# iExec | Confidential Tokens: The Missing Primitive for the Next Generation of DeFi - Martin Leclercq

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2026-09-25
- Watch: https://streameth.org/watch/yt-LKU0MVBThTE
- YouTube: https://www.youtube.com/watch?v=LKU0MVBThTE

## Transcript

Hello everyone. It's very nice to be here. Thank you Eleanor for the invitation. An amazing event dedicated to privacy. I'm going to talk about something I truly believe in. So, I'm Martin, a lead developer at iExec. And you know what? I know your balance. I know the amount of your last transaction last transaction . I know your income strategy, and I can even copy it, even though you spent time creating it. And I'm not a hacker. I didn't hack anything. I just opened a blockchain opened a blockchain explorer. Transparency is what makes blockchain powerful, but in DeFi it can be a problem. Today I want to talk about what I think is missing in DeFi— privacy tokens privacy tokens . Traditional finance works differently: positions are private, strategies are confidential, and disclosure disclosure is optional, but it's all centralized. In DeFi, everything is public, strategies are open, and compliance is all or nothing. In my opinion, things shouldn't work this way online . This can lead to real systemic problems. I think everyone has heard about MEV attacks, bridge breaches, etc. If we want to attract new users, mass adoption, and institutional investors, we need something new and private. So what's the solution? Many people talk about private transactions, mixers, encrypted transfers, but this is not enough. This is useful, and many of you have probably already used such privacy technologies, but it may not be enough. We need to do more than just hide the transaction. We need to hide the asset itself. This is why we need privacy tokens privacy tokens . We need private assets to hide balances, transfer amounts, and to keep data encrypted by default. Technically it's quite simple. You know the ERC-20 standard, and you can convert it to ERC-7984. Has anyone here heard of this standard, ERC- 7984? No one? It was launched by Zama and OpenZeppelin. Zama uses FHE technology. This is great, and in iExec we use TEE— use TEE— Trusted Execution Environment. So you can "wrap" any ERC-20 and get a confidential version confidential version . One to one, encrypted balance, full compatibility. So, how it works: the interface is the same as ERC-20, but everything on the network is not encrypted. As you can see, the balance, a classic ERC-20 balance, becomes a confidential balance, the transfer becomes a balance, the transfer becomes a confidential transfer, and the total supply becomes total supply becomes confidential. But you might think, " you might think, " Okay, it's not because we put " we put " confidential" in the method name that it became confidential became confidential ." You may notice the "enc handle" mark in orange. We use something called a " called a " handle". Essentially, it's byte32. We take a string, decrypt the number, and encrypt it in byte32 format. And this is what we call a descriptor. But that's not all. It is not enough to simply convert data to byte32 to make it completely confidential and private. What is a descriptor? Imagine that you check your coat into the cloakroom and receive a numbered badge, but you can't get all the information about the coat with just that badge. So, the secret value is decrypted outside the network. The user can encrypt an amount in byte32, and this encrypted amount will receive a corresponding descriptor. A descriptor is a pointer. And why do we need a pointer? Because all the calculations, all the logic, mathematical logic, are performed in the TEE, the trusted execution environment execution environment . This is called confidential computing. So, let's talk a little bit about confidential computing. In iExec we use the Intel TDX chipset. Essentially, in this chipset, you can create what we call an enclave in memory. You use it every day, for example, my iPhone has such an enclave. So, in this enclave, everything that happens remains completely confidential. Code, all calculations. And that's what makes confidential computing and confidential tokens so powerful. Because in this TEE, when you initiate a transfer, you get a descriptor, take the corresponding ciphertext, perform logic, mathematical calculations, re -encrypt into a new descriptor, and store it again. So store it again. So , in the user's workflow, he encrypts the amount on the client side. It will be encrypted on the client side. The smart client side. The smart contract checks the confirmation and sends a calculation request to the TEE stack. The TEE performs the transfer, decrypts the balance, verifies it, calculates new balances, and re- encrypts the data. And your new unencrypted balance is written to the chain, both the sender chain, both the sender and the recipient receive a new handle. So, the amount and all sensitive data are never, ever, ever processed in the open. This always happens in this confidential computing space, TEE. So, um computing space, TEE. So, um , a directive map. Okay, it already works, it's not the main topic today, but you can use it. This exists. And as you can see, when you use this technology, what happens in the blockchain browser is completely private. And the transaction amount remains zero remains zero . So, privacy does not mean opacity mean opacity . I'm sure some of you will disagree . In my opinion, if we want mass adoption and people to get involved in DeFi people to get involved in DeFi , we need compromises. And compromise perhaps means compliance . So that doesn't mean that if you use privacy technology, you don't have to be responsible. In my opinion, this is an interesting compromise. And in this, uh compromise. And in this, uh , privacy token technology, we added a compliance feature. This means you can grant permission to someone, a government or a regulator, to inspect specific data, rather than all on-chain wallet activity, etc. Not everything, just what they need to check. For example, if I transfer you, say, 1 million USDC, and the regulator wants to verify that amount, why not? I can only let him check this amount. And since this amount is tied to a descriptor, as soon as your wallet balance changes, the descriptor changes and the authorization is revoked. So, you can grant permission to someone only for certain data at a certain point in time. Let me check something internal. Yes, just to show you how easy it is to get started and create a confidential token confidential token . We have it for everyone. And as you can see, it's basically the same as ERC-20. Here, confidential incineration. That's it. And here you just add the encrypted amount, which will be 32 bytes. So, there are many uses. You can apply this almost everywhere. I was at the Libre Alun conference yesterday and I thought it would be really interesting for Libre Alun to use a privacy token for, you know, everyday use, because everything is private. We launched private, confidential storage with ERC 3646, confidential storage, private lending, equity tokenization, of course, and W S. Things of that nature. It works quite well, and it's not just a concept. This is real concept. This is real . Of course, I work at iExec and will promote our technology. We use TEE, but we are not the only ones. There are many privacy technologies. Privacy protocols such as Zama or others. They use FHE, some of them use ZK. Honestly, all of these privacy technologies are great, and I don't think any one of them is better than the others. FHE is not better than ZK, ZK is not better than TEE. I think we need to talk about hybrid privacy technologies. For example, a TEE that uses MPC, multiparty computation, to generate and use private keys. And ZK, I think Zama uses FHE and a little TEE as well. We have to combine everything to get something much more powerful. And users need something easy to use. As for IX, it is a simple SDK that you can install into your project, decentralized exchange, or DeFi project. With just one SDK, you can implement this privacy, this token technology, into your project token technology, into your project . So, compositeness, simplicity, lack of trust, selective disclosure. Omni-chain, because an interesting point in IX, we used to have a level one called Belcore, but we turned it off. And now we work in Arbitrum and Ethereum. This technology can be deployed in deployed in any EVM network. It's actually very simple. Thank you. Thank you very much. If you have any questions, please contact us.
