# Privacy Without Terrorists by Ameen Soleimani || Ethereum Privacy Stack, Devconnect 2025

- Speakers: Ameen Soleimani
- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-01-09
- Duration: 19:54
- Topics: web3, privacy, now, crypto, cryptography, blockchain, data, security, human right, rights, tech, technology, internet, open source, free, freedom, ethereum, hackers, ethics, cypherpunk, dev, developer, dapp, decentralization, bitcoin, computer, surveillance, cyber, peer2peer, p2p, love, solidity, zk, zero knowledge, education, academy, w3pn, privacy stack, devconnect, 2025, eps25, pse, privacy stewards of ehtereum, ethereum foundation, ef, Education
- Watch: https://streameth.org/watch/yt-87cNFlcGslE
- YouTube: https://www.youtube.com/watch?v=87cNFlcGslE

## Description

0xBow's Ameen Soleimani talks about Zero Knowledge proofs, ZCash and how every user of it is responsible to dispute the claim that no use of ZCash is legitimate as the right to use encryped messages, VPNs and anonymous money as well should be considered normal and default.

Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. 
Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration.

Ethereum Privacy Stack: 
http://eps25.web3privacy.info

Organized by 
Web3Privacy Now & Privacy Stewards of Ethereum

Web3Privacy now collective: http://web3privacy.info
Privacy Stewards of Ethereum: https://pse.dev/

## Transcript

[applause] Hello. Good afternoon. Kind of look like that, right? Uh, thank you DevCon for having me. Thank you, uh, Web3 Privacy Now for putting me up. Uh, to any of you who have already seen this talk this week, I sincerely apologize. uh but I'm doing the same one. [snorts] So this talk is called privacy without terrorists. So last week the Oxbow team went on a retreat to Patagonia. Who here has been to Patagonia? Almost half of you. Who here has heard of Patagonia? All right, everybody. So we went to Bariloce, which is uh in Patagonia. It's got beautiful water, the best water, purest water, and there are people kaying and it was it was a gorgeous experience. And as we were standing there by the edge of the lake, we see three guys roll up with a truck and just start dumping trash into the lake. And I'm shocked. And I walk up to the guys and I say, "Hey, can you stop dumping your trash in the lake?" And the guy turns to me and says, "Bro, [&nbsp;__&nbsp;] off. This lake is permissionless." So, we were horrified by this and we got together and, you know, we saw the the sewage uh draining into the lake and 10 other guys with trucks came and they all started dumping their trash into the lake and the kayakers were disgusted and they started leaving. And so we as Oxbow, we got together and we took over the lake and we kept them from putting their trash in the lake so that the water of Baroce could stay pure and clean for the Argentinians forever. None of this actually happened. Who here has heard about tornado cash? Yeah. Who here has heard about what happened to tornado cashache? Right. So, uh I was proud to be the first check as a grant to tornado cache on behalf of Malik Dao and we supported them through their journey. Tornado cache was the second implementation of zero knowledge proofs in production in human history, the first on Ethereum and uh the first of course in history was Zcash. And we were all very jealous of Zcash. We thought it was very cool how they had privacy and we wanted privacy on Ethereum and we didn't want it so that whenever we send a transaction our entire transaction history is available to the recipient and they also can see our balances and so we made privacy on Ethereum. Uh, everything was going great until uh, North Korea hacked a video game for $500 million. I don't know why they had $500 million, but uh, then they started putting hundreds of millions of those dollars into tornado cash. Uh and in the aftermath of that uh the OFAC uh in the United States sanctioned the tornado cache system and also arrested uh Alexi and Roman and they were both charged with uh 5 years in prison. Yeah. And received sentences for 5 years. [snorts] So I think Roman and Alexi deserve to be free. The devs should not be held liable for the uh crimes of their users. The devs had no criminal intent. It wasn't like they were sitting in a chat room with North Korea coordinating trying to help them, you know, use the system. And further, tornado cache is immutable and there was nothing that the devs could have done to prevent anyone from uh using the system. And beyond that, they did actually take it upon themselves to do what they could do, which was build a compliance tool that attempted to reject funds that came from the uh OFAC uh sanctions list. Both Roman and Alexi are preparing to appeal their court cases and could use your support. And so if you have the means, please consider donating to their legal defense funds. Uh one is at free romanstorm.org and we wantjusticedow.org for Alex tornado cash developers are criminals but what about all of us from a conversation that I had with a economist in Canada in 2021 and he was having a hypothetical question say a criminal deposits the proceeds of crime into the tornado smart contract isn't any noncriminal who interfaces with the tornado smart contract at risk of providing illegal moneyaundering services to that criminal. And I said, I am not a lawyer, but I really hope not. And I tried to make the argument that just like encryptions and VPN, anonymous money is a tool to protect human freedom and should be defended as such. The the annoying thing about arguing with all of you all on Twi on crypto Twitter is that typically I'm arguing against the same arguments that I have historically made. Um the the reality is that unfortunately financial privacy tools are not exactly like encryption. I don't need anyone else to use encryption tools to get the benefit of secrets uh with a counterparty. Uh I can just encrypt my communications and then we can talk privately. But if I'm the only one who uses a financial privacy system, it is very obvious who I am. It provides me no value. And so, was it not the case that the users of Tornado Cache were the ones actually providing privacy to and receiving privacy from North Korean hackers? If North Korea was the only user, wouldn't it be super easy to trace their funds? Uh this isn't going to you know probably the least popular talk here right um I believe that with great power comes great responsibility and the tools that we have built are incredibly powerful. Tornado cache was so powerful that it was temporarily declared a terrorist by the US government and interacting with it in any way could uh have a penalty of up to 20 years in prison. One of the things that Alexis's judge said during the court case was there is no legitimate use for tornado cash. I disagree. I was using it for payroll. Uh Vitalik was using it to send money to Ukraine to help uh protect the Ukrainians without the Russians trying to figure out how much money he was sending. And there's th many use cases between those on that spectrum that are also legitimate use cases. But it is also true that in using tornado cache for those legitimate purposes, we were also providing privacy to and receiving privacy from North Korean hackers who are also using tornado cashache. And so I believe all of us are responsible for correcting this false narrative that there is no legitimate use. But it is on us to figure out how to make our privacy tools such that that we can use them without empowering potential terrorist actors. And this isn't hypothetical. Terrorism is unfortunately real. This is an excerpt from Wikipedia about the AMIA bombing that happened in Buenoseras in 1994. And this is as a result of Argentina deciding to halt technology export of nuclear technology to the Islamic Republic of Iran. And in response, they blew up a Jewish community center and killed about a hundred people. Do you want to be giving and getting privacy from the people who want to blow up your compatriots? I don't think so. So after the sanctions, Vitalik and I got together and he came up with a good idea and they were kind enough to include me on the paper. Uh and the paper was about trying to create a bridge between privacy and compliance. And the general idea was that we could allow for users of privacy systems to prove that they are not some of the potentially bad actors who also might be using the system. And this effort was trying to advance the compliance tools that the tornado cache team pioneered themselves before we knew that these other methods were possible. And with privacy pools, users can publicly dissociate from elicit funds. Whereas in the tornado cache compliance tool, when you used it, you would have to prove exactly which deposit your withdrawal came from, which you couldn't do in public because it would defeat the purpose. And using something like privacy pools aligns with the regulatory objectives because now users can help isolate the illicit funds while still providing privacy for legitimate users. And there's 1,900 ETH deposited, about 700 ETH TVL, and there's only so far about a 2% rejection rate. This is how it works. The user deposits and then must wait for approval. And Oxbow, our company, runs KYT, know your transaction, on the deposits and figures out the source of funds. And if the funds are from untrusted sources, they are rejected. Only the approved deposits are allowed to withdraw privately and the rejected funds are still allowed to withdraw using something called the rage quit. Who here has heard of the rage quit? All right, we got some some people who know the lore. Uh I came up with this when I was working on Mikdow and it was essentially a way to leave the DAO with your money at any time without asking permission and since then it has become a technical term. I remember pitching Joe Luben on the Mikdo concept and he was like this rage quit. Can you call it the graceful exit instead? I said, "No, no, Joe." [snorts] Um, the other thing that is supported in the system is partial withdrawals. So, you know, tornado cash had a 1,0 or 100 ETH pools. I don't always want to pay somebody 1,0 or 100 ETH. And so, in this system, you can have a partial withdrawal where you deposit some amount 5 10 23.2 two and then you can withdraw one two.5 however much you want at a time and the remaining balance gets refunded and so that way you can kind of use it as a payment wallet where you can send funds as you go and the cool thing about this system I think it's cool is that Oxbow can still reject approved deposits later and so if we make a mistake or if we find out later that somebody that we did approve uh is now considered a criminal, we can remove that deposit. And the nice thing about that is that all of the other users of the system immediately just by continuing to use the system and withdrawing are proving by default that their funds do not come from the funds that we have now rejected. And so it lets all of the other users of the system say, "Hey, look, that wasn't me. I'm, you know, my money has not come from those sources. This is a quick overview of how the UI works. You make a deposit. You pay a small vetting fee so that we can run our know your transaction uh lookups. [snorts] And once you deposit into the pool, you can see that the funds are pending. And while the funds are pending, you can of course withdraw. They wouldn't let me call it rage quit on the UI, so it says exit. Uh but yeah, you can still receive your funds back. Um and uh once your funds are approved, you can withdraw privately. And so then you can uh send the funds to a separate address. And in doing so, you are also providing the proof that the deposit that your funds came from is still on the latest association set that Oxbow has published. I'm going to talk a little bit about our admin design. We made some trade-offs in designing the system to help protect our users and ourselves. One is that Oxbow can, for example, uh nuke the association set. uh we could set say okay none of the deposits are now approved and however and all users we wouldn't be able to freeze anybody's money but everybody would have to then rage quit and so we're not rugging the money but we are rugging the privacy but we cannot rug your privacy retroactively and so we cannot deanonymize any withdrawals that you have already done if your deposit is removed from the pool any funds that you have in the pool must be rage quit But any withdrawals that you have already made will remain private forever. Oxbow can has a essentially a kill switch where we can prevent future pool deposits. This is an extreme uh but you know uh fail safe where we would only use this if we thought that we could no longer uh protect the pool. However, we can't freeze or move user money that is already in the pool. And part of this design also is implemented in how we separate our smart contract logic where we have an entry point contract which is responsible for uh updating vetting fees, adding new assets um but and and the relaying transactions but the money that is in the privacy pool is held in an immutable contract and that implements the rage quit and so users have access to their funds at at all times. And so through this we have non-custodial but permissioned privacy. And I don't know who needs to hear this but rail gun is also a permission privacy protocol and that's a good thing. I really like shielded pools and so it took us a bit longer to figure out how to do this in a way that is up to our compliance standards so that we can recover from potentially making a mistake by adding users that we shouldn't have. But we have figured it out and we are working on it. And V2 is coming soon and it will be a shielded pool with internal peer-to-peer payments, support for swaps, no setup required. You will be able to send a private transfer to an Ethereum address even if they have not yet set up an account with privacy pools and then once they do they will be able to spend the money. We'll keep the same withdrawal association proofs so that when you withdraw from the system you'll be able to prove that your money comes from one of the approved deposits. And we are also working on multisig support and earning yield in the pool. And we are honored to be part of the Kohaku integration. And we are also hiring help build privacy for the good guys. Follow us on Twitter. I'm Ein Soul. We work at Oxbow. We're building privacy pools. And we're also looking to partner with builders, uh, wallets, distribution, uh, interfaces. If you're interested in bringing privacy to your users, we want to talk to you. Uh and if you're also building privacy tools, uh part of the reason we started this company is because we don't want our friends to go to prison. So help us work together on compliance. [snorts] And one [clears throat] more thing I will say is uh this is a river and the river is bending and then uh touching itself and uh the little part of it that uh gets split off into a lake that is called an oxbow lake and it is a pool of isolated liquidity. Uh thank you very much for your time. Okay, thank you very much Armen. Um, there's a bit of time for questions if you want to stick around and take a couple. Okay, super. Uh, so the first question is, can anyone run a relay on privacy pools? Yes. Uh, anyone can run a relayer on privacy pools. Uh, uh, you could self-relay transactions. Uh, of course our UI only supports the relayers that uh we're working with, but um you there's nothing preventing anyone from doing so. It's safe in our eyes because all of the withdrawals regardless of the relayer that they come from still have to enforce the same proofs that the deposit comes from one of the deposits that we have approved. &gt;&gt; Okay. Um you you touched a little bit on the privacy pools version two. Uh there was a question here about privacy. What's the V2 privacy pools roadmap? Do you care to share any more about that? Obviously, people are waiting for it and hoping for it. &gt;&gt; Uh yeah, I'll share a little bit about it. Um the TLDDR is that uh essentially we trade some fungeability for recoverability. So when you deposit you will your deposit will be assigned a unique ID and that unique ID will be provided when you send a transaction inside the system uh encrypted for the recipient and that allows you and all downstream recipients to prove that the origin of the money is still on the approved list of uh approved deposits. And it will allow us if we ever reject one of those deposits uh to have all of the other users immediately prove just by using shielded transfers normally as they would that their money does not come from the rejected deposits. Uh and it will be we're aiming to launch this at ETHCC so production in four months. &gt;&gt; Okay. So uh maybe everyone can join me in thanking Amin for the talk and also for his great work in continuing to work on privacy on Ethereum. Well done. [applause]
