# Antonio Seveso - One User ≠ One Address: Enhancing Privacy with Stealth Addresses

- Speakers: Antonio Seveso
- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2025-11-09
- Duration: 26:19
- Watch: https://streameth.org/watch/yt-PD3FJoohlHM
- YouTube: https://www.youtube.com/watch?v=PD3FJoohlHM

## Description

Blockchain users often assume a single identity equals a single address — but this paradigm exposes significant privacy risks. Using multiple addresses or generating a fresh address for every transaction significantly enhances privacy.

Stealth addresses automate this privacy practice by creating unique, unlinkable addresses per transaction, effectively shielding user identities. When combined with privacy pools, stealth addresses disrupt traceability and maximize transactional privacy.

This talk explores how these innovative solutions redefine blockchain privacy, offering a robust model for secure and private on-chain interactions

## Transcript

Hi everyone, I'm Antonio. I am the CTO co-founder of U wallet. Let's simplify this in this way now called Floyd key. And uh today we'll speak about how I see the future of privacy on any chain especially now focusing on EVM chains specifically touching a new technology that has been brought back to life by Vidilik on one of his post a couple of years ago. a little bit more. That was also a post that inspired us on building on this technology and will probably become one of the default ways for obtaining privacy on EVMS. First of all, couple of question to start and you will understand why these are important. Uh if I ask you what is an Ethereum transaction I probably guess that uh yeah maybe you don't give exactly the same word as a definition but we can come up with a definition that we all agree it's obvious what is an Ethereum transaction. No. Now if I ask you what's privacy I'm sure that we will never agree a single definition also because it it it's more like a broad concept privacy. It depends. Oh, if you ask that question to a North Korean person probably will say something that a Swiss person gives for granted as a constitutional right think about that as a privacy. Okay. So the environment what what's our goal what we want to reach define what is privacy for us and in this broad space uh you know privacy doesn't affect only um transfer of value monetary transaction and blockchain. Well, for example, on messaging, probably you all know this app is a signal sel whatever you want to call it is definitely the leader in privacy when it comes to messaging. Okay, even though the majority of the people use WhatsApp, forget about that. It's easier. It's a leader and has worked well since 2014, like more than 10 years uh out there of the leadership. No, again for messaging is pretty easy. Two parties and involved I need to message another person. They're just a very simple encryption, no data to be processed across a lot of node that must be synced and so on and so forth. But when it comes, it's much more chaos. First of all, there are many tools, but none of these is a leader in the section. But the part that scares me most is that any all of these tools are rarely used by most users. Meaning that average user uh transacting onchain doesn't um put privacy and a position that matters to him and rather just no use only one address and if I now want to transact with you and I know you in person you will be able to see all my past history and all my network at least on that specific address. Now how can we be obtain traversy today? There are two main ways of doing that. On the left, what's called privacy pools. It was tornado cashes was not a privacy pool, but just to give you an idea, that's the concept around that. Okay. A way to break traceability. So, I move money in, other people move all the money in the same contract and then this money goes out on the other side, but in and out are not connected. If I do it in the same second, yeah, I'm not super smart, but if I wait time, I don't know out of the money going out which connects to the money getting in. Okay, they're easy to understand. We explain a few seconds. UX is very bad. The user needs to wait a lot of time. There's a lot of multistep to do on that. Uh there is this thing called proof of innocence to prove that my incoming that mean my outgoing is not connecting to a malicious incoming transaction. Very easy from a mathematical perspective but try to explain that to a judge over a case. You will never understand that because there's a lot of math involved and it takes time. On the other side there are salt addresses. That's that's what we're going to talk about today. They provide anonymity uh privacy through unlinkability. Just keep in mind this word because goes against traceability and we will deep dive on the difference between these two words in the next slide in the next slides. It's compatible with any DAP. So ST addresses think about as an a regular address a lot of them all of them controlled by the same private key. But if you look at them from an a third party perspective from outside, you cannot see that the ownership is the same through all these addresses. Okay, it's not black magic. There's we will see how to do that later. They provide great UX. You don't have to wait time. You can interact with any DAP there. The recipient doesn't need to be in the same privacy pool you are also to transact privately with another person and so on. Traceability is preserved. I put in yellow because sometime is good sometime is less good that traceability is preserved and we will go also more in details later. So two ways stalled addresses privacy pools focus on stresses. Now this slide is you probably have noticed that I put bad UX. The majority of the users will never move into privacy if the UX is bad. And I tell you this other thing, forget about all the people that you know that are in the blockchain space. Go think to a person that uh in this space are it's called an army. Okay? Someone that comes from the regular normal financial world. Now if you tell them that uh in crypto at the like the default of crypto is no privacy, they would be like quite shocked because the advantage of going into crypto is self-custody. But in the traditional finance world, privacy at least intended that if I pay you, I don't know how much money you have. That's given for granted like every transaction has privacy. Looking from the eyes of a normie, let's call it in this way. No, inside crypto it's not. We have to build that into the system. So how does it look using stalled addresses? Okay, first of all, solves the privacy in a way that traditional ways of solving solving privacy didn't do. So the traditional way was hide hide the balance, hide the transfers. Okay, addresses plays with the rules of blockchain. Everything is visible. Each address is a regular address, but each users has an infinite amount of those addresses theoretically. Okay? So the user doesn't have all the balance on one place has the balance on a lot of addresses and then and you need a software of course to manage them the same way you need a wallet because I don't think any of us uh runs a row transaction on the blockchain use a wallet can be as simple as a meta mask but there's a wallet under that and so the privacy is obtained not for hiding stuff but for keep putting stuff every time on a new address. So if you pay me the payment goes to a new freshly generated address with no history and no balance on that. Okay. Then the money stays there. And we will see how to manage that because the the misconception is oh but then if I have to move all to my main address you see the money going all in the same place. No the money stays in all of these addresses. These addresses can be also smart account. This is what we do for example flute key and gives a ton more of advantages into that. In fact the management of these addresses you you obtain a great UX if you give a good UI. Okay there are other example of good UI for example umbra cache is another solution built on top of studios that does that. So assault addresses is a one-time address generated by the sender and this can kind of confusing it will go how how it works to privately send funds hiding the recipient's identity on chain. This is another important concept. Salt addresses protect the privacy of the receiver not of the sender. Okay? Because if I receive a payment every time on a new address I am the receiver. The sender can send from his wallet with everything visible. It's his problem, not my problem. Of course, if both the identities use addresses, this fragmentation of assets is shared from both the parties and also the sender is preserved. This is important because uh allows me that care about privacy that want to use to stealth address to receive money from anyone even someone that doesn't care about privacy and doesn't want to segregate his found or use a new wallet that implement this uh technology with this parenthesis around UX and was I had to do that okay on the why user experience is important how that can be solved I bring back the promise I made you before speaking about Unlinkability versus untraceability. Now the unlinkability is enabled by ST addresses. Unlinkability means I have money on a lot of addresses that are not linked together. Okay, it's fast. Again, spinning up an address is milliseconds. Uh it's compatible with any counterparty, any smart contract on public EVM chains. This means that if with one of these contract I want to borrow something I can do with a privacy pool it's it's enough if I can trade any tokens year situ specifically okay it doesn't break traceability sometimes it's an advantage we have customers saying oh we like that because if my funds get mixed with malicious funds it's a mess in this way my fund stays only in addresses that I receiver control never gets mixed with others shielded pools on the other side are slow takes time you know you have to put money in and wait a little bit of time there's a limited set of operation like some of this now brings uh NFTs but even that the NFT is an ID connected to him it's very hard to do that but breaks traceability this means that uh if I want to uh break the traceability of a million dollar payment I received they are perfect and we will see how these two concept and that will be at the end of the our speech are instead a lies okay but at the moment we will focus on start addresses addresses is a concept um it's like I don't know if you're familiar with hashing okay also hashing is a concept now how do you implement hashing there are a lot of different hashing functions in the same way there are different ways of implementing salt addresses the concept is that the user must have one key and control a lot of addresses with that key while onchain not having this connection directly visible otherwise you merely understand who is the owner of all these addresses. Okay, the the left way was the first one was the one that Vidik brought up is part also of an ERC the 5564 and it requires only elliptive curve cryptography very simple very intuitive as just one problem not ideal for key rotation this means that you start with a key and you always have to keep the key the day that key is compromised you cannot use anymore the day you want to use a multisig you cannot rotate keys in a multisig And this is the big problem that comes out with this the most modern way and this is there's nothing in production. We are actually uh working on P and try to bring that in production as soon as possible was also that a suggestion from Vidik that came like less than a year ago was using uh the zero knowledge technology and key stores and uh it works great with multisk also with pass keys. It has a lot of advantages. It just requires a key store and we'll get into the details later. But key store see as a place where you know this key that I want to use to control all the addresses I store in that place and then with a zk proof I control all the addresses. Later we will deep dive into these two. I think the easier one to to understand at the beginning is the elliptic of cryptography. Okay. So how does this works? The user has a private key we say before. Okay. If you and this is again elliptical cryptography if you multiply the public key the address basically the public key sort of of the user that's public anyone can see that also the sender for a secret. Think as a secret as a large number a number so large that cannot be guessed. Okay. you obtain the public address of the recipient. Now this secret needs to be sent to the recipient. So the recipient can use the same secret to multiply his private key and obtain the private key that controls the same address. So in this way anyone can generate an address that only I can control because the private key is never shared with anyone of course. Okay. Now how this number is transferred between the generator and the receiver. This is part of the ERC we said before different ways. You can public encrypted on chain. You can either trust uh trust the third party to generate this address for you. Okay. For example, flute key. This is how it works. It's the way it generate the best privacy. You have a as a fluid key user, you have an ENS name that use a technology VNS called offchain resolver that allows us to every time that ENS is queried generate a new address. It's something not so famous about that, but the address is never published on chain. Okay, but it's connected to an ENS. So if you pay me, just put my ENS in your wallet and the new addresses pop up. If two people do the same, two different addresses pop up in the addresses and flute key acts as an indexer for the end user. So the end user in his UI will see the balance as if it is in just one single address. Instead under the hood, there are payments going every time to a new address and each of these address generated has an associated secret when the user wants to send money on his client. So fully self-custodial we provide him which is the secret of the address and he can move the money of course through our UI. Okay. Uh that's the simplicification we do. Privacy I bring on the concept again must have a good user experience. Friction must be reduced not added. This is why we use ENS because if I if we I was asking a user to have the sender generate the secret. Okay, you need a sender with a PhD probably to that or just for force the sender to go to a specific page. We don't want to do that. Just use ENS. We want users can they keep they should be bring their offchain habits on onchain. So give a way for them to do uh wire transfer, sip transfer, visa payments directly from their account. This is for example what we do with with flute key. Okay, you can just do a bank transfer right from your uh flute key account or you can receive money like there. But and self custody makes a difference. Privacy is expected for a regular user. This means that uh when it's privacy expected uh they want probably to go in some sort of st address generation and they will say oh I love it okay but what if I want to rotate keys because I've lost my previous key I I want maybe a setup that allows me recover keys or something like that because again users are used to go to the bank and just ask them for change them And uh when they ask with a system of stalis you just show before can I rotate keys the question is no okay but but there is a solution and of course the solution is the god of everyone that's zero knowled technology and uh this is very simple what I explained you before how sto generation with zero knowledge technology works there is a place that's called a key store where you store the configuration. Now think about a multisig. Usually you keep the configuration in the multisig. These are the signers. The configuration stays instead in this store and the safe deployed points to a position in the store. Now if this pointing is visible, everyone will see all the addresses that I've generated. If instead in the safe there is what we called a start in it that's the hash of the position and the secret the same secret generated before the standard is the same you generate a random number that you need to share with the other user. Now this hash hides something that can be proved in a zk proof but cannot be reversed. So I cannot see who is the owner of that safe, but the owner of that safe with a zikk proof can control that safe and move money out of that. And you have an infinite amount of that with a benefit that if you change the key in one place, all the addresses you have will change instantly the configuration because changing this position will if we want to be in details change the root hash and changing root hash makes the pass configuration no more valid. Uh I know it is one line. I can speak one hour on that. Okay, I just want just to give you the concept of how stealth addresses can be generated in two way and this is the future of of stealth addresses. So to sum up what's the future of privacy into that? Well, I think that the future and and this connects me to one of the before is the combination of unlinkability and traceability where each of us has not one address as a yes he thinks he has one wallet but 100 there are a lot of addresses and every time I want to break traceability because I've receive a lot of money because I receive money that I want to show who I pay to where this money is coming from or whatever I just have this money going through a shielded pool and go back again into one or more st addresses always controlled by me. Okay, so the shield pool as a mechanism hidden in the wallet with great UX to break through ability and then to bring it back to ST addresses. So how can you help in this space? Well, if you want to use flu, it's free and uh um we call it a a kind of onchain bank in term for the UX it gives. It's fully self custodial though because you can you want to share feedback and make sure to uh spread the word. This is the QR code if you want to go on flu key. This is the team that's currently work on you can follow us on flukey same handle Twitter forecaster telegram or flukey.com and uh thanks for listening and if you have answers I'm questions I'm yes to answer. Thank you. Thank you so much. Thank you so much Antonio. I see that one question came in during all this and you did it great and it lovely with the little power of insecurity because I use multi-chain myself many times difference. So isn't fragmenting address of funds reduce UX? &gt;&gt; Say it again. Sorry. Isn't fragmentmentation of address of funds reduce UX and efficiency effecty of things we can't do in DeFi instead of borrowing capital efficiency in unis swap a a etc compared to having it all in one address. &gt;&gt; Yeah. Uh so um a great question. Uh first of all for everything you do um like the majority of the things you do no because these addresses for example looking at fl key as smart accounts. So if you want to pay someone we compute the most privacy preserving path of taking your funds from your stealth addresses and do that operation. Now specifically in the question they were asking about borrowing be um because lending it works for example in flute key we have a function called auto earn the addresses generated are generated with already a module inside that's a permissionless module that allow us to move your money into an a or more lending pool what does it mean as soon as you receive USDC you don't even have to open the app we automatically spin up the smart account for you and move the money into Morpho, you will keep seeing them as USDC, but they will uh earn yield for you automatically. And if you need them, it's instant. You can move money back. When it comes to borrow though, there's one address in charge of that. And until the protocols will start allowing through ZK proof to have multiple addresses controlling one position, still not possible. The only solution is either or move the money to all one address reducing a little bit of privacy or using the ZK uh or the still privacy pool solution I was showing before. So yes, one address is in charge of borrowing, but you can uh feel put more capital into that address passing through a privacy pool and breaking trace stability. And actually this is what we're working on with rail gun to get a great UX into this setup because the end goal will be keep the same capital efficiencies as you have now with one address of course. &gt;&gt; And we got just got another question in. What do you think about privacy focused blockchains like Aztec for example? &gt;&gt; The uh problem I see is that uh the uh solution is great. By the way, all the ZK circuit are built with that we are building with noir that are that is uh created by ATC. So we are very close to them. We speak a lot about this topics. The risk we see is that will take an infinite amount of time and effort to move the capital to that chain. Okay. So as today still the most liquidity stay on mainet regardless the amount of work that was done by L2s to bring that capital into them you know and bringing even to another chain we see that as a huge fragmentation. So what I see is like more these chains as a pass through or maybe the source where you store your key store and that key store gets then propagated through other chains. So a roll up to support privacy on chains rather the chain where the uh all the privacy will happen. Okay, that's my personal vision on that. &gt;&gt; Well, thank you Antonio. Do you have any more questions from the audience sitting here before I have a very annoying one? No. So I have a very annoying one because I work a lot in web three uh in the communities and I deep dive into wallets. So you change say you're changing the address all the time because every time I look into it at one point two or three wallets out you find a connection back to another wallet again. Is that something you actually doing? So you cannot track through multiple wallets over time. &gt;&gt; So of course we don't break through ability. So if I provide you three four wallets and you and you go back in time probably with a a Dune dashboard some something like that you can find if there's a common source of through I was speaking about that that with the with the CTO of Dune the other day know and we're just saying about that uh what I think is uh probably for the communities is the right approach for example with in flu key we are dropping a score token to one of the many addresses the user have and that can be farmed over time has no monetary value is not transferable. Okay. But this can be used by users to prove you that they are valuable user because they have a high score. This means they have like kept a lot of money for a lot of time in fluid and so on without saying you how much money they have and how they have. So that can be like a way for communities. We got contacted for airdrops like okay just give me which are your valuable users and you can airdrop them because we know they are real users just not the fake users without asking them to provide to share the whole net worth to to us. So yeah &gt;&gt; that's perfect. I just want to ask because I work with airdrop hunters and they always make that one mistake at one point they connect the the multiple wallets when they put into an exchange or when they go into somewhere there is a connection in there. That's where I find them all the time and I love that. I use 16 hours on doing that sometimes. &gt;&gt; Okay, makes sense. Again, spinning up every addresses of course allows users to have a lot of wallets, have a lot of different identities under the hood. No, that's kind of also what we want for privacy, you know. So, yeah, I think that the right solution is always in in the between uh of the two. &gt;&gt; Well, thank you, Antonio. Do we have any more? Because we are going into the next segment very soon. We have a little four-minute break. Again, thank you Antonio. big kind of a boss. Thank you.
