# Privacy on Ethereum in 2026: What Actually Works in Production? — Dima Burov | EPAM Systems

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2026-10-06
- Duration: 20:20
- Topics: People & Blogs
- Watch: https://streameth.org/watch/yt-OynAUFxddIA
- YouTube: https://www.youtube.com/watch?v=OynAUFxddIA

## Transcript

Hello everyone. My name is Dima. I'm solution architect. And today I want to talk about the privacy on Ethereum what we have today in terms of what type of privacy we have and what we have right now in production. And Big note about I mean I'm already 10 years in distributed systems, up-chains, ZK systems, roll-up and I have more than 10 production deployments. Before I participate as a part of Venture Studio and now I'm focused on architecture solution. And let's deep dive in details. In general, we have five type of privacy. And the first lesson here is no any available protocols can cover all five of types and any real system will be like a mix of it. It depends on your requirements. And one type of privacy is a confidential transfer where you can hide sender, receiver. And the second type of privacy is a confidential execution of smart contract is a programmable privacy where you can hide not even only the part of state, you can hide all the computations, all details of smart contracts. Third type of privacy is a confidential computations. It's very interesting part where you can hide the data during execution and The next type of privacy is enterprise permissioning where you have to provide the data for some parties and the same time you have to hide the data and you have to use the advanced role-based access model. And the last type of privacy is focused on identity and governance. One of the mature approach on the market right now. And let's explore all of it one by one. First type of privacy is confidential transfer. It's work really simple where you shield, transfer and unshield transactions. For example, um you send You need to create some private settlement and you can use this type of protocols. You can deposit to the shielded contracts your ERC-20 tokens for example and you will have a proof. Um And for example, you will have UTXO note an encrypted note inside of the Merkle tree. And after the transfer, you can unshield and you operate in the private space. What is the players available on the market? A lot of players focus on created private pools, shielded pools, and Railgun is absolutely most mature player on the market right now. It's already more than 2 year 2 years in production and additionally if we compare with some mixers, it has some proofs additional that you can verify additional details. Or if you need additional observability, you can explore Hincal or Oxbow, but that protocols on a super early stage, especially for Hincal that has been hacked recently. And both supported even by Ethereum Foundation and Vitalik. And and how it works usually you send transaction to smart contract address and you will have for example for Railgun, you will have private ZK address inside of shielded pool and you nobody can see any movement as a typical ERC 20 tokens, no any transfers, changes, all of it exist on the private space and ZK addresses and the privacy here is increasing with the number of participants. And if you want to create the own pool, it may be the the better idea because uh you need much more participants to create a great level of anonymity set. Um The next type of privacy is much more advanced. It's programmable privacy where you can hide all details of and all state and all code of your smart contracts. There is one of the interested uh um area and one of the most complex and where you have a private state, you can use some local execution and on-chain verification uh of details of your computations. And here, let's look on the most notable player on the market. It's Aztec. It's a great product, but it's also still as a most of all privacy solution on EVM and Ethereum market. It's still on the early stage, but they have a mainnet and they recently release alpha V5 version. Uh it bring new capabilities, but they have still a lot of bugs and some bugs can even possible to steal the money or something like that. And recently the foundation uh fired part of the team and we will see what will be on the next stage, but technology already here. And we can explore it on the next stage. Definitely, we'll see the evolution and uh Aztec is a really great product, but one of the biggest disadvantages, from my side as a solution architect, is the language for smart contracts. They use Noir language, and this language still on the alpha stage. It's sometimes, especially for institutional market, it can be too scared to use some languages on the alpha stage, and yes, we'll see. Third type of privacy, what I really like, and it's a confidential computation, where you can hide the data during the computation, and nobody can see, nobody available, even the not owners can verify they can verify the details, but they haven't any observability in terms of what is the data inside, what we working. And usually, we split here all confidential computation in three areas. One area is a fully homomorphic encryption, where we can compute the data without any encryption. All data on computation, on fully on encrypted state. Nobody can see the details, and even you encrypt the data, and make your computation, you will have the same result. But, without data disclosure. Second type is trusted execution environment. For example, it's Intel processors, and you have to trust hardware providers, you have to trust cloud providers that the data is correct, and you all of the details. It has some set of centralization and you have to choose what you should do with it. It depends on your use case, your requirement. And already widely adopted multi-party computations where we can split, for example, some private keys to different parties and nobody can have single private key and any additional details. What we have here in this area, Zama, is most notable product on the market already in mainnet and they have around 20 transaction per second or maybe less but they're working and promise to bring us GPU compute and we will see there in their road map and maybe till the end of this year we will see some updates in terms of throughput, network and so on and it's fully compatible with ERC-20 tokens. And there are smart contracts. It has some additional layers on top of it and their contracts are audited by OpenZeppelin. It's widely adopted, will be soon. And another player is uh um Phoenix What is it? For example, with Zama, they have a modified EVM that focused on confidential compute even on EVM level. But Phoenix working on another direction. It's like a additional tool, additional layer that you can bring on top of your existing unmodified EVM. It's like a co-processor, several lines of code, and you can use uh the same logic with uh fully homomorphic encryption, but you don't need to switch to uh the network uh to Zama, for example. You can add uh co-processor to any uh unmodified EVM network. And uh the last part here is uh mm uh trusted execution environment and TPC MPC uh I think uh mostly all know about it and uh uh let's uh move forward with uh another type of privacy that focused on completely different direction. Uh that's enterprise permissioning uh privacy uh where you have be able uh should be able to uh provide an access to uh the right parties, and the same time, uh you have to uh be be able to limit access to another party. It's not about anonymity set, it's mostly about uh super advanced uh role-based access, because you need from another side some uh disclosure, but another side, you have to have some anonymity set. And uh what we have on the market, mostly uh Zcash thing is uh one of the biggest player right now, and they provide uh Previdium uh node. It's uh uh one point here. You have to uh pay licensing fee, is very big. Uh and the additionally you have to pay for your private transaction even on your uh private hardware. But at the same time uh they can follow super strict uh institutional requirement uh and uh it it can connect can be connected to uh Mhm. Ethereum layer one and Prevedium uh not uh it's a private validium and mhm it's uh too complicated uh to switch for example to another network. For example, you have a your uh own for example on Hyperledger Besu layer one permissioned network and you want to add additional uh level of privacy and it too complicated to switch because uh ZK sync uh for focus it on uh public uh layer one as Ethereum network and anchoring there as a uh roll-up. And Prevedium is a like a layer three solution. And another player is uh very interested product uh uh is a Paladin supported by uh Kaleido uh blockchain as a service provider uh one of the major contributor and uh inside of Paladin we have a three different privacy domains. It's uh Zeta Penta and Notary tokens. Uh for example, for Notary tokens uh uh you use like a notary uh privacy domain and you can ex- provide observability for example for regulators or your operational needs uh but for Penta group it's a private programmable privacy similar with Adhara stack, but Paladin you are creating smart contract on Solidity and Paladin it's like a sidecar pattern to existing unmodified EVM network you you will have two nodes for each party, for example. Uh one node, for example, Ethereum or Besu or uh another node will be the Paladin. And additional, they have a zeta tokens. Zeta tokens is with this tokens nobody can see anything and even for regulators you can provide nothing. Fully you can create dark pool or what do you want. And the biggest problem with Paladin is still on early stage. Uh a lot of big institutional vendors evaluated, but we don't have public uh use cases in production. Mostly all of the projects still on the early stage. Uh and maybe even the pilots. And the last type of privacy is identity e-governance. Mostly focused on uh uh voting or authorization. And uh it focused on how to join, how to act privately during your necessary action and verify it. And the goal here is not to bring the anonymity. Uh the goal here is establish the verifiable uh privacy, um, but not anonymity set. Uh, and here, uh, we have a semaphore. It's, probably, the most mature and maybe even I can say, uh, the market standard right now. And, uh, you have a, uh, ZK group of membership, uh, there. Another product is, uh, Mochi, but when I prepared this, uh, presentation, I checked, uh, their current state and I found that, uh, recently, several days ago, they, uh, their GitHub repository has been archived and, uh, I don't see, uh, any public, updates, uh, what's happened here, uh, but before it, uh, was also like, uh, most mature solution and even Vitalik also supported it. And the last, uh, product is, uh, ZK passport. I think, uh, a lot of, people use it. For example, when you came to Devcon or something like that, you can use ZK passport. And right now, ZK passport is, uh, uh, default gateway for, uh, Aztec and that we already mentioned. And, uh, what else? Uh, how to choose? If you're building, uh, public DeFi, let's definitely explore, uh, Railgun as a default solution. And, uh, we'll see what will happen with Hinkal because it's, uh, on early stage, but, um, it's promising because it has, uh, viewing keys. And, um, um, also, as I mentioned before, uh, you have to avoid, uh, to building your, uh, private pools if you don't have, I don't know, million users, uh, million wallets, uh, that because, uh, private pools is have a dependency of participants. If you have a, uh, regulated business and consortium, uh, prevideo, a very interested, uh, product, but super expensive, &gt;&gt; [snorts] &gt;&gt; uh, and that's what I don't like and, uh, performance in some cases, uh, can be really not so good. Uh, and especially they use, uh, ZK, you have to use super big storage, uh, to store of that proves long time. And, uh, we'll see, uh, what will happen with, uh, identity for dapps. I recommend to explore Zama, uh, as, uh, one of the wonderful product on the market at all. And, uh, is it so? Probably. I'm ready to answer your question. &gt;&gt; [applause]
