
Editor's note: The following conversation has been edited for clarity, brevity, and readability. Questions have been condensed and responses lightly edited to improve flow while preserving the speakers' original meaning.
Key takeaways
- Every public balance, payment, and trade creates competitive risk. Confidential transfers allow businesses to transact onchain without exposing commercially sensitive financial information.
- Regulated finance doesn't require universal transparency but it does require the ability to reveal particular information to approved parties at the appropriate times.
- Confidential transfers make public blockchains practical for enterprise financial workflows, including payments, treasury, settlement, and tokenized capital markets.
Public blockchains achieved trustworthiness through transparency. But moving everyday finance onchain is only practical with confidentiality.
With confidential transfers now available in public beta on Sui, we spoke with Justus Delp, Chief Solutions Officer at Merkle Science, a design partner for confidential transfers, about why protecting commercially sensitive financial information is essential for bringing payments, treasury, capital markets, and other institutional financial workflows onto public blockchains.
The transparency challenge
Abhinav Garg, Group Product Manager, Platform at Mysten Labs: Public blockchains provide transparency, but financial systems rely on confidentiality around balances and transaction amounts. From your perspective, what problem are confidential transfers trying to solve?
Justus Delp: We're coming from a world where every balance, every transfer, and every amount is publicly visible by anyone—whether that's your friend, your competitor, or potentially just a stranger. That's one of the strengths of a public ledger. Everything gets recorded in a decentralized way, everyone can access it, and you can be reassured that balances exist.
But on the other side of the coin, sensitive information becomes public.
Trading activity, balances, payroll, supplier payments, large redemptions, stablecoin balances—anyone can see that information. Competitors can see what you pay a supplier compared to what they pay, renegotiate contracts, or use that information to gain a competitive advantage. If we really want companies to run their operations on blockchain, that needs to be addressed.
It's not only the information itself that's the problem. People can act on it. We've already seen trading bots and MEV take advantage of public information. We've seen address poisoning attacks. At the end of last year, someone lost $50 million USDT because an attacker created a vanity address that looked almost identical to the intended destination after a test transaction.
All of that was possible because the information was publicly visible.
That's really the problem we're trying to solve. How can we continue using blockchain without exposing information that competitors or bad actors can use against us?
Privacy with compliance
Abhinav: Before confidential transfers, different blockchains explored privacy through mixers, zero-knowledge proofs, shielded pools, and other approaches. How have those models worked in practice, and where have they struggled?
Justus Delp: We've largely been living in a world where it's either black or white. You either have public systems or privacy solutions. Mixers are a good example. They solve the privacy problem by making it very difficult to match the funds going in with the funds coming out.
The problem is that compliance was never really part of the design. The technology works, but it was quickly taken advantage of by bad actors who used it to hide illicit funds. Over time, that created a reputation problem for mixers, even though the underlying technology is valid.
We see something similar with Monero. Monero solves the privacy problem, but there's no practical way to selectively disclose information. If someone uses it for illicit activity, it's almost a closed box. There's no straightforward way to investigate what's happening.
Zcash is interesting because it introduced the idea of a view key. However, Zcash's real contribution wasn't privacy - it was selective disclosure: the idea that confidentiality can come with a built-in, cryptographic mechanism for authorized auditing. It never got the surrounding operating model - issuer governance, analytics integration, investigation workflows — so adoption didn't follow. That's the foundation we're completing today.
The common problem we've had is that compliance became an afterthought. That's also what gave privacy technologies such a difficult reputation. If you mention Monero or mixers to regulators or financial institutions today, you don't even want your assets mentioned in the same sentence. Not because the technology itself is flawed, but because of how it's been used and the connotations they carry
Abhinav: It sounds like privacy and compliance have traditionally been treated as opposing goals. Do you see that tradeoff changing?
Justus: I do.
People sometimes think compliance is a bad thing, but compliance is what allows regulated money to move on blockchain infrastructure. The tradeoff used to be that you had to choose between privacy and compliance. What we're trying to do now is narrow that gap by allowing people to have privacy while introducing selective disclosure. Information is only disclosed when there's a reason to be concerned. Otherwise, you don't intervene.
That's what excites me about confidential transfers. We're starting to bridge that gap instead of forcing people to choose one or the other.
From seeing everything to seeing what matters
Abhinav: What does this mean in practice? If I'm an exchange, a payment platform, or a custody provider, what should I expect to be different when supporting confidential assets?
Justus: Not much actually changes.
What happens onchain can be private, but once assets move into the walls of a service—an exchange, a payment platform, or a custodian—they still see balances, deposits, withdrawals, and transaction history just as they do today.
The novel aspect is really the onchain piece.
They still have the behavioral information they need to understand whether an address is behaving normally or whether something looks suspicious.
We're really shifting from a model where you see everything to a model where you see what matters.
Instead of exposing every balance and every transfer amount, analytics systems surface the amounts and transactions that are actually relevant from a compliance perspective. That allows exchanges and payment providers to focus on the activity that matters while still taking the same risk-based approach they're already familiar with in traditional finance.
Banks don't investigate every transaction equally. They investigate the ones that warrant attention. I think confidential transfers move blockchain in that same direction.
It's a nice compromise. We move from seeing everything to seeing what matters, while still allowing institutions to manage risk the way they already do today.
Abhinav: That introduces a much bigger role for analytics providers like Merkle Science. How do you see that role evolving?
Justus: Blockchain analytics has always been important.
The original vision of crypto was financial freedom and pseudonymity. The challenge was that it also attracted bad actors.
Blockchain analytics gave regulated institutions confidence that they could adopt this technology safely by helping distinguish legitimate activity from illicit activity.
Now that confidential transfers introduce privacy, that role becomes even more important.
We're moving beyond simply attributing addresses and increasingly toward behavioral controls and pattern matching. The goal is to surface what actually represents risk while allowing legitimate users to keep their financial activity confidential.
Like any financial system, there will always be bad actors. Our job is to identify those risks, help institutions mitigate them, and give them the confidence to adopt this technology responsibly.
Abhinav: It sounds like firms like Merkle Science become a critical part of making compliant privacy work.
Justus: I think so.
Institutions need confidence that they can use this technology safely. Analytics providers become part of that trust layer by helping regulated entities detect what matters while allowing everyone else to benefit from privacy.
Building trust in confidential finance
Abhinav: We've talked about exchanges and payment providers. How do you think stablecoin issuers gain confidence in this model? What do they need to feel comfortable adopting it?
Justus Delp: I think the stablecoin market has evolved.
We came from a place where issuers were really only held accountable for primary issuance. Companies would complete KYC and KYB, buy the stablecoin, and once it moved into the secondary market, there wasn't much visibility. That also made stablecoins attractive to illicit actors because they wanted the stability of the asset just as much as legitimate businesses did.
Today, issuers play a much more active role. They govern the asset. They hold the view key. They approve access when appropriate, and they can freeze assets when necessary. I think that's one of the things that's made regulators much more comfortable with stablecoins. They know there are mechanisms to intervene when it's necessary.
Working with analytics providers strengthens that even further because issuers can detect suspicious activity in real time and act when it matters instead of weeks or months later. All of the issuers we're working with have expressed a lot of confidence in this evolution.
Ultimately, it's about building trust in the asset.
Institutions need confidence that stablecoins don't introduce unnecessary risk to their business. If they have that confidence, stablecoins become much more practical for settlement, supplier payments, payroll, treasury management, and the broader financial workflows we want to see move onchain.
What confidential finance unlocks
Abhinav: We've talked about institutions. What does confidential finance unlock for builders and users?
Justus: We talk a lot about institutional adoption, but I think this is where it starts to become real.
The payments use case is already here. We're seeing remittances, B2B settlements, and supplier payments move onchain.
What I'm really excited about is what comes next. I think we'll see much deeper integration between traditional financial institutions and DeFi.
A settlement is really just a payment. Once that foundation exists, builders can start creating institutional DeFi infrastructure where banks issue smart contracts, customers hold assets in their own wallets, trades settle in real time, and markets operate continuously. That's where I think builders will really get excited.
Abhinav: And that becomes even more important as we move into agentic systems.
Justus: Exactly.
We're trusting agents with more and more financial activity. It's important that those agents can operate without someone immediately connecting them back to a person or a business simply by observing their financial activity.
The same applies to DeFi. Today, someone can see a trade in the mempool, front-run it, and change the outcome before it settles. Confidentiality helps address those kinds of problems as well.
That's why I think privacy becomes such an important building block for the next generation of financial applications.
Abhinav: Looking ahead, if we're sitting here a year from now, what would success look like?
Justus Delp: I'm very excited to see this model move into production.
For me, success is seeing companies able to plug this into their existing operations and build the confidence to adopt it—not months or years from now, but as soon as it's available.
I'd also look at institutional treasury activity and settlement volume. If exchanges, payment providers, and businesses are adopting the technology, and we see that reflected in growing onchain volume, that's a strong signal that institutions are becoming comfortable with confidential finance.
I'm also very bullish on DeFi. We're already seeing significant progress. Wallets and consumer applications continue to evolve, and we're getting closer to bringing traditional financial services onchain.
I think the privacy element is what's missing right now.
Being able to map those two worlds together is what I would call a successful rollout.





