Dragonfly Asset Management Investment Research
The Privacy Thesis · July 2026

Nothing to Hide,
Everything to Lose

Privacy was the default for the whole of human history. Artificial intelligence undid that in a decade. Here is why Crypto's oldest idea has become its most important investment theme, and how the fund is positioned for it.

Author Pouneh Bligaard, Dragonfly Asset Management Theme Privacy Exposure Venice · NEAR · Targon · Zcash
Executive Summary

The One-Paragraph Version

Every large company now faces a choice it did not have to make five years ago. To use the best artificial intelligence, it must hand its most valuable material, patient records, trading signals, source code, deal strategy, to a handful of firms that also happen to be building products of their own. And to settle value onchain, where finance is steadily moving, it must broadcast every position and transfer to competitors watching the same public ledger in real time. Both problems have the same root: sensitive information, once shared, cannot be taken back. Crypto has spent fifteen years building the only known tools that let an institution prove what it must, a solvency figure, a compliance check, an eligibility claim, while keeping everything else sealed. That capability, once dismissed as a cypherpunk hobby, is now the thing standing between a bank and its own data walking out the door. We think this shift is early, underpriced, and durable. The fund holds four expressions of it.

32%
of all Zcash now held in its shielded pool, up from roughly 11% in early 2024
$20bn
of volume settled through NEAR Intents, which now supports confidential transfers
$1bn
valuation reached by private-AI firm Venice, profitable on roughly $70m of revenue

This report is written to be read by anyone, not only specialists. It makes one argument in plain terms: privacy is not a feature that Crypto happens to offer. It is fast becoming the reason a serious institution would touch Crypto at all. We build the case from first principles, illustrate it with the analogue world most people already understand, and close with the four holdings through which the fund expresses the theme.

02 The Historical Baseline

Privacy Was Never The Exception

For almost the entire span of human life, privacy was simply how things worked. It required no software and no settings page. When you spoke to someone in a room, the conversation stayed in that room. When you bought bread with a coin, the baker knew, and nobody else did, not when, not how much, not what for. A letter travelled inside a sealed envelope, and breaking that seal was treated as a serious violation, protected in law for centuries. A doctor kept your ailments to himself because an oath older than modern medicine told him to. A confession, a legal consultation, a vote: each came wrapped in an expectation of secrecy so complete that we built whole institutions, the confessional, attorney-client privilege, the secret ballot, to guarantee it.

None of that was radical. It was ordinary. What is radical is the world of the last twenty years, in which a single company or government can observe and record the daily behaviour of a billion people at once. Zooko Wilcox, who created Zcash and is fifty years old, makes the point better than we can.

This modern experiment, where a single large government or some megacorporation is able to monitor and control a billion people at once, that is not safe, not stable, not normal. It is a radical, dangerous experiment. Cryptographically based privacy is really just a return to the world I was born in.
Zooko Wilcox · Founder of Zcash · CoinDesk, December 2025

We have been trained to believe the opposite, that privacy is the eccentric preference of people with something to hide, and that ordinary people traded it away, happily, for convenience. Wilcox argues that this belief was manufactured. The claim that nobody cares about privacy, he says, was a convenient story told by the businesses that profit from watching us, because passive users are easier to farm. The evidence that people do care is all around us: the same person who says privacy is dead still thinks carefully about who will see a message, whether a photo might be screenshotted, who is copied on an email. The instinct never left. Only the tools did.

The reframe that matters

Privacy is not a new demand that Crypto invented. It is an old default that the internet quietly removed. The investable question is who rebuilds it, in a form institutions can actually use.

This is the correct frame for everything that follows. We are not describing a fringe ideology going mainstream. We are describing the restoration of a baseline that held for millennia, using the one technology, cryptography, that can enforce it across a network where nobody trusts anyone. What changed is not that privacy suddenly matters. What changed is that the cost of losing it went from an abstraction to a number on a balance sheet. Two forces did that. The first is artificial intelligence. The second is the public ledger itself.

03 The AI Data Problem

The World's Most Valuable Honeypot

Start with a question that anyone can answer. Would you post your bank statement on Facebook? Almost nobody would. Now ask why so many of us paste the same kind of information, our finances, our health, our contracts, our half-formed strategy, into an AI chat window without a second thought.

Facebook was never free. Its users pay for it in full, with their data and their attention, and most of them do so without ever quite registering that this is the deal. The old line still holds: if you are not paying for the product, you are the product. A mainstream AI model runs on the same economics. The subscription is small or absent, and the real price is the stream of information you hand over. What changes the stakes, and turns an irritation into a genuine risk, is the nature of that information. On Facebook, people share what they are content to make semi-public: a holiday photo, an opinion, a birthday. Into an AI model they pour the things they would never post anywhere, a diagnosis, a contract, source code, the plan they have told no one. The business model is identical. The raw material is vastly more sensitive, which makes the pile of it sitting in one place a far greater prize for a competitor, a hacker, or a court to reach for.

The team at Venice, a private-AI company, frames the risk exactly this way. Everything typed into a mainstream model is stored somewhere, and once it is stored, it is exposed to a longer list of parties than most users imagine: the provider's own staff, a rogue employee, an attacker who breaches the system, and any court or government that arrives with an order. Venice's founder, the long-time Crypto figure Erik Voorhees, calls the result a honeypot, the largest concentration of intimate human information ever assembled, sitting in a small number of places, waiting to be subpoenaed or stolen.

You realise, if you have ever put anything into an AI model that you would not want published, why privacy is important. It is somewhat dystopian that a small handful of tech companies are building databases of everybody's most intimate thoughts.
Jesse, CTO of Venice · Bankless, June 2026

For an individual this is uncomfortable. For an institution it is existential, and for two distinct reasons.

Reason one: compelled disclosure

Data that exists can be demanded. The Venice team describes a real pattern from the corporate world: a company executive who used a mainstream chatbot to work out how to terminate an earn-out owed to a business they had acquired, followed the plan, was sued, and then watched the other side obtain the full chat records and use them as evidence of intent. What felt like a private brainstorm became a discovery document. A hospital feeding patient outcomes into a model, or a bank feeding client flows and proprietary signals, is creating exactly this kind of retrievable record, governed by HIPAA and a dozen other regimes it cannot simply ignore. The safest data, as Venice puts it, is the data you never handed over in the first place, because what you do not hold cannot be handed to a court.

Reason two: the provider becomes your competitor

This is the subtler danger, and the one most relevant to why this is an investment theme rather than a compliance footnote. When a company shares its proprietary context with a centralised AI lab, it is handing raw material to a firm that is itself racing to build products. Today that material is used to improve the model. Tomorrow, once the obvious gains are exhausted and margins tighten, it becomes a map of where the profitable products are. Commentators point to a growing pattern of AI labs moving into the exact product areas their own customers occupy, and to the launch of dedicated health and enterprise units by the largest providers. Whether or not any single example holds up, the structural incentive is undeniable: the lab that sees everyone's usage knows precisely which businesses to build next.

Kendall Cole of Proximity Labs, a core contributor to NEAR, put the dynamic plainly on Bankless. The customers of the big labs, he noted, are feeding them all of their data and all of their edge, and those companies are turning it into competitive products, which is a serious breach of an unspoken contract, and one that privacy technology is built to solve.

Why this is a market, not a mood

Venice is now profitable, valued at roughly $1bn, and has committed a $27m fund purely to advance private, uncensored AI. Enterprises are already seeking private inference for HIPAA and competitive reasons. The demand is not hypothetical; it is buying.

The response is not to abandon AI. It is to run it without surrendering the data. That is precisely what a cluster of Crypto projects now offer: models that run inside sealed hardware so that even the operator cannot read the prompt, and inference that is never retained or used for training. We return to the specific companies later. The point here is that the demand is real, large, and, for regulated institutions, non-negotiable.

THE HONEYPOT ALL YOUR DATA rogue staff hacker subpoena One store. Many ways in. Nothing you can take back. SEALED & SELECTIVE AUDITOR view key Sealed by default. One key, one viewer, on your terms.
The shift in one picture. A mainstream model concentrates everyone's most sensitive data in a single place that staff, attackers and courts can all reach. The systems the fund backs invert this: data stays sealed with its owner, who can hand a single view key to a single party when a rule requires it, and to no one else.
04 The Transparency Paradox

The Glass Ledger Problem

There is a second reason privacy has moved to the centre of the conversation, and it is one Crypto created for itself. The public blockchain, the very thing that makes Crypto trustworthy, is also a permanent, searchable, public record of everything that happens on it. Transparency is the feature. For an institution, it is also the bug.

Picture a fund manager rebalancing a large book, or a bank moving collateral, on a transparent chain. Every transfer, every position, every counterparty is visible the instant it settles, not to a regulator behind closed doors, but to every competitor, every trading desk, and every automated system watching the same ledger. In the old world, a large order was worked quietly precisely so the market could not see it coming. Onchain, in its default form, the order is announced to everyone at once. No serious trading operation can accept that, which is why so much institutional value has stayed off the very rails the industry keeps insisting it will move to.

The arrival of AI agents makes this sharply worse. Kendall Cole of NEAR described exactly the concern his enterprise users now raise:

If I am using the blockchain to move assets around, or to rebalance my treasury, that is extremely sensitive commercial information. I cannot possibly imagine revealing that to the whole world, to anyone who is looking, and you can have their agent analysing it and putting together really detailed competitive analysis on me.
Kendall Cole · Proximity Labs, NEAR · Bankless, July 2026

Read that carefully, because it is the whole thesis in miniature. A public ledger was already a competitive leak. An adversary with an AI agent turns that leak into an automated, always-on intelligence operation, one that never sleeps, reads every transaction, and reconstructs your strategy from your footprints. The same technology that makes centralised AI a honeypot makes a transparent ledger a liability. Privacy is the common answer to both.

Crucially, and this is where the naive version of Crypto privacy fails, the answer cannot simply be to hide everything. An institution that becomes fully invisible cannot prove it is solvent, cannot satisfy an auditor, and cannot pass a compliance check. It has traded one unacceptable state for another. What institutions need is narrower and more precise: the ability to keep information sealed by default, and to reveal exactly what is required, to exactly whom, exactly when. That distinction, between hiding and selective disclosure, is the hinge on which the entire opportunity turns.

05 The Unlock

Privacy With Accountability

The breakthrough is not a way to disappear. It is a way to prove things without revealing the underlying data. This is the difference between the privacy coins of the last cycle, which offered blanket concealment and duly attracted regulatory hostility, and the systems institutions are now willing to consider.

Three tools do the work, and none of them requires a reader to understand the mathematics. Zero-knowledge proofs let you demonstrate that a statement is true, that you hold enough collateral, that a client passed screening, that a figure is accurate, without showing the figure itself. Confidential computing runs a calculation inside sealed hardware so that not even the machine's operator can see the inputs. And selective disclosure, usually implemented through what the industry calls view keys, lets the owner of private information hand a specific party, an auditor, a regulator, a counterparty, a key that unlocks exactly the records that party is entitled to see, and nothing more.

THE PRIVACY SPECTRUM FULLY TRANSPARENT Every position public. Competitors see all. SELECTIVE DISCLOSURE Sealed by default. Prove only what is required, to exactly whom, exactly when. ← THE INSTITUTIONAL ZONE → FULLY OPAQUE Cannot prove solvency or pass an audit. Both extremes are unusable. The value is in the middle.
The institutional sweet spot. Regulated capital cannot live at either end of the spectrum. It needs auditable privacy, not anonymity. Every project the fund holds is engineered for the middle.

This is no longer theoretical, and the clearest live demonstration comes from NEAR. In July 2026 NEAR extended its cross-chain settlement layer, NEAR Intents, with confidential transfers. The mechanism is instructive. A dedicated shard of the network runs inside a trusted execution environment, sealed hardware in which the validators processing transactions cannot see balances, amounts, or anything that would identify a user. By default, only the user, holding their own view key, can see their activity. Disclosure happens on the user's terms, when they hand a view key to a chosen party, or, for compliance, through a court order that a supermajority of validators must jointly honour. Cole was explicit that this design exists to make the product acceptable to enterprises, and that the fastest-growing source of demand for privacy is no longer cypherpunks but companies protecting sensitive commercial information.

The institutional research consensus

Independent analyses through 2026, from Chainlink, TRM Labs, ChainSafe and specialist venture research, converge on the same conclusion: institutions reject blanket anonymity and require selective privacy, encrypted by default with programmable viewing keys for regulators and auditors. Privacy has moved, in their words, from niche to core requirement for onchain finance.

The word that keeps recurring in that research is accountability. Fully opaque systems face regulatory bottlenecks and delisting pressure. Systems that combine strong cryptography with disclosure tooling, view keys, audit trails, proof of reserves without revealing the portfolio, are the ones capturing real usage and real capital. This is the specific, investable shape of the theme: not privacy against the world, but privacy with a controlled, auditable window. It is the difference between a locked vault with no key and a locked vault whose owner can open a single drawer for a single inspector. Institutions will only ever use the second.

06 The Remaining Gaps

What Is Still Missing

If the technology works and the demand is real, why has adoption not already happened at scale? Because the barriers are no longer mainly technical. They are practical, and they are the honest part of this thesis. Naming them is how we size the opportunity rather than oversell it.

The first gap is regulatory clarity. Selective-disclosure systems sit in a grey zone: clearly more compliant than blanket anonymity, but not yet blessed by explicit rules that tell a compliance officer they are safe to use. The direction of travel in 2026 is encouraging, with regulators in the United States and Europe moving toward clearer treatment, but the certainty a large institution needs is still arriving rather than arrived.

The second gap is liquidity. Privacy is only useful if an institution can move meaningful size into and out of a shielded position without slippage or signalling. Shielded pools and confidential venues are deepening quickly, but they are not yet as liquid as their transparent equivalents.

The third gap is enterprise-grade user experience and integration. A treasurer will not operate a command line or manage cryptographic keys by hand. The winning products are the ones that hide all of this behind an interface that feels like existing financial software, and that plug into the systems a company already runs. This is unglamorous engineering, and it is the real work of the next eighteen months.

Why the gaps are the opportunity

Each missing piece is being closed in public, on a visible timeline. That is exactly the window in which a liquid fund wants exposure: after the technology is proven, while the adoption curve is still ahead. Projects that deliver privacy with accountability are already capturing usage and capital; the re-rating comes as the gaps close.

None of these is a wall. Each is a task with owners and deadlines. And that is the precise reason the theme is investable now rather than later: the fundamental technology risk has largely been retired, while the adoption that will re-rate these assets is still in front of us. We would rather own the theme through this closing window than wait for the all-clear, by which point the opportunity will be priced.

07 Portfolio Expression

How The Fund Is Exposed

The fund expresses this theme through four liquid positions, each occupying a different layer of the privacy stack. Together they cover private money, private settlement, private enterprise compute, and private consumer AI. They are complements, not duplicates.

Venice · VVV Private Consumer AI Zero-retention inference

Venice is a private, uncensored AI platform that aggregates leading open-source and commercial models and runs them without logging or training on user data. It has reached roughly a billion-dollar valuation, turned profitable on around $70m of annualised revenue, and grown past three million users, a rare case of a Crypto token whose value is tied to a genuinely used product. Notably, it can even deliver commercial models such as Grok privately, through a zero-retention arrangement, so users get frontier capability without frontier surveillance. Its token economy routes real product usage back into demand for the asset.

Thesis: the leading consumer expression of "your AI should not remember you"
NEAR Private Settlement Confidential intents · view keys

NEAR is the connective tissue of the thesis. Its Intents layer already settles cross-chain value at scale, with roughly $20bn processed and confidential transfers now live via a sealed-hardware shard and user-controlled view keys, the clearest institutional implementation of selective disclosure in production. It is also where private money and private AI meet: NEAR's confidential routing gave Zcash's flagship wallet its first major surge, and its private-inference infrastructure is used by others, including Venice, to keep enterprise prompts sealed. Value accrues to NEAR as a cut of the volume it settles.

Thesis: the neutral rails for private, cross-chain, agent-driven value
Targon · SN4 Private Enterprise Compute Hardware-sealed inference (TEE)

Targon, built by Manifold Labs on Bittensor, is the enterprise-grade confidential compute layer, our "Swiss Bank of Decentralised AI." It runs AI inference inside sealed hardware (Intel, NVIDIA and AMD confidential-computing silicon) so that prompts stay private and are never used to retrain a model, the exact opposite of the centralised honeypot. It is the missing privacy layer that lets a regulated enterprise migrate a workload off a mainstream provider, validated by engagements with the likes of PwC and a place in NVIDIA's Inception programme. At our initiation it traded at a clear discount to less-differentiated compute peers.

Thesis: hardware-enforced confidentiality that unlocks enterprise AI
Zcash · ZEC Private Money Shielded pool · view keys

Zcash is the purest expression of the theme: auditable private money. Its shielded pool has grown from roughly 11% of supply in early 2024 to around 32%, a direct measure of how many holders are actively choosing privacy over convenience, and it has surpassed Monero in market share while remaining compatible with compliant, view-key disclosure. Institutional conviction has followed: a major position disclosed by Multicoin, a $25m raise for its development lab from tier-one backers, a Winklevoss-controlled listed treasury vehicle, and a protocol upgrade, Ironwood, targeted for activation in late July 2026 to strengthen the privacy set.

Thesis: a scarce, self-funding, auditable private store of value

We would draw one connection across the four. This is not four bets on the same coin flip. Venice keeps your AI private; Targon keeps an enterprise's AI private at the compute layer; NEAR keeps value private in motion; Zcash keeps value private at rest. A single tailwind, the market finally pricing privacy as critical infrastructure, lifts all four, but each stands on its own product, its own revenue, and its own users. That is the kind of correlated-yet-diversified exposure the fund is built to hold.

SHARE OF ALL ZEC HELD IN THE SHIELDED POOL 0% 10% 20% 30% 40% ~11% ~32% Early 2024 2025 Mid 2026
Skin in the game. The share of all Zcash actively moved into its shielded pool has nearly tripled since early 2024, from roughly 11% to around 32%. Because shielding sacrifices liquidity, this is one of the cleanest available measures of how many holders genuinely value privacy over convenience. Endpoints per public onchain data; the path between is indicative.
A note on figures

Valuations, token prices and market shares cited above move quickly and are drawn from public sources through mid-2026; the Targon figures date from our initiation earlier in the year. They are included to illustrate scale and direction, not as current marks. Nothing here is a recommendation to buy or sell any asset.

08 The Dragonfly Approach

How We Hold The Theme

The dragonfly sees through thousands of separate lenses at once, assembling many narrow views into a single, wide field of vision. That is how we prefer to hold a theme like this one, several distinct positions, each a clear view of one part of the opportunity, combining into a single coherent exposure to the idea that privacy is becoming the price of admission to onchain finance and private AI.

Identifying a powerful investment theme is a useful first step in our process, but it is not the full story. The fund runs a long-only, unlevered mandate in liquid tokens, with no synthetics, which shapes how we express privacy as an idea. Within the theme we aim to assemble a diversified basket of holdings, each chosen for the most attractive risk/reward trade-off we can find. We size for asymmetry, keeping individual positions measured so that the outcomes we are underwriting, several-fold re-ratings as privacy is priced in, do not depend on precise timing or on any single protocol winning. And unlike venture-stage investing, we have the luxury of liquidity as an active risk lever: we can adjust as the regulatory and adoption picture evolves, in either direction.

The one-line thesis

For fifteen years, privacy was the thing Crypto believers cared about and nobody else did. Artificial intelligence has quietly turned it into the thing everybody needs and almost nobody yet has. As always, we at Dragonfly look for these gaps before the market does.