Search

Search for projects by name or address

Privacy

Privacy Pools logo
Privacy Pools

About

A selective-disclosure privacy system for Ethereum that adds compliance-aware association sets.


  • Total Value Locked
    $9.28 M3.18%
    across 14 assets and 14 buckets
  • TVL
    $9.28 M3.18%
  • Assets tracked
    14
  • Buckets tracked
    14
  • Deposits 7D
    10220.9%
  • Deposits 30D
    624
  • Deposits Total
    7.41 K
  • Active Relayers 30D
    4

  • Trusted setup
  • Exit window
  • Privacy
    Link privacy
  • Reproducibility

  • Tracked on
    Ethereum logo
  • Attributes
    ZKAny amount

  • About

    A selective-disclosure privacy system for Ethereum that adds compliance-aware association sets.

    Privacy Pools is a non-custodial privacy protocol on Ethereum built around asset-specific pools and private withdrawals, adding compliance by whitelisting all legitimate deposits. A deposit creates a commitment, which is represented by secret and nullifier, and a later withdrawal uses a zero-knowledge proof to spend that commitment, either partially or in full, without revealing the matching deposit. Losing the secret and the nullifier would effectively mean losing deposited tokens.

    Privacy Pools are controlled by a 2/4 multisig, which has authority to stop deposits and manage the deposit whitelist, but users always have an option to publicly withdraw deposited tokens, linking their withdrawal to their deposit.

    Privacy considerations

    Privacy Pools protocol supports relayed withdrawals, in which relayer processes withdrawals on user’s behalf for a fee, which enables sending funds to fresh addresses.

    Practical privacy also depends on the timing and amounts of deposits and withdrawals, underlying network and browser used to interact with Privacy Pools frontend (if used), RPC providers used to send transactions and query public blockchain state. The official frontend accepts a user-supplied RPC endpoint per network and scans pools whole, so with an own node no third party learns which notes are queried. Without one, all reads go through infrastructure operated by 0xbow. Users are advised to research OPSEC best practice.

    Fees

    Privacy Pools charges a mandatory onchain vetting fee on deposits and caps relayed-withdrawal fees per asset:

    • 0% vetting fee, 10% maximum relayer fee: frxUSD, fxUSD, sUSDS, USDe, USDS, USDT, WBTC, wOETH, wstETH.
    • 0% vetting fee, 5% maximum relayer fee: DAI, USD1.
    • 0.5% vetting fee, 10% maximum relayer fee: BOLD, ETH, USDC.

    The vetting fees are accumulated in the Entrypoint and can be withdrawn by its owner. Relayer fees are paid on withdrawals to the selected relayer and cannot exceed the per-asset cap; relayers can still choose their own quote below that cap and users can self-relay to not pay the fee.

    Compliance

    The main feature of Privacy Pools is compliance, which is enforced through the ASP. Association set is a whitelist of deposits that are allowed to be withdrawn from the protocol. This set is managed in real time by the provider, which is currently a single entity. The full association set is published via IPFS, only its Merkle root is posted onchain. User’s deposit could be excluded from the whitelist at any moment, in this case the user can still ragequit, i.e. publicly withdraw deposited funds and link them to their deposit.

    ASP is designed to vouch that withdrawals from Privacy Pools are not related to any known illegal activity.

    Anonymity set

    The anonymity set consists of all whitelisted deposits of the same token with the value greater than the withdrawal amount. Note that only deposits approved by the ASP add to the anonymity set. To maximize the anonymity set, users are recommended to withdraw smaller amounts and deposit popular tokens.

    What the protocol promises: Hides which deposit funds which withdrawal, for deposits approved by the permissioned ASP. Everything else is public.

    On public blockchains like Ethereum, all actions transparent by default. A privacy protocol can at best cut the link between addresses or offer privacy while deposited. The colour says whether a careful user can keep the link, amount or recipient private against that adversary: green yes, yellow only outside supported options or by accepting another leak, red no. Fields marked at risk stay private only under the condition in their note.

    Link private

    Which approved deposit a withdrawal spends is hidden. Partial withdrawals leave a change note and look like full ones.

    Advice: Exit through a relayer, so no wallet of yours pays gas for the receiving address. Withdraw partially to fresh addresses, and ragequit only untouched deposits: ragequitting a change note reveals the withdrawal it came from.

    Link private

    The approved set at any block is public, bounding the anonymity set. Any amount is allowed, so an unusual one pairs a deposit with its withdrawal. Paying gas from your own wallet instead of a relayer exposes that wallet's fingerprint, its account implementation and fee habits, even from a fresh address.

    Advice: Use a pool with a large anonymity set. Withdraw common amounts rather than everything at once. Wait before exiting and pick a different time of day than the deposit. Exit to a fresh address every time and spend from it with a different wallet than the one that deposited.

    Link private

    The official frontend allows you to set your own RPC endpoint per network, scans every pool whole and matches notes locally, so a node learns only which pools you looked at. 0xbow's servers still see that a session happened, through bulk feeds that carry nothing about the notes. A relayer receives amount and asset for a quote and the recipient once you confirm.

    Advice: Set an endpoint for every network before signing in, and sign in with a recovery phrase so no wallet address is queried. Without an endpoint, every read goes through 0xbow's proxy and Alchemy under 0xbow's key. Read the chain from your own node, send through a public RPC over Tor, and use a popular relayer. If you settle for a VPN instead of Tor, pick one you trust: it hides your IP from the relayer but sees it itself.

    Link at risk

    The ASP postman sets a new approved list at any time with no delay, and the pool accepts only the latest one. It can deny you a private exit or publish a list with only your deposit, which is then your whole anonymity set. The website shows the anonymity set but does not block a tiny one.

    Advice: Check the displayed anonymity set shown before withdrawing.

    Link private

    Nothing encrypted is written onchain and commitments are plain hashes, so a quantum computer recovers nothing. Accounts created from a wallet signature reduce to that wallet's key.

    Advice: Create your account from a seed phrase, not from a wallet signature.

    30 day historic anonymity set

    How many unique addresses you could have blended in with if you withdrew on a particular day after depositing during the previous 30 days. This metric is a proxy for the historic anonymity set and shows how it developed over time.

    The metric looks backwards: it counts deposits that already happened, including from addresses that have since withdrawn. Your real anonymity also depends on deposits made after yours, which cannot be known in advance.

    Estimated anonymity set by holding duration

    An estimate of how many unique addresses you blend in with, depending on how long you leave your deposit in the pool. It is based on historic data of past deposits: each point counts depositors from the preceding period, so holding for up to 30 days effectively means blending in with everyone who deposited during the last 30 days.

    Asset
    Deposits 7D
    Deposits 30D
    Deposits Total
    Value Locked
    USDTUSDT
    27
    $144.69 K
    80
    $461.56 K
    457
    $10.00 M
    $6.64 M
    ETHETH
    59
    $386.07 K
    473
    $788.30 K
    5.89 K
    $11.63 M
    $1.99 M
    USDCUSDC
    16
    $47.71 K
    68
    $248.26 K
    870
    $4.81 M
    $482.70 K
    wstETHwstETH
    0
    $0.00
    2
    $1.51 K
    39
    $313.22 K
    $84.61 K
    BOLDBOLD
    0
    $0.00
    0
    $0.00
    20
    $50.42 K
    $49.63 K
    frxUSDfrxUSD
    0
    $0.00
    0
    $0.00
    9
    $11.73 K
    $10.64 K
    wOETHwOETH
    0
    $0.00
    0
    $0.00
    4
    $12.88 K
    $6.46 K
    WBTCWBTC
    0
    $0.00
    0
    $0.00
    6
    $17.01 K
    $5.86 K
    USDSUSDS
    0
    $0.00
    1
    $499.94
    18
    $13.51 K
    $2.48 K
    sUSDSsUSDS
    0
    $0.00
    0
    $0.00
    11
    $4.83 K
    $1.38 K
    USD1USD1
    0
    $0.00
    0
    $0.00
    4
    $2.33 K
    $1.34 K
    DAIDAI
    0
    $0.00
    0
    $0.00
    6
    $11.50 K
    $779.78
    fxUSDfxUSD
    0
    $0.00
    0
    $0.00
    76
    $1.75 M
    $710.33
    USDeUSDe
    0
    $0.00
    0
    $0.00
    1
    $995.39
    —
    Total
    102
    $578.48 K
    624
    $1.50 M
    7.41 K
    $28.63 M
    $9.28 M

    Funds can be stolen if

    1. the zk proof system is broken, allowing invalid withdrawals.
    2. the trusted setup is compromised or all ceremony participants collude, allowing invalid withdrawals.
    3. the Entrypoint owner deploys a malicious upgrade that steals new deposits.

    Funds can be lost if

    1. a user loses the secret and nullifier required to spend their deposit.

    Privacy can be lost if

    1. no relayer is available and the withdrawal must be submitted from an address that can be linked to the user.
    2. the ASP manager refuses to whitelist a deposit, forcing the user to either wait or exit publicly through ragequit.

    The 2/4 Privacy Pools Multisig can instantly change the system’s critical configs, including the Entrypoint implementation and ASP root used for private withdrawals. The ASP postman (EOA) can also remove any deposit from the whitelist at any time, forcing a public rage-quit if the affected party wishes to withdraw. The guaranteed immutable escape hatch is pool-level ragequit (public withdrawal) to the original depositor address, because that logic lives in the immutable pool contracts and does not depend on the Entrypoint registry and config. This means the system is permissioned in its deposit logic and deposit privacy, but non-custodial for deposited assets. Past, successful (non-ragequit) withdrawals can not be deanonymized by the protocol.

    Privacy Pools

    Snarkjs

    Detailed description

    Trusted setup for two Groth16 Privacy Pools circuits: the Ragequit circuit and the private Withdrawal circuit.

    This trusted setup ceremony builds on top of the 80th contribution to the Perpetual Powers of Tau ceremony as phase 1.

    Phase 2 of the ceremony was publicly announced, open to anonymous and identified participants, and concluded in March 2025. It contains 514 contributions to the Withdraw circuit and 513 participants to the Ragequit circuit. The finalized zKeys were published for independent verification, and the ceremony code and UI were open-sourced.

    Verifier
    Verification
    Used in
    Known deployments
    Privacy Pools verifiers v1.2.1
    by
    Privacy Pools logo

    Verifier ID:Privacy Pools Withdrawal and Ragequit verifiers 03.07.2026

    Known deployments

    Deployment #1

    Used in:
    Privacy Pools logo

    Deployment #2

    Used in:
    Privacy Pools logo

    Verification steps

    Privacy Pools uses two Groth16 circuits — commitment (named ragequit in the trusted-setup ceremony) and withdraw — whose verification keys are hard-coded in the deployed CommitmentVerifier.sol and WithdrawalVerifier.sol smart contracts. This regeneration attests that these onchain verification keys correspond to the circuits published in the Privacy Pools repo.

    Generally, to regenerate the two Privacy Pools verification keys, the following has to be done:

    1. Checkout the v1.2.1 tag of the Privacy Pools core repo (commit hash a80836a47451e662f127af17e11430ffa976c234).
    2. Install the repo-pinned toolchain and compile the .circom circuit sources into .r1cs binaries.
    3. Download the phase 1 trusted setup file ppot_0080_16.ptau (Perpetual Powers of Tau contribution #80), which underlies the ceremony final keys.
    4. Verify the checked-in final prover keys (.zkey) against the compiled circuits and the phase 1 file. This step also implicitly checks the integrity of the phase 2 trusted setup.
    5. Export verification keys from the final prover keys and make sure they are identical to the checked-in .vkey files, whose values are hard-coded in the onchain verifier smart contracts.

    Helper scripts that implement the flow above and more detailed explanations could be found in this script .zip archive. This .zip must be extracted in the privacy-pools-core dir checked out on tag v1.2.1 (commit hash a80836a47451e662f127af17e11430ffa976c234) before the execution.

    2026 May 28, 10:27 UTC
    2changes

    two signers change.

    contract Privacy Pools Multisig (eth:0xAd7f9A19E2598b6eFE0A25C84FB1c87F81eB7159) [GnosisSafe] {
    +++ description: None
    values.$members.2:
    - "eth:0x554c5aF96E9e3c05AEC01ce18221d0DD25975aB4"
    + "eth:0x652E36f8EA937c19417380dCDb48D6e4375d13dA"
    values.$members.3:
    - "eth:0x42FEdcd80C8C9694DBc3b2ff0fD48BB8651dfC62"
    + "eth:0xE8A2cC5c2349615D947b9d9fE5D7F144730cAf77"
    }
    2026 April 30, 16:40 UTC
    19changes

    Discovery rerun on the same block number with only config-related changes.

    Initial discovery

    + Status: CREATED
    contract WithdrawalVerifier (eth:0x022891F938Ae7fDC8Ab9Ead0FBf50aBA8C897D6d)
    +++ description: Stateless Groth16 verifier used by Privacy Pool contracts to verify withdrawal proofs. The verification key is hardcoded in the contract and there are no privileged roles or mutable configuration.
    + Status: CREATED
    contract PrivacyPoolUSDS (eth:0x05e4DBD71B56861eeD2Aaa12d00A797F04B5D3c0)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolWstETH (eth:0x1A604E9DFa0EFDC7FFda378AF16Cb81243b61633)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolDAI (eth:0x1c31C03B8CB2EE674D0F11De77135536db828257)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolsEntrypoint (eth:0x6818809EefCe719E480a7526D76bD3e561526b46)
    +++ description: UUPS-upgradeable hub for Privacy Pools. It accepts deposits, relays withdrawals, tracks association-set roots published by the ASP, and maps each supported asset and scope to a pool. Trusting this contract means trusting OWNER_ROLE holders to upgrade it, manage pools and fees, and withdraw fees, and trusting ASP_POSTMAN holders to publish the latest association-set root used by withdrawals.
    + Status: CREATED
    contract PrivacyPoolWOETH (eth:0x7d2959bCFb936a84531518e8391DdBa844e03ebE)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract RagequitVerifier (eth:0xa45ACa8604a73D80C551fAad6355A5c3A5565eC6)
    +++ description: Stateless Groth16 verifier used by Privacy Pool contracts to verify ragequit proofs. The verification key is hardcoded in the contract and there are no privileged roles or mutable configuration.
    + Status: CREATED
    contract PrivacyPoolsAdminSafe (eth:0xAd7f9A19E2598b6eFE0A25C84FB1c87F81eB7159)
    +++ description: None
    + Status: CREATED
    contract PrivacyPoolUSDC (eth:0xb419c2867aB3CBc78921660cB95150d95A94ce86)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolBOLD (eth:0xb4b5Fd38Fd4788071d7287e3cB52948e0d10b23E)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolSUSDS (eth:0xBBdA2173CDFEA1c3bD7F2908798F1265301d750c)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolUSD1 (eth:0xc0A8Bc0F4F982b4d4f1fFae8F4FCCb58c9B29c98)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolFrxUSD (eth:0xC6C769fac7AABEadd31a03fAe5Ca0Ec5B4C50f84)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolFxUSD (eth:0xD14F4B36E1D1D98c218db782c49149876042BC56)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    EOA (eth:0xd76eEb2A6fcf55dc80D046FFbc96D1A2B45AB52E)
    +++ description: None
    + Status: CREATED
    contract PrivacyPoolUSDe (eth:0xe6D36B33b00A7C0cB0C2a8d39D07e7dB0c526Abc)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolUSDT (eth:0xe859C0bD25f260BaEE534Fb52e307D3b64D24572)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolETH (eth:0xF241d57C6DebAe225c0F2e6eA1529373C9A9C9fB)
    +++ description: Native-asset Privacy Pool that escrows ETH commitments for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    + Status: CREATED
    contract PrivacyPoolWBTC (eth:0xF973f4B180A568157Cd7A0E6006449139E6Bfc32)
    +++ description: ERC20 Privacy Pool that escrows one asset for one scope. Only the Entrypoint can create deposits or wind the pool down. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.
    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner

    Ethereum

    Actors:

    Privacy Pools Multisig0xAd7f…7159

    A Multisig with 2/4 threshold.

    • Can interact with PrivacyPoolsEntrypoint
      • authorize UUPS upgrades to the Entrypoint implementation
      • grant and revoke OWNER_ROLE and ASP_POSTMAN
      • publish new association-set roots and IPFS CIDs used by withdrawals
      • register and remove pools, update per-asset minimum deposits and fee caps, and wind down pools
      • withdraw fees held in the Entrypoint
    • Can interact with PrivacyPoolsEntrypoint
      • publish new association-set roots and IPFS CIDs used by withdrawals
    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner
    A diagram of the smart contract architecture
    A diagram of the smart contract architecture

    Ethereum

    PrivacyPoolUSDS0x05e4…D3c0

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolWstETH0x1A60…1633

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolDAI0x1c31…8257

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    Main hub for Privacy Pools. Entrypoint for deposits, relayed withdrawals, pool registry/configuration, ASP root updates, fee withdrawal, and wind-down management.

    • Roles:
      • aspPostmen: EOA 1, Privacy Pools Multisig
      • ownerRoleMembers: Privacy Pools Multisig
    PrivacyPoolWOETH0x7d29…3ebE

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSDC0xb419…ce86

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolBOLD0xb4b5…b23E

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolSUSDS0xBBdA…750c

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSD10xc0A8…9c98

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolFrxUSD0xC6C7…0f84

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolFxUSD0xD14F…BC56

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSDe0xe6D3…6Abc

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSDT0xe859…4572

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolETH0xF241…C9fB

    Native-asset Privacy Pool that escrows ETH commitments for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolWBTC0xF973…fc32

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    WithdrawalVerifier0x0228…7D6d

    Stateless Groth16 verifier used by Privacy Pool contracts to verify withdrawal proofs.

    RagequitVerifier0xa45A…5eC6

    Stateless Groth16 verifier used by Privacy Pool contracts to verify ragequit proofs.