# ETHWarsaw 2023: Damian Straszak, Aleph Zero - Blockchain Privacy: Mitigating Potential Misuse

- Channel: [ETH Warsaw](https://streameth.org/eth-warsaw)
- Date: 2024-10-07
- Duration: 27:06
- Watch: https://streameth.org/watch/yt-9AaPbavVmcU
- YouTube: https://www.youtube.com/watch?v=9AaPbavVmcU

## Description

Blockchain Privacy: Mitigating Potential Misuse - A compelling talk by Damian Straszak from Aleph Zero exploring privacy concerns on the blockchain and strategies to prevent misuse. 

Follow us for more updates: https://twitter.com/ETHWarsaw

## Transcript

all right uh thanks uh uh so I would be talking about um uh a private order book uh but uh yeah there is there is a general uh much more General topic that I would like to touch upon which is really making things private uh and in particular making def protocols private uh so I'm Diamond stasak I'm with Zer and uh let's jump into this so uh you're you're all probably familiar with this picture which is um a graph of transactions on a public blockchain and well this is the very nature of blockchain that everything here is visible right so you can look at one particular account at one particular user and see the whole history see what this user has done uh and what were the transfers it has done what were the all all the transactions uh this user has ever committed to the chain uh which is really bad right because we would like rather the the transactions to be private um so how can we do how how can you solve this problem uh so in fact there are already um known solutions to that uh um and as you probably have heard they all use this uh famous moon maff right ZK snarks so what I mean here are protocols a to zash tornado cash and what we are working on on Alf zero uh the shielder protocol so why is it called the shielder it's because what we are doing here is often called uh shielding tokens okay so we enter from the public um the public space to some kind of a shielded space where the transactions are pretty much invisible okay so I'll not talk about um technical things today too much I just have one slide to explain you the main idea of of the shielder of how this Moon math how this uh snarks work uh so here's the idea um me let's say address one would like to gain some privacy so what I do is I send one if to the shielder which is let's say some kind of a contract on chain and I attach a particular password uh to this transaction actually not even the password but the has uh so that the password is hidden and then in order to uh withdraw from the shielder after some time I just prove that I know some password of some particular deposit that has uh that has been done uh to the Sher okay so I don't point to a particular one because that would be kind of pointless uh that would actually reveal that this was me who was depositing the main point here is that uh the deposit and the withdrawal are not linkable okay so uh so no one is actually learning the password uh and and this is this is pretty much how it work although it's a little bit simplified I have to say so if you see some gaps you see things that doesn't make sense here uh that's valid and yeah this is only for Simplicity um actually uh yeah it's intentional so all this issues here here are kind of fixable so don't worry so ZK snars how are they used here uh in general what ZK snars allow you to do is to generate proofs of statements of the form given some private data X the result of a computation f um run on X is y okay Y is typically uh public in in in this kind of a uh setting uh so here the way it is used is to kind of prove ownership of a tokens uh because I know some kind of a private password okay and again this is a little bit simplified uh in reality it works a little bit differently um but yeah you like this mental model is is quite accurate actually right um so this was simple right so using this uh simple tricks like the zik snarks we managed to make a talk transfer system which is really private or at least kind of private um so well let's do something even better right let's uh make the whole defi private because that's what we would like to do um and well I think uh yeah I talked to many people some of them technical some of them not uh but I feel like the general uh understanding um especially among nonexpert is that uh privacy is kind of a solved problem uh on blockchain and there is actually even like a very specific recipe that you need to follow to make an app private okay so here is the recipe that I am being told uh quite often so you start with an app and then you just pick your bullets right so there are many many bullets in this box uh these are called ZK snarks uh there are plun Nova and so on like there new bullets are coming coming pretty much every month because this is an active research area and you shoot the bullets of the app as long as it becomes ZK okay um so what I would like to say uh and what you would probably realize uh quite early after spending yeah much time on this is that the story is not so simple um actually uh you will soon realize yeah after you start working on that that um many defi apps they require to store a particular State um in in the contract they have many different components that are not really comparable to token transfers uh as we uh as we have seen before so it's actually much more uh much harder to make them private and yeah it is like uh what I would like to convince you today uh giving some kind of proofs as you will see is that snar are very often not sufficient to make this uh make these things private okay so you will need some more powerful technology and these Technologies are being developed um and and we will surely use them uh to make some uh more sophisticated protocols more sophisticated defi apps private okay so let's see uh the main example that I would like to discuss today is that of an decentralized exchange um so a x and you can think of just uh say the basic design of Unis swab version two okay so you you remember this is the uh the constant product Model A * Bal C uh we will see today in more detail um but yeah this is this is just uh something to keep in mind when we go over the slides um right so let's see what's the simplest way to make a DEX private um so here is the picture let's assume that there is a user who is using this shielder primitive and the user is using the shielder to hold all its tokens okay so this is actually how you are supposed to use the shielder uh may maybe some of the users actually yeah use use this kind of protocols as uh as some mixing uh mixing um uh tools uh where you just enter and then you withdraw uh some at some point later but yeah actually I think like the best way to use them would be just to uh to just hold all your coins and if you make the user experience of that not too bad then I think all user will kind of opt in for this uh for this way of storing coins right um so suppose we have such a user and this user is actually making a swap uh on aex and uh this user is exchanging one e for let's say uh 1,800 die okay so uh what is happening here really is that this Dex that we have on the picture is simply a public Dex so this would be like a regular Unis swap contract okay uh nothing fancy nothing ZK for sure and the only thing which has some like privacy cryptography and this picture is is the shielder thing okay so the user is kind of withdrawing from the shielder making the Swap and coming back to the shielder uh with a different token so well um one observation is that this is indeed giving some privacy because now it is not clear which user actually did the swap so this is good but the issue is that well it is not 100% private because we all see what trade is really happening we are seeing that uh this this transaction to to the Dex this uh uh this this contract call is uh really public so yeah the transaction details are not not quite private right so what we come to is um is this kind of a table which uh gives us some kind of um hierarchy on what could be the levels of privacy that uh we can get on blockchain or we want to get on blockchain so the basic uh level level zero let's say of of privacy on blockchains is pseudonymity okay this is what we get by default because we just use uh accounts right accounts are this like long C that we never remember we just like copy paste them and under such a hash there is normally just one user who who uses uses this account and whenever a transaction happens what you see on chain is just that like one hash send some number of coins to another hash and this is not really revealing uh who the user is it is not revealing what are the what is the real name of the of the user behind a particular account uh of course the issue here is that once someone makes this kind of a mapping once someone kind of uh finds out who the user is behind this particular account then it's pretty bad because then you can actually backtrack the whole blockchain and see what kind of transactions this user made and essentially see the whole history so this is what we would like to avoid and uh yeah this is what an anonymity actually is this is uh the level of privacy where each transaction is anonymous so what we see on the chain is that someone is sending let's say one if to someone else and we don't really see who someone is okay so there are just like a bunch of such transactions and you are always seeing someone and like of course someone is a different person in each transaction but you cannot link them together you cannot link all the transactions of a single user so this is level one and I would say the the final level the best uh what you can get is the full privacy uh and this would also hide the details of the transaction okay so you would not see that someone is sending some tokens or someone is swapping some tokens you would just see that something happened okay but you have no idea what okay you have no idea about the value of the transfer you have no idea about anything right so this is the uh best you we can hope for um great so now we know what privacy is um we can actually try to um try to get it try to make things private um so again uh like uh we have seen a lot of progress in snarks and a lot of people are excited about them and rightfully so because they are really powerful and they can give us a lot of things but uh yeah what I would like to say is that uh it's not that they are solving the whole problem of privacy um so one ideal solution for privacy would be the following uh the problem of blockchain is that the state of the contract is public right so maybe let's just make the state private using snarks guys why don't you do that and well here is a kind of an argument why this is hard or this is not really possible um so what happens on chain when you make a transaction to a particular contract so imagine this is like this uh yeah imaginary ZK contract which is the state hidden uh using snarks um is that there is a state one the transaction happens and the state changes to a state S2 right um so how can we kind of realize such a system such a contract with a private State using snarks um well what we would need to do is to have a approver who will generate a snark that the transition that happened is actually correct of course the issue here is that the states are kind of private so you cannot we you cannot even like prove things about them only about their hushes or something like that but like that that's not the problem here uh the problem is always that in order for someone to prove that the given State transition is correct they need to know the data they need to know the states okay so the approver would need to know both the starting State and the final state of course the transaction as well and the question then becomes well so who is supposed to be the approver at least the transaction uh who who made the transaction is is certainly not able to do that and whoever would be able to do that would need to know the state but the state should be hidden the state should be private so like this is some kind of a contradiction right we cannot really do that uh so one could ask wait so you are saying this is not possible but we just saw that for token transfers this worked right so we could uh make a private system or at least an anonymous system using snarks um so there is a particular reason why this worked the reason was that Alise or whoever made the transaction knew enough about the state of the contract to actually generate this proof of transition okay and this enough was essentially the balance uh of a leas okay the balance uh uh for a particular token of a leas because if she is let's say uh sending some tokens then she can she can generate a particular proof about this um about just this part of the state and this is enough okay so this is like some kind of a generic argument why doing things using snarks is not so easy but it's okay you might not believe it because it is generic it is like very very little detail so I will give you an even more General argument saying that actually no matter what you use you will not get private States okay and by no matter what you use I mean you can use MPC you can use homomorphic encryption you can even use a trusted Hardware okay and well um how do you prove it so here is the thing suppose like this transformation was possible uh that we can uh start from an app and and just make it ZK uh then well there is a simple kind of strategy for the adversary to kind of infer what the state is so the adversary will just like throw a bunch of transactions on the contract and look at the results right um basically using the strategy uh you can uh read a big chunk of the State uh by just like uh seeing what what what the results of the transactions are so this is still very generic so I will like look at this particular example to convince you that this argument is actually valid so using uh so we can you we can can look at the at the example of of the amm deex uh the Unis swap uh with a constant product rule so uh yeah I will I will go very quickly about it but uh what you can do is by sending just three transactions actually three swaps you can actually derive all the variables inside of the state okay so no matter how are they hidden you will be able to actually get them right so private state is not something we can get no matter what the technology behind it is so yeah this is quite sad and uh kind of disappointing but uh uh it's actually not so not so bad because uh one can also realize that maybe it's not the private state that we care about um and the second thing is that well there are many different designs of dexes so maybe amm is not the way to go for privacy and Order books as well and yeah all of this is accurate and I think like one important rule for um for Designing private uh private DBS would be to actually first Define the problem properly okay so we need to say what do we really want to make private for our solution first uh this is like a fundamental uh a fundamental uh step to make and in particular for a DEX what you could probably uh want is uh uh to say I want anonymity like this is a basic thing uh I want some kind of a property that um that uh the moment the trades are kind of revealed is the latest possible meaning that uh we get some kind of a front running protection so this is like a very nice property that um that that privacy would give you right um and well there are some other things that you would like probably limit orders would be nice like this is something that you don't get in vanilla amm uh so these are all nice properties uh that we kind of demand from a from a good private Dex and well um here is what we are working on in Alf zero uh work on common uh which is an order book uh which has privacy uh so I guess I'm running kind of uh out of time so I will not really read out this slide I will just go to the example which explains it quite well I think um and the way the system works is roughly as follows so as a user you hold your tokens in the shielder and if you want to make a uh an order in the uh in the Dex you just send a particular transactions which registered registers an order at the particular price at a particular direction by or sell and it has the amount of the order hidden okay so this amount is encrypted it is not published um so what happens periodically let's say every 10 uh minutes uh but this is uh something to configure um we gather all the buy and sell orders that kind of match the current market price we aggregate them together and then what happens is that the aggregated values on both sides by and cell are revealed okay so what do I mean here by revealing this uh values so this is actually the part of the system which is not using snarks so this is the part of the system where snarks would be kind of not sufficient okay so for this we need like a weak form of multiparty computation so this is like you know a pinch of salt a pinch of non snarks that we kind of need here and actually I would argue every private system for like a kind of a more complex D5 product needs and yeah so this is this is uh a weak MPC primitive which is just collaborat decrypting some kind of a uh value okay so then we get this value in the public we do some internal matching uh between these two uh these two aggregated uh trades or orders and then whatever is left is traded using a Dutch auction in public okay so this is this is kind of the um complete mechanism the Dutch auction importantly is like completely open so nothing private is happening there anymore um it's just open for market makers to just offer uh whatever whatever uh trades they want uh as long as they affer um and yeah after these resolves all tokens are put back into the shielder okay so that uh whatever yeah whatever happens in the trade user essentially claim privately the trade results from shielder to shielder uh so nothing is really leaked about the values or um or um other details so yeah this is this is what I just said uh we don't reveal particular orders uh we uh can also upate the uh the order book by sending some you know uh small orders or zero orders because like this is the way to kind of beat the problem that you need to specify the price but it's just the price right so if the amount under the order is hidden it doesn't tell you much especially if you we like flood the order book with like fake small orders uh so then the aggregation kind of height uh all part all uh individual orders so this is the dod auction so I will kind of skip through it because I'm uh running out of time but this is quite standard it's just uh for economic uh um efficiency of the decks and basically then all the results of the internal marching and the ddge auctions are combined and user can claim the uh traded tokens so just to conclude um yeah the general message message is that making uh private dubs is not so simple and I think it's very case specific so you really need to think about your DB you really need to think what are the properties that you would like to get from the privacy and only then you can actually try uh thinking how to actually achieve that whether snarks are enough maybe you need some kind of stronger technology um and regarding common a big shout out to nethermind uh that team from then white has been working with us on the design of of common and it's been very fruitful um so we think that yeah this will be a private Pro protocol that doesn't compromise on the ux and it's generally something that is both kind of uh good uh from the economic perspective uh and yeah it should be kind of user friendly so this this was our goal uh thanks [Applause] thank you thank you Damian
