Soulbound Security Research. Protocol security review by Gakarot, Director of Blockchain Security (gakarot@soulboundsecurity.io).
Every private transfer system makes the same promise: an observer watching the ledger cannot reconstruct who sent value to whom. The systems differ enormously in where that promise is kept, what it costs a user to reach it, and who else holds keys while it is being kept. For a charity, a congregation or a regulated fintech choosing a rail for real value, those differences matter far more than the headline claim.
Three broad families of cryptographically private transfer systems are in production today: privacy coins, privacy chains, and transaction-level protocols on existing EVM networks. The first two solve a different problem from the one Soulbound Finance solves, so we cover them briefly. The rest of this piece is a protocol-level security review of Privacy Boost, a shielded-pool protocol built by Sunnyside Labs, set against Soulbound Finance.
Neither is ahead or behind. They are differentiated offerings built for different jobs: Privacy Boost is, architecturally, an advanced mixer, while Soulbound Finance is built for regulatory approval of private, blockchain-based transfers.

Privacy coins: private asset, public exits
Monero and Zcash are the reference designs, with privacy built into the asset itself. The cryptography is mature. The problem is everything around it. Value has to be converted into the coin to become private and back out to be useful, and every conversion runs through an exchange that increasingly will not touch the asset. Binance, OKX and Kraken have delisted Monero in some or all markets, and the EU’s Anti-Money Laundering Regulation bars crypto-asset service providers from handling privacy-enhancing coins from July 2027.
A donor who wants to give USDC privately does not want to become a Monero trader first. Privacy coins protect an asset, not a transfer in the assets people actually hold.
Privacy chains: private domain, public ramps
Aztec, Aleo, Secret and Namada move privacy down a layer, so every asset on the chain inherits it. Inside the chain that is genuinely more private than anything on a transparent L1 or L2. It also relocates the exposure rather than removing it. You bridge in and bridge out, and the bridge is a public choke point, frequently multisig-governed, that records exactly the amount and timing an analyst needs. The tokens a treasury or individual actually holds arrive only as wrapped representations whose redemption depends on the bridge.
The action moves to the on and off ramps, which is precisely where regulators, analytics firms and attackers already look.
Transaction-level protocols: same layer, different jobs
The third family keeps users on the chain they already use, with the tokens they already hold, and adds privacy at the level of the individual transfer. Tornado Cash was the first widely used example. Privacy Boost belongs to that mixer lineage, rebuilt with far more advanced cryptography. Soulbound Finance shares the layer but not the goal.
Privacy Boost is a UTXO-style shielded pool. Deposits become Poseidon2 note commitments in a Merkle tree; spending a note requires a nullifier and an EdDSA signature checked inside a Groth16 zero-knowledge proof, with transfers batched into epochs by a prover and relay running in a trusted execution environment (TEE).
Soulbound Finance gates deposits behind a non-transferable Soulbound Token (SBT). A depositor funds a DepositPool, generates a one-time-use (OTU) redemption code off-chain and signs an on-chain EIP-712 attestation of purpose, charitable or commercial. A separate party redeems the code from a ClaimPool to a fresh address, and the protocol never records which deposit that redemption corresponds to.
What each hides, and what neither hides
Both protocols are public at the boundary: anyone can see who deposited, who withdrew, which token, how much and when. The difference is in between. Privacy Boost shields its internal state cryptographically, so which note was spent, who owned it and how value moved inside the pool are hidden by construction. Soulbound Finance’s privacy is structural: the pairing between a deposit and a redemption simply does not exist on-chain to be read.
Privacy Boost optimises for cryptographic concealment inside the pool; Soulbound Finance optimises for unlinkability that a regulator can examine without either party’s identity being exposed. Neither changes what is public at the edges.

Complexity is a cost, not a credential
Privacy Boost’s machinery, including Groth16 verifiers with a trusted-setup dependency, a TEE, relayer infrastructure and auth snapshots, buys a real property. It should be judged on whether that property is worth the surface area, not read as a security credential in itself. Every additional component is another place for a bug, a misconfiguration or a compromised role to matter.
Soulbound Finance’s core flow fits on one line, and its core contracts carry no third-party protocol or library dependencies such as OpenZeppelin or Chainlink, removing a whole class of inherited assumptions from review.
A bank’s risk committee can be walked through the entire Soulbound Finance system in a single sitting.
Who holds the keys
Soulbound Finance has two core roles. The Controller sets fees, supported tokens and the EULA, and is walled off from funds. The Operator can move ClaimPool redemption balances, making it the one key whose compromise is a direct path to lost funds; our own specification says so, and the mitigation is conventional HSM or enclave custody plus balance monitoring. An auxiliary Gas Manager can deploy a dedicated gas fund only to Operator-approved targets and cannot touch the redemption balance.
Privacy Boost spreads power wider. A fully compromised TEE operator cannot forge a spend, because every spend still needs a valid signature and proof; it leaks metadata, not funds. A rogue relay can stall submissions but cannot bypass on-chain verification. The deeper exposure is governance: Privacy Boost’s own threat model acknowledges that misuse of the ProxyAdmin and verifier-owner roles can affect verifier selection, implementation behaviour, relay policy and economic parameters. A compromised key there does not take one balance; it can change what the proof system accepts as valid.
The two designs carry different risk profiles, one direct and narrowly scoped, the other systemic, and a serious reviewer should weigh both.

Immutable versus upgradeable
Soulbound Finance contracts are immutable: no proxies, no delegatecall, nothing to redirect after deployment. Privacy Boost is proxy-upgradeable, and its documentation is candid that the absence of a setter on the forced-withdrawal verifier is not absolute immutability while the proxy remains upgradeable. Upgradeability is a legitimate choice that lets a team patch without migrating users, but it changes the category of guarantee.
Soulbound Finance’s rules cannot be changed by any key. Privacy Boost’s rules can.
Getting your money out
Soulbound Finance’s emergencyWithdraw is unconditional: any SBT holder can pull their full balance at any time, with no fee, even for a token that has since been delisted.
Privacy Boost’s forced withdrawal bypasses the TEE with a client-side proof, which is valuable, but only for keys already captured in an on-chain auth snapshot, and snapshots are created by relays rather than on user demand. A user registered after the latest snapshot cannot force an exit until the next one lands. Privacy Boost documents this window itself. It is a narrow edge case in normal operation and exactly the case that matters when the relays are what has failed.

What Privacy Boost optimises for
Privacy Boost is built to conceal what happens inside the pool, and it does that job with serious machinery and serious documentation: three commissioned OpenZeppelin audits across 2026 and fourteen specification documents with a per-actor trust table, numbered invariants, a leakage table and a candid list of its own known weaknesses. For a user whose only requirement is internal concealment, that is a coherent design. It is simply not designed to be approved by a financial regulator.
What Soulbound Finance optimises for
Soulbound Finance’s core focus is regulatory approval for private, blockchain-based transfers, and the protocol is built around that goal.
Per-transaction attestation. Every transfer carries a proprietary EIP-712 attestation, designed as a legal artefact: a signed, immutable, attributable statement of purpose, with responsibility for a false statement resting on the signer.
On-chain Soulbound ID. Identity lives in the non-transferable SBT, with Privado ID zero-knowledge verification on the 2027 roadmap alongside the regulatory approval path, so identity can be proven without being disclosed. KYC applies where a user’s local jurisdiction requires it.
No stored addresses. Across every layer of the stack, from contracts to backend to database, Soulbound holds zero knowledge of, and stores none of, the Ethereum addresses on either side of a transfer.
Privacy Boost has no equivalent layer: we checked, and it has no KYC or KYB logic, no user allowlist and no identity requirement.
The regulatory question, sized honestly
The obvious precedent is Tornado Cash, and the record is mixed. OFAC designated it in August 2022, alleging billions laundered including Lazarus Group proceeds. That was agency action. In Van Loon v. Treasury the Fifth Circuit held that immutable smart contracts are not blockable property, and Treasury delisted the protocol in March 2025: tested case law, but narrow, turning on immutability rather than endorsing unidentified shielded pools.
Two points follow. Whatever protection Van Loon offers attaches to immutability, and a proxy-upgradeable system with identifiable governance, TEE and relay operators is not obviously inside that holding. More practically, the realistic exposure for a fintech is not a sudden designation but banking-partner risk.
The hard conversation is explaining to a correspondent bank why volume flows through a pool where nobody on either end has attested to anything.
Privacy Boost has no connection to the Tornado Cash matter. The point is architectural.
Different tools, different jobs
Privacy coins protect an asset few people want to transfer value in. Privacy chains protect a domain you have to bridge into. At the transaction level, Privacy Boost and Soulbound Finance are differentiated offerings rather than rivals on one scale.
Privacy Boost is an advanced mixer: deep cryptographic concealment inside its pool, delivered through a larger system with upgradeable rules, more privileged roles and a conditional exit.
Soulbound Finance is built for regulatory approval: per-transaction attestations, on-chain Soulbound ID with zero-knowledge verification, no stored addresses anywhere in the stack, immutable rules and an unconditional exit.
Soulbound Finance has been live on Arbitrum mainnet since April 2026.
The protocol-level security review behind this piece was conducted by Gakarot, Director of Blockchain Security at Soulbound Security. Questions on the analysis: gakarot@soulboundsecurity.io.


Excellent article on the three privacy architectures and p2p competitive.