Newsroom

Vitalik Buterin Tests Three-Layer Setup to Protect Personal Data in Remote AI Queries

4 October, 2026   /   News   /  AI   /   Tags:  buterin, zkapi, remote, diet, vitalik

Vitalik Buterin Tests Three-Layer Setup to Protect Personal Data in Remote AI Queries

Ethereum co-founder Vitalik Buterin used a local model, zkAPI and Tor to generate personalized diet and exercise recommendations while shielding sensitive health and travel details from external AI systems

The Ethereum co-founder Vitalik Buterin conducted a self-experiment on October 4, 2026, applying a layered privacy architecture to remote artificial intelligence services. He retained full access to his personal health and travel records on a local device and sought tailored suggestions for diet and exercise without exposing identifying information to frontier models.

Local model as first layer of query refinement

Buterin ran Alibaba’s open-weight Qwen3.8-Flash-Next model locally on his machine. The model acted as an intermediary, rewriting prompts with reduced personal context before any remote service received them. A skill file guided the local system on when to invoke external models and how to construct queries that stripped away identifying details, such as full writing style or conversation history.

This approach allowed the local component to process sensitive data while delegating complex reasoning to more powerful remote systems. Buterin reported that the resulting diet and exercise recommendations improved when frontier models contributed, compared with purely local outputs. He did not release the exact prompts, recommendations or underlying data.

zkAPI for payment privacy without exposing prompts

The second layer employed zkAPI, a system introduced by the Ethereum Foundation on October 1, 2026. zkAPI separates payment from request content by letting users fund a private balance and prove sufficient funds exist through zero-knowledge proofs. The AI provider receives only the query itself and lacks visibility into the billing identity tied to the deposit.

Buterin wrapped the setup with a command-line tool to route requests through zkAPI. He noted that the payment layer alone does not hide the prompt content, but it does break the link between user identity and individual API calls.

Tor for network and IP anonymity

Tor completed the third layer by masking the user’s IP address from all external services. Buterin linked a recent pull request to the zkAPI repository that adds native Tor-routed client support. The changes adjust timeouts to accommodate slower Tor connections and enable temporary network identities for new requests or conversations.

He emphasized that all three layers are required together. Hiding payment information is insufficient when prompt content or network metadata could still connect sessions.

Performance trade-offs in the current setup

Buterin described practical constraints. The local Qwen3.8-Flash-Next model delivered 20 to 30 tokens per second, below his preference for comfortable speeds above 100 tokens per second. Tor routing introduced latency 10 to 100 times higher than acceptable for frequent requests, making request-by-request unlinking inefficient in tests.

He observed that greater caution in data shared with remote models reduces the usefulness of those systems. “The more careful you are about what data you give to a remote model, the less it can help you,” he wrote.

Doing a bit of a self-experiment. Goal: use my personal health and travel data to provide personalized diet and exercise recommendations for me, using frontier models but in a way that avoids leaking to them any private information. Strategy: use a local model (Qwen 3.8 Flash…
Vitalik Buterin

Ethereum’s path to cryptographic world computer

The experiment coincided with Buterin’s broader vision for Ethereum. He described the upcoming Pectra hard fork as the final traditional upgrade and outlined a subsequent phase focused on recursive STARKs, automated formal verification, optimized consensus mechanisms and quantum resistance. These advances would enable computation that is cheaper, more scalable and more private than prior cycles.

Buterin characterized the post-Pectra period as the start of Ethereum becoming a publicly verifiable network for private, secure and scalable computation across users worldwide.

The network aims to deliver computation that is much cheaper, more scalable, and more private than was possible in previous technology cycles, realizing the vision of a global cryptographic world computer.
Vitalik Buterin

The setup does not achieve complete privacy. Remote providers can still read included prompts, and network or timing metadata may remain observable outside zero-knowledge proofs. Buterin presented the layered approach as a practical step toward balancing utility and data protection in an era of advancing AI systems.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.