The zero-knowledge proof (ZKP) identity market reached an estimated $1.73 billion in 2026, up from $1.32 billion in 2025, growing at a 30.9% compound annual rate, according to Grand View Research. The catalyst: 88 documented identity-verification breaches have exposed between 2.15 billion and 4.5...
"It's not about combating the bots because that will be a lost cause." — Alex Blania, CEO, Tools for Humanity (a16z podcast, April 2026)
The zero-knowledge proof (ZKP) identity market reached an estimated $1.73 billion in 2026, up from $1.32 billion in 2025, growing at a 30.9% compound annual rate, according to Grand View Research. The catalyst: 88 documented identity-verification breaches have exposed between 2.15 billion and 4.54 billion records since 2011, with 42% of those incidents occurring between January 2024 and August 2026 — precisely as mandatory KYC and age-verification requirements expanded globally.
On September 2, World (formerly Worldcoin) open-sourced ProveKit, a production-ready zero-knowledge toolkit that generates identity proofs on a user's phone or browser without transmitting personal data to any server. The release arrives three months before the European Union's December 2026 deadline requiring all member states to deploy at least one European Digital Identity Wallet (EUDI Wallet) under the eIDAS 2.0 framework. Together, these developments mark a structural shift: identity verification infrastructure is moving from centralized data collection — store-everything, breach-everything — to cryptographic selective disclosure where proof replaces exposure.
The broader decentralized identity market was valued at $4.62 billion in 2026, according to GM Insights, with projections reaching $48.31 billion by 2030 at a 79.8% CAGR. Whether that growth materializes depends on technical feasibility at scale, regulatory acceptance of ZKP-based compliance, and enterprise willingness to abandon per-user licensing models for utility-driven credential frameworks.
A Mysterium VPN report published in 2026 documented 88 identity-verification breaches since 2011. Confirmed exposure totals stand at 2.15 billion records; alleged figures reach 4.54 billion. The acceleration is notable: 37 of those 88 incidents (42%) occurred in the 32 months between January 2024 and August 2026.
Select incidents illustrate the pattern:
The Identity Theft Resource Center's H1 2026 data breach report recorded 1,803 incidents and more than 471 million victim notices in the United States alone by midyear, a pace that, if sustained, would exceed 2025's record totals.
The economics are straightforward. Every identity-verification provider that collects and stores PII becomes a target. The regulatory response — requiring more KYC — creates more honeypots. ZKP-based systems propose an alternative: verify a claim without ever holding the underlying data.
World released ProveKit on September 2, 2026, under the MIT license. The toolkit is the same proving system already integrated into World ID, which has processed 3.4 million verifications per week.
Technical specifications:
ProveKit v2 roadmap:
World disclosed that the next version will target reduced proof sizes and lower memory consumption. One path under exploration is Groth16, a zk-SNARK proving scheme whose proofs are significantly more efficient to verify on blockchains including World Chain, Ethereum, Base, and Solana. The trade-off: Groth16 requires a per-circuit trusted setup, reintroducing the constraint ProveKit v1 was designed to avoid.
Limitations worth noting:
The toolkit addresses proof generation, not the underlying credential issuance. A user can prove they hold a valid passport without exposing it, but someone must have verified that passport in the first place. In World's case, that verification occurs at Orb devices using iris biometrics — a process that has drawn criticism from privacy regulators in several jurisdictions. ProveKit as a standalone open-source toolkit is agnostic to credential source, but its primary deployment context remains World's biometric infrastructure.
Regulation (EU) 2024/1183, in force since May 20, 2024, mandates that every EU member state must provide at least one national digital identity wallet by December 24, 2026. The acceptance obligation for businesses and public bodies follows one year later, by December 2027.
Current state of readiness:
The EUDI Wallet specification supports selective-disclosure mechanisms based on cryptographic proofs — architecturally compatible with the same zero-knowledge approach that ProveKit implements. By December 2027, regulated private-sector entities in banking, telecommunications, healthcare, education, and very large online platforms must accept the EUDI Wallet for authentication.
The downstream implication for Web3 is direct. Regulated DeFi protocols serving EU users will receive verified credentials from EUDI wallets that include ZKP-based selective disclosure. A lending protocol could verify that a user meets age and residency requirements without ever storing a passport scan. The infrastructure cost of compliance drops; the attack surface for data breaches shrinks.
Whether this plays out as designed depends on actual member-state delivery. The deadline is 110 days away, and multiple states have acknowledged they will not meet it.
The intersection of zero-knowledge proofs and DeFi compliance is moving from theoretical to operational. Several protocols have deployed KYC gates in 2025-2026:
The ZK-KYC market, which specifically covers zero-knowledge compliance tooling, was valued at $83.6 million in 2025 and is projected to reach $900 million by 2032, according to industry estimates.
The operational model follows a consistent pattern: a regulated KYC provider verifies the user off-chain using standard AML and identity procedures. After successful verification, the provider issues a cryptographic credential to the user's wallet. On-chain, the protocol checks the credential's validity without accessing underlying identity data.
This removes the protocol's need to hold PII — eliminating both the liability and the honeypot. For institutional DeFi, which is expanding into tokenized securities, credit markets, and cross-border payments, this is not a privacy feature. It is a risk-management requirement.
ProveKit enters a market with established participants:
| Project | Verified Users (2026) | Primary Chain(s) | Approach | |---|---|---|---| | World (ProveKit/World ID) | ~18 million (Orb-verified) | World Chain, Ethereum, Base, Solana | Iris biometrics + ZKP | | Civic | 2+ million | Solana, Base, Polygon | Civic Pass credential layer | | Privado ID (fmr. Polygon ID) | Undisclosed | Polygon, Ethereum | ZKP verifiable credentials | | Galxe Identity Protocol | Undisclosed | Multi-chain | ZKP credential infrastructure | | Spruce ID | Developer-focused | Chain-agnostic | Sign-in with Ethereum, DID tooling |
World's scale advantage is clear — 18 million biometrically verified users is an order of magnitude ahead of the nearest competitor. However, the Orb-based verification model requires physical hardware deployment, which limits geographic coverage and imposes capital expenditure that credential-only competitors avoid.
The MIT licensing of ProveKit introduces a different competitive dynamic. Any developer can now embed World's proving system into non-World applications. If third-party adoption materializes, ProveKit becomes infrastructure rather than a proprietary moat — beneficial for ecosystem growth, but potentially dilutive to World's network-effects thesis.
World App has surpassed 30 million total users across 160 countries. Of those, approximately 18 million have completed Orb-based biometric verification. The network processes approximately 3.4 million World ID verifications per week.
Mini Apps on the World App platform generate 3.8 million opens and 6.7 million impressions per day, suggesting a distribution layer that extends beyond identity into consumer-facing applications.
World Chain, the OP Stack rollup built to prioritize verified human users, reported on-chain DeFi TVL of approximately $39.7 million as of mid-2026, with canonical bridge TVL around $602 million. The on-chain DeFi figure represents a 2,567% increase from $1.5 million in October 2024, though the absolute number remains modest relative to major L2s.
The gap between 30 million app users and $39.7 million in on-chain DeFi TVL ($1.32 per user) raises questions about the current economic value generated per verified identity. The network's value proposition — proof of personhood as infrastructure — may require time to translate into measurable on-chain economic activity.
The identity verification industry is caught between two forces: regulators demanding more verification, and attackers exploiting the data that verification collects. Zero-knowledge proofs offer a technical resolution — prove the claim, discard the data — but adoption depends on three conditions: proving systems must work on consumer hardware (ProveKit demonstrates this is feasible), regulators must accept cryptographic proofs as legally sufficient (eIDAS 2.0 suggests directional acceptance), and enterprises must replace per-user licensing revenue models with utility-based alternatives (this transition is early).
The $4.62 billion decentralized identity market exists largely on projections. World's 18 million verified identities and the EU's 450-million-citizen wallet mandate provide the two largest testbeds. If the infrastructure works as specified — and the December 2026 deadline will stress-test that assumption — the economic case for ZKP-based identity shifts from theoretical to observable. If it does not, the collect-and-store model continues, and the breach count continues with it.