Written by: Mario Chow, IOSG
Public chains lay every transaction bare. This isn’t an issue before real asset balance sheets enter the scene. There are three paths to address this: building a private network, like Zcash, Monero, or Canton; adding privacy features to Ethereum, starting with Tornado Cash, then Railgun, and now Zama; or simply not disclosing data—again, Canton.
Each option trades off concealment for functionality. No one has created something that can both hide everything and operate everything.
The demand is real and substantiated. JPMorgan validated that institutional finance can operate in crypto by 2024, launching its deposit tokens on Canton in 2026. A swap affected by a sandwich attack could incur a loss of 0.3% to 0.8%. Institutional spot OTC trading volume increased by 109% in a year, while the top twenty exchanges only grew by 9%; 40% of institutions have moved more than half of their trades off-screen.
However, privacy does not equate to an upgrade in security. It can reduce the probability of being targeted, but once you are, it offers little help, and recovering from incidents becomes even harder. It also inadvertently concealed a vulnerability in Zcash that allowed for the creation of coins out of thin air, which remained hidden for four years.
The money is in the assets, not in the services. Privacy tokens hold about $25 billion. All protocols in this sector collectively earn about $6 million in fees annually; Monero and Zcash have made a total of $3 million in their history; Zama has moved $595 million across its borders, estimating its earnings to be between $840 and $84,000—because it charges by Bitcoin, not by basis points.
The conclusion remains bullish. Demand has been validated, technology is no longer a bottleneck, and regulations starting in July 2027 will push the market towards auditable privacy. What’s missing is just a price, which is the easiest problem to solve in this entire discussion. Therefore, this transaction should be placed on the party that dares to charge in the end.
Blockchain is a shared ledger that records who owns what. Every machine in the network holds an identical copy, and every payment is recorded in all copies. There’s no arbiter determining what is true; anyone can verify the ledger themselves. Strangers can use it without mutual trust, relying on this very fact.
The cost is that this ledger is open to everyone. Your account is called an address, which is essentially a long string of letters and numbers. Anyone can paste the address into a block explorer, a free website, and read its entire history: what it holds, who it has paid, how much, and at what minute. No login, no permission, and no way to opt-out.
▲ A block explorer. Every address, every amount, readable by anyone, forever.
For ten years, this wasn’t much of a concern: there wasn’t much money on-chain, and users were pseudonymous. However, once real asset balance sheets enter the scene, this issue becomes harmful.
Consider what a public ledger actually reveals. A company paying salaries on-chain effectively discloses its payroll. A fund holding open positions reveals its positions, entry prices, and liquidation prices. A business paying suppliers discloses its supplier list and payment terms. And any individual holding a large balance reveals a number significant enough to make them a target for theft.
Two factors have turned this from a theoretical issue into an urgent one. First, stablecoins, which are designed to peg to one dollar and are backed by real dollars in banks, now have significant trading volumes. Second, tokenized real-world assets, such as bonds, funds, and real estate, are entering the scene alongside regulatory bodies. These users cannot accept "everyone can see the amounts" as a condition for entry.
Thus, the problem is easy to articulate but hard to solve: how to hide numbers while allowing thousands of strangers to verify that no one is cheating?
Privacy has always had its rhetoric. Surveillance is bad, freedom is good, and so on. But rhetoric doesn’t sustain products. What changed from 2025 to 2026 was that specific individuals began to lose specific amounts of money due to leaks from public ledgers, and they came out looking to buy solutions.
It’s not about who dislikes being monitored, but rather about who is repeatedly forced to pay due to public ledgers, and this money is exchanged for a private ledger.
▲ Who pays for privacy on chain, plotted by how on-chain the loss is against whether anyone is paying to stop it.
Traders: Losing money due to their own order flow being front-run, losses can be calculated in basis points
Your trade sits in a public queue before it is executed, where bots read it, buy ahead of you, and then sell it back to you. This is known as a sandwich attack. In the year leading up to October 2025, approximately 95,000 such attacks occurred on Ethereum, siphoning off around $60 million, with affected swaps losing 0.3% to 0.8%.
Here, the buyers are professional players, and losses can be calculated in basis points. Therefore, privacy in this scenario is sold as execution quality, not belief.
Public positions on perpetual contract platforms: Exposure is continuous
Holding positions makes this worse than a sandwich attack because the exposure is ongoing. Every position on perpetual contract exchanges is public, including liquidation prices, and anyone can push prices towards them. Just Hyperliquid alone had a monthly trading volume of around $432 billion in April 2026.
The platform's response is commercial, not ideological. Aster launched hidden orders, Paradex and Hibachi sell position privacy, and Zama introduced Confidential RFQ into private testing in July 2026, which will be discussed in Section 6.
Wallets tagged and forced to sell: Strongest demand, least discussion
A fund's unlocked shares are held in a specific wallet, and Arkham and Nansen have already tagged it with real names; the unlock date is publicly accessible. When the money moves, the market jumps ahead of it, and it happens again next quarter.
This revenue already exists but has flowed elsewhere. By the end of 2025, institutional spot OTC trading volume grew by 109%, while the top twenty exchanges only grew by 9%; 40% of institutions listed OTC as their preferred execution venue, with more than half of trades occurring off-screen. A market that can be serviced with just a phone call emerged—because public venues leak.
Strategies that can be copied: Almost no one pays for this
Copy trading tools can replicate a profitable address within a few blocks, meaning that a treasury manager's rebalancing decisions do not gradually diminish over weeks but die at the moment of execution. This isn’t about evading the government; it’s about evading the twelve other peers watching the same panel. Almost no one pays to prevent this, which is precisely what makes this quadrant interesting.
Regulated ledgers moved onto public chains: Demand is real, but it’s taken by permissioned tracks
Over $30 billion in tokenized real-world assets are stuck on public chains, while banks cannot disclose their holdings in real-time. So do banks want this? One case provides answers in both directions.
In November 2024, JPMorgan's blockchain division ran Project EPIC in its sandbox, based on Zama's fhEVM, demonstrating crypto-state fund subscriptions, blind auctions, and direct settlements in crypto values, designed so that even JPMorgan itself could not see the details. But that was just a sandbox; Zama was merely one of a few suppliers. By January 2026, when JPMorgan needed to issue deposit tokens, it went to Canton, a permissioned network.
Thus, institutional demand is real and substantiated, but the path that takes it is through permissioned tracks, not public chain cryptography.
Each project in this sector is built on one or two of these four ideas. The real distinguishing question is simple: where is the secret kept?
▲ The four primitives, sorted by where the secret actually lives.
The cost used to be speed, which is also the fastest part of this article to become outdated. For several years, a fair criticism of FHE was that it could only handle about twenty transactions per second, while ordinary chains could handle thousands. This gap has largely been closed, even faster than those working on it expected.
None of these can fully prevail. Real products are combinations of two: sealed chips for speed, plus a zero-knowledge receipt to prove the chip hasn’t been tampered with; or using FHE to store hidden states and then verifying inputs with zero-knowledge proofs.
There’s also a fifth option, which is to bypass cryptography altogether: only send data to those authorized to see it. This is Canton, which is also why banks favor it.
The earliest attempts were designed around "hiding" to create an entire network, rather than patching an existing one. Two coins lead the way in this regard, but their bets are completely opposite. The third case is designed for banks, not individuals, but belongs to the same family.
Zcash: Privacy is a switch, and that has been its soft spot for ten years
【Summary (plain text, may be empty)】:
Zcash is its own chain, essentially a Bitcoin-like digital cash with a privacy mode added. It has two types of addresses: transparent addresses that are exactly like Bitcoin, revealing everything; and shielded addresses that hide the sender, receiver, and amount. Moving money into the private side is called shielding, while moving it out is called deshielding.
The hiding is done by zk-SNARK, a compact form of zero-knowledge proof. When you spend shielded ZEC, your wallet generates a very short proof that shows the payment is valid and that no coin has been spent twice. Machines maintaining the network verify this proof and accept it, all while not knowing who paid whom or how much.
A design choice defines everything that follows: privacy is optional and can be chosen on a per-transaction basis. This sounds friendly, but it is also a weakness because hiding relies on having many people. If you are the only one in the room wearing a mask, it’s as if you aren’t wearing one at all. For much of Zcash's life, most ZEC has remained in the transparent pool, with the private group being quite sparse.
Most people think of Zcash as one thing, but it is actually four pools. Understanding who is who can only be deciphered in Section 8 regarding the 2026 vulnerability. The usual summary is: Sprout proved that private currency is feasible, Sapling made it usable, and Orchard eliminated reliance on trusted setup.
▲ Zcash's shielded pools over ten years, with the shielded share below and the incidents marked.
One more thing worth knowing about Zcash is the reason for holding it rather than using it: shielded ZEC carries no history. Once a coin has passed through the pool, it no longer carries any trace, and every unit can be exchanged with other units. This feature is called fungibility, which is also what compliance departments truly worry about on transparent chains—on a transparent chain, you might receive a coin that was used for criminal activity by a previous owner, inheriting the trouble along with it.
Monero: Privacy is Default On, There’s No Switch
Monero is also its own chain, choosing the exact opposite: there is no public mode available. Every payment is private to everyone, so there is no need for a small private pool to join—the entire chain is that group of people.
Until recently, it relied on three tools instead of zk-SNARK. Ring signatures mix real coins with decoys to hide the sender, and observers see sixteen possible sources without knowing which one is real. Stealth addresses generate a brand new one-time address for each payment, hiding the receiver. RingCT hides the amount.
▲ How Monero hides the sender, the receiver and the amount.
In early 2026, Monero launched a significant upgrade FCMP++, replacing ring signatures with zero-knowledge membership proofs. The practical effect is that the group of people you hide among has expanded from sixteen decoys to every payment ever made on this chain, over 150 million transactions.
▲ Monero's anonymity set after FCMP++.
Canton: Nothing is Hidden Because Nothing is Shared
The third member of this family is not a coin, and thus is often overlooked in privacy research. However, the largest institutional decision of 2026 fell here, and missing it would be a mistake.
Zcash and Monero accept the premise that "the ledger must be broadcast to everyone," and then use cryptography to hide the content. Canton directly rejects this premise. It does not have a shared ledger that everyone must verify. Each participant only receives their portion of the transaction as a party involved, enforced at the contract level by a language called Daml. If you are not involved, you will never receive this data and will never know that the transaction occurred. A component called Global Synchronizer is responsible for ordering and confirming validity while not seeing the content.
▲ The same three payments on a public chain and on Canton, showing who receives which rows.
Thus, secrecy is protected by "never sending out"; those authorized to see it read it in plaintext. Note that this setup does not use any of the four tools from Section 3: no zero-knowledge proofs, no FHE, and despite long-standing confusion from the outside, no MPC. Daml claims to be a language for multi-party applications, which sounds like multi-party secure computation, but means something entirely different. Integrity relies on cryptography: each participant receives a hash, replacing those branches they cannot read. Confidentiality is purely a matter of "who was sent what."
The reversal of the verification process is interesting. On Ethereum, each validator re-executes every transaction, so everyone must see everything. On Canton, the parties involved in the transaction verify themselves, each side only reruns their branches and then votes. An arbitrator counts the votes according to the confirmation strategy, only seeing the hash. Thus, there is no global re-execution to catch collusion; the comfort is that only parties already inside your contract can harm you.
JPMorgan chose it for JPM Coin, announced in January 2026 and phased in throughout the year, for practical reasons rather than ideology. Privacy is default on, without worrying about whether the crowd is large enough. There is no shared pool, and the freezing that occurs in Circle in Section 8 cannot happen here. Each participant is a legally identified entity, which is a hard requirement for regulated banks, not a compromise. Settlements between applications are atomic. Peers are already on it, including Goldman Sachs and BNY Mellon.
What it sacrifices is equally tangible. There is no permissionless composability, and liquidity is walled off. Privacy is built on access control rather than mathematics, so trading partners with the right to view can see everything, and compromised participant nodes will leak. It is not censorship-resistant—this is a feature for banks, but the original intent was to eliminate qualifications. Even if everything is normal, three things will still leak: the change amount (depending on how the token model is written), who is hosting your participant node, and what the sorter sees in terms of "who is messaging whom."
Canton Coin (code CC) will launch with the Global Synchronizer mainnet in July 2024, used to pay for application and infrastructure fees, rewarding operators running the network, with no pre-mining or pre-sale, and about 100 billion coins can be minted in the first ten years. As of late July 2026, the price was around $0.12, with a market cap close to $4.8 billion, already a top twenty asset.
This number is worth pausing at; it redefines the entire track. The permissioned network built for banks has a token value approximately thirty-five times that of Zama.
A Side-by-Side Comparison of the Three
Three lines can support this argument. Both coins can hide your amount from everyone, but neither can run even one application. Canton can run applications and hide the amount from everyone except trading partners. Moreover, Canton does not need a crowd to hide because there is no shared ledger to hide into, which also circumvents the weakness that has plagued Zcash for a decade.
No one has yet achieved the combination of both. At the end of Section 6, there is a diagram showing how consistent this trade-off is.
Where privacy coins fall short: they can succeed, but live on an island.
Privacy chains do their job well, but they live on an island.
First, let’s talk about real friction. They are independent chains with independent tokens; assets must be moved in and out. Meanwhile, the dollars people actually trade and the lending protocols in real use are all on the other side—on Ethereum and Solana.
However, this island is no longer so isolated. There is a second solution that has nothing to do with "moving privacy to Ethereum": leaving the privacy chain in place but making it accessible.
▲ Buying shielded ZEC with and without a centralized exchange in the path.
NEAR Intents is doing just that and is a major reason for Zcash's revival in 2025. You declare what you want, such as exchanging Bitcoin for ZEC, and a network of competing solvers calculates how to complete the cross-chain transaction, requiring only one signature. Zcash’s own wallet has integrated this setup, allowing users to buy shielded ZEC from another chain or sell it, all without touching a centralized exchange or exposing their Zcash address.
As of March 2026, the cumulative trading volume of ZEC through NEAR Intents reached $1.5 billion, with $600 million coming from the wallet's built-in exchange product (launched in October 2025).
The issue of privacy is real, but it exists on a spectrum rather than as a binary choice, with two competing answers: moving privacy to where the money already is, which is the focus of the remainder of this article; or keeping privacy in place and fixing the surrounding infrastructure, which is cheaper and already in operation.
Then there’s the larger limitation: these chains only deal with money. There are no smart contracts (except for Canton), and smart contracts are those little programs that allow a chain to do more than just transfer funds—like lending, borrowing, paying interest, or running a market. You can hold private cash and send private cash, but you cannot earn yield on it, use it as collateral, or connect it to anything that already exists.
Privacy itself has to pay taxes, with Zcash and Monero each contributing half. Zcash made privacy optional, resulting in a user base that is only as large as "those willing to go through the hassle." Monero made privacy mandatory, creating the strongest user base in the industry but also getting itself delisted from regulated exchanges. Starting in 2027, European regulations will tighten further, returning to this point in Section 9.
Another approach is simply not to move. Keep the money and applications on Ethereum and add a layer of confidentiality. No new chains, no jumping between chains, no new wallets.
Three generations have tried this, with each generation existing because the previous one failed to achieve something. Reading in order, the sequence itself is the argument.
First Generation: Tornado Cash, and how "mixers" became a dirty word
Think of it as a currency exchange window. You deposit a fixed amount (0.1, 1, 10, or 100 ETH) into a pool and receive a secret receipt. You then withdraw to a brand new address, using a zero-knowledge proof to show you own an unspent deposit from the pool, but without revealing which one. The link between the old address and the new address is severed. Your user base consists of all others who have deposited the same amount.
That’s all there is to the product. Money sitting in it is inert, earning no interest and doing nothing, and the fixed denomination means you cannot transfer arbitrary amounts. It severs a link but does not provide you with a private balance.
The outcome is legal, not technical. OFAC sanctioned these contracts in August 2022. In November 2024, the Fifth Circuit Court of Appeals ruled that OFAC overstepped its authority, arguing that an immutable contract controlled by no one is not the property of anyone, and the contract was removed from the sanctions list in March 2025. Then in August 2025, developer Roman Storm was convicted for conspiring to operate an unlicensed money transmission business, with the jury deadlocked on money laundering and sanctions charges, and the prosecution seeking a retrial.
Code won, but developers did not. This outcome explains something you will notice elsewhere in this section: both successors deliberately emphasize that they are not mixers. This statement is about legal work, not technical work.
Tornado also brought two characteristics into everything that followed. Your user base consists only of those who have deposited the same amount, so an unusually sized or timed withdrawal will self-anonymize, which is the same kind of behavioral failure that undermined Zcash users. Additionally, honest users have no way to prove their honesty. Clean money coming out of the pool looks the same as stolen money, and exchanges can only treat everything coming from that address as contaminated.
What Tornado cannot do is the entire reason for the existence of the next tier. It hides your history, not your holdings. You can obscure where the money comes from, but you cannot hold a private balance because the money sitting in the pool does nothing.
Second Generation: Railgun, a shielded pool you can actually use
Tornado is a currency exchange window; Railgun is a private bank account on Ethereum that can make external payments. You shield tokens into its pool on Ethereum (and also Arbitrum, Polygon, and BSC), with the pool internally hiding the sender, receiver, and amount using zero-knowledge proofs.
The distinction from Tornado is worth noting because people often confuse the two. Tornado only accepts fixed denominations, one-time, returning the same denomination at a new address. Railgun accepts any amount of any supported token, maintaining a continuous private balance, allowing you to pay another Railgun user internally without first unshielding, and enabling you to interact with things like Uniswap without prior unshielding. Tornado’s user base consists of other depositors of the same denomination, while Railgun’s user base is the entire pool on that chain.
The clearest understanding is that Railgun is a reconstruction of Zcash’s shielded pool using smart contracts, built on a chain that already has dollars and applications. This makes its privacy stronger than Zama’s because it hides the transaction graph, not just the numbers on the graph.
However, what "reaching into DeFi" means has an important limitation. When Railgun helps you swap on Uniswap, it will unshield the amount, execute the swap in plaintext on the public chain, and then re-shield the output, all in one atomic transaction. So the transaction itself is public, and what is hidden is "this is you." Railgun anonymizes the actor, not the value, which means it does not protect you from sandwiching: bots see the pending swap and its size, not caring who is behind it.
It also has a more elegant compliance answer, directly addressing Tornado’s fatal flaw. Private Proofs of Innocence allow users to generate a zero-knowledge proof that their funds do not come from known illegal lists while not revealing where they actually come from, at the cost of a one-hour delay. So you can be both private and prove you are not a thief—something Tornado never allowed.
The practical use case is through a wallet called Railway: shield, transact, unshield when you want. Vitalik Buterin publicly used it in 2023 and has spoken in favor of compliance solutions of roughly this shape, which only enhances the credibility of this route.
The next section should cool down the rest of this section. Railgun has shielded between $90 million and $110 million across four chains, with a cumulative shielded transaction volume of about $5.16 billion, and historical cumulative protocol revenue of $13 million, of which $4.6 million came from the past year. Zama holds $39.6 million, with a transaction volume of $452 million in the first half of 2026. The metrics are not entirely comparable—Railgun launched in 2021, while Zama’s mainnet will not go live until December 2025—but the direction is clear. In all available metrics, zero-knowledge incumbents are larger than FHE newcomers, and they are already making money.
There are two weaknesses worth mentioning, both of which are rarely discussed. The pool is the user base, so Railgun inherits Zcash’s structural issues entirely: at a shielded scale of about $100 million, the user base is respectable but not deep, and as it becomes sparse, privacy weakens. Worse, spreading across four chains splits that user base into four smaller ones, exactly opposite to what anonymity sets desire. Second, the fees flow into the Railgun DAO treasury, not directly to the tokens, so holding RAIL and holding the economic benefits of this protocol are two different transactions.
So why is there a third generation? Because of an easily overlooked limitation: Railgun can hide your holdings, but two people’s holdings can never meet. Zero-knowledge proofs are about the facts of the data you already hold; they cannot compute on someone else’s hidden state. There are no blind auctions, no encrypted order books, and no treasury that can do arithmetic on deposits it cannot read. This gap is the reason for everything that follows.
Third Generation: Zama, and wrapping your already held dollars
You take regular USDC and wrap it into cUSDC—same dollar, but the balance is encrypted. ERC-20 is the standard formula followed by every ordinary token on Ethereum, while ERC-7984 is the same formula, just with the balance hidden. When wrapping, you pay a small fee and can unwrap back to regular USDC at any time.
▲ Wrapping USDC into cUSDC
What does it hide, and what does it not hide? Two things are encrypted: the amount of each transfer and your real-time balance. The balance is the larger prize—on regular USDC, anyone can permanently see you hold $4.2 million; on cUSDC, that number is forever unreadable.
What remains public are your address, the counterparty’s address, and the time. The contract must know whose balance to update, so the address has to be in plaintext. The transaction graph remains fully intact. Zama hides the numbers written on the side, not the side itself.
The actual consequences are worth stating plainly because this is the easiest place to misread optimistically. Paying thirty employees with cUSDC, everyone can still see you paid those thirty addresses and when you paid them. You hide the salary, not the employment. The same goes for suppliers: you hide the payment terms, not the supplier list. The sensitive thing is a quantity; it protects you; the sensitive thing is a relationship; it has little effect.
There is one exception, which is structural rather than cryptographic. When a contract sits in between (the treasury and the price inquiry are like this), what shows on-chain is that you are talking to the contract, not to the counterparty. Depositing into a confidential treasury will not reveal who is borrowing your money; paying someone directly will reveal who you paid.
Doing arithmetic without unlocking
Zama adds a layer of privacy to Ethereum and other compatible chains, with Solana in the planning stages. The foundation of this is the FHE concept discussed in Section 3. The network needs to confirm that you have enough funds before updating two balances, without revealing any numbers throughout the process. FHE allows it to perform addition and subtraction directly on locked boxes, producing a locked answer.
This is precisely what privacy coins cannot achieve. Zero-knowledge proofs can prove that your payment is valid, but they cannot perform new arithmetic on hidden balances of others. FHE can.
▲ How FHE computes on locked boxes
No One Holds the Master Key
The most immediate concern is: a company somewhere holds a key that can unlock everything. Zama's answer is to ensure that such a complete key does not exist in any one place.
Eighteen operators run this system, divided into two roles. Five co-processors perform encrypted arithmetic. Thirteen key holders (collectively referred to as KMS) each hold only a fragment of the key, and before anything can be decrypted, at least nine out of the thirteen must cooperate. A gateway is responsible for assigning tasks and verifying consensus among operators. ZAMA tokens are used to pay for verification inputs and decryption fees, and operators must also stake them as collateral, which will be forfeited in case of misconduct.
▲ Who runs Zama
This is a hypothesis, not an incident. The statement "no one holds the master key" is based on two conditions: that no more than one-third of the thirteen key-holding nodes are malicious; and that the AWS Nitro enclave where these nodes operate is indeed secure. The second condition pertains to hardware trust.
An Example in Operation: Private Yield on Morpho
The first product to utilize this entire setup is a savings vault. The vault is essentially a pool: it collects deposits, lends out money, and pays interest to depositors.
You shield your USDC into cUSDC for deposit. It does not go directly in—doing so would expose your amount immediately—but instead queues with others’ deposits for about a day to form a batch. When this batch closes, the network only decrypts the total amount of this batch, while individual deposits remain undisclosed, and then invests this aggregated amount into the Prime USDC vault on Morpho's Steakhouse. That vault is standard, public, and audited, with an interest rate of about 4%, plus a launch bonus. You receive a share of it in encrypted form, along with your earnings.
This is not a mixer. Nothing is mixed, rerouted, or laundered through intermediaries. The money goes into a public vault that anyone can check, and the only fact that is hidden is how much each person contributed. The trade-off is that your privacy can only be as good as that of your batch, so the system must wait until there are enough peers before proceeding.
▲ Private yield on Morpho
The Second Product in Operation: Confidential Large Transactions
The vault hides how much you have deposited. The next product hides how much you have traded, which is commercially more interesting.
First, let’s look at the problem it addresses; this scale estimation is the strongest demand argument in this article. Large transactions do not occur on public chains; they happen on OTC desks, and the trend is verifiable: by the end of 2025, institutional spot OTC trading volume is expected to grow by 109%, while the top twenty exchanges only grow by 9%, with 40% of institutions listing OTC as their preferred venue. The analogy with traditional markets is fair, not promotional: about 59% of trading volume in the US stock market is completed outside public exchanges, and dark pools set a record of 40.3% in Q1 2026, with the sole purpose of executing large orders without revealing their hand.
Thus, the insight behind this product is correct. We spent ten years building programmable, verifiable trading infrastructure, yet institutions still negotiate large trades in Telegram groups because that is the only way to avoid being targeted.
Next, let’s walk through the entire mechanism using a real trading pair with numbers. Suppose you have 1,000,000 ZAMA, shielded as cZAMA, and want to exchange it for USD. The mid-price is set at $0.25, meaning you want to sell approximately $250,000, while the total shielded circulation of this token is only $6 million. These numbers are illustrative integers, not actual transactions; the ratio is the key point: on public exchanges, such a transaction relative to that circulation is a gift for bots.
▲ A 1,000,000 cZAMA sale, with the dealer quotes and a table of who can read which field.
The little trick in the first step is worth pausing to look at; it is the most cleverly designed part of the entire setup and costs nothing. You send out two transfers instead of one: the cZAMA you actually want to sell, plus a zero-amount cUSDC leg. Both amounts are encrypted, and observers only see two legs of opposite directions and unknown sizes, unable to distinguish whether this is a sale or a purchase. The principle of hiding "which asset you are trading" is the same, with official commitments to be included in future versions.
Before getting too excited, read the right column of that chart, as that is where promotion and mechanism diverge. Public frontrunning bots indeed cannot see your order, so the sandwich disappears. But market makers on the whitelist will decrypt your intent and can see your size. They cannot see your direction, which is the clever part, and they also cannot see each other’s quotes. The winning market maker will be informed of the direction to complete the settlement. Thus, ultimately, one professional market maker knows your entire transaction, while a few know your size in real-time. This is a trust shape of an OTC desk, not a uniform venue.
The third step is the one that justifies the entire technical choice. Comparing two encrypted quotes without decrypting either party and selecting the higher one is precisely what FHE can do, which zero-knowledge proofs cannot.
Progress needs to be precise. It is an invite-only private test, with three trading pairs opened: cUSDT to cUSDC, cZAMA to cUSDC, and cSteakcUSDC to cUSDC. Public launch is planned for September 2026, followed by multi-chain support. Currently, there is no meaningful trading volume.
The third trading pair is the commercially important one. It allows managers to enter and exit a yield-generating vault position without needing to decrypt or wait for redemption periods. The rotation between strategies is where many allocators truly make money, while leaking rotations is how they lose money.
What’s Inside and What It Tells You
Zama publishes the composition of shielded value quarterly, and this breakdown is much more informative than the headline numbers.
▲ Zama's shielded value by asset class to 30 June 2026, with volume alongside it.
Four things stand out, with only one being pleasant.
The vault is the single largest category, at $18.8 million, surpassing stablecoins at $14.1 million. Thus, the first real emerging demand is not for private payments, but for those wanting yield without publicly disclosing their position sizes.
Subtracting Zama's own tokens from the token category leaves almost nothing. Of the $6.8 million, $6 million is cZAMA. A protocol shielding its own token does not prove that there is a market demand for shielded tokens.
Real-world assets total $52,200, all tokenized gold. Compare this number with how many times the phrase "confidential RWA is an institutional opportunity" has been said, including in Zama's own launch materials.
The truly important number is right next to the total. The shielded scale of $39.6 million has seen a trading volume of $452.3 million over six months, with money turning over about eleven times, not just sitting idle. This is commercially significant because a confidential dollar only incurs costs when it is in motion.
Five weeks later, the protocol's own dashboard made this argument even stronger, adding three things not visible in the June snapshot. As of August 3, 2026, the cumulative shielded value is $320.8 million, with a cumulative unshielded value of $274.2 million, meaning about $595 million has crossed the boundary, while net holdings remain around $46 million.
Confidential dollars are not stagnant; they are moving through. cUSDT has shielded $130.8 million and unshielded $122.8 million, leaving $7.9 million. cUSDC has shielded $69.7 million and unshielded $65.1 million, leaving $4.7 million. Approximately 94% of every stablecoin dollar that once came in has already left. This is a corridor, not a vault. For protocols that profit from money movement, this shape is correct; for anything that profits from balances, this shape is wrong.
The money in the vault consists of four wallets. cSteakcUSDC has four independent shielded wallets, net holding $20.2 million, accounting for about 43% of the total net shielded value within the protocol, corresponding to a Morpho vault holding $28.2 million. The largest and commercially most interesting category in this section is not a market, but four institutions. Please keep this in mind when reading any growth rates here—one redemption can topple it all.
The line of real-world assets has truly begun. In June, it was $52,200 for tokenized gold. By August, there was $5.1 million in tokenized pounds in cTGBP, with another $5.1 million in its packaged version, and gold was at $60,300. Ten million dollars is still small, but it's two orders of magnitude higher than a negligible figure, and it's the first real evidence of the most talked-about phrase in this track.
A correction needs to be made regarding the scale; a number circulating outside has greatly beautified this matter. Zama has deployed 549 contracts on the mainnet. Most reports cite 27,662 confidential contracts, which include all public testnets dating back to July 2025, of which about 98% are not in a production environment. Now there’s also a cBRON token, twenty-one wallets, and $1 million.
How This Circumvents the Island Problem
Because it sits on Ethereum, those private dollars are the same kind of dollars in other people's hands, able to work in applications that already have users. The privacy here is still programmable—contracts can still execute rules on hidden data.
This also leaves room for compliance: auditors or regulators can be authorized to view specific records, and freezing of underlying assets will transmit to the packaging layer. In May 2026, a court order did just that, freezing the entire cUSDC pool for three days. Section 8 discusses what happened at that time.
This Ladder and the Cost of Each Step
Reading through three generations, a pattern emerges that no generation has promoted.
Tornado hides your history. Railgun hides your holdings. Zama hides those holdings that can still interact. The existence of each level is due to a specific thing that the next level cannot do.
But the cost has been moving in the opposite direction. Tornado hides the most but can do nothing with that money. Railgun hides the sender, receiver, and amount. Zama only hides the amount, while the transaction graph is completely public. Each generation buys functionality with concealment.
There’s also a second axis moving in the same direction, tightening this story. Tornado does not provide honest users with any way to self-verify, so exchanges treat the entire pool as contaminated. Railgun precisely addresses this with Private Proofs of Innocence. Zama goes a step further, incorporating view keys and inheritable freezes, which regulators can truly utilize. Thus, the trend among the three is not that privacy has improved, but that privacy is more usable and readable, with bills emerging from concealment.
▲ All six designs plotted by how much they conceal against what the money can do while concealed.
The blank space in the upper right corner is the interesting part. "Hiding everything while being able to operate everything" is the product that no one owns, and Zama is the latest attempt to push that line upward. According to every number in this article, it is also the smallest one.
Who Else is Climbing on the Same Step
Zama is the one with a mainnet, so this section has focused on it. It has been running on Ethereum since December 30, 2025, completing its first confidential stablecoin transfer that day, with named companies using it in a production environment. The token standard ERC-7984 has been implemented as an audited library by OpenZeppelin, along with an on-chain registry mapping ordinary ERC-20s to confidential packaged versions. This detail is worth more than any score: writing a confidential token has become a derivative of an audited OpenZeppelin contract, thus shedding the niche technical skin.
Zama has won this round, but it’s worth noting which round it won: it went live first. This is a real achievement, and this section gives it the recognition it deserves. However, going live first speaks to timing, not design limits, and the route it validates has more than one implementation. Fhenix, Inco, and Mind Network are all doing confidential execution on the same cryptographic foundation, at an earlier stage, and none have a mainnet year available for judgment yet.
This leads to two easily overlooked points. Zama going live is good news for all of them because the challenges in this category have never been about whether the math works, but whether anyone is willing to pay for its use. Now this question hangs on customers, not predictions. The other point is that for such a young cryptographic primitive, having a single implementation is a systemic risk, not a moat. The Orchard vulnerability in Section 8 lay dormant in a codebase for four years without being discovered. Only with multiple independent implementations can such things be uncovered, so the second and third names here carry a value that is invisible in "live product comparisons."
Fhenix raised $22 million, led by Guy Itzhaki, who was responsible for homomorphic encryption at Intel, backed by Multicoin and Collider. It uses fully homomorphic encryption, from the same family as Zama, rather than different cryptography. Multi-party secure computation appears in both (Zama's thirteen key holders and Fhenix's threshold service network), but only as a mechanism for splitting decryption keys. The primitive responsible for hiding is the same.
It was initially an FHE Layer 2 but later abandoned that. The scores released with the ACM CCS 2025 paper support modular design, turning that Layer 2 into CoFHE, an off-chain co-processor callable by any EVM chain, with EigenLayer staking providing economic security underneath. It runs on Ethereum Sepolia, Base Sepolia, and Arbitrum Sepolia, with its documentation stating that the production mainnet is not yet available.
It has a token standard FHERC-20 and a working demo: shielding any ERC-20, private payments, sealed bidding auctions, confidential stablecoins, on-chain inquiries, delegating reading permissions of encrypted balances to a designated party, an anti-front-running Uniswap v4 hook, plus two consumer-grade gadgets. Canopy integration is scheduled for Q4 2026, with Offchain Labs investing through Tandem to bring this technology into Arbitrum.
The truly important seven lines, viewed side by side.
Most of that gap is calendar time, not capability, but there are two lines in the table that are not. Zama and Fhenix have already converged architecturally, so "no new chains, no jumping chain bridges" is not a differentiator; both can allow Solidity developers to use about one line of code plus a cryptographic type. What truly separates them is which bottleneck each is attacking. The latency users feel in homomorphic systems is due to decryption round trips, not arithmetic, and that is precisely what Fhenix is attacking: 64,319 operations per second, with a latency of 8.48 milliseconds, published in ACM CCS 2025 and awarded outstanding paper. Zama's headline number is one thousand transactions per second on H100, self-reported, and not yet activated. Laboratory numbers degrade in production; the two are not even measuring the same thing, but on the only axis that can be directly compared, the peer-reviewed numbers belong to the one that has not yet gone live.
The demand side is no longer hypothetical, which is a more interesting development. From July 2 to late July 2026, Fhenix announced an acquisition and three integrations, and their shapes are worth reading. It acquired Sunscreen, one of the earliest FHE teams in the industry, bringing a set of compiler technology and a BFV research background, working in parallel with its own TFHE efforts, while Sunscreen founder Ravital Solomon joined and leads the research. Sedona, a self-custodied trading new bank, is migrating to Arbitrum and replacing its trusted execution environment with CoFHE, covering balances, positions, and the spending limits it sets for AI agents. Nomyx, which issues compliant RWA, uses it to achieve confidential positions with selective disclosure: private to the market, verifiable to regulators. Canopy, in turn, integrates encrypted computation by default into its application framework. Coupled with earlier Monaco research collaboration, the mainnet target is set for October, going live on Ethereum and Arbitrum.
Three things in that list are more important than quantity. The Sedona deal is a customer migrating from TEE to FHE, which is the only evidence so far that this security upgrade is worth the cost of delay for a live product. Nomyx points to the argument in Section 2 about regulated ledgers—what is needed there is not concealment, but disclosure according to the holder's wishes. The spending limit for agents is a use case that did not exist when all this was designed; the opponent you are defending against is your own deployed software. None of these are revenues yet; October is a target, not a fact. But this is a pipeline with named counterparties, more than a typical pre-mainnet agreement has.
So the focus should extend beyond the first mainnet. The issues in this category have never been whether the math works, but whether anyone will pay, and Zama is now answering it with customers rather than predictions, which helps every implementation of the same idea. For such a young primitive, a single implementation is also a risk, not a moat; Section 8 will soon show how costly a vulnerability that lay dormant in a codebase for four years can be. At the same time, the first layer that went live is a neutral layer, and the neutral layer receives almost no payment for what it delivers, so being ahead on it does not equate to staying in the place where the money ultimately belongs. This is why the second and third attempts are worth watching: whether confidentiality is consumed through the shared primitive or through Fhenix's ongoing bets, backed by Offchain Labs' Layer 2 and consumer-grade entry points, remains undecided, and it determines where the value in this category lies.
What has been discussed above is what these designs can do. This section only talks about how much they charge for it, as the answer is small, publicly available, and is a number that is least scrutinized in this field.
The following numbers are on-chain fee data as of August 2026. The last column is the key point: in this field, receiving fees and earning revenue are not the same thing.
First, read the lines about privacy chains; they hold almost all the market value in this field and are the clearest examples. Monero has earned $1.58 million in fees throughout its history, while Zcash has earned $1.37 million since 2016, and those are payments to miners, not revenue for any company. No entity is collecting them, and there is no profit margin involved.
There is a circulating number that needs correction, as it is off by nearly three orders of magnitude. In June 2026, multiple media outlets reported Zcash's annual fees at $405 million, leading Ethereum and Solana. The actual figure for the past year is $567,000. That public number seems to have been extrapolated from a single high-activity window and coincidentally aligns with Zcash's price at the time, which is a more likely explanation. Estimating the market size based on that headline would result in a discrepancy of seven hundred times.
Tornado Cash is the most enlightening line. Its users paid $9.3 million, and the protocol received nothing; every dollar went to withdrawal relayers, with fee data clearly stating that protocol revenue is zero. The largest mixer over the past decade has created real cash flow for operators but has generated nothing for itself—when sanctions arrived, it had no profit and loss statement to defend itself, which is one reason. Railgun is the counterexample and the only real business in the table, collecting 25 basis points at both ends into its treasury. Relative to a cumulative transaction volume of $5.16 billion, $13 million translates to about nine basis points, corresponding to a nominal fee rate of fifty basis points. This gap itself is a clue: money is shielded once, transferred for free inside, and only paid when entering and exiting.
In total, the entire field's annual revenue is approximately $6 million to $7 million for all protocols, while the value of the assets parked in these protocols is about $25 billion. Two-thirds of this flow goes to the relayers of Railgun and Tornado. The few chains holding almost all the market value collectively only receive about $2 million a year.
The lower half of the remaining table features Zama, which is interesting: it does collect fees but uses a completely different billing mechanism. It does not take a percentage from anything but charges per operation, priced in dollars based on Bitcoin—validating proofs on encrypted inputs, decrypting ciphertext, and moving it across chains. Homomorphic computation itself is free, deploying an application is also free, and no permission is required.
Using its own traffic to quantify this difference, in the seven months since December 30, 2025, the protocol has processed 104,848 mainnet transactions across 549 mainnet contracts, while $320.8 million was shielded, $274.2 million was unshielded, and about $595 million crossed the boundary, with an average single shield of about $24,000.
According to Railgun's fee schedule, this flow would generate $1.49 million. According to Zama's publicly available price list, it generates between $840 and $84,000, likely falling in the lower half of that range, as rolling discounts over thirty days would push heavy users below a penny, and this flow concentrates on allowing the largest payers to receive the deepest discounts. In terms of rates: a $24,000 shield costs thirteen cents, which is one-fiftieth of a basis point, while Railgun is twenty-five basis points. Charging eighteen times to one thousand seven hundred times less, depending on where the actual number falls in the range.
To clarify, this number is derived, not disclosed. The number of transactions is published on the protocol's own dashboard. Thirteen cents is the news number at launch, and the price list in the simplified white paper sets a confidential transfer at between eighty cents and eighty cents, depending on the operation combination. Therefore, the range is more important than any single point estimate, and this argument does not require a single point estimate—every reading of the public price list lands in the same place. By the way, the exact number is knowable: every protocol fee is burned, and the cumulative burn amount at that address is the observable version of this number, which anyone can check.
Why is it so cheap
The most straightforward reading is that Zama has mispriced itself. A more likely reading is that it is buying customers first and charging later, and the evidence points to the latter rather than an oversight.
A layer that takes 25 basis points is a tax on every integrator, while Zama aims to build the privacy layer that others construct on top, not a competing venue. Pricing like cloud services is necessary to get your token standard implemented as an audited library by OpenZeppelin, a wrapper registry, integration paths with wallets and exchanges, and a payroll company willing to run payroll on you. None of these buyers will cross a fifty basis point toll to come in. Bron will not pay 25 basis points to hide a payroll, and the four wallets holding $20.2 million in that treasury will not pay to shift a position.
So this low fee rate is doing work. It is buying what is truly scarce at this stage, namely benchmark customers and a standard that others will adopt, pushing revenue to a transaction volume large enough to make a small fee worth collecting one day. Under this reading, the current fee item is a customer acquisition cost rather than a business, and the number to watch is not this year's fees but whether that billing mechanism will change.
Two things make this reading falsifiable, not just a matter of tolerance. Fees can be increased without changing the cryptography: at today's transaction volume, $5.65 per transaction could earn a million dollars a year, and calculated in basis points, it is still about ten times cheaper than Railgun. Moreover, value is accumulating somewhere during this time: up a layer, going to the operators of the venue, not the neutral rails below, which is why pricing inquiries are more important to Zama's economic model than the protocol itself.
It is easy to write about privacy technologies as if they can all run smoothly. Three incidents are worth knowing, each failing in different areas: the cryptography itself, the software surrounding it, and the laws governing both.
▲ Nine years of privacy failures, grouped by which part of the stack gave way.
Zcash: The Orchard vulnerability in June 2026 and its cost of $3 billion
Starting with the most recent incident, as it is the single most destructive value loss in this field, and it can explain a market movement that many remember but do not know the reason for.
On May 29, 2026, a security researcher named Taylor Hornby (commissioned by Shielded Labs in April) discovered a soundness defect in the circuit behind Orchard. Soundness is the property that makes a zero-knowledge proof valuable; it guarantees that you cannot create a seemingly valid proof for a false proposition. With this defect, you could. Hornby created an exploit that could mint unlimited counterfeit ZEC in a test environment without detection.
Since Orchard went live in May 2022, this defect had been lying in that circuit. For four years, after multiple professional audits, no one found it. He found it with the help of an AI model (Claude Opus 4.8) and a set of self-developed analytical tools. This is the truly new fact in this article. The audit process that repeatedly cleared this code was human, while the thing that ultimately broke through it was not.
The engineering response was swift. An emergency soft fork on June 2 disabled Orchard operations at a specified block height. A hard fork carrying the corrected circuit completed the permanent fix on June 3. There was no chain split, and no funds were lost.
Then the market took over. The public disclosure was on June 5. ZEC was actually rising before the announcement, from about $544 to $624, as a clean emergency fix is a hallmark of a rigorous engineering team. Once the substantive content landed, it dropped to about $309 within 48 hours, a nearly 50% retracement, taking away more than $3 billion in market value. Arthur Hayes publicly exited on June 4, citing that privacy assets require perfection rather than "just probably fine," which triggered forced liquidations among leveraged holders. Monero fell about 13% in sympathy, so the market interpreted this as a Zcash issue rather than a privacy issue.
Now to the part that should truly concern you, and it is not this vulnerability. Shielded Labs plainly states that cryptography alone cannot determine whether anyone exploited it before it was discovered. This is not a wordplay but a direct consequence of the design. A hidden pool conceals the ability to forge as strongly as it conceals the ability to make payments, so a four-year window of potentially undiscovered inflation cannot be closed by looking at the chain. Their remedy has been launched as Ironwood, accounting for each Orchard coin with a turnstile, making the supply independently verifiable.
For newcomers, this is the most important idea in this section. The tug-of-war between privacy and auditability occurs at the level of the currency supply itself, not just at the level of "who paid whom."
Is there really a vulnerability? Yes, and it's serious. When you spend hidden money on Zcash, you don't show the coins to the network. You give it a mathematical receipt that proves you own them and that you haven't double-spent. The vulnerability lies in that receipt verifier, which will accept certain forged receipts. This means ZEC can be printed out of thin air.
Has it ever been used to steal anything? Almost certainly not. A researcher hired specifically to look for such issues discovered it, verified it on his own test copy, and it was patched two days later. No known person has used it on the official network.
Can anyone prove that no one used it in those four years? No. On an open chain, you can count coins, and too many coins mean someone is forging. Zcash's hidden pool intentionally makes coins uncountable, because that's the product itself. So the honest answer is: there is no evidence that it has been used, and this cannot be upgraded to a proof that "it has not been used."
So there's one obvious question left: if no money is lost, why did the price drop by half? Because the entire premise of ZEC is that the math is airtight, and "probably nothing is wrong" and "airtight" are two different products.
It's worth noting that this is the second forged defect of the same kind; there was one in the proof system used when Zcash first launched in 2018. Two different proof systems, eight years apart, the same hidden pool design, and neither chain can tell you whether they have been used. This is a pattern, not bad luck. There's an additional layer of irony in this pairing: Orchard exists because trusted setups were seen as Zcash's biggest unresolved risk, and Halo 2 was adopted specifically to remove it. The pool built to avoid trust is precisely the one that was later proven to be unreliable.
Zcash: Wallet Leak, and This is a More Typical Failure
This one is smaller, but it is the most representative failure in this section.
In October 2025, investigator ZachXBT tested the jump chain exchange feature in Zcash's main wallet, Zashi, which routes through NEAR Intents. He jumped from Solana to Zcash and then withdrew ETH. An unexpected refund of 0.001598 ZEC landed in his transparent address, fully visible. NEAR Intents processed the refund through a visible Zcash address instead of the shielded pool, and the wallet reused the same transparent address each time. By matching the time and amount, you can deanonymize someone's transparent address and associate it with their shielded activity.
Nothing was stolen, and no cryptography was broken. The proof itself is fine. The integration surrounding it has issues.
It's important to be precise about the fix because it only did half the job. Now, the exchange generates a one-time transparent address for each transaction, using a standard called ZIP 320, so there is no longer a long-lived address that can accumulate history. The shielded exchange was announced on November 17, 2025, about a month after the disclosure. The second commitment, to also process the refund within the shielded pool, has not been publicly confirmed: a user directly asked in the same thread on November 20, 2025, and received no response, while the wallet's support documentation still requires users to provide a refund address without specifying whether it must be a shielded address.
Moreover, there is a residual leak that no fix can eliminate. Sending shielded funds to a one-time transparent address requires two public transactions, one to unshield and one to spend, and for any single exchange, an observer can still match the two based on time and amount. The one-time address buys you the ability to prevent anyone from linking your multiple exchanges or associating them with the rest of your wallet.
Zama: No Exploited Vulnerabilities Yet, but It's the Most Insightful Failure
There has not been an exploited protocol vulnerability, which is exactly what you would expect from something that will launch in 2026 after about seventy audit weeks. Zama faced a legal-level failure, and this is precisely what you should present to any institution considering this product.
On May 30, 2026, at 01:08 UTC, Circle blacklisted Zama's cUSDC contract on Ethereum, freezing 12,606,386 USDC. The trigger was a temporary restraining order issued the day before by a U.S. district court, in a civil lawsuit alleging that a founder of an unrelated protocol, Overnight Finance, transferred over $15.77 million from its treasury just before a holder vote to liquidate, and deposited $12.4 million of that into cUSDC on the same day.
Now, here’s the part that should make potential users stop and think. cUSDC is a pooled contract. Blacklisting it locked up every depositor, not just the disputed address, and the disputed funds happened to account for over 99% of the pool. On June 1, a judge in the Northern District of California lifted the order, releasing about $12.5 million. This is the first known case where a Circle blacklist at the contract level was overturned through litigation in a private civil dispute.
Both interpretations of this event are valid, and you need to hold both simultaneously. The compliance hook is real, and that's precisely why a regulated entity is willing to touch this product. And they are indiscriminate, which is the price you pay for "privacy that the court can still reach into." A shared pool is not just a shared crowd; it is also a shared fate.
Commonalities Among These Three Events
None of them involved someone breaking cryptography and stealing money. The Orchard defect was patched before it was public and was never used, yet it still cost holders over $3 billion, so if you hold a privacy asset, you are shorting the news of a vulnerability, not the vulnerability itself. The exchange leak is an integration detail, not a proof failure. And the freeze comes from the court, which no audit can catch.
This points to the same conclusion that the rest of this article repeatedly arrives at: the math itself has stood the test, while the software surrounding it and the laws governing it have not.
All of the above are established facts. Next comes judgment, and three debatable questions.
There are many names in this field, and people usually classify them by cryptography, which provides almost no useful information. Change it to classify them by their position in the tech stack, as that determines who the customers are and how this thing makes money.
Question 1: Is the demand real?
Yes, and this is the strongest part of the entire argument.
JPMorgan is not doing Project EPIC as a hobby. Fund subscriptions for crypto, blind pool auctions, completing silver and currency transactions on hidden values, identity verification for crypto data—its design means that banks themselves cannot read the details. Then it issued real deposit tokens on Canton. Circle is testing a private version of USDC on Aleo. Coinbase has acquired the Iron Fish team. Goldman Sachs and BNY Mellon are backing Canton. This is not a narrative; it is a pattern of capital expenditure.
On the trading side, losses are quantified, not asserted. A sandwich exchange incurs a cost of 0.3% to 0.8%. Each position on perpetual venues is public, including its liquidation price. The clearest evidence is that institutions place more than half of their trades off-screen and pay a spread for it, aiming to prevent anyone from seeing the volume.
Question 2: Does privacy really reduce risk?
It reduces the risk of being targeted. Predators pick their prey from what they can read, so hiding balances can take you off the list. This is real, and it is the strongest claim privacy can make.
It does nothing against being compromised. A stolen key clears a crypto balance just as quickly as it clears a public balance. Malware, a wrong signature, a compromised frontend: crypto protects the contents of the ledger, not your device or your judgment.
And it actively makes recovery worse. Monero's own community cannot track stolen crowdfunding wallets because Monero works as designed. Privacy is temporally asymmetric: it protects you before an attack and protects the thief after the attack.
At the protocol level, it’s worse because privacy blinds the defenders as well. On a transparent chain, a vulnerability exploit will show up in the supply within days. Orchard's reliability defect lay dormant for four years without being discovered, and the reason lies here. More privacy machines also mean a larger attack surface: thirteen key holders, five co-processors, one gateway, a set of threshold assumptions, and the AWS enclave underpinning the whole thing.
Question 3: How do you price it?
This is the question that this track avoids, and it has a real answer. The value of privacy equals the cost of a leak. There are three categories that can be calculated.
Execution slippage is the cleanest one. A sandwich exchange loses 0.3% to 0.8%, so eliminating it on a billion dollars of annual flow creates about five million dollars of value, and then you can argue how much can be captured. Railgun provides the only real data point in this track: $5.16 billion in cumulative trading volume has generated a historical cumulative revenue of $13 million, even if it captured nine basis points.
Market impact of block trades has long been priced, and this is an undervalued point. Institutions pay spreads to OTC desks to avoid revealing volume. That spread is the observable market price of privacy, and it is being paid on most institutional trades today. The reachable market for confidential trading is not conjectured; it is the existing OTC spread pool.
Follow-on alpha decay is real, and no one has published a number for it. To calculate it, you need to run performance differences between tracked and untracked addresses with similar strategies. It is worth labeling it as unmeasured rather than pretending it is known.
Now let's apply this method to the next obvious product. If Zama creates a confidential AMM, how much of the position value can be hidden? There is one constraint that will change the answer: the AMM needs to have publicly disclosed reserves to establish a price. If the pool's holdings are encrypted, price discovery breaks down. What can be hidden is the individual LP's share and the size of an order at the time of submission.
This means that the value of a confidential AMM primarily lies in order flow privacy rather than position privacy, which brings us back to the first category: basis points saved on execution. Hiding LP positions does have value, but it is smaller, mainly to prevent active strategies from being copied and to avoid immediate liquidity squeezing your fees. Thus, the valuation is based on the sandwich tax on the trading volume it attracts, multiplied by a capture rate close to Railgun's nine basis points. On an annual trading volume of one billion dollars, that translates to single-digit million dollars in protocol revenue. Real, but far from a multi-billion dollar valuation.
There is also a fourth category, and the already launched products fit right into it. Some leaks simply cannot be measured by a single transaction.
Look at what has actually appeared on the mainnet in the first seven months, as it does not align with the scale estimates predicted above. Bron's CFO paid the company's salaries with confidential USDT. Raycash launched an account shaped like Revolut, complete with IBAN, cards, and earnings, while keeping the balance private. GSR completed its first confidential institutional OTC transaction in March 2026, with two KYC'd counterparties, the amount encrypted on-chain. TokenOps conducted confidential unlocks and airdrops, Zaiffer converted regular ERC-20 tokens into confidential ones, and Zama utilized both of these in its own token. In July 2026, it integrated with Elliptic for compliance screening.
Only GSR belongs to that basis point story. The rest are companies buying "a piece of information not disclosed," and the harm they avoid does not scale with the size of the transfer carrying it. A payroll leak costs you the knowledge of your team's salaries, and your competitors knowing your burn rate. Making a vesting schedule public costs you the chance of your own unlock being front-run. These are fixed harms attached to a fact, rather than proportional losses attached to a payment.
This affects pricing, not demand. The demand in this category is broader than trading theory, and it is less suited to per-transaction pricing than any of the first three categories. And this is precisely what the fee data shows.
Several Ongoing Debates
Is privacy a chain or a feature? As of July 2026, evidence splits along an axis that people often confuse. The feature side wins on new use cases: sealed quote trading, confidential vaults, payroll. The chain side wins on price, with Monero around $12.9 billion, Zcash around $7.1 billion, while Zama is valued at $115 million to $142 million. Two different markets, two different types of buyers.
Is optional privacy a trap? It creates a small crowd, and that small crowd has weak privacy. That has been Zcash's flaw for a decade. What changes it is the least glamorous thing you can think of: not cryptography, but a wallet. Starting in February 2024, the Electric Coin Company launched Zashi, which defaults to private, with three pools behind one address, and the exchange function allows users to shield ZEC with just a few clicks. The proportion of shielded supply rose from about 5% to over twenty to nearly thirty percent, while the proportion of shielded transactions rose from about 30% to a reported peak of 59.3%. Josh Swihart, then CEO of ECC, put the causal relationship plainly: after Zashi came out, shielded pools grew exponentially. The timeline matches.
There is a hidden danger, and it is a governance issue rather than a technical one. In January 2026, the entire Zashi team collectively resigned from ECC due to governance, funding, and autonomy issues, forming the Zcash Open Development Lab, and in February 2026, renamed the wallet to Zodl. So the only software that carried the popularization of Zcash privacy is no longer built by the foundation that manages the protocol.
Does compliance-friendly privacy count as privacy? Critics say a privacy system with a toggle is a queue, not a privacy system. Supporters argue that it is the only version that institutions can legally touch, and the alternative leads to the fate of Tornado Cash. Both sides are correct. They are selling to different customers, and both types of customers exist.
Regulatory clock. The EU Anti-Money Laundering Regulation (specifically Article 79 of Regulation 2024/1624) will take effect on July 1, 2027. From that day on, crypto service providers cannot maintain anonymous accounts or handle privacy assets like XMR and ZEC, and a new regulatory body called AMLA will oversee about forty of the largest providers. Read the scope carefully: this prohibits trading venues from touching those assets. It does not stop those chains. It siphons off regulated liquidity from Europe, and the second-order effect is that it pushes the market towards auditable privacy.
What Data to Watch
Four numbers, to be checked once a quarter.
The trading volume on confidential exchanges, and from counterparties not associated with the protocol. After launching in September, this is the number that determines whether the trading theory holds, as exchange fees will repurchase ZAMA, and trading volume is cash flow. A venue without strangers on the other side is just a private way of talking to oneself.
Railgun's revenue compared to Zama's. The incumbent has already received about nine basis points on real traffic. If Zama cannot approach that level within a year of public launch, then no one is paying the premium for FHE.
The first company outside the crypto industry to pay salaries or suppliers through confidential stablecoins. Note that cUSDC hides the amount, not the supplier list, so for this use case to really take off, it needs more than just crypto balances.
Canton Coin's fee revenue, if it can ever be audited. A $4.8 billion token, built on usage that no one can verify externally, is the largest unexamined valuation in this space.
The fee destruction amount achieved by Zama, in dollars. Every protocol fee is destroyed, so the cumulative destruction amount can be queried on-chain, and it is the only indisputable measure of whether anyone is paying for all this. It is currently in the four-digit range, while the forecast is in the ten-digit range. The month it moves an order of magnitude is a signal that pricing has changed, and that is the single most informative number in this article.
Will those four wallets become forty? Forty-three percent of the net shielded value sits in four addresses in one vault. A decrease in concentration is more important than an increase in total.
Will someone start charging subscription fees instead of pay-per-use? The gap recorded above is a pricing gap, so the first confidential product to charge by seat, asset size, or spread is more worthy of attention than the next cryptographic score.
The mainnet timing of Fhenix, and whether its rollup is built on cryptography it owns. These two answers determine whether FHE in this category is one company or several.
Conclusion
Three answers to one question, and an honest summary of all of them is a trade-off, not a victory. Each design in this article is about buying more by exposing more, and that corner of "hiding everything while running everything" is empty.
Demand is real. A bank spent real money to prove it, traders are losing measurable basis points, and institutions have sent most trades to those venues where the entire product is "not revealing your size."
But privacy is not a one-time security upgrade. It changes who targets you and makes it harder to get your money back, and at the protocol level, it hides the flaws of the very thing you are trusting.
And valuations do not align with revenues. About $25 billion in value sits in privacy assets, distributed among Monero, Zcash, and Canton Coin. On the service side, the numbers are precise rather than approximate, and they are smaller than single-digit million dollars. Railgun, the best among them, collects 25 basis points on each side, having historically accumulated $13 million, while Monero and Zcash have collectively earned $3 million in fees since 2014 and 2016. Zama processed 104,848 mainnet transactions, moving $595 million across its boundaries, and because it charges by bits rather than basis points, according to its published price list, it has only received between $840 and $84,000. Running Zama's traffic through Railgun's fee schedule yields $1.49 million, which is 18 to 1,700 times more, depending on where the real numbers fall within the range. In terms of fee rates, it is one-fiftieth of a basis point versus twenty-five basis points.
So the dilemma at the beginning of this article has been resolved, and the answer is better than any of its corners. These services are underpriced, not because no one wants them. They are underpriced because the meter is connected to the wrong thing. A protocol that charges by bits hides a $20 million vault position and a ten-dollar transfer, charging the same fee, while currently four institutions are jointly hiding $20 million for a few cents.
This is why I conclude with a bullish note, but with a caveat on "what exactly to be bullish about."
Demand is validated rather than predicted, and this is rare at such an early stage. A bank spent real money to establish that crypto finance is viable, then issued its actual deposit token on the track it built itself. Institutions have moved most trades off-screen and paid a spread for that privilege. Dark pools captured a record 40.3% of U.S. equity trading volume in Q1 2026. As long as allowed, money has been flowing privately everywhere, and the only question public chains need to answer is whether they can provide the same level of programmability that made them worth using in the first place without giving it up. As of August 2026, one of them has achieved this, in a production environment, with real companies on it, moving $595 million across boundaries, with money turning over eleven times.
Technology is no longer a constraint, and this has been the silent change over the past year. Confidential tokens now have a standard and an audited OpenZeppelin implementation, making writing them an inheritance rather than cryptography. A court order passed through the packaging layer and was lifted within three days, revealing a compliance feature discovered the hard way, rather than a failure. The upcoming regulation on July 1, 2027, will pull European liquidity from uniform assets while pushing everything towards the kind of auditable privacy that these designs conveniently provide. The pieces are in place, and the clock is ticking in their favor.
What’s missing is a price, and a missing price is the easiest problem to solve in this article. Charging $5.65 instead of thirteen cents per transaction could earn a million dollars a year based on today’s trading volume, while still depressing the incumbents tenfold. This doesn’t require any mathematical improvements. It just needs someone to bill covertly as it is charged elsewhere, by seat, by subscription, or by basis points of asset size, and the first batch of customers is exactly the companies that the procurement department expected to receive an invoice in that shape.
Thus, the position is to go long on demand and to charge for it in the end, and according to current evidence, that is the trading venues, wallets, or authorized businesses, rather than the neutral layer underneath. Verify it with four numbers: the volume from strangers after the September launch, the dollar value of fees actually burned, whether those four wallets in the treasury will become forty, and the date when someone sends out the first privacy subscription invoice. The buyer with the budget line is a bank rather than a crypto punk, and the encouraging part of all this is that the bank has already started to make purchases.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.



























Revolut ends support for USDT across the EEA and Switzerland on 31 August 2026: any balance still in the app is automatically converted into the account's main currency at what Revolut calls the current market rate, with the customer controlling neither the rate nor the timing. Buying already stopped on 6 July and deposits after 30 July, leaving an in-app sale or a withdrawal to a wallet you control as the choices before the deadline.

The deadline for the Base, Early Lump-Sum and Intermediate Repayments in the Mt. Gox civil rehabilitation is 31 October 2026 (JST), set by the Rehabilitation Trustee's notice of 27 October 2025 with the permission of the court. The trustee's own notices record five changes to that deadline, not three, and state no consequence for the 2026 date passing.

