|=[ RESEARCH :: FILE 05 ]=

HOW CONFIDENTIAL ARE ZAMA'S FIFTEEN NEW VAULTS?

ZAMA · MORPHO VAULT V2 · FHEVM · ETHEREUM MAINNET

On 15.09.2026 Zama launched fifteen new confidential Morpho vaults across five curators, and I re-indexed every public event they emit through 28.09.2026. 96.0% of joiner-vault appearances are traced at the wrap, 40 of 80 finalised batches attribute to exact per person amounts, and the six careful joiners turn out to be one operator. The June vault lost its whale and was refilled with $5.18M of Zama's own money.

ORIGINAL RESEARCH 5 LEAKS PUBLIC DATA ONLY

DATA — 15.09.2026 → 28.09.2026 · ETHEREUM MAINNET

15
Vaults
five curators · five confidential assets
814
Batch joins
556 vault deposits · 311 quits
96.0%
Traced at the wrap
534 of 556 appearances
40/80
Batches solved
exact per person amounts
101
Proven-zero joins
Zama's own cover traffic

EVERY PUBLIC EVENT AROUND THE FIFTEEN VAULTS, RE-INDEXED FROM THE CONTRACTS

THE FIFTEEN VAULTS

tl;dr: Not very, again. 96.0% of depositor appearances across the fifteen vaults launched on 15ᵗʰ September can be traced to a public wrap, with amounts, addresses, and timestamps. There were six depositors who could not be identified via wrap and deposit, but can be tracked to one operator. 40 of the 80 finalised batches can be attributed to exact, per person amounts. The original June vault lost its whale and was refilled with $5.18M of Zama's own money. The same arithmetic catches Zama's own cover traffic: 101 joins are proven to have moved nothing at all.

You can see the full set of vaults:

The whole set at a glance

WHAT DID I ACTUALLY DO THIS TIME?

Last month I took apart the first Zama x Morpho confidential vault and showed 98.1% of its depositors were publicly identifiable. On 15ᵗʰ September, Zama launched fifteen more, across five curators (Steakhouse, Armitage by Wintermute, Flowdesk, RockawayX, Bitwise) and five confidential assets (cUSDC, cUSDT, cWBTC, cAUSD, ctGBP). Each of these vaults used the same architecture as the original: you wrap public money into an ERC-7984 token, join an encrypted batch, the KMS decrypts only the aggregate, and one public lump sum lands in the vault.

I ran the same analysis, re-indexing every event from the batcher creation, from the 15ᵗʰ to 28ᵗʰ September. There were 814 joins from 556 vault deposits, 161 unique depositors, and 311 quits. I went slightly further than I did in June, adding two analyses:

The funding graph - ERC-7984's ConfidentialTransfer encrypts the amount but publishes sender and receiver, and every wrap mint names its recipient while the paying side sits in the same transaction's public logs. I went through each transfer to find where the original wrap occurred.

The batch solver - Every finalised batch is an equation with the total deposit amount public, so I wrote a solver that deaggregates the deposit amounts.

It is also important to understand the lifecycle of depositing into a vault, as there are significantly more transactions in the new vaults:

01 Wrap.

This is public, USDC goes to the wrapper, cUSDC comes back; amount, address and time are all visible.

02 Join.

You register into the current batch with an encrypted amount, with your address and batch number public.

03 Dispatch and finalise.

Zama's operators trigger the FHE decryption of the batch's aggregate, then a callback moves the lump sum publicly into the vault.

04 Claim.

You collect your confidential share tokens to your address.

05 Quit.

A quit is the joiner pulling their join before settlement.

06 Cancel.

Zama abandon the whole batch and the amounts are never decrypted.

There are three ways for a join to amount to nothing; quit, cancel, or the decoy transactions deployed by Zama.

5 LEAKS, AGAIN

#1 · The Wrapoooors return

96.0% (534 of 556) of depositor appearances wrap their own tokens before joining, compared to 98.1% of depositors in June.

Many of the depositors from the original vault return in September. 0xb81a0e6c…0c5bfd, was a $26.7M cUSDC whale from the first study, turned up in cUSDT on 17ᵗʰ September, funding $5M from Binance's labelled wallets:

The Binance whale, hop by hop

They also added another $1M in the same hour and $1M more on 18ᵗʰ September, all funded from Binance. Each of these were wrapped and joined, but the batch transaction shows a deposit into three vaults. Zama implemented zero value deposits to help cover your deposits, but we know that this whale's funds only landed in fcUSDT.

One whale, three joins, one landing
Traced at wrap, per vault

For each of the new vaults, you can trace between 50% (bbqTGBP, two joiners) to 98.6% (the cUSDT cluster), counted over everyone who joined, including joins that never settled and joins that never carried money. On unique joiners, we can trace 155 of 161 joiners, and the remaining six can get traced through the funding graph, who get their own chapter later on. 47 of the depositors in the new vaults were also June vault depositors.

#2 · Privacy is better with real friends

You get more privacy when your batch has more depositors join you, and those depositors actually deposit real money. Four new batches only had one depositor and can be easily doxxed:

The singleton batches

The last two are from the weekend, 0xc4a3391a…ab37 quit batch 14, only to rejoin alone in batch 15.

If a batch has more than one member, you can still work out the amount by using basic maths. Every finalised batch publishes the total amount. If everyone in the batch is accounted for except one person, their total minus batch total is that person's amount. This model assumes that a join spends the full wrap, and if no combination of the public wraps add up to the total, the model fails.

As of 28ᵗʰ September, 50% (40/80) of the finalised batches solve completely, and 203 of 382 member appearances can be filtered to an exact amount. The other 40 are still partially unsolved.

There are an incredible amount of cancellations for these vaults, of the 224 dispatched, 144 were cancelled. It is particularly extreme for armUSDCp; 33 joiners wrapped $6.45M, 47 joins, and exactly one batch ever settled, $45.00, batch 3. Compare this to fcUSDT or roxcUSDC where 14/15 and 12/15 batches were settled respectively. Zama also settle and cancel batches in one multicall transaction - 0x8b5df5de…caf7 - finalising five batches and cancelling seven more.

Batch 11 was joined on eleven vaults and finalised on five, about a day late. Batch 16, joined on eight vaults on 28ᵗʰ September, never dispatched anywhere. A cancelled batch publishes no total; the quit is public too.

Batches dispatched, finalised, cancelled
#3 · The exit boundary again

Claiming your confidential shares is private, but turning them back into money is not. fcUSDT had 59 public burns by 13 accounts, about $8.94M, plus $1.04M of depositor unwraps. At the time of writing, fcUSDT had $19.66M in, $8.94M burned, and $10.75M held, putting us within 0.25% of the TVL.

The biggest exit of the window belongs to the June vault's whale. 0xb81a0e6c…0c5bfd unwrapped 982,966 shares from the confidential wrapper on 29ᵗʰ August (0xcb62ce11…ddb0), then burned everything across 24 public redemptions totalling $8,018,351.68 between 21ᵗʰ August and 11ᵗʰ September (largest single: 989,935 shares for $1,005,594.50).

#4 · The six careful joiners

Every set has its careful minority, joiners who never wrapped the asset they joined with, who received confidential tokens from elsewhere and leave no amount to trace. In June, I complimented them, and how they understood how confidential vaults and tokens work. For September, I looked into their funding, to find out they are one operator.

The operator cluster

All six are fed by nine EIP-1167 minimal-proxy wallets, with identical 45-byte bytecode, zero ETH inflows, one factory (0xb894a4b3…8fE6), and one deployer. Five of the six share gas wallets with each other, or the dust tester 0x40a86041, who smoke-tested 13 of the 15 vaults. Their money enters publicly: 0x76fc4e4432 wrapped 199,999.4 AUSD and 74,222.92 tGBP; 0xa657c36f wrapped 2.57359 WBTC and 1,000,786.34 USDT; 0x5c178c08 wrapped 5.34M USDT; 0xe7151c92 wrapped 2.78M tGBP.

We can breakdown their movement into proven deposit amounts, bounded deposit amounts, and opaque deposit amounts.

Proven deposit amounts

0x3be9e7fa…bed1 deposited exactly 300.000000 tGBP in bbqTGBP batch 3, recovered by arithmetic (leak 2).

Bounded deposit amounts

Its cWBTC came from a proxy four minutes before its armcWBTC join, rooted at a public 2.57359 WBTC wrap. At most we know their deposits were 2.57359 WBTC, 199,999.4 cAUSD and 74,222.92 ctGBP.

0x5e310f01…a82d's confidential inbound is bounded too, receiving 25,000.01 USDT from one funder, and 2,783,990 tGBP from another.

Opaque deposit amounts

The cUSDT edges, which route through two aggregation hubs and a Safe, where per-edge amounts stop being attributable.

https://x.com/donnoh_eth/status/2103101708469751999

This leak seems to be by design of Zama, which leads to weakened privacy for users. Every privacy design has a choice and their own consequences. The above is what that choice costs, nothing was ever decrypted, but wrapping the tokens leaks the recipient, every ConfidentialTransfer publishes sender and receiver, and the gas wallets are shared.

I think the framing also deserves pushback, implying that a mixer is bad, and it is the only way to hide addresses. Aztec keeps the link graph inside the note layer, and designs like Privacy Pools break the link while still screening funds; even the Tornado Cash sanctions were ruled unlawful in 2025 (Free Roman and Alex). The positives of hiding addresses are from Zama's own product pitch, the launch post sells these vaults as keeping positions "private from competitors, front-runners, and other observers", which is precisely what hidden links provide and precisely what the public graph takes away. Address-hiding is the one feature that would have stopped this section. Orion Finance uses this approach to hide deposits, allocations, and addresses for curators.

#5 · Patience is a virtue, still

Median wrap→join is 18 to 174 seconds everywhere except bbqTGBP, where the single traced joiner waited 84 days on a pre-existing ctGBP balance. 59 to 91% of traced joiners join within five minutes of wrapping. June's 96-second median was not abnormal; it is how the product is used.

Wrap-to-join and settlement latency

THE ZERO FUNDERS

The app itself has started patching the metadata leak, so here is what it is, how it works, and how well. Deposit through the UI and it now tells you: "To hide which vault you chose, this deposit also sends a zero-amount deposit to 3 other vaults. No funds move to them."

This is essentially cover traffic, sending decoy joins to sibling vaults so a watcher cannot tell which vault your deposit went to. It works because of the FHE clamp: a join with no balance behind it settles as a silent no-op, indistinguishable in the event log from a real one: Joined(batch, address, encrypted handle).

Launch day supplied the worked example. 0x5e310f01…a82d, June's $49,990 singleton depositor, joined batch 2 on all five cUSDT vaults in one transaction at block 25,982,584, then sprayed the cUSDC, tGBP and AUSD vaults over the next thirty-five minutes: eleven vaults, four transactions, no fresh wraps that day. Of the five same-transaction joins, the solver proves four settled at exactly zero; the fifth sits in a batch the solver cannot close.

Proving a zero join

The census at 28ᵗʰ September makes the pattern measurable. Of the 814 joins, 784 came in multi-vault sprays: one transaction hitting several sibling vaults at once. Spraying is the default. Most sprays carry exactly one real deposit: in 138 of the 267, one leg moved money and the rest were decoys. Across the set, 101 joins in 38 finalised batches are proven zeros.

One thing proves nothing is claiming. Every one of the 101 zero joiners claimed their shares anyway; the claim transaction moves an encrypted share amount whether or not you were owed one.

Count money instead of joins and the identical clusters evaporate. Take the three cUSDT vaults, the same 72 addresses joined all of them, usually in the same transaction.

Then look at who actually moved money. On fcUSDT, 59 of the 72, on armUSDTs, 8, and on armUSDTp, 4. The rest were decoys. Joins that carried nothing, sprayed to make the real deposit harder to place. The same pattern holds in every cluster.

Zero joins can work, but currently do not:

  • Zero joins are provable in retrospect, once the other members of a finalised batch are accounted for, the zero is forced.
  • Decoys carry no funding trail. The real join has a wrap or a confidential inbound, the decoys have nothing. They ride in the same transaction, so the spray clusters itself for free.
  • Vault totals still move. The real vault's batch gains the full deposit while the decoy vaults gain nothing, so at settle time the choice is public again.

It only buys ambiguity for a live mempool watcher until the batch transaction settles. Fixing it costs money, and a lot of it. Decoys need real, randomly-sized amounts, a varying count, separate transactions at randomised delays, and cover at claim and exit too, where today there is none.

THE VAULTS

The headline TVL is not confidential TVL. The fifteen vaults hold $336.9M of totalAssets onchain; the confidential TVL is $35.08M, above a tenth. Two vaults hold almost all of it, 92% of the batch-routed total. roxcUSDC holds $17.09M, 99.98% of that vault, and the only one born confidential. fcUSDT holds $10.75M, 92.7% of its vault, including the Binance whale's $7.0M from leak 1. bbqTGBP's apparent $5.0M was never batch-routed at all: minted publicly and shielded into the wrapper afterwards, so excluding it the batch-routed confidential TVL is $30.1M. Seven of the fifteen vaults hold under $75K.

Confidential TVL vs headline TVL

WHAT STAYS PRIVATE

The core product continues to do what it claims. Balances and in-flight amounts are encrypted, and 40 of the 80 finalised batches resisted the solver. The leaks are the seams, and they are the same seams as June; the wrap is public, the funding graph is public, the batch total is public, the exit burn is public, the timing is public.

If you use these vaults there are important things to remember:

  • Wrap from a wallet that isn't the one everyone knows, days before you join, in uneven chunks, because the wrap is your deposit slip.
  • Remember that whoever sends you confidential tokens is visible even when the amount isn't.
  • Exit the way you entered, because the confidential path ends in a public burn.
  • Watch the batch size: too small to matter now gets cancelled, and alone in a batch means alone in the total.
  • Do not trust the app's decoy joins to cover you: the zero sprays are visible as sprays, they ride in your transaction, and every one of the 101 proven-zero joiners claimed anyway.

SO, ARE ZAMA'S FIFTEEN NEW VAULTS CONFIDENTIAL?

To remind you of the definition of Confidential, per the dictionary: private and meant to be kept secret. Information that should not be shared with others, often because it is sensitive, personal, or legally protected.

Using this definition, we can hold the 15ᵗʰ September launch post to that standard:

The launch post vs the public record

The same conclusion as in June can be made, a vault whose entry is public is a public vault with a confidential middle. The infrastructure is still useful, but these positions can be front run, competitors can see your positions, and other observers can identify your assets.

METHODOLOGY

Everything in this piece derives from public Ethereum mainnet logs, re-indexed per event per contract via a keyed RPC endpoint, with Blockscout for labels and funding traces. No FHE was broken; the events around the cryptography did the talking.

The solver works on one equation per finalised batch: the member amounts sum to the public aggregate moved by the finalise transaction. Each member's amount is either zero or one of their earlier public wraps, and a wrap is spent once across the sibling vaults, which share one confidential balance. It solves to exact integers, or says so when it cannot. Verification anchors, all reproduced model-free: armcWBTC batch 9 = 4.599552 WBTC to 0x2dc600e8; steakUSDT batch 4 = 0.001 USDT to the dust tester; armcWBTC batch 15 = 0.105706 WBTC to 0xc4a3391a; steakUSDT batch 14 = 71,131.68 USDT to 0x20c578d3. The four finalise transactions: 0x213e0570 · 0x5fc2d7d7 · 0x6b3b0a69 · 0xe0464388.

Reconciliation: reconstructed confidential TVL lands within +0.03% to +0.24% of the onchain figure across the fourteen normally-behaving vaults; bbqTGBP is excluded, since its apparent $5.0M was shielded after public minting, never through the batcher. Rates fixed at the 24ᵗʰ September values (WBTC $83,388, tGBP $1.32) so then-now comparisons carry no FX noise. Window: contract creation to 28ᵗʰ September 2026, block 26,079,396.

Honest limits: 40 batches stay partly unsolved; a cancelled batch never decrypts, so its amounts are unknowable; claims prove nothing; fleet-internal amounts stay opaque past the aggregation hubs; funding traces are samples, not exhaustive. Raw dumps, per-batch solutions and the funding graph are all derived from public logs only.

Evaluating confidential vaults but not sure if one fits your product? Talk to Ben.

TALK TO BEN →

FILE UNDER — RESEARCH

NEXT READS

HOW PRIVATE IS PRIVACY POOLS? seven heuristics across every v1 transaction: what actually links a withdrawal to its deposit HOW CONFIDENTIAL IS ZAMA'S CONFIDENTIAL VAULT? every public event around the confidential vault: 98.1% of depositors traced at the wrap HOW MUCH STEALTH DOES A STEALTH ADDRESS GET YOU? three generations of stealth protocols measured on public data: most active users linked at the spend

DEEP DIVES · RESEARCH · WORK WITH ME