manifesto · 001 · compliant privacy on base
Prove you are clean.
Reveal nothing else.
A public ledger records every payment you will ever make. Blend is the layer that lets you move through it unseen — while proving, to anyone who must know, that your money is clean.
Blend — a shielded pool
network · Base
token · $BLEND
working paper 001
I
The ledger sees everything
Every transaction you have ever made on a public blockchain is visible to everyone, forever. Not your bank. Not a subpoenaed record sealed in a filing cabinet. Everyone — a stranger, a competitor, an employer, a border guard, a future government — can open a block explorer and read the whole of your economic life at once: what you hold, who pays you, what you buy, when you sleep, whom you owe, and what you fear.
This was sold as a feature. Transparency, we were told, is the cure for the opacity of the old financial system — for its hidden fees, its unaccountable intermediaries, its quiet frauds. And in one narrow sense that is true: a public chain lets anyone audit the rules. But there is a difference, enormous and deliberately blurred, between the transparency of a system and the transparency of a person. A public rulebook is a virtue. A public diary is a wound.
No functioning society has ever asked its members to broadcast their finances to the world. The cash in your pocket does not announce where it has been. Your salary is not painted on your door. A shopkeeper does not publish, next to the till, a running feed of every customer's balance. We accept — everywhere, in every culture, across every century — that a person is entitled to conduct the ordinary business of living without an audience. Public blockchains quietly revoked that entitlement and called the revocation progress.
The cost compounds. A single leaked address is not a single disclosure; it is a key that unlocks a permanent, searchable, cross-referenced history. Chain-analysis firms exist to do nothing else. They cluster your addresses, tag your counterparties, price your holdings, and sell the dossier. What you did in 2021 is not forgotten in 2026; it is indexed. The chain does not merely see everything. It remembers everything, and forgets nothing, and tells anyone who asks.
A settlement system that exposes its users is not a neutral tool. It is surveillance infrastructure that happens to move money.
Blend begins from this refusal. We do not accept that using programmable money should require surrendering the most basic financial dignity that cash, checks, and bank accounts have always afforded. The transparency of the ledger is real and permanent. The question this document answers is how a person can live inside it without being read.
II
Privacy was the default
For most of economic history, financial privacy was not a right anyone had to argue for. It was simply the texture of ordinary life. Value moved hand to hand, in coin and note, leaving no trace beyond the memory of the two people present. The absence of a record was the default state of the world; a record was the exception, created on purpose, for a reason.
Institutions grew up inside that default. Bank secrecy was, for centuries, a professional obligation, not a scandal. A merchant's ledger was the merchant's own. The state could compel disclosure — with a warrant, a court, a specific and justified cause — but the burden fell on the one demanding to see, not on the person living their life. Privacy was the ground; surveillance was the figure that had to be drawn against it.
The digital era inverted this. Payment by card, by app, by transfer, each transaction now defaults to a record held by an intermediary. We traded the friction of cash for the convenience of rails that watch. For a while the watching was diffuse: your bank knew its slice, the card network knew another, and no single party held the whole. Public blockchains completed the inversion by making the whole visible to every party at once, and by making the record permanent and global rather than private and local.
So when we speak of privacy, we are not asking for something new, exotic, or suspicious. We are asking to restore a condition that every previous form of money took for granted. The novelty is not the desire; the novelty is that fulfilling it now requires cryptography, because the medium itself has been built to expose.
A distinction we will keep
The old world gave privacy by default and disclosure on demand — a warrant, a cause, a record made for a reason. Blend aims at the same shape by different means: privacy by construction, and disclosure that the user can produce, in cryptographic form, when they choose or when they must.
To restore the default is not nostalgia. It is the recognition that a payment system unfit to carry a salary, a rent, a medical bill, or a political donation without exposing all of them is unfit to be money at all. Cash could carry those things privately. Anything that means to replace cash must be able to as well.
III
Secrecy is not privacy
The most important distinction in this manifesto is the one most often collapsed. Privacy and secrecy are not the same thing, and the confusion between them is exactly the confusion that doomed the tools that came before Blend and that fuels the suspicion aimed at the ones that came after.
Secrecy is the withholding of information from everyone, absolutely. It is a wall. Nothing passes it, no matter who asks or why. Secrecy is what a criminal wants: no trace, no accountability, no way for anyone — a counterparty, an auditor, a court — to ever establish where value came from.
Privacy is control over who learns what, and when. It is not a wall but a door with a handle on the inside. A private person is not an unaccountable one. You keep your medical history private, and you disclose it, precisely and selectively, to your doctor. You keep your finances private, and you disclose them, precisely and selectively, to a lender deciding on a mortgage. Privacy is the capacity to make that choice yourself, rather than having the choice made by a default that exposes everything to everyone.
The opposite of privacy is not disclosure. The opposite of privacy is exposure — disclosure you did not choose, to people you did not choose, forever.
This distinction is the whole architecture of Blend in a sentence. We are not building a wall. We are building a door with the handle on the inside — a system where the link between your identity and your activity is severed by default, and where you retain the ability to prove what needs proving: that the money is yours, that it is clean, that it descends from a legitimate source. The proof reveals that fact and nothing adjacent to it.
A tool that offers only secrecy serves the guilty and endangers the innocent, because it makes no distinction between them and so invites the authorities to treat all its users as one. A tool that offers privacy — real privacy, with selective, user-controlled proof — serves the honest majority and gives them a way to stand apart from the guilty. Everything that follows is the engineering of that difference.
IV
The first generation and its ruin
We owe a debt to the tools that came before us, including the honesty to say plainly why they failed. The first generation of on-chain privacy tools — the mixers — proved that cryptographic privacy on a public ledger was possible. They also proved, at great cost, that privacy without a compliance dimension does not survive contact with the world.
Their design was simple and, on its own terms, elegant. Many users deposit identical amounts into a common contract; each later withdraws to a fresh address; because every deposit is interchangeable, no observer can match a given withdrawal to a given deposit. The mathematics worked. The privacy was real.
But the design had a fatal property: it hid everyone, indiscriminately. The honest user seeking to shield a salary and the thief laundering stolen funds received exactly the same cover, and — this is the crucial part — the honest user had no way to distinguish themselves from the thief. Once illicit funds entered the pool, every withdrawal from it inherited the taint by association. The tool that was meant to protect the innocent ended up marking them.
The response was predictable and, from the regulator's chair, not unreasonable. If a system cannot tell clean money from dirty, and offers no mechanism for a user to prove which they hold, then the system itself becomes the unit of suspicion. Sanctions followed. Front-ends fell. Honest users lost access alongside the criminals, and were left holding funds that exchanges would no longer touch.
The lesson, stated exactly
The failure of the first generation was not that it provided privacy. It was that it provided indiscriminate privacy — privacy that could not coexist with an honest user's need to prove their innocence. The mistake was architectural, not moral.
Blend takes this lesson as its starting premise rather than its eventual regret. Privacy that lasts must be compatible with compliance — not compliance imposed by a gatekeeper who can freeze and seize, but compliance the user can demonstrate, cryptographically, without surrendering their privacy to do so. The first generation proved the primitive. We intend to prove that the primitive can survive.
V
Two freedoms, one design
There are two freedoms that most people believe cannot be held at once, and the entire wager of Blend is that they can. The first is the freedom to transact privately — to move value without broadcasting it. The second is the freedom to participate in the legitimate economy — to hold funds that a counterparty, an exchange, an employer, or a court will accept as clean. For a decade the market has been told to choose one.
Choose privacy, and you inherit the mixer's fate: your funds become interchangeable with everyone else's in the pool, including the worst of them, and the honest world learns to keep its distance. Choose acceptance, and you accept the ledger's exposure: every payment legible, every history permanent, privacy surrendered as the price of being allowed to participate. The two freedoms were framed as a dial with a single needle — turn toward one, turn away from the other.
Blend's claim is that this was never a dial. It was a failure to separate two questions that only looked like one.
The two questions are these. Who are you? And where did your money come from? The old designs answered both together or neither together — reveal your identity and your provenance is legible, or hide your identity and your provenance is unknowable. Blend answers them separately. It severs the link between your identity and your activity, so the first question goes unanswered by default. And it lets you prove your provenance — that your funds descend from a legitimate, approved source — without re-attaching your identity to do so.
You get privacy and provenance at once, because provenance never required identity in the first place. It only ever required a proof. The rest of this manifesto is the demonstration that such a proof exists, is efficient, is honest, and can be built on infrastructure that already exists today, on Base, in production, in your browser.
VI
Clean, and only that
The sentence at the head of this document is not a slogan. It is a specification. Prove you are clean; reveal nothing else. Every word carries weight, and the discipline of the design is the discipline of that final clause — nothing else.
When you withdraw from Blend, you produce a proof. That proof establishes exactly one economic fact: that the funds you are withdrawing entered the system through a deposit that belongs to an approved set of legitimate deposits. It does not reveal which deposit. It does not reveal your identity, your other holdings, your counterparties, the timing of your original deposit, or any link between your withdrawal address and the address that funded you. It reveals membership in a set of clean funds — and it reveals it in zero knowledge, meaning the verifier learns that the statement is true and learns nothing further.
This is a profoundly different posture from both the exposure of the raw ledger and the secrecy of the mixer. The raw ledger reveals everything. The mixer reveals nothing — including, fatally, the one thing an honest user needs to reveal. Blend reveals one thing, the right thing, the minimum thing: this money is clean.
Minimum disclosure as a principle
Good privacy engineering is the relentless minimization of what is revealed. Not "hide as much as possible" — that is the mixer's error, which hides even what should be provable. The principle is: reveal exactly what a legitimate counterparty needs and not one bit more. For clean funds moving through a compliant system, that minimum is provenance. Blend discloses the minimum and protects the rest absolutely.
The consequence is that an honest user of Blend is not merely hidden in a crowd. They are hidden in a crowd and able to step forward, on demand, holding a receipt that proves they belong to the legitimate part of it. The criminal, holding funds that cannot descend from the approved set, cannot produce that receipt. For the first time, the honest and the illicit are distinguishable inside a private system — not by surveilling the honest, but by empowering them to prove.
VII
The association set
The mechanism that makes this possible is called the association set, and it is the single idea that separates Blend from the tools that preceded it. Understanding it is understanding the whole thesis in its concrete form.
An association set is a curated list of deposits deemed legitimate. Membership is established by provenance — a deposit qualifies because it can be shown to originate from a source outside the set of known illicit activity. The set is published as a compact cryptographic commitment, a single value that summarizes the entire membership without listing it. Anyone can check a claimed membership against that commitment; no one can read the membership off it.
When you withdraw, your proof demonstrates that your deposit is a member of the current association set — without revealing which member. You are not saying "I am deposit number 4,812." You are saying "I am one of the deposits in this approved set, and here is a proof you can verify, and no, I will not tell you which one." The verifier checks the proof against the published commitment and is satisfied, learning only that you belong.
The association set turns provenance into a property you can prove about your funds, rather than a history someone can read off your funds.
This inverts the mixer's failure precisely. In a mixer, illicit funds contaminate the pool because there is no way to exclude them and no way for honest users to prove they are not among them. In Blend, the association set defines what "clean" means and lets each honest user prove they are inside that definition. Illicit deposits may exist in the underlying pool — anyone can deposit — but they cannot join the association set, and so their holders cannot produce a valid withdrawal proof against it. The taint does not spread, because cleanliness is proven per-note, not assumed per-pool.
Who curates the set, and by what criteria, is a question of governance and neutrality that we return to in Part IV. What matters here is the shape of the primitive: a public standard of legitimacy, committed to cryptographically, against which any user can privately prove their own compliance. That primitive is the hinge on which compliant privacy turns.
VIII
The crowd
Privacy is never produced alone. A single person transacting through any system, however cryptographically sophisticated, is a single person: their deposit and their withdrawal, being the only ones, are trivially linked. Privacy is a collective good, produced by a crowd and shared among its members. The pool is the crowd, and its name is where "Blend" comes from — not the blending of clean money into dirty, which is the mixer's sin, but the blending of each honest participant into the many.
The pool holds deposits of a fixed denomination together in a single contract. Fixed denominations are not an inconvenience; they are load-bearing. If amounts varied, an observer could match a deposit to a withdrawal by size alone — a deposit of 1.37 ETH and a later withdrawal of 1.37 ETH are almost certainly the same funds, no matter how the link is otherwise obscured. Standard denominations make every note in a pool interchangeable, so that a withdrawal could correspond to any deposit the pool has ever received.
From this comes the central, unglamorous truth of every privacy system, which we will state rather than hide: your privacy is only as strong as the crowd you blend into. A pool with three deposits offers the cover of three. A pool with thirty thousand offers the cover of thirty thousand. The anonymity you receive is not a fixed property of the cryptography; it grows with participation. This is why adoption is not a marketing goal layered on top of a private protocol — it is the privacy. Every honest deposit strengthens every other.
Splitting value
To move a non-standard amount, a user splits it across standard denominations — several notes, each landing in the largest pool it fits, each deposited and withdrawn on its own schedule. Nine small exits spread over time to separate addresses leak far less than one exit that reconstructs the original sum. The client handles the arithmetic; the user sees an amount.
The crowd is also why we reject the framing of privacy as a niche concern for those with something to hide. A crowd is built by ordinary people doing ordinary things — and the larger and more ordinary the crowd, the better the privacy for everyone in it, including those with the most to protect. Privacy is for everyone precisely because it is produced by everyone. The person who says "I have nothing to hide, so I will transact in the open" is not merely exposing themselves; they are thinning the crowd that protects the journalist, the dissident, the ordinary family who does. To join the pool is a small act of solidarity as much as self-interest.
IX
Compliance without gatekeepers
The word compliance has been made to mean its opposite. In the language of the surveillance-finance world, to be compliant is to submit — to hand your identity to a gatekeeper, to let a custodian hold the power to freeze you, to be watched as the price of being allowed to transact. Blend uses the word in its older, cleaner sense: to comply is to meet a standard, and the interesting question is who gets to verify that you have met it, and what they must learn about you to do so.
The gatekeeper model answers: an intermediary verifies, and they must learn everything. You surrender your identity, your documents, your history; they decide whether you pass; and having decided, they retain the power to reverse the decision, freeze your funds, and report your activity. Compliance becomes a relationship of subordination to a party who holds a lever over you. This is the model that public blockchains were meant to escape, and that mixers escaped by abandoning compliance entirely — throwing out the standard along with the gatekeeper.
Blend keeps the standard and removes the gatekeeper. The standard is the association set: an objective, public definition of clean provenance. The verifier is a smart contract, which checks a zero-knowledge proof and learns exactly one bit — valid or not. There is no intermediary who must learn your identity, because proving membership in the clean set requires no identity. There is no custodian who can freeze you, because the contract holds no discretion. You comply by proving, not by submitting; you meet the standard without kneeling to anyone who enforces it.
Compliance was never supposed to mean surrender. It meant meeting a standard. Blend restores the standard and retires the one who used to hold it over you.
This is the difference between being permitted and being able to prove. A permission can be revoked; a proof cannot be un-proven. When your legitimacy lives in a cryptographic fact about your funds rather than in a gatekeeper's ledger of who is allowed, no one can quietly move you from the allowed column to the forbidden one for reasons that have nothing to do with the cleanliness of your money. Compliance without gatekeepers is compliance that cannot be weaponized against the compliant. That is the only kind worth having.
X
The note
At the base of the system is an object small enough to hold in your hand and powerful enough to hold your funds. It is called a note, and it is a secret you generate on your own device, never transmitted, never stored by anyone but you. From it everything else is derived. Whoever holds the note holds the money; lose it and the money is gone, with no one to appeal to. This is not a flaw to be apologized for. It is the shape of self-custody, stated without euphemism.
A note is a pair of random values, produced entirely client-side: a secret, which will prove your ownership when you exit, and a nullifier seed, which will produce a one-time spend tag that prevents your note from ever being used twice. Neither value leaves your machine. What leaves your machine, at the moment of deposit, is only a commitment — a cryptographic hash that binds you to the note while revealing nothing about it.
The commitment is published on the chain as a leaf in the pool's accumulator. It is a promise with no readable content: it proves that some note exists, that you knew it when you deposited, and that you are bound to it — but it discloses neither the secret nor the seed, and it cannot be reversed to recover them. The chain sees a meaningless-looking number. You hold the only key that gives it meaning.
The note is a bearer instrument, born on your device, known to no one else. Back it up the moment you make it. There is no reset, because there is no one holding a copy to reset from.
This is where privacy and self-custody become the same fact rather than two features. Because the note never touches a server, there is no database to breach, no operator to subpoena, no custodian to fail. The system cannot leak what it never holds. The burden this places on the user — guard your note — is the exact price of removing every other party's power over your funds. We think it is a price worth naming honestly and paying deliberately.
XI
The proof
When you withdraw, you must convince the contract of several things at once, and convince it of nothing beyond them. You must show that you know a note whose commitment sits in the pool. You must show that this note has not already been spent. You must show that the note's deposit belongs to the current association set. And you must do all of this without revealing which note is yours, which deposit, or who you are. The instrument that accomplishes this is a zero-knowledge proof.
A zero-knowledge proof is one of the genuinely strange and beautiful results of modern cryptography: a way to demonstrate that a statement is true while revealing nothing about why it is true. The verifier finishes convinced that you possess a valid note in a clean deposit, and leaves knowing exactly that and no more — not your secret, not your position in the tree, not your association-set index, not your identity. Conviction without disclosure. Certainty without exposure.
The proof is generated on your own device, in your browser, from the note you hold and the public state of the pool. It compiles the several claims — membership in the pool's accumulator, membership in the association set, correctness of the derived nullifier, ownership of the secret — into a single compact object that the on-chain verifier can check in a fixed, small amount of work. Producing it takes seconds on an ordinary machine; checking it costs the network almost nothing.
What the proof does and does not rest on
The integrity guarantees — that no one can steal, forge, double-spend, or exit with dirty funds — rest only on standard cryptographic hardness and the soundness of the proof system. The privacy guarantees additionally treat the hash as an ideal random function. A reader who rejects that idealization still keeps every integrity property. Soundness and privacy rest on different, clearly separated assumptions, and we do not blur them.
This is the technical heart of the whole thesis. Everything Blend claims — privacy and provenance held together — reduces to the existence of a proof that says "clean" and says nothing else. That proof is not speculative. It is the well-studied machinery of succinct zero-knowledge arguments, applied with care to a specific, honest statement. The cryptography is not where the risk lives; the cryptography is the part that works.
XII
The nullifier
A private system faces a problem the transparent ledger solves trivially: if no one can see which note you are spending, what stops you from spending it twice? The transparent chain prevents double-spending by watching every coin. A private system must prevent it while watching nothing. The answer is the nullifier — a mechanism as clever as it is quiet.
From your note, and only from your note, your client derives a deterministic value called the nullifier hash. It is a one-time spend tag: the same note always produces the same tag, and no other note can produce it. When you withdraw, you publish this tag. The contract records it. Should anyone ever attempt to withdraw again using the same note, the tag they produce will already be on record, and the contract will reject the attempt.
The elegance is that the tag reveals nothing about the note it came from. It cannot be reversed to identify your deposit; it cannot be linked to your commitment; it cannot be tied to your identity. It is simply a fingerprint that is unique to the note and meaningless to everyone but the contract's bookkeeping. The chain accumulates a list of spent tags, learns nothing from them, and yet is made perfectly certain that no note is ever spent twice.
The nullifier is how a system that sees nothing nonetheless permits nothing to be stolen. Privacy and integrity, in one small deterministic value.
Here again the design refuses the false choice. One might assume that hiding transactions must weaken the guarantees that transparency provides — that you cannot have both secrecy and soundness. The nullifier is the proof that you can. The pool conserves value exactly; every unit that leaves corresponds to a unit that entered; no note is double-spent; and none of this requires the network to see who is doing what. The books balance in the dark.
XIII
The tree
Every commitment ever deposited must be remembered, so that a withdrawal can prove its note is among them — and yet the proof must be cheap to check even when the deposits number in the millions. The structure that squares this is an accumulator, and the accumulator Blend uses is a tree: a hierarchy of hashes that folds an unbounded set of commitments into a single value called the root, small enough to hold on-chain and rich enough to prove membership against.
The idea is quiet and deep. Each commitment is a leaf. Pairs of leaves are hashed together into parent nodes, those parents hashed into grandparents, and so on up to a single root that summarizes the entire set. To prove that your commitment is in the tree, you do not reveal the whole tree; you reveal a short path — the handful of sibling hashes along the route from your leaf to the root. Anyone holding only the root can follow that path and confirm your leaf belongs, while learning nothing about the millions of other leaves or which one is yours.
This is what makes privacy scale. The pool can accept any number of deposits, and each withdrawal still proves membership with a proof of fixed, small size — a path through the tree, folded inside the zero-knowledge proof so that even the path itself is hidden. The verifier checks the proof against the current root and is satisfied. The root is the pool's entire memory, compressed to a single number, and it is enough.
Two roots, two questions
A Blend withdrawal proves membership against two accumulators at once: the pool's tree, which answers "is this a real, unspent deposit?", and the association set, which answers "is this deposit clean?". Two roots, two proofs of belonging, one combined argument — and neither reveals which member you are. Provenance and validity, established together, in the dark.
The tree is unglamorous infrastructure, the kind of thing that never appears in marketing and quietly does the essential work. But it is where the promise of the crowd becomes real: it is the structure that lets a pool grow to hold everyone's deposits together, indistinguishable, and still let each honest holder prove they are inside it. A big crowd is only useful if you can prove membership in it cheaply and privately. The tree is how.
XIV
The ceremony
Honesty requires us to describe the one assumption in the system that is not pure mathematics but human ritual. The zero-knowledge proofs Blend uses depend on a set of public parameters that must be generated once, in a procedure called a trusted setup. If the secret randomness used to generate those parameters were known to someone and never destroyed, that someone could forge proofs. The ceremony is how that secret is destroyed, and why we can be confident it is gone.
The mechanism is elegant precisely because it does not require you to trust any single participant. The setup is performed collaboratively by many people, each contributing their own secret randomness and then destroying it. The final parameters are safe as long as even one participant was honest and destroyed their contribution. To compromise the system, every single participant would have had to collude and preserve their secrets — a failure that grows more implausible with every additional contributor. This is the one-of-many guarantee: security that holds unless everyone betrayed it.
We treat this assumption the way we treat every other in this document: named, bounded, and separated from the guarantees that do not depend on it. The trusted setup underlies the soundness of the proofs. A public, well-attended ceremony with many independent contributors reduces the risk to the point where the honest destruction of a single secret among many is all that stands between the system and safety — and that is a threshold the mathematics of the ceremony makes very hard to fail.
We would rather tell you plainly that the system rests on a ceremony, and explain why the ceremony is trustworthy, than let you discover the assumption for yourself and wonder what else we left out.
There is a lesson in the ceremony that runs through all of Blend. Trust, where it cannot be eliminated, should be distributed until it is negligible, made public so that it can be witnessed, and stated openly so that no one is surprised by it. We could have passed over the trusted setup in silence, as many projects do. We describe it because a manifesto that hides its one soft assumption has forfeited the right to be believed about the hard ones.
XV
The last link
There is a subtle way for all of this careful machinery to leak, and an honest manifesto must name it. Suppose everything above works perfectly: your deposit is unlinkable to your withdrawal, your proof reveals only cleanliness, your nullifier discloses nothing. You go to withdraw to a fresh address — and that fresh address has no funds, because it is fresh, and so it cannot pay the gas fee the network requires to process the withdrawal. If you fund it from an address already tied to you, you have, in one careless motion, re-attached the very link you spent so much to sever.
This is the last link, and closing it is the job of the relayer. A relayer is a service that submits your withdrawal transaction on your behalf and pays the gas, taking its fee from the withdrawn amount itself rather than requiring you to fund the destination in advance. Your clean funds arrive at a fresh address that never had to be touched by anything connected to you. The chain of custody from your identity to your withdrawal is broken at the one remaining seam.
Crucially, the relayer is not trusted with your funds or your privacy. It cannot steal — the proof and the withdrawal descriptor bind the destination and the amount, and the relayer can only submit what you have authorized. It cannot deanonymize you — it sees a valid proof and a destination address, not a note, not a deposit, not a link. It is a convenience that closes a gap, not a custodian that holds a secret. If one relayer misbehaves or censors, another can serve; the role is permissionless by design.
Privacy is not automatic
Even with the relayer, privacy can be undone by the user's own patterns: withdrawing the exact amount you deposited moments later, reusing addresses, tying a withdrawal to an identifiable action. The protocol severs the cryptographic link. Timing, amounts, and behavior can re-attach it. Good privacy is a practice as well as a protocol, and we will document that practice as carefully as we document the code.
With the last link closed, the circuit is complete: deposit in public, hold a note that no one else can see, prove cleanliness in zero knowledge, spend once and only once, and exit through a relayer to an address that owes nothing to your past. Each piece is modest. Together they are the machinery of a private, compliant, self-custodial payment — the thing that was said to be impossible, assembled from parts that already work.
XVI
Non-custodial by construction
Blend never holds your funds. This is not a policy we adopt and might revise; it is a property of the construction that we could not violate if we wanted to. There is no account we manage on your behalf, no balance we could freeze, no withdrawal we could halt, no key we hold that moves your money. The note is yours, generated on your device, and the contract releases funds to whoever presents a valid proof — including when that person is you and the party who wrote the contract would rather they could not.
The distinction between non-custodial by policy and non-custodial by construction is the distinction between a promise and a fact. A custodian who promises not to freeze your funds can break that promise under pressure — from a regulator, a court, an attacker, or their own change of heart. A system that cannot freeze your funds offers a guarantee no pressure can bend, because there is no lever to pull. We have deliberately built ourselves out of the loop.
The right question to ask of any financial system is not "will they behave well?" but "what can they do to me if they do not?" Our answer is: nothing. We designed it that way.
This has a cost we accept openly. If you lose your note, we cannot recover it. If you make an error the proof permits, we cannot reverse it. There is no support desk that can reach into your funds, because a support desk that could reach into your funds is a lever, and a lever is a vulnerability. The absence of a backdoor for us is the absence of a backdoor for everyone — the attacker who compromises us, the state that compels us, the insider who betrays us. Power we do not hold cannot be turned against you.
Self-custody is often described as a burden, and it is one. But it is the same burden as owning cash, or holding a key to your own home: the responsibility that is the other face of genuine ownership. We will do everything possible to make that responsibility bearable — clear interfaces, careful defaults, honest warnings, good documentation. We will not do the one thing that would lift it, because that one thing is the surrender of your sovereignty back to an intermediary, and the intermediary was the problem.
XVII
Credible neutrality
A protocol that decides what counts as clean holds real power, and power invites capture. The association set — the standard of legitimacy against which users prove their provenance — is the point where Blend's neutrality will be tested. We take that test seriously, because a compliance mechanism that can be quietly bent to exclude the disfavored or admit the connected is not a compliance mechanism; it is a weapon wearing compliance as a costume.
Credible neutrality means the rules apply the same way to everyone, that they are legible in advance, and that no privileged party can make exceptions in the dark. For the association set this implies several commitments: that the criteria for membership are public and objective rather than discretionary; that the sets and their updates are published transparently, so that inclusion and exclusion can be audited; and that the mechanism cannot be used to target individuals for reasons unrelated to the provenance of their funds. A user should be able to know, in advance, whether their clean funds will qualify — and to see, after the fact, that the standard was applied evenly.
This is a hard problem and we will not pretend it is solved by good intentions. Provenance standards can encode bias; curation can drift toward the preferences of whoever curates; pressure can be applied to the point of curation as surely as to a custodian. Our answer is not to claim we are above these forces but to build against them — toward objective criteria, published records, multiple independent providers where the architecture allows, and a long-term path that reduces rather than concentrates discretion. The goal is a compliance layer that a skeptic can verify, not one they must trust.
Neutrality is a design constraint, not a virtue we assert
We would rather be judged by whether the mechanism can be abused than by whether we promise not to abuse it. Where discretion is unavoidable, it should be visible. Where it can be removed, it should be. A neutral protocol earns trust by making trust unnecessary.
We hold this principle even against our own short-term interest, because the alternative destroys the thing itself. A privacy protocol that discriminates is not private; it is a filter that hides its criteria. A compliance layer that plays favorites is not compliant; it is corruption with a proof system attached. Blend is worth building only if it is neutral, and it is worth defending only as long as it stays that way.
XVIII
Against the backdoor
Every generation relearns the same lesson about privacy, and every generation is asked to unlearn it in the name of safety. The demand arrives reasonable and specific: surely, for the worst cases, there should be a way in — a master key, an exceptional-access mechanism, a lawful backdoor that only the good actors can use. Blend refuses to build one, not out of defiance, but because the demand rests on a technical impossibility that decades of hard experience have made undeniable.
A backdoor is not a door that only the virtuous can open. It is a door, and doors can be opened by whoever holds or steals or compels the key. A master key that lets an authority decrypt in the name of justice is the same master key that an attacker will exploit, a hostile government will demand, an insider will sell, and a future regime will inherit and turn to purposes its designers never imagined. There is no cryptographic construction for "accessible to the good, sealed to the bad," because the mathematics does not know who is good. A weakness introduced for anyone is a weakness available to everyone.
You cannot build a lock that opens for the righteous and holds against the wicked. There is only a lock, or a lock with a flaw. The flaw does not check credentials.
This is why the same absence of a backdoor that we described for custody in Article XIII extends to the whole system. We hold no key that can decrypt your activity, because such a key would become the single most valuable target in the system and the single point at which all its guarantees could be broken. The security you receive from Blend is inseparable from the fact that its makers cannot betray it — that there is no privileged position from which the whole can be unlocked, not for us, not for an attacker who becomes us, not for anyone who compels us.
We understand that this makes some genuinely hard cases harder, and we do not pretend otherwise. But the alternative is not a system that catches only the guilty; it is a system that exposes everyone, forever, on the theory that the exposure will mostly be used well. History is unkind to that theory. The compliance Blend offers works the other way: it does not weaken privacy for all to enable access to some, but empowers each honest user to prove their own legitimacy, leaving the wall around everyone else intact. That is the only design that protects the innocent without building the weapon that will eventually be turned on them.
XIX
Privacy as public infrastructure
We do not think of privacy as a product we sell to individuals who want it. We think of it as infrastructure a society needs, in the way it needs roads, courts, and the secret ballot — a public good whose value is diffuse, whose absence is catastrophic, and whose provision cannot be left to the goodwill of whoever happens to control the rails.
Consider what depends on financial privacy once you look for it. A journalist paying a source. A dissident receiving support across a border. A business protecting its margins and supplier terms from competitors who could read them off the chain. A family whose wealth, if broadcast, would make them a target. An employee whose salary is nobody's business but their own. A donor to an unpopular cause who is entitled to give without retaliation. None of these people has anything to hide in the sense the phrase implies. All of them have everything to protect.
Strip privacy away and you do not merely inconvenience these people; you chill the activities themselves. Sources stop talking when payment reveals them. Donors stop giving when giving is exposed. Ordinary economic life contracts into the shape that surveillance permits. The harm of a transparent-by-default financial system is not primarily the transactions it exposes; it is the transactions that never happen because exposure was certain. Privacy is the precondition for a wide range of legitimate behavior, most of which we will never see, because it is precisely the behavior that surveillance suppresses.
A society is not free because its members have nothing to hide. It is free because they are not required to show.
Treating privacy as infrastructure changes how we build. Infrastructure must be neutral, durable, and available to all — not tuned to the profitable user, not withdrawn when it becomes inconvenient, not quietly degraded to serve some other end. It must outlast its builders. Our ambition for Blend is not to own a private payment rail but to help establish one that no one owns — a public good that persists because it is useful, credibly neutral, and beyond any single party's power to revoke, including ours.
XX
The honest limits
A manifesto that only makes claims is propaganda. This one intends to be trustworthy, and trust is built as much by naming what a thing cannot do as by celebrating what it can. So here, plainly, are the limits of Blend — the things it does not promise, the ways it can fail, the responsibilities it cannot lift from the user.
Blend does not make you anonymous against your own carelessness. The protocol severs the cryptographic link between deposit and withdrawal; it cannot sever the behavioral link you create by reusing an address, withdrawing a telltale amount, or acting at a telltale time. Privacy is a joint product of the protocol and your practice. We will document the practice, but we cannot enforce it.
Blend does not make weak privacy strong by cryptography alone. Your anonymity is bounded by the size of the crowd you join; a thin pool offers thin cover regardless of how sound the proofs are. Early users accept weaker privacy than later ones — an honest fact about every privacy system, and one we will not obscure with reassuring language. The set grows with participation, and until it is large, its protection is modest.
Blend does not guarantee that every jurisdiction will treat its use the way we believe it should be treated. The law surrounding financial privacy is unsettled and varies by place, and it will keep moving. We build toward a compliance mechanism that gives honest users a way to demonstrate legitimacy, because we believe that is both right and durable — but we do not, and cannot, promise that a proof of clean provenance will satisfy every authority in every place at every time. Users remain responsible for their own conduct under their own law.
Why we say this out loud
Every failure mode named here is a failure mode of all honest privacy systems; the dishonest ones simply do not mention them. We would rather lose a user to clear-eyed caution than keep one on a false promise. A tool you understand is a tool you can use safely. We are trying to give you that.
None of these limits refutes the thesis; each one sharpens it. Blend is not magic and does not ask to be treated as such. It is a carefully built machine that does a specific, valuable thing — private, compliant, self-custodial payment — within honest bounds, for users who understand those bounds. That is a smaller claim than the marketing of this industry usually makes, and a far more durable one.
XXI
$BLEND
A protocol meant to be public infrastructure needs a way to sustain itself, coordinate its participants, and resist capture, without reintroducing the very intermediary it was built to remove. $BLEND is the instrument of that coordination. It is not the point of Blend — the point is private, compliant payment — but it is the mechanism by which the protocol funds its upkeep, aligns those who maintain it, and distributes the authority to govern it beyond any single hand.
We state our discipline about the token before its details, because in this industry the order is usually reversed and the reversal is usually the tell. A token should exist to serve the protocol, not the protocol to pump the token. Where the two conflict, the protocol wins. We would rather have a smaller token attached to infrastructure people rely on than a larger one attached to a thing they have already left. Everything about $BLEND is designed to keep that ordering intact.
The functions we intend for $BLEND are the functions a protocol like this genuinely requires: to align the parties who operate its supporting services — relayers, association-set providers, and the maintainers of its code — so that the network of honest actors is incentivized to stay honest and available; to route a share of protocol fees toward the continued development, auditing, and defense of the system; and to distribute governance over the parameters that must remain adjustable, so that no founder, company, or investor holds unilateral control over a piece of public infrastructure.
On specifics
Supply, distribution, emissions, and the precise mechanics of fee capture are commitments too consequential to improvise in a manifesto. They will be published in a dedicated token document, in full, before they bind anyone — with the same discipline of honest limits that governs the rest of this text. This section states the philosophy the specifics must obey; it does not substitute for them.
What we will commit to here is the posture: no design that enriches insiders at the expense of users; no mechanism that makes the token's price depend on extracting value from the people the protocol is meant to serve; no governance capture dressed as decentralization. If $BLEND cannot be built on those terms, it should not be built. The measure of the token is whether, years from now, it is still doing the quiet work of keeping a piece of neutral infrastructure alive — not whether it spiked.
XXII
Why B20
$BLEND is issued as a native B20 token — Base's own token standard, built into the chain itself rather than deployed as a separate contract. The choice is deliberate and it is characteristic: we prefer standards to bespoke code, audited primitives to hand-rolled ones, and infrastructure that the whole ecosystem shares to infrastructure only we understand.
B20 mirrors the familiar fungible-token interface, so every wallet, exchange, and indexer treats $BLEND as an ordinary token with no special handling. But because it runs as a native part of the chain rather than as user-deployed code, it inherits properties that hand-written token contracts must reimplement and re-audit each time: a stable interface reviewed once at the protocol level, predictable behavior, and lower operational overhead. For a token meant to underpin infrastructure for years, boring reliability is a feature, and standardization is how you get it.
We will also be candid about a tension a careful reader will notice. The B20 standard includes issuer-level controls — the ability, for some configurations, to restrict or freeze token transfers. This sits uneasily beside a protocol whose entire identity is that it cannot freeze your funds. The resolution is that these are two different layers, and we will keep them cleanly separate. The pool — where your value lives, protected by notes and proofs — is non-custodial by construction, and nothing about the token changes that. The token is a coordination instrument, and the posture we take toward any issuer controls it carries will be governed by the same commitment to credible neutrality that governs everything else: minimized, disclosed, and moved out of any single party's discretion over time.
We chose the standard the ecosystem audits together over the contract only we would maintain. Shared infrastructure is more trustworthy than clever infrastructure.
Choosing B20 is, in miniature, the whole engineering philosophy of Blend: build on what is proven, prefer the boring and the shared, be honest about the trade-offs, and keep the layer that holds people's money as free of discretion as the mathematics allows.
XXIII
Alignment, not extraction
There are two ways to build an economy around a protocol. One aligns the incentives of its participants with the health of the system, so that everyone prospers by making the thing better. The other extracts value from users and routes it to insiders, so that a few prosper by making the thing worse. The industry is littered with the second kind, and the wreckage has taught the market to assume the worst. We intend to earn a different assumption by design, not by assertion.
Alignment means that the people who keep Blend running are rewarded for keeping it running well. A relayer earns a modest, transparent fee for the real service of closing the last link. An association-set provider is compensated for the real work of maintaining a credible, neutral standard of provenance. A developer who improves the protocol, finds a vulnerability, or strengthens the proofs contributes to something whose success they share in. Value flows to those who create it, in proportion to the value created.
Extraction is everything that inverts this: fees that exist to enrich rather than to sustain, emissions that transfer wealth from latecomers to insiders, governance that concentrates rather than distributes, mechanics engineered so that the token's price depends on a stream of new entrants rather than on the usefulness of the system. We name these patterns because naming them is how you commit to avoiding them. A reader should be able to hold this document up against whatever we actually ship and check.
The test we accept
Ask of every economic mechanism in Blend: does this reward someone for making the protocol more useful, or for making it more extractive? If the former, it aligns. If the latter, it does not belong, however profitable. We would rather forgo a profitable mechanism than install an extractive one, because the extractive ones are exactly what killed trust in this space.
This is not idealism at the expense of durability; it is durability correctly understood. Extractive systems are fragile — they depend on a supply of people to extract from, and they collapse when that supply thins. Aligned systems are anti-fragile: the better they serve their users, the stronger they get, and the stronger they get, the better they serve. We are choosing the slower, sturdier path because it is the only one that ends somewhere worth arriving.
XXIV
Governance as restraint
Most governance systems are designed to enable action — to make it easy for a majority, or a quorum, or a delegate, to change the rules. We think the more important function of governance in a protocol like this is the opposite: to restrain action, to make certain changes hard or impossible, to protect the core guarantees from the enthusiasms and pressures of any given moment. Good governance is less a steering wheel than a set of brakes and guardrails.
There are properties of Blend that should never be up for a vote, because they are the properties that make it what it is: that the pool is non-custodial, that no party can freeze or seize user funds, that the association-set mechanism cannot be turned into a tool for targeting individuals, that privacy is not silently weakened. These are not parameters; they are commitments. A governance system worth having is one that puts them beyond easy reach — that can adjust fees and add pools and fund development, while being structurally unable to betray the people who trusted the guarantees.
Where governance must act, it should do so transparently, on a clock, with the changes legible in advance and the record public afterward. Sudden, opaque, discretionary change is the behavior of a custodian, and we have spent this whole document explaining why we refuse to be one. The point of distributing $BLEND governance is not to stage the theater of decentralization but to remove the single points of control that pressure can be applied to — to ensure that no founder can be leaned on, no company compelled, no insider bribed, because no one holds the lever alone.
The measure of governance is not what it lets the powerful do. It is what it prevents them from doing to everyone else.
We are aware of the irony of a founding team writing the rules that are meant to bind founding teams. We accept it as the necessary starting condition and commit to the direction of travel: from more discretion to less, from concentrated control to distributed restraint, from trust in us to verification of the system. If we do this well, the eventual and desirable outcome is that our own power over Blend becomes small, bounded, and finally unnecessary. That is not a loss we tolerate. It is the goal.
XXV
“Isn’t this just a mixer?”
This is the first objection and the most important to answer cleanly, because the surface resemblance is real and the underlying difference is everything. Yes, Blend pools deposits and severs the link between deposit and withdrawal, and so does a mixer. But a mixer offers only that — indiscriminate concealment, with no way for an honest user to distinguish their clean funds from the pool's worst. Blend adds the one thing the mixer structurally cannot: a proof of clean provenance.
The difference is not a feature bolted on; it inverts the security posture. In a mixer, all funds are made equivalent, and the honest user inherits the pool's taint by association with no recourse. In Blend, each withdrawal must prove membership in the association set — the public standard of clean provenance — and funds that cannot descend from that set cannot produce a valid proof. The honest user does not merely hide; they hide and hold a receipt distinguishing them from the illicit. The mixer makes everyone the same. Blend lets the clean prove they are clean.
So the honest answer to "isn't this just a mixer?" is: it shares the mixer's privacy and rejects the mixer's fatal flaw. It is what a mixer would have had to become to survive — privacy that carries proof of legitimacy, concealment that does not require abandoning compliance. The resemblance is the starting point. The association set is the departure. Judge Blend by the departure.
XXVI
“Won’t criminals use it?”
Criminals use cash, banks, phones, cars, the postal service, and the internet. The relevant question is never whether bad actors could touch a tool — every useful tool can be misused — but whether the tool is designed to serve them, whether the honest use vastly outweighs the illicit, and whether the design frustrates abuse where it can. On all three, Blend answers clearly.
Blend is designed to serve the honest, and its central mechanism actively disadvantages the illicit. The association set means that funds which cannot demonstrate clean provenance cannot be privately withdrawn against it — the proof simply fails. A tool built for laundering would omit exactly this mechanism, as mixers did; we built it in. Far from offering criminals frictionless cover, Blend raises a barrier precisely where indiscriminate systems offered none: at the boundary between clean and dirty funds.
A tool that helps the innocent should not be forbidden because the guilty exist. It should be built so that the guilty gain the least, and the innocent the most.
The deeper point is one of proportion and precedent. If the mere possibility of criminal use justified banning a technology, we would have no encryption, no private messaging, no cash, no locks on doors. Society has repeatedly decided that the enormous benefit of these tools to ordinary people outweighs their misuse by a few — and it defends against the misuse by targeting the acts, not by exposing everyone. Blend takes the same stance and goes further, engineering its compliance layer so that honest use is empowered and illicit use is structurally disfavored. That is more than most tools do, and far more than the transparent ledger does.
XXVII
“What if the association set is captured?”
This is the sharpest objection, and we respect it, because it aims at the true soft point of the design. The association set is where power concentrates: whoever defines clean provenance holds influence over who can privately transact. A captured set could exclude the disfavored, admit the connected, or become a covert instrument of the very surveillance the protocol exists to prevent. We do not wave this away. We build against it, and we tell you exactly how, so you can check.
The defenses are those named in Article XIV, made concrete. Criteria for membership should be objective and public, not discretionary, so that inclusion can be predicted and audited rather than granted. The sets and their updates should be published transparently, so that exclusion leaves a visible trace. Where the architecture allows, multiple independent providers should compete, so that no single curator holds a monopoly on the definition of legitimacy. And the long-term direction should reduce discretion rather than entrench it. None of these is a promise to be good; each is a structural constraint that makes capture visible, costly, or impossible.
We will also say what we cannot promise. We cannot guarantee that pressure will never be applied to the point of curation, any more than we can guarantee it for any institution. What we can do is refuse to build the mechanism that would make captured curation invisible — refuse the secret blocklist, the discretionary exception, the unaudited update. If the set is ever bent, we want it to be bent in the open, where users, watchdogs, and competitors can see it and route around it. A neutral protocol is not one that promises never to be pressured. It is one where pressure cannot act in the dark.
Hold us to this above all else. Of everything in this manifesto, the neutrality of the association set is the commitment most worth watching, because it is the one whose betrayal would most quietly turn Blend into the opposite of what it claims to be. We have made it the center of our stated principles precisely so that its failure would be a visible violation of a public standard — and not, as capture usually is, a slow drift no one agreed to.
XXVIII
“What about the regulators?”
We do not treat regulators as an enemy to be evaded, and we do not treat them as an authority to be appeased into abandoning our users. We treat the regulatory question as a design problem, and we believe the design answers it better than either evasion or surrender could. The reason the first generation of privacy tools was shut down is not that they were private; it is that they offered no way to tell clean money from dirty, and so left authorities no option but to treat the whole as suspect.
Blend's entire architecture is a response to that failure. By giving honest users a cryptographic means to demonstrate clean provenance, it does the thing the mixers could not: it distinguishes the legitimate from the illicit without surveilling the legitimate. This is not a concession that weakens privacy to placate authority; it is a design that makes privacy and legitimate oversight coexist, which is precisely the combination that regulators have said, again and again, that they actually want. We are not betting that regulators will tolerate privacy. We are betting that they will accept private compliance once it exists, because it gives them what indiscriminate secrecy never could.
The durable path is not privacy that hides from oversight, nor oversight that abolishes privacy, but privacy that carries its own proof of legitimacy. We are building the third thing.
We are also clear-eyed. The law is unsettled, it varies by place, and it will keep moving, and we cannot promise that every authority in every jurisdiction will greet compliant privacy warmly on the first day. What we can do is build the tool that makes the honest case impossible to ignore: a system where an honest user's legitimacy is a verifiable fact rather than a plea. Over time, we believe that changes the conversation from "should private transactions be permitted?" to "here is how private transactions prove they are clean." That is a conversation privacy can win, and it is the one Blend is designed to have.
XXIX
“Why should we trust you?”
You should not, and we have spent this entire document trying to make sure you do not have to. That is not a rhetorical flourish; it is the organizing principle of the whole design. Every place where Blend could have asked for your trust, we have tried instead to remove the need for it — and where we could not remove it, we have tried to name it, bound it, and make it something you can verify rather than something you must take on faith.
We cannot take your funds, because the pool is non-custodial by construction, not by our promise. We cannot forge or steal, because the proofs are sound on assumptions you can inspect. We cannot secretly weaken your privacy, because the code is open and the deployments are on-chain. We cannot quietly capture the association set, because we have committed to public criteria and transparent updates and invited you to watch. At each point, the answer to "why trust you?" is "you don't have to — here is the thing you can check instead."
Where trust genuinely remains — in the trusted-setup ceremony, in our conduct during the period before governance is distributed, in our discipline about the token — we have said so plainly, in this document, rather than letting you discover it later. A project that hides its residual trust assumptions is asking for blind faith. A project that lists them is asking for informed judgment. We are asking for the second, and we have tried to give you everything you need to render it.
So do not trust us. Read the code. Verify the contracts. Watch the association set. Hold this manifesto up against what we ship and mark every place we fall short. The highest compliment you can pay Blend is not belief but scrutiny — because a system built to be verified rather than trusted gets stronger, not weaker, the harder it is examined. We wrote down the standard. Now hold us to it.
XXX
Why Base
A protocol is only as available as the ground it stands on, and we chose Base deliberately. Privacy that reaches only the few who can afford high fees is not the public infrastructure this manifesto argues for; it is a luxury good. The crowd that produces privacy must be able to form, and it forms where transacting is cheap enough that ordinary people transact often. Low, predictable cost is not a convenience on Base. For a privacy protocol, it is a precondition.
Base offers what Blend needs: the security and settlement assurances of Ethereum, the throughput and low cost of a mature layer two, and an ecosystem large enough that a real crowd can gather. Proof generation happens in your browser; verification and settlement happen on Base at a fraction of mainnet cost; the pool can grow deep because depositing into it does not require wealth. The economics of privacy improve directly with the economics of the chain, and Base's are among the best available for the job.
The choice of the B20 token standard is part of the same reasoning. By building $BLEND on Base's native standard, we align ourselves with the chain's own direction rather than working against it — inheriting shared audits, standard tooling, and the compatibility that lets the whole ecosystem treat our token as an ordinary citizen. We are not bolting a privacy protocol onto a reluctant host; we are building on infrastructure whose builders have said, in their own words, that privacy is for everyone. We take them at that word and intend to help make it true.
Privacy is for everyone only if everyone can afford it. That sentence chose our chain.
None of this ties Blend permanently to a single place. The design is portable, the cryptography is chain-agnostic, and public infrastructure should not depend on the fortunes of one host. But a thing must launch somewhere, grow a crowd somewhere, prove itself somewhere. Base is where we begin, because it is where the crowd can form fastest and the cost of joining it is lowest — and the crowd, as we have said, is the privacy.
XXXI
What we will build
A manifesto should be answerable to a roadmap, or it is only a mood. Here is the shape of what we are building, stated as intentions we can be held to rather than promises with dates we would only break. The order reflects dependency and priority, not a calendar.
First, the core protocol on Base: the pools, the verifiers, the entrypoint, the note and proof machinery — the machine described in Part III, deployed, open-source, and verifiable on-chain by anyone who cares to check. The contracts are the foundation, and the foundation ships first and stands in public.
Second, the honest supporting services that make the core usable: a client that generates notes and proofs in your browser without ever transmitting a secret; relayers that close the last link; and the association-set infrastructure that makes compliant, private withdrawal real rather than theoretical. A private protocol without these is a proof of concept. With them, it is a payment system.
Third, the practice around the protocol: documentation of how to preserve privacy in use, clear warnings about the failure modes named in Article XVI, and interfaces whose defaults protect users who do not read documentation. We consider the education of users part of the product, because a privacy tool people misuse is a privacy tool that fails them quietly.
Open by default
The protocol's source is public. The proofs are verifiable. The deployments are on-chain and inspectable. We would rather be checked than believed. An audit you can run yourself is worth more than an assurance you must accept, and everything we build will be built to be checked.
Beyond this lies the longer work: additional denominations and assets as the crowd deepens; progressive decentralization of the parameters that must stay adjustable; the reduction of our own discretion described in Part V; and the slow, unglamorous labor of hardening, auditing, and defending a piece of infrastructure that we hope people will come to depend on. None of it is finished at launch. Infrastructure is never finished. It is maintained, or it decays, and we are committing to the maintenance.
XXXII
What we ask of you
This is where most manifestos ask you to buy something. We ask you, first, to understand something — because a privacy protocol used without understanding is a danger to its own users, and we would rather have fewer users who know what they hold than many who do not.
We ask you to understand that your privacy is produced by a crowd, and that by joining honestly you strengthen the protection of everyone in it, including those who need it far more than you do. To deposit into Blend is not only to protect yourself; it is to thicken the cover that shields the journalist, the dissident, and the ordinary family who cannot afford to be seen. Participation is, in a small but real way, an act of solidarity.
We ask you to hold us to this document. Read it against what we ship. Check the contracts against the claims. Watch whether the association set stays neutral, whether the token serves the protocol or the reverse, whether our discretion shrinks over time as we have promised or quietly grows. We have written down the standard we mean to be judged by precisely so that you can judge us by it. Skepticism aimed at us is not hostility; it is the exact vigilance that keeps public infrastructure honest, and we invite it.
And we ask you to guard your note, to learn the practice of private transaction, and to use the tool with the seriousness that self-custody demands. The protocol gives you sovereignty over your funds and privacy over your activity. Sovereignty is not a convenience; it is a responsibility, and it is yours. We built the machine to remove every other party's power over your money. What remains is your power over it, and your care for it.
We are not asking you to trust us. We built Blend so that you would not have to. We are asking you to verify us, and to use what we made with open eyes.
If, having understood all this, you choose to deposit — to join the crowd, to hold a note, to move through the public ledger unseen while carrying the proof that your money is clean — then you are not a customer of Blend. You are a participant in it, a producer of the privacy you consume, and a stakeholder in whether a piece of neutral infrastructure survives. That is the relationship we want. It is the only one worthy of the thing.
XXXIII
The long game
We are not trying to win a cycle. We are trying to establish a piece of infrastructure that is still useful, still neutral, and still standing when the cycle that carried it here is forgotten. Everything in this manifesto — the refusal of custody, the discipline about the token, the insistence on credible neutrality, the honesty about limits — is a bet on longevity over momentum, and it is a bet made on purpose.
The short game in this industry is well understood and easy to play: maximal claims, engineered scarcity, incentives tuned to extract, attention chased and converted before the thing underneath is even real. It works, briefly, and it ends the same way every time, and it has taught the world to expect nothing better from anyone building here. We think that expectation is the single greatest obstacle to privacy becoming ordinary — and we think the only way through it is to be, visibly and over years, the counterexample.
The long game is slower and it asks more. It asks us to ship a real protocol and open it to inspection. It asks us to keep the token in service of the system even when the reverse would pay better. It asks us to hold neutrality under pressure, to shrink our own power on schedule, to name our limits when it would be easier to make promises, and to maintain a thing long after launching it stops being exciting. It asks us to be worth trusting by building so that trust is not required. We are choosing it with our eyes open.
Financial privacy is not a feature that some future version of money might include. It is a condition that money has always had, until we built money that lacked it, and it is a condition a free society cannot do without. Restoring it on infrastructure that is public, permanent, and hostile to concealment is a hard thing to do, and doing it in a way that survives contact with the world is harder still. That difficulty is the reason to attempt it. Easy things do not need manifestos.
Prove you are clean. Reveal nothing else. And help us build the layer where that is simply how money works.