Vitalik Buterin Tests AI Privacy Through zkAPI and Tor Routing
Key Takeaways
- •Buterin used a local Qwen 3.8 Flash Next model to compose prompts and coordinate calls to frontier AI systems, reducing the risk that distinctive phrasing or personal details reached remote services.
- •The experiment layered three complementary protections: locally written prompts, private payments through zkAPI using zero-knowledge proofs, and Tor routing to conceal IP addresses.
- •The Ethereum Foundation announced zkAPI on October 1 as private usage credits that let users fund a vault and authorize spending without linking payments to their identity or prompts.
- •Buterin identified four weaknesses, including Tor's poor separation between requests, latency he estimated at 10 to 100 times higher than necessary, local generation of only 20 to 30 tokens per second, and reduced recommendation quality when context was withheld.
- •The experiment follows his September 27 essay describing Ethereum as a cryptographic world computer, with the Hegotá fork planned for next year as the likely last normal fork before recursive STARKs, formal verification, and quantum-safe technology.

Ethereum cofounder Vitalik Buterin has run a self-experiment into whether AI systems can deliver personalized recommendations without the user giving up sensitive personal data. In posts shared on X on October 4, he described using his own health and travel information to generate diet and exercise suggestions, with a local model coordinating requests to more capable remote systems and drawing on their reasoning and knowledge.
The privacy setup combined carefully written prompts, private payments through zkAPI, and Tor routing, with each layer addressing a different source of identity leakage. The experiment speaks to a routine exposure in commercial AI, where paid services can tie every prompt to the paying account and the originating network behind it, so identifying details can accumulate even when a name is never typed. Buterin said the recommendations benefited from the remote input, although the privacy protections still needed improvement. He also reported slow responses and a tradeoff between sharing less information and receiving useful advice.
Three Privacy Layers for AI Queries
Buterin identified his local coordinator as Qwen 3.8 Flash Next, which called frontier models when needed. A skill file guided those calls, instructing the local system to disclose as little personal information as possible.
Doing a bit of a self-experiment. Goal: use my personal health and travel data to provide personalized diet and exercise recommendations for me, using frontier models but in a way that avoids leaking to them any private information. Strategy: use a local model (Qwen 3.8 Flash… pic.twitter.com/mi38E5jlfN
— vitalik.eth (@VitalikButerin) October 4, 2026
The first layer addressed both the contents of prompts and their writing style. Because the local model composed the questions, remote services faced a reduced risk of identifying him through distinctive phrasing or personal details.
The second layer covered payments, which can connect AI requests to an identifiable customer account. For this, the experiment used zkAPI, a system designed to separate payment authorization from user identity. Zero-knowledge proofs, the cryptographic tool underneath, allow a service to verify a claim — such as a vault being funded — without seeing the data behind it. The Ethereum Foundation described zkAPI in an October 1 announcement as private usage credits for paid services. Users fund a vault, then authorize spending with zero-knowledge proofs rather than revealing which deposit paid for the requests. In runtime key mode, temporary API keys cap spending, while signed usage receipts determine the actual charge. The payment service checks funding without receiving the prompts, which go directly to the AI provider.
Tor supplied the third layer, targeting network information such as IP addresses. The long-established anonymity network routes traffic through relays so that a destination service cannot see the user's real address. Buterin accessed zkAPI through a Tor-wrapped command line tool, combining payment privacy with anonymous network routing.
The design treats these protections as complementary because each covers a different route to identification. Removing names from prompts still leaves payment records or network details as potential links. The Foundation also cautioned that AI providers can still read submitted prompts, and its documentation says repeated personal details, reused conversation histories, and writing patterns can allow separate sessions to be linked.
Speed Limits and Data Tradeoffs
Buterin reported that the experiment returned recommendations improved by knowledge from frontier models. However, he identified four weaknesses, spanning network design, request construction, local performance, and the balance between privacy and usefulness — four gaps that would need closing before such a setup could move beyond a personal trial.
He argued that Tor handles separation between individual requests poorly and may provide insufficient privacy for this use. He also estimated that latency was 10 to 100 times higher than it could be. The skill file, meanwhile, needed better strategies for deciding what information remote models should receive, making request preparation another unresolved part of the experiment.
On local performance, Buterin said the Qwen model generated roughly 20 to 30 tokens per second on his setup. He wanted speeds above 100 tokens per second before the system would feel comfortably fast.
The privacy tradeoff also remained visible: withholding more context reduced the help available from remote models. That suggests payment and network safeguards alone cannot preserve personalized recommendation quality when requests omit important contextual details.
Broader Ethereum Vision
The experiment follows a September 27 essay in which Buterin described Ethereum as a future cryptographic world computer, combining blockchain security with cryptographic privacy, verification, and decentralized computing outside the chain. In that essay, he identified Hegotá, planned for next year, as the likely last normal fork. Later development would involve recursive STARKs, automated formal verification, optimized consensus, and quantum-safe technology. Cryptographic proofs run through both efforts: zero-knowledge proofs handle the zkAPI payment layer, while the roadmap points to recursive STARKs and formal verification at protocol scale.
He also cited PeerDAS as an early step toward this broader architecture. The intended result is cheaper, more scalable, and more private computation secured through modern cryptography. With Hegotá slated for next year, that fork stands as the nearest checkpoint for observing how the roadmap's cryptographic components take shape.