The Privacy Thesis
The most complete privacy stack in crypto is live on Starknet, and the market hasn't noticed yet
For two quarters, the most watched investor in the world bought $6.7 billion of a company and nobody saw it. Berkshire Hathaway built its Chubb position in silence because the SEC allows exactly that: large investors can file confidentially while they accumulate, precisely because information moves prices. The most regulated market on earth decided long ago that forcing every position into daylight does not make markets fairer. It makes them unusable for anyone with size.
In crypto, no such machinery exists: every pending trade sits in a public mempool. Every treasury, salary, and counterparty relationship is readable by competitors, bots, analytics firms, and strangers, at the same time, forever, with no way to take any of it back.
For most of financial history, the resting state of a transaction was discretion. Two parties knew, their bank knew, and a court could compel the rest. Bitcoin inverted that resting state, not out of ideology but out of engineering necessity: a chain that verifies by re-executing every transaction needs every input in the open. The industry then spent fifteen years mistaking that constraint for a principle. The philosopher Helen Nissenbaum gave the broken thing a name: contextual integrity. Information is not simply private or public; it flows within contexts that have rules:
Your doctor holds your medical file, and that is normal;
your employer reading it is a violation, even though the file never changed.
Finance ran on the same rules for centuries. But public blockchains have no contexts at all. The tax authority, your competitor, and the sandwich bot extracting value from your trade all see the same transaction, at the same moment, with the same level of detail.
This article will show you how Starknet is rebuilding those contexts onchain, without giving up public settlement or lawful oversight. It is the only production system today that holds every piece of the solution, and the market is not pricing it yet.
What being public costs
The costs of transparency show up in three ledgers: extraction, strategy, and absence.
Extraction is the quantified one. A transaction waiting in a public mempool announces what you are about to do to the parties best equipped to charge you for it. The bill on Ethereum has run into the billions since the Merge; Solana's is better documented still, with an estimated $370 to $500 million taken by sandwich bots in barely a year and a half. Let’s call it what it is: a standing tax on anyone who trades where everyone can watch.
Strategy is the second ledger. In May 2025, a trader known as James Wynn built the largest publicly visible leveraged position in crypto history: a $1.25 billion Bitcoin long at 40x on Hyperliquid. Publicly visible is the operative phrase. His wallet was tracked in real time, his liquidation price was known to the dollar, and half of crypto Twitter watched the countdown live. Bitcoin dipped below $105,000, the position was wiped, and the account that had touched nine figures ended the month holding $23. When he reopened a $100 million position days later, he spent that week publicly accusing market makers of pushing price into his levels, pleading with followers not to let them liquidate him. Whether anyone actually needed to conspire is beside the point: the coordinates were public, and a visible liquidation level is a standing invitation. The market accepted it, twice.
And Wynn is only the loudest example among many. Here is another one, again on Hyperliquid (screenshot below). The same pattern plays out across other DeFi sectors too: a year earlier, Curve founder Michael Egorov carried roughly $96 million in loans against his own CRV, liquidation points readable onchain across several lending markets; the market went and got those too, and the cascade left about $10 million nobody would repay.
Absence is the largest ledger and the hardest to see, because it is measured in capital that never arrives. Bitcoin’s market value sits around $1.5 trillion; barely $14 billion of it does any work in DeFi. The spot Bitcoin ETFs launched in January 2024 with every issuer declining to publish its addresses. It took Arkham twelve days to publish them anyway: BlackRock’s and Fidelity’s wallets, more than 58,000 BTC between them, mapped and public before either firm had said a word. Tokenized real-world assets quintupled to over $30 billion by mid-2026, yet the assets mostly sit onchain as registry entries while the actual usage stays off. Stablecoins clear roughly $226 billion a year in B2B payments against an $89 trillion global market. The bottleneck is not fees or finality, it’s transparency. A multinational does not publish its supplier list, so it will not pay its suppliers on rails that do.
And a fourth ledger is opening. As AI agents begin executing onchain on people’s behalf, a transparent chain turns every automated strategy into a serialized publication. A rival agent can then reverse-engineers a playbook, then trades it before its owner can. This extraction layer barely exists yet, only because the AI agents don’t as well. The chains that host that volume will need to have been private before it arrived.
Three walls, fifty years of precedent
Crypto has attempted privacy for a decade. Every attempt hit at least one of the following three walls.
The first one: the compliance wall. Tornado Cash was the category’s most used product until OFAC sanctioned it in 2022. What put it on the list was not the hiding itself; it was the absence of any mechanism, for anyone, ever, to answer a court. The human cost of that design choice fell on the people who wrote it:
Alexey Pertsev was arrested in the Netherlands days after the sanctions and sentenced in 2024 to more than five years for money laundering; he is still appealing.
Roman Storm was arrested at his home near Seattle in 2023 and, after a four-week federal trial, convicted in August 2025 of conspiring to run an unlicensed money transmitting business, with the jury hung on the heavier laundering and sanctions counts that carried up to forty more years between them.
The sanctions themselves were eventually struck down and lifted. But the important part here is that a privacy tool without any disclosure path is not a privacy system for a regulator, and those become unusable for TradFi players.
The second wall: the composability wall. Zcash and Monero put real cryptography on dedicated chains and paid two prices:
Isolation: no shared liquidity, a single asset, not connected with the rest of the crypto space
No programmability: not enough expressivity to build a concrete & advanced DeFi ecosystem on top of them
Aztec attacked the problem from the opposite end: a dedicated privacy-first L2, with serious engineering behind it. But the flaw is structural, as Aztec built its own chain from scratch relatively recently. So existing applications cannot be connected; they have to be rebuilt inside Aztec’s private programming model. The chain launched with privacy and almost nothing to use it on. As such, an Aztec user who wants to actually do something faces a routine that defeats the purpose:
bridge out, publicly, with the amount and timing visible on the destination chain. Execute the trade in the open like everyone else.
Bridge back in, publicly again.
The privacy holds precisely while the capital is doing nothing, and evaporates at both border crossings, which are the exact moments an observer needs to link a user to their activity.
Railgun made the opposite bet: stay on the public EVM chains and add a shielded pool as an application on top. That preserves access to real liquidity, but the host chains verify by re-execution and were never built to check proofs, so every private operation fights the base layer. As such, the costs show up in the fee model: Railgun takes a percentage cut on shielding and unshielding, 0.25% each way, which means hiding a $50 million treasury costs $250,000 while hiding $500 costs pennies. The price of privacy scales with exactly how much you need it.
And the last wall: scale. Privacy systems have a property that no amount of cryptography can engineer away: how hidden you are depends on how many people you could plausibly be. If a thousand users shield similar amounts at similar times, you are lost in the crowd; if three do, you are one of three. Every prior system struggled to gather that crowd. Tornado Cash split deposits into fixed denominations, separate pools of 0.1, 1, 10 and 100 ETH, so the crowd fragmented four ways, and cover was scarcest exactly where positions were largest. Zcash made shielding optional, and for most of its history under a tenth of the supply was shielded (the share sat near 8% as recently as early 2024). UCL researchers showed back in 2018 that simple heuristics on timing and amounts could collapse much of the effective anonymity set. And the loop is vicious: users only come for privacy once the crowd exists, and the crowd only exists once users come. Most entrants died in that loop before compliance or composability ever became their problem.
The Ethereum Foundation’s Privacy and Scaling Explorations team published user research this year explaining the main issues facing privacy projects:
anonymity sets fragmented across products,
private balances cut off from DeFi,
wallets that never integrated the flows,
disclosure nobody could explain,
costs that scaled with usage.
In short: privacy kept being built as a separate place users had to travel to, and places like that empty out.
Traditional finance hit this exact wall and built its way around it, starting in 1969. That December, Instinet went live: a network that let banks, insurers, and pension funds trade blocks with each other directly, anonymously, without walking an order across an exchange floor where everyone could see it coming. The regulators’ bargain was specific, and it still defines the model today: the venue hides the order before the trade, never the trade after it. The principle behind it is simple: confidential to the market, transparent to the law. Half a century later, that architecture is now the market itself. Bloomberg reported in January 2025 that, for the first time on record, the majority of all US stock trading, 51.8% of volume, was executing away from public exchanges. The deepest equity market on earth moved most of its flow into discreet venues. Crypto, the market that made total transparency a founding principle, is the only serious one that never built this layer. That is the hole in its market structure.
Why Starknet is the answer
The gap persisted for an architectural reason, and it closes for one too.
A chain that verifies by re-execution cannot retrofit privacy: strip out the inputs and there is nothing left for the validators to check. Starknet verifies differently: one party computes and produces a STARK proof; everyone else checks the proof. And checking a proof requires none of the underlying data.
This verification model, powered by Zero-Knowledge (ZK) proofs, unlocks two things: (1) scale, and (2) privacy. And after spending the better part of a decade on the scaling half, Starknet and StarkWare are now turning the same machinery toward privacy.
The interesting part is that this was the plan from the very beginning: Eli Ben-Sasson, StarkWare’s co-founder, presented the core idea, proving a statement without revealing its contents, at a Bitcoin conference in San Jose back in 2013, and co-authored the 2014 Zerocash paper that introduced the note-and-nullifier model every modern shielded system descends from, Zcash included.
And when a forum user asked Satoshi about zero-knowledge proofs in 2010, his reply was that a solution would make possible “a much better, easier, more convenient implementation of Bitcoin.” Eli Ben-Sasson and StarkWare have spent more than a decade building that solution, and it is now live on Starknet.
Four properties have to coexist for privacy to work at market scale. And while plenty of chains have one or two, Starknet is the only chain in production to gather all of 4 in one stack.
Speed: a privacy system is a consumer product before it is a cryptographic one. Every private action requires generating and verifying a proof on top of the normal transaction work, so the underlying chain needs both high throughput to absorb that extra computation and low latency, because users abandon anything that makes them wait, especially in our TikTok era. This is what disqualifies the purpose-built privacy chains at scale. Starknet runs around 1,000 TPS today with a stated path to 10,000 in 2027, and settles in seconds.
Succinct verifiability: at scale, privacy means users, using their phones or browsers, can verify chain state themselves without outsourcing trust to someone else’s server, because a privacy system where you must trust an intermediary to tell you what happened has reintroduced the intermediary it was built to remove. That requires the chain to be checkable through compact proofs rather than by replaying everything. This is what disqualifies the fast-but-heavy chains: Solana can support strong privacy features at the application layer, but the chain itself cannot be verified succinctly, so a phone can never independently check it. Starknet was built on STARKs from day one; succinct verification is therefore the settlement mechanism.
3. ZK-nativeness, end to end: private computation means proving everything, constantly: hash functions, signatures, the virtual machine itself. If any layer of the stack is expensive to prove, every private transaction pays that tax forever. This is where the EVM architecture loses: it welds proofs onto a virtual machine that predates the idea, and every opcode that was never designed to be proven adds a cost that cannot be optimized away. The strongest confirmation comes from Ethereum itself: Vitalik has publicly proposed replacing the EVM with a ZK-friendly architecture, and the Foundation’s roadmap now centers on proving the chain in real time. The bet StarkWare made in 2018 is the one Ethereum is converging on nearly a decade later. Starknet never had to converge, because it started there: Cairo was designed as a language whose execution is cheap to prove, the VM was built for STARK generation and recursion, and nothing in the stack is constrained by EVM compatibility. The entire architecture was shaped around the proving.
4. Cheap proof verification at the protocol level: the first three properties existed on Starknet for years. The fourth is what turned them into a product, and it only arrived this April 2026. Indeed, before the Shinobi upgrade (v0.14.2), a user’s STARK proof had to be verified inside smart contracts, and STARK proofs are tens of thousands of field elements, larger than a transaction could even carry. Simply put: privacy was architecturally possible on Starknet but economically absurd. To fix that, SNIP-36 moved verification into consensus itself: a transaction now carries its proof, and the network checks it as part of its ordinary block work. That single change took private transactions from impractical to seconds and cents, which is why the entire product wave, strkBTC in May, STRK20 in June, shipped in the weeks that followed.
With all four properties in place, Starknet is now shipping the most complete privacy ecosyste, the market has seen, designed against the failure list of the past decade:
a disclosure path where Tornado had none,
composability where Aztec built an island,
expressivity where Zcash and Monero have none,
flat-fee privacy for DeFi where Railgun charges by position size,
and one shared crowd where everyone else fragmented theirs.
The Starknet privacy ecosystem
At the end of the day, infrastructure is just infrastructure; what matters is what is built on top of it. And with the best privacy infrastructure now in place, the Starknet ecosystem started gathering a few months ago to build the best privacy ecosystem on the market.
At the base of this ecosystem sits a privacy pool operating at the protocol level. Protocol level means the pool is not an application bolted onto the chain: proofs are generated with Stwo, the very same prover that has been securing Starknet blocks in production for years, and verified by the consensus itself. As such, applications and builders never need to touch the cryptography; the chain does all the privacy work the very same way it does for every other kind of verification. You can learn more about the design in the STRK20 Technical Paper.
Then, six properties of that base layer make Starknet the best place for privacy, both for users and builders:
One privacy pool for all assets, a first in crypto. That means Starknet's privacy pool is the only pool handling all ERC-20 assets together: STRK, USDC, USDT, ETH, BTC, Ekubo, Hype, all your favorite memecoins, etc. EVERY ASSET inside the same privacy pool, with atomic execution and zero fragmentation. So every new asset and user improve the anonymity set.
Any amount, no denominations. While Tornado forced deposits into fixed sizes and fragmented its crowd, Starknet's privacy pool takes arbitrary amounts through note splitting and merging.
A flat fee of 4 STRK per private action, ~$0.12 as of July 16, 2026. Shielding a billion dollars costs the same dime as shielding a hundred. Do the math compared to Railgun's percentage model, where hiding a $50 million treasury costs $250,000.
Best-in class UX. Shielding is a few clicks inside the Ready or Xverse wallets, settling in seconds.
Security-first stack. Public whitepaper, an OpenZeppelin audit, a formal Lean model with machine-checked theorems covering double-spends, note accounting, and the completeness of disclosure.
A compliance path, making privacy actually usable for everyone. Entry is gated, meaning you cannot use the pool without escrowing a viewing key, encrypted to an auditing entity, and the proof itself enforces the escrow. Deposits are screened at the edge. Under a lawful request, the auditor can unwind a single user's trail in either direction while the rest of the pool stays sealed. Critically, the auditor's key reads; it cannot freeze, cannot seize, cannot spend. The auditing entity has a name and an architecture: Financial Privacy Inc, founded by the team behind QEDIT, holding the master key in a dual-enclave TEE, under a 3-of-4 multisig split between StarkWare and FPI, with Starknet Security Council backup and Council sign-off required for any change to the compliance model. Lawful request, and every other aspect, is clearly defined in this article. And for those who want no compliance layer at all, the privacy stack is open source under Apache 2.0, and anyone can fork the pool and deploy their own implementation without the viewing-key escrow. StarkWare and the Foundation will keep pushing the compliance-enabled pool, because that is where institutional capital can actually go, but every fork inherits the same UX, cost, and infrastructure optimizations as the ecosystem keeps shipping them.
On top of that, a real ecosystem of private use cases is currently being built, divided into three categories.
The first one is Starknet DeFi grafting itself onto the pool:
private swaps powered by avnu and Ekubo are live today, executed as one atomic transaction,
private liquid staking powered by Endur is only a few days away,
private yield generation by Troves, ArcX and ForgeYields is in the works,
private lending & borrowing by Vesu too,
private order flow through Zylith's call-auction dark pool is already live on testnet,
private gaming by Cartridge in the exploration phase,
private payroll, already live through PriPay,
private KYC PoC, already released,
and much more to come.
The second one is making Starknet's pool the confidentiality layer for all other ecosystems. The first of these, OffMarket, routes trades into Polymarket's existing markets through disposable execution accounts, so a trader's positions stop being attributable to their main wallet. Simply put: trade anonymously using Polymarket's liquidity, in a few seconds and a few clicks, using your existing EVM wallets. That model will be rolled out to many more use cases over the next few months.
The last one is StarkWare and the Starknet Foundation building their own products and UX optimizations on top of it. Ten projects are currently under development:
Private Payroll, allowing companies to pay onchain without revealing who is paying what to whom,
Private KYC, allowing people to prove they hold one attribute without revealing their whole documents and identity,
Starknet's enclave, allowing smart contracts to work with encrypted or hidden information without exposing that information publicly onchain,
Beam, allowing users to pay privately with their phone number,
Privacy on top of Polymarket, OffMarket, mentioned above, testing this model before expanding it to other use cases,
Solana & EVM wallet integrations into the privacy pool, allowing Phantom, MetaMask, Rabby, and other wallets to use Starknet's privacy pool,
Spindle, one interface allowing Solana users to easily and quickly shield their assets on Starknet, with the full complexity of bridging, installing a new wallet, and everything else abstracted away,
Sub-accounts, allowing users to create fresh Starknet accounts for DeFi interactions directly from the privacy pool, with no public link to the user's main account or other sub-accounts,
Proof of Privacy, a Starknet’s Foundation-backed incubator whose mentor bench includes Pantera and YZi Labs.
And while existing DeFi applications, StarkWare, and the Starknet Foundation are already building on top of it, anyone can now join them:
The Privacy SDK is live and the Wallet API spec is released,
STRK20s by example shows how to bring privacy to your specific use case,
And for teams looking for a starting point, the STRK20 RFP catalogs what the ecosystem wants as use cases
The privacy moat, and where Starknet fits in it
Here is the part I believe the market understands least.
Blockspace is commoditizing; speed and fees converge to zero everywhere. And most chains are now competing for users' attention with incentives and short-term attention games. But the real moat an ecosystem can have is sticky liquidity. And privacy pushes liquidity to be sticky by default, because privacy changes the switching dynamics between ecosystems.
On a fully transparent chain, moving capital from one ecosystem to another is frictionless. Users can bridge out, chase better yields, speculate elsewhere, and rotate back later at relatively low cost. But once meaningful privacy is introduced at the ecosystem level, switching becomes more complex.
Bridging is no longer just a technical operation; it can become one of the main risk points for confidentiality. Timing, size correlations, network traces, and contextual patterns can all leak information when users move between private and public environments. This is why privacy is not just a feature inside one app. At scale, it becomes an ecosystem property.
So if users find a private environment they trust, plus useful applications and good enough UX, they are more likely to stay than they would be on a generic transparent chain. That is where a real moat begins to emerge. Privacy creates a form of lock-in through confidentiality-preserving switching costs. And those switching costs can be economically powerful:
They improve retention
Retention helps liquidity thicken
Deeper liquidity attracts better applications
Better applications create more activity
And activity, if properly captured, can translate into more durable ecosystem revenue
As such, privacy is not only about hiding information, it can also improve market structure. It can reduce the speed at which value gets extracted and rotated elsewhere. It can help chains convert activity into durable economic weight rather than temporary volume spikes. Starknet’s design is built to maximize that compounding: one multi-asset pool instead of per-asset silos, flat fees instead of size penalties, and the ecosystem’s existing flows, and soon other ecosystems’ flows, routed through the same anonymity set.
The potential is huge for Starknet as a chain, for two main reasons.
The first one is that, despite flawed architectures, current privacy ecosystems see real demand:
Tornado Cash still holds around $550 million in TVL and generates over $5M in annualized user fees, years after sanctions
Railgun holds $80 to 90 million in TVL, with consistent transaction volume over time, and a cumulative revenue of $13M in two years.
Zcash saw its shielded pool grow from 11% to roughly 30% of total supply in a single year, more growth than the previous eight years combined, all while the price of ZEC has been soaring (~10x in a year)
And now Starknet is entering the market with a better architecture, better UX, more use cases, the cheapest solution to use, and plenty of optimizations and cross-chain flows to come. As of today, July 16, 2026, half a million dollars in value, across 19 assets, is already private inside the same privacy pool.
Note that:
Yes, the value inside is still relatively low, but this is only the beginning of this pool, and the growth is steadily up and to the right.
Plenty of optimizations and integrations are coming in the next few weeks and months; only 10% of the design the team has in mind is live today.
The architecture itself makes STRK20 the natural privacy pool for cross-chain shielding, meaning most of the flow in the future will probably be: deposit from a chain, withdraw back to that chain on a new wallet.
The second reason is that institutions are now entering the market at full speed, as recently shown by Robinhood and eToro, and these players need privacy more than anyone else. As Mert recently highlighted, privacy is probably the last 100x PvE bet, and institutions will accelerate that momentum.
Demand is proven, the architecture is finally complete, and the crowd compounds from here: the Starknet moat is forming.
The bottom line
Strip everything away and the thesis is simple.
Crypto's transparency was never a principle; it was an engineering constraint, and the largest pools of capital on earth, treasuries, institutions, funds, sovereigns, have been waiting fifteen years for someone to remove it without removing the law. Every previous attempt broke on compliance, composability, or scale. Starknet is the first production system to clear all three at once, and it already shipped the foundation:
One privacy pool for all assets,
A $0.12 cost per private transaction, whatever the amount,
Accessible in a few clicks and a few seconds, at the wallet level,
With deep DeFi integrations from the Starknet ecosystem, and soon from other ecosystems as well,
A compliance path built in,
And a privacy SDK and wallet API, allowing anyone to permissionlessly integrate it into their apps.
Dark pools took US equities from zero to half of all volume, and the market grew the whole way. The same layer is being built for crypto right now, on one chain, in public, at a valuation that assumes it does not exist yet. Starknet is flipping the blockchain’s default state back: from transparent by default, to private by choice.
Today the pool holds half a million dollars, and Starknet is valued at roughly $290M FDV.
See you in a couple of years.
None of the content of this newsletter is financial advice. Always do your own research.
Thank you for reading. If you enjoy my content, subscribe so you don’t miss future articles, it’s completely free!

















