📈 Get daily crypto insights that make you smarter about your money

Vitalik Buterin’s Three-Layer Privacy Stack: Local AI Rewrites, zkAPI Payments and Tor Routing

Ethereum co-founder Vitalik Buterin has gone public with a self-experiment in private artificial intelligence, revealing on Oct. 4 a personal setup that lets him query frontier models about his own health and travel data without handing that data to the companies behind the models. The architecture, assembled from a local open-source model, a new zero-knowledge payment system and the Tor network, is arguably the most detailed public blueprint yet for how privacy-conscious users could interact with centralized AI without being tracked across every request.

Three layers, one privacy stack

Buterin described the design as a three-layer privacy setup covering the content of requests, payment information and internet traffic. The first layer runs locally: his machine hosts Alibaba’s Qwen3.8-Flash-Next, a compact model that holds his health and travel records, decides when a more powerful remote model is needed and rewrites the request before sending it. The local model constructs queries with less identifying information, stripping personal context and even paraphrasing wording so his writing style does not give him away.

The second layer uses zkAPI, a system the Ethereum Foundation introduced on Oct. 1 that lets users pay for metered APIs without linking individual requests to their identity. Built by the Open Anonymity Project with the Ethereum Foundation and running on Ethereum mainnet, zkAPI works through private balances: a user funds a balance, then proves sufficient funds exist without revealing which deposit pays for which request. The AI provider receives the prompt but not the billing identity; the payment processor sees the transaction but not the prompt.

Tor provides the third layer, hiding the user’s IP address from the services receiving the requests. Buterin was blunt about why all three are required, writing that hiding payment information alone does not prevent an AI provider from learning details through prompt content or network metadata. You need all three, he said.

What the stack does not protect

The setup has honest limits, and both Buterin and the zkAPI documentation acknowledge them. The upstream AI provider still sees whatever information is deliberately included in a prompt, and network timing information can remain observable outside the zero-knowledge proof system. Reused personal details, writing patterns, conversation history or attached documents can still link sessions together — which is precisely why the local rewriting layer exists. The design reduces exposure rather than eliminating it.

Buterin said the experiment produced diet and exercise recommendations and that information returned by frontier models improved the results compared with purely local processing. He did not publish the underlying health records or an independent evaluation of the recommendations, keeping the experiment a demonstration of plumbing rather than a clinical claim.

zkAPI as Ethereum infrastructure

For Ethereum, the more consequential piece may be zkAPI itself. Metered API payments that require no account, no card and no identity link are a general-purpose primitive: they could serve AI inference, data feeds, content paywalls or any service billed per call. The system turns zero-knowledge proofs into a billing technology, using Ethereum mainnet as the settlement layer that guarantees a private balance is real and spent only once.

The timing is deliberate. Buterin has argued since at least April 2025 that growing AI capabilities and centralized data collection increase the need for stronger privacy tools, and zkAPI’s launch — followed days later by his personal demo — reads as a coordinated argument that Ethereum’s cryptographic toolset is ready for the AI era. A new change in the zkAPI repository adds Tor-routed client support, closing the loop on the third layer of his stack.

Why this matters beyond one founder’s diet plan

The mainstream AI experience today is a privacy trade: users hand over context to get quality, and providers accumulate that context into durable behavioral profiles. Buterin’s experiment sketches an alternative where a local model acts as a privacy-preserving intermediary, a zero-knowledge layer anonymizes the commercial relationship, and anonymized networking hides the transport. None of these components is new in isolation, but their composition into a working personal workflow by a high-profile user gives the pattern visibility it has lacked.

The open question is packaging. Assembling a local model, a zkAPI balance and Tor is beyond most users today. But the same was true of running an Ethereum node in 2016, and wallets eventually absorbed that complexity. If zkAPI or similar systems get integrated into consumer AI clients, the three-layer stack could quietly become the default architecture for private AI access — with Ethereum providing the trustless meter underneath.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Digital assets are volatile and readers should do their own research.

27 thoughts on “Vitalik Buterin’s Three-Layer Privacy Stack: Local AI Rewrites, zkAPI Payments and Tor Routing”

  1. deposit to request unlinkability in zkAPI is the piece providers could ship tomorrow. no local model needed, just stop linking billing to prompts

  2. tor_exit_enjoyer

    man really runs qwen locally, pays with zk proofs and routes through tor just so an ai cant snitch on him. dedication

    1. the zk payment layer is the part everyone skips. local model means nothing if your billing address leaks on every request

  3. three layers of hassle for health questions i could google in 5 seconds. cool blueprint but the timing attack caveat he admits himself basically breaks it

    1. googling symptoms and querying your own labs against your travel history are different products entirely. the hassle is the point, not a bug

    2. you can google a symptom, you cant google your own labs against your own travel history. the stack is for the second thing

  4. The writing style fingerprint point is underrated. Even with Tor and zero knowledge payments, your phrasing alone can link sessions together.

    1. timing analysis is the forever asterisk on these stacks. every anon setup leaks at the edges and people treat it as binary instead of risk reduction

  5. The zkAPI design is the reusable part here. Deposit and request unlinkability is something every AI provider could adopt tomorrow without waiting for local models to get good enough.

  6. Petter Lindqvist

    Local Qwen rewriting prompts before they hit a frontier model is the underrated layer here. Paraphrasing style so your writing pattern does not deanonymize you is a real threat model most people never consider.

    1. Timing metadata stays observable though. He admits it himself. Three layers reduce exposure, none of them erase it, and people will treat this like it is perfect anonymity anyway.

      1. agree the rewrite layer is the weakest link. paraphrasing is lossy, and the frontier model can still infer the missing context from structure. it lowers the signal, doesnt erase it

        1. yeah the frontier model reconstructing missing context from sentence structure is the nightmare case. sanitized words, same skeleton

  7. tor exit nodes are still the chokepoint. routing privacy through a handful of volunteers just moves the metadata problem one hop down the stack

    1. onion_kate’s tor point is underrated here. everyone fixates on the zk payments because they’re shiny, but exit node observation plus timing is the cheap attack. vitalik’s own stack still admits this in the fine print

  8. zkAPI proving a funded balance exists without linking deposit to request is clean separation. Provider sees the prompt, processor sees payment. Neither sees both.

    1. The part I want audited is what the local model strips before forwarding health data. If the rewrite leaks one diagnosis phrase, the zk payment layer is theater.

      1. this is the real question. paraphrasing strips style but the local model still decides what counts as identifying, and that mapping is exactly where leaks live

        1. the local rewrite deciding what counts as identifying is the whole ballgame. one lazy summary and the zk payment layer is protecting a leaked prompt

      2. the rewrite model deciding what counts as identifying is the part nobody audits. until someone red-teams the paraphraser with medical prompts this stays theory

        1. sauna_dev exactly, and the deeper problem is the rewrite model can’t know what the frontier model can infer. you’re sanitizing against an attacker that keeps getting better at reconstruction. stack assumes static adversary

          1. static adversary assumption is the core flaw. the day frontier models do entity resolution from writing style alone, the sentence skeleton leaks identity regardless of words

          2. writing style fingerprinting is already scarily good, paraphrasing the words keeps the rhythm. the stack needs a cadence randomizer, not only a rewrite model

      3. unless the rewrite keeps diagnosis adjacent phrasing, which paraphrasers love to do. red team the sanitizer with oncology prompts and this either survives or dies in public

      4. one leaked diagnosis phrase and the tor routing protects a secret everyone already knows. the sanitizer is the single point of failure in the whole design

  9. qwen running local triage so the frontier model only sees sanitized queries is the real architecture win here. zk payments get the hype, prompt hygiene does the work

  10. local qwen rewriting queries so your health questions stop reading like your health questions. wild part is anyone patient can build this stack today

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$85,725.00+0.3%ETH$2,709.89+0.3%SOL$120.11-1.1%BNB$786.63-0.3%XRP$1.50-0.4%ADA$0.2660+4.2%DOGE$0.0953-0.2%DOT$1.22-0.6%AVAX$10.90-1.7%LINK$13.94-1.5%UNI$9.09+0.6%ATOM$1.83+3.5%LTC$70.30-1.2%ARB$0.2079+2.0%NEAR$5.18+4.1%FIL$1.13+7.6%SUI$1.19-2.1%BTC$85,725.00+0.3%ETH$2,709.89+0.3%SOL$120.11-1.1%BNB$786.63-0.3%XRP$1.50-0.4%ADA$0.2660+4.2%DOGE$0.0953-0.2%DOT$1.22-0.6%AVAX$10.90-1.7%LINK$13.94-1.5%UNI$9.09+0.6%ATOM$1.83+3.5%LTC$70.30-1.2%ARB$0.2079+2.0%NEAR$5.18+4.1%FIL$1.13+7.6%SUI$1.19-2.1%
Scroll to Top