Search

Search for projects by name or address

Privacy

Privacy Pools logo
Privacy Pools

About

A selective-disclosure privacy system for Ethereum that adds compliance-aware association sets.


  • Total Value Locked
    $8.69 Macross 14 assets and 14 buckets
  • TVL
    $8.69 M
  • Assets tracked
    14
  • Buckets tracked
    14
  • Deposits 7D
    120
  • Deposits 30D
    611
  • Deposits Total
    6.03 K
  • Trusted setup
  • Exit window
  • Privacy
  • Reproducibility
  • Attributes
    ZKAny amount

  • About

    A selective-disclosure privacy system for Ethereum that adds compliance-aware association sets.

    Privacy Pools is a non-custodial privacy protocol on Ethereum built around asset-specific pools and private withdrawals, adding compliance by whitelisting all legitimate deposits. A deposit creates a commitment, which is represented by secret and nullifier, and a later withdrawal uses a zero-knowledge proof to spend that commitment, either partially or in full, without revealing the matching deposit. Losing the secret and the nullifier would effectively mean losing deposited tokens.

    Privacy Pools are controlled by a 2/4 multisig, which has authority to stop deposits and manage the deposit whitelist, but users always have an option to publicly withdraw deposited tokens, linking their withdrawal to their deposit.

    Privacy considerations

    Privacy Pools protocol supports relayed withdrawals, in which relayer processes withdrawals on user’s behalf for a fee, which enables sending funds to fresh addresses.

    Practical privacy also depends on the timing and amounts of deposits and withdrawals, underlying network and browser used to interact with Privacy Pools frontend (if used), RPC providers used to send transactions and query public blockchain state. Users are advised to research OPSEC best practice.

    Fees

    Privacy Pools charges a mandatory onchain vetting fee on deposits and caps relayed-withdrawal fees per asset:

    • 0% vetting fee, 10% maximum relayer fee: frxUSD, fxUSD, sUSDS, USDe, USDS, USDT, WBTC, wOETH, wstETH.
    • 0% vetting fee, 5% maximum relayer fee: DAI, USD1.
    • 0.5% vetting fee, 10% maximum relayer fee: BOLD, ETH, USDC.

    The vetting fees are accumulated in the Entrypoint and can be withdrawn by its owner. Relayer fees are paid on withdrawals to the selected relayer and cannot exceed the per-asset cap; relayers can still choose their own quote below that cap and users can self-relay to not pay the fee.

    Compliance

    The main feature of Privacy Pools is compliance, which is enforced through the ASP. Association set is a whitelist of deposits that are allowed to be withdrawn from the protocol. This set is managed in real time by the provider, which is currently a single entity. The full association set is published via IPFS, only its Merkle root is posted onchain. User’s deposit could be excluded from the whitelist at any moment, in this case the user can still ragequit, i.e. publicly withdraw deposited funds and link them to their deposit.

    ASP is designed to vouch that withdrawals from Privacy Pools are not related to any known illegal activity.

    Anonymity set

    The anonymity set consists of all whitelisted deposits of the same token with the value greater than the withdrawal amount. Note that only deposits approved by the ASP add to the anonymity set. To maximize the anonymity set, users are recommended to withdraw smaller amounts and deposit popular tokens.

    2025 Jul 26 — 2026 Jul 26

    2025 Jul 26 — 2026 Jul 26

    Asset
    Deposits 7D
    Deposits 30D
    Deposits Total
    Value Locked
    USDTUSDT
    19
    $682.00 K
    61
    $1.18 M
    302
    $7.96 M
    $5.74 M
    ETHETH
    84
    $317.83 K
    465
    $453.71 K
    4.81 K
    $10.46 M
    $1.56 M
    USDCUSDC
    16
    $206.46 K
    81
    $487.45 K
    728
    $4.17 M
    $1.25 M
    wstETHwstETH
    0
    $0.00
    2
    $680.57
    37
    $311.71 K
    $60.18 K
    BOLDBOLD
    0
    $0.00
    0
    $0.00
    20
    $50.42 K
    $50.06 K
    frxUSDfrxUSD
    0
    $0.00
    0
    $0.00
    9
    $11.73 K
    $10.64 K
    wOETHwOETH
    0
    $0.00
    0
    $0.00
    4
    $12.88 K
    $4.62 K
    WBTCWBTC
    1
    $2.60 K
    2
    $4.50 K
    6
    $17.01 K
    $4.51 K
    USDSUSDS
    0
    $0.00
    0
    $0.00
    17
    $13.01 K
    $2.48 K
    sUSDSsUSDS
    0
    $0.00
    0
    $0.00
    11
    $4.83 K
    $1.37 K
    USD1USD1
    0
    $0.00
    0
    $0.00
    4
    $2.33 K
    $1.34 K
    DAIDAI
    0
    $0.00
    0
    $0.00
    6
    $11.50 K
    $779.87
    fxUSDfxUSD
    0
    $0.00
    0
    $0.00
    76
    $1.75 M
    $716.13
    USDeUSDe
    0
    $0.00
    0
    $0.00
    1
    $995.39
    Total
    120
    $1.20 M
    611
    $2.12 M
    6.03 K
    $24.79 M
    $8.69 M

    Funds can be stolen if

    1. the zk proof system is broken, allowing invalid withdrawals.
    2. the trusted setup is compromised or all ceremony participants collude, allowing invalid withdrawals.
    3. the Entrypoint owner deploys a malicious upgrade that steals new deposits.

    Funds can be lost if

    1. a user loses the secret and nullifier required to spend their deposit.

    Privacy can be lost if

    1. no relayer is available and the withdrawal must be submitted from an address that can be linked to the user.
    2. the ASP manager refuses to whitelist a deposit, forcing the user to either wait or exit publicly through ragequit.

    The 2/4 Privacy Pools Multisig can instantly change the system’s critical configs, including the Entrypoint implementation and ASP root used for private withdrawals. The ASP postman (EOA) can also remove any deposit from the whitelist at any time, forcing a public rage-quit if the affected party wishes to withdraw. The guaranteed immutable escape hatch is pool-level ragequit (public withdrawal) to the original depositor address, because that logic lives in the immutable pool contracts and does not depend on the Entrypoint registry and config. This means the system is permissioned in its deposit logic and deposit privacy, but non-custodial for deposited assets. Past, successful (non-ragequit) withdrawals can not be deanonymized by the protocol.

    Privacy Pools

    Snarkjs

    Detailed description

    Trusted setup for two Groth16 Privacy Pools circuits: the Ragequit circuit and the private Withdrawal circuit.

    This trusted setup ceremony builds on top of the 80th contribution to the Perpetual Powers of Tau ceremony as phase 1.

    Phase 2 of the ceremony was publicly announced, open to anonymous and identified participants, and concluded in March 2025. It contains 514 contributions to the Withdraw circuit and 513 participants to the Ragequit circuit. The finalized zKeys were published for independent verification, and the ceremony code and UI were open-sourced.

    Verifier
    Verification
    Used in
    Known deployments
    Privacy Pools verifiers v1.2.1
    by
    Privacy Pools logo

    Verifier ID:Privacy Pools Withdrawal and Ragequit verifiers 03.07.2026

    Known deployments

    Deployment #1

    Used in:
    Privacy Pools logo

    Deployment #2

    Used in:
    Privacy Pools logo

    Verification steps

    Privacy Pools uses two Groth16 circuits — commitment (named ragequit in the trusted-setup ceremony) and withdraw — whose verification keys are hard-coded in the deployed CommitmentVerifier.sol and WithdrawalVerifier.sol smart contracts. This regeneration attests that these onchain verification keys correspond to the circuits published in the Privacy Pools repo.

    Generally, to regenerate the two Privacy Pools verification keys, the following has to be done:

    1. Checkout the v1.2.1 tag of the Privacy Pools core repo (commit hash a80836a47451e662f127af17e11430ffa976c234).
    2. Install the repo-pinned toolchain and compile the .circom circuit sources into .r1cs binaries.
    3. Download the phase 1 trusted setup file ppot_0080_16.ptau (Perpetual Powers of Tau contribution #80), which underlies the ceremony final keys.
    4. Verify the checked-in final prover keys (.zkey) against the compiled circuits and the phase 1 file. This step also implicitly checks the integrity of the phase 2 trusted setup.
    5. Export verification keys from the final prover keys and make sure they are identical to the checked-in .vkey files, whose values are hard-coded in the onchain verifier smart contracts.

    Helper scripts that implement the flow above and more detailed explanations could be found in this script .zip archive. This .zip must be extracted in the privacy-pools-core dir checked out on tag v1.2.1 (commit hash a80836a47451e662f127af17e11430ffa976c234) before the execution.

    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner

    Ethereum

    Actors:

    Privacy Pools Multisig0xAd7f…7159

    A Multisig with 2/4 threshold.

    • Can interact with PrivacyPoolsEntrypoint
      • authorize UUPS upgrades to the Entrypoint implementation
      • grant and revoke OWNER_ROLE and ASP_POSTMAN
      • publish new association-set roots and IPFS CIDs used by withdrawals
      • register and remove pools, update per-asset minimum deposits and fee caps, and wind down pools
      • withdraw fees held in the Entrypoint
    • Can interact with PrivacyPoolsEntrypoint
      • publish new association-set roots and IPFS CIDs used by withdrawals
    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner
    A diagram of the smart contract architecture
    A diagram of the smart contract architecture

    Ethereum

    PrivacyPoolUSDS0x05e4…D3c0

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolWstETH0x1A60…1633

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolDAI0x1c31…8257

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    Main hub for Privacy Pools. Entrypoint for deposits, relayed withdrawals, pool registry/configuration, ASP root updates, fee withdrawal, and wind-down management.

    • Roles:
      • aspPostmen: EOA 1, Privacy Pools Multisig
      • ownerRoleMembers: Privacy Pools Multisig
    PrivacyPoolWOETH0x7d29…3ebE

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSDC0xb419…ce86

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolBOLD0xb4b5…b23E

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolSUSDS0xBBdA…750c

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSD10xc0A8…9c98

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolFrxUSD0xC6C7…0f84

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolFxUSD0xD14F…BC56

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSDe0xe6D3…6Abc

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolUSDT0xe859…4572

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolETH0xF241…C9fB

    Native-asset Privacy Pool that escrows ETH commitments for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    PrivacyPoolWBTC0xF973…fc32

    ERC20 Privacy Pool that escrows one asset for one scope. Withdrawals and ragequits depend on the linked Groth16 verifiers and on the latest association-set root in the Entrypoint.

    WithdrawalVerifier0x0228…7D6d

    Stateless Groth16 verifier used by Privacy Pool contracts to verify withdrawal proofs.

    RagequitVerifier0xa45A…5eC6

    Stateless Groth16 verifier used by Privacy Pool contracts to verify ragequit proofs.