New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Panel | The Future of Privacy: Protocols, not Promises | ETHDam III - 2025

CryptoCanalTue, Oct 7, 2025, 12:00 AM

Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo. 🌷 https://www.ethdam.com// 🌷 ------------------ Panel | The Future of Privacy: Protocols, not Promises | ETHDam III - 2025 🎙 Panelists: Nathaniel Fried - 0xbow / Privacy Pools - CEO / https://twitter.com/nattyfried http://0xbow.io/ Lisa Akselrod - Aztec Labs - DevRel/Tech.writing / https://x.com/cryptobuilder_ https://aztec.network/ Oleksandr Kurbatov - Rarimo - Lead of cryptography / https://x.com/olkurbatov https://rarimo.com/ mf - Web3Privacy Now - Chief Caffeine / https://x.com/0x_m_f https://web3privacy.info/ ------------------ About ETHDam & CryptoCanal ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance. ------------------ 🎥 Credits: Intro / outro by babyPRO - https://babypro.art/ ETHDam Photography by Paulus – https://concretestate.eu/ ------------------ Special thanks to our partners who made ETHDam possible: 🌹 Hackathon – Bouquet: Oasis Network https://oasisprotocol.org/ 🌷 Hackathon – Petal: Circles https://aboutcircles.com 💛 Conference – Gold: Zano https://zano.org/ Dash https://www.dash.org/ Bitvavo https://bitvavo.com/en 🩶 Conference – Silver: Igra Labs https://igralabs.com/hero 💛 Conference – Copper: Lido https://lido.fi/ DeTrip https://detrip.travel/ Cake Wallet https://cakewallet.com/ The Grid https://thegrid.id/ Calimero Network https://calimero.network/ 0xbow https://0xbow.io/ Mina https://minaprotocol.com/ JobStash https://jobstash.xyz/ Cyber Capital https://www.cyber.capital/ POAP https://poap.xyz/ Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 🌱 Sponsor: EF Ecosystem Support Program https://esp.ethereum.foundation ------------------ 0:00 – Intro 0:43 – Speaker introductions 1:22 – What are privacy pools? 3:05 – ZK mechanics and Merkle proofs 6:10 – Scaling and the privacy tradeoff 8:47 – Keeping bad actors out 11:07 – Should native assets be restricted? 12:28 – Trust and open-source systems 14:02 – Regulatory alignment and UX 18:15 – Final takeaways

Transcript

Welcome to [Music] Easter. Okay, clock tick tock. Let's start. Thank you everybody for being here. Part two.

Um, we're going to start with a short introduction. I am Mil MF. I'll be your moderator and host for today. Uh, there are no cars under your seat. I'm sorry for that.

Production said no cars to give away. But uh yeah, today we'll be talking about privacy pools. We'll go deeper into what they are, how they are, why are they relevant. But before we do that, I would like to have a short introduction from all of us. Uh Lisa, why don't you go ahead?

Hi everyone, my name is Lisa Axelrod. I am part of Devil team at AdStech privacum. Hi everyone, my name is uh Nathaniel. Uh my background's open source intelligence and national security. I'm the CEO of Oxbow, which is building onchain privacy without the terrorists.

Yeah. Hey, uh my name is Alex. I'm lead of cryptography at Ryo Protocol. So, yeah, I feel more comfortable writing papers than pitching something. But thank you anyway.

Well, good that you are the one writing the papers then and I'm not. So, um for everybody here, can you just raise your hands if you know roughly what are private PTC pools? what do they entail? Wow, that is a a growing amount of people. Uh but why don't we start um explaining me what are privacy pools?

Yeah, of course. Um probably useful to add some context around where they where they came from as well. So um after tornado cu tornado cash was sanctioned by the US government there was a paper written by Amin Salami over here um by Vitalik by chalysis and um some professors as well which um laid forwards a way um where you could build onchain privacy but keep all of the illicit funds out so that the privacy solutions that we're building are not funding you know North Korea's nuclear program. That's kind of the core issue. Um and the idea of the the paper was pretty simple.

So users can deposit into privacy uh into a privacy pool. Um and then an ASP so an association set provider will conduct KYT not KYC on the flow of funds coming in. Um and if they pass that vetting the user will get um added to essentially a white list. Um and then when they withdraw, instead of saying this withdrawal equals this um deposit, you say this withdrawal comes from this list of known good deposits. So all of these deposits have been vetted that they don't come from they're not hack funds on their way to Kim Jong-un.

That's a great way to avoid the let's say the sketchy business of it all. Uh thanks for explaining that to me. Um then now if we dive a little bit deeper in the technology without going uh too deep um can you Alexander explain me a bit more how the pools combine ZK uh specifically without compromising on the aspects of um yeah the general affectionations. Okay. Yeah.

um by the hood like we have a technology that allows you like to merkealize some like statements for example yeah if you have like a chance to merize something it's better to do that so uh to cache used malization for incoming deposits uh privacy pools like uses that as well but additionally there's like extended with the mechanism that allows you to build additional trees and like prove that you're part of particular tree or like non-membership. For example, uh we are like in Rhymo we are building merized registries with uh statements about the digital identity. So you can for example prove that you have a valid passport and create a commitment in the tree. You can create your biometry proof and also create a commitment for for the registry. So we are trying like to create a lot of different criterias that allows uh yeah that allow you to build like more difficult eligibility statements.

U yeah and how does that help standard standardizing access to the blockchain network? um you know I think uh blockchain access is standardized so because uh you need like to be able to control a key pair for accessing your account uh and you need to be able like to produce a digital signature. So yeah by default that's it. But um I don't want to like see a world where users uh for accessing blockchains need to like pass KYC procedures, need to verify like and scan their documents. Uh but for some cases definitely we need like to have some instruments and tools that allow you to achieve eligibility.

uh and uh for these cases we can resolve the problem in several ways. The first one we can keep everything public but definitely that's not what we want to achieve. Uh next one we can create a nave privacy when we can have some auditors that can track everything and we can reveal like any data we want to like to share and privacy pools this like a tradeoff uh this like yeah privacy without terrorists. You can be private but at the same time you can create the proofs of eligibility that you are mixing only between eligible and public and and whit listed users. Oh, that's also a great explanation.

Thank you. I definitely learned a bit there. Um, if we let's dive a bit deeper and generally and I'm aiming this question towards you, Lisa. Um, within privacy and security, there's always the triangle tradeoff. Uh, do we go for scaling?

Do we go for the security aspect or do we focus on um more performance or privacy? So how would you say is the biggest challenge in scaling these privacy pools and looking at the the triangle in which we are willing to sacrifice or not? I will try to be a bit less technical than previous speakers and to talk a bit more about common sense. Um, you call it privacy without terrorists because it sounds cool, but I think we should call it privacy without terrorists that we already know for accuracy. And this refers directly to scaling because every day we know motorists and motorists and motorists and our database is growing and um whenever we will need to uh generate a proof that I am not in the list or I'm in the list it doesn't matter.

Um formally speaking it will depend on the amount of database that we have. Then if we think about it as like implementation of particular hash function of something thinking about like amount of people in the world it doesn't matter that much because it's not growing to to infinity. We are bounded by the number of people on the earth. So thinking from this perspective in terms of scaling we seem to be good to go. Uh thinking about um security always depends on the definition of security and what has mentioned that like also privacy is particular definition of privacy what we call privacy here.

Um I think that privacy pool as we know them today have pretty particular model how they operate and pretty particular privacy model. It doesn't tell us that like oh it will be like perfect. We do not try to achieve perfect. We try to make a bit better than it was last time so that maybe it fits the world as it is. Thank you.

Um, I actually really liked how you were diving into the general ideology of known and unknown terrorist. Um, it also provide, and this is more a question to all of you, um, how exactly are privacy pools making sure that either new or old terrorists are not participating in this game? Yeah. So, there's kind of three categories of assessment you can do. You can do like known good money comes from say Coinbase has been KYTed.

If there was a police investigation, the police could go to Coinbase and pull that data and then it's gone straight into priv privacy pools. That's pretty easy to identify as known good. There's no bad like stuff on the OFAC lists or stuff that CH analysis elliptic TRM has um tagged and identified um that comes from illicit sources. And then there's like this kind of surprisingly small kind of gray area in the middle where it's very hard and basically requires manual investigation. And we at Oxbow like to be super cautious on this.

Um although you can update the ASP. So if you discover later on that you know someone ran money through um privacy pools and then um went on to you know donate it to Hezbollah or something like this then um you can update um and we can up we do update our ASP so that users can then reprove against it or all future users going forwards won't be associated with those elicit funds that um did get in but that middle area like the the current KYT capabilities on the market don't um like either fail on on that stuff um or just don't have enough um data. So you're kind of completely right on that stuff and it basically requires manual investigation um and being super kind of cautious. Sounds like a very labor intensive kind of a job to make sure we keep the bad guys out. Um I see you wanted to say something.

Yeah, I wanted like to ask Nataniel. uh do you believe we need to have such tools for native is so for example I I have like no question for supporting real world assets for example some tokens uh some like stable coins issued by particular I don't know entity so we need to have such like tools for them but should we support with the same mechanism like native currencies um like is for example ask this question again Yeah. Yeah. Yeah. So I'm totally okay like to support this uh eligibility preserving mechanism for operating with stable coins with tokenized assets with I don't know different shares etc.

But should we support them? Yeah. Should we actually support them for uh cryptocurrencies? Yeah, why not? I love the spicy argument.

Please dive into it and Lisa, if you have your opinions on there too. Um go ahead. Yeah, I think we should not prescribe general rules for the world because whenever someone uh wants to put high level world high level rule that is imposed on everyone, it usually ends in a bad way. Um I think that if there is a stable coin that assumes that for its mechanism it's great, go for it. If there is another another stable coin that leans towards like total anarchy, go for it.

If there is something in the middle, awesome. And then like there are a lot of smart people in the world um with different risk models incorporated in their brains. Everyone goes for whatever they think is right and then the world uh shows how it reflects like the world's need and sentiment. Sometimes it shows in quite harsh way but uh this is part of uh this earth game I guess. Yeah, you can use a hammer to build a house or to do some other bad things too.

I guess that um what role uh and question to all of you and how would privacy pools help increase the trust and transport you have in open source systems? Well, privacy pools is open source, so you can go and uh spin your own up. Um the the UX, everything behind it. Um, I think privacy is just like a really important human right. Um, you can see like some quite physical manifestations of the like the the pseudonmous nature of um, crypto lean to like people getting kidnapped and robbed especially in like London where I come from and in Paris as well.

Um, and so I think like it's just building trust in the the system. There is some people that care very very deeply about privacy for a variety of reasons. Um, but just generally it's something that like we have in the the banking sector with the in the US the banking secrecy act. So why wouldn't we want to have that in in crypto? That's great.

Um, and Lisa, I was curious also for for your thoughts more on how we could uh avoid then making sure that through using these trust and transparency systems the wrong people end up on a white list. You're asking me. I think you brought up the great thing with the who can be a terrorist or um Oh yeah, I hope they have awesome model of scoring that works. That's everything I can I have to say about it. That's more than great.

Thank you. It works guys. We only build things that work, right? This is the memo for today. Don't um Okay, great.

Thanks for those answers. Um, and in which ways can we bridge the onchain transactions with the regulatory compliance that is coming up more and more right now? Like we already talked about the ability to whitelist to try to keep the bad guys out. Um, is there more required? Are regulatory bodies happy with this or how do you see that translate in the future to everybody?

I can start. Um I think it's a very like this process that you mentioned like of like bridging the gap. It's a very long process because regulators and people who build products they are like aliens for each other. People who build products we mostly want things to get done. We do not want 100 conversations about how how something might be hypothetically maybe done one day.

I do not know any single like technical person who can go through it at least voluntarily and on regulatory side it's a very it's like about let's talk we do not promise anything we do not promise to do anything but let's talk and uh this seems to be quite long process I think that privacy pools is a great step towards like it's a jump. It's not a step. It's like okay, we will jump. We understand like that we already have some like achievements in terms of KYC. We don't like them as like uh cyer punk sovereign individual community.

We do not like everything that calls KYC but like it uh we also can't ignore the reality because if we ignore the reality, the reality ignores us. So we do this jump. Um and then if like thinking from like our perspective in Aztec, we solve it a bit from the perspective how we facilitate or not facilitate the crosschain mechanism at all like the crosschain messaging. What we do as a network, we leave it to the application to decide how they facilitate the crosschain that is um usually affiliated with compliance because it says who can bring what and uh take what and then we say okay is up to application decide are they full anarchy are they fully compliant compliant to which jurisdiction are they something in between and I think this is also the way the way to go what we will and get longterm. We will see.

So, making my own assumptions here and correct me if I'm wrong as well. Uh, does that mean that there are uh sensor abilities within privacy pools to, you know, if you say there's too much chaos after people use them, can you shut them off? She was talking about Aztec, like bridging stuff to Aztec. Uh it's uh up to application. If application determines the rule that people who satisfies this criteria are not allowed, then this is the coded rule.

They are not allowed because they decided this way. Yes. But you're not from a a foundational level uh regulating on how the applications are enforcing these rules. uh it's more here is our technology you can do with it or do you also have a regulatory responsibility to follow up on those on how they use your technology? We do not have canonical bridge like we just do not have it.

How applications solve the problem of bridging? Maybe they do not need it. Maybe they one one layer application they just don't care. if they need it, it's completely their decision of how they handle it. Okay, that explains it well.

Thank you very much. Um, imagine like we are getting further and further in the future with privacy pools and they start being accepted by regulatory bodies and let's assume as how they are now for simplicity. Um, what necessary steps do we still need to work on to support larger, more complex financial products or derivatives? Uh, yes, that's a good question. That's a good question.

Yeah, I'm waiting when uh transfers will be like added to privacy pools. So, because it's like a very important uh operation for for like any financial system. Uh yeah building like private defy applications is like very complex. Uh but um why we are also working on that because um why we are trying like to digitize the real world because compliance is coming from the real physical world and if you have like a proper way how to create how to convert this like real world rules into like programmable rules that can be executed and provable within smart contracts. That's like a way how we can follow u real world war rules with the fire applications.

So um yeah right now you have a lot of criteria and when you're doing like web two payments you need like to pro provide like a lot of proofs that you're eligible in like form of scans of like paper documents like some history credit score etc. And we need like to aggregate all this information into some like compressed format uh compressed verifiable format into like web3 environment. And I think this process is very difficult as well. Wow. Thank you for the answer there.

Um I have a final question for each of you individually before we give the community also to answer us some questions. Um, how do you see that how the community and other developers can work together in the best possible way to help your guys in your job, but also to help the ecosystem of privacy pools to grow bigger? Uh, if you had a message or u a call to action, let's say for our audience, what would it be? So privacy pools the when you're using privacy it's a lot of people kind of compare privacy to encryption but it's slightly slightly different like I can encrypt my hard drive by myself and get the benefits of that. If I made a a privacy protocol and it was only me using that protocol then it would be really obvious that all the deposits were me and all the withdrawals were me.

So I'm not really you know utilizing privacy. So for privacy um systems to work they need a lot of um money coming into them and you know they need to be active and cycling around and that's called the anonymity set and so it's really really important that um that an anonymity set um is like multiasset and has a large amount of funds flowing through it on a regular basis. So, if you believe in privacy, go and utilize um privacy protocols, not just privacy pools. Go check out Aztec as well. Um and go and try out all of these um these tools and find what you like, find what you what you don't like.

The real kind of gold standard of of privacy is tech that kind of seamlessly integrates into, you know, the the tools and things you're using on a um or the exchanges or whatever that you're using on a on a daily basis. And that's kind of where we want to to go towards. But at the moment it's just on like mainet with um ETH. So head on over to privacypools.com and try it out.

Thank you very much. Use the working technology. That's the mission statement here. I hear uh Alexander or Lisa, who would like to go next? Are we talking about what should be done to use more privacy pools or to use more ads?

I should answer priv privacy pools. This is not a sponsored call. Um, but no, you can uh I would say particularly because the privacy pools exist out of so many different technical components uh I would not necessarily only need to focus on that but anything that would support the general growth into the direction privacy pools is going as well. Okay. I think the best thing to do is to be a bit less maximalistic about everything because now we're like oh like someone here's KYC that's it we throw it away or like uh on the opposite like um like fully fully sovereignity let's let's make everything decentralized like being a bit less a bit more diplomatic and just allow a bit more flex flexibility in ideas, in approaches, talk a bit more to people, especially those people we do not agree with.

I think it will help. Okay. Reduce maximalism and thank you for that mission statement too, Alexander. Yeah, I think like uh privacy pools is like one component of the huge infrastructure and we can have like one private application and a hund of public applications around and it means that um when you're launching some private solution in the public infrastructure it means like all inputs into the solution are traceable and probably um the layer of publicity of like applications around can decrease the level of privacy of privacy pools or or like privacy other privacy preserving applications. So we need like build more privacy oriented products.

Okay, build more applications is what I hear focused on privacy. Great call. Well, thank you very much. Um now's the time for all your burning questions. Um, I'm a Capricorn 12th of January in case anybody was curious about that.

But I think the main questions you can push to the screen and I'll happily give them to the people to answer. So I'm getting a first question here from Mr. Anon. This is a stage. Um, are there working integrations from Mirarimo for ZKYC?

If yes, which jurisdictions are these valid for? It wasn't our goal. Uh initially like we uh yeah, we launched Trio as like layer for private identity solutions and the first application was like freedom tool that reuses passports for launching like anonymous voting. Um so yeah a lot of people told us you need like to implement zero knowledge KYC in different exchanges in different centralized services etc etc. The problem number one these services don't need this technology right now because they have built a huge infrastructures for controlling personal data of their users.

Uh and that's very like that's a hard process like to switch to the new technology. uh even if that's like bulletproof and yeah f future proof for example this is a clear case but um yeah honestly I don't see like the need from their side like to implement this those tools okay I don't know from who this question came but I hope it answered it for you if not pop one more in here um the next question comes from m Mr or Mrs. Big Bird, most of the issues raised about onchain money laundering are related to hacks. Wouldn't it be less controversial to simply KYT against known hacks? Um, I think no.

The reason people talk about hacks is cuz that's kind of what ends up in the the press, but there's a whole world of criminality that exists out there in crypto. like this picture um of me earlier when we had all the pictures of all the speakers up was at the um Interport IA which is crimes against um children um and there is like an element of um transactions going on which are funding CSAM which is child abuse material um and I don't want to associate with child abusers. I don't want to facilitate them that has uh if you know anyone that's been like affected by that stuff, it's absolutely soul destroying, but it's just like a lower money amount. Like it might be like 30 bucks or 50 bucks, but it has like sharing that and distributing that material is like life ruining for for people. Um it just is not as like big number stuff.

Um there's also like terrorist financing and a bunch of other um areas. You also then there is other privacy protocols that exist, you know, like rail gun and tornado cash. And so if you say, "Hey, I don't want to have any, you know, even hacked um money in privacy pools," you essentially have to say, you know, there's currently a certain amount of money sitting in rail gun sitting in tornado cash, which comes from North Korea, and we like don't support the standard of vetting they do to keep that money out. And so there's no way to say if the money coming out of tornado or rail gun is that hacked or stolen funds. And so you also have to um block kind of funds coming in that um are from other privacy protocols.

Um, so it probably would be less controversial, but it's not like serving the mission of uh making sure you don't associate with thread actors. Thank you. Do you have something to add to that, Lisa, or should we jump to the next one? All right. How decentralized are privacy pools?

Um yeah, smart contracts are decentralized and they are like um operating on top of decentralized network but yeah there is as mentioned is like u yeah is the centralized integration with QAC providers but this it doesn't affect on on your control yeah on your ownership of this money on or on your operator with privacy pools So from the like perspective of money controls it's totally decentralized. Uh from the perspective who exactly is uh deciding uh if you are allow it or disallow it. It's like more centralized. But I I don't like see any ways right now to manage uh this component in the centralized manner. Thank you.

And we got one more audience question on the board here. Are we building another tornado cash? Um, just quickly on the previous one, um, privacy pools is also um, non-custodial, so you can always pull your money out. Even if you get rejected or get accepted, whatever, you can always withdraw to the original wallet. So, you won't get privacy, but you can always pull your money out.

Um, is Aztec building another tornado cash? Aztec is not a privacy pool building to another cash. Um yeah, without the terrorists our tagline. Is Varimmore building another tornado cash? I say no or not.

Is anybody else here building a tornado cash? This is the wrong country to admit on the fifth on the fifth floor. Okay, thank you very much. Um before I'll let you go and escape and enjoy your weekend. Um did anybody have a question but we're not able to go through the online question system?

Please raise your hands. If not, then all clap your hands instead. Thank you very much for being here. Thank you guys for Thank you very much.

Automatic transcript — names and jargon may be misspelled.