Ethereum's zkAPI Gives AI Payments a Privacy Cloak With a Catch The Ethereum Foundation and the Open Anonymity Project launched zkAPI on Oct. 1, a system that lets users deposit ETH, USDC or other supported credits into an Ethereum vault and pay for AI API requests without revealing the billing identity behind them. The protocol uses Groth16 proofs on the BN254 curve, Poseidon hashing and nullifiers within a 32-level Merkle tree to separate payment from identity, and issues short-lived, dollar-capped API keys that live only in device memory, so "the server that handles money never sees content, and the provider that sees content never learns the billing identity behind a key," according to the Foundation. The public blockchain sees deposits, closes and withdrawals but not what the balance purchased, and users can close their balance and withdraw onchain even if every zkAPI server disappears. Ethereum's zkAPI Gives AI Payments a Privacy Cloak With a Catch news.bitcoin.com 3 m Ethereum Wants to Break AI’s Paper Trail Every question fired at a commercial AI model can leave more breadcrumbs than most users probably imagine. An API key connects to an account. The account connects to money. The prompts accumulate behind both. The Ethereum Foundation EF puts the problem plainly. “Every AI API call today carries an identity.” That’s the trail zkAPI is trying to break. Launched Oct. 1 by the Ethereum Foundation and Open Anonymity Project, zkAPI lets somebody deposit ETH, USDC or other supported credits into an Ethereum vault and later pay for AI requests without telling the payment server who they are. The AI provider gets the request but not the billing identity behind it. The Foundation’s description is striking because of how personal that billing history can become. “Prompts are personal. People ask AI models about their health, their finances, their doubts,” the Foundation’s blog post titled “Introducing zkAPI: private usage credits for any API” states. Pile up enough of those questions under one account and the provider doesn’t merely have a bill. It can have a years-long record of what someone has been thinking about. Know when your coins move Alerts, real-time prices, and market news — all in one app 4.8 based on 40K reviews in the App Store and Google Play Put Money in the Vault, Then Disappear From the Bill zkAPI’s trick starts with a normal Ethereum transaction. A user deposits credits into a vault contract. After that, the funds are represented by a private note that can be spent without identifying which original deposit supplied the money. As the EF description explains it, “zkAPI separates payment from identity.” Software running on the user’s device then produces a zero-knowledge proof showing that a funded note can cover the requested spending and hasn’t already been spent. The server verifies the statement without learning which note belongs to the user. The plumbing gets technical fast. Deposits are commitments inside a Merkle tree 32 levels deep. Spending produces one-way serial numbers called nullifiers, while Groth16 proofs on the BN254 curve and Poseidon hashing handle the cryptographic heavy lifting. The nullifier is the cop on the beat. Try spending the same balance twice and the duplicate gives the game away. Stay within the balance, and the protocol is designed to keep the note unlinkable. Or, in the Foundation’s words: “A user who stays within their balance stays unlinkable.” The AI Gets a Disposable Key The cleverest part happens after payment authorization. Instead of giving the artificial intelligence AI provider a permanent API key attached to an ordinary customer account, zkAPI’s server checks the payment proof and creates a fresh, short-lived key with a dollar cap. The key lives only in the user’s device memory. Then the prompt heads directly to the AI provider. “The server that handles money never sees content, and the provider that sees content never learns the billing identity behind a key,” the Foundation explained. When that temporary key expires, the provider records the amount actually consumed in a signed usage receipt. zkAPI deducts that amount from the user’s private note rather than automatically taking the entire spending cap. That means one authorization can cover a session instead of requiring an Ethereum transaction for every question. The payment system knows that somebody paid. The AI knows that somebody asked. Neither is supposed to know enough to connect the two. Ethereum itself gets an even narrower view. The public blockchain can see deposits, closes and withdrawals, but not what the balance purchased. The money can also be reclaimed if the zkAPI servers vanish. “You can close your balance and withdraw onchain, even if every zkAPI server disappears,” the EF blog post explains. The Privacy Trick Has an Escape Hatch There is, however, no invisibility cloak here. The zkAPI tech separates billing identity from API usage. It does not magically hide what somebody types into an AI model. The provider still receives prompts and responses because it has to run the model. Network information can also betray the person on the other end. A stable IP address, timing patterns or repeated behavior can help reconnect supposedly separate sessions. The Foundation is very candid about another problem, stating: “Shared prompt contents can act as fingerprints for anyone who can read the prompts.” Keep mentioning the same employer, family members, writing habits, project documents or old conversation history, and the content itself can start putting Humpty Dumpty back together again. Users seeking stronger network anonymity are pointed toward Tor and fresh circuits for separate sessions. The protocol’s repository also labels zkAPI experimental. Still, AI is merely first through the door. The same system could handle blockchain RPC queries, image and video jobs, VPN bandwidth and machine-to-machine services where software agents pay for work without maintaining conventional customer accounts. That makes zkAPI’s proposition both narrower and more interesting than anonymous AI. It doesn’t promise that nobody knows anything. It tries to make sure nobody knows everything.