66 EIP candidates. One goal: native privacy on Ethereum’s L1. But the gap between a proposal pool and a functioning protocol is measured in years, not weeks.
The Ethereum Foundation announced that the upcoming Hegotá upgrade will narrow down 66 EIP candidates, with a focus on bringing native privacy to the base layer. On the surface, it’s a bullish signal—developers are active, the roadmap is expanding. But for anyone who has traced the scars left by previous privacy attempts, this is less a breakthrough and more a minefield dressed in cryptographic jargon.
Context: The Privacy Paradox
Ethereum’s historical value proposition rests on transparency. Every transaction, every contract state, is visible to every node. This is what makes DeFi composable and audits feasible. But it’s also what keeps institutional capital on the sidelines—banks don’t want their settlement patterns exposed to competitors. The answer has always been "privacy layers," like Aztec on L2 or Monero as a standalone chain. Hegotá aims to solve this at the L1 level, embedding privacy into the execution layer itself. That’s a paradigm shift, but one that comes with a price tag measured in complexity.
The 66 EIPs currently under consideration represent a broad spectrum—some are privacy-specific, others are routine execution optimizations. The term "narrowing" signals that the final scope is still undecided. This is standard for Ethereum’s upgrade cycle, but it also means that the privacy narrative could be diluted or delayed if core developers decide the trade-offs are too severe.
Core: The Technical Teardown
Native L1 privacy requires new cryptographic primitives—likely zero-knowledge proofs or encrypted state models. The challenge isn’t just writing the code; it’s ensuring that the system remains verifiable under the same security assumptions that currently allow any node to validate the chain. If you hide the sender, receiver, and amount, how does a validator know the transaction is valid without seeing the data? The answer is some form of shielded execution, but that introduces a fundamental tension: privacy versus programmability.

Based on my audit experience with the Compound oracle exploit and the BAYC wash trading patterns, I’ve learned that complexity is the enemy of security. Every additional cryptographic layer adds surface area for bugs. The Parity heist of 2017 showed that a single library update could freeze millions. Hegotá’s privacy layer will touch every module of the execution layer—gas metering, state access, MEV extraction. The risk of a critical vulnerability is non-trivial.
Performance is another question mark. Privacy operations are computationally heavy. A single shielded transaction on Aztec costs roughly 10x the gas of a standard ETH transfer. At L1 scale, that could push node hardware requirements upward, potentially reducing decentralization. The Ethereum Foundation has historically prioritized security over throughput, but this time the trade-off may be starker.
Regulatory Landmines
The biggest risk isn’t technical—it’s regulatory. Tornado Cash was sanctioned by OFAC in 2022, and its developers faced criminal charges. If Ethereum L1 becomes a native privacy layer, every exchange, custodial wallet, and stablecoin issuer will have to decide whether to interact with transactions that hide the source of funds. The travel rule, KYC, and AML frameworks all assume traceability. Native privacy breaks that assumption.
"Hype is a mask; the ledger is the face beneath it." But if the ledger hides the face, regulators will demand a mirror. Hegotá could force a fork between a compliant, transparent Ethereum and a censor-resistant, private one. That’s not a theoretical risk—it’s a replay of the Bitcoin scaling debates, but with higher stakes.
Governance: The 66-Candidate Gauntlet
Narrowing 66 EIPs to a manageable set is a political process. Each proposal has a champion—a researcher or client team—and each has trade-offs. Core developers meet weekly in ACD calls, but decisions are made by rough consensus. The history of Ethereum upgrades shows that ambitious proposals often get postponed to later forks. The Dencun upgrade, for example, originally included EIP-4844 (proto-danksharding) but delayed other features.
If Hegotá tries to bite off too much, it may end up as a "mixed upgrade" that delivers minor optimizations while the privacy dream is pushed to a future hard fork. That would deflate the narrative and waste developer attention. The prudent approach would be to start with a limited privacy feature—like optional private transactions for specific contract types—and iterate. But that’s not what the market wants to hear.
Contrarian: What the Bulls Got Right
Despite the skepticism, there are genuine reasons to be optimistic. The demand for on-chain privacy is real, and the current solutions (Tornado Cash, Aztec, Monero) are either compliance-heavy or architecturally separate. If Ethereum can ship a native, programmable privacy layer that allows selective disclosure (e.g., revealing tx details to a trusted auditor), it would unlock institutional use cases that are currently stuck in pilot purgatory.
"Numbers have no emotions, only consequences." The consequence of inaction is that Solana, Fhenix, or other competitors will capture the privacy narrative. Hegotá’s first mover advantage is real, even if the timeline is long. The Ethereum Foundation has a track record of delivering complex upgrades—Dencun, the Merge, and the Beacon Chain all faced similar early skepticism.
Takeaway: Accountability, Not Hype
The market is treating Hegotá as a bullish narrative seed. But a seed needs soil, water, and years of care before it bears fruit. The 66 EIPs are a sign of life, not a guarantee of delivery. Investors and developers should focus on the specific EIPs that get selected, the testnet results, and the regulatory signals from the U.S. Treasury and the EU.
"Every transaction leaves a scar on the chain." If Hegotá’s privacy scars are too deep, the chain itself may fracture. Until then, treat the upgrade as a long-term research project, not a near-term catalyst. The ledger will tell the truth—eventually.