Skip to main content
Back to Research
ResearchFree

Railgun's Privacy Pool: Down Roughly 45% From Its 2025 Peak

Railgun's privacy pool peaked near $138M in 2025 and has since fallen 45% to about $76M. Here is what its compliance mechanism actually proves.

Kai Nakamoto

Kai Nakamoto

AI Persona - Emerging Tech

13 min read
Reviewed by Kamyar Taher, Editor-in-Chief
Railgun's Privacy Pool: Down Roughly 45% From Its 2025 Peak

Railgun's on-chain privacy pool grew roughly 10x in under two years, reaching an all-time high near $138 million in August 2025, then gave back nearly half of that growth. By the time the Ethereum Foundation built Railgun into its Kohaku wallet toolkit that October, TVL had already slipped to about $106 million. By mid-August 2026, live data from DefiLlama puts it closer to $76 million. That is Railgun's own observed TVL path; this piece has no broader-market or DeFi-sector benchmark series to say whether it moved with or against the rest of crypto, or whether privacy demand itself specifically rose or fell, and the regulatory story behind the protocol turned out to be more contested than the bull case admitted.

The Bear-Market Crypto Privacy Demand Hypothesis

One hypothesis is that bear markets change the incentive to shield a portfolio: speculation gives way to protection, and portfolio visibility becomes a liability rather than a flex. Railgun's own TVL does not support that hypothesis on its face: after peaking near $138 million in August 2025, the protocol's tracked TVL had already fallen to about $106 million by October 2025, and live data from DefiLlama puts it closer to $76 million by mid-August 2026, a decline rather than the rise the hypothesis would predict; this piece has no DeFi-sector or broader-market benchmark to say how that path compared to the rest of the market over the same stretch.

💡

Crypto privacy splits into two distinct categories. Monero and Zcash are privacy coins: standalone currencies with confidentiality built into the base layer. Railgun and Privacy Pools are privacy protocols: add-on infrastructure that shields transactions on top of an existing chain, most often Ethereum.

Three factors are plausible hypotheses for a shift toward protocol-level crypto privacy specifically, none of them verified here against Railgun's own TVL curve, which the Lead already flagged as unable to prove that privacy demand itself specifically rose or fell:

  • Regulatory pressure is one candidate driver. The EU's MiCA framework and tightening exchange compliance requirements could make on-chain crypto privacy a practical necessity for more users, though this piece has no data isolating that effect from the rest of the bear market.
  • Surveillance tool improvements are a second candidate. Standard blockchain transactions are more traceable than they were even two years ago, and chain-analysis firms now correlate activity across multiple networks in close to real time; whether that traceability is itself pushing users toward Railgun specifically is not something this piece can measure.
  • A genuine compliance mechanism arrived. Railgun did not just promise privacy; it built a way to prove funds are absent from a maintained list of known bad transactions, without revealing who owns them. Whether that mechanism is what got builders who avoid Tornado Cash to take Railgun seriously is a hypothesis this piece has not tested against direct statements from adopters; it is not evidence about why TVL rose or fell.

Railgun: An Early, Unaudited Ethereum Foundation Integration

Railgun's central claim is that it fixed a design flaw the protocol attributes to Tornado Cash: in Railgun's framing, Tornado Cash mixed all deposited funds indiscriminately, with no way to distinguish clean deposits from stolen ones once they entered the pool. Tornado Cash was sanctioned by OFAC, an action covered later in this piece; this piece does not have OFAC's own stated rationale for that sanction. Railgun's actual mechanism, which the protocol calls Private Proofs of Innocence, works differently: when a user shields tokens, the protocol generates a blinded zero-knowledge proof that those tokens are not part of a "bad transaction list" maintained by an independent list provider. Crucially, that proof reveals nothing else. Railgun's own documentation is explicit that "all data relating to 0zk addresses (including balances, history, and addresses) are and always will be encrypted to everyone," and that an outside party can confirm funds are legitimate "without revealing any of the encrypted details of the interaction or the user."

That is a narrower and more precise claim than "privacy that satisfies regulators," and it is worth stating plainly: Private Proofs of Innocence proves a negative (these funds are not on a known bad-actor list), not a positive guarantee of full legal compliance for every jurisdiction a user might be in. Anyone reading Railgun's privacy claim as a compliance guarantee is reading past what the protocol actually verifies.

What Actually Shipped in 2026

The Ethereum Foundation's Kohaku initiative is the concrete event behind Railgun's renewed attention: one early SDK integration, not a broader Ethereum roadmap commitment. In October 2025, the Foundation integrated Railgun into Kohaku, its open-source privacy wallet toolkit, and RAIL's price reacted immediately. On May 25, 2026, Kohaku shipped its first public SDK release, published on GitHub, giving any wallet developer a package (@kohaku-eth/railgun) to embed Railgun's shielded pool directly at the wallet layer rather than requiring users to visit a separate app, though the repository marks that code unaudited. That release made ERC-4337 mempool relaying operational for Railgun transactions, letting a shielded transfer reach the chain without exposing the sender's address to the public mempool. Tornado Cash and Privacy Pools integrations are listed in the same repository as separate, still-planned work, not as Railgun's own roadmap.

Vitalik Buterin endorsed the release directly. Responding to the Kohaku update on X on May 26, 2026, he wrote: "We've accelerated narratives enough. Let's accelerate the cypherpunk privacy reality", explicitly framing wallet-level privacy as something to ship rather than debate.

Two things temper the story. First, the Kohaku repository itself warns that "some parts of this project are work in progress and NOT READY FOR PRODUCTION USE. Packages contain UNAUDITED CODE," a caution worth taking seriously before treating wallet-level Railgun integration as a finished product. Second, live TVL data from DefiLlama puts Railgun's total value locked at roughly $76 million as this is written, down from the ~$106 million level around the Kohaku announcement, which was itself already a decline from the protocol's actual peak of ~$138 million in August 2025. Whether adoption of the protocol collapsed cannot be judged from TVL alone, since that figure does not capture volume, active users, or intent. But the headline growth number people cite from late 2025 was already past the real high, not a floor, and any comparison should use the current figure rather than the announcement-day one.

The Compliance Story Is Real, and It Is Also Contested

The idea that crypto privacy and regulatory compliance are opposites is the biggest misconception in this space, and Private Proofs of Innocence is a genuine technical answer to it: a zero-knowledge proof can show funds are absent from a maintained list of known bad transactions, without exposing the sender, the amount, or the destination. That is a real advance over both fully transparent chains and fully opaque mixers, though it proves absence from that specific list, not that the funds are clean by every possible standard.

What it does not do is settle the legal question for the people who build and operate this kind of infrastructure. The clearest test case is Tornado Cash itself. The U.S. Treasury's Office of Foreign Assets Control removed Tornado Cash from its sanctions list on March 21, 2025, ending the entity-level sanction that had made interacting with the protocol itself a sanctions risk. But that delisting did not end the criminal case against Tornado Cash co-founder Roman Storm: his trial began July 14, 2025, and after roughly three weeks he was found guilty on one of three charges, conspiracy to operate an unlicensed money-transmitting business, according to Wikipedia's sourced account of the case.

💡

Read those two facts together, not separately. OFAC delisting Tornado Cash means the protocol is no longer entity-sanctioned. Storm's conviction means a developer of privacy infrastructure was still successfully prosecuted, on a different legal theory, more than two years after the code shipped. "Compliant privacy" may reduce how often a user's transactions get flagged alongside listed bad-actor transactions; whether that translates into reduced legal exposure has not been tested, and it has not yet been tested as a shield for the people who build one.

That distinction matters for how much weight to put on Railgun's own compliance-by-design pitch. Private Proofs of Innocence is a stronger privacy-plus-verification design than anything Tornado Cash offered, and unlike Tornado Cash, Railgun's list-provider model lets a user generate a proof that their funds are absent from a maintained list of known bad transactions, without exposing the funds themselves. That is a proof users can produce, not a filter the protocol applies before funds enter the shielded pool. Whether that difference is enough to change how prosecutors treat the people who operate similar infrastructure is a question the Storm case has not fully answered, since Storm was tried under Tornado Cash's older, unfiltered mixing design rather than a Private-Proofs-of-Innocence-style system.

The Competitive Landscape: Where Railgun Fits

Crypto privacy is not a one-protocol game. The landscape breaks into three tiers:

CategoryExamplesTrade-offs
Privacy coinsMonero, ZcashMonero is private by default; Zcash offers optional shielded transactions alongside transparent ones. Both have faced exchange delistings from platforms citing MiCA compliance
Protocol-level privacyRailgun, Privacy PoolsCompliance-oriented design but depends on base-chain adoption
Native chain privacyPenumbra, AleoPurpose-built but smaller ecosystems

Railgun's advantage is positioning. It operates on Ethereum, BSC, Polygon, and Arbitrum, the chains where DeFi activity is concentrated, and its code is public and reviewable rather than closed. Unlike Privacy Pools, still mostly a research and pilot effort, Railgun is live, with the TVL history documented above, and now has the Kohaku SDK integration on Ethereum specifically.

The competitive risk from Kohaku lands on the wrapper products built on top of Railgun's pool. If Kohaku matures from an opt-in SDK into privacy that ships by default in mainstream wallets, third-party wrapper products built on Railgun could lose much of their reason to exist, even though Railgun would remain the shielded-pool engine underneath. Railgun's counter is its documented TVL history and the Ethereum Foundation's Kohaku integration built on top of its code.

For a broader look at how privacy coins performed in the 2025 rally, our earlier analysis covers the sector-wide price action in more detail. And as institutional players increasingly diverge from retail sentiment, our expectation, not a measured trend, is that demand for transaction confidentiality that does not require trusting a mixer keeps growing regardless of which specific protocol captures it.

What This Means for the Bear Market

The extreme-fear environment that shaped this article's original framing suggested a specific opening for privacy protocols. Whether that opening still holds after Railgun's TVL pullback is an unverified hypothesis, not a measured conclusion.

One interpretation, not something this piece's data can confirm, is that investors hiding portfolio sizes from predatory actors have more reason to want crypto privacy when markets are vulnerable than when they are euphoric, and that whales accumulating during downturns have a stronger incentive than usual to shield transaction sizes from front-runners. The data available here is Railgun's TVL, not transaction volume or investor intent, and that dollar-denominated TVL fell rather than rising over the same period; this piece has no broader-market benchmark to say whether that fall tracked, outpaced, or lagged the rest of crypto. Separately, tools that can demonstrate a working compliance mechanism may be better positioned to survive bear-market regulatory scrutiny than mixers with no filtering step at all, though this piece has not tested that claim against an enforcement case involving a compliance-oriented protocol.

Multiple jurisdictions have imposed bans or restrictions on privacy coins specifically. Whether that restriction shifts trading activity toward protocol-level tools like Railgun, which separate the privacy layer from the base asset, is a hypothesis this piece has not tested against Railgun's own volume or user-count data; only the TVL figures above are tracked here.

Risk Assessment

Crypto privacy carries real risks that go beyond ordinary market volatility.

Regulatory exposure is not settled. Storm was tried over Tornado Cash's older design, so his conviction leaves untested how a court would treat a privacy-plus-verification design as a defense for the people running similar infrastructure. A single high-profile enforcement action against a "compliant" protocol, rather than an unfiltered mixer, would land differently than anything seen so far.

The TVL decline is a real observation, not noise. Measured against Railgun's actual peak, about $138 million in August 2025, the current ~$76 million figure is a roughly 45% retracement, not the 29% a comparison against the October $106 million level would suggest, since that October number was already a decline from the true high rather than the high itself. That does not make the protocol unhealthy, but it means neither the $106 million nor the $138 million figure should be quoted as a current number.

Kohaku ships with an explicit unaudited-code warning. Wallet-level integration is early. Bugs in the relay layer, not just the core Railgun contracts, are now part of the attack surface for anyone using an EF-integrated wallet.

Competition from Kohaku itself. If Kohaku's privacy features become default rather than opt-in, third-party wrapper products built on top of Railgun could lose their reason to exist even as the underlying shielded-pool protocol keeps functioning.

The STRICT score for Railgun reflects these dynamics. Innovation scores high at 8.5/10, driven by the Private Proofs of Innocence design and multi-chain deployment. Transparency sits at 6.5/10: the protocol's code is open source and its mechanism is documented in detail, but the team behind it still operates with limited public visibility compared to fully doxxed competitors.

Looking at What the Numbers Actually Say Now

Two verifiable data points anchor where this stands as of August 2026, rather than at the article's original publication. Railgun's total value locked, tracked live by DefiLlama, sits around $76 million, down roughly 45% from its true peak near $138 million in August 2025 (TVL had already slipped to about $106 million by the October 2025 Kohaku integration), but still roughly 5.6x where it started in early 2024, when TVL opened the year near $13.6 million. And the Ethereum Foundation's Kohaku SDK is a shipped, dated, sourced fact rather than a roadmap item: version v0.0.1-alpha.21, released May 25, 2026, with Railgun relaying operational and Tornado Cash and Privacy Pools integrations still in progress.

The broader question is whether "compliant crypto privacy" becomes a permanent category or a temporary narrative built on one integration announcement. The Kohaku SDK and the Storm conviction point in opposite directions on that question: one shows an early privacy SDK integration inside the Ethereum ecosystem, the other shows that building privacy tooling still carries prosecutorial risk that a compliance-oriented design has not yet dissolved. Both are true at once, and neither should be read past what it actually establishes.

Disclaimer: Informational purposes only, not financial advice. Cryptocurrency investments carry significant risk. Always conduct your own research and consult a qualified financial advisor before making investment decisions.

Weekly Crypto Insights

Market analysis and actionable insights. No spam, ever.