The privacy flip

Onchain, everything is public.

Crypto built the most surveilled financial system in history, by accident. Starknet shipped the layer that ends it: private to the market, answerable to the law, and live today.

  • 7/7Completeness score
  • ~$0.12Lowest privacy fee in DeFi

Starknet made that optional

01

The cost of being visible

The problem

Transparency is not free. The invoice arrives on three separate bills: extraction, strategy, and absence.

BILL Nº 01 · EXTRACTION01 / 03
STATUS

A STANDING TAX

CHARGED ON EVERY VISIBLE TRADE

FINE PRINT · EXTRACTION

Every pending transaction in the public mempool announces what you are about to do to the parties best equipped to charge you for it. Billions extracted on Ethereum since the Merge; $370 to $500 million taken by Solana's sandwich bots in barely a year and a half; the same extraction runs on every transparent chain. A standing tax on anyone who interacts where everyone can watch.

  • 01MEV extracted on Ethereum since the Merge$B+
  • 02Sandwich bots on Solana in 16 months$370 to 500M
BILL Nº 02 · STRATEGY02 / 03
STATUS

BAIT, ACCEPTED

YOUR LIQUIDATION LEVELS, PUBLISHED TRANSPARENTLY TO THE ENTIRE WORLD

FINE PRINT · STRATEGY

May 2025: James Wynn runs the largest publicly visible leveraged position in crypto history, $1.25B at 40x leverage on Hyperliquid. His liquidation price was known to everyone, down to the penny. The position got liquidated, and the account ended the month at $23. "They are hunting me," he posted, reopening a $100M position, which got liquidated too. A year earlier, the market got Egorov's levels the same way, in his borrowing strategy against his own CRV, and left $10M of bad debt across several lending markets. And this is no isolated event: it happens every day, across every DeFi vertical.

  • 01J. Wynn, $1.25B position, liq. price publicLIQUIDATED
  • 02M. Egorov, $96M in loans against his own CRVLIQUIDATED
  • 03Bad debt left to the lending markets$10M
BILL Nº 03 · ABSENCE03 / 03
STATUS

WAITING OUTSIDE

THE CAPITAL THAT NEVER ARRIVES

FINE PRINT · ABSENCE

Institutions do not publish supplier lists, treasuries do not broadcast rebalances, and sovereigns do not accumulate in daylight. The spot Bitcoin ETFs launched in January 2024 with every issuer declining to publish its addresses; it took Arkham twelve days to map BlackRock's and Fidelity's wallets anyway, over 58,000 BTC exposed before either firm had said a word. That is why the capital stays away: on transparent rails, showing up means being mapped. This is the bill nobody sees getting paid, and it is the biggest of the three.

  • 01BTC in use in DeFi vs total value$14B / $1.5T
  • 02Tokenized RWAs parked as registry entries, usage kept off$30B+
  • 03B2B stablecoins vs the market they can't attract$226B / $89T

There is one way to cut every line on those bills: onchain privacy.

02

Three walls, fifty years of precedent

The precedent

Crypto has attempted privacy for a decade. Every attempt hit at least one of three walls: compliance, composability, and scale.

Tornado Cash was the category's most used product until OFAC sanctioned it in 2022, and what put it on the list was not the hiding: it was the absence of any mechanism, for anyone, ever, to answer a court. Zcash, Monero and Aztec chose dedicated chains and paid for it in isolation, while Railgun stayed on the EVM and charges 0.25% each way. And a crowd you can count is not a crowd: Tornado split its users into fixed denominations and thinned every one of them.

01 · COMPLIANCE

Compliance: a privacy system with no disclosure path is unbankable by design.

Sanctioned in 2022, and the people who wrote it went to prison. Not for the hiding, for having no way to answer a court.

CASE FILE · NL
ALEXEY PERTSEV
Arrested in the Netherlands days after the sanctions. Sentenced May 2024: five years and four months of jail, money laundering.
STATUS: APPEALING
CASE FILE · US
ROMAN STORM
Arrested near Seattle, 2023. Convicted August 2025: unlicensed money transmitting. Jury hung on counts carrying forty more years.
STATUS: POST-TRIAL MOTIONS
02 · COMPOSABILITY

Composability: privacy kept being built as a destination, and destinations empty out.

A private chain of your own means no applications and no liquidity. Reaching either one means crossing back out in public.

PRIVACY ISLAND
ZCASH · MONERO · AZTEC
REAL PRIVACY, NO ECONOMY
EVERY CROSSING IS PUBLIC
DEFI MAINLAND
LIQUIDITY · LENDING · MARKETS
REAL ECONOMY, NO PRIVACY
03 · SCALE

Scale: anonymity is headcount. You are only as hidden as the crowd is large.

Hiding needs a crowd, and a crowd needs users. Drag the slider: at eight, you are one of eight.

HOW HIDDEN ARE YOU? DRAG THE CROWD.

2022

The year OFAC sanctioned Tornado Cash, until then the category's most used product.

$500,000

The Railgun cut on shielding then unshielding a $100M treasury, for privacy alone.

69.1%

How far simple heuristics could shrink Zcash's effective anonymity set (UCL, 2018).

Starknet is the first design to clear all three at once.

03

Why Starknet, structurally

The architecture

Strip away the branding and it comes down to architecture: Starknet is, structurally, the strongest privacy platform in production today. Not on one criterion. On all of them.

Privacy completeness by protocol. Seven criteria scored yes, partial (not counted) or no, with each protocol's total out of seven.
CriterionSTRK207/7AZTEC4/7ZAMA4/7RAILGUN3/7CANTON3/7MONERO2/7ZCASH1/7
Multi-AssetMulti-asset, one pool, all tokensyesyesyesyesnonono
No SecretsNo user-managed secrets, nothing to back upyesnononononono
ComplianceCompliance path, scoped disclosureyespartial, not countedyespartial, not countedyespartial, not countedpartial, not counted
FastFast shield and unshield, seconds both waysyesyesnononoyesno
ProgrammableProgrammable, private app logicyesyesyesnononono
DefiDeFi composability, existing protocolsyesyesnoyesyesnono
EcosystemExisting ecosystem, real users and liquidityyesnoyesyesyesyesyes

Yes Partial, not counted No

So how does one chain check every box at once?

The answer starts sixteen years back, with Satoshi himself naming the tool.

Satoshi Nakamoto's reply on Bitcointalk, August 11, 2010: This is a very interesting topic. If a solution was found, a much better, easier, more convenient implementation of Bitcoin would be possible. It's hard to think of how to apply zero-knowledge-proofs in this case.
Satoshi Nakamoto, Bitcointalk thread 770, August 11, 2010

Satoshi's open question

Satoshi says a much better Bitcoin would be possible if privacy could be solved, and that he cannot see how to apply zero-knowledge proofs to it.

Bitcointalk, thread 770

The San Jose talk

At Bitcoin 2013, Eli Ben-Sasson puts succinct zero-knowledge proofs in front of a Bitcoin audience: the tool Satoshi could not see how to use.

Bitcoin 2013, San Jose

The Zerocash paper

Fully private payments on a public ledger, from zero-knowledge proofs, with Eli Ben-Sasson among the authors.

Zerocash, IEEE S&P 2014

Zcash founding scientist

The Zerocash design ships as a live chain, with Eli Ben-Sasson as founding scientist. Private, but one asset on one purpose-built network.

Zcash, founding scientist

StarkWare founded

STARK proofs go to production: transparent, hash-based, built to scale. The proof system that would carry Starknet.

StarkWare

STRK20 live

Private transfers, swaps and balances for any asset on Starknet, with wallet-level UX. The 2010 question has an answer on a general-purpose chain.

Starknet, mainnet
Sixteen years later, the answer shipped.

Eli Ben-Sasson presented ZK as the fix for Bitcoin's privacy and scaling at the San Jose conference in 2013. He co-authored the 2014 Zerocash paper, the note-and-nullifier model every modern shielded system descends from, and became a founding scientist of Zcash to fix privacy in crypto. Then he co-founded StarkWare to fix scaling with ZK-STARKs. In 2026, the circle closed: ZK-STARK on Starknet switched on its second property, privacy coupled with scaling.

And the mechanism was the point.

The main strength of ZK-STARKs is the verification model itself. Chains that verify by re-execution cannot retrofit privacy: strip out the inputs and there is nothing left for validators to check. Starknet, based on ZK-STARKs, verifies proofs instead, and checking a proof requires none of the underlying data. And this was the plan from the very beginning.

The core of Starknet's architecture.
VIDEO 01 · TO BE ADDED
ARCHITECTURE01 · 2:42

How Starknet's ZK architecture works in practice

Watch
VIDEO 02 · TO BE ADDED
SEQUENCER02 · 2:24

ZK-STARK Under the Hood: Starknet's Sequencer

Watch
VIDEO 03 · TO BE ADDED
PROVER03 · 2:26

ZK-STARK Under the Hood: Starknet's Prover

Watch
VIDEO 04 · TO BE ADDED
VERIFICATION04 · 3:28

ZK-STARK Under the Hood: Proof Verification on Ethereum

Watch
PREFER IT WRITTEN? THE FULL ARCHITECTURE BEHIND STARKNET AND STARK PROOFS

Based on that, Starknet built everything around proving, from scratch, optimizing every layer of the stack:

PROOF, NOT REPLAY
PROPERTY 01

Speed

A privacy system is a consumer product before it is a cryptographic one, and private UX dies at high latency. Starknet runs at around 1,000 TPS today, with 10,000+ targeted for 2027, and latency sits in the hundreds of milliseconds for regular transactions, a few seconds for private ones.

ELIMINATES: DEDICATED PRIVACY L1s
PROPERTY 02

Succinct verifiability

Privacy at scale eventually needs clients, on browsers or phones, that verify the chain without borrowing trust from someone else's server. That requires compact proofs, not replaying everything.

ELIMINATES: FAST-BUT-HEAVY CHAINS
PROPERTY 03

ZK-native, end to end

Private computation means proving everything, constantly. Cairo was designed as a language whose execution is cheap to prove; EVM chains run a virtual machine that predates the idea, where every opcode never designed to be proven adds a cost that cannot be optimized away, and Ethereum itself is now converging on the bet StarkWare made in 2018.

ELIMINATES: EVM CHAINS
PROPERTY 04

In-protocol proof verification

The last missing piece of the proving stack. The Shinobi upgrade (SNIP-36) moved proof verification into consensus itself: a transaction carries its proof, the network checks it as part of ordinary block work, and private transactions went from impractical to seconds and cents.

ARRIVED: APRIL 2026 (SNIP-36)

With all four properties in place, Starknet is now shipping the most complete privacy ecosystem the market has seen, designed against the failure list of the past decade.

04

The most complete privacy ecosystem

The ecosystem

From first announcement to a live, multi-asset, wallet-native privacy system: in under a year. Here is what is live today, and the foundation it stands on.

The foundation everything builds on.

14,532 BTC
FEE: ~$0.12 · PAID IN STRK SHIELDED IN SECONDS
01
One pool for all assets

STRK, USDC, USDT, ETH, BTC, memecoins: every asset deepens the same crowd.

A first in crypto: STRK, USDC, USDT, ETH, BTC, memecoins... ALL crypto assets in the same pool. Every new user and asset deepens the same crowd.

02
Any amount, no denominations

Arbitrary amounts through note splitting and merging, no fixed sizes.

Where Tornado forced fixed sizes and fragmented its crowd, the Starknet pool takes arbitrary amounts through note splitting and merging.

03
Fee: ~$0.12 per action

Charged per action, not per amount, and settled in STRK.

Shielding a billion dollars costs the same as shielding a hundred: the fee is charged per action, not per amount. The protocol targets about $0.12 per action and settles it in STRK; the STRK amount floats, adjusted by the protocol as the price moves.

04
Best-in-class UX

A few clicks inside Ready or Xverse, settled in seconds.

A few clicks inside Ready or Xverse, settled in seconds. No separate app, no new seed phrase, no protocol to learn.

05
Security-first stack

Public whitepaper, OpenZeppelin audit, formal Lean model, Apache 2.0.

Public whitepaper, OpenZeppelin audit, formal Lean model with machine-checked theorems, and fully open source under Apache 2.0.

06
Deep DeFi integration

Private swaps, lending, staking and yield, atomic, into live Starknet DeFi.

The pool plugs straight into live Starknet DeFi: private swaps, lending, staking, yield, all atomic, your funds never sitting at a public address in between. And it already reaches other ecosystems: anonymous trading on Polymarket's liquidity works today, straight from an EVM wallet.

07
A compliance path built in

Private to the market, transparent to the law. Section 06 below.

Private to the market, transparent to the law. Section 06 below.

Anyone can join the ecosystem, at any time.

05

The pool, measured live.

The pool

Shielded value over timeUSD, STACKED BY ASSET, DAILY
SOURCE: STARKSCAN ↗
Pool compositionUSD BY ASSET, LATEST
SOURCE: STARKSCAN ↗
TransactionsCOUNT, DAILY
SOURCE: STRK20 DASHBOARD ↗
New usersVIEWING-KEY REGISTRATIONS, DAILY + CUMULATIVE
SOURCE: STRK20 DASHBOARD ↗
Private swap volumeUSD BY TOKEN, DAILY
SOURCE: STRK20 DASHBOARD ↗
DeFi volume privately routedUSD BY PROTOCOL, DAILY
SOURCE: STRK20 DASHBOARD ↗
RevenuePROTOCOL FEES, MEASURED, DAILY + CUMULATIVE
SOURCE: STRK20 DASHBOARD ↗
Estimated revenueESTIMATED: FLAT FEE ~$0.12 × DAILY TRANSACTIONS
SOURCE: STRK20 DASHBOARD, DAILY TRANSACTIONS ↗
06

Private, not invisible

The law

Onchain privacy earned its reputation problem: for a decade, private meant nothing to show the regulator. STRK20 was built for the opposite reading: confidential to the market, answerable to the law under a verified lawful request and only within its scope, and the mechanism is published in full.

Entry requires escrowing a viewing key, enforced by the proof itself. By default that key does nothing: it sits sealed in hardware, untouched for the overwhelming majority of users. Under a verified lawful request it can unwind one user's trail while the rest of the pool stays sealed. And even then, the key only reads: it cannot freeze, cannot seize, cannot spend.

01 · THE POOL

Protocol-enforced escrow

No escrowed viewing key, no entry: the proof itself enforces it.

02 · THE KEY

Financial Privacy Inc (FPI)

Sealed in dual hardware enclaves, governed by StarkWare, FPI, and the Starknet Security Council.

03 · THE REQUEST

Lawful request, defined

Only an authenticated order from a competent authority, on a verified legal basis.

04 · THE DISCLOSURE

Scoped, and nothing more

The minimum the request covers, re-encrypted to that authority, and nobody else.

And the whole stack is open source under Apache 2.0.

Privacy is probably the last 100x PvE bet in crypto.
Starknet is building the best ecosystem for it.

One pool for every asset, at the lowest fees of any privacy system with real DeFi access: shielded in seconds, straight from the wallet, composable across DeFi, and secured by audits and machine-checked formal proofs.