- Aztec Labs is relaunching zk.money, a self-custodial wallet that moves payments onto the Aztec Network to hide balances, amounts and counterparties, and lets users send to readable names such as bob.zk.money or request funds through a link. Users can deposit DAI, USDC and USDT from Ethereum, with USDC and USDT converted into DAI on entry so DAI is the only currency used inside.
- The privacy is partial by design. Aztec documentation states that a deposit from Ethereum reveals the sender and the amount, even though the recipient on Aztec can remain private, so the entry point remains publicly visible.
- Limits are tight. Each deposit, payment and withdrawal must be below $2,500, and all users share a $50,000 daily deposit allowance that replenishes over time. A deposit costs 35 cents plus Ethereum fees and a withdrawal 20 cents, with 100 sponsored transactions a day, though payments wait if the contract covering network fees runs short.
- Contributors disclosed a critical flaw in the network V5 proof system in August with a fix planned for V6. Chief executive Joe Andrews said zk.money will launch before that fix is complete, with a separate system called Oxide checking payments for errors caused by software bugs, and users able to migrate once the fix ships.
What Happened?
On Ethereum, anyone holding a wallet address can view its balance and trace past transfers, which can expose a company payments to suppliers or an individual spending history. Andrews said transactions between two people should not mean publishing a financial history to the world, and that DAI was chosen because the firm considers it the most decentralised of the mass-market stablecoins, with other assets possible later. The wallet screens Ethereum addresses used for deposits and withdrawals against a sanctions policy, and a sealed server co-signs operations, though documentation states it cannot spend user funds on its own. The original zk.money ran from 2021 to 2024, serving more than 75,000 wallets and processing over $100 million. The network remains in early Alpha and its software has not been fully audited. Ethereum developers are separately weighing privacy changes for the planned 2027 Hegota upgrade.
Why It Matters?
The most consequential detail sits at the end of the article. Aztec is shipping a product that holds user funds while a critical flaw in its proof system remains unfixed, disclosed by its own contributors in August, with a remedy scheduled for a later version. Oxide, the error-checking system Andrews describes, is a compensating control rather than a fix. Anyone evaluating this should weigh that against the $2,500 transaction cap, which limits individual exposure but does not change the underlying risk. Andrews is at least explicit about it, and the honest framing is that this is experimental cryptography handling real money. The privacy on offer is also narrower than the product description suggests. Deposits reveal both sender and amount, so the chain of custody is public at the point of entry, which follows the same pattern seen in bridge failures where the weakest link defines the security of the whole arrangement. The caps make this commercially marginal for now. A $2,500 ceiling per transaction and a $50,000 daily allowance shared across all users is a retail experiment, not infrastructure any business or substantial holder could use, and readers should not mistake the launch for a meaningful shift in payment privacy. The compliance architecture is the genuinely interesting part. A privacy wallet that screens addresses against sanctions policy and uses a sealed co-signing server is a hybrid, and it means privacy here is conditional on the operator rather than absolute. That is probably the only form regulators would tolerate, given reporting that sanctioned entities received 694% more crypto during 2025 and that European supervisors are making this area a priority from 2027. There is also a small effect on stablecoin issuers, since converting USDC and USDT into DAI on entry reduces their circulating float.
What Next?
The V6 fix for the disclosed proof system flaw is the milestone that matters most, and until it ships the product carries a known unresolved vulnerability. Watch whether Aztec raises the $2,500 and $50,000 caps, which Andrews says requires a new contract and greater confidence, since that is the measure of whether the system is judged sound. A full audit of the software would be the credible signal. On the ecosystem side, the Ethereum Hegota upgrade planned for 2027 could let privacy applications handle approvals and fees with less outside help, which would reduce the need for separate networks. Regulatory attention is the largest external risk, particularly around whether sanctions screening at the deposit and withdrawal points satisfies supervisors in the US and Europe.
Affected Tickers and Coins: ETH, DAI, USDC, USDT, CRCL, COIN
Source: CoinDesk












