Compliance Privacy, What is Ethereum's Latest Privacy Major Upgrade Kohaku?
On November 16, Ethereum founder Vitalik showcased Kohaku, a privacy-first tool for the Ethereum ecosystem, at Devcon 2025 in Buenos Aires, Argentina. Kohaku aims to enhance the privacy and security of the Ethereum ecosystem.
What exactly is Kohaku? How does it achieve privacy? Is privacy becoming increasingly important in the Ethereum ecosystem?
Ethereum in 2025: Increasing Focus on Privacy and Security
As early as 2023, Vitalik mentioned the "Privacy Transition" in his article on the "Three Transitions":
"Ensure privacy-protecting value transfer services and that all other tools under development (social recovery, identity, reputation) have privacy-protecting features."
"Without a privacy transition, Ethereum will fail because exposing all transactions (including POAP, etc.) for everyone to see is too much privacy loss for many users, who will turn to at least somewhat data-hiding centralized solutions."
Two months after the publication of the "Three Transitions" article, Vitalik was involved in co-authoring "How Privacy-Preserving Pool Protocols Balance Privacy and Compliance Requirements." Later, when we introduce Kohaku, we can see the practical results of Ethereum in this direction.
At the end of 2024, Vitalik published a blog post elaborating on the vision for an ideal secure wallet, once again mentioning that "Privacy and security attributes are the most valuable to focus on."
Entering 2025, Vitalik increasingly emphasizes privacy, and the Ethereum Foundation has also taken more actions in the privacy direction. In April of this year, Vitalik released a simplified version of the Ethereum L1 Privacy Roadmap.
In May, he posted on social media, stating, "Nordic countries are abandoning the push for a cashless society because they found the centralized implementation of this concept too fragile. It turns out that cash as an alternative means is necessary. Ethereum needs to have enough resilience and privacy to play a trusted role in this scenario."
On September 14, the Ethereum Foundation released an end-to-end privacy roadmap aimed at building comprehensive privacy protection for the world's second-largest blockchain. The original "Privacy and Scalability Exploratory Team" was renamed the "Ethereum Privacy Stewardship" (PSE), shifting its focus from speculative exploration to solving real problems and optimizing ecosystem outcomes.
On October 9, the Ethereum Foundation announced the formation of a Privacy Cluster, consisting of 47 top blockchain researchers, engineers, coordinators, and cryptography experts, to drive privacy-preserving features for the Ethereum network. Led by Igor Barinov, the cluster will integrate existing foundation privacy R&D projects and drive new privacy-related initiatives. On the same day, Vitalik retweeted the Kohaku roadmap, stating that full-stack privacy and security are Ethereum's top priorities.
On October 10, the Ethereum Foundation's Fund Recovery Coordinator team partnered with Keyring Network to launch a new funding mechanism to support privacy developers.
The latest and perhaps most significant development is what we saw at Devcon, the on-site demonstration of Kohaku. It's worth mentioning that in a year where Ethereum has increasingly focused on advancing privacy and security, the token that has benefited the most is likely Railgun ($RAIL), which just hit a historic high of $5 earlier this month, nearly 10 times its price from the low point in April.
What Is Kohaku?
Kohaku is an open-source project designed to enhance on-chain privacy and security. It provides a modular framework that allows developers to build secure, privacy-focused wallets without relying on centralized third-party entities.
On Kohaku's official Github page, the documentation mentions three privacy-preserving liquidity pool protocols: Railgun, Privacy Pools (in development), and Tornado (in development). These protocols enable users to securely obfuscate funds.
Kohaku may be the largest privacy upgrade solution for Ethereum to date. To better understand its workflow, here is a Kohaku workflow diagram drawn by @iamjosephyoung:

- Suppose Bob has a regular address (0xABC...); he creates a stealth key pair associated with that address
- Based on that key pair, Alice derives a completely random and one-time-use stealth address and transfers $1000 to that address
- Bob scans the network to see if the address associated with his stealth key pair has received funds
- Bob spends or claims the $1000; the one-time address expires and is no longer used
In summary, Kohaku uses a user's public key to create a temporary stealth address, allowing you to perform private operations without revealing the association with the main wallet. The stealth address is a privacy solution proposed by Vitalik (ERC-5564 standard), allowing the sender to generate a unique, one-time address for the recipient. This address is designed for a single transaction and is not reused, preventing the transaction from being traced back to the user's identity. People can only see that Alice sent money to this address, but they cannot know that behind this address is Bob, who can directly control the assets in this address through his key pair.
Unlike a mixing pool like Tornado Cash, which is shared by all users, Kohaku does not rely on mixing with other users at all. It is compliant with regulations because Bob can selectively disclose a full transaction history as needed.
Railgun even has a decentralized anti-malware transaction prevention system called "Private Proofs of Innocence," which uses only publicly available malicious address sets from the chain to prove the security of fund sources without compromising user privacy, preventing users from receiving illicit funds.
At Devcon in person, Privacy Pools (@0xprivacypools) demonstrated this feature live in a transfer.

Kohaku not only follows the compliance trend without compromising auditability but also addresses privacy needs. In the long run, this could provide an ideal option for institutions looking to transfer large amounts of funds on-chain.
You may also like

Morning Report | Kraken freezes IPO plans due to difficult market conditions; Polymarket acquires DeFi infrastructure Brahma; World launches AgentKit integrated with Coinbase

Bitmain, mired in controversy, has found its strongest backing in the United States

Full text of the Federal Reserve's decision: Maintain interest rates unchanged and expect one rate cut within the year, with Governor Mulan casting a dissenting vote

Guarding billions in assets, yet unable to sustain itself: Tally bids a dignified farewell after five years

SEC’s Stance on Crypto Assets: Most Not Considered Securities
Key Takeaways: The SEC’s new interpretation categorizes most crypto assets as non-securities under federal law. This move aims…

South Korea’s New Crypto Seizure Guidelines After Asset Mismanagement Incidents
Key Takeaways: South Korea’s National Police Agency (KNPA) has drafted guidelines for crypto seizure, with a focus on…

Institutional Confidence in Crypto’s 2026 Growth Trajectory
Key Takeaways: A significant 73% of institutional investors plan to increase their crypto holdings by 2026. Exchange-traded products…

Ethereum Reduces Bridge Times by 98% with Fast Confirmation Rule
Key Takeaways: Ethereum introduces the Fast Confirmation Rule (FCR) aiming to cut bridge times from L1 to L2…

Crypto Firms Advocate DeFi Education in US Colleges
Key Takeaways: Twenty-one crypto organizations have called on US colleges to integrate decentralized finance (DeFi) into their curricula…

RedotPay Reorganizes Amidst Funding Tries and IPO Goals
Key Takeaways: RedotPay is facing leadership changes and concerns over its connections with mainland China while eyeing a…

Bitcoin ETF Streak Nears October Highs While Inflows Lag Behind
Key Takeaways: US spot Bitcoin ETFs have continued their inflow streak for seven straight days, accumulating $1.2 billion…

Connecticut Suspends Bitcoin Depot as Revenue Prospects for 2026 Worsen
Key Takeaways: Connecticut halts Bitcoin Depot’s operations, citing regulatory breaches related to the Money Transmission Act. Bitcoin Depot…

DAO Governance Platform Tally Shuts Down Due to Market Challenges
Key Takeaways: Tally, after operating for five years, is shutting down due to a lack of viable business…

Trump Memecoin Shows Volatility Amid Mar-a-Lago Event
Key Takeaways: TRUMP memecoin holders surpassed 83 wallets with over one million tokens after a luncheon announcement with…

Bitcoin Surge in Australian E-commerce Faces Banking Hurdles: In-depth Analysis
Key Takeaways: Cryptocurrency usage in Australia for purchasing goods and services doubled from 6% to 12% in 2026.…

Meta Shuts Down Horizon Worlds VR for Mobile-Centric Strategy
Key Takeaways: Meta is transitioning Horizon Worlds from a VR to a mobile-centric platform starting June 2026. The…

Bitcoin Exchange Inflows Surge Amidst $75,000 Resistance
Key Takeaways: Bitcoin inflows to exchanges have spiked to 6,100 BTC, hinting at potential selling pressure. The large…

Bitrefill Identifies Lazarus Group Behind Cyberattack and Stolen Funds
Key Takeaways: Bitrefill suffered a cyberattack on March 1, likely orchestrated by the infamous Lazarus Group using sophisticated…
Morning Report | Kraken freezes IPO plans due to difficult market conditions; Polymarket acquires DeFi infrastructure Brahma; World launches AgentKit integrated with Coinbase
Bitmain, mired in controversy, has found its strongest backing in the United States
Full text of the Federal Reserve's decision: Maintain interest rates unchanged and expect one rate cut within the year, with Governor Mulan casting a dissenting vote
Guarding billions in assets, yet unable to sustain itself: Tally bids a dignified farewell after five years
SEC’s Stance on Crypto Assets: Most Not Considered Securities
Key Takeaways: The SEC’s new interpretation categorizes most crypto assets as non-securities under federal law. This move aims…
South Korea’s New Crypto Seizure Guidelines After Asset Mismanagement Incidents
Key Takeaways: South Korea’s National Police Agency (KNPA) has drafted guidelines for crypto seizure, with a focus on…