The privacy flip

[Your savings.] [Your strategy.] [Your next trade.]
Onchain, anyone can read all of it. Forever. Starknet just made that optional.

Crypto built the most surveilled financial system in history, by accident. Starknet shipped the layer that ends it: private to the market, transparent to the law, and live today.

ZK-STARK
PROTOCOL-LEVEL PRIVACY
STRK20s
PRIVATE DEFI
01

The cost of being visible

The problem

Transparency is not free. The invoice arrives on three separate bills: extraction, strategy, and absence.

BILL Nº 01 — EXTRACTION
CHARGED ON EVERY VISIBLE TRADE
MEV extracted on Ethereum since the Merge$B+
Sandwich bots on Solana in 16 months$370–500M
STATUSA STANDING TAX
FINE PRINT — EXTRACTION

Every pending transaction in the public mempool announces what you are about to do to the parties best equipped to charge you for it. Billions extracted on Ethereum since the Merge; $370 to $500 million taken by Solana's sandwich bots in barely a year and a half; the same extraction runs on every transparent chain. A standing tax on anyone who interacts where everyone can watch.

BILL Nº 02 — STRATEGY
YOUR LIQUIDATION LEVELS, PUBLISHED TRANSPARENTLY TO THE ENTIRE WORLD
J. Wynn, $1.25B position, liq. price publicLIQUIDATED
M. Egorov, $96M in loans against his own CRVLIQUIDATED
Bad debt left to the lending markets$10M
STATUSBAIT, ACCEPTED
FINE PRINT — STRATEGY

May 2025: James Wynn runs the largest publicly visible leveraged position in crypto history, $1.25B at 40x leverage on Hyperliquid. His liquidation price was known to everyone, down to the penny. The position got liquidated, and the account ended the month at $23. "They are hunting me," he posted, reopening a $100M position, which got liquidated too. The reality is that everything was public; nobody needed to conspire. A year earlier, the market got Egorov's levels the same way, in his borrowing strategy against his own CRV, and left $10M of bad debt across several lending markets. And this is no isolated event: it happens every day, across every DeFi vertical.

BILL Nº 03 — ABSENCE
THE CAPITAL THAT NEVER ARRIVES
BTC in use in DeFi vs total value$14B / $1.5T
Tokenized RWAs parked as registry entries, usage kept off$30B+
B2B stablecoins vs the market they can't attract$226B / $89T
STATUSWAITING OUTSIDE
FINE PRINT — ABSENCE

Institutions do not publish supplier lists, treasuries do not broadcast rebalances, and sovereigns do not accumulate in daylight. The spot Bitcoin ETFs launched in January 2024 with every issuer declining to publish its addresses; it took Arkham twelve days to map BlackRock's and Fidelity's wallets anyway, over 58,000 BTC exposed before either firm had said a word. That is why the capital stays away: on transparent rails, showing up means being mapped. This is the bill nobody sees getting paid, and it is the biggest of the three.

There is one way to cut every line on those bills: onchain privacy. And Starknet has just shipped the design that finally works. See for yourself:

WHAT YOUR ADDRESS REVEALS
0x7f3a…c92e
SALARY DETECTED
4,200 USDC / month
Same counterparty, same amount, first business day. Your employer, your paycheck, your raise history.
LIQUIDATION PRICE
$52,534
Your loan's exact breaking point, published to everyone able to push price toward it.
COUNTERPARTIES
142 addresses linked
Who you pay, who pays you, how often, and since when. Your entire commercial graph.
STRATEGY READ
DCA + rotation pattern
Timing and sizing across venues. Anyone can position ahead of your next move.
02

Three walls, fifty years of precedent

The precedent

Crypto has attempted privacy for a decade. Every attempt hit at least one of three walls.

WALL Nº 01Compliance: a privacy system with no disclosure path is a mixer with better branding.

Tornado Cash was the category's most used product until OFAC sanctioned it in 2022. What put it on the list was not the hiding itself; it was the absence of any mechanism, for anyone, ever, to answer a court. The human cost of that design choice fell on the people who wrote it.

CASE FILE — NL
ALEXEY PERTSEV
Arrested in the Netherlands days after the sanctions. Sentenced May 2024: five years and four months of jail, money laundering.
STATUS: APPEALING
CASE FILE — US
ROMAN STORM
Arrested near Seattle, 2023. Convicted August 2025: unlicensed money transmitting. Jury hung on counts carrying forty more years.
STATUS: POST-TRIAL MOTIONS

The sanctions were eventually struck down. But without a disclosure path, privacy is not a system a regulator can accept, and TradFi capital cannot touch it.

WALL Nº 02Composability: privacy kept being built as a destination, and destinations empty out.

Zcash and Monero put real cryptography on dedicated chains and paid two prices: isolation and no programmability. Aztec rebuilt privacy as its own L2, but applications cannot be connected, they have to be rebuilt, and reaching real liquidity means bridging out in public and bridging back in public. Railgun stayed on the EVM chains but takes a 0.25% cut each way, on every shield and on every unshield. Do the math: shielding then unshielding a $100M treasury costs $500,000, for privacy alone.

PRIVACY ISLAND
ZCASH · MONERO · AZTEC
REAL PRIVACY, NO ECONOMY
EVERY CROSSING IS PUBLIC
DEFI MAINLAND
LIQUIDITY · LENDING · MARKETS
REAL ECONOMY, NO PRIVACY

WALL Nº 03Scale: anonymity is headcount. You are only as hidden as the crowd is large.

If a thousand users shield similar amounts at similar times, you are lost in the crowd; if three do, you are one of three. Tornado split its users into fixed denominations and thinned each crowd. UCL researchers showed in 2018 that simple timing-and-amount heuristics collapsed much of Zcash's effective anonymity set.

HOW HIDDEN ARE YOU? DRAG THE CROWD.

Compliance. Composability. Scale. Three walls, a decade of failed attempts. Starknet is the first design to clear all three at once.

03

Why Starknet, structurally

The architecture

Strip away the branding and it comes down to architecture: Starknet is, structurally, the strongest privacy platform in production today. Not on one criterion. On all of them.

PROTOCOL MULTI-ASSET
one pool, all tokens
NO USER-MANAGED
SECRETS
nothing to back up
COMPLIANCE PATH
scoped disclosure
FAST SHIELD /
UNSHIELD
seconds, both ways
PROGRAMMABLE
private app logic
DEFI
COMPOSABILITY
existing protocols
EXISTING
ECOSYSTEM
real users, liquidity
STRK20
ZCASH
MONERO
RAILGUN
AZTEC
CANTON
ZAMA

So how does one chain check every box at once?

The answer starts fifteen years back, with Satoshi himself naming the tool.

satoshi
FOUNDER
ACTIVITY: 364
This is a very interesting topic. If a solution was found, a much better, easier, more convenient implementation of Bitcoin would be possible. [...] It's hard to think of how to apply zero-knowledge-proofs in this case.
Sixteen years later, the answer shipped.
Eli Ben-Sasson presented ZK as the fix for Bitcoin's privacy and scaling at the San Jose conference in 2013. He co-authored the 2014 Zerocash paper, the note-and-nullifier model every modern shielded system descends from, and became a founding scientist of Zcash to fix privacy in crypto. Then he co-founded StarkWare to fix scaling with ZK-STARKs. In 2026, the circle closed: ZK-STARK on Starknet switched on its second property, privacy coupled with scaling.
2010
SATOSHI'S
OPEN QUESTION
2013
SAN JOSE
TALK
2014
ZEROCASH
PAPER
2016
ZCASH
FOUNDING SCIENTIST
2018
STARKWARE
FOUNDED
2026
STRK20
LIVE

The main strength of ZK-STARKs is the verification model itself. Chains that verify by re-execution cannot retrofit privacy: strip out the inputs and there is nothing left for validators to check. Starknet, based on ZK-STARKs, verifies proofs instead, and checking a proof requires none of the underlying data. And this was the plan from the very beginning.

The core of Starknet's architecture.
VIDEO 01 — TO BE ADDED

How Starknet's ZK architecture works in practice

VIDEO 02 — TO BE ADDED

ZK-STARK Under the Hood: Starknet's Sequencer

VIDEO 03 — TO BE ADDED

ZK-STARK Under the Hood: Starknet's Prover

VIDEO 04 — TO BE ADDED

ZK-STARK Under the Hood: Proof Verification on Ethereum

PREFER IT WRITTEN? THE FULL ARCHITECTURE BEHIND STARKNET AND STARK PROOFS

Based on that, Starknet built everything around proving, from scratch, optimizing every layer of the stack:

PROPERTY 01

Speed

A privacy system is a consumer product before it is a cryptographic one, and private UX dies at high latency. Starknet runs at around 1,000 TPS today, with 10,000+ targeted for 2027, and latency sits in the hundreds of milliseconds for regular transactions, a few seconds for private ones.

ELIMINATES: DEDICATED PRIVACY L1s
PROPERTY 02

Succinct verifiability

Privacy at scale eventually needs clients, on browsers or phones, that verify the chain without borrowing trust from someone else's server. That requires compact proofs, not replaying everything.

ELIMINATES: FAST-BUT-HEAVY CHAINS
PROPERTY 03

ZK-native, end to end

Private computation means proving everything, constantly. Cairo was designed as a language whose execution is cheap to prove; EVM chains run a virtual machine that predates the idea, where every opcode never designed to be proven adds a cost that cannot be optimized away, and Ethereum itself is now converging on the bet StarkWare made in 2018.

ELIMINATES: EVM CHAINS
PROPERTY 04

In-protocol proof verification

The piece that arrived this year. The Shinobi upgrade (April 2026, SNIP-36) moved proof verification into consensus itself: a transaction carries its proof, the network checks it as part of ordinary block work, and private transactions went from impractical to seconds and cents.

With all four properties in place, Starknet is now shipping the most complete privacy ecosystem the market has seen, designed against the failure list of the past decade.

04

The most complete privacy ecosystem

The ecosystem

From first announcement to a live, multi-asset, wallet-native privacy system: in under a year. Here is what is live today, and the foundation it stands on.

The foundation everything builds on.
14,532 BTC
FLAT FEE ~$0.12 SHIELDED IN SECONDS
SEVEN PROPERTIES OF THE BASE LAYER
01
One pool for all assets

A first in crypto: STRK, USDC, USDT, ETH, BTC, memecoins... ALL crypto assets in the same pool. Every new user and asset deepens the same crowd.

02
Any amount, no denominations

Where Tornado forced fixed sizes and fragmented its crowd, the Starknet pool takes arbitrary amounts through note splitting and merging.

03
Flat fee: 4 STRK (~$0.12)

Shielding a billion dollars costs the same dime as shielding a hundred: the cheapest privacy solution with real DeFi access, and the only one where the fee stays flat whatever the size.

04
Best-in-class UX

A few clicks inside Ready or Xverse, settled in seconds. No separate app, no new seed phrase, no protocol to learn.

05
Security-first stack

Public whitepaper, OpenZeppelin audit, formal Lean model with machine-checked theorems, and fully open source under Apache 2.0.

06
Deep DeFi integration

The pool plugs straight into live Starknet DeFi: private swaps, lending, staking, yield, all atomic, your funds never sitting at a public address in between. And it already reaches other ecosystems: anonymous trading on Polymarket's liquidity works today, straight from an EVM wallet.

07
A compliance path built in

Private to the market, transparent to the law. Section 05 below.

ONE BALANCE, TWO STATES, ONE CLICK APART
WHAT THE MARKET SEES
owner: 0x7f3a…c92e (you, mapped)
balance: 1.284 BTC
last tx: 0.4 BTC → 0x91bb…e07a
history: complete, forever
note: 0xa93f…e4d1 (ciphertext)
owner: unreadable
amount: unreadable
link to past tx: none
WHAT YOU SEE
balance: 1.284 [₿]
spendable: instantly, atomically
DeFi access: swaps, lending, staking... all of it
disclosure: scoped, lawful request only
SAME TOKENS, SAME WALLET.
Three fronts are building on top of it.
STARKNET DEFI
Starknet DeFi grafts itself onto the pool
Wallet-native shielding · Ready & XverseLIVE

The privacy pool built directly into the Ready and Xverse wallet UI, one toggle away.

Private swaps · avnu & EkuboLIVE

Swap privately against Starknet's existing public liquidity through avnu & Ekubo.

Private USDC · w/ CircleLIVE

Shielded USDC live on Starknet, highlighted by Circle itself.

Private payroll · PriPayLIVE

Onchain salary payments with amounts and counterparties shielded. PriPay ↗

Private KYCLIVE

Prove who you are without revealing more than the check requires. Private KYC ↗

Dark pool · ZylithTESTNET

A call-auction dark pool on Starknet: order sizes and identities sealed until execution. Zylith ↗

Liquid staking · EndurCOMING

Private liquid staking positions on Starknet. Endur ↗

Lending & borrowing · VesuCOMING

Borrow and lend without publishing your positions and liquidation levels. Vesu ↗

Yield · Troves, ArcX, ForgeYieldsCOMING

Yield strategies without broadcasting your allocations. Troves ↗ ArcX ↗ ForgeYields ↗

Private CASH stablecoin minting · OpusCOMING

Mint the CASH stablecoin privately, straight from the pool. Opus ↗

Private payments · DashXCOMING

Private payments on Starknet. DashX ↗

OTHER ECOSYSTEMS
The confidentiality layer for other ecosystems
OffMarket · on PolymarketLIVE

Anonymous trading on Polymarket's liquidity, straight from an EVM wallet. OffMarket ↗

More integrationsCOMING

Additional ecosystems and apps connecting to the pool over the coming months.

FIRST-PARTY PIPELINE
Nine first-party projects by StarkWare & the Foundation
Private PayrollLIVE

StarkWare's own payroll product on the pool.

Private KYCLIVE

The KYC PoC hardened into a product.

OffMarket · on PolymarketLIVE

Anonymous trading on Polymarket's liquidity from an EVM wallet; the model expands to more venues next. OffMarket ↗

Proof of Privacy incubatorCOHORT 01

The Foundation's incubator for teams building on the pool.

Starknet EnclaveCOMING

Allowing smart contracts to work with encrypted or hidden information without exposing it publicly onchain.

Beam · pay by phone numberCOMING

Private payments addressed to a phone number, not an 0x address.

Solana & EVM wallet integrationsCOMING

Allowing Phantom, MetaMask, Rabby, and other wallets to use Starknet's privacy pool.

Spindle · Solana one-click shieldingCOMING

One interface for Solana users to shield their assets on Starknet in a few clicks, with bridging, wallet setup, and everything else abstracted away.

Sub-accountsCOMING

Allowing users to create fresh Starknet accounts for DeFi directly from the privacy pool, with no public link to their main account or other sub-accounts.

Anyone can now join them.
The pool, measured live.
SHIELDED VALUE OVER TIMEUSD, STACKED BY ASSET, DAILY
SOURCE: STARKSCAN ↗
PRIVATE SWAP VOLUMEUSD BY TOKEN, DAILY
SOURCE: STRK20 DASHBOARD ↗
DEFI VOLUME PRIVATELY ROUTEDUSD BY PROTOCOL, DAILY
SOURCE: STRK20 DASHBOARD ↗
TRANSACTIONSCOUNT, DAILY
SOURCE: STRK20 DASHBOARD ↗
NEW USERSVIEWING-KEY REGISTRATIONS, DAILY + CUMULATIVE
SOURCE: STRK20 DASHBOARD ↗
05

Private, not invisible

The law

Onchain privacy earned its reputation problem: for a decade, private meant nothing to show the regulator. STRK20 was built for the opposite reading, confidential to the market, transparent to the law, and the mechanism is published in full.

Entry requires escrowing a viewing key, enforced by the proof itself. By default that key does nothing: it sits sealed in hardware, untouched for the overwhelming majority of users. Under a verified lawful request it can unwind one user's trail while the rest of the pool stays sealed. And even then, the key only reads: it cannot freeze, cannot seize, cannot spend.

THE POOL
Protocol-enforced escrow

No escrowed viewing key, no entry: the proof itself enforces it.

  • · Viewing key escrowed at entry, encrypted to the auditor
  • · The escrow is enforced by the proof itself
  • · Deposits screened at the edge
THE KEY
Financial Privacy Inc (FPI)

Sealed in dual hardware enclaves, governed by StarkWare, FPI, and the Starknet Security Council.

  • · Founded by the QEDIT team
  • · Master key sealed in a dual-enclave TEE
  • · 3-of-4 multisig: StarkWare + FPI
  • · Starknet Security Council backup & upgrade control
  • · Never touched for the overwhelming majority of users
THE REQUEST
Lawful request, defined

Only an authenticated order from a competent authority, on a verified legal basis.

  • · An authenticated order from a competent authority
  • · Acting inside its jurisdiction
  • · On a verified legal basis
  • · Anything less is refused
THE DISCLOSURE
Scoped, and nothing more

The minimum the request covers, re-encrypted to that authority, and nobody else.

  • · Minimum necessary scope: potentially a single transfer in a defined window
  • · Re-encrypted inside the enclave
  • · Delivered to the requesting authority, and nobody else
  • · The rest of the pool stays sealed

And the whole stack is open source under Apache 2.0.

Privacy is probably the last 100x PvE bet in crypto.
Starknet is building the best ecosystem for it.