# Luis - Privacy Is Normal: Everyday Applications of Commit-and-Reveal Encryption

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2025-10-07
- Duration: 23:05
- Watch: https://streameth.org/watch/yt-LefPh9fWbXU
- YouTube: https://www.youtube.com/watch?v=LefPh9fWbXU

## Description

Shutter is already enabling live, encrypted dapps, bringing threshold encryption to real-world applications. In this talk, we showcase several applications using the new Shutter API. Among these are: Shutter Hongbao, a time-locked encrypted, non-custodial gifting app, and Shutter Predict, where users can make encrypted predictions that are automatically revealed in the future. 
We also explore upcoming use cases, including sealed bid RFPs for DAOs and sealed bid auctions. Join us to see how Shutter API is live today, making encrypted on-chain interactions seamless and practical for DeFi, gaming, and beyond!

## Transcript

And yeah, uh hope I'm not boring you. I'll try to make it quick. Last talk of the day. Um I'm Luis. Um yeah, I'll talk about um privacy, how privacy is normal, and then I connect it to um the products that we're building in our um threshold encryption um solution. Um and I'll talk kind of about privacy in the broadest sense. So it's not not just anonymity, but also um temporarily hiding information. So yeah. Uh, and I even found this little sticker from web priv privacy now um, which actually says privacy is normal. So that's a good coincidence. Um, just briefly, why do I think uh, privacy is normal? Um, well quite simply because you just can't do um, business without it really if you think about any kind of serious situation where you financially transact. if it's just in the open, you'll sort of lose your competitive advantage and it's just not you're not yeah you just can't really do business, right? Um and then I think some people have this misconception that blockchain sort of synonymity that the address is like a good protection but I think as soon as you do let's say like four or five um separate actions on separate apps um it is it's going to be extremely simple to connect the dots um and lead back to you basically. Yeah. So that's really not not a protection at all. Um and obviously yeah you also need to protect it it to protect yourself from malicious actors. Um but I think the point is also that I'm trying to make is not the most important thing. Um it's the last thing there because I'm thinking like even just for normal people who maybe are not pursued or are not in countries where they must be afraid of the government government even for them they just need um privacy right. Um so yeah and then how this connects to shutter um what we're we're building um is is a threshold encryption um commit reveal sort of gadget and it's also a distributed key generation mechanism. So it encrypts and then decrypts um and in a decentralized way. Uh and we apply it to um especially to the encrypted meool which is um an protocol level feature which encrypts transactions and the validator um have has to commit to the inclusion and the order of the transactions while they're still encrypted. So they can't um so because they don't see what's in actions um while they have to commit to them they can't really censor or front run. So that's kind of how we can prevent sort of front running malicious mev and then also real-time censorship. And then we have this other um sort of API sh API and an SDK where we apply it to every everything else and it's just four API calls that you can um plug in to your app essentially more application level and then it's about governance and information symmetry and I'll go into into these essentially um so and in this talk we'll focus really on the second one the shutter API and these applications not really the the encrypted mele because that's really a separate um topic um and just a little bit about commit reveal because again like it's we kind of have privacy with um shutter but it's not um the only thing it's like commit reveal is kind of the point uh which is you commit to something and then you you reveal it and what I'm trying trying to make the point here is that you don't really see it but commit reveal is everywhere so it's in trading but a simple example is rock paper scissors so rock paper scissors you have two people making a move at the same time right and if someone makes sees the move of the other person before um they make their own move, the game is broken. Yeah, you see what the other person does and then you react to it and just the game is no fun anymore. So you need sort of a commit reveal. You need that you need both to be revealed at the same time or you need if you will build it in in as a application you would need the server to make sure that both are hidden and then released at the same time, right? And that's happening in trading all the time, right? But it's also happening in in decision- making and all kinds of other um places. And usually you need this centralized party to to ensure the step this encrypt decrypt or encrypt commit decrypt sort of sequence. But um the cool thing is in crypto or in crypto you maybe you don't have that decentralized party that centralized party. So the cool thing is with thresh encryption we can drust and decentralize that party. Um yeah, so shedddter API um is this kind of simpler just API to offer this encryption service. Um these are some of the use cases, but I think it's better if we just run through the applications that we built. Um this is the the API calls. It's just four of these API calls. um just a setup phase and then you you retrieve your encryption key essentially use that to encry encrypt and then you um can later once time has passed you can then re receive the decryption key um so this is one application that is live integrated into snapshot so it's shield voting um yeah and it hides the voting results during the vote the real-time voting results during the vote and it really assures information symmetry, right? If you see the results during the vote and you people who vote later have a lot more information than the people who vote earlier and that leads to like strategic dec um voting. So you you might want to game the system, right? Or you Yeah, it's just in general people agree that information symmetry and having the result having the real-time results hidden is a more fair and a better leads to better voting outcomes. Um and hopefully also more votes. Um uh because think about sort of like if you already see that a vote is how how vote is going you might be not inclined to vote because you think oh it doesn't make any difference if I vote or not. Um whereas if you don't see the current tally you might have a higher chance of thinking well I need to change the outcome so I need to vote right that's why in the real world we're we're not showing the real time results of the vote right in real elections. Um yeah and we have uh in life since since about a year large larger DS like arbitrum or shape shift um D are using it. Um and we would kind of recommend everyone who uses snapshot to use it and just switch it on in your snapshot D just like go to admin settings and switch it on. Um here's another fun one for Chinese New Year that's um Hongba right this red envelope. Um you can and you can time lock g encrypt it and you can it unlock you gift some crypto to someone and it unlocks on the just on the Luna new year and it does it like force like it does it with a special encryption approach and automatically right um and it's also like a cool showcase of like full non-custodialness right the the private key is in the in the link is like a onetime private key so you can send it to someone who doesn't have cry crypto beforehand. Um, you just need the link and then it creates a new wallet for you uh using pass keys. So using the your fingerprint so it's also like a cool little onboarding use case. I think this one is another one. Maybe you've seen these hashes. So people um so for example Kobe uh dur before the FTX collapse posted this hash and it's like mysterious. What is he doing? What is he doing? Right? But what what he's doing is he wants to disclose some information or wants to prove that he has some information without disclosing the information and later he revealed it in a tweet and said I told you so like two months ago right maybe he doesn't want to influence the market or maybe he want he has it's like inside information that he wants to personally benefit from yeah but people do that quite a lot also for like co and and other use cases and we built it as so the issue with this is it's just a hash the two issues right people don't know how to do it like normal people don't know how to do Um, and so we built an app for it. And number two, if it's just a hash, you can just just not reveal it later. You say you predict something and it doesn't happen, then you might just say, "Oh, then I'm not going to reveal." And it kind of like So, so how we built it, it enforced. So you have the actual cipher text and it it enforces the decryption. Uh, so you you it's a simple app. You just put your prediction, put the reveal time and then kind of put it on chain. And then we have a Twitter bot. Uh so this is the automatic kind of text. So here for example, someone from the optimism ecosystem uh predicted something about this optimism future key experiment. Um how the how the results would be and then um and then we have this bot that later once that happens it uh automatically tweets it. Right. Yep. And you can Yeah. This one is um for Claros juror voting. Um Claros is arbitration court, right? And they have jurors and the the jurors need to vote and that the and this is also going to receive um kind of shutter shielded voting very soon. Um and here it's extremely important actually because have an incentive mechanism that incentivizes voting with the majority. So, so in the end you get more kind of receive more incentive more token if you vote how everyone else voted. So if the vote is open you'll just have like chaos. You just have people saying oh it's already like decided I'm going to go with with the majority. So the first vote that will happen probably everyone just will attach to that. So it'll break kind of the game theory. So they really need a commit reveal system. Um they have one but they but that one is like centralized uh and and and we and um the one that that shutter is will be decentralized and will be better UX because you don't have to do reveal yourself. User only has to do one transaction to vote. They don't have to then reveal as well. Um this is another one where we call a sealed bit RFP. So request for proposals right? So Dows do this right? they they want to fund something, they issue an request for proposals and then people are submitting bids and um there again you want to have ideally privacy during the bidding phase because again you might have people then if you see the open bids you might just have like this bidding war live on the bids um and undercutting the other people and maybe they then they change then they go back they want to change their bid right you'll usually RFP process ES also in the real world are again sort of hidden. Um and again in crypto we don't have that centralized party to hide it. So here we can solve it with this with shre API. Um submit bids and then submit um encrypted bids and then they get automatically uh revealed and we use this for our own um uh for a task. This created these sealed bit auctions for for a project that we an auction project and we successfully selected um so in the end general magic here was selected as the provider to build that build out that use case here. Um talking about this auction use case. So, Paddle Battle, this is um an impact focused auction um website website that we're bootstrapping which you can auction off just cool stuff, right? Let's say um uh a Dapcon ticket or um a DAP node um and the proceeds go to a good cause um that that can be choose chosen and it it'll it'll use um sealed bit auctions um sooner sealed bid auctions essentially. Yeah. Um, onchain shielded voting just means we're we'll be bringing uh the the snapshot offchain shielded voting. We're bringing that onchain and we have it kind of speced out and we have vibe coded a little p. It works. It just needs to we just need to we're working with tally and with decent um to to bring it to market. If someone want we we're just waiting for that kind of dowo that says okay let's let's build it. Um but so I'm showing you kind of how easy it is to build these apps, right? But uh um actually I think the apps are dead because uh we have MCP. So I don't know if you know but this is like this way how people can plug in like functions into their um into their clot or into their LLM. And the cool thing about MCP is I think it's a really nice translation layer between the user and this more complex kind of function in this case the this complex cryptography function that maybe needs to be explained and maybe it needs to be um and maybe it needs the usage of it is hard but if you put that layer in in between it um and if you just use kind of the encryption directly from your cloud this is the normal cloud right and I just put the MCP server in it and is writing encrypt this to 1 minute from now this text right and then it calls it explains what it's doing it calls this shutter function to um to encrypt and then boom perfect it did encrypt it tells me the time and gives me some of the information the transaction hash and stuff like this and then it's locked um then I can check the other one is the other function is like check it please um uh how Yeah. What's the status right now? It's like it's not it's not it's not um it's not unlocked yet. I think it'll say yeah, it's not ready because it's before the 1 minute, right? So, uh and then I'll fast forward and then I I'll tell it decrypt it now and it uh it then decrypts, right? So I think it's a really cool way of I think not just that but like in general kind of more complex things like this cryptography advanced cryptography I think is a cool way to use it and you can also like ask it questions right let's say you don't understand the primitive you can ask this the same thing like a question about it uh so yeah we built the same thing for the transaction encryption Um yeah, maybe this is too long, but essentially this is the same concept the MCP server and it can then use the encrypted meool. So you just tell it send 01 XI to D and use the encrypted meool and it'll just do the same this transaction call um on Nosis chain using the crypted meool and then on the right you'll see that um being executed then you'll see that this our shutter explorer but yeah I I think it's kind of like out of and then we have another one this is actually unrelated just another MCP um where you can analyze a smart contract and this is illustrating this example of MCP. This is a little bit off off topic but essentially here what I built is just tell me about the smart contract and then uh and then use it right and then it it finds out what this is. It's a savings um XI adapt. It's the the SI um thing right on Nosis chain where you can select lending protocol right and then it um understands the contract and you can then um uh talk to it and deposit and I the next thing is just like uh deposit And I should have sped this up and it it didn't it didn't know this contract before, right? So it just understood it but based on the based on the API. So it has a function to pull the API pull the code understands the contract and then does the does the uh uh deposits it into it. So perfect deposit successfully submitted yada boom. Yeah. Um oops doesn't uh so yeah what's next is that it yeah um we yeah want to build this kind of MCP server into a real thing. This is more like a demo um so that people can use shutter sort of natively like this. we want to add. So we now we kind of we only have this the time locked the time based decryption trigger but we want to have any kind of event to be a decryption trigger. Um and this widens the use cases and also like includes more of the privacy use cases. And then ideally at some point we want to do uh be able to homorphically do um transa do operations on the encrypted data um that and that is simple for some use cases and then very hard for like generally all all use cases because FH is um very expensive uh computationally wise. Yeah. Uh, one more thing. So, that's a little thing that we're doing for the Ethereum 10th anniversary. Um, that's coming up that it is the Ethereum time capsule, which means you can have you can, let's say you have a story about Ethereum or something that personally connects you to Ethereum that you want to dig into the time capsule and then sort of later have it be revealed. That's a way to do it, right? And we'll we'll on Monday we we launched this little app where you can do this you you put a text and you put an image and you encrypt it with shutter and it gets sort of dig into the ground and then in one in exactly one year it'll be all all all the capsules will be revealed and um I think it'll be a nice sort of way to remember Ethereum or to to celebrate this um occasion essentially. Yeah. So it would be awesome if if as many of you guys as possible would be willing to do that. And here you can just follow the Twitter. &gt;&gt; Yep. Thanks. That's it. &gt;&gt; Thank you so much, Louis. I must admit I really love that shielding thing is uh to shield votes, especially if you go on more layer 2 so we don't have another Luna incident basically. &gt;&gt; I I at least earn money on that one. &gt;&gt; Yeah. Sounds good. &gt;&gt; Yeah. &gt;&gt; So, do you have any questions from the audience before we start in with the apps here? &gt;&gt; Uh, you had like messages locked for 1 minute or whatever. Who enforces that time difference? Can I just change on a system like the the clock and I hack it or &gt;&gt; Yeah. So, two things, right? The the So, there's the keepers that are that's the centralized set of keepers. Um and they're sync with the blockchain for the for the time for the time based thing. Yeah. But there is a trust assumption right. So threshold encryption and all same as like for multi-party computation you have this um an honest majority trust assumption. So you need to trust that at least a certain number of these nodes are are honest and are following the the the protocol. Yeah. But you could slash for example if if they don't if they yeah you can prove that you can yeah you could slash if you if they don't. &gt;&gt; Thank you so much. So we have a few questions here on the stage that come off. So we have the first one here on top. How does Shutter handle balance between you user privacy and transparency on public blockchains especially in a case like sealed bid auctions or DAO RFPS's where audibility is also important? &gt;&gt; Yeah, it's a very good question um and and also a very simple answer for us today because it's com it's revealed always right. So at the end of these use cases currently it'll just be revealed and then onchain it'll just look like um it was never encrypted essentially or maybe you'll see that it was encrypted but it'll be just as audible auditable as before. Yeah. But the question will be very very re relevant if let's say we move into this FH territory um homorphic encryption territory where you can keep have it be kept um private and um I mean the the answer to that question like what what should be private what should be transparent is extremely hard right and it'll depend on per case I just think overall I would say first we need to have the functional like I think right now people don't even have the ability to have stuff private right and and it's very hard to discuss even like because it's not even possible. So I think we first just need to build the functionality at the at the protocol level or at the at the smart contract level that privacy for everything can be achieved and I think then we can talk about okay how can we do stuff like privacy pools where you have maybe exclude people yourself from malicious actors or maybe some some kind of auditability on top um using FH or something. Yeah, &gt;&gt; thank you. I think that was a beautiful answer. Uh we have the next one. Why is encryption onchain important now and what problem does it solve that current DAPs can't handle? As you said, DAPs were dead basically. Yeah, deps are also dead. Yeah, but I mean um I think the the question so I think lots of problems, right? We saw so the the simple problem is privacy, right? So um as I said, we don't have privacy and we need privacy. um a specific example of this for shutter for example or something like encryption is um a smart accounts. So, so um like EOAs can use Fileverse and they can end to end encrypt the document on Fileverse, right? Um but the with a smart account, let's say this kind of the the idea is right, we're moving to smart accounts. Um you don't have the you don't necessarily have one private key. So, you don't necessarily have any private key associated with the smart account because it might be like that the account is transferred or you might it might be like owned by six people or something, right? So the same encryption ability you don't have for smart accounts. So this like file kind of breaks for smart accounts um because you can't do private documents with something like shutter um you could ensure privacy there again. Yeah. So but privacy as I said before is is just only one of those problems that we're trying to solve. The other one is like this like information symmetry problems right front running um and then things like this unfairness and voting uh and all these kind of um issues. Yeah. That's a very good point. Do we have more questions now from the audience? Well, everybody's uh quiet today, but thank you so much, Louis, for coming by. Please, everybody, give him a massive hand. Thank you.
