Unchained - Zcash, Ethereum, Aztec, Canton and More: Which Chain Will Win the Privacy Race?
Episode Date: July 31, 2026Privacy is having a moment in crypto. As competition heats up, the pitfalls of the technology around the quantum threat, regulatory risk and more make the trajectory hard to predict. A counterfeit... bug sat undetected in Zcash's Orchard privacy pool for four years, capable of minting an unlimited supply of untraceable coins, illustrating the risks of one of the hottest crazes in crypto. Joe Andrews, CEO of Aztec Labs, Jarrad Hope, founder of Logos, and Mert Mumtaz, cofounder and CEO of Helius, join Laura Shin to argue the bug is less alarming than what it reveals: cryptographic privacy is difficult to get right, and the industry is racing to get it right anyway, because institutions will not come onchain without it. They cover Zcash's quantum-recoverable Ironwood upgrade and the turnstile proving the counterfeit coins never moved, Ethereum's sprawling privacy roadmap and the risk it arrives too late, Logos' mixnet built to protect validators from block relays now censoring transactions, and why all three see Canton's private stablecoins as little more than a bank with extra steps. The fight over what actually counts as privacy on a blockchain is only getting started. Host Laura Shin - Founder, CEO and Host of Unchained Guest Joe Andrews - CEO of Aztec Labs Jarrad Hope - Founder of Logos Mert Mumtaz - Cofounder and CEO of Helius Sponsor Cape: Your biggest crypto vulnerability isn't your wallet, it's your phone number. Cape is America's privacy-first mobile carrier that rotates your SIM identity daily and blocks SIM swaps before they happen. Get 33% off your first six months at https://cape.co/unchained (use code: UNCHAINED). Timestamps: 🔐 01:52 Why Joe, Jarrad, and Mert think privacy's crypto moment is now 💙 18:18 Cape: Get 33% off your first six months with code unchained at https://cape.co/unchained ⚖️ 19:14 Why Jarrad says the weak need privacy and the powerful need transparency 🔬 24:49 How zero knowledge proofs actually update encrypted state onchain 🕸️ 33:07 Why 43.7% of block relays now censor, and how Logos fixes it 🐛 36:32 The undetected Zcash bug that could have minted infinite fake coins 🔒 46:32 Mert explains how Zcash's Ironwood upgrade closes the counterfeit hole 🛤️ 51:44 Why Joe worries Ethereum's privacy roadmap might arrive too late 🏦 57:39 Why Mert calls Canton no more private than trusting JPMorgan Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
I don't consider a leader in the privacy space any more than I would consider JPMorgan a leader in the privacy space,
which is to say that those guarantees in terms of privacy that you would get,
which is just trusting your counterparty are totally achievable without using crypto in the way that they've done it.
And so I don't see any reason why I would want to expose myself to that.
Like why I would want bank level guarantees, I would just use a bank.
Hi everyone, welcome to Unchained.
You're no hype resource for all things crypto.
I'm your host, Laura Shin.
Thanks for joining this live stream,
and we will first take a quick word from the sponsors
who make the show possible.
This episode is brought to you by Cape,
America's Privacy First Mobile Carrier.
Same premium service you'd expect from any other carrier,
but designed so your number, your location, and your data actually stay yours.
Get 33% off six months at cape.co slash unchained.
Today's topic is privacy.
Here to discuss are Joe Andrews, CEO of Aztec Labs, Jared Hope, founder of Lagos, and MertMutt Muntaz, co-founder and CEO of Helius.
Welcome, Joe, Jared and Mert.
Good to be here.
Hi, thanks for us.
Hey, yeah, thanks for having us.
We're facing a moment in crypto when it just feels like privacy is going to start mattering a lot more.
It's already starting to matter a lot more.
And more chains are going to be adopting it in various ways, and they always.
already are working on that. Obviously, Zcash saw a huge renaissance in the last year. Manero also
got a boost. Ethereum announced this privacy roadmap. NIR had or has confidential transactions.
Canton is drawing institutions to its private chain and more. But before we get into all the
details on that, let's just start with each of you explaining your interest in privacy and why you
think this is the moment that this direction is gaining momentum now. Why don't we
start with Jared? Sure. I guess like, you know, I got into like the space through the sort of
BBS and piracy scene and found Sleferbunks and like crypto anarchy. So in the 90s, I was already
pretty naturally inclined towards these ideas. But and I've argued, you know, for privacy on a civil
Liberty's standpoint, as well as, you know, against the sort of surveillance state,
particularly after 9-11.
But I think what's interesting to me about it now is like how my thoughts have developed
a lot more.
And I started to realize that it's privacy is actually a property that's required to
unblock new market activity as well as creating stronger institutional quality.
I don't know if you want me to go into that in more detail now,
but it requires a little bit of understanding of token,
sorry, transaction cost economics and institutional economics.
Sure, go ahead.
Maybe I'll let the other one less.
Oh, yeah, okay.
So I guess like it's, when you think about like what a blockchain is actually selling, right?
It's not really saying just block space, right?
We have all of these mechanisms in place to effectively create what's called credible commitments.
Credible commitments is like this notion behind an institution and what makes an institution like pretty high quality.
So for example, like a state can be very powerful, but he who giveth can take it away, right?
So what actually matters in terms of an institution is its ability to be able to hold
its promises, right? Hold in such way. So these promises are effectively called credible
commitments and there's two types, right? There's motivational commitments. This is like,
trust me, bro, I've got it, don't worry about it, I'll honor my agreements. And then there's
imperative commitments, which are a lot stronger. And we started to see like, an example of this is
like in medieval times, right? A king might have some kind of deal with.
with another king and leave their firstborn son with the other king as kind of collateral.
Williamson basically talks about the sort of ideal version of this, which is the ugly princess,
right?
It's a lot of high value to the father, maybe not so much value to the other king.
But if the other king does not honor his agreement, then, you know, maybe there's a beheading
involved, right?
So this is an example of an imperative commitment.
So in blockchains, you know, we do this with, you know,
cryptography.
We do this with, you know, game theory, mechanism design, and even decentralization.
These are all things that basically make the commitments that are made on chain much, much stronger.
Now, the other side of this is, like, a lot of people think of a transaction when it happens on chain is, like,
and that's basically the only thing that's happening
of a transaction, right?
But in transaction cost economics,
there's like seven steps that are involved in a transaction.
You can view this as a life cycle or a process
or even a supply chain.
And the blockchain is really only doing
the settlement and some of the other ones, right?
So think about it.
Like, when you do a transaction,
you actually have to discover your counterparty,
you have to communicate with them.
You then have to, you know, negotiate
or come into contract with them, and there's a few things that happen after the fact as well.
Now, the problem is, is like, pretty much the reason why crypto, you know, has kind of a bad
reputation these days is because a lot of people are making these motivational commitments
outside of the chain itself, right?
Whether it's a centralized exchange that goes bad or, you know, a scam, and so on.
And each one of these steps effectively has sort of hazard.
quality to it, right? You have basically two people who can prevent you from doing a transaction
any of these steps, right? One is your counterparty, right? They might have some self-interest
and try to undermine the transaction or, you know, scam you on some sense. But then there's also
the class of actors who are not directly involved in the transaction. So this might be, you know,
a hacker, this might be the state, it might be a competitor, and so on.
on. And their capacity to influence the transaction that you're making is really determined by,
let's say three things, right? It's capacity for coercion, both you and your counterparty,
it's impunity, like what its estimate of its recourse is, as well as the information of that
transaction, right? And that information is really important because we can't really
modify its, this predators or this other actor's ability to, we can't change the coercion
really easily unless, you know, maybe we, you know, get violent in some sense.
We can't really do much about impunity unless, you know, we're relying on a very strong legal
system, you know, as an example.
But we can control information within these systems.
And if you can reduce that information down to zero, then the capacity for influencing a transaction also drops.
And so this is kind of where privacy comes into play, right?
If you can secure privacy at each of these steps in the transaction and provide not only privacy,
but also like integrity to those steps in transaction, you start to understand why like we cared about decentralized file storage systems.
You know, for example, you know, the ByBit hack could have maybe been prevented by having a higher sort of integrity over the content hash over accessing its front end, for example, rather than being served through the motivational commitment of running a server on Amazon or wherever it was.
So that's what I really care about because as you do this, you reduce the hazards that.
involved in any kind of contracting, which then allows or unblocks market behavior.
And this means like institutions can come on.
It means that, you know, people who are not transacting because they got hurt by some other
system or actor can come on.
You can quantify this, right?
You could even look at blockchain forensics as a, I can't remember how many billion dollar
industry it is, right?
but they are looking at this information
and that's preventing a lot of other market activity
from happening on chain.
So that's a nutshell of why I care about.
I mean,
like what comes to mind is almost,
I know it's like a funny analogy,
but when there's a party and let's say it's a more formalish party
and the music starts and the dance floor is empty,
it's like who will go on the dance floor first?
And it's sort of like that when you have these
public transactions, right? That everybody can see, everybody can watch. It, like, just exposes
you in different ways. So that makes a lot of sense. Mur, do you want to explain, you know,
what your interest is in privacy and why you think this is the moment it's gaining traction?
Sure. So I have two main interests in privacy and crypto specifically. Obviously,
there's privacy and trust outside of crypto, but I'll reduce the scope. One is,
in the frame of Zcash.
And there what I'm interested in is the original ethos and idea of Bitcoin, which is to say
an alternative monetary currency that has a shot at being a safe haven or being able to separate
money from the state in some capacity for some segment of the market.
Right.
I think that's primarily why a lot of people.
at least back in the day, got into crypto and why it's still clearly the number one asset in crypto
by several lowers of magnitude.
And there's a lot of problems.
There's a lot of unfinished sort of paths that Bitcoin sort of left in my view, right?
So the way I tell the story is generally something like, first we had to prove that
cryptographic money could work, and that was Bitcoin and had to gain legitimacy and traction.
and you have to just prove out the concept.
And then Battala came and said,
well, actually, it's sort of weird
that this isn't programmable, and then Ethereum came.
And then perhaps Salana came and said,
this also has to be scalable.
But then the concept of privacy,
which ironically is implicitly assumed
when you're talking about Bitcoin
to anybody outside of the industry, right?
So for example, if you ever watch a TV show,
something like a blacklist,
and the content,
in which Bitcoin comes around is generally some criminals asking another person for ransom.
And every time I watch something like that, I'm like, what are you doing?
That is way more traceable than cash.
It makes absolutely no sense.
And so it's this deep sort of belief that you think, oh, it's cryptographic money.
Obviously, it must be private, right?
And so it's not even really understood that I actually know it is traceable digital gold
as the official Bitcoin account,
which I'm not even sure who owns that,
on Twitter literally says in their bio.
Right.
And there's all sorts of supporting anecdotes here.
So, for example, when Halifini was alive,
he would tweet about wanting to add anonymity to Bitcoin.
And you can see the early Bitcoin forums
where Satoshi himself says something like,
if this was possible, referring to using ZK,
this would make for a better, more efficient implementation of Bitcoin,
but I don't know how to solve a double spend problem.
And naturally, that was because ZK was super early in its, I mean, Zcash didn't exist.
There was no production deployment of ZK Snarks at that time.
But now we have the tech, right?
And so now it feels like especially at a time where all sorts of liberties
and let's say things that you took for granted are being attacked,
whether it's age verification, whether it's AI, being able to make sense of unstructured data,
or whether it's the institutionalization of crypto, there remains that last branch,
which is, or the last frontier in my view, which is not only in terms of market cap and price,
but also in terms of impact and clear market gap, right, which is adding privacy to this internet currency.
The second part is, let's say slightly more boring, but it is sort of a prerequisite.
for being able to do finance at scale, right?
Nobody really thinks of privacy as a scaling technology,
but it actually is a scaling technology
because without it, a very large group of actors
physically cannot come on chain, right?
So what's been most ironic in this past cycle
since we've had Trump as president
and perhaps there's been some regulatory clarity
is that while your average user
might not care too much, perhaps through,
lack of education or some other thing.
The institutions that are coming on chain absolutely care for
OPSEC reasons, regulatory reasons, legal reasons, all sorts of other reasons, right?
Like they physically cannot come on chain in a meaningful capacity beyond some
newspaper headline for a very basic POC.
It's very hard for them to actually move a significant portion of their business when you can
see, well, here's all the people who have this token, here are all.
the loan parameters and it so within the context of privacy security that's a complete non-starter
for any serious financial institution and so on the other side of this where I'm building on salon
with calius we're building a zK privacy protocol to help alleviate a lot of those gaps so
to basically to answer your question twofold one is the currency and then two is the scaling of
finance. I love it. So interesting. All right, Joe, what about you? Why are you interested in
privacy and why do you think it's gaining momentum now? Yeah, I think maybe, again, two parts. The first part,
I think, just following on from what Mert said, we got into this with Aztec for exactly that reason
of trying to bring institutions on chain. Aztec was actually created 2017, 2018, to try and put
bank grade loans on Ethereum.
And we kind of ran into that, you know,
scaling problem of institutions can't move onto these chains without at least the
level of privacy that they get from intermediaries that they transact with in Web 2.
And so we kind of were trying to build these loan origination products and loan trading products.
And we realized that Ethereum as it stood was not like kind of the right tool for the job.
and we had to go down a many-year rabbit hole to build out a lot of the underlying zero-knowledge-proof technology
to make that possible, which has culminated in Aztec, which is a layer two on Ethereum.
And I agree with a lot of what's been said previously.
Like now having privacy on these layers means you can build much stronger commitments about who you are,
whether that's in the real world, tying into kind of like existing.
trust anchors or kind of just putting information that you don't want to be broadcast publicly
inside a transaction and getting a blockchain to attest to it, which has been our mission for the
last kind of eight years or so. So I think that side of things just excites me seeing blockchains
reach more into the real world with this new kind of capability. I think that's why a lot of
fraction is happening at the moment because the tech has kind of met use cases. And
at a really interesting kind of intersection.
The second kind of reason that I'm interested is,
is just about kind of thinking about impact on the world
and where the world's going to be.
And people talk a lot about,
you know, leveling the playing field or financial playing field.
And if you look at the current public blockchains,
I just think we have a moral obligation to not let people use those
because it's a worse,
it's a worse form of money than most people on,
on this podcast deal within their daily lives.
And so we are going to onboard lots and lots of people to these new layers.
I think we have an obligation to at least give people the level of privacy we have in our bank accounts.
And I think we can do a lot better than that with kind of ZKPs and other tools.
So those two kind of things kind of are a bit Ying and Yang where they keep me motivated to kind of work on this.
And I think the kind of end human at the end of the day has a right to this privacy.
And also it's very cool to see what we can do now with this.
institutions on chain because we have privacy.
All right. So in a moment, we're going to talk a little bit more about who benefits from privacy
on chain, but first we'll take a quick word from the sponsors who make this show possible.
If you hold crypto on your phone, your biggest vulnerability isn't your wallet. It's your carrier.
AT&T, Verizon, and T-Mobile have been breached again and again. And SIM swaps are still one of
the easiest ways for attackers to drain accounts. That's where Cape comes in. America's
privacy-first mobile carrier. Same premium service, but CAPE rotates the identifier on your SIM
every 24 hours, deletes your call-and-text metadata after a day, and protects against SIM swaps with a
24-word recovery phrase that only you control. You also get two middle-to-end encrypted secondary
numbers for banking and sign-ups, so you stop handing your real number to every app that asks.
go to cape.co slash unchained and use code unchained for 33% off your first six months.
Back to my conversation with Joe, Jared, and Mert.
So let's talk about like different constituencies who would benefit from privacy on chain.
Like, you know, what are some of the reasons that people would want this and like who do you feel would benefit most?
And any one of you can talk.
Maybe just to start, I think it's helpful to lay out the different.
types of privacy on chain because there are two very clear camps and I think maybe this
call is more in one camp but there's there's a lot of people trying to get privacy on chain through
intermediaries which is kind of replicating what we have in web two which is kind of you know you have
a permission blockchain or or a blockchain where not everyone is a node so that you get some kind of
like privacy because there's a lack of like global consensus and to me that's kind of
not a very good form of privacy.
The very interesting form of privacy is privacy through cryptography.
And so I think, yeah, when thinking about who benefits from that,
it's important to look at the different types,
because some types of privacy are kind of just institutions
trying to fit their way into kind of a crypto world by replicating what they have.
But that's not that interesting because I don't think it breaks down the barriers
and it doesn't let us live up to the promise of this technology.
So I'm much more interested in the cryptographic type of privacy,
but maybe just to say that to start.
I would say to answer your question of who would benefit,
so the obvious answer is everybody.
And the way to frame that is to think of privacy as having an option.
Right.
So I believe the very first line of the Cipherfang manifesto
by Eric Hughes is that privacy is not secrecy, rather it is the ability to selectively disclose
oneself. And the frame to think about here is something like your thoughts by default are private.
And then you can choose to publish your thoughts on through secure messaging, through social media,
through writing a book, whatever might be. Same with your photos on Instagram. Same with your files,
right? You always, in most things in life, you have a choice in what you publish publicly versus
privately versus in crypto. Today, you physically do not have that choice, depending on which
system you use, but for example, on Bitcoin, you don't actually have that choice. And so,
there is nothing, besides hiring out some technical details, of course, because the tech does
need to improve somewhat from here, and I believe it certainly will. But besides that,
there's basically no benefit to be gained by not having the option, right? So it's something that must be built in
similar to the structural integrity of a bridge, so to speak, that is taken for granted, but that you only
notice when it's not there. Right. And so basically the answer, in my view, the only correct
answer is that everybody. I love it. Jared.
I mean, I don't have much more to add other than everybody, of course.
It's a little hard to do that.
I mean, there's some spicier takes in there, of course.
You know, I'm certainly concerned of, you know, people who are under, you know, tyrannical regimes, for example.
You know, their ability to transact economically, I feel is a right.
You know, a lot of civil liberties sort of arguments come up here.
Right to associate freedom of speech and so on.
So that's definitely one case.
I think, you know, just to kind of be a little bit spicy,
perhaps another way to say everybody as well is when you start to understand
like the cost of compliance around KYC and AML,
or more broadly, like follow the money methods, right?
And I think that when we start implementing these kind of tools,
it's going to require smarter approaches to those regulatory challenges.
But the reason why I say that is because those compliance costs, they don't get paid by like a bank.
That gets paid down to the individuals, right?
Like the general public.
And the main sort of perpetrators or people who benefit from avoiding KYC are typically
are the sort of political and financial elite, right?
And they don't need the privacy in the same way they do because they're effectively writing the rule.
So there's a power issue here.
And like this kind of goes back to the sort of cyphopunk
motto, you know, privacy for the weak and transparency for the powerful.
So I think that our public institutions should be, you know, public
and everyone else should be able to selectively reveal themselves.
Yeah, yeah, that makes a lot of sense.
It feels like anybody who's in some kind of situation
where they cannot enact their own agency,
like they have some sort of restriction on what they want to do with their life that they would benefit from privacy.
And there's so many examples throughout history of people being in that situation.
And you could imagine that being able to have your own private money would be super helpful.
All right.
So now let's get into the nitty-gritty part about what's actually happening.
on chain, which is I'm sure going to be a little bit contentious. I'd love to hear you guys argue a little bit.
But so let's actually, so let's break this down. Let's talk about all the different ways privacy can
come on chain. I'm going to just list a few based on, you know, how Ethereum kind of described
its privacy roadmap, but reads and rights, proving identities, experience, like the user experience,
and then wallets, things like that. I don't know if there's anything else. He would want to
but feel free to do so.
But just generally, you know, talk about like the different methods or applications
you're seeing for privacy, you know, that are coming on chain or that are being rolled
out soon that you're most excited about.
I think a lot of the fundamental kind of tech behind privacy is obviously zero mortgage proofs.
There are new technologies coming out, but, you know, may, may kind of improve on that
baseline, but the most exciting thing that I feel that all of these technologies are trying to do,
and especially in the Ethereum roadmap, is you have a program and you prove that program locally
on your device, and as a result of that program being verified successfully, some encrypted
state is updated somewhere. And you can take the basic kind of Zcash program, which is like
U2XO in, U2XO is in, UteXO is out, and you know, you verify that no money's not been double spent,
and you can kind of extend that in lots of different ways to make things much more complicated.
But the basic way that this is kind of happening at the moment is two things have changed that have
made this possible.
One is we can prove a lot more in a program, so there's very exciting use cases that can now
be built that just weren't possible before because they couldn't be proven on.
consumer devices. And the second is, you know, the capacity to kind of like do state
reads and state rights is growing just based on on Moore's law. Like the amount of kind of
scaling we have in these systems and the different data structures that exist to store
private state. There's a lot more technology there. So I think when whether you're talking about
on Ethereum or Zcash or any of these layers, I think the basic tenant is still the same.
There's a program that's proven, usually in a zero-knowledge proof, and then some state is written as a result.
And yeah, I think the possibilities that enable is pretty vast.
Where it gets kind of interesting is how do these things talk to each other?
Like, you know, is there a universal language for privacy?
Can Zcash talk to Ethereum?
Can privacy network on Solana talk to one on Ethereum?
and there's some like tools that have been developed there to make that easier,
kind of like shared languages, shared libraries,
but that's kind of where we are today.
So I think the Ethereum roadmap is a huge step in the right direction
because it's trying to create a lot more of those standards.
And maybe it's a force that helps actually get people to adopt them.
Jared or Mert, either privacy technologies or applications you're excited about.
Sure, I'll talk my own book.
Well, I'm pretty excited about obviously timely topic of formal verification applied to ZK circuits to.
So one, let's reduce scope to talk only about Zcash, for example.
One tradeoff, historically speaking, in privacy has been, in the case of a monetary asset, it's been about the supply of that asset.
Right. So, for example, if you have perfect privacy, then you technically have to make some tradeoffs in terms of the auditability of that supply.
Right. And we saw this when there was a counterfeit vulnerability discovered a few months ago at this point in Zcache's orchard pool.
And a lot of people weren't aware of this that if you are using ZK to encrypt literally everything, then there has to be.
some tradeoff in observability of, for example, who holds what and the summation of those
to add up to the total supply. And so you'll have things like turnstiles that limit the total
supply or ensure the total integrity of the supply, but you'll still have some tradeoffs,
for example, if one of the pools is insolvent. And I think a lot of this comes from,
I wrote a piece on this called Crypto's Entering the Space Age,
but a lot of this comes from crypto-oriented code being written in a very floppy sort of Facebook-ish way,
where, for example, in centralized systems, if you write code and it's a given that all software engineers will write bugs or cause bugs they didn't intend,
you can generally speaking just release a patch right away and everything is fine again, right?
But in the case of crypto, when you were securing billions in assets, it's more akin to like a pacemaker or a spaceship in that, first of all, you can't really roll it back in most cases.
And if it blows up, then there's a catastrophic event of billions of dollars lost.
Right.
And so, and obviously a lot of this is due to the new cyber capabilities of AI in being able to really break security of many things that we took for granted.
before. But the flip side of that, of course, is that AI also helps one perform formal
verification easier and more scalably without requiring many months and years to actually be able
to translate the spec into code and then mathematically verified that it does everything you thought
it would do. And so what I'm most excited about in the case of ZK and privacy, specifically
is the formal verification of the ZK circuits such that this.
This trade-off that we always treat it as some fundamental thing, it'll always still be there, to be clear, but the risk will be reduced by orders of magnitude, right?
As you get the ZK circuits simpler in what they do and what they claim to do, and you have all these machines literally writing out theorems and formally verifying the actual properties of it and ensuring integrity, then basically
I believe that you're going to get a 10x improvement in the risk reduction that is required for people to actually feel comfortable encrypting their money, so to speak.
So that's what I'm most interested in these days.
I would just second that.
I think, yeah, especially with AI and the rate of progress, like people see kind of, I guess, the negative externalities here,
where there's a crypto hack or crypto bug,
but for a system that's fixed
and the code is not changing,
with an ever-advancing level of like AI intelligence,
the capacity to find all the bugs in that system
is getting much, much better,
which means that we can kind of pull from the future
a state of security that we kind of could only dream of a few years ago.
And I think whether that's fuzzing or more verification
or just AI audits,
the kind of security of these systems is getting much, much, much more secure, even though
bugs are being discovered in that process.
But it's much better that that happens today than kind of in a few years' time.
So I think I'm just excited that the hardening of the technology is getting to a point where it can
actually power the world's financial rails because of the advancements in AI.
Jared, do you want to name some of the other technologies or apps you're most excited about?
Yeah, I mean, I think I'm still living in the past, right?
I'm still concerned about the fallout after tornado cash, right?
Like if you go to like mevwatch. info, you know, it's, we're having, you know, block relays, self-censoring at like 43.7% as of today, right?
that's a huge threat to everything that happens on chain, right?
Like, if the blockchain is not able to maintain its integrity,
then it basically loses all value, right?
And so, like, you can kind of break,
so just accessing these networks is important, right?
And so this is like where anonymous communication protocols come into play.
And really, we need to do two things here, right?
We need to protect users who want to transatlanticians,
transact with a network. We also need to protect people, the validators or miners, people who are actually securing the nodes that are securing the network.
And that's not quite a trivial thing to do, right? Like, what I see a lot of is people think you can just sort of slap, tore or maybe a mix net onto it and, you know, you're done.
The thing is, that doesn't really work. That might work for users, but it doesn't really work for validators and miners.
And the reason for that is because of the nature of the traffic.
Say, like, when you're participating in consensus,
what you're actually doing is creating the sort of deterministic wall of traffic, right?
And it's hitting on a regular heartbeat, right?
Everyone's basically communicating, you know,
every time there's a new block being produced or proposed.
And that's a huge challenge.
So in Lupec style mix nets, they effectively get their anonity through delays,
you can say.
And if you start getting so many people do like so many nodes doing this, you actually start blowing out those delays so you can't actually progress the chain if you know you need to have a block coming out every 30 seconds or whatever, right?
And the same thing is similar with onion routing, right?
Like this deterministic wall of traffic can be identified really easily.
So we've had to work at Logos on effectively a hybrid between a mixed net and a flooding, flooding routing routing routing routing routing routing routing routing sort of network. It's a bit weird, right? But what's great about it is that we can guarantee, you know, a certain amount of like basically everyone who's participating will get the messages. You know, they're doing mixed net like pass the parcel of the envelopes around.
and we're treating that as a form of routing within it.
But we can guarantee that we can get the block proposal unlinked.
And under an active adversary threat model,
we can kind of raise the cost to about seven years to try and figure out
who actually did that,
which is plenty of time for you to take your bags and put it into another account.
And that's what I'm really excited about,
because that allows us to really strengthen these systems and maintain their autonomy.
All right.
So let's actually now talk a little bit more about Zcash.
Like MIRD kind of started this, but I have a few questions about this.
So first of all, this is, you know, a coin that is focused on being either private digital
coals or some form of currency, however you, you know, want to look at it.
And yet, like, I am not really sure how it achieves either of those places in the world.
You know, Bitcoin kind of is claiming the digital gold.
I'm not sure how we see a transition from Bitcoin having that spot to Zcash having it.
And then Bitcoin's original purpose or whatever you want to call it based on the white paper was peer-to-peer electronic cash.
system, so I'm not sure if Zcash is going for that. But I'm just wondering if you guys see a way
for it to achieve either of those routes or something completely different.
Well, certainly I'll kick it off. But so, well, so let's look at the facts, right?
So you actually, I think the first question you asked a few questions ago was what kicked off
this sudden interest in privacy, so to speak. And certainly Zcash going from the facts,
the top 100 to the top 10, I think, played quite a large role in that.
Because, again, it is crypto, attention, liquidity equals, you know, price action,
which then leads to opportunities and more people sort of trying to use that attention.
But also it helps teams who were always kind of sort of doing that to begin with.
And so that's why I call it the last PVE.
It's obviously a meme, but it is one of the things left in finance that is player versus
environment, so to speak, rather than player versus player, right?
Because if I have privacy and Laura, you have privacy, that's good for both of us.
And we don't necessarily have to cannibalize each other against that, right?
And so that's sort of how I would say even how we ended up on this podcast today.
I'm not sure if you would have, if Zcash hadn't sort of really gotten attention back to the sector starting last year.
So in terms of whether, so you mentioned, well, can it be Bitcoin?
Can it be digital gold?
Can it be a currency?
So, first of all, I don't think there's room.
I don't think it's a winner-takes-all.
And there's all sorts of anecdotes I might give for this from.
traditional analogies from, for example, they're never just being one store value in the world
to never one market being 100% dominated by any single player. Right. And so there will always
be certain people who like the idea of Bitcoin, so to speak, but really require that additional
privacy. So in Zcash's case, the privacy isn't privacy for its own sake. It's to enable a better
monetary property for that asset, right?
It's sort of a, for example, one thing you might think of is fungibility, right?
In the digital realm, if a coin has a history, for example, maybe I'll refer to the Canadian
trucker protests, if a coin has history and you can see its providence, then there is a case
in which you will not be allowed to use that coin because of its history.
And so you actually sacrifice somewhat on the true fungibility of that asset.
Whereas cash, for example, is devoid of all information.
If I give you a $5 bill, you don't see anything about where that cash bill has been in the past.
There's, of course, other parts of this, right?
So Zcash isn't just about the privacy, but sort of the holistic asset.
And so one thing people might have missed in the Ironwood upgrade is that it is now quantum recoverable.
Right.
So you probably heard at some point about all sorts of panic about Bitcoin's quantum readiness.
while Zcash is actually quantum recoverable today,
and then it'll be quantum proof towards the end of autumn.
Right.
And so that's another thing that's kind of checked off the list.
Because a store of value fundamentally requires one to have a low entropy channel,
so to speak, and entropy is defined as surprise,
meaning you don't want to be surprised.
You want to be able to just store it somewhere, and that's sort of that, right?
And then, of course, there's other lesser-known things, for example,
Zcash is actually scaling in terms of compared to Bitcoin, right?
It's going from 75 second block times to 20 second block times.
The TPS target is a few thousand TPS, which is obviously not the case for Bitcoin.
I'm not sure it's not on me.
It's for the market to decide in terms of who buys it or who treats it as what.
But for a specific set of users, me included, it feels to me, it solves my needs better than Bitcoin would.
That is not to say I don't hold Bitcoin, of course.
But that does mean that it is a clear, viable alternative for some sets of uses that I care about personally.
And I'm curious to hear Jared's and Joe's take on, you know, what you think the trajectory of Z-Cash is.
But I also just want to ask in the same breath, but they're not that bug that Merr talked about earlier, you know, in the orchard pull.
if that gave you any pause or what.
And just for the audience, you know, to be clear, that was the one where an attacker could
have created an unlimited number of counterfeit tokens.
Most likely they did not, you know, just from the way the market activity has looked.
But that bug was there for four years and nobody had detected it.
So it's another fact that's a little alarming.
But, yeah, I'd be curious to hear Jared and Joe's take on, you know, where you think Zcash could go.
I'm having to start.
And I think two things that I agree with the kind of more of the digital goal thesis.
I think, you know, wealth and net worth is kind of something that a lot of people are just
sensitive about.
Like people wouldn't say on this call like what their worth and like privacy and net worth
have always been kind of like fairly hand in hand.
So I do think that that is a kind of the support market bit there.
I also think if you think about Zcash as a payment instrument, there's UX friction there.
You know, every time, you know, in the real world someone wants to pay with something,
there's a spread against their local currency.
And so it's not the best, like, last mile payment instrument.
And so, yeah, I think it just makes more natural sense for it to be digital gold and other technologies,
you know, private stable coins that are actually decentralized on different chains,
probably a better payment instrument for that.
I also think that as soon as you start thinking about payment instruments,
you start talking about payment volumes and payment fees,
rather than the asset as something that you want to buy and hold.
And so the valuation metrics get a little bit strange here.
So I'm definitely more on the digital gold camp
and kind of let other networks deal with privacy and kind of like crypto assets
in the real world.
And yeah, that's kind of my natural take.
On the bug, I think it's a little surprising that it was like that undiscovered for that long,
but I think it's more just a testament to how far like AI audits have come and the tools
we have today.
So, yeah, I think it's the same point as before where, you know, things that we took for granted
as being secure, not just on crypto rails.
are definitely not secure under the current threat models.
And it's actually what makes me more kind of more bullish on the digital gold thesis,
because if you, you know, if you keep your wealth in a broker account and these other kind of
web two things, we haven't had an AI-led attack vector on Web2 infrastructure that's kind of
been systemic yet.
But I do think that that will happen at some point.
and the crypto rails have already been ardent by that because they're kind of the ones that are easiest to attack first.
So I think this is actually going to be a positive thing in the long run as we see the effects of kind of more upper, more adversarial environments play out.
Yeah, I mean, I'm not too.
Firstly, like, I mean, I have a sort of libertarian streak to me, right?
So I really like the idea of sound money.
And of course, fungibility to me is a very important property.
and that's kind of why I use their cash shielded transactions.
So on the sort of bug, I mean, like, yeah, I mean, it's unfortunate, it's a little bit of an eyebrow rays,
but at the same time, like, you have to realize that most cryptographers would warn against using any kind of
cryptography that's new for, like, you know, five or even 10 years, perhaps even more.
And those who are daring enough to implement that and to take it to market, you know, should really deserve the sort of praise of their guess.
And, you know, these systems do run in an adversarial environment.
They are anti-fragile by nature and they get fixed as a result of this.
So I'm just glad it's fixed.
All right.
So to wrap up this little Z-cash section, I do have to ask Merck, because,
we just had a big upgrade in Zecash, Ironwood, which he alluded to earlier.
But why don't you explain, you know, what happened in this upgrade, why you're excited about it?
Sure.
So as we just discussed, there was a bug or a vulnerability found in specifically the orchard pool.
So Zcash has several shielded pools.
And Ironwood was the latest one up until iron, or orchard was the latest one up until ironwood.
and Taylor from Shielded Labs, who, by the way, is a very advanced high domain knowledge person.
It wasn't sort of just vibe-coded.
He had access to some pretty lit frontier AI tools and found disclosed and patched with the coordination of other teams, of course, this bug.
And obviously, so some people have the same reservation or that you have, which is like, okay, well, could they have done anything with that?
And while all the signs and heuristics point towards no, there wasn't.
So, for example, in terms of the shielded pool activity going up over time rather than going down,
the price action, the fact that it was announced that there would be a fix.
And so the hacker would, in theory, would want to get out before sort of they lost that window.
You can point to all sorts of these things as heuristics, but fundamentally, it's crypto.
So you have to be able to verify it.
And so to do that, a new shield.
pool called Ironwood was released.
And it's similar to Orchard, except it also has quantum recoverability.
And by the way, a few days after this was found, the old Orchard Pool and Ironwood were
both formally verified on three separate occasions, actually, and audited in all sorts of
different ways.
And so one of the, what the formerly, and you can see Sean Bow on.
Twitter, he has a few posts on where he goes in a detail because I'm sure I'll push her the
technicalities here. But basically the claim that there can be no undetectable counterfeiting
bugs going forward has been formally verified, right? So, of course, there could be other
types of bugs just as in any software system. But the specific set of bugs has been rendered
mathematically not feasible. Like that's, anyways, you can sort of look at that blog post to confirm
But anyway, so how do you confirm the supply actually is like, how do you confirm that there was no new notes in Orchard pool specifically?
Right.
So you said, for example, and I think a lot of people have this confusion where people think it's just an unlimited amount of Zcash, but it's actually just an unlimited amount of Zcash in the orchard pool, which is about 28% of the supply.
Right.
And so to confirm that, what you have to do is you have to migrate from that pool.
to the orchard pool to the ironwood pool.
And if there was an attack, what would happen is this thing called a turnstile would trigger.
And all a turnstile does is it ensures that what goes out can't be more than what went in, right?
Because you know what went in and you know what's going out in terms of aggregate amounts.
And so imagine, for example, the pool orchard had a billion dollars worth in it.
And imagine that 500 million has left it now.
and then the turnstile triggers, well, then that 500 million remaining would be technically
insolvent because you don't know who owns what notes in that pool.
Right.
And so the idea here is that as the funds migrate from Orchard to Ironwood, they would tend
from, you know, a billion to 500 million to 5 million until basically it approaches zero.
Now, of course, it'll never actually be zero because I'm sure some people have died and lost their keys or lost their devices or whatever.
And so it'll be a probabilistic bound in terms of what supply is for sure certainly not counterfeit.
And then what supplies still might be insolvent.
And so that already went live two days ago.
There's no hiccups so far.
they're trying to make the migration such that it has built-in privacy when you migrate
such that you don't expose who owns what notes.
And so the app teams are also working on that.
But basically, so to summarize what you get with Ironwood is you get mathematical deterministic
guarantees that no undetectable counterfeiting bugs like this one can exist in the future.
you get a mechanism for verifying the supply wasn't in orchard, it wasn't counterfeited.
You get quantum recuperability.
But then also there's a few other goodies smuggled in there about faster sync times
and faster signing and just a general performance upgrade.
Great.
Okay.
So now let's switch to Ethereum because Ethereum has a really extensive privacy.
roadmap and it covers a number of different areas. You know, they announced this big push,
as I mentioned. And as I also mentioned earlier, there's a number of initiatives that, you know,
range from, you know, everything including like R&D to UXUI. So it really covers the gamut.
What about, you know, Ethereum's privacy roadmap? Like which segments of it are most exciting
to you? And which do you think will really?
move the needle. I'm happy to start with this one. I think, yeah,
Ethereum's Roadmap is very good to see. I think there's also like a lot of ways to get
privacy on Ethereum today that don't need this. So Aztex is obviously one of those and just
general like verifying zero noise proofs work today on Ethereum. So I think it's important to
just state that. The things that are exciting to me are some of the things that Zegas has
already achieved. The
of upgrades, talk about having a post-quantum kind of proving system and just new state types
that make existing privacy apps much easier to build.
And as tech exists as a layer too because Ethereum isn't that easy to build privacy apps on.
You have to put a roll up.
You have to build all of these additional metrics and like functionality to enable privacy.
a few years once this roadmap is kind of fully built, the job of teams like Aztec gets a lot easier
because there's kind of art of Ethereum that just do do things kind of for free. So I think it should
see a lot more teams building in the space. You won't need to raise as much kind of money to
like bring privacy to Ethereum and you can kind of get started a lot quicker. My only kind of
complaints about it are it's quite far out. And so, you know, like we're dealing with privacy
today on Ethereum. Our V5 network went live last week. And so it's kind of like there's a tradeoff
between, you know, the shiny city on the hill where, you know, everything could be perfect.
And what can you actually do today? And I think the only risk I see is that the battle is
being fought today for cryptographic privacy on blockchains.
And there's a chance that if the roadmap comes too late,
and the only type of privacy that is legally allowed is privacy through intermediaries.
And that obviously brings us on to tornado cash and other things.
But yeah, my only concern with it is like it could be too late to actually show that there's
meaningful demand for this privacy.
And so I'd like to see more done like today on what's possible,
kind of on Ethereum
and kind of embracing
those privacy solutions that exist today.
But I mean, you must also think that
if it comes to fruition, then
in a way it's almost competitive with what
you're doing and could siphon
like TVL or whatever. Am I right?
Not really.
I think the
way to think about it is like there's a
bunch of things in the EVM today that enable
Aztec to exist.
And there we're about to get
even more, which means that we can build a better Aztec.
I think Ethereum is, at the protocol level,
is building features into the network
that enable people to build privacy applications.
And so it just makes our job easier.
The network effect is still going to accrue
to some application on Aztec that makes use of those.
And the way to think about Aztec is just,
it's a very generic execution environment
for writing private applications.
And the privacy roadmap is not necessarily around that.
It's about making the job of teams like us,
teams like privacy pools, easier so that we have more private applications.
So I think the two are kind of very compatible.
The only place it's maybe kind of competing is like,
you know, if EF has native private transfers,
it's probably better if those occur on Ethereum L1 than on Aztec.
we're more focused about kind of like real-world use cases of privacy and like programmable money
like dollars and and kind of decentralized stable coins. So I think, yeah, I don't see it as fully
competitive. I agree actually. Like Ethereum's privacy roadmap is a very ecosystem focused, right?
And I think that's for the right play for them because they have such a dominant ecosystem
of, you know, DAP developers, people building on Ethereum.
So that's a huge part of their focus.
And I think that's probably the fastest way that they can achieve those kind of goals.
As for the rest of the roadmap, it's very ambitious, particularly for a system that's
live that's already got a lot of value, right?
It's kind of a, it's very challenging to retrofit an existing system with some of these
technologies and have everything go really well. Having that said, like, you know, I've been around
the Ethereum community for a very long time now, and I've had to raise eyebrows a couple of times,
and it's a huge testament to that community that they have pulled off some of the things that
they've pulled off, particularly a transition to Ethereum 2. So if anyone can do it, they can
definitely do it. It is ambitious, and I guess we'll see.
All right. So in the interest of time, even though I'm sure Merck would probably have some thoughts, we're going to talk about Canton because I think that will take up the rest of the time. And this obviously is a chain that sort of came out of nowhere. And there are private transactions on it, even private stable coin transactions. And I wonder what you think about it and how, like, do you consider it like a leader in the privacy space on chain?
or how do you think about what they're doing and how it relates to privacy?
I don't consider a leader in the privacy space any more than I would consider J.P. Morgan,
a leader in the privacy space, which is to say that those guarantees in terms of privacy that you would get,
which is just trusting your counterparty are totally achievable without using crypto in the way that they've done it.
And so I don't see any reason why I would want to expose myself to that.
I would like why I would want bank level guarantees, I would just use a bank.
Yeah.
I second.
That is what I touched on earlier with privacy through intermediaries versus cryptographic
privacy.
And the way that they achieve their private stable coins or private transactions is
exactly the trust people.
There's a sequencer who has a reputation and you send all your transactions to that
sequencer and you trust with a non-credible commitment that they're not going to
monetize that data or sell that data to anyone.
And so whilst it kind of, you know, it jumps on the privacy ban wagon.
It's basically a bunch of banks trying to adopt a different tech stock.
And yeah, I think that it should come out in the wash for kind of at least these use cases
that require strong credible commitments and actual privacy that's backed by kind of
cryptographic guarantees.
So, Jared, I'm assuming you agree.
So I want to switch up the question a little bit.
Like, what do you think then happens?
So we have a bunch of financial institutions that are transacting on this chain.
Like, what do you think happens to Canton?
Do you think that eventually goes away and that they end up using ones that have actual,
you know, technologically secure privacy or, you know, where does this go?
How does it play out?
Yeah, well, I mean, I don't have a crystal ball, right?
So I think, you know, one way you could view that in a positive light is that you could get the sort of early market adoption or, you know, bringing these other sort of institutions this way.
And then hopefully they recognize the risks that are associated with that approach.
And then once they have that sort of market, they can transition to something that has much strong.
imperative or credible commitments or imperative commitments,
cryptographic commitments.
So that's what I would hope to see from them.
Whether that's the case or not is a little unclear, right?
I think that you have to be thinking about this pretty early on,
for similar reasons why I think it's difficult to retrofit an existing chain
with some of these technologies.
It's possible, but if you're an engineer, you like, you know,
you work on these things and you accumulate technology.
debt and people say like something is temporary and then you find out that five years later that's
you know this piece of software is still operating in the same way right because you know business
interests go in different directions um at the same time like i i think that it's great to see
more and more chains more different approaches uh because it is still pretty early like you know
crypto as an industry is still relatively quite small and we have a lot of uh blocked market activity
to unlock, you know, if we want to see, you know, real world assets and, you know, more stable coins,
you know, more value, whatever your heart desires to be on chain. So more approaches, more surface
area, bring more people in, and then, you know, hopefully the use of these technologies make good
judgments over time. All right. Well, this is all the time we have. There were a few other
topics, but we'll have to touch upon them another time. Thank you guys so much for coming on Unchained
and sharing your thoughts on privacy. Thank you so much, Laura. See you. All right. Thanks for
thanks everyone for joining this live stream. We will catch you next week. Bye now. Nothing you
hear on Unchained is investment advice. This show is for informational and entertainment purposes only,
and my guest and I may hold assets discussed on the show. For more disclosures, visit UnchainedCrypto.com.
