Why
Institutional privacy converged on one shape in 2026 — Tessera on Sui, XRPL's confidential transfers, Circle's Arc Privacy, Canton, Midnight — and the shape is: encrypt the value, publish the graph. Sui states it without hedging in its own announcement: the chain shows who paid whom and when, and the amount appears as ▦▦▦. That is offered as the harmless half. This card asks whether it is.
In B2B settlement the commercially sensitive facts are often structural rather than numeric. Who your suppliers are, which relationships are contractual and which are one-off, when a contract started or stopped, whether you have begun paying late. A competitor does not need your invoice value to see that you onboarded a supplier last month and dropped another one. And the asymmetry is worse than it looks — an amount that leaks is one number, while a published graph edge cannot be un-published, and the graph compounds as every later payment adds to it.
The point is not that the cryptography is weak. Twisted ElGamal over Ristretto255 with zero-knowledge proofs does exactly what it claims. The point is that the thing left in the clear was chosen for a technical reason, not a privacy one — the chain must still name the accounts whose ciphertexts it updates.
Which makes it a real trilemma rather than a gotcha, and worth stating as one. Hiding the graph too means a shielded-pool design, which breaks exactly the auditability institutions are buying. Canton is the comparison arm precisely because it resolves it differently, keeping the graph off the public ledger at the cost of being a permissioned network. There is no free corner here.
The other half of the card is the tool that answers a different question entirely, and it is the one problem in this catalogue that cryptography solves and a blockchain does not. On-chain work makes data public and verifiable; a clean room needs the opposite — compute over data that never becomes readable, so two parties learn a joint result without either seeing the other's input. The reference case is a hospital or registry collaboration where the legal constraint is that raw records cannot leave the owner at all. Worth understanding as a distinct tool rather than assuming encryption-at-rest covers it, and worth doing hands-on rather than surveying, because the two numbers that decide its usability are latency and ciphertext size and neither is knowable from a paper.
And the trust model deserves the same scepticism as the cryptography. Seal grants scoped, time-limited, revocable access to regulators, tax authorities and dispute arbiters, which is the right shape for compliance; network operators can onboard, freeze accounts, or pause the network. Both are sensible. Both also mean the confidentiality is conditional on whoever holds the threshold shares — worth recording next to third-party-blast-radius, because a privacy guarantee an operator can revoke is a policy, not a cryptographic property.
How it works
Two opposite tools, and the question each answers
| Confidential settlement (Tessera, XRPL, Arc) | FHE clean room | |
|---|---|---|
| What is hidden | The value | The inputs, permanently |
| What is published | Sender, receiver, timestamp | A joint result only |
| Answers | Can a public ledger carry commercial payments? | Can two parties compute without either seeing the other's data? |
| The constraint it respects | Auditability | Raw records cannot leave the owner at all |
| The number that decides it | What the graph still leaks | Latency and ciphertext size |
The attack, and it runs entirely on synthetic data
Build a B2B payment graph with realistic structure, publish only sender, receiver, timestamp — no amounts, not even ranges — then recover what you can:
| Inference | The signal it comes from |
|---|---|
| Contractual versus one-off relationships | Interval regularity |
| Contract initiation and termination | Edge start and stop dates |
| Counterparty importance ranking | Frequency |
| Financial distress | Cadence slippage — arrives before any public filing |
The output is a number rather than an opinion: what share of those inferences is recoverable, at what accuracy, with zero value data.
The trilemma, stated as one
| Design | Graph hidden? | Value hidden? | Auditable? | Cost |
|---|---|---|---|---|
| Public chain, plaintext | No | No | Yes | No confidentiality |
| Confidential transfers (Tessera et al.) | No | Yes | Yes | The graph compounds forever |
| Shielded pool | Yes | Yes | No | Breaks what institutions are buying |
| Canton | Yes | Yes | Yes | Permissioned network |
There is no free corner. Saying so is more useful than scoring points against any one design.
The trust model, which is the second half of the guarantee
| Capability | Held by | What it means |
|---|---|---|
| Seal access grants | Regulators, tax authorities, arbiters | Scoped, time-limited, revocable — the right shape for compliance |
| Account freeze, network pause | Network operators | Sensible operationally |
| Threshold shares | Whoever holds them | The confidentiality is conditional on them |
A privacy guarantee an operator can revoke is a policy, not a cryptographic property — the same question third-party-blast-radius asks of any threshold scheme, and the same one that decides whether build-rent-or-own-the-rail's consortium ledger can keep a bank's counterparties from its competitors.
The FHE half, done as a measurement rather than a survey
One library, one aggregate — a sum or a count over encrypted inputs — end to end, and record two numbers: latency and ciphertext size. Those decide whether a clean room is a product or a paper. The reference case stays a hospital or registry collaboration, because that is where the legal constraint is absolute rather than commercial: the raw records cannot leave, at any price.
Privacy as a feature, privacy as an architecture
EIP-8182 proposes a protocol-level shielded pool — private ETH and ERC-20 transfers with no dedicated wallet, no separate app, nothing for a user to opt into beyond the transaction they were already sending. It targets Hegotá, and it is one of 66 proposals with only a single one confirmed so far, so it is a candidate rather than a plan.
Where it meets this card is one line: the placement of privacy decides whether it survives.
- Privacy as a feature sits beside the ledger. A shielded pool, a mixer, a separate chain. It gets absorbed, and the mechanism is always the same three things: it competes on UX against a transparent default that is one click cheaper, its anonymity set is only as large as its own adoption, and every surrounding tool — explorers, compliance vendors, bridges, wallets — is built for the transparent side. Aztec is the reference case.
- Privacy as an architecture removes the thing that leaks. Canton has no global ledger: a participant sees only the sub-transactions it is party to, so there is no public graph to correlate against. Nothing had to be hidden, because nothing was ever published.
Putting the shielded pool in the base protocol rather than in a wallet is the first serious attempt to move Ethereum from the first column toward the second. Whether it lands is exactly this card's test, applied to a new subject: the pool hides amounts — does it hide the graph? A shielded pool with a thin anonymity set and public deposit and withdrawal edges still publishes who paid whom and when, which this card argues is the half worth hiding.
So the thing to read for in the EIP text, before adopting the framing: whether 8182 shields the edges or only the values, and what the anonymity set is at the moment of a given transfer rather than in aggregate over a year.
The scale numbers, and the one that is double-counted
Canton is worth stating in figures precisely because the privacy-first design is not a research artifact: roughly $300B in daily volume, DTCC same-day settlement of treasuries and equities, JP Morgan and HSBC in live production. That is a different order of magnitude from the chains this catalogue usually measures, and it was built by not having the global public ledger everything else starts from.
One quoted number needs the gross-over-net treatment before it is repeated. The $8T-per-month repo figure is a flow inflated by overnight re-booking: an overnight repo re-books every day, so a month of the same principal counts roughly twenty times. The comparable figure is net outstanding, and it is not the one being quoted. Same rule as the recycling multiple, in a different market: when a headline is a flow, ask what the stock is.
Notes — discussion (2026-09-03)
The word "graph", and the easiest version of the card
"Graph" here is not a chart. It is the network sense: dots and connections — dots are companies (accounts), a line between two dots is "A paid B on this date." Draw every payment ever made and you get a web of who-is-connected-to-whom. That web is the payment graph.
The easiest version of the whole card: imagine your bank statement published with every amount blacked out. Still visible: you pay a divorce lawyer weekly, you stopped paying your gym, you started paying a hospital, and your rent — always the 1st — now lands on the 9th. No numbers anywhere, and your whole life is exposed. Swap "you" for a company: a new monthly payee is a signed contract, a stopped one is a dropped supplier, and slipping cadence is cash trouble visible to the world before any filing. The 2026 confidential-settlement chains publish exactly that blacked-out statement, for every participant, forever. Hiding the number is the easy half; the connection pattern is the half that leaks — and the half they publish.
Why this card exists now — the incidents next door
For these exact products there has been no accident yet — they are months old. The card exists because the same accident already happened in every neighboring system:
- The chain-analysis industry is the standing proof. Chainalysis, Elliptic and TRM built a billion-dollar business on nothing but graph analysis — it caught Silk Road's operator, clawed back the Colonial Pipeline ransom (2021), and traced Mt. Gox coins for a decade. The connection pattern identified people when nothing else did.
- Mixers proved the leak twice. Tornado Cash existed because the graph leaks; then researchers deanonymized users anyway via deposit-withdrawal timing correlation — the pool hid values, the boundary edges gave people away.
- Finance already trades on pattern-without-the-number. The alternative-data industry sells card-spend cadence and satellite photos with no revenue figures attached, and it moves markets; Dun & Bradstreet has scored companies on payment lateness for a century. Publishing the graph on-chain is the same data minus the paywall — the card is not discovering a new risk, it is un-pricing an existing intelligence product.
- The classic precedent is the metadata debate: "we only collect metadata" was answered by a former NSA/CIA director with "we kill people based on metadata." Who-whom-when was enough. This card is that sentence applied to B2B payments.
Why 2026: this is the first year institutions are putting real supply-chain payments on public rails, and vendors shipped "amount hidden, graph visible" within months of each other, marketing the visible half as harmless. The card runs the accident in a lab, on synthetic data, so the leak has a number before the first scandal instead of in its post-mortem.
Discussion threads (2026-09-03)
- Circularity warning for the attack experiment. The graph is synthesized with structure (tiers, net-30, churn) and then that structure is "recovered" — generator and attacker share assumptions. Hold out generator parameters the attacker does not know, and sanity-check a few inferences against one real public payment graph (stablecoin B2B flows are observable today), before quoting the recovery percentage.
- The trilemma's "auditable" column conflates two demands. Public verifiability (anyone checks supply and finality) and scoped auditability (a regulator with a key checks my account) are different things, and institutions mostly need the second. Viewing-key designs and Canton both deliver scoped audit; what forces the graph into the clear is public verifiability specifically — a public validator set must name the accounts whose ciphertexts it updates. That is why Canton, which gave up public verifiability rather than auditability, escapes.
- Expect the FHE measurement to indict FHE and acquit the problem. One sum over encrypted inputs will come back usable; anything past aggregates will not — and deployed clean rooms (ads measurement, health registries) mostly run MPC or TEEs for exactly the two numbers this card measures. Worth pre-registering the follow-up: same aggregate, three tools — FHE vs MPC vs TEE — same two numbers plus a trust-model row. FHE's answer to "who must you trust" is the cleanest; that is what the latency buys.
- Boundary edges deserve equal billing in the EIP-8182 test. "Does it shield the edges or only the values" is the right question, and deposit/withdrawal edges at the pool boundary plus thin-set timing correlation are how every prior pool was actually broken — read for those before the anonymity-set-in-aggregate number.
- Jayverse design rule that falls out of this card: the planned Intra Jayverse Bridge is bookkeeping over a shared vault — an internal ledger with no public graph, Canton's shape in miniature. The moment any Jayverse service settles per-transaction on public rails, its payment cadence to facilitators and counterparties becomes a published edge. Batch and net before touching the public chain.