From layer-2s to privacy protocols. The L2BEAT platform has just launched a new section that evaluates each privacy protocol based on a variety of criteria. The analytics platform, which has become the unofficial arbiter of Ethereum rollup decentralization, is applying the same method that built its reputation: breaking down trust assumptions rather than simply handing out labels.
Tired of rankings based on TVL, volume, or other metrics that aren't always relevant, L2BEAT is proposing a technical approach by analyzing the core of these protocols, their decentralization, and the trade-offs inherent in their structure.
Key takeaways
- L2BEAT now evaluates each privacy protocol against five distinct adversary profiles, without providing a single overall score
- The framework ranges from the passive blockchain observer to the state-level adversary capable of coercing an operator
- No protocol protects against all five: Zcash, Privacy Pools, or Railgun each accept different trade-offs
- The platform is adopting the "Stages" method that previously pressured Ethereum rollups to reduce their administrative powers
L2BEAT puts privacy protocols to the test against five adversaries
L2BEAT built its reputation by eschewing the ease of TVL or volume-based rankings. Initially, the platform allowed users to compare various Ethereum layer-2 solutions. Its risk radars and three-stage advancement scale for L2s—from Stage 0 to Stage 2—forced Arbitrum, Optimism, and their competitors to publicly document the components of their infrastructure. Their emergency keys, the composition of their security councils, and their withdrawal delays were all put under the microscope. Now, the platform aims to apply the same approach to an even more obscure field: privacy solutions.

Indeed, not all privacy solutions are created equal. They don't all share the same approaches or levels of privacy. For example, a mixer might obscure the link between a deposit and a withdrawal for anyone simply reading the chain. However, that same mixer could potentially reveal the user's IP address to the RPC provider relaying the transaction, effectively shattering the privacy attempt.
To measure these different solutions, L2BEAT has identified five types of attackers, ranging from the most common to the most sophisticated:
- The passive observer, who only exploits public on-chain data;
- The transaction counterparty, who already possesses some context;
- The infrastructure operator (relayer, sequencer, RPC node), who sees the metadata passing through;
- The protocol team, who often holds upgrade keys or secrets from the "trusted setup"—the ceremony used to generate the initial parameters of a proof system;
- The state-level adversary, capable of coercing an operator, issuing subpoenas to a host, and correlating network traffic.
Currently, no single protocol checks all five boxes. The Zcash shielded pool resists on-chain analysis very well, but is far less effective against targeted network surveillance. Systems built on association sets, with Privacy Pools leading the way, intentionally leave a door open for verifying the origin of funds. Categorizing these solutions in a single ranking finally makes comparison possible for users who lack the time or expertise to audit a cryptographic circuit.
Aztec, Zcash, Kohaku: crypto privacy has hit a new scale
The timing is hardly coincidental. Earlier this year, Vitalik Buterin published the Ethereum roadmap for 2029, reaffirming the commitment to bringing native privacy to Ethereum.
Privacy also appears to be at the heart of user demand. We have seen several recent price increases for Zcash, largely driven by the influx of funds into its shielded pool. Aztec has opened its public testnet after seven years of work on zero-knowledge proofs. Railgun, Privacy Pools, and a series of younger projects are now competing for users who previously had no serious tools to evaluate their respective security guarantees.
Regulatory pressure is also intensifying. The European anti-money laundering regulation will prohibit digital asset service providers from maintaining anonymous accounts and handling privacy-focused cryptocurrencies starting in July 2027. In the United States, OFAC removed Tornado Cash from its blacklist in the spring of 2025, but the partial verdict rendered against its developer Roman Storm keeps the threat of criminal prosecution hanging over code creators. Knowing exactly what adversary a protocol protects against is no longer just a hobby for cryptographers.
L2BEAT is already inviting the teams involved to challenge their ratings on its Discord, just as it did for rollups. At the time, several chains provided their fraud proofs and reduced their administrative powers to secure "Stage 1" status, all under the watchful eye of a dashboard consulted by the entire ecosystem. Applied to privacy protocols, this same mechanism will force every team to clearly spell out the exact limits of their promises.
The news that matters, summarized in 2 minutes. Monday to Friday, straight to your inbox.