0xBow | Privacy Pools in production - Ameen Soleimani | ETHDam III - 2025
CryptoCanal·Tue, Oct 7, 2025, 12:00 AM
Speaker
Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo. 🌷 https://www.ethdam.com// 🌷 ------------------ 0xBow | Privacy Pools in production - Ameen Soleimani | ETHDam III - 2025 🎤 About the Speaker: Project Leader @ Privacy Pools. Advisor @ 0xbow. Summoner @ MolochDAO & IranUnchained. Co-founder @ RAI & HAI. CEO @ SpankChain. 𝕏 Follow: https://x.com/ameensol https://0xbow.io/ https://x.com/0xbowio ------------------ About ETHDam & CryptoCanal ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance. ------------------ 🎥 Credits: Intro / outro by babyPRO - https://babypro.art/ ETHDam Photography by Paulus – https://concretestate.eu/ ------------------ Special thanks to our partners who made ETHDam possible: 🌹 Hackathon – Bouquet: Oasis Network https://oasisprotocol.org/ 🌷 Hackathon – Petal: Circles https://aboutcircles.com 💛 Conference – Gold: Zano https://zano.org/ Dash https://www.dash.org/ Bitvavo https://bitvavo.com/en 🩶 Conference – Silver: Igra Labs https://igralabs.com/hero 💛 Conference – Copper: Lido https://lido.fi/ DeTrip https://detrip.travel/ Cake Wallet https://cakewallet.com/ The Grid https://thegrid.id/ Calimero Network https://calimero.network/ 0xbow https://0xbow.io/ Mina https://minaprotocol.com/ JobStash https://jobstash.xyz/ Cyber Capital https://www.cyber.capital/ POAP https://poap.xyz/ Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 🌱 Sponsor: EF Ecosystem Support Program https://esp.ethereum.foundation ------------------ 0:00 – Opening & Context: Why Privacy Still Matters 1:14 – Historical Warning: Surveillance and the Holocaust 2:00 – Tornado Cash, Alexey’s Case & Legal Injustice 3:41 – Support the Privacy Developers 4:28 – Privacy Pools Origins & Paper with Vitalik 6:42 – How Privacy Pools Works: KYT, Whitelisting, Rage Quits 10:28 – Live Demo: Deposits, Approvals, and Withdrawals 13:32 – Non-Custodial Design & Immutable Privacy Guarantees 17:01 – Smart Contracts, Permissions & Immutable Pool Logic 20:55 – Roadmap: ERC20, Yield Support, Multi-Chain, and StarkNet
Transcript
Welcome to [Music] East. Thank you for the introduction. Uh my security tip is never check your email. Uh from the last panel. Uh thank you for having me back.
Uh honor to be here. Uh the last couple years that I got to talk to this crowd, I talked about the product that we were about to build. Uh this year I got to talk about the product that we have shipped uh last month and it's way better. [Applause] Yeah. Um so uh before I go into this, so I'm Amin Solmani.
I'm the CTO of a company called Oxbow. Uh we do uh onchain privacy but without the terrorists. Um so why privacy? Uh want to ground this conversation and uh some sort of real stuff. One of the things that this actually applies to the Netherlands uh had the highest casualt one of the highest casualty rates during the Holocaust because of their civil surveillance infrastructure.
Uh and the the lesson to learn from this is that you don't always know who is going to inherit the systems that you build. Uh and so you might want to design them in a way that also limits your power uh over the people that you are for example governing or building for. Um, this is a quote tweet of Ryan Shawn Adams talking about the day that Alexi lost his court case uh and was sentenced to five years in prison. Uh, Alexi is currently out on bail. He's here with us.
Uh, it's always an honor to see him. Um, but this is what happens when you prosecute developers for the crimes of their users. Uh and one of the judges in the case uh said that there is no uh positive use case for tornado cash. I was using it for payroll. Vitalik was using it to send money to Ukraine without the Russians knowing how much money he was sending.
Uh and so we disagree with that assessment. And part of the motivation for the product and the company that we have today is to show that you can have p, you know, privacy for the good guys. Um, so the fight for privacy goes on. Um, Alexis Perzv is uh having an appeal trial. Uh, we'll find out more about that in June.
Uh, Roman's trial in the US is still pending as well. Um, just last week there was a EU announcement that they're planning on banning uh anonymous crypto accounts and privacy coins in the next couple years. So, it's important that we continue to fight this in the courtrooms. Uh, and even though you know Trump is elected and regardless of what you may think of him, he he did free Ross, but he hasn't freed Roman yet. And uh we're you know it's not over till it's over.
And there is some at least progress that has been made on that front. And that is uh one of the memos that was published by the Department of Justice uh last month about how developers should not be held liable for the crimes of their users and that any court cases that are ongoing that are not aligned with this memo should be dropped but they have not yet been dropped. So, the fight goes on. Um, take a minute to shout out Alexi. So, if you uh can if you want to uh support him uh and his legal defense, um we wantjusticedow.
org or you can go to juicebox.money and buy an NFT. Um, I'm not saying that there will be ever a token or that, you know, if you, but if you were going to hypothetically do an airdrop, uh, the people who supported the legal defense fundraiser would be great people to support in any future community building exercise. So since the tornado cache program was sanctioned uh we tried to figure out a way to do this uh without having North Korea end up being a power user of these systems. So I published this tweet uh a little over two years ago at ETH Denver.
Um and this was about privacy pools. Uh the first demo that we launched uh it's been a little bit of a journey since then. Uh we I wrote a paper with Vitalic uh about privacy pools. This concept it got published went to Basil in Switzerland. We uh co-wrote the paper with the guy who runs the blockchain department at the University of Basil.
And so we got to present it at his blockchain conference to a bunch of Swiss bankers and central bankers. Uh which was cool. The Swiss really like privacy. Uh they do not agree with the Dutch judge that uh privacy has no positive use cases. Uh I think we should try to build for the communities that appreciate uh privacy and uh conclusively demonstrate that it does have positive use cases.
Um privacy pools is a uh iteration evolution on the tornado cache compliance tool. Uh they don't get enough credit for this. The tornado cache team themselves built a compliance tool. It allowed you to use the secret note that you get when you create uh a deposit into cache to prove which specific deposit belonged to you. Uh this way if you go to a financial institution or Coinbase or whatever uh and you don't want to reveal onchain which deposit belonged to you, you can say hey look I can privately prove to you that this deposit belonged to me.
Uh and so you can think of this as a very you know specific thing specific form of what privacy pools is. Privacy pools is the idea that you can prove you know a subset of the deposits that you uh are or are not. And so that way you can do it on chain without basically showing exactly which one you are. So in order to uh figure that you know manage this we have a company our company is called Oxbow. Oxbow manages the approval process.
So, anybody is allowed to deposit into privacy pools and we make sure that we identify the illicit funds that are attempting to uh deposit into it and then we only whitelist the funds that we consider legitimate. We launched this last month with a one ETH limit. So, deposit while we battle tested our system and we removed that deposit limit today. I am the first person to deposit 100 ETH into this thing. I did so like an hour ago sitting over there.
So uh yeah, I hope I hope other people do too. I'm not like the only one because uh if you deposit 100 ETH, you know, if I went and then like you know, everybody else has only deposited one ETH, right? So if I went and deposited two ETH tomorrow, uh clearly that's me. uh if I deposited one if I withdrew one ETH then I could be any of the other people uh that also deposited one ETH. Uh I'll I'll explain more about how this works in a second and um yeah so it's open for business and we have onchain privacy without the terrorist.
So the way the system works is users deposit they wait for approval. Uh Oxbow does KYT stands for know your transaction. Uh so we do transaction screening. We see where the money is coming from. If it comes from a, for example, reputable KYC exchange, we'll probably accept it.
If it comes from, you know, Vitalic.eth or people with a seemingly uh public transaction history, we'll accept it. If it comes from known hackers, we won't accept it. If it comes from other privacy protocols that are not necessarily up to our standards of compliance, we won't accept it. sketchy crosschain.
No KYC dexes won't accept it. Um, and so after we have vetted the funds, we approve the money that we want and then we publish a Merkel route of the association set and we update that periodically on chain. And that way users can prove uh that they are on that list and they're allowed to withdraw privately. They have to prove that they are on that list to to be able to withdraw privately. But if they are not on the list, they don't get accepted, they get rejected, uh they can still rage quit.
Raise your hand if you've heard the term rage quit before. All right. Like half of you, more than half. Yeah. Okay, cool.
It's good. I I helped popularize this term in the context of Mollik Dow. It was a term for being able to essentially permissionlessly take your money out of a DAO without needing to ask the DAO for permission. It has the same definition in this context. It just means that you can withdraw your funds.
Uh and no one can stop you from doing that. Um partial withdrawals are supported and so this is a nice UX feature. So you can deposit a 100 ETH and it's not like tornado cash where you can deposit one0 or 100, you know, and then withdraw 100 or 100. I don't always want to pay somebody one 10 or 100 ETH. So uh now I can deposit 100 ETH, withdraw one, withdraw three, withdraw five, you know, I can do any combination.
The rest of the money gets redeposited and the redeposited money references the original deposit and so uh Oxbow can still kick out your app your initial deposit later and any funds that you still have in the pool are then forced to rage quit. And when you rage quit, the money goes back to the original deposit address. And so that it does not look provide you any privacy. Uh now I'm gonna do a demo. Let's hope it works.
It's always risky doing a demo, you know, in front of a crowd. Can you guys see this? Yeah. Okay. So I'm already logged in.
Uh and so you basically have a seed phrase. uh instead of needing to have a note for each deposit, it's all stored on the single seed phrase. And so I can uh deposit I'm going to just do one ETH for now. Uh and just for the sake of the demo, show you how it works. Um one thing to note here is that the fees are added on top.
uh we have a 0.5% vetting fee that gets paid even if you get rejected. So, you know, uh as a dis, you know, to dissuade people who are probably going to get rejected from trying to deposit lots of money into it. And um the reason that we add the fee on top is because if we took the fee out of it, I would end up with.995 ETH in the pool.
And then if I withdrew 0.995 ETH, you would all know that I've deposited one ETH. Uh and so that would limit my anonymity set. But if I deposit uh one and the fees get added on top and then later I withdraw one. I could have been anybody who withdrew who deposited more than uh one.
Your anonymity set is all of the deposits larger than your withdrawal. So I click deposit. Uh it's going to confirm using MetaMask. It's going to process the deposit. Hopefully gas isn't too expensive right now.
You know, seems seems like it's working. And so now I can see that I have uh a pending transaction going into the pool. I have already gone ahead and deposited two other ETHs to show you guys how this works. I approved one and rejected one. Typically, that's not going to happen where the same deposit address has one deposit approved and one rejected.
But, uh, this just shows that each deposit is vetted independently. Uh, you can, for example, deposit money and then later deposit other money and then we realize that we shouldn't have deposited, you know, or accepted it in the first place. But what we would typically do then is uh reject all of your deposits, not just the latest one. So first let's show the happy case where I try to withdraw. I can withdraw my one ETH.
I'm just going to withdraw it to another public address that I have and it will generate a zero knowledge proof. Uh, this proof is proving that I have valid money in the pool that is unspent and that is on the latest association set published by Oxbow and that the amount that I'm withdrawing is not more than the amount that I have. Uh, and so then I hit confirm and it's failing because it's saying the gas price is too high. Uh what is the gas price right now? Gas price Ethereum.
It's set to like a two gay M five way. Yeah, I'm blown. Uh so the gas price is too high right now. We are fixing this. Uh right now the problem is if you can see that the fees are 0.
001 ETH because it's set to 0.1%. Uh they're not dynamically set. Uh what it should do, what it will do soon uh is it will basically charge me a 1% margin on top of whatever the gas costs. So if the gas costs five guay right now, that's means this would cost me I don't know something like $5.
And so it's going to charge me $7 because it's going to charge me that $2 on top of the $5 and then and then I'll be able to withdraw. So, um, we'll we'll come back to this, but when it comes to rage quitting, you send the transaction yourself from the address that you deposited from. And so for the money that has been declined, uh, I can't withdraw it and but I can click the exit button. Uh, it's it's called exit in the UI, not rage quit, unfortunately. And so I can click this and it'll pop up MetaMask because I'm paying the gas and it says that it's going to give me one ETH.
And once this uh is processed, then I will have received the ETH back to my depositing address. Uh and so that has exited and I can do the same with the pending. So I don't have to wait for it to get approved or rejected. I can still exit money that is uh in flight, you know, pending being accepted. Uh and so together this combination uh where I can withdraw my money at any time that makes the system non-custodial.
Uh so Oxbow cannot move your money. We can't freeze your money. You always have custody of your own money at all times. Uh, unless the gas price is too high and then you No, I mean I I could still exit it, but like it's just I I doubt it's gone down from from five. Yeah, it's still okay.
Uh, well, that's it for the demo. Um, thank [Applause] you and then I'll go back to this presentation. Uh this is just repeating some of the stuff that I said earlier. Um when you design a system like this, it's important to think about what privileges the admin has, how they can be used, how they can be abused. And so in for example an emergency scenario uh Oxbow could nuke the whole association set of approved uh deposits that are allowed to withdraw privately and say nobody is allowed to withdraw privately.
Um and all the users still have control of their money. They can uh rage quit. And what we cannot do uh is retroactively deanonymize withdrawals. And so this system does not create a honeypot of uh you know financial data once you have been approved and you have withdrawn. There's no way for us to go back and say this you know withdrawal uh is like corresponds to this deposit.
So we have a button where we can prevent future deposits to the pool. uh we can kill the pool, but we cannot freeze or move the users funds that are already in the pool. Uh and so the users have, you know, still have the ability to rage quit and take their money out. Um we can there's two smart contracts that uh make the system and one is called the entry point and the entry point corresponds to like control over setting the fees. So we can update the fee schedule.
Like one thing we plan to do is maybe at right now it's like a 0.5% apply to everybody. You know if people deposit a lot we might want to have uh lower the fees for you know uh high volume users in the same way that exchanges have like you know volume discounts. Um that would be something that we would upgrade the entry point to be able to do. uh as well as the relay function if we want to for example add the ability to use uh account abstraction relayer network for uh relaying instead of like a specific relayer.
But what we cannot do is upgrade the privacy pool contract which holds all of the users funds and implements the rage quit function. Uh that is immutable. It's going to be the same until the end of time. uh and that is part of what contributes to making the system non-custodial. And so it is permissioned, but it's not permission the same way like Tether is permission where it has a blacklist button that can freeze all your money.
Uh it's permission in the sense that the privacy part of it is permissioned. um but you still get the privacy and this is the trade-off that we implemented uh in order to satisfy both our compliance requirements or legal requirements and create a system that cannot be essentially tainted by North Korean hackers trying to steal everybody's money and then uh launder it through you know systems that uh would then associate with everybody else. So this is the evolution of the tornado cache compliance tool and this is how we have onchain privacy but without the terrorists. So we have some future plans. We plan to add ERC20 support.
It's already there in the contract level circuit level. Uh just need to add to the UI and update the relayers. Uh one of the things people seem to want is uh yield bearing tokens because you want to keep your money in the pool for a long time. You want it to be earning yield while you do. It works out of the box with like a USDC or you know like wrap stake teeth and and things like that.
You can also even tokenize like LP positions and throw that in the pool and anonymize those too. Uh we want to add smarter relayer fees. Uh you guys saw this demo, you understand that part. Uh need to dynamically respond to gas prices. We want to deploy this on all the EVM chains and also add uh none EVM support probably Starknet first.
Uh we're rewriting this in Cairo. Uh same uh compliance system just uh updated contracts circuits still work. So we have some ideas for V2, but first we're going to just roll with the system that we have. and um yeah, there's fun features like you can do swaps, keep the money in the pool and uh have an account system. So right now every single deposit you make is like a separate account.
Uh you might want to have like the deposit address be an account and then be able to merge all of your money corresponds to that. You might want to have balances in all of the different tokens uh without needing to like deposit each token separately. So, uh, these are all things that we'll we'll be working on. Uh, we are hiring. Uh, please join us if you're interested in this kind of thing.
We're building privacy for the good guys. Follow us on Twitter. I'm Amin Soul. Uh, this project is called Oxbow and, uh, privacy pools. Uh, thank you.
Who knows what this is? PG. Uh, this is what's called an oxbow lake. Uh and so what happens is that the river goes and then it bends and uh but then the it like attaches to itself and then the bend ends up as a pool of isolated liquidity h and it also starts with like a zero x. So we thought it was cool.
So anyway, thank you uh for for time. Yes, thank you very much. Thank you very much. there question. Um, can you guys hear me?
Okay. Yeah. Yeah. Okay. Um, thank you for Jamine.
Um, we'll quickly pivot to the slide though for some questions. Actually, one of the questions was um, if we can get it on. Yeah. Perfect. How did you come up with the name?
But I think that's pretty much already answered at this point. Uh, the second question is um, yeah. So, what's the difference between tornado cache and oxbow? And yeah, um, in the sense that yeah, how do you get relegate? Um, yeah, you know.
Yeah, I'll answer that one. Uh main difference between tornado cache and oxbow. We solve the most important problem which is keep the terrace out. We solve the second uh an a a less important but also important problem which is the UX. Uh so you know you can do partial withdrawals.
Partial withdrawals are nice because I can keep most of the money in there and then just send it out as I need it. Send you one ETH, send you two ETH, send you four ETH. Um and that's basically it. Um yeah. What are the key differences between privacy pools implementation and rail gun's POI?
Any pros or cons? Yeah, so props to rail gun for implementing the research that Mollik Dao uh paid for and funded. Um, thank you uh for pioneering this rail gun. The the main difference between these uh two systems is that they cannot remove people from the whitelist. So once you get into the rail gun, uh you your deposit is approved, you're in forever.
And I prefer not uh that that seems a little extreme for me. Uh I it's not a very uh recoverable system from mistakes. If you make a mistake, you let elicit funds in uh it's going to taint your uh pool forever. Whereas in privacy pools, if we discover that we make a mistake or it's not necessarily a mistake like somebody has deposited money and like this happens where there's I don't know like Roman Seovv is a horrible example for this I know because like I love the guy but uh he is on the US sanctions list and as a US company you have to block his money and so uh if he had deposited money into the system and then we had to you know he got sanctioned or anybody got sanctioned you could then remove that deposit uh because they became a criminal later. So uh yeah and and then when you remove that deposit, everyone else who withdraws from that point forward dissociates from that uh user uh and and those funds and I see there's a message also from the team.
Uh so it says training wheels are off. Yeah, privacy pools removes um yeah deposit limits. Um, I think someone I don't know if it's a question. Someone said, "If bad hackers stole your crypto, it's your fault for failing to protect it." But I think that's really a question.
That sounds like uh somebody who who is friends with the hackers, you know, probably probably. I I mean, I vaguely agree, but like uh it's it's it's it's like I prefer to not, you know, associate with the funds of the people who stole money from my friends uh if I can. Yeah. And lastly, do you think exchanges will be pressured by leg legislation to even censor addresses that have interacted with privacy pools? Well, if the EU passes their ban on anonymous coins, then the answer to this question is a resounding potentially yes.
And so it's important that we not only fight this battle with code but we also fight this battle in uh legislature and uh legit provide legitimate use cases for the technology to drive the conversation uh to get you know actual privacy and security for people in practice not just in theory. All right I want you guys to uh thank Amin once again for his uh speech.
Automatic transcript — names and jargon may be misspelled.