The privacy flip
Crypto built the most surveilled financial system in history, by accident. Starknet shipped the layer that ends it: private to the market, transparent to the law, and live today.
The problem
Transparency is not free. The invoice arrives on three separate bills: extraction, strategy, and absence.
Every pending transaction in the public mempool announces what you are about to do to the parties best equipped to charge you for it. Billions extracted on Ethereum since the Merge; $370 to $500 million taken by Solana's sandwich bots in barely a year and a half; the same extraction runs on every transparent chain. A standing tax on anyone who interacts where everyone can watch.
May 2025: James Wynn runs the largest publicly visible leveraged position in crypto history, $1.25B at 40x leverage on Hyperliquid. His liquidation price was known to everyone, down to the penny. The position got liquidated, and the account ended the month at $23. "They are hunting me," he posted, reopening a $100M position, which got liquidated too. The reality is that everything was public; nobody needed to conspire. A year earlier, the market got Egorov's levels the same way, in his borrowing strategy against his own CRV, and left $10M of bad debt across several lending markets. And this is no isolated event: it happens every day, across every DeFi vertical.
Institutions do not publish supplier lists, treasuries do not broadcast rebalances, and sovereigns do not accumulate in daylight. The spot Bitcoin ETFs launched in January 2024 with every issuer declining to publish its addresses; it took Arkham twelve days to map BlackRock's and Fidelity's wallets anyway, over 58,000 BTC exposed before either firm had said a word. That is why the capital stays away: on transparent rails, showing up means being mapped. This is the bill nobody sees getting paid, and it is the biggest of the three.
There is one way to cut every line on those bills: onchain privacy. And Starknet has just shipped the design that finally works. See for yourself:
The precedent
Crypto has attempted privacy for a decade. Every attempt hit at least one of three walls.
Tornado Cash was the category's most used product until OFAC sanctioned it in 2022. What put it on the list was not the hiding itself; it was the absence of any mechanism, for anyone, ever, to answer a court. The human cost of that design choice fell on the people who wrote it.
The sanctions were eventually struck down. But without a disclosure path, privacy is not a system a regulator can accept, and TradFi capital cannot touch it.
Zcash and Monero put real cryptography on dedicated chains and paid two prices: isolation and no programmability. Aztec rebuilt privacy as its own L2, but applications cannot be connected, they have to be rebuilt, and reaching real liquidity means bridging out in public and bridging back in public. Railgun stayed on the EVM chains but takes a 0.25% cut each way, on every shield and on every unshield. Do the math: shielding then unshielding a $100M treasury costs $500,000, for privacy alone.
If a thousand users shield similar amounts at similar times, you are lost in the crowd; if three do, you are one of three. Tornado split its users into fixed denominations and thinned each crowd. UCL researchers showed in 2018 that simple timing-and-amount heuristics collapsed much of Zcash's effective anonymity set.
Compliance. Composability. Scale. Three walls, a decade of failed attempts. Starknet is the first design to clear all three at once.
The architecture
Strip away the branding and it comes down to architecture: Starknet is, structurally, the strongest privacy platform in production today. Not on one criterion. On all of them.
| PROTOCOL | MULTI-ASSET one pool, all tokens |
NO USER-MANAGED SECRETS nothing to back up |
COMPLIANCE PATH scoped disclosure |
FAST SHIELD / UNSHIELD seconds, both ways |
PROGRAMMABLE private app logic |
DEFI COMPOSABILITY existing protocols |
EXISTING ECOSYSTEM real users, liquidity |
|---|---|---|---|---|---|---|---|
| STRK20 | |||||||
| ZCASH | |||||||
| MONERO | |||||||
| RAILGUN | |||||||
| AZTEC | |||||||
| CANTON | |||||||
| ZAMA |
The answer starts fifteen years back, with Satoshi himself naming the tool.
The main strength of ZK-STARKs is the verification model itself. Chains that verify by re-execution cannot retrofit privacy: strip out the inputs and there is nothing left for validators to check. Starknet, based on ZK-STARKs, verifies proofs instead, and checking a proof requires none of the underlying data. And this was the plan from the very beginning.
Based on that, Starknet built everything around proving, from scratch, optimizing every layer of the stack:
A privacy system is a consumer product before it is a cryptographic one, and private UX dies at high latency. Starknet runs at around 1,000 TPS today, with 10,000+ targeted for 2027, and latency sits in the hundreds of milliseconds for regular transactions, a few seconds for private ones.
Privacy at scale eventually needs clients, on browsers or phones, that verify the chain without borrowing trust from someone else's server. That requires compact proofs, not replaying everything.
Private computation means proving everything, constantly. Cairo was designed as a language whose execution is cheap to prove; EVM chains run a virtual machine that predates the idea, where every opcode never designed to be proven adds a cost that cannot be optimized away, and Ethereum itself is now converging on the bet StarkWare made in 2018.
The piece that arrived this year. The Shinobi upgrade (April 2026, SNIP-36) moved proof verification into consensus itself: a transaction carries its proof, the network checks it as part of ordinary block work, and private transactions went from impractical to seconds and cents.
With all four properties in place, Starknet is now shipping the most complete privacy ecosystem the market has seen, designed against the failure list of the past decade.
The ecosystem
From first announcement to a live, multi-asset, wallet-native privacy system: in under a year. Here is what is live today, and the foundation it stands on.
₿
A first in crypto: STRK, USDC, USDT, ETH, BTC, memecoins... ALL crypto assets in the same pool. Every new user and asset deepens the same crowd.
Where Tornado forced fixed sizes and fragmented its crowd, the Starknet pool takes arbitrary amounts through note splitting and merging.
Shielding a billion dollars costs the same dime as shielding a hundred: the cheapest privacy solution with real DeFi access, and the only one where the fee stays flat whatever the size.
A few clicks inside Ready or Xverse, settled in seconds. No separate app, no new seed phrase, no protocol to learn.
Public whitepaper, OpenZeppelin audit, formal Lean model with machine-checked theorems, and fully open source under Apache 2.0.
The pool plugs straight into live Starknet DeFi: private swaps, lending, staking, yield, all atomic, your funds never sitting at a public address in between. And it already reaches other ecosystems: anonymous trading on Polymarket's liquidity works today, straight from an EVM wallet.
Private to the market, transparent to the law. Section 05 below.
The privacy pool built directly into the Ready and Xverse wallet UI, one toggle away.
Swap privately against Starknet's existing public liquidity through avnu & Ekubo.
Shielded USDC live on Starknet, highlighted by Circle itself.
Onchain salary payments with amounts and counterparties shielded. PriPay ↗
Prove who you are without revealing more than the check requires. Private KYC ↗
A call-auction dark pool on Starknet: order sizes and identities sealed until execution. Zylith ↗
Private liquid staking positions on Starknet. Endur ↗
Borrow and lend without publishing your positions and liquidation levels. Vesu ↗
Yield strategies without broadcasting your allocations. Troves ↗ ArcX ↗ ForgeYields ↗
Mint the CASH stablecoin privately, straight from the pool. Opus ↗
Private payments on Starknet. DashX ↗
Anonymous trading on Polymarket's liquidity, straight from an EVM wallet. OffMarket ↗
Additional ecosystems and apps connecting to the pool over the coming months.
StarkWare's own payroll product on the pool.
The KYC PoC hardened into a product.
Anonymous trading on Polymarket's liquidity from an EVM wallet; the model expands to more venues next. OffMarket ↗
The Foundation's incubator for teams building on the pool.
Allowing smart contracts to work with encrypted or hidden information without exposing it publicly onchain.
Private payments addressed to a phone number, not an 0x address.
Allowing Phantom, MetaMask, Rabby, and other wallets to use Starknet's privacy pool.
One interface for Solana users to shield their assets on Starknet in a few clicks, with bridging, wallet setup, and everything else abstracted away.
Allowing users to create fresh Starknet accounts for DeFi directly from the privacy pool, with no public link to their main account or other sub-accounts.
The law
Onchain privacy earned its reputation problem: for a decade, private meant nothing to show the regulator. STRK20 was built for the opposite reading, confidential to the market, transparent to the law, and the mechanism is published in full.
Entry requires escrowing a viewing key, enforced by the proof itself. By default that key does nothing: it sits sealed in hardware, untouched for the overwhelming majority of users. Under a verified lawful request it can unwind one user's trail while the rest of the pool stays sealed. And even then, the key only reads: it cannot freeze, cannot seize, cannot spend.
No escrowed viewing key, no entry: the proof itself enforces it.
Sealed in dual hardware enclaves, governed by StarkWare, FPI, and the Starknet Security Council.
Only an authenticated order from a competent authority, on a verified legal basis.
The minimum the request covers, re-encrypted to that authority, and nobody else.
And the whole stack is open source under Apache 2.0.