Unchained - Zcash, Ethereum, Aztec, Canton and More: Which Chain Will Win the Privacy Race?

Episode Date: July 31, 2026

Privacy is having a moment in crypto. As competition heats up, the pitfalls of the technology around the quantum threat, regulatory risk and more make the trajectory hard to predict. A counterfeit... bug sat undetected in Zcash's Orchard privacy pool for four years, capable of minting an unlimited supply of untraceable coins, illustrating the risks of one of the hottest crazes in crypto. Joe Andrews, CEO of Aztec Labs, Jarrad Hope, founder of Logos, and Mert Mumtaz, cofounder and CEO of Helius, join Laura Shin to argue the bug is less alarming than what it reveals: cryptographic privacy is difficult to get right, and the industry is racing to get it right anyway, because institutions will not come onchain without it. They cover Zcash's quantum-recoverable Ironwood upgrade and the turnstile proving the counterfeit coins never moved, Ethereum's sprawling privacy roadmap and the risk it arrives too late, Logos' mixnet built to protect validators from block relays now censoring transactions, and why all three see Canton's private stablecoins as little more than a bank with extra steps. The fight over what actually counts as privacy on a blockchain is only getting started. Host ⁠Laura Shin⁠ - Founder, CEO and Host of Unchained Guest ⁠Joe Andrews - CEO of Aztec Labs ⁠Jarrad Hope - Founder of Logos ⁠Mert Mumtaz - Cofounder and CEO of Helius Sponsor ⁠Cape⁠: Your biggest crypto vulnerability isn't your wallet, it's your phone number. Cape is America's privacy-first mobile carrier that rotates your SIM identity daily and blocks SIM swaps before they happen. Get 33% off your first six months at ⁠https://cape.co/unchained⁠   (use code: UNCHAINED). Timestamps: 🔐 01:52 Why Joe, Jarrad, and Mert think privacy's crypto moment is now 💙 18:18 Cape: Get 33% off your first six months with code unchained at https://cape.co/unchained ⚖️ 19:14 Why Jarrad says the weak need privacy and the powerful need transparency 🔬 24:49 How zero knowledge proofs actually update encrypted state onchain 🕸️ 33:07 Why 43.7% of block relays now censor, and how Logos fixes it 🐛 36:32 The undetected Zcash bug that could have minted infinite fake coins 🔒 46:32 Mert explains how Zcash's Ironwood upgrade closes the counterfeit hole 🛤️ 51:44 Why Joe worries Ethereum's privacy roadmap might arrive too late 🏦 57:39 Why Mert calls Canton no more private than trusting JPMorgan Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 I don't consider a leader in the privacy space any more than I would consider JPMorgan a leader in the privacy space, which is to say that those guarantees in terms of privacy that you would get, which is just trusting your counterparty are totally achievable without using crypto in the way that they've done it. And so I don't see any reason why I would want to expose myself to that. Like why I would want bank level guarantees, I would just use a bank. Hi everyone, welcome to Unchained. You're no hype resource for all things crypto. I'm your host, Laura Shin.
Starting point is 00:00:31 Thanks for joining this live stream, and we will first take a quick word from the sponsors who make the show possible. This episode is brought to you by Cape, America's Privacy First Mobile Carrier. Same premium service you'd expect from any other carrier, but designed so your number, your location, and your data actually stay yours. Get 33% off six months at cape.co slash unchained.
Starting point is 00:00:58 Today's topic is privacy. Here to discuss are Joe Andrews, CEO of Aztec Labs, Jared Hope, founder of Lagos, and MertMutt Muntaz, co-founder and CEO of Helius. Welcome, Joe, Jared and Mert. Good to be here. Hi, thanks for us. Hey, yeah, thanks for having us. We're facing a moment in crypto when it just feels like privacy is going to start mattering a lot more. It's already starting to matter a lot more.
Starting point is 00:01:25 And more chains are going to be adopting it in various ways, and they always. already are working on that. Obviously, Zcash saw a huge renaissance in the last year. Manero also got a boost. Ethereum announced this privacy roadmap. NIR had or has confidential transactions. Canton is drawing institutions to its private chain and more. But before we get into all the details on that, let's just start with each of you explaining your interest in privacy and why you think this is the moment that this direction is gaining momentum now. Why don't we start with Jared? Sure. I guess like, you know, I got into like the space through the sort of BBS and piracy scene and found Sleferbunks and like crypto anarchy. So in the 90s, I was already
Starting point is 00:02:17 pretty naturally inclined towards these ideas. But and I've argued, you know, for privacy on a civil Liberty's standpoint, as well as, you know, against the sort of surveillance state, particularly after 9-11. But I think what's interesting to me about it now is like how my thoughts have developed a lot more. And I started to realize that it's privacy is actually a property that's required to unblock new market activity as well as creating stronger institutional quality. I don't know if you want me to go into that in more detail now,
Starting point is 00:02:59 but it requires a little bit of understanding of token, sorry, transaction cost economics and institutional economics. Sure, go ahead. Maybe I'll let the other one less. Oh, yeah, okay. So I guess like it's, when you think about like what a blockchain is actually selling, right? It's not really saying just block space, right? We have all of these mechanisms in place to effectively create what's called credible commitments.
Starting point is 00:03:30 Credible commitments is like this notion behind an institution and what makes an institution like pretty high quality. So for example, like a state can be very powerful, but he who giveth can take it away, right? So what actually matters in terms of an institution is its ability to be able to hold its promises, right? Hold in such way. So these promises are effectively called credible commitments and there's two types, right? There's motivational commitments. This is like, trust me, bro, I've got it, don't worry about it, I'll honor my agreements. And then there's imperative commitments, which are a lot stronger. And we started to see like, an example of this is like in medieval times, right? A king might have some kind of deal with.
Starting point is 00:04:22 with another king and leave their firstborn son with the other king as kind of collateral. Williamson basically talks about the sort of ideal version of this, which is the ugly princess, right? It's a lot of high value to the father, maybe not so much value to the other king. But if the other king does not honor his agreement, then, you know, maybe there's a beheading involved, right? So this is an example of an imperative commitment. So in blockchains, you know, we do this with, you know,
Starting point is 00:04:56 cryptography. We do this with, you know, game theory, mechanism design, and even decentralization. These are all things that basically make the commitments that are made on chain much, much stronger. Now, the other side of this is, like, a lot of people think of a transaction when it happens on chain is, like, and that's basically the only thing that's happening of a transaction, right? But in transaction cost economics, there's like seven steps that are involved in a transaction.
Starting point is 00:05:32 You can view this as a life cycle or a process or even a supply chain. And the blockchain is really only doing the settlement and some of the other ones, right? So think about it. Like, when you do a transaction, you actually have to discover your counterparty, you have to communicate with them.
Starting point is 00:05:48 You then have to, you know, negotiate or come into contract with them, and there's a few things that happen after the fact as well. Now, the problem is, is like, pretty much the reason why crypto, you know, has kind of a bad reputation these days is because a lot of people are making these motivational commitments outside of the chain itself, right? Whether it's a centralized exchange that goes bad or, you know, a scam, and so on. And each one of these steps effectively has sort of hazard. quality to it, right? You have basically two people who can prevent you from doing a transaction
Starting point is 00:06:27 any of these steps, right? One is your counterparty, right? They might have some self-interest and try to undermine the transaction or, you know, scam you on some sense. But then there's also the class of actors who are not directly involved in the transaction. So this might be, you know, a hacker, this might be the state, it might be a competitor, and so on. on. And their capacity to influence the transaction that you're making is really determined by, let's say three things, right? It's capacity for coercion, both you and your counterparty, it's impunity, like what its estimate of its recourse is, as well as the information of that transaction, right? And that information is really important because we can't really
Starting point is 00:07:21 modify its, this predators or this other actor's ability to, we can't change the coercion really easily unless, you know, maybe we, you know, get violent in some sense. We can't really do much about impunity unless, you know, we're relying on a very strong legal system, you know, as an example. But we can control information within these systems. And if you can reduce that information down to zero, then the capacity for influencing a transaction also drops. And so this is kind of where privacy comes into play, right? If you can secure privacy at each of these steps in the transaction and provide not only privacy,
Starting point is 00:08:07 but also like integrity to those steps in transaction, you start to understand why like we cared about decentralized file storage systems. You know, for example, you know, the ByBit hack could have maybe been prevented by having a higher sort of integrity over the content hash over accessing its front end, for example, rather than being served through the motivational commitment of running a server on Amazon or wherever it was. So that's what I really care about because as you do this, you reduce the hazards that. involved in any kind of contracting, which then allows or unblocks market behavior. And this means like institutions can come on. It means that, you know, people who are not transacting because they got hurt by some other system or actor can come on. You can quantify this, right?
Starting point is 00:09:04 You could even look at blockchain forensics as a, I can't remember how many billion dollar industry it is, right? but they are looking at this information and that's preventing a lot of other market activity from happening on chain. So that's a nutshell of why I care about. I mean, like what comes to mind is almost,
Starting point is 00:09:26 I know it's like a funny analogy, but when there's a party and let's say it's a more formalish party and the music starts and the dance floor is empty, it's like who will go on the dance floor first? And it's sort of like that when you have these public transactions, right? That everybody can see, everybody can watch. It, like, just exposes you in different ways. So that makes a lot of sense. Mur, do you want to explain, you know, what your interest is in privacy and why you think this is the moment it's gaining traction?
Starting point is 00:10:00 Sure. So I have two main interests in privacy and crypto specifically. Obviously, there's privacy and trust outside of crypto, but I'll reduce the scope. One is, in the frame of Zcash. And there what I'm interested in is the original ethos and idea of Bitcoin, which is to say an alternative monetary currency that has a shot at being a safe haven or being able to separate money from the state in some capacity for some segment of the market. Right. I think that's primarily why a lot of people.
Starting point is 00:10:43 at least back in the day, got into crypto and why it's still clearly the number one asset in crypto by several lowers of magnitude. And there's a lot of problems. There's a lot of unfinished sort of paths that Bitcoin sort of left in my view, right? So the way I tell the story is generally something like, first we had to prove that cryptographic money could work, and that was Bitcoin and had to gain legitimacy and traction. and you have to just prove out the concept. And then Battala came and said,
Starting point is 00:11:17 well, actually, it's sort of weird that this isn't programmable, and then Ethereum came. And then perhaps Salana came and said, this also has to be scalable. But then the concept of privacy, which ironically is implicitly assumed when you're talking about Bitcoin to anybody outside of the industry, right?
Starting point is 00:11:36 So for example, if you ever watch a TV show, something like a blacklist, and the content, in which Bitcoin comes around is generally some criminals asking another person for ransom. And every time I watch something like that, I'm like, what are you doing? That is way more traceable than cash. It makes absolutely no sense. And so it's this deep sort of belief that you think, oh, it's cryptographic money.
Starting point is 00:12:03 Obviously, it must be private, right? And so it's not even really understood that I actually know it is traceable digital gold as the official Bitcoin account, which I'm not even sure who owns that, on Twitter literally says in their bio. Right. And there's all sorts of supporting anecdotes here. So, for example, when Halifini was alive,
Starting point is 00:12:27 he would tweet about wanting to add anonymity to Bitcoin. And you can see the early Bitcoin forums where Satoshi himself says something like, if this was possible, referring to using ZK, this would make for a better, more efficient implementation of Bitcoin, but I don't know how to solve a double spend problem. And naturally, that was because ZK was super early in its, I mean, Zcash didn't exist. There was no production deployment of ZK Snarks at that time.
Starting point is 00:12:56 But now we have the tech, right? And so now it feels like especially at a time where all sorts of liberties and let's say things that you took for granted are being attacked, whether it's age verification, whether it's AI, being able to make sense of unstructured data, or whether it's the institutionalization of crypto, there remains that last branch, which is, or the last frontier in my view, which is not only in terms of market cap and price, but also in terms of impact and clear market gap, right, which is adding privacy to this internet currency. The second part is, let's say slightly more boring, but it is sort of a prerequisite.
Starting point is 00:13:39 for being able to do finance at scale, right? Nobody really thinks of privacy as a scaling technology, but it actually is a scaling technology because without it, a very large group of actors physically cannot come on chain, right? So what's been most ironic in this past cycle since we've had Trump as president and perhaps there's been some regulatory clarity
Starting point is 00:14:03 is that while your average user might not care too much, perhaps through, lack of education or some other thing. The institutions that are coming on chain absolutely care for OPSEC reasons, regulatory reasons, legal reasons, all sorts of other reasons, right? Like they physically cannot come on chain in a meaningful capacity beyond some newspaper headline for a very basic POC. It's very hard for them to actually move a significant portion of their business when you can
Starting point is 00:14:34 see, well, here's all the people who have this token, here are all. the loan parameters and it so within the context of privacy security that's a complete non-starter for any serious financial institution and so on the other side of this where I'm building on salon with calius we're building a zK privacy protocol to help alleviate a lot of those gaps so to basically to answer your question twofold one is the currency and then two is the scaling of finance. I love it. So interesting. All right, Joe, what about you? Why are you interested in privacy and why do you think it's gaining momentum now? Yeah, I think maybe, again, two parts. The first part, I think, just following on from what Mert said, we got into this with Aztec for exactly that reason
Starting point is 00:15:26 of trying to bring institutions on chain. Aztec was actually created 2017, 2018, to try and put bank grade loans on Ethereum. And we kind of ran into that, you know, scaling problem of institutions can't move onto these chains without at least the level of privacy that they get from intermediaries that they transact with in Web 2. And so we kind of were trying to build these loan origination products and loan trading products. And we realized that Ethereum as it stood was not like kind of the right tool for the job. and we had to go down a many-year rabbit hole to build out a lot of the underlying zero-knowledge-proof technology
Starting point is 00:16:11 to make that possible, which has culminated in Aztec, which is a layer two on Ethereum. And I agree with a lot of what's been said previously. Like now having privacy on these layers means you can build much stronger commitments about who you are, whether that's in the real world, tying into kind of like existing. trust anchors or kind of just putting information that you don't want to be broadcast publicly inside a transaction and getting a blockchain to attest to it, which has been our mission for the last kind of eight years or so. So I think that side of things just excites me seeing blockchains reach more into the real world with this new kind of capability. I think that's why a lot of
Starting point is 00:16:57 fraction is happening at the moment because the tech has kind of met use cases. And at a really interesting kind of intersection. The second kind of reason that I'm interested is, is just about kind of thinking about impact on the world and where the world's going to be. And people talk a lot about, you know, leveling the playing field or financial playing field. And if you look at the current public blockchains,
Starting point is 00:17:22 I just think we have a moral obligation to not let people use those because it's a worse, it's a worse form of money than most people on, on this podcast deal within their daily lives. And so we are going to onboard lots and lots of people to these new layers. I think we have an obligation to at least give people the level of privacy we have in our bank accounts. And I think we can do a lot better than that with kind of ZKPs and other tools. So those two kind of things kind of are a bit Ying and Yang where they keep me motivated to kind of work on this.
Starting point is 00:17:54 And I think the kind of end human at the end of the day has a right to this privacy. And also it's very cool to see what we can do now with this. institutions on chain because we have privacy. All right. So in a moment, we're going to talk a little bit more about who benefits from privacy on chain, but first we'll take a quick word from the sponsors who make this show possible. If you hold crypto on your phone, your biggest vulnerability isn't your wallet. It's your carrier. AT&T, Verizon, and T-Mobile have been breached again and again. And SIM swaps are still one of the easiest ways for attackers to drain accounts. That's where Cape comes in. America's
Starting point is 00:18:33 privacy-first mobile carrier. Same premium service, but CAPE rotates the identifier on your SIM every 24 hours, deletes your call-and-text metadata after a day, and protects against SIM swaps with a 24-word recovery phrase that only you control. You also get two middle-to-end encrypted secondary numbers for banking and sign-ups, so you stop handing your real number to every app that asks. go to cape.co slash unchained and use code unchained for 33% off your first six months. Back to my conversation with Joe, Jared, and Mert. So let's talk about like different constituencies who would benefit from privacy on chain. Like, you know, what are some of the reasons that people would want this and like who do you feel would benefit most?
Starting point is 00:19:23 And any one of you can talk. Maybe just to start, I think it's helpful to lay out the different. types of privacy on chain because there are two very clear camps and I think maybe this call is more in one camp but there's there's a lot of people trying to get privacy on chain through intermediaries which is kind of replicating what we have in web two which is kind of you know you have a permission blockchain or or a blockchain where not everyone is a node so that you get some kind of like privacy because there's a lack of like global consensus and to me that's kind of not a very good form of privacy.
Starting point is 00:20:02 The very interesting form of privacy is privacy through cryptography. And so I think, yeah, when thinking about who benefits from that, it's important to look at the different types, because some types of privacy are kind of just institutions trying to fit their way into kind of a crypto world by replicating what they have. But that's not that interesting because I don't think it breaks down the barriers and it doesn't let us live up to the promise of this technology. So I'm much more interested in the cryptographic type of privacy,
Starting point is 00:20:34 but maybe just to say that to start. I would say to answer your question of who would benefit, so the obvious answer is everybody. And the way to frame that is to think of privacy as having an option. Right. So I believe the very first line of the Cipherfang manifesto by Eric Hughes is that privacy is not secrecy, rather it is the ability to selectively disclose oneself. And the frame to think about here is something like your thoughts by default are private.
Starting point is 00:21:13 And then you can choose to publish your thoughts on through secure messaging, through social media, through writing a book, whatever might be. Same with your photos on Instagram. Same with your files, right? You always, in most things in life, you have a choice in what you publish publicly versus privately versus in crypto. Today, you physically do not have that choice, depending on which system you use, but for example, on Bitcoin, you don't actually have that choice. And so, there is nothing, besides hiring out some technical details, of course, because the tech does need to improve somewhat from here, and I believe it certainly will. But besides that, there's basically no benefit to be gained by not having the option, right? So it's something that must be built in
Starting point is 00:22:05 similar to the structural integrity of a bridge, so to speak, that is taken for granted, but that you only notice when it's not there. Right. And so basically the answer, in my view, the only correct answer is that everybody. I love it. Jared. I mean, I don't have much more to add other than everybody, of course. It's a little hard to do that. I mean, there's some spicier takes in there, of course. You know, I'm certainly concerned of, you know, people who are under, you know, tyrannical regimes, for example. You know, their ability to transact economically, I feel is a right.
Starting point is 00:22:47 You know, a lot of civil liberties sort of arguments come up here. Right to associate freedom of speech and so on. So that's definitely one case. I think, you know, just to kind of be a little bit spicy, perhaps another way to say everybody as well is when you start to understand like the cost of compliance around KYC and AML, or more broadly, like follow the money methods, right? And I think that when we start implementing these kind of tools,
Starting point is 00:23:21 it's going to require smarter approaches to those regulatory challenges. But the reason why I say that is because those compliance costs, they don't get paid by like a bank. That gets paid down to the individuals, right? Like the general public. And the main sort of perpetrators or people who benefit from avoiding KYC are typically are the sort of political and financial elite, right? And they don't need the privacy in the same way they do because they're effectively writing the rule. So there's a power issue here.
Starting point is 00:23:59 And like this kind of goes back to the sort of cyphopunk motto, you know, privacy for the weak and transparency for the powerful. So I think that our public institutions should be, you know, public and everyone else should be able to selectively reveal themselves. Yeah, yeah, that makes a lot of sense. It feels like anybody who's in some kind of situation where they cannot enact their own agency, like they have some sort of restriction on what they want to do with their life that they would benefit from privacy.
Starting point is 00:24:35 And there's so many examples throughout history of people being in that situation. And you could imagine that being able to have your own private money would be super helpful. All right. So now let's get into the nitty-gritty part about what's actually happening. on chain, which is I'm sure going to be a little bit contentious. I'd love to hear you guys argue a little bit. But so let's actually, so let's break this down. Let's talk about all the different ways privacy can come on chain. I'm going to just list a few based on, you know, how Ethereum kind of described its privacy roadmap, but reads and rights, proving identities, experience, like the user experience,
Starting point is 00:25:20 and then wallets, things like that. I don't know if there's anything else. He would want to but feel free to do so. But just generally, you know, talk about like the different methods or applications you're seeing for privacy, you know, that are coming on chain or that are being rolled out soon that you're most excited about. I think a lot of the fundamental kind of tech behind privacy is obviously zero mortgage proofs. There are new technologies coming out, but, you know, may, may kind of improve on that baseline, but the most exciting thing that I feel that all of these technologies are trying to do,
Starting point is 00:25:59 and especially in the Ethereum roadmap, is you have a program and you prove that program locally on your device, and as a result of that program being verified successfully, some encrypted state is updated somewhere. And you can take the basic kind of Zcash program, which is like U2XO in, U2XO is in, UteXO is out, and you know, you verify that no money's not been double spent, and you can kind of extend that in lots of different ways to make things much more complicated. But the basic way that this is kind of happening at the moment is two things have changed that have made this possible. One is we can prove a lot more in a program, so there's very exciting use cases that can now
Starting point is 00:26:44 be built that just weren't possible before because they couldn't be proven on. consumer devices. And the second is, you know, the capacity to kind of like do state reads and state rights is growing just based on on Moore's law. Like the amount of kind of scaling we have in these systems and the different data structures that exist to store private state. There's a lot more technology there. So I think when whether you're talking about on Ethereum or Zcash or any of these layers, I think the basic tenant is still the same. There's a program that's proven, usually in a zero-knowledge proof, and then some state is written as a result. And yeah, I think the possibilities that enable is pretty vast.
Starting point is 00:27:29 Where it gets kind of interesting is how do these things talk to each other? Like, you know, is there a universal language for privacy? Can Zcash talk to Ethereum? Can privacy network on Solana talk to one on Ethereum? and there's some like tools that have been developed there to make that easier, kind of like shared languages, shared libraries, but that's kind of where we are today. So I think the Ethereum roadmap is a huge step in the right direction
Starting point is 00:27:59 because it's trying to create a lot more of those standards. And maybe it's a force that helps actually get people to adopt them. Jared or Mert, either privacy technologies or applications you're excited about. Sure, I'll talk my own book. Well, I'm pretty excited about obviously timely topic of formal verification applied to ZK circuits to. So one, let's reduce scope to talk only about Zcash, for example. One tradeoff, historically speaking, in privacy has been, in the case of a monetary asset, it's been about the supply of that asset. Right. So, for example, if you have perfect privacy, then you technically have to make some tradeoffs in terms of the auditability of that supply.
Starting point is 00:28:58 Right. And we saw this when there was a counterfeit vulnerability discovered a few months ago at this point in Zcache's orchard pool. And a lot of people weren't aware of this that if you are using ZK to encrypt literally everything, then there has to be. some tradeoff in observability of, for example, who holds what and the summation of those to add up to the total supply. And so you'll have things like turnstiles that limit the total supply or ensure the total integrity of the supply, but you'll still have some tradeoffs, for example, if one of the pools is insolvent. And I think a lot of this comes from, I wrote a piece on this called Crypto's Entering the Space Age, but a lot of this comes from crypto-oriented code being written in a very floppy sort of Facebook-ish way,
Starting point is 00:29:56 where, for example, in centralized systems, if you write code and it's a given that all software engineers will write bugs or cause bugs they didn't intend, you can generally speaking just release a patch right away and everything is fine again, right? But in the case of crypto, when you were securing billions in assets, it's more akin to like a pacemaker or a spaceship in that, first of all, you can't really roll it back in most cases. And if it blows up, then there's a catastrophic event of billions of dollars lost. Right. And so, and obviously a lot of this is due to the new cyber capabilities of AI in being able to really break security of many things that we took for granted. before. But the flip side of that, of course, is that AI also helps one perform formal verification easier and more scalably without requiring many months and years to actually be able
Starting point is 00:30:56 to translate the spec into code and then mathematically verified that it does everything you thought it would do. And so what I'm most excited about in the case of ZK and privacy, specifically is the formal verification of the ZK circuits such that this. This trade-off that we always treat it as some fundamental thing, it'll always still be there, to be clear, but the risk will be reduced by orders of magnitude, right? As you get the ZK circuits simpler in what they do and what they claim to do, and you have all these machines literally writing out theorems and formally verifying the actual properties of it and ensuring integrity, then basically I believe that you're going to get a 10x improvement in the risk reduction that is required for people to actually feel comfortable encrypting their money, so to speak. So that's what I'm most interested in these days. I would just second that.
Starting point is 00:32:00 I think, yeah, especially with AI and the rate of progress, like people see kind of, I guess, the negative externalities here, where there's a crypto hack or crypto bug, but for a system that's fixed and the code is not changing, with an ever-advancing level of like AI intelligence, the capacity to find all the bugs in that system is getting much, much better, which means that we can kind of pull from the future
Starting point is 00:32:30 a state of security that we kind of could only dream of a few years ago. And I think whether that's fuzzing or more verification or just AI audits, the kind of security of these systems is getting much, much, much more secure, even though bugs are being discovered in that process. But it's much better that that happens today than kind of in a few years' time. So I think I'm just excited that the hardening of the technology is getting to a point where it can actually power the world's financial rails because of the advancements in AI.
Starting point is 00:33:04 Jared, do you want to name some of the other technologies or apps you're most excited about? Yeah, I mean, I think I'm still living in the past, right? I'm still concerned about the fallout after tornado cash, right? Like if you go to like mevwatch. info, you know, it's, we're having, you know, block relays, self-censoring at like 43.7% as of today, right? that's a huge threat to everything that happens on chain, right? Like, if the blockchain is not able to maintain its integrity, then it basically loses all value, right? And so, like, you can kind of break,
Starting point is 00:33:49 so just accessing these networks is important, right? And so this is like where anonymous communication protocols come into play. And really, we need to do two things here, right? We need to protect users who want to transatlanticians, transact with a network. We also need to protect people, the validators or miners, people who are actually securing the nodes that are securing the network. And that's not quite a trivial thing to do, right? Like, what I see a lot of is people think you can just sort of slap, tore or maybe a mix net onto it and, you know, you're done. The thing is, that doesn't really work. That might work for users, but it doesn't really work for validators and miners. And the reason for that is because of the nature of the traffic.
Starting point is 00:34:37 Say, like, when you're participating in consensus, what you're actually doing is creating the sort of deterministic wall of traffic, right? And it's hitting on a regular heartbeat, right? Everyone's basically communicating, you know, every time there's a new block being produced or proposed. And that's a huge challenge. So in Lupec style mix nets, they effectively get their anonity through delays, you can say.
Starting point is 00:35:02 And if you start getting so many people do like so many nodes doing this, you actually start blowing out those delays so you can't actually progress the chain if you know you need to have a block coming out every 30 seconds or whatever, right? And the same thing is similar with onion routing, right? Like this deterministic wall of traffic can be identified really easily. So we've had to work at Logos on effectively a hybrid between a mixed net and a flooding, flooding routing routing routing routing routing routing routing routing sort of network. It's a bit weird, right? But what's great about it is that we can guarantee, you know, a certain amount of like basically everyone who's participating will get the messages. You know, they're doing mixed net like pass the parcel of the envelopes around. and we're treating that as a form of routing within it. But we can guarantee that we can get the block proposal unlinked. And under an active adversary threat model, we can kind of raise the cost to about seven years to try and figure out
Starting point is 00:36:17 who actually did that, which is plenty of time for you to take your bags and put it into another account. And that's what I'm really excited about, because that allows us to really strengthen these systems and maintain their autonomy. All right. So let's actually now talk a little bit more about Zcash. Like MIRD kind of started this, but I have a few questions about this. So first of all, this is, you know, a coin that is focused on being either private digital
Starting point is 00:36:52 coals or some form of currency, however you, you know, want to look at it. And yet, like, I am not really sure how it achieves either of those places in the world. You know, Bitcoin kind of is claiming the digital gold. I'm not sure how we see a transition from Bitcoin having that spot to Zcash having it. And then Bitcoin's original purpose or whatever you want to call it based on the white paper was peer-to-peer electronic cash. system, so I'm not sure if Zcash is going for that. But I'm just wondering if you guys see a way for it to achieve either of those routes or something completely different. Well, certainly I'll kick it off. But so, well, so let's look at the facts, right?
Starting point is 00:37:53 So you actually, I think the first question you asked a few questions ago was what kicked off this sudden interest in privacy, so to speak. And certainly Zcash going from the facts, the top 100 to the top 10, I think, played quite a large role in that. Because, again, it is crypto, attention, liquidity equals, you know, price action, which then leads to opportunities and more people sort of trying to use that attention. But also it helps teams who were always kind of sort of doing that to begin with. And so that's why I call it the last PVE. It's obviously a meme, but it is one of the things left in finance that is player versus
Starting point is 00:38:34 environment, so to speak, rather than player versus player, right? Because if I have privacy and Laura, you have privacy, that's good for both of us. And we don't necessarily have to cannibalize each other against that, right? And so that's sort of how I would say even how we ended up on this podcast today. I'm not sure if you would have, if Zcash hadn't sort of really gotten attention back to the sector starting last year. So in terms of whether, so you mentioned, well, can it be Bitcoin? Can it be digital gold? Can it be a currency?
Starting point is 00:39:14 So, first of all, I don't think there's room. I don't think it's a winner-takes-all. And there's all sorts of anecdotes I might give for this from. traditional analogies from, for example, they're never just being one store value in the world to never one market being 100% dominated by any single player. Right. And so there will always be certain people who like the idea of Bitcoin, so to speak, but really require that additional privacy. So in Zcash's case, the privacy isn't privacy for its own sake. It's to enable a better monetary property for that asset, right?
Starting point is 00:39:54 It's sort of a, for example, one thing you might think of is fungibility, right? In the digital realm, if a coin has a history, for example, maybe I'll refer to the Canadian trucker protests, if a coin has history and you can see its providence, then there is a case in which you will not be allowed to use that coin because of its history. And so you actually sacrifice somewhat on the true fungibility of that asset. Whereas cash, for example, is devoid of all information. If I give you a $5 bill, you don't see anything about where that cash bill has been in the past. There's, of course, other parts of this, right?
Starting point is 00:40:32 So Zcash isn't just about the privacy, but sort of the holistic asset. And so one thing people might have missed in the Ironwood upgrade is that it is now quantum recoverable. Right. So you probably heard at some point about all sorts of panic about Bitcoin's quantum readiness. while Zcash is actually quantum recoverable today, and then it'll be quantum proof towards the end of autumn. Right. And so that's another thing that's kind of checked off the list.
Starting point is 00:40:59 Because a store of value fundamentally requires one to have a low entropy channel, so to speak, and entropy is defined as surprise, meaning you don't want to be surprised. You want to be able to just store it somewhere, and that's sort of that, right? And then, of course, there's other lesser-known things, for example, Zcash is actually scaling in terms of compared to Bitcoin, right? It's going from 75 second block times to 20 second block times. The TPS target is a few thousand TPS, which is obviously not the case for Bitcoin.
Starting point is 00:41:32 I'm not sure it's not on me. It's for the market to decide in terms of who buys it or who treats it as what. But for a specific set of users, me included, it feels to me, it solves my needs better than Bitcoin would. That is not to say I don't hold Bitcoin, of course. But that does mean that it is a clear, viable alternative for some sets of uses that I care about personally. And I'm curious to hear Jared's and Joe's take on, you know, what you think the trajectory of Z-Cash is. But I also just want to ask in the same breath, but they're not that bug that Merr talked about earlier, you know, in the orchard pull. if that gave you any pause or what.
Starting point is 00:42:20 And just for the audience, you know, to be clear, that was the one where an attacker could have created an unlimited number of counterfeit tokens. Most likely they did not, you know, just from the way the market activity has looked. But that bug was there for four years and nobody had detected it. So it's another fact that's a little alarming. But, yeah, I'd be curious to hear Jared and Joe's take on, you know, where you think Zcash could go. I'm having to start. And I think two things that I agree with the kind of more of the digital goal thesis.
Starting point is 00:42:55 I think, you know, wealth and net worth is kind of something that a lot of people are just sensitive about. Like people wouldn't say on this call like what their worth and like privacy and net worth have always been kind of like fairly hand in hand. So I do think that that is a kind of the support market bit there. I also think if you think about Zcash as a payment instrument, there's UX friction there. You know, every time, you know, in the real world someone wants to pay with something, there's a spread against their local currency.
Starting point is 00:43:33 And so it's not the best, like, last mile payment instrument. And so, yeah, I think it just makes more natural sense for it to be digital gold and other technologies, you know, private stable coins that are actually decentralized on different chains, probably a better payment instrument for that. I also think that as soon as you start thinking about payment instruments, you start talking about payment volumes and payment fees, rather than the asset as something that you want to buy and hold. And so the valuation metrics get a little bit strange here.
Starting point is 00:44:09 So I'm definitely more on the digital gold camp and kind of let other networks deal with privacy and kind of like crypto assets in the real world. And yeah, that's kind of my natural take. On the bug, I think it's a little surprising that it was like that undiscovered for that long, but I think it's more just a testament to how far like AI audits have come and the tools we have today. So, yeah, I think it's the same point as before where, you know, things that we took for granted
Starting point is 00:44:44 as being secure, not just on crypto rails. are definitely not secure under the current threat models. And it's actually what makes me more kind of more bullish on the digital gold thesis, because if you, you know, if you keep your wealth in a broker account and these other kind of web two things, we haven't had an AI-led attack vector on Web2 infrastructure that's kind of been systemic yet. But I do think that that will happen at some point. and the crypto rails have already been ardent by that because they're kind of the ones that are easiest to attack first.
Starting point is 00:45:22 So I think this is actually going to be a positive thing in the long run as we see the effects of kind of more upper, more adversarial environments play out. Yeah, I mean, I'm not too. Firstly, like, I mean, I have a sort of libertarian streak to me, right? So I really like the idea of sound money. And of course, fungibility to me is a very important property. and that's kind of why I use their cash shielded transactions. So on the sort of bug, I mean, like, yeah, I mean, it's unfortunate, it's a little bit of an eyebrow rays, but at the same time, like, you have to realize that most cryptographers would warn against using any kind of
Starting point is 00:46:03 cryptography that's new for, like, you know, five or even 10 years, perhaps even more. And those who are daring enough to implement that and to take it to market, you know, should really deserve the sort of praise of their guess. And, you know, these systems do run in an adversarial environment. They are anti-fragile by nature and they get fixed as a result of this. So I'm just glad it's fixed. All right. So to wrap up this little Z-cash section, I do have to ask Merck, because, we just had a big upgrade in Zecash, Ironwood, which he alluded to earlier.
Starting point is 00:46:45 But why don't you explain, you know, what happened in this upgrade, why you're excited about it? Sure. So as we just discussed, there was a bug or a vulnerability found in specifically the orchard pool. So Zcash has several shielded pools. And Ironwood was the latest one up until iron, or orchard was the latest one up until ironwood. and Taylor from Shielded Labs, who, by the way, is a very advanced high domain knowledge person. It wasn't sort of just vibe-coded. He had access to some pretty lit frontier AI tools and found disclosed and patched with the coordination of other teams, of course, this bug.
Starting point is 00:47:31 And obviously, so some people have the same reservation or that you have, which is like, okay, well, could they have done anything with that? And while all the signs and heuristics point towards no, there wasn't. So, for example, in terms of the shielded pool activity going up over time rather than going down, the price action, the fact that it was announced that there would be a fix. And so the hacker would, in theory, would want to get out before sort of they lost that window. You can point to all sorts of these things as heuristics, but fundamentally, it's crypto. So you have to be able to verify it. And so to do that, a new shield.
Starting point is 00:48:08 pool called Ironwood was released. And it's similar to Orchard, except it also has quantum recoverability. And by the way, a few days after this was found, the old Orchard Pool and Ironwood were both formally verified on three separate occasions, actually, and audited in all sorts of different ways. And so one of the, what the formerly, and you can see Sean Bow on. Twitter, he has a few posts on where he goes in a detail because I'm sure I'll push her the technicalities here. But basically the claim that there can be no undetectable counterfeiting
Starting point is 00:48:50 bugs going forward has been formally verified, right? So, of course, there could be other types of bugs just as in any software system. But the specific set of bugs has been rendered mathematically not feasible. Like that's, anyways, you can sort of look at that blog post to confirm But anyway, so how do you confirm the supply actually is like, how do you confirm that there was no new notes in Orchard pool specifically? Right. So you said, for example, and I think a lot of people have this confusion where people think it's just an unlimited amount of Zcash, but it's actually just an unlimited amount of Zcash in the orchard pool, which is about 28% of the supply. Right. And so to confirm that, what you have to do is you have to migrate from that pool.
Starting point is 00:49:38 to the orchard pool to the ironwood pool. And if there was an attack, what would happen is this thing called a turnstile would trigger. And all a turnstile does is it ensures that what goes out can't be more than what went in, right? Because you know what went in and you know what's going out in terms of aggregate amounts. And so imagine, for example, the pool orchard had a billion dollars worth in it. And imagine that 500 million has left it now. and then the turnstile triggers, well, then that 500 million remaining would be technically insolvent because you don't know who owns what notes in that pool.
Starting point is 00:50:19 Right. And so the idea here is that as the funds migrate from Orchard to Ironwood, they would tend from, you know, a billion to 500 million to 5 million until basically it approaches zero. Now, of course, it'll never actually be zero because I'm sure some people have died and lost their keys or lost their devices or whatever. And so it'll be a probabilistic bound in terms of what supply is for sure certainly not counterfeit. And then what supplies still might be insolvent. And so that already went live two days ago. There's no hiccups so far.
Starting point is 00:50:58 they're trying to make the migration such that it has built-in privacy when you migrate such that you don't expose who owns what notes. And so the app teams are also working on that. But basically, so to summarize what you get with Ironwood is you get mathematical deterministic guarantees that no undetectable counterfeiting bugs like this one can exist in the future. you get a mechanism for verifying the supply wasn't in orchard, it wasn't counterfeited. You get quantum recuperability. But then also there's a few other goodies smuggled in there about faster sync times
Starting point is 00:51:39 and faster signing and just a general performance upgrade. Great. Okay. So now let's switch to Ethereum because Ethereum has a really extensive privacy. roadmap and it covers a number of different areas. You know, they announced this big push, as I mentioned. And as I also mentioned earlier, there's a number of initiatives that, you know, range from, you know, everything including like R&D to UXUI. So it really covers the gamut. What about, you know, Ethereum's privacy roadmap? Like which segments of it are most exciting
Starting point is 00:52:21 to you? And which do you think will really? move the needle. I'm happy to start with this one. I think, yeah, Ethereum's Roadmap is very good to see. I think there's also like a lot of ways to get privacy on Ethereum today that don't need this. So Aztex is obviously one of those and just general like verifying zero noise proofs work today on Ethereum. So I think it's important to just state that. The things that are exciting to me are some of the things that Zegas has already achieved. The of upgrades, talk about having a post-quantum kind of proving system and just new state types
Starting point is 00:53:03 that make existing privacy apps much easier to build. And as tech exists as a layer too because Ethereum isn't that easy to build privacy apps on. You have to put a roll up. You have to build all of these additional metrics and like functionality to enable privacy. a few years once this roadmap is kind of fully built, the job of teams like Aztec gets a lot easier because there's kind of art of Ethereum that just do do things kind of for free. So I think it should see a lot more teams building in the space. You won't need to raise as much kind of money to like bring privacy to Ethereum and you can kind of get started a lot quicker. My only kind of
Starting point is 00:53:49 complaints about it are it's quite far out. And so, you know, like we're dealing with privacy today on Ethereum. Our V5 network went live last week. And so it's kind of like there's a tradeoff between, you know, the shiny city on the hill where, you know, everything could be perfect. And what can you actually do today? And I think the only risk I see is that the battle is being fought today for cryptographic privacy on blockchains. And there's a chance that if the roadmap comes too late, and the only type of privacy that is legally allowed is privacy through intermediaries. And that obviously brings us on to tornado cash and other things.
Starting point is 00:54:31 But yeah, my only concern with it is like it could be too late to actually show that there's meaningful demand for this privacy. And so I'd like to see more done like today on what's possible, kind of on Ethereum and kind of embracing those privacy solutions that exist today. But I mean, you must also think that if it comes to fruition, then
Starting point is 00:54:54 in a way it's almost competitive with what you're doing and could siphon like TVL or whatever. Am I right? Not really. I think the way to think about it is like there's a bunch of things in the EVM today that enable Aztec to exist.
Starting point is 00:55:12 And there we're about to get even more, which means that we can build a better Aztec. I think Ethereum is, at the protocol level, is building features into the network that enable people to build privacy applications. And so it just makes our job easier. The network effect is still going to accrue to some application on Aztec that makes use of those.
Starting point is 00:55:39 And the way to think about Aztec is just, it's a very generic execution environment for writing private applications. And the privacy roadmap is not necessarily around that. It's about making the job of teams like us, teams like privacy pools, easier so that we have more private applications. So I think the two are kind of very compatible. The only place it's maybe kind of competing is like,
Starting point is 00:56:06 you know, if EF has native private transfers, it's probably better if those occur on Ethereum L1 than on Aztec. we're more focused about kind of like real-world use cases of privacy and like programmable money like dollars and and kind of decentralized stable coins. So I think, yeah, I don't see it as fully competitive. I agree actually. Like Ethereum's privacy roadmap is a very ecosystem focused, right? And I think that's for the right play for them because they have such a dominant ecosystem of, you know, DAP developers, people building on Ethereum. So that's a huge part of their focus.
Starting point is 00:56:47 And I think that's probably the fastest way that they can achieve those kind of goals. As for the rest of the roadmap, it's very ambitious, particularly for a system that's live that's already got a lot of value, right? It's kind of a, it's very challenging to retrofit an existing system with some of these technologies and have everything go really well. Having that said, like, you know, I've been around the Ethereum community for a very long time now, and I've had to raise eyebrows a couple of times, and it's a huge testament to that community that they have pulled off some of the things that they've pulled off, particularly a transition to Ethereum 2. So if anyone can do it, they can
Starting point is 00:57:31 definitely do it. It is ambitious, and I guess we'll see. All right. So in the interest of time, even though I'm sure Merck would probably have some thoughts, we're going to talk about Canton because I think that will take up the rest of the time. And this obviously is a chain that sort of came out of nowhere. And there are private transactions on it, even private stable coin transactions. And I wonder what you think about it and how, like, do you consider it like a leader in the privacy space on chain? or how do you think about what they're doing and how it relates to privacy? I don't consider a leader in the privacy space any more than I would consider J.P. Morgan, a leader in the privacy space, which is to say that those guarantees in terms of privacy that you would get, which is just trusting your counterparty are totally achievable without using crypto in the way that they've done it. And so I don't see any reason why I would want to expose myself to that. I would like why I would want bank level guarantees, I would just use a bank.
Starting point is 00:58:43 Yeah. I second. That is what I touched on earlier with privacy through intermediaries versus cryptographic privacy. And the way that they achieve their private stable coins or private transactions is exactly the trust people. There's a sequencer who has a reputation and you send all your transactions to that sequencer and you trust with a non-credible commitment that they're not going to
Starting point is 00:59:08 monetize that data or sell that data to anyone. And so whilst it kind of, you know, it jumps on the privacy ban wagon. It's basically a bunch of banks trying to adopt a different tech stock. And yeah, I think that it should come out in the wash for kind of at least these use cases that require strong credible commitments and actual privacy that's backed by kind of cryptographic guarantees. So, Jared, I'm assuming you agree. So I want to switch up the question a little bit.
Starting point is 00:59:45 Like, what do you think then happens? So we have a bunch of financial institutions that are transacting on this chain. Like, what do you think happens to Canton? Do you think that eventually goes away and that they end up using ones that have actual, you know, technologically secure privacy or, you know, where does this go? How does it play out? Yeah, well, I mean, I don't have a crystal ball, right? So I think, you know, one way you could view that in a positive light is that you could get the sort of early market adoption or, you know, bringing these other sort of institutions this way.
Starting point is 01:00:23 And then hopefully they recognize the risks that are associated with that approach. And then once they have that sort of market, they can transition to something that has much strong. imperative or credible commitments or imperative commitments, cryptographic commitments. So that's what I would hope to see from them. Whether that's the case or not is a little unclear, right? I think that you have to be thinking about this pretty early on, for similar reasons why I think it's difficult to retrofit an existing chain
Starting point is 01:00:58 with some of these technologies. It's possible, but if you're an engineer, you like, you know, you work on these things and you accumulate technology. debt and people say like something is temporary and then you find out that five years later that's you know this piece of software is still operating in the same way right because you know business interests go in different directions um at the same time like i i think that it's great to see more and more chains more different approaches uh because it is still pretty early like you know crypto as an industry is still relatively quite small and we have a lot of uh blocked market activity
Starting point is 01:01:37 to unlock, you know, if we want to see, you know, real world assets and, you know, more stable coins, you know, more value, whatever your heart desires to be on chain. So more approaches, more surface area, bring more people in, and then, you know, hopefully the use of these technologies make good judgments over time. All right. Well, this is all the time we have. There were a few other topics, but we'll have to touch upon them another time. Thank you guys so much for coming on Unchained and sharing your thoughts on privacy. Thank you so much, Laura. See you. All right. Thanks for thanks everyone for joining this live stream. We will catch you next week. Bye now. Nothing you hear on Unchained is investment advice. This show is for informational and entertainment purposes only,
Starting point is 01:02:29 and my guest and I may hold assets discussed on the show. For more disclosures, visit UnchainedCrypto.com.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.