Skip to content

LibraryPrivacy2023Design paperCorpus record

Privacy pools: association-set proofs for compliant withdrawals

Privacy Pools. Vitalik Buterin, Jacob Illum, Fabian Schär, Ameen Soleimani and others.

The privacy-pools paper proposes that a withdrawal prove membership in an association set that has excluded known bad deposits, so privacy and a blocklist are both explicit.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

The privacy-pools paper proposes that a withdrawal prove membership in an association set that has excluded known bad deposits, so privacy and a blocklist are both explicit.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
1

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    A pool that hides all history and a pool that hides history inside an association set are different products. The set is the policy.

  2. Claim 02 · Paper model

    The proposal

    The privacy-pools paper proposes that a withdrawal prove membership in an association set that has excluded known bad deposits, so privacy and a blocklist are both explicit.

  3. Claim 03 · Paper model

    The mechanism

    Users deposit into a pool. A withdrawal proves the note is in a chosen association set, not merely in the whole pool.

  4. Claim 04 · Paper model

    The bound

    This note does not say any regulator has accepted the construction.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    A pool that hides all history and a pool that hides history inside an association set are different products. The set is the policy.

    Model

    What has to hold

    You are reading the privacy-pools paper. A deployed mixer is a different system.

    Falsifier

    What would retire it

    Who publishes the association set?

  2. 02 The proposal

    Observation

    What the study says

    The privacy-pools paper proposes that a withdrawal prove membership in an association set that has excluded known bad deposits, so privacy and a blocklist are both explicit.

    Model

    What has to hold

    You are reading the privacy-pools paper. A deployed mixer is a different system.

    Falsifier

    What would retire it

    What does the withdrawal prove: inclusion in the set, exclusion of a list, or both?

  3. 03 The mechanism

    Observation

    What the study says

    Users deposit into a pool. A withdrawal proves the note is in a chosen association set, not merely in the whole pool.

    Model

    What has to hold

    No price, supply, yield, or adoption figure is added by this desk.

    Falsifier

    What would retire it

    Who publishes the association set?

  4. 04 The bound

    Observation

    What the study says

    This note does not say any regulator has accepted the construction.

    Model

    What has to hold

    You are reading the privacy-pools paper. A deployed mixer is a different system.

    Falsifier

    What would retire it

    Who publishes the association set?

03 Sequence

One action, as an operating tape

  1. 01Users deposit into a pool. A withdrawal proves the note is in a chosen association set, not merely in the whole pool.
  2. 02The association set is curated by a published rule. Who edits that set is the governance of the design.
  3. 03Exclusion of a deposit does not seize it inside the paper's construction. It removes it from the set honest users prove against. Read the paper before describing a seizure.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    The privacy-pools paper proposes that a withdrawal prove membership in an association set that has excluded known bad deposits, so privacy and a blocklist are both explicit.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    This is not Tornado Cash's deployed contract. It is a later proposal about association sets.

  2. What actually moves

    The cut

    The association set is curated by a published rule. Who edits that set is the governance of the design.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    This is not Tornado Cash's deployed contract. It is a later proposal about association sets.

  3. What a later deployment may change

    The cut

    Exclusion of a deposit does not seize it inside the paper's construction. It removes it from the set honest users prove against. Read the paper before describing a seizure.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    This note does not say any regulator has accepted the construction.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading the privacy-pools paper. A deployed mixer is a different system.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

This is not Tornado Cash's deployed contract. It is a later proposal about association sets.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

A pool that hides all history and a pool that hides history inside an association set are different products. The set is the policy.

What the design proposes

  • Users deposit into a pool. A withdrawal proves the note is in a chosen association set, not merely in the whole pool.
  • The association set is curated by a published rule. Who edits that set is the governance of the design.
  • Exclusion of a deposit does not seize it inside the paper's construction. It removes it from the set honest users prove against. Read the paper before describing a seizure.

How the mechanism is specified

  • Users deposit into a pool. A withdrawal proves the note is in a chosen association set, not merely in the whole pool.
  • The association set is curated by a published rule. Who edits that set is the governance of the design.
  • Exclusion of a deposit does not seize it inside the paper's construction. It removes it from the set honest users prove against. Read the paper before describing a seizure.

What this page does not treat as proven

  • This note does not say any regulator has accepted the construction.
  • It states no set size.
  • This is not Tornado Cash's deployed contract. It is a later proposal about association sets.

Why the desk still reads it

The privacy-pools paper proposes that a withdrawal prove membership in an association set that has excluded known bad deposits, so privacy and a blocklist are both explicit.

09 Lexicon

Terms, opened into the record

Association set
A published subset of deposits that a withdrawal proves membership in.
Exclusion
Leaving a deposit out of that set. It is not, by itself, a description of a law-enforcement action.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.