
The analytics platform extends its transparency methodology to privacy solutions on Ethereum.
AI-generated summary
L2BEAT is an analytics platform specializing in evaluating the decentralization of layer 2 solutions on Ethereum. It uses a methodology based on the analysis of confidence hypotheses.
From layer-2 to confidentiality protocols. The L2BEAT platform has just put a new section online which evaluates each confidentiality protocol according to several criteria. The analysis platform, which has become the unofficial arbiter of the decentralization of Ethereum rollups, here applies the method that has made its reputation: breaking down the trust hypotheses instead of distributing labels.
Tired of rankings by TVL, volume or other metrics that are not always relevant, L2BEAT offers a technical approach, analyzing the heart of the protocols, their decentralization and the compromises induced by their structure.
Key Points
L2BEAT now rates each privacy protocol against five distinct adversary profiles, with no single overall score
The grid goes from the passive observer of the blockchain to the state adversary capable of constraining an operator
No protocol protects against all five: Zcash, Privacy Pools or Railgun assume different trade-offs
The platform uses the Stages method which had pushed Ethereum rollups to reduce their administrative powers
L2BEAT passes confidentiality protocols through the sieve of five adversaries
L2BEAT has built its reputation by refusing the ease of classification by TVL or volume. Initially, the platform made it possible to compare the different layer-2 solutions on Ethereum. Its risk rosettes and its L2 progression scale in three levels, from Stage 0 to Stage 2, have forced Arbitrum, Optimism and their competitors to publicly document the building blocks of their infrastructure. Their emergency keys, the composition of their security tips and their withdrawal times, everything is scrutinized. Now, the platform wants to apply the same approach to an even more obscure area: privacy solutions.
Indeed, not all privacy solutions are equal. Not all have the same approaches and degrees of confidentiality. Thus, a mixer can blur the link between a deposit and a withdrawal for those who simply read the chain. However, the mixer can deliver the user's IP address to the RPC provider who relays his transaction, shattering the attempt at confidentiality.
In order to measure these different solutions, L2BEAT has identified five attacker profiles which range from the most banal to the best armed:
the passive observer, who only uses the chain’s public data;
the counterparty of the transaction, who already knows part of the context;
the infrastructure operator (relayer, sequencer, RPC node), who sees the metadata pass;
the protocol team, often holding update keys or a secret from the trusted setup, this ceremony for generating the initial parameters of a proof system;
the state adversary, capable of coercing an operator, assigning a host and correlating network traffic.
Currently, no protocol checks all five boxes. Zcash’s shielded pool is very resistant to on-chain analysis and much less resistant to targeted network surveillance. Systems built on sets of associations, Privacy Pools in the lead, assume to leave a door open to verifying the origin of funds. Arranging these different solutions in the same classification finally makes the comparison possible for a user who has neither the time nor the skills to audit a cryptographic circuit.
Aztec, Zcash, Kohaku: crypto confidentiality has changed scale
The calendar is not trivial. At the start of the year, Vitalik Buterin published the Ethereum roadmap for 2029. This reaffirms the desire to bring native confidentiality to Ethereum.
Confidentiality also seems to be at the heart of user needs. Thus, we have seen several recent increases in the price of Zcash, notably driven by the influx of funds into its shielded pool. Aztec opened its public testnet after seven years of work on zero-knowledge proofs. Railgun, Privacy Pools and a series of younger projects are now competing for users who had no serious tool to decide between their respective guarantees.
Legal pressure is also increasing. Indeed, the European anti-money laundering regulation will prohibit digital asset service providers from maintaining anonymous accounts and treating cryptocurrencies with confidentiality from July 2027. In the United States, OFAC removed Tornado Cash from its blacklist in spring 2025, but the partial verdict against its developer Roman Storm keeps the criminal threat above code authors. Knowing precisely against which adversary a protocol protects ceases to be a cryptographer's vanity.
L2BEAT is already inviting the teams concerned to challenge their ratings on its Discord, exactly as it did for rollups. Several chains then provided their evidence of fraud and reduced their administrative powers to obtain Stage 1, under the gaze of a dashboard consulted by the entire ecosystem. Applied to confidentiality protocols, the same mechanism will force each team to write in black and white the exact limits of what they promise.
AI outlook — possibilities, not facts
Protocol teams will contest their ratings on the L2BEAT Discord.
Likely · Within weeks

A flaw in Limit Break’s Payment Processor V2 allowed the theft of thousands of NFTs. White hat 0xQuit was able to secure 23,155, but 660 WETH remains lost. Users are asked to revoke their permissions on vulnerable contracts.

The Services and Payment Agency confirms a data leak via fraudulent access to a user account on August 27, 2026, detected the next day. More than 143,000 people would be affected according to FrenchBreaches, with 2023-2024 payment notices from the Île-de-France “Coup de Pouce Energie” system containing names, addresses, IBAN/BIC, beneficiary numbers and amounts paid. This is the second such leak at ASP in five months.

China opened an investigation in late September 2026 into DeepSeek and Moonshot AI after Anthropic's accusations of allegedly using fraudulent accounts to train their models on Claude's responses. CAC investigators are seeking to determine whether sensitive Chinese data was transferred to U.S. servers, rather than focusing on alleged technological theft to the detriment of Anthropic.

Ukraine's Ministry of Digital Transformation gains access to Daybreak, OpenAI's cybersecurity tool powered by GPT-5.6 Sol, to audit its aging infrastructure in the face of Russian attacks.

Cardano joins the x402 protocol, enabling automated payments for AI agents and online services. The official TypeScript kit now supports ADA and native tokens, although usage is currently limited to the staging network.

More than 52 bitcoins from the Coldcard wallet hack were transferred to a legal trust in Wyoming to be returned to their owners, after being sheltered by ethical hackers.