Privacy under pressure

Privacy is real — but not guaranteed

The privacy page made the case that financial privacy is worth having, and that on Zcash it is a property you keep by how you use the tool — not a switch that is simply on. This page is the honest other half of that story. Privacy technology is real, but it is not automatic, and it has not always lived up to what was promised for it.

It helps to keep three different things apart, because they carry very different lessons. A privacy tool can be promised but not delivered — marketed as private without really being so. It can be made, then defeated — genuinely private, until someone finds a way to undo it, usually by analysing how people use it or by watching the network underneath, not by breaking the mathematics. And it can be interrupted while a bug is fixed — working as intended, until a separate flaw forces the team to switch the private system off until a repair ships. Most of what follows is the third kind: bugs that researchers found and teams fixed, which is how security is supposed to work. The point of cataloguing it is the opposite of fear — a reader who knows how privacy has actually come under pressure is harder to mislead about what any coin can promise.

1. Promised, but not delivered

The clearest version of "it didn't do what the label said" is a tool whose privacy was thinner than its marketing. Verge (XVG) is the stock example. It marketed itself on the word Privacy, built around its Wraith Protocol (launched at the end of 2017), which routed a user's connection through the Tor and I2P networks to hide their IP address. The gap was in what that covered. Verge runs a transparent ledger: its transactions are publicly viewable on-chain, as in Bitcoin. It offered an optional "stealth" mode said to hide transaction amounts, but its privacy was a set of opt-in layers bolted onto that transparent base — not the mandatory, on-by-default on-chain confidentiality a shielded coin provides. Marketed as anonymity, what shipped was narrower than the word suggested — a reminder to check what a "privacy coin" actually hides before trusting it with anything.

2. Made, then defeated

Here the privacy was genuine and the cryptography held — but it could still be undone from the outside. These are the cases the privacy page's transaction hygiene section was built on: real privacy is lost through careless use or through the network layer, not through broken maths.

3. Interrupted while a bug was fixed

The last kind is the most common — and, read carefully, the most reassuring. Here privacy went offline not because it failed, but because the responsible response to a different bug was to switch it off until a fix shipped.

What the pattern teaches

Put the three side by side and a single lesson falls out, and it is not "privacy doesn't work." The promised-but-not-delivered case says: check what a tool actually hides, not what it is marketed as. The made-then-defeated cases say: real privacy can still be lost through careless use or through the network underneath it — which is why the privacy page spent its time on transaction hygiene and on the separate, network layer that Tor and mixnets address. And the interrupted-while-fixed cases say something almost steadying: when a serious bug turns up in a privacy system, the responsible move is to disclose it, switch off what is unsafe, and ship a fix — even at the cost of taking privacy temporarily offline. Privacy is not a switch that is permanently on. It is a property a sound design protects, an honest team defends, and a careful user keeps.

Sources