Written by: Mario Chow, IOSG
Summary
The public blockchain lays bare every amount. This is not a problem before real balance sheets enter the scene. There are three approaches to address it: build a privacy network by oneself, such as Zcash, Monero, and Canton; add privacy features to Ethereum, starting with Tornado Cash, followed by Railgun, and then Zama; or simply not disclose any data—Canton does that too.
Each of these options trades off concealment for functionality. No one has yet created something that can conceal everything while still being functional.
The demand is real and verifiable. JPMorgan validated the institutional finance running in crypto in 2024 and issued its deposit token on Canton in 2026. A trade subjected to a sandwich attack has to spit out 0.3% to 0.8%. Institutional spot OTC trading volume increased by 109% in one year; during the same period, the top twenty exchanges only grew by 9%; 40% of institutions have already moved more than half of their trades off-screen.
However, privacy does not equate to a security upgrade. It can reduce your chances of being targeted, but once you are singled out, it is of no use; recovery becomes even harder if an issue occurs. It has also hid a vulnerability in Zcash that allows for the inflation of coins, which remained undiscovered for four years.
Money is in assets, not in services. There is about 25 billion dollars weighted on privacy tokens. All protocols within the entire track collectively only charge around 6 million dollars in fees each year; Monero and Zcash combined have earned 3 million dollars in their entire histories; Zama has moved 595 million dollars across its borders, estimating received fees between 840 and 84,000 dollars—because it charges by bit, not by basis point.
The conclusion still leans bullish. Demand has been validated, technology is no longer a bottleneck, and the regulations starting in July 2027 will push the market towards auditable privacy. What’s missing is a price, which is the easiest problem to solve in the entire text. Therefore, this transaction should be placed on the side that dares to charge ultimately.
Where the Problem Lies: The Public Ledger Discloses What Should Not Be Disclosed
Blockchain is a shared ledger that records who owns what. Every machine in the network holds an identical copy, and each payment is written into all copies. There is no intermediary deciding what is true; anyone can verify the ledger themselves. Strangers can use it without mutual trust, relying solely on this principle.
The cost is that this ledger is open to everyone. Your account is called an address, which is essentially a long string of letters and numbers. Anyone can paste your address into a free block explorer website and read its entire history: what it holds, who it has paid, how much it paid, and at which minute. No logging in, no permission, and there is no way to opt out.

▲ A block explorer. Every address, every amount, readable by anyone, forever.
For a decade, this didn’t matter much: there wasn’t much money on-chain, and the users were all pseudonymous. Once real balance sheets enter the scene, this becomes harmful.
Consider what a public ledger actually discloses. Companies issuing salaries on-chain effectively publish their payroll. Funds holding open positions reveal their stakes, entry prices, and prices where they might get liquidated. Companies making payments to suppliers disclose their supplier lists and payment terms. Any individual holding a large balance reveals a number that makes them a potential target for theft.
Two aspects have turned this from a theoretical issue into an urgent one. First, stablecoins, which are tokens anchored to a dollar and backed by actual dollars in banks, now have significant trading volumes. Second, tokenized real-world assets—bonds, funds, and real estate in token form—are entering the market alongside regulated institutions. These users cannot accept "everyone can see the amount" as an entry condition.
So the problem is easy to articulate but hard to solve: how to hide the numbers while still allowing thousands of strangers to verify that no one is cheating?
Who is Really Paying for This: Those Whose Losses Can Be Measured in Basis Points
Privacy has always had a narrative. Surveillance is bad, freedom is good, and so on. But narratives do not sustain products. What truly changed between 2025 and 2026 is that real people started losing real money due to public ledger leaks and then came out looking to buy something.
It is not about who dislikes being surveilled, but about who the public ledger repeatedly forces to pay, and this money is exchanged for a private ledger.

▲ Who pays for privacy on-chain, plotted by how on-chain the loss is against whether anyone is paying to stop it.
Traders: Losing to their own order flow, measurable in basis points
Your trade first sits in a public queue before executing; bots see this, buy ahead of you, and then sell the execution back to you. This is called a sandwich attack. In the year ending October 2025, there were approximately 95,000 such occurrences on Ethereum, extracting around 60 million dollars, with the losses in sandwiches between 0.3% to 0.8%.
The buyers here are professional players whose losses can be quantified in basis points. Thus, privacy in this scenario sells execution quality, not belief.
Public positions on perpetual contract platforms: Exposure is ongoing
Having positions out there is worse than a sandwich attack because the exposure is continuous. Each position on perpetual contract exchanges is public, including liquidation prices, and anyone can push prices towards that. Just Hyperliquid alone had a trading volume of around 432 billion dollars in April 2026.
The platform's response is commercial, not ideological. Aster launched hidden orders, Paradex and Hibachi sell position privacy, and Zama introduced Confidential RFQ in its private testing in July 2026, which will be discussed in detail in Section 6.
Wallets with labeled tags that must sell: The strongest demand, least discussion
A fund's unlocked share is held in a specific wallet, which Arkham and Nansen have long tagged with real names, and anyone can look up the unlocking date. When money moves, the market jumps on it, and another episode happens the next quarter.
This source of revenue exists; it has just flowed to a different place. By the end of 2025, institutional spot OTC trading volume grew by 109%, while the top twenty exchanges only grew by 9%; 40% of institutions preferred OTC as their trading venue, with more than half of trades occurring off-screen. The market that can be serviced by a phone call comes from this—because public venues leak.
Strategies that can be copied: Almost no one pays for this
Copy trading tools can replicate a profitable address in several blocks, so the treasury manager's reallocation decisions do not gradually fade over weeks but die at the moment of execution. This isn’t about avoiding the government; it is about avoiding the thirteen other peers watching the same board. Almost no one pays to stop it, and that is precisely what makes this quadrant interesting.
Regulated ledgers moved to public chains: The demand is real, but it has been taken away by permissioned rails
Over 30 billion dollars of tokenized real-world assets are sitting on public chains, and banks cannot disclose their holdings in real-time. So, do banks want this stuff or not? There is one case where both directions of the answer were provided.
In November 2024, JPMorgan's blockchain division ran Project EPIC within their sandbox, based on Zama's fhEVM, demonstrated crypto-state fund subscriptions, blind-bid auctions, and direct settlement on crypto values, designed so that even JPMorgan could not see the details. But that was just a sandbox; Zama was only one of a few vendors. By the time JPMorgan actually chose a place to issue its deposit tokens in January 2026, it went to Canton, a permissioned network.
So institutional demand is real and verifiable, but what takes it away is a permissioned rail, not public blockchain cryptography.
Toolbox: Four Ways to Keep Secrets, Differentiated by Where the Secret Is Stored
Each project in this track is built on one or two of these four ideas. The real differentiator between them is simple: where the secret is stored.

▲ The four primitives, sorted by where the secret actually lives.
The cost used to be speed, which is also the fastest-obsolete part of this text. For several years, a fair critique of FHE was that it could only handle about twenty transactions per second, while ordinary chains could handle thousands. This gap has essentially closed, even faster than those doing it anticipated.
No single method can win comprehensively. Real products are a combination of two approaches: sealed chips for speed, plus a zero-knowledge receipt to prove the chip hasn't gone astray; or use FHE to store hidden states and then use zero-knowledge proofs to validate the inputs.
There’s also a fifth option, simply bypassing cryptography: only sending data to those authorized to see it. This is Canton, and it’s also why banks like it.
The First Answer: Build the Network as Private from the Beginning
The earliest attempts were designed around "hiding" to create an entire network rather than patching an existing one. There are two currencies leading in this path, but the bets are entirely opposite. The third case is made for banks, not for individuals, but belongs to the same family.
Zcash: Privacy is a switch, which has been its weakness for ten years
Zcash is its own chain, essentially Bitcoin-style digital cash with a privacy mode added. It has two types of addresses: transparent addresses that are just like Bitcoin, revealing everything; and shielded addresses that hide the sender, receiver, and amount. Moving money into the private side is called shielding (shielding), and moving it out is called deshielding (deshielding).
The hiding is done by zk-SNARK, a compact form of zero-knowledge proofs. When you spend shielded ZEC, the wallet sends a very short proof indicating that this payment reconciles and that no coin was spent twice. The machines maintaining the network verify this proof and accept it throughout, without knowing who paid whom or how much.
One design choice defined everything following: privacy is optional and can be chosen per transaction. It sounds friendly, but it is a weakness because concealment relies on having many users. If there is only you in the room wearing a mask, the mask might as well not be on. During much of Zcash's life, the majority of ZEC has remained in the transparent pool, and the private group has always been sparse.
Most people see Zcash as a single thing, but it is actually four pools. Understanding who is who requires the understanding from Section 8 to comprehend the vulnerability in 2026. The usual summary is: Sprout proved that private currency is feasible, Sapling made it usable, and Orchard eliminated the reliance on trusted setup.

▲ Zcash's shielded pools over ten years, with the shielded share below and the incidents marked.
It is worth noting about Zcash that the reason to hold it, rather than use it, is that shielded ZEC has no history. Once a coin passes through the pool, it no longer carries any trace, and every unit can interchange with others. This characteristic is called fungibility, and it is what compliance departments are really troubled by on transparent chains—on a transparent chain, you might receive a coin that had been used for crime by three prior owners and then inherit the trouble along with it.
Monero: Privacy is defaulted on; there is fundamentally no switch
Monero is also its own chain, choosing the exact opposite: there is no public mode available. Every payment is private for everyone, so there is no need for a small private pool to join—the whole chain is that group of people.
Until recently, it relied on three tools rather than zk-SNARK. Ring signatures mix real coins with decoys to hide the sender, so observers see sixteen possible sources, not knowing which one is real. Stealth addresses generate a brand-new disposable address for each payment to conceal the receiver. RingCT hides the amount.

▲ How Monero hides the sender, the receiver, and the amount.
In early 2026, Monero launched a significant upgrade FCMP++, replacing ring signatures with zero-knowledge membership proofs. The actual effect is that the group of people you have hidden has shifted from sixteen decoys to every transaction ever done on the chain, over 150 million transactions.

▲ Monero's anonymity set after FCMP++.
Canton: Nothing is hidden because nothing is shared
The third member of this family is not a coin, and as a result, it is often overlooked in privacy studies. But the largest institutional decision of 2026 fell on it, so ignoring it is a mistake.
Zcash and Monero accept the premise that "the ledger needs to be broadcasted to everyone" and then uses cryptography to hide the contents. Canton directly denies this premise. It does not have a shared ledger requiring everyone's validation. Each participant only receives their portion of the transaction they are involved in, enforced at the contract level by a language called Daml. If you are not relevant, you will never receive that data or know that the transaction occurred. A component called Global Synchronizer is responsible for sorting, confirming validity, while not seeing the content.

▲ The same three payments on a public chain and on Canton, showing who receives which rows.
So secrets are protected by "never being sent out," and the authorized viewers read the plaintext. Note that this setup doesn’t rely on any of the four tools mentioned in Section 3: no zero-knowledge proofs, no FHE, and despite long-term confusion, also no MPC. Daml claims to be a language for multi-party applications, which sounds like multi-party secure computation, but means something entirely different. Integrity relies on cryptography: each participant receives a hash, substituting for those branches that cannot be read. Confidentiality is purely a matter of "who received what."
The reversal of the verification phase is intriguing. On Ethereum, each validator reexecutes every transaction, so everyone must see everything. On Canton, the parties to the transaction verify themselves, each side only rerunning their respective branches, then voting. An arbitrator counts the confirmations, only seeing the hash. So there’s no global reexecution to catch collusion, and the comfort is that only the parties already within your contract can harm you.
JPMorgan chose it for JPM Coin, announced in January 2026, with gradual rollout throughout the year, justified by practicality rather than ideology. Privacy is defaulted on, and there’s no concern about having a large enough crowd. There’s no shared pool; Circle's case mentioned in Section 8 cannot happen here. Every participant is a legally identifiable entity, which is a hard requiremen
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。