Privacy That Protects and Privacy That Launders: zk-Mixers, Private Swaps, and Systemic Contagion in Decentralized Finance
Abstract
Zero-knowledge privacy protocols let users hide transaction details on public blockchains. Systems like Tornado Cash, FixedFloat, and the Houdini Private Swap feature recently added to Jumper rely on cryptographic techniques that unlink sender and receiver addresses. These constructions give legitimate users meaningful protection for their financial activity. They also create a straightforward dual-use dilemma. The February 2025 Bybit incident supplies a clear example. Thieves stole $1.5 billion in ETH, the largest cryptocurrency theft on record. The FBI linked the attack to North Korea’s Lazarus Group. The stolen funds moved quickly through Tornado Cash. The resulting lack of transparency triggered a wave of customer withdrawals. Bybit responded by securing loans of several hundred million dollars from other institutions to keep its operations running. Cases like this demonstrate that zk-based privacy tools, when used at large scale for illicit purposes, can accelerate liquidity crises and place costs on market participants who had no involvement in the original theft. The real problem is not the underlying mathematics that delivers privacy. It lies in the missing mechanisms that could impose accountability on criminal actors while leaving the privacy protections for everyone else intact.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.