Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ All notable changes to the EthSystems Map are documented here.

## [Unreleased]

- fix: factual audit of the [Private RWA Tokenization](use-cases/private-rwa-tokenization.md) entry and the cards one hop out. Refresh RWA market figures to rwa.xyz (29 Sep 2026) and repair moved category links; correct Merces gas, MPC model and throughput in [Private Bonds](approaches/approach-private-bonds.md) and note the Aztec Alpha V5 soundness disclosure and decentralized sequencer set; scope the no-trusted-setup claim to the PoC in both approaches and mark Fhenix CoFHE testnet-only in [Private Payments](approaches/approach-private-payments.md); fix co-SNARK threat model (a colluding coalition breaks privacy, not soundness) and licensing in [co-SNARK](patterns/pattern-co-snark.md); fix HNDL misuse and post-quantum mitigations in [ERC-3643](patterns/pattern-erc3643-rwa.md), [ZK-KYC](patterns/pattern-zk-kyc-ml-id-erc734-735.md) and [L2 Encrypted Off-chain Audit](patterns/pattern-l2-encrypted-offchain-audit.md); scope amount privacy in [Private PvP via ERC-7573](patterns/pattern-private-pvp-stablecoins-erc7573.md) to contracts running inside the shielded layer; replace dead ERC-734/735 and EAS docs links
- fix: factual audit of the private-stablecoins entry and the cards one hop out
- fix(pattern): clarify [ERC-3643 Tokenized RWAs](patterns/pattern-erc3643-rwa.md) transfer-path semantics; distinguish investor-initiated transfer checks from mint and forced-transfer paths, and separate owner and agent controls.
- fix(pattern): correct cross-chain atomicity claims. [Private PvP via ERC-7573](patterns/pattern-private-pvp-stablecoins-erc7573.md) now follows the ERC-7573 shape (one leg locked, the other paid through the decryption contract, an oracle-released key that releases or returns the locked leg) and states conditional settlement instead of "both legs settle or both revert"; the old recipe finalised one leg and then claimed both escrows revert. [Atomic DvP via ERC-7573](patterns/pattern-dvp-erc7573.md) drops the timeout reclaim that ERC-7573 does not define and names the oracle condition. [Permissioned Ledger Interoperability](patterns/pattern-permissioned-ledger-interoperability.md) states the coordinator trust assumption of two-phase commit ([#198](https://github.com/ethsystems/map/pull/198))
Expand Down
28 changes: 14 additions & 14 deletions approaches/approach-private-bonds.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: "Approach: Private Bond Issuance & Trading"
status: ready
last_reviewed: 2026-06-24
last_reviewed: 2026-09-29

use_case: private-bonds
related_use_cases: [private-corporate-bonds, private-government-debt]
Expand Down Expand Up @@ -43,7 +43,7 @@ open_source_implementations:
- url: https://github.com/AztecProtocol/aztec-packages
description: "Aztec privacy-native L2"
language: TypeScript / Noir
- url: https://github.com/0xMiden/miden-base
- url: https://github.com/0xMiden/protocol
description: "Miden client-side ZK rollup"
language: Rust
---
Expand All @@ -54,7 +54,7 @@ open_source_implementations:

### Scenario

A bank issues a EUR 100M corporate bond series with private allocation amounts to 50 institutional investors and operates an active secondary market with RFQ-based price discovery. The bank needs hidden positions and trade sizes, atomic same-chain DvP against EURC, jurisdiction-specific selective disclosure (eWpG, MiCA), and an automated 24/7 market with daily settlement.
A bank issues a EUR 100M corporate bond series with private allocation amounts to 50 institutional investors and operates an active secondary market with RFQ-based price discovery. The bank needs hidden positions and trade sizes, atomic same-chain DvP against EURC, jurisdiction-specific selective disclosure (eWpG for the bond; MiCA for the EURC leg, since bonds that are MiFID II financial instruments fall outside MiCA), and an automated 24/7 market with daily settlement.

### Requirements

Expand Down Expand Up @@ -92,7 +92,7 @@ example_vendors: [paladin, railgun]
- L1 consensus and the verifier contract
- Gas relayer for liveness on private withdrawals
- Issuer for the global-note-to-holder-notes split at issuance
- No per-circuit trusted setup (UltraHonk uses a universal KZG SRS)
- No per-circuit trusted setup in the PoC (UltraHonk uses a universal KZG SRS); Groth16-based vendors (Railgun, Paladin Zeto) rely on per-circuit setup ceremonies

**Threat model:**
- A circuit or verifier soundness bug (e.g., an under-constrained circuit) lets an attacker forge or double-spend notes; metadata leakage at deposit/withdraw boundaries is the practical privacy exposure
Expand Down Expand Up @@ -126,14 +126,14 @@ example_vendors: [aztec, miden]
**How it works:** Aztec exposes private notes and contracts as native primitives. Bond issuance, transfer, and coupon logic run in private functions with client-side proving. Incoming Viewing Keys (IVKs) provide account-level read access; nullifier keys are app-siloed for damage containment.

**Trust assumptions:**
- Sequencer for ordering (currently centralized in early deployments)
- Sequencer set for ordering (Aztec Alpha mainnet uses a staked, decentralized sequencer set; Alpha is early-stage and Aztec advises limiting deposits)
- Bridge contract for L1 settlement
- Aztec proving system soundness
- Aztec proving system soundness (a critical soundness vulnerability in the Alpha V5 proving system was disclosed on 2026-07-27)

**Threat model:**
- Sequencer outage or censorship; rollup escape paths leak linkage during forced exit
- Bridge boundary leaks deposit and withdraw amounts
- IVK compromise reveals all account-level flows
- IVK compromise reveals every note the account receives, including its own change notes; it grants no spending authority

**Works best when:**
- Bond logic is complex (coupons, lifecycle) and benefits from native privacy primitives
Expand All @@ -159,7 +159,7 @@ example_vendors: [taceo-merces]
**How it works:** Bond state lives offchain under MPC sharing; institutional senders submit shares, the committee computes the transition under MPC, and emits a co-SNARK on chain. Account-model simplicity is preserved at the application layer; addresses remain visible.

**Trust assumptions:**
- Honest-majority 3-party MPC committee (TACEO coNoir uses REP3 / 3-party Shamir, tolerating one corrupt node)
- Honest-majority 3-party MPC committee (Merces uses semi-honest 3-party replicated secret sharing, tolerating one corrupt node)
- Co-SNARK soundness
- Committee liveness

Expand All @@ -171,7 +171,7 @@ example_vendors: [taceo-merces]
**Works best when:**
- Institutional custodial models are acceptable
- Amount confidentiality is sufficient and counterparty privacy is not required
- Throughput target matches batched proving (~200 TPS, TACEO-reported)
- Throughput target matches batched proving (~200-300 TPS, TACEO-reported)

**Avoid when:**
- Honest-majority assumption among MPC nodes is incompatible with the threat model
Expand All @@ -198,9 +198,9 @@ example_vendors: [zama, fhenix]
- ACL model adoption by all bond participants

**Threat model:**
- Threshold compromise reveals ciphertexts
- Compromise of the threshold network above its threshold decrypts all ciphertexts
- No revocation per ciphertext; revocation requires a re-encryption / re-grant on balance update
- Shared throughput (500-1000 TPS, vendor-reported) is a network-wide bottleneck
- Shared per-chain throughput (over 20 TPS on CPU; 500-1000 TPS projected with GPUs by end-2026, vendor-reported) is a bottleneck

**Works best when:**
- Bond logic involves complex calculations (coupon accruals, derivatives) that map naturally to FHE
Expand All @@ -220,7 +220,7 @@ example_vendors: [zama, fhenix]
| **CROPS** | CR:hi O:y P:full S:hi | CR:med O:part P:full S:med | CR:med O:part P:part S:med | CR:med O:part P:part S:med |
| **Trust model** | Self-custody (L1 + ZK) | Sequencer + bridge | Honest-majority 3-party MPC | t-of-n threshold network |
| **Privacy scope** | Amounts + addresses (via gas relayer) | Amounts + addresses (account level) | Amounts only; addresses public | Amounts only; addresses public |
| **Performance** | High gas, chain-dependent throughput | L2-internal fees, unknown TPS | ~95K gas/tx batched, ~200 TPS (vendor) | ~300K gas/tx, 500-1000 TPS shared (vendor) |
| **Performance** | High gas, chain-dependent throughput | L2-internal fees, unknown TPS | ~0.9M gas per transfer intent plus ~3.8M per 50-tx batch, ~200-300 TPS (vendor) | ~300K gas/tx, 20+ TPS shared, 500-1000 projected (vendor) |
| **Operator req.** | No (gas relayer optional) | Yes (sequencer) | Yes (MPC committee) | Yes (threshold network) |
| **Cost class** | High (L1 verify) | Low (L2-internal) | Low (batched) | Medium |
| **Regulatory fit** | Strong (per-note view keys) | Strong (IVKs, app-siloed nullifiers) | Strong for known counterparty | Strong (per-balance ACL) |
Expand All @@ -230,7 +230,7 @@ example_vendors: [zama, fhenix]

### Business perspective

For institutional bond issuance and trading at scale, UTXO Shielded Notes is the default: production maturity (Railgun ~USD 5b lifetime shielded volume as of 2026), white-label vendor coverage (Paladin), privacy over amounts, counterparties, and addresses (addresses via gas relayer), and a regulatory story built on per-note viewing keys that maps cleanly onto eWpG and MiCA disclosure regimes. Privacy L2 fits where bond logic is complex (coupons, structured lifecycle) because it removes circuit-engineering work, but the issuer must accept the rollup's decentralization timeline. co-SNARKs and FHE fit specific institutional contexts: bilateral or club-mode markets where address visibility is acceptable, or coupon-heavy products where homomorphic arithmetic is the natural model.
For institutional bond issuance and trading at scale, UTXO Shielded Notes is the default: production maturity (Railgun ~USD 5b lifetime shielded volume as of 2026), white-label vendor coverage (Paladin), privacy over amounts, counterparties, and addresses (addresses via gas relayer), and a disclosure story built on per-note viewing keys that can be assessed against eWpG (and MiCA for the EURC leg). Privacy L2 fits where bond logic is complex (coupons, structured lifecycle) because it removes circuit-engineering work, but the issuer must accept the rollup's decentralization timeline. co-SNARKs and FHE fit specific institutional contexts: bilateral or club-mode markets where address visibility is acceptable, or coupon-heavy products where homomorphic arithmetic is the natural model.

### Technical perspective

Expand All @@ -244,7 +244,7 @@ This is a perspective for legal review by the deploying issuer, not legal advice

### Default

For institutional bond issuance and trading on a 1-2 year production timeline, default to UTXO Shielded Notes with [Paladin](../vendors/paladin.md) or [Railgun](../vendors/railgun.md) as the underlying shielded pool. This is the category with documented production volume, vendor coverage, and a disclosure interface that has been mapped onto eWpG / MiCA expectations.
For institutional bond issuance and trading on a 1-2 year production timeline, default to UTXO Shielded Notes with [Paladin](../vendors/paladin.md) or [Railgun](../vendors/railgun.md) as the underlying shielded pool. This is the category with documented production volume, vendor coverage, and a per-note viewing-key disclosure interface that can be assessed against eWpG expectations.

### Decision factors

Expand Down
21 changes: 13 additions & 8 deletions approaches/approach-private-payments.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: "Approach: Private Payments"
status: ready
last_reviewed: 2026-09-18
last_reviewed: 2026-09-29

use_case: private-stablecoins
related_use_cases: [resilient-disbursement-rails, private-treasuries]
Expand Down Expand Up @@ -40,6 +40,10 @@ pocs:
sub_approach: "Stateless Plasma"
spec: pocs/private-payment/plasma/SPEC.md
status: benchmarked
- name: "Resilient Disbursement Rails"
sub_approach: "Resilient Disbursement Rails"
spec: pocs/private-payment/resilient-disbursement-rails/SPEC.md
status: implemented

open_source_implementations:
- url: https://github.com/Railgun-Privacy/contract
Expand Down Expand Up @@ -105,7 +109,7 @@ example_vendors: [railgun]

- L1 consensus and the verifier contract
- Gas relayer is willing to relay (liveness only; not custodial)
- No per-circuit trusted setup (UltraHonk uses a universal KZG SRS)
- No per-circuit trusted setup in the PoC (UltraHonk uses a universal KZG SRS); Groth16-based vendors (Railgun, Paladin Zeto) rely on per-circuit setup ceremonies

**Threat model:**

Expand Down Expand Up @@ -155,11 +159,11 @@ example_vendors: [aztec, fhenix]

**Summary:** Confidential transfers run inside a privacy-native rollup where state is hidden by default at the protocol layer.

**How it works:** Users post transactions with client-side zero-knowledge proofs to a privacy-native sequencer (Aztec) or use FHE-based confidential balances (Fhenix). Hidden state, encrypted memo, and account-level viewing keys give institutional readers controlled access. Bridging to L1 is the privacy boundary.
**How it works:** Users post transactions with client-side zero-knowledge proofs to a privacy-native sequencer (Aztec) or use FHE-based confidential balances computed by a coprocessor on an existing EVM chain (Fhenix CoFHE, testnet only). Hidden state, encrypted memo, and account-level viewing keys give institutional readers controlled access. Bridging to L1 is the privacy boundary.

**Trust assumptions:**

- Sequencer for ordering (currently centralized in early deployments)
- Sequencer set for ordering (centralized on most privacy L2s; Aztec runs a permissionless staked sequencer set)
- Bridge contract for L1 settlement integrity
- Viewing-key custody at the institution

Expand Down Expand Up @@ -219,7 +223,7 @@ poc_spec: pocs/private-payment/plasma/SPEC.md
- User-side state custody is operationally infeasible
- Exit-delay risk is not tolerable for the asset class

**Implementation notes:** PoC uses Plonky2 with operator-side recursive aggregation; client proofs run in 5.9-9.8s, operator proofs in 42-49s. PlasmaBlind (folding-scheme aggregation) is a tracked alternative.
**Implementation notes:** PoC uses Plonky2 with operator-side recursive aggregation; client proofs run in 5.9-9.8s, operator proofs in 38-49s. PlasmaBlind (folding-scheme aggregation) is a tracked alternative.

#### Benchmarks

Expand All @@ -230,7 +234,7 @@ poc_spec: pocs/private-payment/plasma/SPEC.md
| Gas: withdraw | ~343K (operator, amortized) |
| Gas: batch | ~255K (operator, amortized) |
| Proof gen (client) | 5.9-9.8s |
| Proof gen (operator) | 42-49s |
| Proof gen (operator) | 38-49s |

### TEE-Based Privacy

Expand Down Expand Up @@ -325,6 +329,7 @@ uses_patterns:
pattern-forced-withdrawal,
pattern-verifiable-attestation,
]
poc_spec: pocs/private-payment/resilient-disbursement-rails/SPEC.md
example_vendors: []
```

Expand Down Expand Up @@ -363,7 +368,7 @@ example_vendors: []

| Axis | L1 Shielded | Privacy L2 | Stateless Plasma | TEE | MPC | Resilient Disbursement |
| ------------------ | --------------------------------------- | ----------------------------------- | ---------------------------------------------------- | -------------------------------- | ----------------------------------- | -------------------------------------------------------- |
| **Maturity** | prototyped | prototyped | prototyped | documented | prototyped | documented |
| **Maturity** | prototyped | prototyped | prototyped | documented | prototyped | prototyped |
| **Context** | both | both | both | i2i | i2i | i2u |
| **CROPS** | CR:hi O:y P:part S:hi | CR:med O:part P:full S:med | CR:med O:part P:full S:med | CR:med O:no P:full S:lo | CR:med O:part P:part S:med | CR:hi O:y P:full S:hi |
| **Trust model** | L1 + relayer liveness | Sequencer + bridge | Operator + L1 anchor | TEE vendor + supply chain | Honest-majority MPC | Multi-relay + smartcard + IResilientIdentity |
Expand Down Expand Up @@ -392,7 +397,7 @@ This is a perspective for legal review by the deploying institution, not legal a

### Default

For institutional treasury and payment operations at moderate volume with standard compliance, default to a Hybrid L1/L2 composition: Privacy L2 (Aztec for native confidential transfers, Fhenix for FHE-based balances) handles frequent operations; L1 Shielded Payments (Railgun-style) handles high-value transfers or anonymity-sensitive flows. Selective disclosure runs through user-controlled viewing keys plus regulator viewing keys with time-bound, threshold-controlled scope. ISO 20022 message interpreters handle SWIFT compatibility; ERC-3643 handles compliance gating where the asset is a regulated security.
For institutional treasury and payment operations at moderate volume with standard compliance, default to a Hybrid L1/L2 composition: Privacy L2 (Aztec for native confidential transfers, Fhenix CoFHE for FHE-based balances once it leaves testnet) handles frequent operations; L1 Shielded Payments (Railgun-style) handles high-value transfers or anonymity-sensitive flows. Selective disclosure runs through user-controlled viewing keys plus regulator viewing keys with time-bound, threshold-controlled scope. ISO 20022 message interpreters handle SWIFT compatibility; ERC-3643 handles compliance gating where the asset is a regulated security.

### Decision factors

Expand Down
Loading
Loading