Skip to content

BLOCKCHAIN LAB BRIEFING · AI AGENTS

Vitalik Says He Used a Local Model, zkAPI and Tor So a Remote Model Would Not See His Data

The useful part is the failure list. He says the three layers are finally available to some extent, and then says Tor is the wrong shape for this job and the local model is too slow.

4 October 2026

All briefings

01

What happened

On 4 October 2026 @VitalikButerin posted that he was running a personal experiment: health and travel data used to produce diet and exercise recommendations, with a local model orchestrating and frontier models used only as a tool call. He names three layers. The local model, not he, writes the queries, so writing style and identifiers stay off the remote model. zkAPI is meant to stop the payment from identifying him. Tor is meant to stop the IP from identifying him. He writes that you need all three, and that they now exist at least to some extent. The snapshot, taken the same night, shows 24 reposts, 15 quotes, 98 replies and 300 likes.

He then lists the deficiencies in his own note. Tor is not optimised for dropping identity between requests, which he says is the only network privacy that makes sense now, and the latency is 10 to 100 times higher than it could be. The skill file's request construction is far from optimal. The local model runs at 20 to 30 tokens a second and would need to be past 100 to feel fast. And the more carefully you withhold data, the less the remote model can help.

02

Why it matters

This is the agent-payment problem in one person's stack. A tool call is still a disclosure. Wrapping the payment does not wrap the prompt. He says so.

It is also a concrete use of the zkAPI claim posted by newsrooms two days earlier. His post is a user report. It is not an audit of that deployment.

03

The operating layer

Anyone copying the setup still has to decide what the local model is allowed to put in the tool call. That policy is the control. The proof and the onion are the other two, and he says one of them is the weak one.

Do not ship 'we use zkAPI' as a privacy claim if the prompt contains the person.

04

What is verified

The post is from @VitalikButerin on 4 October 2026. The goals, the three layers, and the four deficiencies are in his text.

This desk has not inspected his machine or the zkAPI deployment.

05

What is still unclear

Whether the local model in fact stripped identifiers, which only he can know.

Which remote models were called.

Whether zkAPI was the Ethereum Foundation deployment or another endpoint.

06

The catch

He did not say the stack is private enough. He said Tor probably is not, and that withholding data reduces the quality of the answer. A diagram with three ticks would misquote him.

WATCH

What builders should watch

  1. 01Which zkAPI endpoint he actually called.
  2. 02The skill file, if he publishes it.
  3. 03The network layer he himself calls inadequate.
  4. 04The tradeoff he states: less data, less help.

BOTTOM LINE

Vitalik says a local model, zkAPI and Tor let him query a frontier model without handing it his health data, and then says the network layer is probably not private enough and the local model is too slow. The caveat is the result.

Sources

Blockchain Lab uses public social posts as reporting leads, not as proof. Every published briefing is assessed against primary sources, available documentation and relevant technical context. Social engagement is not used as evidence of the underlying claim.

Continue