside traditional systems abstract that a way that over time we continue to position zero knowledge identity to be able to replace traditional identity solutions and that's really how we've been approaching this is that you can actually aggregate across multiple solutions simultaneously uh for a more unified verification I'll give an example of this shortly uh you have a front-end experience that allows a user to you know go through whatever process they have whether that's getting a ZK identity solution are going through traditional KYC and then immediately being routed back to what they need to do. So what I'm emphasizing here is the need for seamless US u UX experience right like it has to be seamless that is a big breakoff point for most financial systems is any changes in u uh in the user experience halts activity you can see that drop off you can say you know there's a thousand people coming in oh they got blocked here you see a 20% drop off you see a 30% drop off we can't allow that to happen we have to ensure the best UX possible And then the last one of course is enforcing these requirements at a smart contract level such that if something isn't met it's rejected. So I'm sure many of you saw the Aztec uh the uh the Aztec token sale. So this is exactly what we do there. So if you go to Aztec there's two flows. You can choose to use ZK passport which has a fully zero knowledge identity solution. But if you're someone in a market who doesn't have an NFC chip in their passport or don't have a passport or um your your passport NFT chip is NFC chip isn't working or perhaps you're not able to download ZK passport. We also have a more traditional KYC approach and then of course for KYB which is for businesses who need to participate zero knowledge identities doesn't currently offer a solution there. So really what we've done is we've given users choice on which direction they want to go through. All of this is unified right? So from a user standpoint, they can choose what they want and these are still enforced by predicate. Um in addition to that, we have some additional uh components that are integrated on the back end. But again, it's it's about a unified experience in which people don't realize where people have the ability to choose what they want to do. And from a technical standpoint, it's all the same unified experience. And really this is where we see the world is that organizations need to think about a holistic set of rules whatever that is right whether that is they're a financial institution in Europe that has to think about mika whether they're a payment system in Latin America that has to think about payments across different countries in the region there's a holistic set of business legal and regulatory requirements that they all have to consider and so that is a multitude of not just AML Not just KYC but things such as rate limits, security, geoloccation, all these really matter and this is crucial when we think about the scaling of Ethereum. And then the last part of course is uh can't leave a presentation without talking about AI. Uh when we think about an agentic economy when we think about transactions across AI agents, you will need to ensure that your AI agent behaves in the manner that you want it to behave, right? How do you ensure that it does the things you want it to do? And so last I wanted to end with this is we're working on a we're finalizing a paper with Inko uh on complant privacy. And so really the purpose of the paper is there are so many different approaches to compliance and it really is a tricky thing to figure out right like how should I be building privacy and how should I be building compliance and there's a lot of different ways to do it. And so with the purpose of the paper is we present a framework for different styles and it includes a number of different case studies for many organizations that do it not just the ones I mentioned but I think other great examples are privacy pools by uh by Amin by Oxbow and Amin Solommani. Uh rail gun also has an excellent approach to this. So there's many many different styles, layers and forms to it. And there's of course many different types of privacy use case, many different types of privacy, fully anonymous, confidential, uh public of course or pseudo anonymous. Uh and so really the purpose of this paper is how can we make that a little bit easier to understand for organizations and developers. And so with that, I'll be around for uh the rest of the morning and early afternoon. If you're interested in learning more about the paper, anything we do, happy to talk further. So with that, uh, thank you very much.
