← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Confidential DeFi Goes Live Across Three Fronts

Zephyra|June 23, 2026|BPF
EXECUTIVE SUMMARY

Three concurrent developments in the week of June 23, 2026 mark the emergence of confidential decentralized finance as a production-grade infrastructure layer. Zama, Morpho, and Steakhouse Financial opened deposits for the first encrypted-USDC yield vault on Ethereum, allowing institutions to ear...

"Until now, operating on a public blockchain meant exposing your entire financial playbook to your competitors. By bringing Fully Homomorphic Encryption to core financial primitives like lending vaults, we are proving that privacy and decentralization are no longer mutually exclusive." — Dr. Rand Hindi, CEO, Zama

Executive Summary

Three concurrent developments in the week of June 23, 2026 mark the emergence of confidential decentralized finance as a production-grade infrastructure layer. Zama, Morpho, and Steakhouse Financial opened deposits for the first encrypted-USDC yield vault on Ethereum, allowing institutions to earn lending yield without exposing balances, trade sizes, or strategy timing on-chain. Separately, Starknet's STRK20 privacy framework — live since June 11 — now shields any ERC-20 token behind zero-knowledge proofs on its Layer 2, while Ethereum's core developers formally proposed EIP-8182 for inclusion in the Hegota hard fork, which would embed a native shielded pool at the protocol level.

The convergence is not coincidental. Institutional traders moved $2.3 billion through private DeFi channels in Q3 2025 alone, according to insights4vc research. The $840 million lost to DeFi exploits in the first five months of 2026 — with $14 billion subsequently withdrawn from the sector — has intensified demand for infrastructure that limits information leakage to front-runners, MEV extractors, and attackers. What was once a niche privacy-coin concern has become an institutional infrastructure requirement.

The economic implications are substantial. Morpho currently manages over $11 billion in deposits. Steakhouse Financial oversees $4.5 billion across its products. Zama, valued at over $1 billion after its $57 million Series B and $121 million token auction, is positioning fully homomorphic encryption (FHE) as the default confidentiality layer for public blockchains. The question is no longer whether DeFi needs privacy, but which encryption standard will capture the institutional capital pipeline.

Table of Contents

  1. The Zama-Morpho Confidential Vault: How It Works
  2. Starknet STRK20: Zero-Knowledge Privacy at the L2 Layer
  3. EIP-8182: Privacy Enters Ethereum's Core Roadmap
  4. The Institutional Economics of On-Chain Confidentiality
  5. Technology Stack Comparison: FHE vs. ZK vs. Hybrid
  6. Economic Value Analysis: Who Captures the Privacy Premium
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Zama-Morpho Confidential Vault: How It Works

The Steakhouse Confidential USDC Prime vault, which opened for deposits on June 23, 2026, operates through a two-step process. Users first convert standard USDC into encrypted confidential USDC (cUSDC) directly on Ethereum — no bridge to a separate chain required. The shielded token is then deposited into Morpho's existing Steakhouse USDC Prime vault, one of Morpho's oldest and most liquid strategies.

The underlying technology is Zama's fhEVM, a smart contract engine that processes encrypted data directly on-chain using fully homomorphic encryption. Computations — interest accrual, collateral checks, liquidation logic — execute over ciphertext. At no point during the lending process are balances, deposit sizes, or withdrawal timing visible in plaintext on the public ledger.

"Zama's confidentiality stack built on top of Morpho allows institutions to allocate into Morpho Vaults just like any allocation onchain without compromising operational privacy," Morpho co-founder Merlin Egalite stated in the June 18 announcement.

The vault's compliance architecture embeds auditability into the encryption layer. Designated auditors can access transaction data through viewing keys without compromising the privacy of uninvolved depositors. This mirrors the regulatory access model that traditional financial intermediaries provide — selective disclosure on demand, blanket confidentiality by default.

The economic scale is significant. Morpho's $11 billion in total deposits positions even a small percentage of migration to confidential vaults as a multi-hundred-million-dollar flow. Steakhouse Financial's $4.5 billion under management, serving clients including Coinbase, Bitget, Crypto.com, Safe, and Trust Wallet, provides the institutional distribution network.

Zama's path to this launch has been methodical. The company raised $57 million in a June 2025 Series B co-led by Pantera Capital and Blockchange Ventures, with personal investments from Solana's Anatoly Yakovenko, Polkadot's Gavin Wood, and Filecoin's Juan Benet. In February 2026, Zama conducted the first FHE-encrypted Dutch auction for its token sale, raising approximately $121 million. Total funding exceeds $176 million. In March 2026, GSR and Zama completed the first confidential OTC trade on Ethereum between fully KYC-compliant counterparties, demonstrating that encrypted settlement and regulatory compliance can operate on the same ledger.

Starknet STRK20: Zero-Knowledge Privacy at the L2 Layer

Starknet activated its STRK20 Privacy Pool on June 11, 2026, enabling one-click shielded transactions for any ERC-20 token on the network. The framework, prepared through the v0.14.2 protocol upgrade in April, introduces native in-protocol proof verification for privacy transactions.

The architecture differs fundamentally from mixing services or privacy coins. STRK20 operates as a note-based privacy pool. When a user shields an ERC-20 token, it enters the pool and is represented as an encrypted note. Private transfers spend existing notes and generate new ones. Each private transaction carries a fixed fee of four STRK tokens.

The system supports wallet-level shielding through Ready X and Xverse wallets. Once shielded, token balances and transaction histories are concealed from public view. The first asset built on STRK20 is strkBTC, offering users the option to toggle between public and shielded modes — hiding selected balances and transfers before returning to a transparent state.

STRK20 includes a regulatory compliance layer: an encrypted viewing-key framework where a designated third-party audit firm holds keys that can trace specific transaction history in response to valid legal requests, without exposing uninvolved users. This attempts to resolve the persistent tension between privacy and regulatory access that has constrained institutional adoption of previous privacy solutions.

DeFi integration is expanding but not yet comprehensive. Private swaps are operational through avnu and Ekubo. Lending through Vesu and staking through Endur are planned. Broader DeFi primitives — private lending and borrowing — are not yet live.

The Starknet Foundation has launched an eight-week "Proof of Privacy" incubator to accelerate application development on the STRK20 framework.

EIP-8182: Privacy Enters Ethereum's Core Roadmap

On June 12, 2026, Ethereum developers formally proposed EIP-8182 for inclusion in the upcoming Hegota hard fork, targeting H2 2026. Drafted by Facet co-founder Tom Lehman and first published in March 2026, the proposal would add a shared shielded pool and ZK precompile at the protocol level.

The proposal's core is a system contract deployed at a fixed address holding all state for a global shielded pool — note-commitment tree, nullifier set, user and delivery-key registries, and an authorization policy registry. The design specifies no proxy, no admin function, and no on-chain upgrade mechanism.

If adopted, users could send private ETH and ERC-20 transfers to any Ethereum address or ENS name from existing wallets. The proposal envisions atomic "de-sensitization → interaction → re-privatization" flows, allowing users to exit shielded mode, execute a DeFi transaction, and re-enter shielded mode within a single transaction.

Transaction validity would be verified using Groth16 zero-knowledge proofs — the same proof system used by Zcash at scale. The network confirms transfers are mathematically sound without revealing underlying values.

A companion proposal, pERC-20 (EIP-8287, created June 9, 2026), takes a more radical approach. It defines a token standard where balances and transfer amounts are private by default, replacing ERC-20's public balance/allowance model entirely with a zero-knowledge note-based interface. pERC-20 maintains publicly verifiable totalSupply but removes all individual balance visibility.

EIP-8182 remains in draft stage and must pass All Core Developers review, where client teams and researchers evaluate technical feasibility, security assumptions, and protocol fit. Adoption is not guaranteed.

The Institutional Economics of On-Chain Confidentiality

The institutional demand signal is measurable. According to insights4vc research, institutional traders moved $2.3 billion through private DeFi channels in Q3 2025 — the inflection point where confidential transactions shifted from experimental to essential.

The economic rationale is straightforward. On transparent blockchains, institutional positions are visible to all participants in real time. A large deposit into a lending vault, a collateral adjustment, or a withdrawal signal telegraphs strategy to competitors and front-runners. MEV extraction — estimated at $3-7 billion annually across all chains — directly profits from this information leakage. Institutional allocators subsidize MEV infrastructure with every visible transaction.

The $840 million lost to DeFi exploits in the first five months of 2026 compounds the problem. North Korean-linked hackers accounted for 76% of global crypto hack losses through April 2026, according to multiple security reports. The April 2026 Kelp DAO exploit alone drained $293 million, triggering $6.2 billion in withdrawals from Aave. Total DeFi sector withdrawals following the 2026 hack wave reached $14 billion.

Confidential transactions reduce the attack surface. Encrypted balances and trade flows provide less intelligence to potential attackers mapping high-value targets. They also eliminate front-running and sandwich attacks, which depend on reading pending transaction data.

The compliance question — historically the barrier to institutional privacy adoption — appears to be resolving through architectural design rather than regulatory negotiation. Both Zama's FHE vault and Starknet's STRK20 embed viewing-key mechanisms that allow authorized parties to audit specific accounts without compromising network-wide privacy. This "privacy by default, disclosure on demand" model aligns with existing financial confidentiality frameworks where banks protect client data but produce records in response to subpoenas.

Technology Stack Comparison: FHE vs. ZK vs. Hybrid

Three distinct cryptographic approaches now compete for the confidential DeFi layer:

Fully Homomorphic Encryption (Zama): Computations execute directly on encrypted data. Smart contracts process ciphertext without decryption at any stage. The advantage is full programmability — any DeFi logic can operate on encrypted state. The limitation is computational overhead; FHE operations are orders of magnitude slower than plaintext computation, though Zama's TFHE library has accelerated performance significantly. Zama's FHE scheme is quantum-resistant, a property that ZK-based systems using elliptic curve cryptography do not share.

Zero-Knowledge Proofs (Starknet STRK20, EIP-8182): Transactions are validated through mathematical proofs that confirm correctness without revealing data. ZK proofs are faster and more mature than FHE for transfer operations. Starknet uses STARKs (no trusted setup required), while EIP-8182 specifies Groth16 SNARKs (trusted setup required, smaller proof size). The limitation is composability — complex DeFi logic (multi-step lending, liquidations) requires additional proof circuits.

Hybrid Architectures: A growing pattern combines MPC (multi-party computation) for off-chain confidential computation with ZK proofs for on-chain verification. DTCC's tokenized U.S. Treasury pilot with Canton Network uses a permissioned chain where only relevant parties see trade details.

The approaches are not mutually exclusive. An ecosystem may use ZK proofs for simple transfers and FHE for complex vault operations on the same chain.

Economic Value Analysis: Who Captures the Privacy Premium

Confidential DeFi introduces a new value-extraction layer to blockchain economics. Where transparent DeFi distributes value among validators, MEV extractors, protocol treasuries, and oracle providers, confidential DeFi redirects a portion of MEV-extractable value to the privacy infrastructure layer.

Zama captures value through its ZAMA token (used for encryption/decryption fees on the fhEVM), protocol licensing to DeFi platforms, and its position as the sole FHE provider integrated with Morpho's $11 billion deposit base. The company's $176 million in total funding and $1 billion+ valuation reflect investor expectations that FHE becomes a critical infrastructure layer.

Starknet monetizes through STRK token fees — four STRK per private transaction — flowing to the protocol's existing economic model. Privacy functionality is additive to the existing fee structure rather than a separate revenue stream.

Ethereum L1, if EIP-8182 is adopted, would embed privacy as a protocol-level public good with no additional fee beyond standard gas costs. This would position Ethereum's base layer as the privacy settlement layer, potentially drawing confidential transaction volume away from L2 solutions.

The MEV implications are substantial. If institutional capital migrates to confidential vaults, the addressable MEV extraction opportunity shrinks. Flashbots and builder networks, which collectively extract $100-300 million annually in builder profits, face revenue compression as high-value transactions become opaque.

The economic question is whether the privacy premium — the additional cost of encrypted computation — is lower than the MEV and information-leakage costs that institutions currently absorb on transparent chains. Current data suggests the answer is yes for large allocators, where a single front-run trade can cost more than months of encryption fees.

Key Takeaways

  • Zama's confidential USDC vault on Morpho opened for deposits June 23, representing the first production deployment of FHE-encrypted yield on Ethereum with $11B+ in accessible lending infrastructure.

  • Starknet's STRK20 framework, live since June 11, enables one-click privacy for any ERC-20 token on its Layer 2, with strkBTC as its first live asset.

  • EIP-8182 entered Ethereum's Proposal for Inclusion review on June 12, targeting the Hegota hard fork. If adopted, it would make private ETH and ERC-20 transfers a native protocol feature.

  • Institutional demand is quantifiable: $2.3 billion moved through private DeFi channels in Q3 2025 alone. The $840M in 2026 DeFi exploit losses and $14B in subsequent withdrawals have accelerated urgency.

  • Compliance integration through viewing-key architectures in both Zama and STRK20 signals that the industry has moved past the "privacy vs. regulation" binary.

  • MEV extraction ($3-7B annually) faces structural disruption if institutional capital shifts to confidential vaults, reducing the information available to front-runners and sandwich attackers.

  • Three cryptographic approaches — FHE, ZK proofs, and hybrid MPC/ZK — are competing for the confidential DeFi layer, with no clear winner and potential for coexistence.

Conclusion

Confidential DeFi is transitioning from research prototype to production infrastructure in a compressed timeframe. The simultaneous deployment of Zama's FHE vault, Starknet's STRK20 framework, and Ethereum's EIP-8182 proposal represents a coordinated — if unplanned — industry response to a structural problem: public blockchains leak too much information for institutional capital at scale.

The economic math is simple. Institutions absorb billions annually in MEV extraction and information leakage costs on transparent chains. The security crisis — $840 million in exploit losses, $14 billion in withdrawals — makes position visibility an active liability. Privacy infrastructure that reduces these costs while maintaining regulatory compliance addresses a quantifiable demand.

What remains uncertain is standardization. Three competing cryptographic approaches, deployed across multiple chains and layers, create fragmentation risk. FHE offers full programmability but carries computational overhead. ZK proofs are faster but less composable. Neither has achieved the network effects necessary to establish a dominant standard.

The next 12 months will determine whether confidential DeFi consolidates around a single approach or fragments across competing ecosystems. What the data makes clear is that the demand is real, the infrastructure is live, and the capital is waiting.

Sources & References

  1. Zama Launches USDC Confidential Lending in Partnership with Morpho and Steakhouse Financial — Benzinga, June 18, 2026. Vault launch details and executive quotes.
  2. Zama, Morpho and Steakhouse Launch First Confidential DeFi Yield Vault on Ethereum — CryptoBriefing, June 2026. Technical vault architecture details.
  3. Starknet Launches STRK20 Privacy for Every ERC-20 Token — Crypto.news, June 2026. STRK20 framework features and launch.
  4. Starknet v0.14.2: The Privacy Engine Arrives — Starknet Blog. Protocol upgrade enabling STRK20.
  5. EIP-8182: Private ETH and ERC-20 Transfers — Ethereum Improvement Proposals. Draft specification.
  6. EIP-8182 Proposed for Hegota Hard Fork to Enable Privacy Transfers on Ethereum — CryptoBriefing, June 12, 2026. PFI review status.
  7. Ethereum Developers Explore New Token Standards as Privacy Returns to Focus — CoinDesk, June 10, 2026. pERC-20 and privacy standard overview.
  8. GSR and Zama Complete First Confidential OTC Trade on Ethereum — GSR, March 2026. First institutional FHE trade.
  9. Privacy Trends for 2026 — insights4vc. Institutional flow data and market analysis.
  10. DeFi Security Crisis 2026: $840M Lost — Thirdweb, May 2026. Exploit statistics.
  11. Nearly $14 Billion Withdrawn from DeFi Sector — ECIKS, 2026. DeFi withdrawal data following hacks.
  12. Zama Raises $57M in Series B — Financial IT, June 2025. Zama funding details.
  13. The 2026 Guide to Blockchain Privacy: 5 Approaches for Institutional Adoption — ChainSafe, 2026. Privacy technology comparison.
  14. Starknet Foundation Launches Proof of Privacy Incubator — CryptoBriefing, June 2026. STRK20 developer ecosystem.