Crypto built the most surveilled financial system in history, by accident. Starknet shipped the layer that ends it: private to the market, answerable to the law, and live today.
Transparency is not free. The invoice arrives on three separate bills: extraction, strategy, and absence.
BILL Nº 01 · EXTRACTION01 / 03
STATUS
A STANDING TAX
CHARGED ON EVERY VISIBLE TRADE
FINE PRINT · EXTRACTION
Every pending transaction in the public mempool announces what you are about to do to the parties best equipped to charge you for it. Billions extracted on Ethereum since the Merge; $370 to $500 million taken by Solana's sandwich bots in barely a year and a half; the same extraction runs on every transparent chain. A standing tax on anyone who interacts where everyone can watch.
01MEV extracted on Ethereum since the Merge$B+
02Sandwich bots on Solana in 16 months$370 to 500M
BILL Nº 02 · STRATEGY02 / 03
STATUS
BAIT, ACCEPTED
YOUR LIQUIDATION LEVELS, PUBLISHED TRANSPARENTLY TO THE ENTIRE WORLD
FINE PRINT · STRATEGY
May 2025: James Wynn runs the largest publicly visible leveraged position in crypto history, $1.25B at 40x leverage on Hyperliquid. His liquidation price was known to everyone, down to the penny. The position got liquidated, and the account ended the month at $23. "They are hunting me," he posted, reopening a $100M position, which got liquidated too. A year earlier, the market got Egorov's levels the same way, in his borrowing strategy against his own CRV, and left $10M of bad debt across several lending markets. And this is no isolated event: it happens every day, across every DeFi vertical.
02M. Egorov, $96M in loans against his own CRVLIQUIDATED
03Bad debt left to the lending markets$10M
BILL Nº 03 · ABSENCE03 / 03
STATUS
WAITING OUTSIDE
THE CAPITAL THAT NEVER ARRIVES
FINE PRINT · ABSENCE
Institutions do not publish supplier lists, treasuries do not broadcast rebalances, and sovereigns do not accumulate in daylight. The spot Bitcoin ETFs launched in January 2024 with every issuer declining to publish its addresses; it took Arkham twelve days to map BlackRock's and Fidelity's wallets anyway, over 58,000 BTC exposed before either firm had said a word. That is why the capital stays away: on transparent rails, showing up means being mapped. This is the bill nobody sees getting paid, and it is the biggest of the three.
01BTC in use in DeFi vs total value$14B / $1.5T
02Tokenized RWAs parked as registry entries, usage kept off$30B+
03B2B stablecoins vs the market they can't attract$226B / $89T
There is one way to cut every line on those bills: onchain privacy.
02
Three walls, fifty years of precedent
The precedent
Crypto has attempted privacy for a decade. Every attempt hit at least one of three walls: compliance, composability, and scale.
Tornado Cash was the category's most used product until OFAC sanctioned it in 2022, and what put it on the list was not the hiding: it was the absence of any mechanism, for anyone, ever, to answer a court. Zcash, Monero and Aztec chose dedicated chains and paid for it in isolation, while Railgun stayed on the EVM and charges 0.25% each way. And a crowd you can count is not a crowd: Tornado split its users into fixed denominations and thinned every one of them.
01 · COMPLIANCE
Compliance: a privacy system with no disclosure path is unbankable by design.
Sanctioned in 2022, and the people who wrote it went to prison. Not for the hiding, for having no way to answer a court.
CASE FILE · NL
ALEXEY PERTSEV
Arrested in the Netherlands days after the sanctions. Sentenced May 2024: five years and four months of jail, money laundering.
STATUS: APPEALING
CASE FILE · US
ROMAN STORM
Arrested near Seattle, 2023. Convicted August 2025: unlicensed money transmitting. Jury hung on counts carrying forty more years.
STATUS: POST-TRIAL MOTIONS
02 · COMPOSABILITY
Composability: privacy kept being built as a destination, and destinations empty out.
A private chain of your own means no applications and no liquidity. Reaching either one means crossing back out in public.
PRIVACY ISLAND
ZCASH · MONERO · AZTEC REAL PRIVACY, NO ECONOMY
EVERY CROSSING IS PUBLIC
DEFI MAINLAND
LIQUIDITY · LENDING · MARKETS REAL ECONOMY, NO PRIVACY
03 · SCALE
Scale: anonymity is headcount. You are only as hidden as the crowd is large.
Hiding needs a crowd, and a crowd needs users. Drag the slider: at eight, you are one of eight.
HOW HIDDEN ARE YOU? DRAG THE CROWD.
2022
The year OFAC sanctioned Tornado Cash, until then the category's most used product.
$500,000
The Railgun cut on shielding then unshielding a $100M treasury, for privacy alone.
69.1%
How far simple heuristics could shrink Zcash's effective anonymity set (UCL, 2018).
Starknet is the first design to clear all three at once.
03
Why Starknet, structurally
The architecture
Strip away the branding and it comes down to architecture: Starknet is, structurally, the strongest privacy platform in production today. Not on one criterion. On all of them.
Privacy completeness by protocol. Seven criteria scored yes, partial (not counted) or no, with each protocol's total out of seven.
Criterion
STRK207/7
AZTEC4/7
ZAMA4/7
RAILGUN3/7
CANTON3/7
MONERO2/7
ZCASH1/7
Multi-AssetMulti-asset, one pool, all tokens
yes
yes
yes
yes
–no
–no
–no
No SecretsNo user-managed secrets, nothing to back up
yes
–no
–no
–no
–no
–no
–no
ComplianceCompliance path, scoped disclosure
yes
partial, not counted
yes
partial, not counted
yes
partial, not counted
partial, not counted
FastFast shield and unshield, seconds both ways
yes
yes
–no
–no
–no
yes
–no
ProgrammableProgrammable, private app logic
yes
yes
yes
–no
–no
–no
–no
DefiDeFi composability, existing protocols
yes
yes
–no
yes
yes
–no
–no
EcosystemExisting ecosystem, real users and liquidity
yes
–no
yes
yes
yes
yes
yes
Yes Partial, not counted– No
So how does one chain check every box at once?
The answer starts sixteen years back, with Satoshi himself naming the tool.
Eli Ben-Sasson presented ZK as the fix for Bitcoin's privacy and scaling at the San Jose conference in 2013. He co-authored the 2014 Zerocash paper, the note-and-nullifier model every modern shielded system descends from, and became a founding scientist of Zcash to fix privacy in crypto. Then he co-founded StarkWare to fix scaling with ZK-STARKs. In 2026, the circle closed: ZK-STARK on Starknet switched on its second property, privacy coupled with scaling.
And the mechanism was the point.
The main strength of ZK-STARKs is the verification model itself. Chains that verify by re-execution cannot retrofit privacy: strip out the inputs and there is nothing left for validators to check. Starknet, based on ZK-STARKs, verifies proofs instead, and checking a proof requires none of the underlying data. And this was the plan from the very beginning.
The core of Starknet's architecture.
VIDEO 01 · TO BE ADDED
ARCHITECTURE01 · 2:42
How Starknet's ZK architecture works in practice
→Watch
VIDEO 02 · TO BE ADDED
SEQUENCER02 · 2:24
ZK-STARK Under the Hood: Starknet's Sequencer
→Watch
VIDEO 03 · TO BE ADDED
PROVER03 · 2:26
ZK-STARK Under the Hood: Starknet's Prover
→Watch
VIDEO 04 · TO BE ADDED
VERIFICATION04 · 3:28
ZK-STARK Under the Hood: Proof Verification on Ethereum
Based on that, Starknet built everything around proving, from scratch, optimizing every layer of the stack:
PROPERTY 01
Speed
ELIMINATES: DEDICATED PRIVACY L1s
PROPERTY 02
Succinct verifiability
ELIMINATES: FAST-BUT-HEAVY CHAINS
PROPERTY 03
ZK-native, end to end
ELIMINATES: EVM CHAINS
PROPERTY 04
In-protocol proof verification
ARRIVED: APRIL 2026 (SNIP-36)
PROOF, NOT REPLAY
PROPERTY 01
Speed
A privacy system is a consumer product before it is a cryptographic one, and private UX dies at high latency. Starknet runs at around 1,000 TPS today, with 10,000+ targeted for 2027, and latency sits in the hundreds of milliseconds for regular transactions, a few seconds for private ones.
ELIMINATES: DEDICATED PRIVACY L1s
PROPERTY 02
Succinct verifiability
Privacy at scale eventually needs clients, on browsers or phones, that verify the chain without borrowing trust from someone else's server. That requires compact proofs, not replaying everything.
ELIMINATES: FAST-BUT-HEAVY CHAINS
PROPERTY 03
ZK-native, end to end
Private computation means proving everything, constantly. Cairo was designed as a language whose execution is cheap to prove; EVM chains run a virtual machine that predates the idea, where every opcode never designed to be proven adds a cost that cannot be optimized away, and Ethereum itself is now converging on the bet StarkWare made in 2018.
ELIMINATES: EVM CHAINS
PROPERTY 04
In-protocol proof verification
The last missing piece of the proving stack. The Shinobi upgrade (SNIP-36) moved proof verification into consensus itself: a transaction carries its proof, the network checks it as part of ordinary block work, and private transactions went from impractical to seconds and cents.
ARRIVED: APRIL 2026 (SNIP-36)
With all four properties in place, Starknet is now shipping the most complete privacy ecosystem the market has seen, designed against the failure list of the past decade.
04
The most complete privacy ecosystem
The ecosystem
From first announcement to a live, multi-asset, wallet-native privacy system: in under a year. Here is what is live today, and the foundation it stands on.
The foundation everything builds on.
[ ]
₿
14,532 BTC
FEE: ~$0.12 · PAID IN STRKSHIELDED IN SECONDS
01
One pool for all assets
STRK, USDC, USDT, ETH, BTC, memecoins: every asset deepens the same crowd.
A first in crypto: STRK, USDC, USDT, ETH, BTC, memecoins... ALL crypto assets in the same pool. Every new user and asset deepens the same crowd.
02
Any amount, no denominations
Arbitrary amounts through note splitting and merging, no fixed sizes.
Where Tornado forced fixed sizes and fragmented its crowd, the Starknet pool takes arbitrary amounts through note splitting and merging.
03
Fee: ~$0.12 per action
Charged per action, not per amount, and settled in STRK.
Shielding a billion dollars costs the same as shielding a hundred: the fee is charged per action, not per amount. The protocol targets about $0.12 per action and settles it in STRK; the STRK amount floats, adjusted by the protocol as the price moves.
04
Best-in-class UX
A few clicks inside Ready or Xverse, settled in seconds.
A few clicks inside Ready or Xverse, settled in seconds. No separate app, no new seed phrase, no protocol to learn.
05
Security-first stack
Public whitepaper, OpenZeppelin audit, formal Lean model, Apache 2.0.
Public whitepaper, OpenZeppelin audit, formal Lean model with machine-checked theorems, and fully open source under Apache 2.0.
06
Deep DeFi integration
Private swaps, lending, staking and yield, atomic, into live Starknet DeFi.
The pool plugs straight into live Starknet DeFi: private swaps, lending, staking, yield, all atomic, your funds never sitting at a public address in between. And it already reaches other ecosystems: anonymous trading on Polymarket's liquidity works today, straight from an EVM wallet.
07
A compliance path built in
Private to the market, transparent to the law. Section 06 below.
Private to the market, transparent to the law. Section 06 below.
What users get, in one wallet.
ONE WALLET, TWO STATESSAME WALLET, NOTHING TO READ
Allowing smart contracts to work with encrypted or hidden information without exposing it publicly onchain.
BeamCOMING
Pay by phone number: private payments addressed to a phone number, not an 0x address.
Solana & EVM walletsCOMING
Allowing Phantom, MetaMask, Rabby, and other wallets to use Starknet's privacy pool.
SpindleCOMING
Solana one-click shielding: one interface for Solana users to shield their assets on Starknet in a few clicks, with bridging, wallet setup, and everything else abstracted away.
Shadow accountsCOMING
Fresh Starknet accounts for DeFi created directly from the privacy pool, with no public link to the main account or other shadow accounts.
Onchain privacy earned its reputation problem: for a decade, private meant nothing to show the regulator. STRK20 was built for the opposite reading: confidential to the market, answerable to the law under a verified lawful request and only within its scope, and the mechanism is published in full.
Entry requires escrowing a viewing key, enforced by the proof itself. By default that key does nothing: it sits sealed in hardware, untouched for the overwhelming majority of users. Under a verified lawful request it can unwind one user's trail while the rest of the pool stays sealed. And even then, the key only reads: it cannot freeze, cannot seize, cannot spend.
01 · THE POOL
Protocol-enforced escrow
No escrowed viewing key, no entry: the proof itself enforces it.
02 · THE KEY
Financial Privacy Inc (FPI)
Sealed in dual hardware enclaves, governed by StarkWare, FPI, and the Starknet Security Council.
03 · THE REQUEST
Lawful request, defined
Only an authenticated order from a competent authority, on a verified legal basis.
04 · THE DISCLOSURE
Scoped, and nothing more
The minimum the request covers, re-encrypted to that authority, and nobody else.
And the whole stack is open source under Apache 2.0.
Privacy is probably the last 100x PvE bet in crypto. Starknet is building the best ecosystem for it.
One pool for every asset, at the lowest fees of any privacy system with real DeFi access: shielded in seconds, straight from the wallet, composable across DeFi, and secured by audits and machine-checked formal proofs.