Back to Community Homepage
Canborsa: When Privacy Works Too Well
ArticleCommunityCanborsa

Canborsa: When Privacy Works Too Well

Canborsa raises a difficult question for Canton: can the network’s privacy architecture protect users from the very institutions that operate it? This article examines the tension between institutional compliance, no-KYC access, and Daml’s powerful sub-transaction privacy.

August 11, 2026X (Twitter)
MR.RED_A
MR.RED_A
@kazuisizu75584 · Canton Creator

I. The Question Canborsa Asks Canton

Canborsa is not merely a product. It is a question posed to Canton.

The question is simple: is sub-transaction privacy one of the network’s most valuable features a strength or a vulnerability?

For the first time, an application is using Daml privacy not only to protect institutions from position leakage, but also to shield end-user identities from those very institutions.

Goldman Sachs cannot see the trading positions of Canborsa users on Canton. Nor can it see who is trading U.S. equity derivatives with up to 30x leverage on the same infrastructure.

This is not a bug. It is a consequence of a design that has never been fully tested under conditions like this.

II. Two Paradigms Sharing One Infrastructure

Canton was built as a habitat for already regulated entities.

DTCC, Deutsche Börse, BNP Paribas, J.P. Morgan these institutions operate behind walls of KYC, banking onboarding, oversight, and verified audit trails.

Then a new entity appears: Code Capital LLC, registered in Kyrgyzstan, with no public investor list, no disclosed vesting schedule, and no KYC at onboarding.

Users simply log in via email or an X account, connect a Web3 wallet, and immediately gain access to trading tokenized equities and commodities with leverage of up to 30x.

This is not merely “DeFi entering institutions.”

Instead, it is two fundamentally incompatible paradigms forced to coexist on the same infrastructure.

On one side: a financial system built on identity, compliance, and oversight.

On the other: an access model designed to minimize those very requirements.

The question is no longer whether they can coexist.

The real question is: who ultimately bears the risk when they collide within the same network?

III. When Daml Privacy Works Too Well

Canton’s Daml architecture is designed as a boundary of cryptographic visibility.

Each transaction is decomposed into a hierarchy of sub-transactions, where only relevant parties can access specific details.

In an institutional context, this makes perfect sense.

Validator nodes operated by large institutions do not need full visibility into positions or liquidation prices. This privacy reduces risks such as front-running and prevents sensitive information from leaking.

But the same architecture has another consequence.

Daml privacy also shields the identities of Canborsa’s end users from Super Validators.

In other words, a mechanism designed to protect confidentiality between institutions can also create a privacy layer between users and the very institutions that, in many jurisdictions, are required to know who is using their infrastructure.

The system works exactly as intended.

Perhaps too well.

On-Chain Footprint

Party ID:

"canborsa-vault-1::122056522877d74ffc2938195dfea95c1bea9bd9174968a81294591429d6a5cdc49d"

Entity: Code Capital LLC, KGZ

No public GitHub.

No visible repositories.

The team is described as 10+ builders, with claims of previously managing over $300 million in AUM.

Yet the fundamental question remains:

Who are they?

For now, the answer remains a black box.

IV. A Tenant in an Institutional Building

Canborsa did not build its own bridge.

It did not build its own oracle. Nor did it build its own consensus mechanism.

It is a tenant in a building constructed and maintained by others.

Its infrastructure relies on external components, including LayerZero (the first interoperability protocol to go live on Canton in March 2026), Zenith for native EVM execution, and ChainSafe CIP-56 middleware to translate EVM assets into Canton format.

The implication is critical:

Canborsa does not possess full technical sovereignty.

If Goldman Sachs or other Super Validators decide that no-KYC applications cannot be tolerated, they do not need to directly attack Canborsa.

They can simply adjust the parameters of the infrastructure that enables Canborsa to exist.

And if regulators pressure Super Validators to restrict or censor Canborsa’s sub-transactions, the platform could theoretically be frozen from within.

Not through lawsuits.

Not through exploits.

But through the collective decisions of the institutions that provide the very ground it stands on.

V. Canborsa Gold: A Revealing Contradiction

There is one product that reveals Canborsa’s awareness of the risks it faces: Canborsa Gold (CBG).

The model is straightforward:

1 CBG = 1 gram of physical gold stored in Swiss vaults, with an initial backing of one metric ton and the option for physical redemption.

This is Canborsa’s most “institutional” product.

Ironically, it is also the clearest signal that Canborsa understands a core principle of finance:

In uncertain environments, collateral that cannot be easily debased serves as a form of insurance.

Yet this is where the contradiction becomes more pronounced.

CBG depends on trust custodians, reserves, audits, and redemption mechanisms.

Meanwhile, another part of Canborsa’s business no-KYC perpetual swaps with up to 30x leverage explicitly rejects that same trust framework.

In effect, Canborsa is attempting to be both institutional and anti-institutional at the same time.

It seeks to build products that speak to TradFi, while maintaining an access model that diverges sharply from it.

And it is attempting to do both on infrastructure that was originally designed primarily for institutional use.

VI. Canton’s Real Test

After Canborsa, every future project on Canton may be evaluated under a stricter lens.

No longer simply:

“Is this innovative?”

But rather:

“Can this network accommodate what we are building without putting everyone else at risk?”

Canborsa is writing the answer to that question one anonymous sub-transaction at a time.

And Canton’s Super Validators are watching, calculating, and assessing the risk.

Because ultimately, a deeper question looms:

What happens when the privacy built to protect institutions is used to shield activities those institutions never agreed to support?

When that moment arrives, Canton will have to define its boundaries.

Will that wall of privacy truly belong to everyone?

Or does it ultimately belong only to those who paid to build it?

Have a question about this content?
Ask CantonNews AI for context, its impact on the Canton ecosystem, or related coverage.