Cointime

Download App
iOS & Android

What is Privacy in Web3?

Validated Venture

Introduction

For Web3, privacy is the elephant in the room. It is at once crypto’s biggest selling point, going hand in hand with the principles of decentralization, anonymity, and trustlessness, and its biggest pain point, with excruciating KYCs, easily trackable PII, and an ever-suspicious gaze from the outside world.

Unfortunately, this is also a topic that is largely misunderstood and misconceived, with many people viewing crypto “privacy” as simply an excuse to finance terrorists and conduct money laundering. The fact that crypto Twitter prides itself for its “anon culture” and that mainstream media often (intentionally or unintentionally) reinforces these biases doesn’t help a case in dissolving these stereotypes.

Because Web3 privacy is such an all-encompassing concept, touching upon everything from ape profile pictures to cryptography and Zero Knowledge Proofs, its useless to talk about it in the aggregate, and make lump-sum judgements on whether it is good or bad. Instead, we must break down the problem into different smaller segments. In this essay, I will first break down and analyze Web3’s “privacy” infrastructure at three distinct levels — network level privacy, protocol level privacy, and user level privacy — before exploring the role that technological solutions such as Zero Knowledge Proofs play in the future of Web3 privacy.

Network Level Privacy

The first and oldest conception of privacy is at the network level. Network level privacy is where every transaction of a cryptocurrency on a given blockchain network is guaranteed privacy through underlying consensus mechanisms of the blockchain and network-level design choices. As such, these are also called “privacy coins.”

This conception of privacy traces its roots all the way back to the Bitcoin protocol, and its idea of anonymizing “wallet addresses” as 160-bit cryptographic hashes [1]. While Bitcoin itself has fully transparent transactions, where any user can inspect any transaction on its network, Bitcoin’s design principles of decentralization and anonymity have undoubtedly inspired the driving force behind the development of “network level privacy” and privacy-first blockchains.

One of the leading projects in establishing network level privacy is Monero, a privacy-first blockchain established in 2014. Unlike Bitcoin, Monero hides both user wallets and transactions behind “Ring Signatures,” in which users within a given “ring” have access to a certain group signature, and use that group signature to sign transactions. Therefore, for any given transaction on the Monero network, you can only tell that it comes from a certain group, but you don’t know which user in that group actually signed the transaction. In essence, this is a form of “privacy in the crowd,” in which users band together into groups in order to provide everyone with privacy. [2]

Another project that tackles this same space is ZCash, an early pioneer of a form of Zero Knowledge Proofs called zk-SNARKs which has been recently popularized. The fundamental concept behind Zero Knowledge Proofs is that it is a way of proving something is true without revealing any further information (which could compromise security and privacy) [4].

A simple example of a Zero Knowledge Proof is a Gradescope autograder [5]. You need to “prove” that you did your CS homework correctly, but don’t need to tell the autograder any further details about your code implementation. Instead, the autograder checks your “knowledge” through running a bunch of hidden test cases, and your code must match the “expected” output of the Gradescope autograder. Through matching the “expected” output, you can provide a Zero Knowledge Proof that you’ve done your homework without showing your actual code implementation.

In the case of ZCash, while transactions are by default transparent, users can choose to use these “Zero Knowledge Proofs” to create private transactions. When a user wants to send a transaction, they create a transaction message that includes the sender’s public address, the recipient’s public address, and the amount of the transaction, and then convert this into a zk-SNARK proof, which is the only thing sent to the network. This zk-SNARK proof contains all the necessary information to prove the validity of the transaction, but doesn’t reveal any of the details of the transaction itself. This means that the network can validate the transaction without knowing who sent it, who received it, or the amount involved.

Despite their design and implementation differences, for both Monero and ZCash the transaction privacy is guaranteed at the blockchain level, such that all transactions happening on the network are automatically guaranteed to be private. This privacy guarantee can be easily abused by bad actors to conduct money laundering, terrorist activities, and drug trafficking, and Monero is particularly notorious for its popularity on the Dark Web [6]. Furthermore, as Monero and other “privacy coins” become synonymous with illicit financial activities, this drives away users using these “privacy coins” out of legitimate privacy concerns, feeding a negative feedback loop that only results in a more harmful shadow economy.

This is the biggest drawback of guaranteeing privacy at the network level: it is an “all or nothing” approach in design, where there is a zero-sum tradeoff between the transparency of a transaction versus the privacy of this transaction. It is precisely because of this lack of transparency that “network level privacy” draws the most ire from regulators, and the reason why several major centralized cryptocurrency exchanges, such as Coinbase, Kraken, and Huobi have delisted Monero, ZCash, and other privacy coins in several jurisdictions [7].

Protocol Level Privacy

A different approach to privacy is to ensure “protocol level privacy,” where instead of hardcoding private transactions into the consensus level of the blockchain network, we process private transactions on a “protocol” or an “application” that runs on top of a blockchain network.

Because early blockchain networks, such as Bitcoin, had limited programmability, building “protocol level privacy” was incredibly hard to do, and it was much easier to fork the Bitcoin network and implement privacy from the ground up in the form of a new blockchain and “privacy coin.” But with the advent of Ethereum and the rise of “smart contracts,” this opened a whole new avenue for privacy-preserving protocols.

One of the most notable examples of “protocol level privacy” is Tornado Cash, which is a decentralized application (dApp) on Ethereum that “mixes” transactions together into a pool in order to guarantee transaction privacy — conceptually somewhat similar to Monero’s “blend in with the crowd” approach.

The Tornado Cash protocol roughly speaking has three main steps:

  1. Deposit: Users send their funds to a Tornado Cash smart contract. This initiates a private transaction with a randomly generated “anonymity set,” which is a group of users who are also making transactions at the same time.
  2. Mixing: Tornado Cash mixes the deposited funds with other users’ funds in the anonymity set, making it difficult to trace the original sender or recipient. This process is called “mixing” or “anonymizing.”
  3. Withdrawal: Once the funds have been mixed, users can withdraw their funds to a new address of their choice, breaking the link between their original address and the destination address. The user can then complete the transaction by sending the funds directly from the “new” destination address to the recipient. [9]

Unfortunately, in August 2022, Tornado Cash was sanctioned by the US government, as the Office of Foreign Assets Control (OFAC) alleged that North Korean hackers were using the protocol to launder stolen funds [10]. As a result of this crackdown, US users, companies, and networks are no longer able to use Tornado Cash. USDC stablecoin issuer Circle went a step further, freezing over $75,000 worth of funds connected to Tornado Cash addresses, and GitHub deleted the accounts of Tornado Cash developers [11].

This triggered a controversial storm in the crypto sphere, as many argued that with the vast majority of users using Tornado Cash for legitimate privacy-preserving transactions, and that protocol users should not be punished for the bad actions of a small minority. But importantly, because Tornado Cash is a “protocol level privacy” on Ethereum, rather than a “network level privacy” solution, the crackdown and fallout was restricted only to this one protocol on the Ethereum network rather than affecting the entire network — unlike Monero and ZCash, Ethereum didn’t get delisted from Coinbase because of these sanctions.

An alternate approach to “protocol level privacy” pioneered by the Aztec Network focuses on “rollups” to shield user funds and support private transactions. Aztec’s primary product is zk.money, which uses a 2-layer deep recursive Zero Knowledge Proof for both scaling and privacy. The first ZKP proves the correctness of the shielded transaction, ensuring that the transaction was in fact private and there was no informational leak. The second ZKP is used for the rollup itself, in order to bundle the computation of batches of transactions together and ensure that all of these were executed correctly [12].

While rollup-based “protocol level privacy” solutions are still in their early stages, they represent the next evolution of “protocol level privacy” solutions. One key advantage of rollup solutions over dApp-based “protocol level privacy” solutions such as Tornado Cash, such as their enhanced scalability, as the heavy-lifting of the computation largely happens off-chain. Furthermore, because much rollup research has been focused solely on increasing computation, there is still ample space for exploration in applying and extending these technologies into the privacy sphere.

User Level Privacy

A third (and most recent) approach to conceptualizing privacy in Web3 is through exploring “user level privacy,” where privacy guarantees are made for an individual user’s data rather than focusing on the data of the user’s transaction. In both the “network” and “protocol” level, we witness the recurring problem of a minority of bad actors (such as Dark Web transactions and money laundering schemes) affecting the use of the network and protocol for the innocent majority that are simply concerned for their personal data privacy.

The crucial point of “user level privacy” is that through focusing on individual users of a network itself, we conduct a “targeted” form of filtering where benign users and addresses are free to interact with the blockchain network privately, while bad users can be quickly filtered out. As you can imagine, this is a Herculean task, walking a fine line between transparency and privacy. This user-centric view of privacy also spawns an entire debate (and industry) about the role and future of decentralized identity (dID) adjacent and derived from the question of Web3 privacy [13]. For the sake of brevity, I will not discuss this question of KYC and authentication in Web3.

The core insight of “user level privacy” is to separate and reimagine the relationship between the user themselves and their wallet addresses on-chain, as wallet addresses are the atomic identifiers on a blockchain network. Importantly, there is a one-to-many mapping from users to chains: users often control more than one wallet address on each blockchain network they interact with. This is the idea of “on-chain identity fragmentation.” Thus, the crux of “user level privacy” is finding a secure way of mapping users’ personally identifiable information (PII) to all these fragmented on-chain identities.

A key project in this regard is Notebook Labs, which seeks to use Zero Knowledge Proofs to link fragmented identities together with a user’s PII [14], while providing the following guarantees:

  1. Users can prove their humanity with any fragmented on-chain identity
  2. It is impossible to link these identities together (unless the user’s secret key is leaked)
  3. It is impossible for any third party or adversary to link a fragmented on-chain identity to the user’s real-world identity
  4. Credentials can be aggregated across identities
  5. Each human receives a single set of fragmented on-chain identities [15]

While the cryptographic specifics of the protocol are beyond the scope of this essay, Notebook Labs demonstrates two core principles of “user level privacy” — the importance of addressing reimagining the relationship between the multitude of fragmented on-chain identities with real-world human users, as well as important role that Zero Knowledge Proofs play in aggregating and linking together all of these identities [16].

Another emerging solution to the question of “user level privacy” is the idea of “stealth wallets.” Again, the idea of “stealth wallets” capitalizes on the fragmentation of on-chain identities, using the fact that a user typically has more than one identity on-chain. Unlike Tornado Cash and other “protocol level privacy” solutions, which seek to obscure the transaction data itself, stealth addresses seek to obscure who the real people are behind the sender and recipient addresses. This is implemented through essentially finding an algorithm to quickly and automatically generate “one-time wallets” for a user’s transaction [17].

One important conceptual difference between “stealth wallets” and previously discussed privacy solutions such as Monero and Tornado Cash is that this is not a form of “privacy in the crowd.” This means that unlike Tornado Cash, which can only make privacy guarantees for mainstream token transfers such as ETH, stealth wallets can also provide security guarantees for niche tokens and NFTs, or unique on-chain assets that have no “crowd” to blend into [17]. Nonetheless, thus far the discussion of “stealth wallets” on Ethereum has remained at the theoretical stage, and the implementation effectiveness and legal repercussions of this novel technological solution are yet to be seen.

ZKPs and The Future for Privacy in Web3

As we can see, privacy is complicated in Web3. Different approaches to the problem — at the network level, at the protocol level, and at the user level — invite different solutions to it, and explore different tradeoffs between transparency and privacy. That said, any discussion of privacy is incomplete without considering the flip side of the coin: transparency and accountability.

For better or for worse, regulators are right in saying that there needs to be a greater accountability in cryptocurrency transactions. Bad actors engaged in money laundering, terrorist activities, and financial fraud should be held accountable, regardless of whether they use fiat or crypto to complete their transactions. But hopefully, in Web3 this accountability can be achieved without governments resorting to shutting off privacy networks altogether and forcing people to use these blockchains “cryptographically naked.” Privacy should be seen as a basic right, and a measure of digital dignity.

For a long time, privacy and accountability were seen as a zero-sum game, where you could either hide your data and have privacy, or show your data and have transparency. The innovativeness of Web3 comes in its pioneering of elegant technological solutions, especially Zero Knowledge Proofs, to overcome this zero-sum dilemma. But the burden is on the Web3 community, not regulatory agencies, to show that these technologies can actually work in ensuring both privacy and accountability.

Far too often, Zero Knowledge Proofs are touted as the end-all-be-all for any privacy problem. But despite all their mathematical magic, ZKPs are far from being a panacea for all of Web3’s privacy concerns and have several critical drawbacks. Firstly, ZKPs are often highly specialized circuits used to prove a certain piece of information structured in a particular way. In general, they suffer from a lack of scalability and compatibility. Secondly, they are very expensive to create, run, and maintain, requiring orders of magnitude more of computation power than an equivalent non-ZKP program.

Thus, when thinking about ZKPs in the realm of privacy, the important question will always be “what” are you going to prove, and “why”? After all, there’s no free lunch, and designing a ZKP always will always come with a cost. It is just as irresponsible for tech evangelists to declare that ZKPs will solve everything in privacy as it is for regulators to shut down all privacy protocols.

Fundamentally, privacy in Web3 is not just an engineering question; it’s a first principles one. Ever since the release of the Bitcoin whitepaper and the commercial adoption of the blockchain, one of the foundational principles of Web3 is its emphasis on trustlessness — where you don’t need to trust information to any party that could potentially turn that trust against you. A network can only truly be trustless when its users’ privacy is guaranteed through a decentralized, transparent, and unbiased manner.

Comments

All Comments

Recommended for you

  • Economic Daily: 'Patience' is Becoming the Most Scarce and Urgent Demand in the Market

    On September 27, Economic Daily published an article stating that patience is not only a friend of time but also the soil for innovation. Technological innovation inherently features high investment, high risk, and long cycles. Who has the capability to support this expedition in scientific innovation? Tian Xuan, Dean of the Guanghua School of Management at Peking University, provides the answer in his book 'Patient Capital: Building a New Ecology of Long-term Investment'—patient capital. The characteristic of patient capital lies in its pursuit of long-term investment horizons and strategic stability, rather than short-term financial returns. As global economic uncertainty rises and China’s economy stands at a critical juncture of transitioning from factor-driven to innovation-driven growth, the concept of 'patience' is becoming the most scarce and urgent demand in the market. At the macro level, patient capital can effectively smooth short-term market fluctuations and enhance overall market confidence and resilience through long-term asset holding and rational decision-making, while creating a stable financial environment for the implementation of medium- to long-term economic and industrial policies by the state. At the micro level, patient capital can cover the entire development cycle of technological innovation, providing a tolerant space for trial and error in technology, and shifting resources from short-term market projects to long-term innovation projects. Furthermore, the participation of patient capital can send positive signals to the outside world, reduce information asymmetry between market investors and upstream and downstream companies, and alleviate financing difficulties for enterprises. Beyond financial support, it can also promote knowledge transfer and market resource integration through its own network, enhancing the success rate of innovation and research and development in invested companies, and driving the development of new productive forces and the upgrading of economic structure. Strengthening patient capital means not only extending the investment horizon but also respecting the laws of technological iteration, trusting in the long-term evolution of industries, and building a consensus on long-term value. Its deep binding with the real economy will become another important force supporting the stable and long-term development of the Chinese economy.

  • Iranian Military: Pursuit of Trump and Netanyahu Will Continue After War

    On September 27, senior spokesman for the Iranian armed forces, Shekarchi, stated that even after the war ends, the Iranian military will continue to pursue U.S. President Trump and Israeli Prime Minister Netanyahu, labeling them as "murderers" who will inevitably face punishment. "Even if the war ends, we will not spare Trump, Netanyahu, and their accomplices. Regardless of whether they remain in power, they must pay the price for their actions," Shekarchi said. He emphasized that Tehran will never allow the U.S. to regain its former status in the emerging world order. The only safe path for U.S. troops is to withdraw from the Middle East, and the faster they leave, the fewer losses they will incur. "Americans can dream of intervening in the Strait of Hormuz. But if they dare to meddle in the Strait of Hormuz, they will receive a hard slap in the face."

  • Iranian Foreign Minister: Opening of Strait of Hormuz Depends on Iran's Conditions Being Met

    On September 27, Iranian Foreign Minister Zarif stated that Iran will not make concessions to the United States on established conditions. The opening of the Strait of Hormuz depends on whether Iran's proposed conditions are met, and any progress regarding the opening of the Strait will depend on the implementation of these conditions. Iran will never compromise on these issues. Zarif mentioned that Iran has been informed of the U.S. initial response to the proposal for reopening the Strait of Hormuz but has not yet received any specific information conveyed by the mediators. Iran is waiting for the mediators to communicate the final position, and will make decisions based on that. U.S. President Trump stated on the 26th that he rejected Iran's proposal to reopen the Strait of Hormuz. (CCTV News)

  • US to Lower Fuel Economy Standards, Fuel Consumption and Emissions May Rise

    On September 27, US officials announced on Saturday that the Department of Transportation will finalize regulations to significantly lower fuel economy standards for cars on Monday, applicable until 2031. This means the US will reverse the policies promoted during the Biden administration that encouraged automakers to produce more electric vehicles. Former President Trump stated that he has approved new fuel economy standards for cars and trucks, claiming that the new regulations will reduce the prices of new vehicles. US Transportation Secretary Duffy remarked, 'American auto workers will celebrate a major victory on Monday.' According to estimates from the Department of Transportation, the new standards will lower the cost of new cars, but fuel consumption and carbon dioxide emissions will increase over the coming decades.

  • U.S. Spot Bitcoin ETF Sees $2.39 Billion Net Inflow in a Week, Highest Since 2026

    On September 26, BeInCrypto reported that the U.S. spot Bitcoin ETF experienced a net inflow of $2.39 billion this week, marking the largest single-week net inflow since 2026. According to SoSoValue data, the week started with an inflow of $998.95 million on September 21, but subsequently declined daily to $134.47 million by Friday, approximately 87% lower than Monday. Nonetheless, funds continued to flow in for the seventh consecutive trading day. The significant inflow on Monday followed a 6.7% surge in Bitcoin, which led to about $262 million in short positions being liquidated within an hour. A global business survey by S&P on September 23 indicated that the U.S. economy is growing at its fastest pace since July 2021, with the 10-year U.S. Treasury yield surpassing 5%, causing Bitcoin to drop below $84,000 within an hour. The total assets of the ETF currently stand at $108.42 billion.

  • Riot Repays Coinbase Loan Early and Terminates $200 Million Bitcoin Collateral Credit Line

    On September 26, according to U.S. SEC filings, Bitcoin mining company Riot Platforms (NASDAQ: RIOT) voluntarily repaid all outstanding loans to Coinbase Credit on September 21 and terminated its $200 million credit line, while also releasing the lender's claim on the collateralized Bitcoin. Riot paid the full principal and accrued interest, incurring no early termination fees or penalties, and Coinbase's subsequent lending commitments were also terminated. The credit line, revised in April 2026, carried a fixed annual interest rate of 6.15% with a maturity date extended to April 20, 2027, and Riot had previously fully drawn the amount. At this rate, the annual interest on the $200 million balance is approximately $12.3 million. As of June 30, Riot had pledged 5,821 Bitcoins as collateral, valued at about $340.7 million, which accounted for approximately 51% of its total holdings of 11,380 Bitcoins at that time; the collateral also included USDC and cash held in Coinbase Custody Trust. This credit line was initially established in April 2025 for $100 million with a variable interest rate; it was doubled to $200 million the following month with a one-time fee of $1 million. Since the window for early termination fees specified in the agreement closed on August 21, no fees were required for the repayment in September. Riot is simultaneously expanding its data center operations, having announced in August a 20-year lease agreement with an unnamed AI developer for 191 megawatts of computing power at its Rockdale facility, which is expected to generate approximately $9.1 billion in initial revenue.

  • Trump: 'Super Intelligence' is a More Fitting Term than 'Artificial Intelligence'

    On September 26, U.S. President Trump stated: 'Super Intelligence' is a more fitting name. This name is more accurate because the term 'Artificial' often implies 'false' or 'not real'; however, it (Artificial Intelligence) is not a false entity, but rather an extremely powerful form of intelligence.

  • US and China Reach Agreement to Cut Tariffs on $30 Billion in Goods

    On September 26, the United States and China reached an agreement to reduce tariffs on $30 billion worth of goods following talks between President Xi Jinping and US President Donald Trump. (Watcher.Guru)

  • BTC Surpasses $84,000

    Market data shows that BTC has surpassed $84,000, currently priced at $84,015.64, with a 24-hour increase of 0.31%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.