header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

IOSG: How Does Blockchain Keep Secrets? Three Answers to On-chain Privacy

Read this article in 111 Minutes
The demand has been validated, technology is no longer a bottleneck, and regulatory efforts starting in July 2027 will push the market towards auditable privacy.
Original Title: "IOSG Weekly Brief | How Blockchain Preserves Secrecy: Three Answers to On-chain Privacy #339"


Abstract


A public blockchain lays out every transaction for everyone to see. This wasn't an issue before the real balance sheet arrived. There are three ways to address this: build your own private network like Zcash, Monero, and Canton have done; add privacy to Ethereum through projects like Tornado Cash, then Railgun, and now Zama; or simply do not disclose data—another approach adopted by Canton.


Each approach sacrifices transparency for functionality. Something that can hide everything and still function effectively has yet to be developed.


The demand is real and backed by evidence. In 2024, JPMorgan confirmed that institutional finance can work on a cryptographically secured basis, and in 2026, issued its own deposit token on Canton. A sandwich attack on an exchange transaction can cost between 0.3% and 0.8%. Institutional spot over-the-counter (OTC) trading volumes increased by 109% in one year, while the top 20 exchanges only grew by 9% over the same period; 40% of institutions have moved more than half of their trading off-screen.


However, privacy does not equate to security. While it can reduce the probability of being targeted, once you are under surveillance, privacy offers little protection, and recovering from an incident becomes even more challenging. It also inadvertently concealed a vulnerability in Zcash that allowed for the creation of coins out of thin air, a flaw that remained hidden for four years.


The money is in the assets, not the services. Around $250 billion is locked in privacy-oriented tokens. The total fees collected by all protocols in the entire field add up to approximately $6 million per year; Monero and Zcash have earned a total of $3 million to date; Zama has moved $595 million across its boundaries, estimated to have received between $840 and $84,000—since it charges fees based on the amount of Bitcoin transferred, not a percentage.


The consensus remains bullish. The demand has been validated, the technology is no longer a bottleneck, and regulations from July 2027 onwards will push the market towards auditable privacy. The only missing piece is a pricing mechanism, which is the most solvable issue in the entire ecosystem. Therefore, this particular transaction should fall on the party that dares to charge a fee in the end.


The Issue: Public Ledgers Revealing What Should Remain Private


Blockchain is a shared ledger that records who owns what. Every machine on the network holds an identical copy, and every transaction is recorded on all copies. There is no central authority to determine the truth, and anyone can validate the ledger independently. The trustless nature enables strangers to transact without relying on trust.


The cost is that this ledger is open to everyone. Your account, called an address, is essentially a long string of letters and numbers. Anyone can paste an address into a block explorer, a free website, and see its entire history: what has been held, who it has been paid to, how much has been paid, and the minute it was paid. No need to log in, no need for permission, and no way to opt out.


For ten years, this wasn't much of a concern: there wasn't much money on the chain, and the users were all pseudonymous. But once a real balance sheet entered the scene, this became no longer benign.


Think about what a public ledger actually reveals. For a company that pays salaries on-chain, it's like publishing the payroll. For a fund holding open positions, it's like disclosing the position size, entry price, and the price at which a liquidation would occur. For an enterprise paying suppliers, it's like revealing the supplier list and payment terms. And for any individual holding a large balance, what they disclose is a number big enough to make themselves a target.


Two things have turned this from a theoretical issue into an urgent matter. One is stablecoins, tokens designed to be pegged to the dollar and backed by actual dollars in a bank; the current transaction volume is significant. The other is the tokenization of real-world assets, such as bonds, funds, and real estate, which are entering the scene with regulatory oversight. These users cannot accept "everyone can see the amount" as a condition of entry.


So the problem is easy to state but hard to solve: how can you hide the numbers while allowing thousands of strangers to verify that no one is cheating?


Who is actually paying for this: those whose losses can be measured in basis points


Privacy has always had a set of arguments. Surveillance is bad, freedom is good, and so on. But arguments don't sustain a product. What really changed between 2025 and 2026 is that specific individuals started losing actual money because something was leaked on the public ledger, and then they came out looking to buy something.


It's not about who dislikes being surveilled; it's about who the public ledger repeatedly makes pay, converting that payment into a private ledger.


▲ Who pays for privacy on chain, plotted by how on-chain the loss is against whether anyone is paying to stop it.


Trader: Front-Run on Own Order Flow Results in Loss Measured in Basis Points


Your trade lies in a public queue before execution, gets picked up by a bot, front-ran to buy ahead of you, and then sold to you upon execution. This is known as a sandwich attack. In the year ending October 2025, around 95,000 of these occurred on Ethereum, siphoning off about $60 million, with a sandwiched swap losing between 0.3% and 0.8%.


The buyer here is a pro player, with the loss measurable in basis points. So, privacy in this scenario sells execution quality, not belief.


Public Positions on Perpetual Contract Platforms: Continuous Exposure


If you carry a position, this is worse than a sandwich, as the exposure is continuous. On perpetual contract trading platforms, every position is public, even the liquidation price is visible, and anyone can nudge the price there. Just for Hyperliquid alone, the monthly volume in April 2026 was around $432 billion.


The platform's response is commercial, not ideological. Aster introduced hidden orders, Paradex and Hibachi sell position privacy, and Zama included Confidential RFQ in their private beta in July 2026, which will be covered in Section 6.


Tagged Wallets That Must Sell: Highest Demand, Least Discussion


A fund's unlocking shares sit in a wallet, already labeled by Arkham and Nansen, with the unlocking date publicly available. As soon as the money moves, the market front-runs it, and the cycle repeats each quarter.


This revenue already exists; it just flows elsewhere. In the year ending 2025, institutional spot OTC trading volume grew by 109%, with the top twenty exchanges growing by only 9%; 40% of institutions prefer OTC as their execution venue, with over half of the trades happening off-screen. This phone-serviced market is the way it is because public venues leak.


Strategies That Will Be Copied: Virtually No One Pays for This


A mirroring tool can replicate a profitable address within a few blocks, so a treasury manager's rebalancing decision doesn't decay over weeks but dies at the moment of execution. It's not to evade the government but to avoid the other twelve peers watching the same board. Virtually no one pays to prevent it from being picked off, and that's precisely what makes this quadrant intriguing.


Regulated Ledger Onboarding to Public Blockchains: Genuine Demand, Yet Sidelined onto Permissioned Rails


Over $300 billion worth of tokenized real-world assets sit idle on public blockchains, while banks are unable to publicly disclose their holdings in real time. So, do banks even want this stuff? There's a case where both answers point in opposite directions.


In November 2024, JPMorgan's blockchain division conducted Project EPIC within their own sandbox, showcasing encrypted-state fund subscriptions, blind bid auctions, and direct settlement on encrypted values based on Zama's fhEVM, designed in a way that even JPMorgan couldn't see the details. However, that was just a sandbox, and Zama was just one of several vendors. By January 2026, when JPMorgan actually decided to issue a deposit token, it went to Canton, a permissioned network.


Thus, while institutions demand authenticity and verifiability, what has taken it off the table is permissioned rails, not the cryptography of public blockchains.


Toolkit: Four Privacy Techniques, Distinguished by Where the Secret Lies


Within this landscape, each project is built on a combination of these four ideas. The key differentiator between them is a simple question: where does the secret reside.


▲ The four primitives, sorted by where the secret actually lives.


The trade-off used to be speed, making this section the quickest to age in this article. For several years, a fair critique of FHE was that it could only process around twenty transactions per second, while regular chains could handle thousands. This gap has essentially closed, faster than the people working on it expected.


No single method reigns supreme. Real-world solutions combine two: sacrificing speed for a secure enclave chip, then adding a zero-knowledge proof chip to ensure the chip behaves; or using FHE for stateful storage, then employing zero-knowledge proofs to verify inputs.


There's also a fifth option, bypassing cryptography altogether: only sharing data with authorized parties. This is Canton, and this is why banks like it.


First Response: Building the Network with Privacy from the Start


The earliest attempts revolved around designing an entire network around "hiding" rather than patching an existing network. While two coins led the way on this path, the bet placed was completely different. The third case was built for banks, not individuals, but it belongs to the same family.


Zcash: Privacy is a toggle, and that's been its Achilles' heel for a decade


Zcash is its own chain, fundamentally Bitcoin-like digital cash with an added privacy mode. It has two types of addresses: transparent addresses, just like Bitcoin, revealing everything; and shielded addresses hiding the sender, receiver, and amount. Moving funds into the private side is called shielding, and moving out is called deshielding.


The hiding dance is done by zk-SNARKs, a form of succinct zero-knowledge proof. When you spend shielded ZEC, the wallet produces a very short proof showing that the payment adds up and no coin was double-spent. Machines in the network verify this proof, accept it, and all along do not know who paid whom or how much.


One design choice defined everything that followed: privacy is optional and per-transaction. This sounds user-friendly but is also a weakness because privacy depends on numbers. If you're the only one wearing a mask at a party, wearing a mask is as good as not wearing one. For most of Zcash's existence, the majority of ZEC has stayed in the transparent pool, while the private group has always been thin.


Most people see Zcash as one thing, when it is actually four pools. Knowing who's who makes sense after reading about that 2026 bug in Section 8. The short version is: Sprout proved private money could work, Sapling made it usable, and Orchard made it not rely on trusted setups anymore.


▲ Zcash's shielded pools over ten years, with the shielded share below and the incidents marked.


There's one more thing to know about Zcash, and that's a reason to hold it and not spend it: shielded ZEC doesn't come with a history. Once a coin passes through the pool, it loses any trace, and each unit is interchangeable with every other unit. This feature is called fungibility, and it's a headache for compliance departments on transparent chains — on a transparent chain, you could receive a coin previously used in a crime by three other holders, inheriting all the trouble.


Monero: Privacy is default, there's simply no toggle


Monero also has its own chain, opting for the exact opposite: no transparent mode to choose from. Each payment is private to everyone, so there is also no small private pool to join—everyone on the chain is all there is.


Until recently, it relied on three tools instead of zk-SNARKs. Ring signatures mix actual coins with decoys to hide the sender, with observers seeing sixteen possible sources without knowing which one is real. Stealth addresses generate a brand-new one-time address for each payment to conceal the receiver. RingCT hides the amount.


▲ How Monero hides the sender, the receiver, and the amount.


In early 2026, Monero underwent a major upgrade with FCMP++, replacing ring signatures with zero-knowledge proofs. The practical effect is that the group you hide among has changed from sixteen decoys to every single payment in the history of this chain, totaling over 1.5 billion transactions.


▲ Monero's anonymity set after FCMP++.


Canton: Nothing is hidden because nothing is shared


The third member of this family is not a coin and is therefore often overlooked in privacy-focused research. However, the largest institutional decision of 2026 landed on it, making its omission a mistake.


Zcash and Monero accept the premise that the ledger must be broadcast to everyone and then use cryptography to hide the content. Canton directly challenges this premise. It does not have a shared ledger that everyone must validate. Each participant only receives the part of the transactions where they are directly involved, enforced at the contract level by a language called Daml. If you are not party to a transaction, you will never receive this data and will never know the transaction occurred. A component named Global Synchronizer handles ordering, confirms validity, and yet does not see the content.


▲ The same three payments on a public chain and on Canton, showing who receives which rows.


So the secret is protected by "never being disclosed," and those with permission can read the plaintext. Note that none of the four tools in Section 3 is used: no zero-knowledge proofs, no FHE, and despite external obfuscation, no MPC. Daml claims to be a language for multi-party applications, which sounds like multi-party secure computation, but means something completely different. Integrity is ensured through cryptography: each participant receives a hash, representing the branches they cannot read. Confidentiality is purely a matter of "who received what."


The reverse in the verification process is quite interesting. On Ethereum, every validator re-executes every transaction, so everyone must see everything. On Canton, the parties to the transaction themselves verify, each party only reruns their own branches, and then votes. An arbiter votes according to the confirmation policy, only seeing the hash. So there is no global re-execution to detect collusion, and the reassurance is: only the parties already inside your contract can harm you.


JPMorgan Chase chose it for JPM Coin, announced in January 2026, with a phased rollout throughout the year, the reason being practicality rather than ideology. Privacy is on by default, without worrying about whether the network is large enough. There is no shared pool, so freezing like that of Circle in Section 8 cannot happen here. Each participant is a legally identifiable entity, a hard requirement for regulated banks, not a compromise. Settlement between applications is atomic. Peers are already on board, including Goldman Sachs and BNY Mellon.


It is also very real in what it gives up. There is no permissionless composability, and liquidity is walled off. Privacy is based on access control rather than mathematics, so transaction counterparties with permission to view can see everything, and breached participating nodes will leak. It is not censorship-resistant—this is a feature for banks, and the original intent for all of this was disqualification. Even if everything is normal, three things will leak: change amounts (depending on how the token model is written), who is hosting your participating node, and "who is sending messages to whom" that the sequencer sees.


Canton Coin (code CC) went live on the Global Synchronizer mainnet in July 2024, to pay for application and infrastructure fees, reward network operators, with no pre-mine or presale, and approximately 1 trillion coins can be minted in the first decade. By late July 2026, the price was around $0.12, with a market capitalization of nearly $48 billion, already ranking as a top twenty asset.


This figure is worth pondering; it redefines the entire track. For a permissioned network built for banks, the token's value is approximately thirty-five times that of Zama.


Seeing All Three Alongside Each Other



Three lines to make the point. Both coins can shield your amounts from everyone but still can't escape a single app. Canton is able to run apps, shield amounts from everyone except the transacting party. And Canton doesn't require crowds to hide in because there is no shared ledger to hide into, bypassing the decade-old weak point that has plagued Zcash.


Something that combines both has yet to be achieved. There is an image at the end of Section 6 that shows how consistent this balance is.


Where the Privacy Coin Road is Broken: It Can Do It, But Lives on an Island


A privacy chain has done its job well, but it resides on an island.


First, the real friction. It is a separate chain with a separate token, assets need to move in and out. Yet the dollars people actually trade with, the lending protocols people actually use, are all on the other side—on Ethereum and Solana.


But this island is no longer so isolated. There is a second solution that has nothing to do with "moving privacy onto Ethereum": leave the privacy chain where it is, just make it reachable.


▲ Buying shielded ZEC with and without a centralised exchange in the path.


That’s what NEAR Intents does, and it’s a major reason for Zcash's 2025 revival. You declare what you want, like swapping Bitcoin for ZEC, a bidder network figures out how to hop chains, and you sign only once. Zcash's own wallet integrated this system, allowing users to buy shielded ZEC from another chain or sell it, without touching a centralized exchange throughout the process, nor exposing their Zcash addresses.


As of March 2026, the total transaction volume of ZEC through NEAR Intents has reached $1.5 billion, with $600 million coming from the wallet’s native swap product launched in October 2025.


So the island issue is real, but it's a spectrum, not a wall, with two competing answers: move privacy where the money already is, which is what the rest of this piece covers; or leave privacy in place, fix the surrounding pipes, which is cheaper and already in motion.


Next is a larger limitation: these chains only deal with money. There are no smart contracts (except for Canton), and smart contracts are the little programs that allow a chain to do more than just transfers—lending, borrowing, earning interest, running a marketplace. You can hold private money, send private money. You cannot use it to earn yield, cannot use it as collateral, and cannot plug into anything else.


Privacy itself is taxed, with Zcash and Monero each paying a price. Zcash made hiding optional, resulting in a user base of only those who are "willing to go through the trouble." Monero made hiding mandatory, creating the strongest community in the industry but also placing itself under regulated exchanges. Starting in 2027, European regulations will tighten again, revisiting this point in Section 9.


The Second Answer: Adding Privacy to Chains People Are Already Using


Another approach is to stay put. Keep the money and applications on Ethereum and add a layer of privacy on top. No new chains, no chain bridges, no new wallets.


Three generations have tried this, with each generation's existence stemming from what the previous generation couldn't accomplish. Read in sequence, the order itself is the argument.


First Generation: Tornado Cash, And How "Mixer" Became a Curse Word


Think of it as a coin-swapping window. You deposit a fixed denomination (0.1, 1, 10, or 100 ETH) into the pool and receive a secret voucher. Then, you withdraw to a brand-new address, using a zero-knowledge proof to demonstrate ownership of an unspecified unspent deposit in the pool. The link between the old and new addresses is severed. Your cohort is everyone who deposited the same denomination.



That's about it for the product. The money sitting inside is inert, earning no interest and not working for you. The fixed denomination means you can't withdraw arbitrary amounts. It severs one link, but doesn't give you a private balance.


The resolution was legal, not technical. In August 2022, OFAC sanctioned these contracts. In November 2024, the Fifth Circuit Court of Appeals ruled that OFAC had overstepped, arguing that an unmanned immutable contract wasn't anyone's property, and the contracts were delisted from sanctions in March 2025. Then in August 2025, developer Roman Storm was convicted of conspiring to operate an unlicensed money transmission business. The jury was deadlocked on the money laundering and sanctions charges, and the prosecution requested a retrial.


The code won, not the developers. This outcome can explain one more thing you might have noticed elsewhere in this section: both successors made a point to emphasize that they are not mixers. This sentence is legal work, not technical work.


Tornado also had two features brought into everything that followed. Your crowd only has people who have deposited the same denomination, so a withdrawal of an unusual size or at an unusual time will de-anonymize itself, which is the same behavioral failure as attacking Zcash users. Additionally, honest users have no way to prove their honesty. Clean money coming out of the pool looks the same as stolen money, so exchanges almost have to treat everything coming from that address as tainted.


What Tornado cannot do is the whole reason for the next step. It hides your history, not your holdings. You can obfuscate where the money comes from, but you cannot hold a private balance because the money just sits in the pool doing nothing.


Second Generation: Railgun, a Shielded Pool You Can Actually Use


Tornado is a coin swap window, Railgun is a private banking account on Ethereum that can still make external payments. You shield tokens into its pool on Ethereum (and also on Arbitrum, Polygon, and BSC), with the pool internally hiding the sender, receiver, and amount with zero-knowledge proofs.



Its difference from Tornado is worth noting because people always confuse the two. Tornado only takes fixed denominations, once, and refunds the same amount to a new address. Railgun accepts any amount of any supported token, maintains a continuous private balance, allows you to pay another Railgun user within the shielded pool, and enables you to interact with Uniswap and similar things without first unshielding. Tornado's crowd is other depositors with the same denomination, while Railgun's crowd is the entire pool on that chain.


The clearest understanding is: Railgun basically recreates Zcash's shielded pool in a smart contract on a chain that already has USD and apps. This makes its privacy stronger than Zama because it hides the transaction graph, not just the values on the graph.


However, the term 'DeFi-native' has an important caveat. When Railgun helps you exchange on Uniswap, it unshields the amount, executes the exchange in plaintext on the public chain, then reshields the output, all in one atomic transaction. So the transaction itself is public, but what is hidden is 'this is you'. Railgun anonymizes the actor, not the value, meaning it does not protect you from sandwiching: bots see the pending swap and its size and do not care who is behind it.


It also has a more elegant compliance answer, derived directly from the fatal flaw of Tornado. Private Proofs of Innocence allow users to generate a zero-knowledge proof demonstrating that their funds do not come from a known illicit source, without revealing where the funds actually come from, at the cost of a one-hour delay. So, you can be private and provably innocent — something Tornado has never allowed.


The practical use is through a wallet called Railway: shield, transact, unshield when needed. Vitalik Buterin publicly used it in 2023 and has spoken favorably about a compliance solution of roughly this shape, only adding credibility to this route.


The next segment should cool down the rest of this section. Railgun has shielded between $90 million and $110 million across four chains, with a total shielded transaction volume of approximately $5.16 billion, a protocol revenue history of $13 million, $4.6 million of which came in the past year. Zama holds $39.6 million, with a transaction volume in the first half of 2026 amounting to $452 million. Figures may not be directly comparable — Railgun launched as early as 2021, while Zama's mainnet only went live in December 2025 — but the direction is clear. In all accessible metrics, the zero-knowledge incumbent is larger than the FHE newcomer, and it's already taking money in.


There are two weaknesses worth mentioning, both rarely brought up. The pool is the crowd, so Railgun inherits Zcash's structural issue: at a shielded scale of around $100 million, the crowd looks respectable but not deep, quick to reveal privacy if thinned. Worse, sharding across four chains dismantles that crowd into four smaller ones, precisely the opposite of what an anonymity set would want. Secondly, transaction fees flow into the Railgun DAO treasury, not straight back to the token, so holding RAIL and holding economic interest in the protocol represent two distinct transactions.


So why bother with a third generation? Because of a restriction that's easily missed: Railgun can conceal your holding, but two people's holdings can never touch each other. Zero-knowledge proofs are about facts concerning data you already own; they cannot perform computations on hidden states owned by others. There's no blind-bid auction, no encrypted order book, and no treasury capable of arithmetic on deposits you can't see — this gap is the reason for everything that follows.


Third Generation: Zama, Wrapping Your Existings Dollars


You take regular USDC and wrap it into cUSDC — the same dollar, but with the balance encrypted. The ERC-20 is the standard recipe followed by every regular token on Ethereum, and ERC-7984 is the same recipe, just hiding the balance. A small fee is paid during the wrapping, and you can unwrap it back to regular USDC anytime.


▲ Wrapping USDC into cUSDC


What It Hides, and What It Doesn’t. The encryption is of two things: the amount of each transfer and your real-time balance. The balance is the bigger prize—on plain USDC, anyone can permanently see you hold $4.2 million; on cUSDC, that number is forever hidden.


Still public are your address, the counterparty’s address, and the time. The contract needs to know whose balance to update, so the address has to be in plaintext. The transaction graph is fully retained. What Zama hides is the number written on the side, not the side itself.


The practical consequences are worth stating plainly, because this is the easiest spot to misread optimistically. Paying thirty employees with cUSDC, everyone can still see you paid those thirty addresses and when. What you hide is the compensation, not the act of employment. Likewise for suppliers: what’s hidden is the billing cycle, not the vendor list. When the sensitive thing is a number, it guards you; when the sensitive thing is a relationship, it has little effect.


There’s one exception, which is structural rather than cryptographic. When there’s a contract in the middle (like a vault or an oracle), on-chain it shows you’re talking to the contract, not the counterparty. Depositing in a private vault won’t reveal who’s lending you money; paying someone directly will reveal who you paid.


Doing Arithmetic Without Unlocking


Zama adds a privacy layer to Ethereum and other compatible chains, with Solana in the roadmap. What enables it is the FHE approach from Section 3. The network needs to confirm you have enough funds, then update two balances without seeing either number throughout. FHE lets it perform arithmetic directly on locked boxes, yielding a locked answer.


This is something privacy coins cannot do. Zero-knowledge proofs can validate your own payment, but cannot perform new arithmetic on balances others are keeping hidden. FHE can.


▲ How FHE computes on locked boxes


No One Holds the Master Key


The most direct concern is: somewhere a company holds a key that can unlock everything. Zama's answer is to ensure that such a master key does not exist in any single location.


Eighteen operators run this system, divided into two types of roles. Five coprocessors perform cryptographic operations. Thirteen Key Management Service (KMS) holders each possess only a shard of the key, requiring the coordination of at least nine out of thirteen KMS holders before anything can be decrypted. A gateway is responsible for assigning tasks and verifying consensus among operators. The ZAMA token is used to pay for validation inputs and decryption fees, and operators must also stake these tokens as collateral, which will be forfeited in case of malicious behavior.


▲ Who runs Zama


This is an assumption, not an accident. The statement "No one holds the master key" is based on two conditions: that no more than one-third of the thirteen key-holding nodes are malicious, and that the AWS Nitro Enclaves where these nodes operate are indeed secure. The second condition pertains to hardware trust.


An Online Example: Private Yield on Morpho


The first product to implement this entire system is a savings cooperative. A cooperative is like a pool: it takes deposits, lends money, and pays interest to depositors.


You shield USDC into cUSDC and deposit it. Instead of going in directly—which would immediately expose your balance—it queues with others' deposits to form a batch that closes approximately once a day. When this batch closes, the network only decrypts the total amount of this batch, individual deposits always remain encrypted. This total amount is then invested in the Prime USDC vault of Morpho Steakhouse. This vault is standard, public, and audited, with an interest rate of around 4%, plus an additional online bonus. You receive a cryptographic share of it and your earnings.


This is not a mixer. Nothing is mixed, rerouted, or laundered through intermediaries. The money goes into a publicly auditable vault where everything is visible except for how much each participant contributed. The trade-off is that your privacy is only as good as that of the group, so the system waits until there are enough peers before processing.


▲ Private yield on Morpho


Second Product Launched: Confidential Large-scale Transactions


The vault holds what you have stored. The next product hides what you have transacted, with the latter being more commercially intriguing.


First, consider the problem it targets, as this scalability estimate is the strongest argument in this article. Large transactions do not occur on the public chain; they occur on OTC desks. The trend direction is also verifiable: in the year ending 2025, institutional spot OTC trading volume grew by 109%, while the top twenty trading platforms only grew by 9%, with 40% of institutions listing OTC as their preferred venue. The comparison with traditional markets is fair, not just rhetoric: approximately 59% of US stock trading volume is already completed outside public trading platforms, with dark pools hitting a record 40.3% in the first quarter of 2026, all with the sole purpose of executing large trades without revealing their hand.


Therefore, the insight underpinning this product is correct. We have spent ten years building a programmable, verifiable transaction infrastructure, yet institutions still discuss block trades in Telegram groups because that is the only way to execute large trades without being targeted.


Below, we will walk through the entire mechanism with a real trading pair, complete with numbers. Let's say you hold 1,000,000 ZAMA, shielded as cZAMA, and want to convert it to dollars. Assuming a mid-price of $0.25, you would be selling approximately $250,000, while the total shielded circulating supply of this token is only $6 million. These quantities are rounded for illustrative purposes; the key point is the ratio: on a public trading platform, such a transaction relative to that circulating supply is a gift to bots.


▲ A 1,000,000 cZAMA sale, with the dealer quotes and a table of who can read which field.


The trick in the first step is worth pausing to consider; it is the most ingenious part of the entire design and costs nothing. What you send out are two transactions, not one: the actual cZAMA you want to sell, along with a zero-value cUSDC leg. Both amounts are encrypted, and observers only see two legs going in opposite directions, with unknown sizes, making it impossible to tell if it is a sell or a buy. The principle of concealing "which asset you are trading" is the same, with the official commitment slated for a future version.


Before getting too excited, read the right-hand column of that diagram because that is where the promotion diverges from the mechanism. Indeed, public frontrunning bots cannot see your order, so the sandwich disappears. However, whitelisted market makers decrypt your intent and can see your volume. They cannot see your direction, which is a clever part; they also cannot see each other's quotes. The winning bidder will then be informed of the direction to finalize settlement. In the end, a select few professional market makers know your entire transaction, while a handful in real-time know your volume. This is the trust shape of an OTC desk, not an anonymous venue.


The third step is the one that finally validates the entire tech stack. Comparing two encrypted bids without decrypting either party, selecting the higher one is something only FHE can do, which zero-knowledge proof cannot achieve.


Progress must be accurate. It is an invitation-only private test, with three trading pairs opened: cUSDT to cUSDC, cZAMA to cUSDC, cSteakcUSDC to cUSDC. The public launch is planned for September 2026, with further cross-chain integration to follow. Currently, there is no significant trading volume.


The third trading pair is the one that holds the most commercial importance. It enables the manager to enter and exit a yield-bearing vault position without needing to decrypt the position or wait for the redemption period. The rotation between strategies is where many allocators truly make money, while leaking rotation is how they lose it.


What's Inside and What It Tells You


Zama releases a quarterly breakdown of shielded value composition, which provides much more insightful information than just headline figures.


▲ Zama's shielded value by asset class to 30 June 2026, with volume alongside it.


Four things stand out, but only one sounds good.


The vault is the largest single category at $18.8 million, exceeding the stablecoins at $14.1 million. Therefore, the first genuine emerging demand is not for private payments but for individuals seeking yield without disclosing the size of their position.


Excluding Zama's own token from the token category leaves almost nothing. Of the $6.8 million, $6 million consists of cZAMA. A protocol shielding its own token does not prove there is a market demand for shielded tokens.


The total for real-world assets is $52,200, all in tokenized gold. Reflecting on how many times the phrase "Confidential RWA is an institutional opportunity" has been mentioned, including in Zama's own launch material.


The truly critical figure lies next to the total. A shielded scale of $39.6 million, with a transaction volume of $452.3 million in six months, indicating a turnover of approximately eleven times. This is crucial in business terms because a confidential dollar only incurs a cost when it is in motion.


Five weeks later, the protocol's own dashboard made this point even stronger, and added three things that were not visible in the June snapshot. As of August 3, 2026, a cumulative shielded value of $3.208 billion and a cumulative unshielded value of $2.742 billion have moved approximately $5.95 billion both ways across the border, with the net position stabilizing at around $46 million.


The shielded dollars do not sit still; they flow through. cUSDT has shielded $1.308 billion, unshielded $1.228 billion, leaving $7.9 million. cUSDC has shielded $69.7 million, unshielded $65.1 million, leaving $4.7 million. Out of every stablecoin dollar that has come in, about ninety-four percent has gone out. This is a corridor, not a vault. For a protocol that makes money flow by money, this shape is right; for anything that makes money by balance sheet, this shape is wrong.


The money in the vault is four wallets. cSteakcUSDC has four distinct shielded wallets, with a net holding of $20.2 million, accounting for approximately forty-three percent of the total net shielded value within the protocol, corresponding to $28.2 million held in the Morpho vault. The largest and commercially most interesting category in this section is not a market, but four institutions. Any growth rate mentioned here, please bear in mind this—the whole thing can turn on the smallest redemption.


The line of real-world assets has truly started. In June, it was a $52,200 tokenized gold. By August, there were $5.1 million worth of tokenized pounds in cTGBP, $5.1 million in its wrapped version, and gold was at $60,300. Ten million dollars is still small, but it’s two orders of magnitude higher than a negligible remainder and is the first real evidence of the most talked-about line in this race.


To make a correction about the scale, an overly glorified number circulating outside. Zama deployed 549 contracts on the mainnet. Most reports cite 27,662 shielded contracts, including all public testnets dating back to July 2025, with approximately ninety-eight percent of that number not in production. Now there is an additional cBRON token, twenty-one wallets, and $1 million.


Why This Can Circumvent the Island Problem


Because it sits on Ethereum, those shielded dollars are the same dollars in someone else’s hands, able to work in applications that already have users. The privacy here is still programmable—the contracts can still enforce rules on hidden data.


This also leaves room for compliance: auditors or regulators can be authorized to view specific records, and freezes on the underlying asset would cascade to the wrapping layer. In May 2026, a court order did just that, freezing the entire cUSDC pool for three days. Section 8 talks about what happened at the time.


The Staircase, and the Cost of Each Level


Reading through three generations in a row reveals a pattern that none of the generations has highlighted.


Tornado hides your history. Railgun hides your holdings. Zama hides the holdings that can still interact. The existence of each level is defined by the specific thing the next level cannot do.


However, the cost has always moved in the opposite direction. Tornado hides the most but cannot do anything with that money. Railgun hides the sender, receiver, and amount. Zama only hides the amount, with the transaction graph being completely public. Each generation has acquired its functionality through concealment.


There is also a second axis moving in the same direction, adding more tension to this story. Tornado did not provide any self-proving method to honest users, causing exchanges to treat the entire pool as tainted. Railgun precisely addressed this with Private Proofs of Innocence. Zama went a step further, introducing viewing keys and inheritable freezes, which regulators can truly take advantage of. Therefore, the trend among the three is not that privacy has improved, but that privacy has become more usable and readable, with transparency emerging from concealment.


▲ All six designs plotted by how much they conceal against what the money can do while concealed.


The blank space in the upper right corner is the interesting part. The product of "concealing everything while enabling everything" is owned by no one, with Zama being the latest attempt to push that line upwards. According to each number in this article, it is also the smallest one.


On the Same Level of the Staircase, Who Else Is Climbing Up


Zama is the one with a mainnet, so it has been the focus of this section. Starting December 30, 2025, operating on Ethereum, it completed the first confidential stablecoin transfer on the same day. Named companies have used it in a production environment, and the token standard ERC-7984 has been implemented as an audited library by OpenZeppelin, along with a registry on-chain to map regular ERC-20s to the confidential wrapped version. The final detail is more valuable than any benchmark: writing a confidential token became an inheritance from an audited OpenZeppelin contract, stripping a technical feat of its niche and esoteric nature.


Zama won this round, and which round exactly it won is worth specifying: it went live first. This is a real achievement, and this section also gave it the recognition it deserves. However, going live first refers to timing, not a design limitation, and the route it has validated has more than one implementation. Fhenix, Inco, and Mind Network are all working on confidential execution on the same cryptographic base, but in earlier stages, and none of them have a mainnet for evaluation yet.


From this, two things that are easy to overlook can be inferred. Zama's launch is good news for all of them because the challenge in this category has never been about the math working or not, but about whether anyone is willing to pay to use it. The issue hanging over this question now is customers, not predictions. Another thing is: for such a young cryptographic primitive, having only a single implementation is a systemic risk, not a moat. The Orchard bug in Section 8 lurked in a codebase for four years without being discovered. The same idea has multiple independent implementations; that is the way such things get rooted out. Therefore, the second and third names here carry a value that is not visible in the "live product comparison."


Fhenix raised $22 million, led by Guy Itzhaki, who was previously responsible for homomorphic encryption at Intel, with backing from Multicoin and Collider. It uses full homomorphic encryption, part of the same family as Zama, rather than a different branch of cryptography. Secure multiparty computation appears in both (Zama's thirteen key holders and Fhenix's threshold service network), but only as the mechanism for split decryption keys. The real primitive responsible for concealment is the same.


It was originally an FHE Layer 2 but later abandoned this approach. The scoring released with the ACM CCS 2025 paper also supports modular design. That Layer 2 then became CoFHE, an off-chain coprocessor callable by any EVM chain, with economic security provided by staking on the EigenLayer below. It runs on Ethereum Sepolia, Base Sepolia, and Arbitrum Sepolia, with its documentation stating that the production mainnet is not yet available.


It has a token standard, FHERC-20, and a set of demos that can run: shielding any ERC-20, private payments, sealed-bid auctions, private stablecoins, on-chain price queries, delegation of read access to encrypted balances to a designated party, an anti-front-running Uniswap v4 hook, and two consumer-grade knickknacks. Canopy integration is slated for Q4 2026, and Offchain Labs has invested in Tandem to bring this technology to Arbitrum.


The truly important seven lines, viewed side by side.



Most of that gap is in the calendar, not in capability, but two lines in the table are not. Zama and Fhenix have already converged in architecture, so the "no new chain, no chain-hopping bridge" is not a point of differentiation; both can enable Solidity developers to add an encryption type in about one line of code. What truly sets them apart is which bottleneck each is tackling. In a homomorphic system, the delay users feel is in decryption roundtrips, not in arithmetic, and that is precisely what Fhenix is addressing: 64,319 operations per second, an 8.48-millisecond delay, published in ACM CCS 2025 and awarded Outstanding Paper. Zama's headline number is a thousand transfers per second on H100, self-reported and not yet live. Lab numbers degrade when they hit production, the two are not even measuring the same thing, but on the one axis where a direct comparison can be drawn, peer-reviewed numbers belong to the side that has not yet gone live.


The demand side is no longer a hypothetical; this is a more interesting development. From July 2 to late July 2026, Fhenix announced one acquisition and three integrations, each with a shape worth noting. It acquired Sunscreen, one of the earliest FHE teams in the industry, bringing a set of compiler technologies and a BFV research core, working in parallel with its own TFHE efforts, with Sunscreen founder Ravital Solomon joining to lead research. Sedona, a self-custodial transaction neo-bank, is migrating to Arbitrum and swapping its trusted execution environment for CoFHE, covering balances, positions, and the spending cap set for AI agents. Nomyx, focused on compliant RWA issuance, uses it to achieve selectively disclosed confidential positions: market-private, regulator-provable. Canopy then bakes privacy-preserving computation into its application framework. Coupled with earlier Monaco research collaborations, the mainnet is set for October, on Ethereum and Arbitrum.


There are three things on that list more important than quantity. The Sedona deal is a customer moving from TEE to FHE, the only evidence to date that this security upgrade is worth the latency a live product must bear. Nomyx points to point 2 about the regulated ledger—that area calls for not concealment but disclosure at the holder's discretion. And the agent spending cap is a use case that didn't exist when all this was designed initially; your adversary is software you yourself deploy. These are not revenues yet, October is a target, not a fact. But this is a pipeline with named counterparties, more than what a pre-mainnet protocol usually holds.


So the focus needs to be beyond the first mainnet. The issue in this category has never been whether the math works, but whether there are people willing to pay. Zama has now answered it with customers instead of predictions, which is beneficial for every implementation of the same idea. For such a young primitive, a single implementation is also a risk, not a moat, as Section 8 will soon demonstrate how costly a four-year-old undiscovered vulnerability in a codebase can be. At the same time, the first layer that goes live is a neutral layer, and a neutral layer almost never receives payment for what it delivers, so getting ahead of it does not mean staying where the money eventually flows. That's why the second and third attempts are worth watching: whether confidentiality is actually consumed through the common primitive or through what Fhenix is betting on, backed by Offchain Labs' Layer 2 and consumer-grade entry point, is still up in the air, and it determines where the value in this category lands.


How much revenue has this track generated


All of the above discussed what these designs can do. This section only talks about how much money they have made from it, because the answer is small, public, and the most under-reviewed number in this track.


Each number below is on-chain fee data as of August 2026. The last column is the key: in this track, receiving fees and earning revenue are not the same.



Start with the few lines about privacy chains, which hold almost all of the market cap in this track and are the clearest example. Monero has earned $1.58 million in fees throughout its history, Zcash has earned $1.37 million since 2016, and those are fees paid to miners, not revenue for any company. No entity is collecting them, and there is no profit inside.


There is a circulating number that needs correction, as it is off by nearly three orders of magnitude. In 2026, several media outlets reported Zcash's annualized fees are $405 million, surpassing Ethereum and Solana. Its actual past year was $567,000. The publicized number seems to have been extrapolated from a single high-activity window and happened to align with Zcash's price at the time, which is a more likely explanation. Using that headline to estimate the track's size would be off by a factor of seven hundred.


Tornado Cash is the most inspiring line. Its users paid $9.3 million, with the protocol not getting a cent, with every dollar going to the withdraw relayers, and the fee data clearly states the protocol's revenue is zero. The biggest mixer in the past decade created real cash flow for the operator, but it created nothing for itself—when sanctions arrive, it has no balance sheet to defend itself, which is also a reason. Railgun is a counterexample and the only real business on the surface, collecting 25 basis points on each side into the treasury. Out of a cumulative transaction volume of $516 billion, $13 million resulted in about nine basis points, corresponding to a nominal fee rate of fifty basis points. The gap itself is a clue: money is shielded once, can move freely inside for free, and only pays on entry and exit.


Altogether, the entire track's annual revenue is approximately $6 to $7 million from all protocols combined, while the value parked in these assets is about $25 billion. Two-thirds of the traffic in this pool flows to the successors of Railgun and Tornado. The chains that hold almost all the market value collectively receive only about $2 million per year.


The bottom half of the table is where Zama is interesting: it is indeed collecting fees but has switched to a completely different metering system. Instead of taking a percentage of anything, it charges per operation, priced in dollars per bit—proving a cryptographic input, decrypting a ciphertext, or moving it cross-chain. Homomorphic computation itself is free, deploying an application is also free, and no permission is required.



To put a number on this difference with its own traffic. In the seven months since December 30, 2025, the protocol has processed 104,848 on-chain transactions across 549 mainnet contracts, with $320.8 million shielded and $274.2 million unshielded, approximately $595 million crossing the border, with an average shield of around $24,000 per transaction.



Based on Railgun's fee schedule, this traffic would generate $1.49 million. According to Zama's publicly available price list, it generates between $840 and $84,000, likely falling in the lower half of that range because the rolling 30-day discount presses heavy users below a penny, and this traffic aggregates to let the largest payer qualify for the deepest discount. In fee terms: shielding a $24,000 transaction costs thirteen cents, which is one-fiftieth of a basis point; Railgun charges twenty-five basis points. Being undercharged by eighteen to seventeen hundred times, depending on where the real number falls in the range.


To be clear, this number is derived, not disclosed. The transaction volume is public on the protocol's own dashboard. Thirteen cents was a news figure at launch; the simplified whitepaper's price guide pegs a private transfer from eighty cents to eighty dollars, depending on the operation mix. So, the range is more important than any single estimate, and the argument does not require any single estimate—every reading of the public price list converges to the same spot. By the way, the exact number is knowable: every protocol fee is burned, and the cumulative burn on that address is an observable version of the figure, open to anyone checking.


Why So Cheap


The most straightforward interpretation is that Zama mispriced itself. A more likely reading is that it onboarded customers first and will charge later, a case that the evidence points toward, rather than toward an oversight.


A 25 basis point toll is a tax on every integrator, and what Zama is trying to do is the cloakroom someone else builds on top, not a place that competes with them. Priced like a cloud service, it can justify your token standard being both an OpenZeppelin-implemented, audited library, a wrapper registry, an integration path to wallets and exchanges, and a payroll company willing to run salaries atop you. None of these buyers will come through a fifty basis point tollbooth. Bron won't pay 25 basis points for a single salary run, and that treasury with four wallets containing $20.2 million won't pay it to shuffle positions.


So, this low fee is doing work. It's really scarce things at this stage that it's buying, benchmark customers and a standard someone else will adopt, and driving revenue to the day trading volume is high enough to warrant a small fee. Under this reading, the current fee item is a cost of customer acquisition rather than a business, and the figure to watch is not this year's fee, but whether that toll collector will change.


Two things make this reading falsifiable, not just indulgent. The fee can rise without moving cryptography: at today's trading volume, $5.65 per transaction per annum makes a million dollars, and it's still about a tenth cheaper than Railgun on a basis point basis. And value is accumulating somewhere over this time: upstream, to the operators, not the neutral rails below, which is why pricing is more important to Zama's economic model than the protocol itself.


Privacy Tech: Where It's Failed


It's easy to write privacy tech as if it all holds up. There have been three incidents worth knowing, each bad in a different place: the cryptography itself, the software wrapped around it, and the law above both.


▲ Nine years of privacy failures, grouped by which part of the stack gave way.


Zcash: The Orchard Bug of June 2026 and Its $30 Billion Cost


Starting with the most recent, as it's the single most costly meltdown in this race and can explain a price action many remember but don't know the reason for.


On May 29, 2026, a security researcher named Taylor Hornby (who had been commissioned by Shielded Labs in April) discovered a soundness bug in the circuit behind Orchard. Soundness is the property that makes a zero-knowledge proof valuable, ensuring that you cannot create a valid proof for a false statement. With this bug, you are able to. Hornby developed an exploit that could infinitely mint counterfeit ZEC in a test environment, completely undetectable.


Since Orchard launched in May 2022, this bug has been lying dormant in that circuit. For four years, through multiple professional audits, no one found it. He found it with the help of an AI model (Claude Opus 4.8) and a set of in-house analysis tools. That is the truly fresh fact in this article. The audit process that repeatedly cleared this code was human, but what ultimately broke it was not.


The engineering response was swift. An emergency soft fork on June 2 disabled Orchard operations at a specified block height. On June 3, a hard fork carrying the fixed circuit completed the permanent repair. There was no chain split, and no funds were lost.


Then the market took over. The disclosure was made public on June 5. ZEC had actually risen before the announcement, from around $544 to $624, as a clean emergency fix was seen as a hallmark of a rigorous engineering team. Once the substance landed, it dropped to around $309 within 48 hours, a retracement of almost 50%, wiping out over $3 billion in market cap. Arthur Hayes publicly exited on June 4, stating that privacy assets need perfection, not just "good enough," triggering forced liquidations among leveraged holders. Monero sympathetically dropped by about 13%, so the market interpreted this event as a Zcash issue rather than a privacy issue.


Now, the part that should really worry you, and it's not the bug itself. Shielded Labs bluntly stated that cryptography alone cannot determine whether the bug was exploited prior to its discovery. This is not an insinuation but a direct consequence of design. A shielded pool's ability to conceal counterfeiting is as strong as its ability to conceal payments, so a potential four-year window of undetected inflation cannot be closed by blockchain analysis. Their remedy, implemented as Ironwood, involves gatekeeping every Orchard coin to make the supply independently verifiable.


For newcomers, this is the most important concept of this section. The tension between privacy and auditability occurs at the level of the currency's money supply itself, not just at the level of "who paid whom."


So, is it really a vulnerability? Yes, and a severe one at that. When you spend shielded money on Zcash, you don't show the coins to the network. You present it with a cryptographic proof, proving you own them and haven't double-spent. The vulnerability lies in that proof verifier, which can accept certain forged proofs. This means creating ZEC out of thin air.


Has it been exploited to steal anything? Most likely not. A researcher hired specifically to find such issues discovered it, validated it on their testnet, and it was patched two days later. There's no known instance of anyone exploiting it on the mainnet.


Can anyone prove it hasn't been used in those four years? No. On a transparent chain, you can count coins; too many coins mean someone is counterfeiting. Zcash's shielded pool is deliberately made uncountable because that's the product itself. So the honest answer is: there's no evidence it has been used, and this cannot be elevated to proof that it hasn't been used.


That leaves one glaring question: if no money is lost, why did the price tank by half? Because ZEC's entire proposition is that airtight math, and "probably fine" and "airtight" are two different products.


It's worth noting that this is the second fake vulnerability of the same category, with the first one present in the proof system used when Zcash launched back in 2018. Two different proof systems, separated by eight years, the same shielded pool design, and twice the chain can't tell you if they've been utilized. This is a pattern, not a stroke of bad luck. There's an added layer of irony in this pairing: Orchard exists because the trusted setup was seen as Zcash's biggest outstanding risk, and Halo 2 was adopted specifically to eliminate it. The very pool built to be trustless turned out to be unreliable later on.


Zcash: Wallet Leak, the More Canonical Failure


This incident is smaller but is the most emblematic failure in this section.


In October 2025, investigator ZachXBT tested the shielded-to-transparent exchange feature in the Zcash main wallet, Zashi, routing via NEAR Intents. He hopped Solana to Zcash and then cashed out to ETH. An accidental 0.001598 ZEC refund landed on his transparent address, fully visible. NEAR Intents were routing refunds through a visible Zcash address instead of the shielded pool at that time, and the wallet was consistently reusing the same transparent address. By timing and amount, you could de-anonymize someone's transparent address, linking it to their shielded activities.


Nothing was stolen, and no cryptographic breakthrough occurred. The proof itself is sound. The issue lies with the integrations surrounding it.


Regarding the fix, precision is key as it has only been half-implemented. Exchanges will now generate a one-time transparent address for each transaction, following a standard called ZIP 320, eliminating the long-lived, historically accumulating addresses. The shielded exchange was announced on November 17, 2025, in the Zcash community forums, approximately a month after the disclosure. The second commitment, regarding embedding the refund itself in the shielded pool, has not been publicly confirmed: a user directly inquired about this in the same thread on November 20, 2025, without a response, while wallet support documentation still requests users to provide a refund address without specifying if it must be a shielded address.


Furthermore, there is a residual leak that no fix can eliminate. Sending shielded funds to a one-time transparent address requires two public transactions, one to unshield and one to spend, allowing observers to potentially link the two for any single exchange through timing and amounts. The one-time address you receive shields your multiple exchanges from being linked by anyone or associated with the rest of your wallet.


Zama: No Exploits Yet Exploited, But Already Most Inspirational Failure


It has not experienced any protocol exploit events, which is exactly what you'd expect for something that went live in 2026 after around seventy audit weeks. Zama faced a failure on a legal front, and that's the one you should lay before any entity considering this product.


On May 30, 2026, at 01:08 UTC, Circle blacklisted Zama's cUSDC contract on Ethereum, freezing 12,606,386 USDC. The trigger was a temporary restraining order issued by a US District Court a day earlier, alleging in a civil suit that a founder of an unrelated protocol, Overnight Finance, had moved over $15.77 million out of its treasury just before a shareholder vote liquidation and had deposited $12.4 million of that into cUSDC on the same day.


Now let's address the part that potential users should pause and think about. cUSDC is a pooled contract. Blacklisting it locked every depositor, not just the contentious address, and that contentious sum represented over 99% of the pool. On June 1, a judge in the Northern District of California lifted the order, releasing around $12.5 million. This is a known instance of a Circle blacklist in a private civil dispute at the contract layer being overturned through litigation.


Both readings of this matter are correct, and you need to hold them both at once. The compliance hooks are real, and that is why a regulatory body is willing to touch this product. And they are indiscriminate, and that is the cost you pay for the "privacy a court can still reach into." A shared pool is not just a shared crowd; it is also a shared fate.


The Common Thread of These Three Events


None of them involved someone breaking the cryptography and stealing money. The Orchard bug was patched before disclosure and was never exploited, yet it still led to over $30 billion in losses, so if you hold a privacy coin, you are shorting the news of the bug, not the bug itself. The exchange leak was an integration detail, not a proof of failure. And the freeze came from the court, beyond the reach of any audit.


And this points to the same conclusion that the rest of this article repeatedly arrives at: math itself has withstood the test, but the software around it and the laws above it have not.


So, What Is It Really Worth?


All of the above is established fact. What comes next is judgment and three contentious questions.


There are many names in this field, and people usually classify them by cryptography, which provides almost no useful information. Instead, classify them by their place in the tech stack, as that determines who the customer is and what this thing charges for.


▲ The privacy sector has four layers plus two groups that cut across all of them.


Question One: Is There Real Demand?


Yes, and this is the strongest part of the entire argument.


JPMorgan's Project EPIC is not a hobby. Crypto fund subscriptions, blind pool auctions, silver deliver-vs.-payment achieved on hidden numbers, identity proofs for crypto data where the bank itself can't read the details. Then it issued real deposit tokens on Canton. Circle is testing a private version of USDC on Aleo. Coinbase absorbed the Iron Fish team. Goldman Sachs and BNY Mellon are backing Canton. This is not a narrative but a pattern of capital expenditure.


On the transaction side, slippage is quantified, not asserted. A sandwiched trade incurs a fee of 0.3% to 0.8%. On perpetual platforms, every position is public, including its liquidation price. The clearest evidence is that institutions execute over half of their trades off-screen to avoid revealing their volume.


Issue 2: Does Privacy Really Reduce Risk?


It reduces the risk of being targeted. Adversaries choose their prey based on what they can see, so hiding your balance can keep you off the list. This is a valid and arguably the strongest claim privacy can make.


It does nothing when breached. A stolen key empties a crypto balance just as fast whether it's private or public. Malware, a mistaken signature, a compromised frontend: encryption protects the ledger's content, not your device or your judgment.


And it actively makes recovery worse. Monero's own community couldn't trace a stolen crowdfund wallet because Monero works as intended. Privacy is asymmetric in time: it shields you pre-attack and the thief post-attack.


At the protocol layer, it's worse because privacy blindsides the defense too. On a transparent chain, an exploit is visible in the supply within days. Orchard's reliability flaw remained undiscovered for four years, precisely for that reason. More privacy machinery also means a broader attack surface: thirteen trustees, five coprocessors, a gateway, a threshold relay, and an AWS redoubt underlying it all.


Issue 3: How Do You Price It?


This is the question this space dodges, and it has a real answer. The value of privacy equals the cost of leaks. Three categories can be computed.


Slippage impact is the cleanest one. A sandwiched trade incurs a loss of 0.3% to 0.8%, so eliminating it on a billion-dollar annual flow creates roughly $5 million of value, and then you can argue how much can be captured. Railgun provides the only real datapoint in this space: $51.6 billion in cumulative traded volume yielding $13 million in cumulative revenue, even if it catches only nine basis points.


The market impact of block trades has long been priced, and this is a point overlooked. Institutions pay an OTC desk a spread precisely to obfuscate their volume. That spread is the observable market price of privacy, and it is being paid today on most institutional trades. The accessible market for confidential trading is not conjectured; it is the existing OTC spread pool.


Alpha decay caused by slippage is real, but no one has ever put a number on it. To calculate it, you need to run the performance differential between tracked and untracked addresses running similar strategies. It's worth noting outright that it is unmeasured, rather than pretending to be known.


Now apply this methodology to the next obvious product. If Zama were to create a private AMM, how much would be hidden in position value? There's one constraint that changes the answer: the AMM needs a public reserve to have a price. Encrypting the pool holdings would break price discovery. What can be hidden is an individual LP's share and the volume at order submission.


This means the value of a private AMM is primarily in order flow privacy, not position privacy, which brings us back to the first category: basis points saved in execution. Hiding LP positions is indeed valuable, but smaller, mainly to prevent active strategies from being copied and to prevent front-running your fees. So the valuation is the sandwich tax attracted to its trading volume, multiplied by a close-to-9-basis-point capture rate akin to Railgun. At a billion dollars in annual trading volume, that's millions of dollars in protocol revenue. Real, but a far cry from a billion-dollar valuation.


There's a fourth category, and the products already launched fit right into it. Some leaks simply have no transaction to measure against.


Look at what actually happened on the mainnet in the first seven months, as it wasn't what the above scale estimation predicted. Bron's CFO issued the company's payroll using private USDT. Raycash rolled out a Revolut-style account with IBAN, card, and yield, all while keeping the balance private. GSR completed the first confidential institutional OTC trade in March 2026, with two KYC-ed counterparties transacting on-chain. TokenOps did private unlocks and airdrops, Zaiffer converted regular ERC-20s to private, and Zama used both on its own token. In July 2026, Elliptic was onboarded for compliance screening.


Only GSR fits into that basis point story. The rest are enterprises buying "one piece of undisclosed information," and the harm they avoid doesn't scale with the size of the transfer it rides on. A single payroll leak costs your team their mutual salary knowledge, and your competitors know your burn rate. Publicize an unlocking schedule, and you risk having your own unlocks front-run. These are fixed harms attached to a fact, not percentage losses attached to a payment.


This affects pricing, not demand. The demand in this category is broader than the transaction narrative, and it is less suitable for per-transaction pricing than any of the first three categories, which is exactly what fee data shows.


Ongoing Debates Yet to Be Resolved


Is Privacy a Chain or a Feature? As of July 2026, evidence remains split along a single axis that continues to confound. The Feature side has prevailed in new use cases: Shielded Quote Transactions, Confidential Treasury, and Payroll. The Chain side has prevailed in terms of valuation, with Monero around $12.9 billion, Zcash around $7.1 billion, and Zama at $115 million to $142 million. Two distinct markets, two different sets of buyers.


Is Opt-in Privacy a Trap? It creates a small set, and a small set is weak privacy. That has been the decade-long flaw of Zcash. What changed it is the least glamorous thing you could think of: not cryptography, but a wallet. Starting in February 2024, the Electric Coin Company made Zashi, default privacy, with all three pools behind a single address, and the exchange feature allowing buyers of shielded ZEC with just a few clicks. The shielded supply ratio increased from around 5% to over twenty to almost thirty percent, while the shielded transaction ratio increased from around 30% to a reported peak of 59.3%. Then-ECC CEO Josh Swihart put the cause and effect bluntly: after Zashi, shielded pools exploded exponentially. The timelines match up.


There is a vulnerability here, and it’s at the governance level rather than the technical level. In January 2026, the entire Zashi team collectively resigned from ECC over governance, funding, and autonomy issues, forming the Zcash Open Development Lab and renaming the wallet to Zodl in February 2026. So the one piece of software that carried the torch for Zcash privacy adoption is no longer being built by the foundation governing the protocol.


Is Privacy That's Compliance-Friendly Still Privacy? Critics argue that a privacy system with a covering switch is a turnstile, not a privacy system. Supporters argue that it’s the only version institutions can legally touch, with the alternative ending up like Tornado Cash. Both sides are right. They are selling to different customers, and both types of customers exist.


Regulatory Clocks. The EU Anti-Money Laundering Regulation (specifically Regulation 2024/1624 Article 79) will come into effect on July 1, 2027. From that day forward, crypto service providers must not maintain anonymous accounts or handle privacy assets like XMR, ZEC, and will be overseen by a new regulatory body called AMLA that supervises approximately forty of the largest providers. Pay close attention to the scope: this bans exchanges from dealing with these assets. It doesn’t block out the chains. What it siphons away is Europe’s regulated liquidity, with the second-order effect being to drive the market towards auditable privacy.


What to Watch


Four numbers, checked quarterly.


Volume on privacy-preserving exchanges, sourced from unrelated counterparties. Since launching in September, this is the number that determines whether a trade narrative holds up, as exchange fees buy back ZAMA, and volume is the cash flow. A venue with no strangers on the other side, just a private muttered soliloquy.


Railgun revenue compared to Zama's. Incumbents have already seen about nine basis points in real traffic. If Zama can't come close to that level within a year of going public, there's no premium being paid for FHE.


The first company outside the crypto industry to pay salaries or suppliers with a privacy coin. Note that cUSDC hides the amount, not the supplier list, so this use case needs more than just crypto balances to actually work.


Canton Coin fee revenue if it's ever auditable. A $48 billion token built on opaque usage that no one outside can verify is the largest unaudited valuation in this race.


Zama's realized fee burn, in USD terms. Every protocol fee is burned, so the cumulative burn can be queried on-chain, and it's the only indisputable measure of whether anyone is paying. It's currently four digits and forecasted for five. The month it moves a magnitude is the signal that pricing has shifted, and that's the single richest number in this email.


Will those four wallets become forty? Forty-three percent of the net shielded value is parked in four addresses. The drop in concentration matters more than the rise in total.


Will someone start charging subscriptions instead of metered billing? The gap noted above is of a pricing variety, so the first product that prices by seat, asset size, or spread over a meter in privacy is more worth watching than the next crypto scoring.


Fhenix's mainnet timing and whether its rollup is built on its own cryptography. These two answers determine whether in the FHE category, there's one firm or many.


Conclusion


Three answers to one question, with a candid summary of them all being a trade-off, not a victory. Every design in this post is for buying more exposure to do more, and the corner of "hide everything and run everything" is vacant here.


The demand is real. A bank has spent real money to prove it, traders are losing measurable basis points, and institutions have been sending most of the trades to desks that are all about "not showing your hand."


But privacy isn't a one-time security upgrade. It changes who targets you and makes it harder for you to reclaim your money, and at the protocol level, it hides the flaws of the very thing you are trusting.


And the valuation doesn't match the income. Approximately $250 billion in value is locked in privacy assets, distributed across Monero, Zcash, and Canton Coin. On the servicing side, the numbers are now precise rather than ballpark figures, and they are less than single-digit million dollars. Railgun, the best performer among them, charges 25 basis points on each side, has cumulatively earned $13 million, while Monero and Zcash have earned $3 million in fees combined since 2014 and 2016, respectively. Zama has processed 104,848 mainnet transactions, moved $595 million across its borders, and because it charges based on bits rather than basis points, based on the publicly available fee schedule, it has received only between $840 and $84,000. Running Zama's traffic through Railgun's fee schedule yields $1.49 million, which is an overcharge of eighteen to seventeen hundred times, depending on where the actual numbers fall within the range. Converted into rates, it is one-fifth to twenty-five basis points of a basis point.


So the dilemma presented at the beginning of this article has been resolved, and the answer is better than any of its corners. These services are underpriced not because no one wants them. They are underpriced because the meter is attached to the wrong thing. A protocol that charges based on bits hides a $20 million treasury position and a $10 transfer behind the same fee, and currently four institutions are collectively hiding $20 million for a few cents.


This is also why I end this piece on a bullish note, but with a caveat on "bullish on what exactly."


The demand is verified, not predicted, and this is rare at such an early stage. A bank has spent real money to establish the viability of crypto finance, then issued its true deposit token on the track it built itself. Institutions have pushed most trades off-screen and paid a spread for that privilege. Dark pools captured a record 40.3% of US stock trading volume in Q1 2026. Money is already flowing privately everywhere as long as it is allowed, and the only question that the public chain needs to answer is whether it can provide the same obfuscation without relinquishing the programmability that made it worth using in the first place. As of August 2026, one of them has achieved that, with real companies on top in a production setting, $595 million flowing across borders, and money turning over eleven times.


Technology is no longer the constraint it once was, and that has been the silent shift of the past year. Privacy coins now have a standard and an audited OpenZeppelin implementation, so coding one is now about inheritance rather than cryptography. A court order pierced through the obfuscation layer and was lifted in three days, a compliance feature discovered the hard way, not a failure. And the regulation that arrived on July 1, 2027, stripped European liquidity from anonymous assets, driving everything toward the auditable privacy these designs happen to provide. All the pieces are in place, and the clock is ticking in their favor.


What is missing is a price, and a missing price is the easiest problem to solve in this text. Charging $5.65 per transaction instead of thirteen cents, with today's transaction volume, could earn a million dollars a year, while still undercutting incumbents by a factor of ten. This requires no mathematical improvement. It simply needs someone to charge the obfuscated in the same way they are billed elsewhere, by seat, by subscription, or by asset under management basis, with the first batch of customers, the procurement team anticipating a bill that looks just like that shape.


So the position is a long demand, and the long ultimately pays the fee, and by current indicators, that is the exchange, wallet, or authorized entity, not the underlying neutral layer. Verify it with four figures: the volume from strangers post-September launch, the dollar value of actual burned fees, whether the four wallets in the treasury become forty, and the date the first private subscription invoice is sent out. The buyer with budget line items is a bank, not a crypto punk, and the encouraging part in all this is that the bank has already started shopping.


Original Article Link


Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia

Choose Library
Add Library
Cancel
Finish
Add Library
Visible to myself only
Public
Save
Correction/Report
Submit