Search for projects by name or address
Zama Confidential Tokens is an app that wraps ERC-20 assets into confidential tokens and hides balances and transfer amounts using Zama FHEVM on Ethereum.
Zama Confidential Tokens is an app that wraps ERC-20 assets into confidential tokens and hides balances and transfer amounts using Zama FHEVM on Ethereum.
Zama Confidential Tokens is an account-based confidential token system on Ethereum, using the Zama FHE protocol. It is based on ERC-7984. Users deposit regular ERC-20 tokens into asset-specific escrows and receive confidential tokens whose balances and internal transfer amounts are represented as encrypted handles.
‘Confidential’ here means from: and to: addresses and transfer timestamps always remain public. Only balances and transfer amounts are hidden. Each confidential token aggregates encrypted balances for a single underlying asset, so the hidden state is the amount and balance data, not the public address graph.

The Zama FHE protocol uses fully homomorphic encryption to let smart contracts operate on encrypted values. Balances are stored as encrypted handles instead of plaintext balances, and FHEVM system contracts are called for encrypted arithmetic, comparisons, transfers, minting, or burning, but most of the actual FHE execution happens offchain.
The FHE coprocessor is an offchain service that performs FHE-related work the EVM cannot execute directly. Encrypted user inputs are accepted onchain only after the InputVerifier checks signatures from the coprocessor signer set (currently 1/1). The coprocessor is constrained on what it can commit onchain by the smart contract, but it is not trustless and can affect validity if compromised.
The ACL is the onchain access-control registry for encrypted handles. It records which accounts or contracts are allowed to use a ciphertext handle, which prevents arbitrary users from reusing encrypted values they do not control.
The (T)KMS is the threshold key-management service used for private and public decryptions. It holds the FHE secret key and functions like a multisig; the current Ethereum verifier context (KMS signer set) has a public-decryption threshold of 7/13. KMS signer sets and thresholds are managed onchain in the ProtocolConfig contract, where governance can create and destroy contexts and retune the thresholds of any live context — including the current one — without rotating it. Each context can be different but retains its full permissions until explicitly invalidated onchain. A malicious new Ethereum verifier context, or the threshold of any retained Ethereum verifier context, can attest an inflated amount for an attacker’s real unwrap handle and drain pooled backing deposited by other users. The KMS Signers are operated by Zama, Dfns, Figment, Fireblocks, InfStones, Unit410, LayerZero, Ledger, Omakase, Stake Capital, OpenZeppelin, Etherscan, and Conduit.
The onchain KMS signer addresses are ECDSA credentials used to attest KMS outputs; they are not the FHE key shares. Zama states that KMS MPC nodes run inside AWS Nitro Enclaves, and its offchain software maps node signing keys to MPC parties, but the contracts do not verify Nitro attestations or prove that a configured signer runs inside a TEE, holds an FHE key share, or participated in the threshold computation. Changing an onchain KMS context only changes which signatures are accepted; it neither triggers nor verifies redistribution or destruction of FHE key shares.
There are many moving parts and offchain components in the Zama FHE protocol on which Zama Confidential Tokens is built. The Zama Gateway, an L3 on Arbitrum, is currently used for coordination/aggregation and ciphertext-metadata. FHE key- and CRS-generation is orchestrated onchain on Ethereum through the KMSGeneration contract: governance triggers a generation, and KMS node responses are accepted at a signature threshold configured in ProtocolConfig. Ethereum does not trust the Gateway’s state directly and independently verifies operator signatures before accepting inputs or withdrawals, but current relayer and operator workflows depend on Gateway availability to produce those proofs.
Deposits and withdrawals are public privacy boundaries. A wrap emits the confidential-token recipient and the rounded clear underlying-token amount. The recipient can be different from the depositor, but that relationship is still visible in the deposit event. Withdrawals then reveal the recipient and amount.
Within a confidential token, holders can make confidential transfers between transparent EVM addresses. These transfers reveal the parties and encrypted ciphertext handles, but not the clear amount or resulting balances. The confidential balances and transfer amounts of users can be decrypted retroactively if enough KMS key shares are combined.
The smart contracts do not fully validate FHE offchain work, which makes the KMS and coprocessor each trusted for security, privacy and liveness. Encrypted user inputs are accepted through the InputVerifier, which requires 1/1 coprocessor signatures. Public decryptions are accepted through the KMSVerifier, which requires the threshold of any selected non-invalidated context (signer set), not necessarily the displayed current 7/13 context. Decentralization of the critical offchain services is announced in the docs but not implemented onchain (e.g. coprocessors, fraud proofs, slashing, zk proofs).
Practical privacy also depends on timing, amounts, address reuse, wallet/RPC providers, and any frontend or service used to create encrypted inputs. Users are advised to research OPSEC best practice.
There currently is no protocol fee. Users still pay Ethereum gas for each action, including confidential token transfers, and may pay costs charged by external wallets, relayers, or services used to create or submit transactions.
Compliance is enforced in each confidential token contract. The owner can block and unblock local users, and confidential token contracts can be configured to call an underlying-token denylist function. These checks apply to direct deposits, ERC-1363 callback deposits, confidential transfers, unwrap requests, and unwrap finalization.
Because confidential tokens are backed by underlying tokens held in their contract addresses, issuer or token-admin controls over those underlyings remain a dependency. If an underlying token admin blocks a confidential token address, the escrowed token can become stuck. If a user address is blocked by an underlying token and the confidential token has a transitive denylist hook configured, that address can be prevented from depositing, transferring, or completing withdrawals.
Zama Confidential Tokens does not use fixed-denomination notes. For a given finalized withdrawal, the set of prior deposits that could have funded the withdrawing account through the public address graph is its effective anonymity set: deposits credited to the same address, or to addresses that visibly transferred confidential tokens to it before the withdrawal. Amounts are private inside the confidential token, so links within the remaining candidate set can remain ambiguous, but deposits and finalized withdrawals expose each boundary amount and endpoint address. Integration with DeFi and its use from inside the confidential token increases the anonymity set.
As mentioned in ‘Privacy Considerations’, the mostly centralized offchain services that cannot be circumvented can corrupt practical privacy, independent of the abstract measurable anonymity set.
2025 Dec 27 — 2026 Aug 16
2026 May 12 — Aug 16
Asset | Deposits 7D | Deposits 30D | Deposits Total | Value Locked |
|---|---|---|---|---|
steakcUSDC | 7 $2.45 M | 32 $28.21 M | 197 $68.24 M | $32.10 M |
USDT | 15 $48.65 K | 57 $716.43 K | 180 $1.27 M | $7.84 M |
ZAMA | 1 $81.12 | 18 $3.11 K | 49 $18.74 K | $6.36 M |
bbqTGBP | 0 $0.00 | 0 $0.00 | 1 $5.07 M | $5.11 M |
USDC | 41 $2.39 M | 270 $28.75 M | 2.51 K $78.08 M | $3.98 M |
XAUt | 0 $0.00 | 0 $0.00 | 2 $0.53 | $43.69 K |
WETH | 1 $1.88 | 8 $54.68 K | 51 $153.43 K | $39.54 K |
tGBP | 0 $0.00 | 0 $0.00 | 2 $10.16 K | $10.40 K |
| Total | 65 $4.89 M | 385 $57.74 M | 3.00 K $152.86 M | $55.51 M |
Zama Confidential Tokens governance is implemented through an Aragon ‘DAO’ deployment controlled by two multisigs: ZamaGovMultisigA with a 9/17 threshold and ZamaGovMultisigB with a 3/5 threshold. The Gateway contracts are controlled separately by the SafeL2 multisig listed in the permissions section. These accounts can upgrade contracts or change critical configuration without a timelock. On the Gateway, the owner multisig can create and destroy KMS contexts, change the thresholds of any live context, and disable or remove registered host chains, halting Gateway workflows for those chains.
Confidential token owners and underlying token owners can freeze users. The Ethereum ACL owner can manage ACL-level account blocking, unpause the ACL, change HCU limits, and — through the ProtocolConfig contract — create KMS contexts with arbitrary signer sets and thresholds, retune the thresholds of any live context (including the current one) in place, and trigger or abort FHE key- and CRS-generation in the KMSGeneration contract. A new context immediately becomes the default verifier authority and can attest unwrap amounts for assets deposited before it existed. Superseded contexts remain equally authoritative for all past and future ciphertext handles until the ACL owner explicitly destroys them; the current context cannot be destroyed. Changing an onchain KMS context changes only the accepted ECDSA credentials and does not trigger or verify resharing or destruction of the underlying FHE key shares.
Offchain components like the coprocessor and KMS are trusted for liveness, privacy and security and are currently not decentralized.
Transparent proving systems require no trusted setups and have no additional setup-related trust assumptions.

A Multisig with 3/5 threshold. Aragon multisig plugin for creating proposals and collecting approvals against a configurable threshold.
A Multisig with 9/17 threshold. Aragon multisig plugin for creating proposals and collecting approvals against a configurable threshold.
Aragon DAO that stores governance state and executes proposal action batches. Member of ZamaGovMultisigA.
A Multisig with 3/5 threshold. Gateway owner Safe. Its LayerZero governance module is outside the Zama Gateway protocol surface covered here.

Tracks and enforces per-transaction and per-block homomorphic computation unit limits for FHEVM operation requests. v0.3.0 adds pricing for the fheSum and fheIsIn operations.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
Ethereum host-chain verifier for public decryption results produced through the Zama Gateway Decryption contract. Since v0.3.0 it is a stateless proof checker: KMS signer sets and thresholds are read from the ProtocolConfig contract, and confidential token wrappers accept a decrypted value when it is signed by the threshold of the current or any explicitly selected non-destroyed KMS context.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
Ethereum host-chain access-control registry for encrypted handles, storing handle allowances and delegation state for ciphertext references. Its public-decryption and user-delegation events are mirrored into the Gateway MultichainACL by coprocessor consensus. Since v0.4.0 users can delegate user decryption of their handles across all app contracts at once via a wildcard delegation.
Ethereum host-chain verifier for encrypted input attestations produced by the Zama Gateway InputVerification contract. The FHEVMExecutor calls it before accepting user-provided ciphertext handles.
Ethereum host-chain registry of KMS node sets, per-context thresholds, and context lifecycle, introduced in the v0.3.0 KMSVerifier upgrade. A KMS context snapshots node transaction senders and signers; the four per-context thresholds (public decryption, user decryption, key generation, MPC) can be retuned by the ACL owner for any live context, including the current one. A newly created context becomes current immediately; older contexts remain selectable for public decryption proofs until destroyed.
FHEVM executor that accepts encrypted operation requests, accounts for computation usage, and stores ciphertext handles for operation results. v0.4.0 adds the n-ary encrypted operations fheSum and fheIsIn (encrypted set membership) over bounded ciphertext collections.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
ERC-20 wrapper that escrows an underlying token and issues confidential balances. It supports encrypted transfers, wrapping, unwrapping, local blocking, and optional underlying-token denylist checks.
Registry for Zama confidential token wrappers.
Orchestrates FHE key and CRS generation on the Ethereum host chain, taking over the workflows removed from the Gateway KMSGeneration in v0.5.0. The ACL owner triggers and aborts generations; KMS node transaction senders registered in ProtocolConfig submit EIP-712-signed responses that activate a key or CRS once the ProtocolConfig key-generation threshold is reached.
Aragon DAO that stores governance state and executes proposal action batches.
Maintains the pauser account set used in pause-control checks.
Staking contract that escrows ZAMA, issues non-transferable staked voting tokens, and mints protocol rewards to eligible stakers at a configurable reward rate.
Staking contract that escrows ZAMA, issues non-transferable staked voting tokens, and mints protocol rewards to eligible stakers at a configurable reward rate.
Gateway-side ACL mirror that records coprocessor consensus for host-chain public decryption permissions, account handle allowances, and delegated user-decryption access. For Ethereum, it mirrors ACL events emitted by the L1 ACL contract registered in GatewayConfig.
Gateway contract that orchestrates public and user decryption requests and checks committed ciphertext material. Each request pins a KMS context at request time (explicitly through extraData or the then-current context) and rejects unknown or destroyed contexts; responses must reference the pinned context. Requests recorded before v0.5.0 fall back to the context declared by each response. KMS nodes enforce host-chain ACL state offchain, and Ethereum KMSVerifier verifies public results against this contract’s EIP-712 domain.
View-only gateway contract retaining historical queries for previously generated FHE keys and CRS materials. All state-changing key-generation, CRS-generation, PRSS, and key-resharing workflows were removed in v0.5.0 after their move to Ethereum.
Gateway fee contract that charges ZAMA fees for encrypted input verification, public decryption, and user decryption requests, then forwards the collected fees to the configured fee burner sender.
Gateway contract that receives encrypted input verification requests from registered and enabled host chains, collects coprocessor responses, and emits a threshold-signed attestation once coprocessor consensus is reached. Ethereum InputVerifier verifies attestations against this contract’s EIP-712 domain.
Gateway contract that stores ciphertext and SNS ciphertext digests after coprocessor consensus, allowing decryption requests to reference committed ciphertext material. Digests referencing unregistered or disabled host chains are rejected.
Central configuration contract for the Zama Gateway. A KMS context snapshots node transaction senders, signers, and workflow thresholds; the owner can create new contexts, retune the thresholds of any live context, and destroy non-current contexts, which immediately invalidates them for decryption. Registered host chains can be disabled, re-enabled, or removed by the owner.
Maintains the set of accounts allowed to pause gateway contracts. The set is managed by the GatewayConfig owner.