# Exploring Flavors of Private Decentralized Exchanges | Adam Gagol | Aleph Zero | ETHDam 2023

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2023-10-07
- Duration: 16:05
- Watch: https://streameth.org/watch/yt-dD3zptMRm6c
- YouTube: https://www.youtube.com/watch?v=dD3zptMRm6c

## Description

Adam Gagol is a co-founder of Aleph Zero. 
https://twitter.com/GagolAdam

ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. 

Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants.

ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: 

CryptoCanal https://www.cryptocanal.org/
CryptoCanal Twitter https://twitter.com/CryptoCanal
Join CryptoCanal Community https://t.me/CryptoCanalCommunity 

We would like to thank our partners and sponsors that made this event possible. 🌷
Our BFF 1inch https://1inch.io/

Our Frens: 
Sismo https://www.sismo.io/
Aleph Zero https://alephzero.org/
Scroll https://scroll.io/
RAILGUN https://railgun.org/#/

And our Sisters:
oasis.app https://oasis.app/#earn
Maven11 https://www.maven11.com/
bitvavo https://bitvavo.com/en
Lido https://lido.fi/
Spankchain https://spankchain.com/
API3 https://api3.org/
Gelato https://www.gelato.network/
VanEck https://www.vaneck.com/nl/en/crypto-etn
Marlin Protocol https://www.marlin.org/
Silent Protocol https://www.silentprotocol.org/
Cyber Capital https://cyber.capital/
… and Proto https://twitter.com/protolambda 🍍

## Transcript

foreign [Music] audible right now I think so great um okay so I'm Adam from Olive zero and I'm gonna talk about um private dexes first I'm gonna introduce the challenge with and provide some background on on definitions then do a very very quick overview of current approaches and I'll Finance with our own take on on private order book so first uh like conceptual definitions here so where is the difference between anonymity privacy and pseudonymity pseudonymity is basically what we kind of have as given in most of the blockchains means that we don't usually write our own name ever we rather have addresses which are serving as a as pseudonyms so of course it this is how it works on bitcoin this is how it works on ethereum and most other chains uh so whenever there is an on-train transaction we see just that some some tokens have been sent from one address to another and of course there is the entire business around tracking with addresses and assigning to individuals when there is the next step which is called anonymity and then if we have Anonymous protocols for example shielded transactions on zcash um tornado Cas Nova and railgun or us then what what is seen on chain is um either what happens let's not not or sometimes this is concealed but let's say that it is seen what action is is being done it is not seen who who initiates the action and there are various flavors here sometimes the value is also uh also concealed sometimes the type of token is also concealed but this works mostly for user to user interaction and privacy is uh basically considering everything so the only thing that is visible on chain is that something happened no one knows what happened so how usually the solutions are built is that they are using something that we call Shield their primitive and the name originates from from shielding transactions on zcash and this is basically the same thing that that multiple products right now are implementing uh so if we have uh like this graph of value transfers where Alice is sending some tokens to Edgar which is sending some tokens to Frank and so on so on where you can use different addresses but still these transfers are trackable then we may have like this specific special special box here where some transfers are happening inside but there is some cryptographic magic but I'm not gonna explore during this talk which allows uh these things to be considered so what's seen for the outside Observer is that well some tokens have been deposited to this crypto magical thing cryptomagic award and then something happens inside maybe and some talkers went out of it so it's a very big privacy pool uh and from for the outside world it's actually seen as a one super user so so um tokens of all the users which are using this this primitive are are mixed together we have our own instantation of this is called shooter um and one of the interesting things that can be done with the children not only ours also for example railgun is working on very similar solution is it is possible to initiate a smart contract interaction from inside of the cylinder so then how it looks like is that we have a normal transparent public decentralized exchange it may be for coffee swap or actually the original uni swap so we initiate the transactions from from inside of a shielder so so it's it goes out of the shield there so everyone can see that from the shoulder the transaction for for example one eater have been initiated it has been changed on the decks for let's say 1800 die and then it goes back to the shoulder so that's the information that the entire world sees what's not seen here is who actually initiated in this action so there are multiple users of a shielder and they are effectively mixed together um so this gives us Anonymous exchanges so as I'm referring to the slide before it's not private because everyone sees what actually happened and no one sees who initiated it so no one sees uh who who was a Trader um and once again this is just a regular text it doesn't need to be like privacy enhancing decks or anything like that actually there is already privacy enhancing enough to to be able to to integrate with with normal D5 so right now the challenge that we're uh that we're tackling is actually is conceiving this thing so what happens uh here it's not private and it's actually it will be nice to to have it private especially in case of order books because oftentimes when the order comes to the exchange it is published it's uh causes a market to react even before it is starting to get filled so what we're trying to do is to create such an order book where anyone can put the order but without causing Market to react instantly and it prevents order from training and and things like that so mostly these are economical uh positive consequences of considering this as anonymity is something that we had anyway there are two flavors of uh of doing this right now so the first one which is perhaps more straightforward is peer-to-peer so these are protocols such as for example Renegade finance and they are based on the idea that the trader which is uh trying to swap exchange some tokens he's connecting to other potential potential Traders and running some kind of a private protocol to see whether they are a match in the sense that they can trade with each other so they initiate like cryptographic Tinder like interaction where like if they are willing to trade opposite sides of a pair then they get informed about it and they actually initiate this private private Swap and if they if they do anything else they they don't doesn't learn anything about their intents they they just well they just see that there is no match so it's good because it's full privacy at least in theory I'm gonna say a sentence about the 18 moments but it's slow and expensive so basically user who wants to trade anything needs to be constantly online and constantly connects to this other peers searching for for the matches for this particular trade and so what actually happens in most of the protocols and specifically in the inverena gate is that these Traders are are having three layers which act on their behalf so so there are specific parties called three layers and Trader needs to reveal all their intentions to vary layers so here we are sacrificing some privacy because this relayer network they do have information about all the orders but well the user experience is unmeasurably better because users doesn't need to stay online at all times uh so it's kind of adjustable level of privacy uh but the protocol in any case is pretty slow and there is another way which is let's say aggregated reveal way and the idea here is that we are having the orders encrypted but then we are creating batches of this order and we are decrypting the entire batch so this is uh connected to the concept of differential privacy in a way so the individual order or individual intent of a single user is never revealed the only thing that is ever revealed is the aggregated intent of bigger group of of users um so it definitely offers better ux in the sense that user needs to do just one action and generate some cryptographic think on chain and that's when this thing will be processed by the system it's much faster and this case is much better because in the peer-to-peer Network the more peers the longer you you need to wait for for your trade counter party this this uh this approach doesn't have this problem um it has limited privacy in the sense that well yes it does reveal the entire batches it can be some improved by by some heuristics for example it's uh possible and pretty cheap to to just put fake empty requests into the order books of the actual order book is made up of mostly empty request and just fuel non-empty ones so when the each of the Aggregates is pretty big with only few actual users but well anyway it's definitely privacy is more limited than in peer-to-peer with perfect perfect model it's good enough to to provide this economic benefits well so uh the last thing I want to show is our like our kind of architecture or the the draft of our architecture as in in fact system is a bit more complex than what's written here so the idea here is that anyone who is keeping the tokens in the shoulder in this cryptographic black box can create order out of it so if someone had some usdt investigator the user can freeze this usdt associated with the order we order specifies the price at which it should be cleared it it has concealed value so no one can see whether it's an empty order or very big order nothing like this can be seen so first entire on-chain order book of such value encrypted orders and then the system proceeds as follows there is a price Oracle required so the system queries the price from Price Oracle and basically chooses the orders which are kind of possible to be filled in the in the current market conditions so the orders which are saving usdt at a good enough price or buying it is also a good enough price so these things they are encrypted on chain so this is homomorphic encryption and they are aggregated into into one batch so the one batch is like very let's say in this example two orders so they are aggregated into one request which has just the sum of the values and free requests from the other side are aggregated into one where they also have just some of the values then this is the only thing which gets ever revealed in this system which is about aggregated batch so now we see how many tokens are meant to be traded one way and how many are meant to be traded the other way then there is this is interesting economic optimization where actually doing in batch trading like inside trading is the best thing that can happen to users because this is outside of of the normal markets so no front running can apply here and users are exchanging tokens at perfect prices because they have are have been just much to the counterparties and the rest of this is just regularly traded and goes back into the shooter so uh like summing it up uh the entire flow is that the user puts value and encrypted request and just Waits until it is traded the request itself is never revealed the only thing that is ever revealed is the entire batch into which the trade was aggregated so um and well the trick here which well the Privacy by by like academic standards it's not perfect although it's technically pretty easy to actually obfuscate this order book by placing multiple empty orders at every every price which is close to the current Marketplace so like every batch will be actually filled with orders where well uh unknown amount of them will be will be actual user orders and it has this economic benefits of adding this privacy that that some of the orders are in batch so they are just matched with the counter parties at perfect prices um so that's all for the talk if anyone has any questions I would be super happy to uh to address them [Applause] thank you very much there's no questions on slido but if there are any questions please raise your hand we go old school you have one in the back which one oh there you go does shielder have any compliance features does it have compliance feature that's a very good question uh so right now we're working on uh zero knowledge ID system so basically we are focusing very much on ID that is user controlled so we will not have like a any kind of master key where any third party can reveal anything uh what we want to do is to allow users to produce proofs such of statements such as I never did a deposit from any of these addresses which are on on chain let's say Blacklist or sanctioned Oracle or things like that so right now the protocols for doing non-inclusion proofs like snark proofs are are getting much better so so this is the solutions that we're that we're following rather than having this kind of master key so the answer is yes cool um so you can put the order at any moment and like there is a continuous process of of batch aggregation so uh like there are just few predefined moments like there is a moment where the batch is finished and then revealed and then there will be there's actually um economic mechanisms of Dutch auction in in clearing the the badge so it's it's going for several blocks we are um layer one so we have a very low block time uh one second so in general like the entire batch production can can fit into below 10 seconds and together with the auction and like placing the orders into your their book can happen at any time it's just like if you do it at the time the auction of the previous batch is proceeding you're gonna wait like few seconds more for for the order to be uh to be included in the batch but uh like from the user perspective you you don't need to care about when the the batteries are getting aggregated cool any more questions this is the last chance okay well thank you very much thank you very much [Applause]
