Privacy Center

The cryptography, the science, and the vision behind STRK20 — and why it matters for your portfolio

Privacy is a design choice, not a guarantee

Veilfolio uses STRK20 to give each execution context its own veil of privacy — while the Starknet layer beneath it was designed by the people who invented modern zero-knowledge proofs.

The Vision Behind the Layer

Starknet was built by the co-founder of Zcash

Eli Ben-Sasson — a proof theorist trained at the Hebrew University, MIT, Harvard and Princeton — co-founded Zcash, the first major privacy coin, before founding StarkWare and co-inventing the STARK proof system that Starknet runs on. His life's work: using brilliant math to reconcile personal privacy with institutional integrity.

“Public-by-default was a design shortcut, not a design goal. Traders shouldn’t have to publish their entire strategy or compromise their right for anonymity just because they want to participate in a market.”
— Eli Ben-Sasson (@EliBenSasson)

Veilfolio is the practical expression of that position: isolate your trading, DeFi and long-term holdings into separate private identities, and stop publishing your strategy by default.

The Math of Privacy: STARK Proofs

Zero-knowledge proofs, without trust

A zero-knowledge proof lets you convince an on-chain verifier that a statement is true without revealing what the statement is about. STARKs — Scalable Transparent ARguments of Knowledge — are the generation of proofs Ben-Sasson and colleagues introduced in 2018. They were deliberately designed with four properties:

  • +Transparency. No trusted setup. No secret "toxic waste" parameters that could be exploited. Public randomness only.
  • +Post-quantum assumptions. Built on collision-resistant hash functions, not elliptic-curve pairings.
  • +Scalability. Proofs verify in polylogarithmic time — a fraction of the cost of re-running the computation.
  • +Soundness. The math behind them, called FRI, let Starknet compress months of transactions into one proof that settles on Ethereum.

In the words of the 2018 paper that started it all: “Human dignity demands that personal information be hidden from the public — but veils of secrecy designed to preserve privacy may also be abused.” ZK proofs enforce one without conceding the other.

Where the graph happens

WALLET → STRK20 POOL (PUBLIC DEPOSIT)

          ↓ (funds become shielded notes)

POOL → PRIVATE OPS (ZK-PROVEN, UNLINKABLE)

          ↓ (proof > trust)

POOL → WALLET (PUBLIC WITHDRAWAL)

Every shielded balance and private transfer you see in Veilfolio is a set of cryptographic notes and nullifiers, validated on Starknet by STARK-proof-backed transactions.

Post-Quantum Security: Built-In, Not Bolted On

Why quantum computers threaten most chains

Most blockchains secure their signatures and proofs with elliptic-curve cryptography. Shor’s algorithm — the kind of program a sufficiently large quantum computer would run — can break elliptic-curve and pairing-based schemes outright. That is why StarkWare’s CEO calls the industry’s inaction “ironic for an industry born from rejecting legacy systems”: the quantum-resistant tools have existed for decades.

Where Starknet already holds

STARKs run on hash functions, not elliptic curves. Quantum computers can attack hashes only with a quadratic speedup (Grover’s), which is far from the exponential break that Shor’s delivers on curves. This is structural: the proving layer runs on post-quantum-secure assumptions, which is why cryptography researchers describe STARKs as “the most scalable, safe, and secure post-quantum cryptography.”

The roadmap to hardening

StarkWare published a three-step quantum-resistance roadmap for Starknet (June 2026): first, replace the Pedersen hash with a quantum-resistant hash and add quantum-resistant signatures; second, build migration tools so existing contracts move automatically; third, coordinate the parts that depend on Ethereum’s own upgrade path. Ben-Sasson is blunt about timing: switching a live chain is like “replacing an airplane’s engine mid-flight” — you start planning long before the threat arrives.

For Veilfolio this means your identities, shielded notes and privacy operations inherit a post-quantum posture at the layer that matters most. Like every Ethereum L2, the last-mile deposit from L1 still signs with ECDSA today — the industry-wide migration we are actively tracking.

Cairo: Programs That Prove Themselves

Starknet's smart contracts are written in Cairo — a language built by StarkWare specifically so that programs can generate a STARK proof of their own execution. The Cairo Book puts it elegantly:

“Just as C.S. Lewis defined integrity as doing the right thing, even when no one is watching, Cairo enables programs to prove they’ve done the right computation, even when executed on untrusted machines.”
— The Cairo Book

Veilfolio's smart contracts — the IdentityManager and the Anonymizer — are written in Cairo 2024_07 and deployed on Sepolia. Your identity records, their activation state and your shielded operations are all provable programs in that language.

The Privacy Model, In Practice

Entry and Exit

When you fund an execution identity:

WALLET → STRK20 POOL (PUBLIC)

          ↓ (funds enter pool)

POOL → EXECUTION CONTEXT (SHIELDED)

Private Operations

Once funded, your identity can:

  • +Send private transfers to other STRK20-shielded recipients
  • +Interact with private DeFi (where supported)
  • +Execute proof-backed privacy transactions
  • +Maintain separate strategy activity from other identities

Withdrawal

When you withdraw from an identity:

CONTEXT → STRK20 POOL (UNSHIELD)

          ↓ (funds exit pool)

POOL → WALLET (PUBLIC)

Exactly What “Private” Means Here

Shielded Inside the Pool

  • +Sender identity — hidden inside the pool
  • +Recipient identity — private transfer destinations
  • +Transaction amounts — shielded within the privacy pool
  • +Token information — hidden for pool-internal transfers
  • +Transaction details — private to other users and observers

Public on the Blockchain

  • !Deposit transactions — ERC-20 transfer to the pool is public
  • !Withdrawal transactions — ERC-20 transfer to wallet is public
  • !Deposit amounts — funding transactions show amounts
  • !Block-level metadata — timing correlations are possible
  • !Network metadata — IP addresses and node-level information

What Veilfolio Stores

Stored Locally (In Your Browser)

  • +Execution identity configuration
  • +Your portfolio organization
  • +Transaction history (your local record)
  • +Account preferences

We NEVER Store Server-Side

  • -Private keys
  • -Viewing keys or proving secrets
  • -Raw note data
  • -Wallet recovery information
  • -Secret seed phrases

Privacy Limitations, Stated Honestly

What Veilfolio Cannot Protect Against

  • -Wallet compromise — all execution contexts are exposed
  • -Browser compromise — malware can observe your activities
  • -User-initiated linking — voluntarily connecting identities
  • -Timing analysis — sophisticated observers may correlate transactions
  • -IP-level tracking — network metadata can be observed
  • -ERC-20 deposit/withdrawal correlation — public blockchain links

What Comes Next

Native STRK20 Private Sub-Accounts

  • +Protocol-level private sub-account management
  • +Deeper separation of execution contexts
  • +Reduced deposit/withdrawal correlation risk
  • +Improved privacy without changing your experience

The Road Ahead on Starknet

  • +Confidential institutional rails — EY Nightfall brought private-by-default payments, treasury and DeFi to Starknet (2026)
  • +Post-quantum hardening — StarkWare’s roadmap replaces Pedersen hashing and adds quantum-resistant signatures
  • +Asset-level privacy — STRK20 extends the standard so balances and transfers stay confidential by default when you choose them
  • +A world demanding more privacy — the direction Ben-Sasson has charted since Zcash

Sources & Further Reading