Ethereum Foundation debuts zkAPI for anonymous AI payments
AI & Agents ·
A new zero-knowledge protocol lets users fund AI service requests with ETH on mainnet without tying their identity to the queries they send.
The Ethereum Foundation and the Open Anonymity Project have rolled out zkAPI, a system that splits payment records from the actual prompts users submit to AI providers, according to cryptopotato.com. The protocol runs live on Ethereum mainnet and was credited to researcher Davide Crapis and co-founder Vitalik Buterin as original proposers, with the Open Anonymity team responsible for building the client, server, smart contracts, and browser integration. The Ethereum Foundation had promoted the launch on October 2 as a tool for private AI usage, a detail also captured by blog.ethereum.org.
Mechanically, a user deposits ETH into a contract called ZkAPIVault, which converts that deposit into a cryptographic commitment using a Merkle tree while the remaining spendable balance stays recorded privately on the user's own device. When a session begins, the browser produces a zero-knowledge proof demonstrating sufficient, unspent funds, letting the system confirm payment without exposing which deposit is being drawn from or who the depositor is. Once verified, a capped-spend API key is issued so the prompt travels directly from browser to AI provider, and afterward a usage receipt triggers a deduction from the private balance, with a one-time nullifier code blocking any attempt to reuse the same funds. The design relies on Groth16 proofs, BN254 cryptography, and Poseidon hashing, and leftover balances can be withdrawn straight from the vault contract even if zkAPI's own servers go offline, per the reporting on theblock.co.
The protocol's privacy guarantee is partial by design. It conceals the link between a payment and its payer, but not the substance of what's sent: AI providers still see the submitted prompts along with network-level data such as IP addresses, and could potentially correlate separate sessions through timing patterns. To offset that gap, developers recommend routing traffic through Tor with a new circuit for each session, since reused phrasing, writing style, or personal details across sessions could let a provider re-identify a user despite the payment-layer anonymity, a caveat detailed by decrypt.co.
Coverage across the cluster describes overlapping but slightly varied framings of the same launch, with some accounts referencing prepaid USDC alongside ETH and metered API access as part of the broader payment model, pointing to multiple outlets tracking the rollout in parallel. The launch also follows Buterin's recent public roadmap emphasizing cryptographic proofs and verification as a long-term direction for Ethereum, suggesting zkAPI functions as an applied test case for that broader design philosophy rather than a standalone product.
Open questions include how widely AI service providers will adopt zkAPI as a payment rail, whether the suggested Tor-based session hygiene will be followed in practice, and how the protocol's partial privacy model — hiding payment links but not content or network metadata — holds up once used at scale.