Confidential Onchain Yield: The Missing Infrastructure for Institutional Capital
A new DeFi category is forming around a simple premise: institutions want the composability of public blockchains without broadcasting their positions to every competitor and MEV bot watching the chain.
Executive Summary
A new DeFi category is forming around a simple premise: institutions want the composability of public blockchains without broadcasting their positions to every competitor and MEV bot watching the chain. Call it confidential DeFi — the use of Fully Homomorphic Encryption (FHE), zero-knowledge proofs (ZK), multi-party computation (MPC), or trusted execution environments (TEEs) to keep balances, trade sizes, and strategies private while settlement stays on a public, auditable chain.
DefiLlama currently tracks 38 protocols under its privacy category, with a combined $892.4M in TVL — up 24.4% over the past 30 days but roughly flat (+4.6%) over the trailing year. That category mixes two very different things, though: anonymity-focused mixers like Tornado Cash, which most institutional compliance frameworks explicitly exclude, and compliance-compatible confidential-DeFi infrastructure such as
Railgun,
Zama, and
Privacy Pools. Stripping out Tornado Cash, the remaining tracked cohort grew from roughly $70.1M in combined TVL in March 2025 to $163.2M in September 2026 — a rise of about 133% over eighteen months. That is a genuine expansion of on-chain confidential balances, not merely a re-shuffling of an existing pool.
Live implementations today span all four cryptographic approaches, but one has moved decisively ahead on the institutional-yield use case: on September 15, 2026, Zama, Morpho, and five institutional curators (
Steakhouse Financial,
Armitage by Wintermute,
Flowdesk,
RockawayX,
Bitwise) are expanding from a single confidential USDC vault to 16 confidential vaults spanning five asset classes (USDC, USDT, WBTC, AUSD, tGBP), alongside the launch of the Zama Swap Protocol for confidential swaps between shielded positions. This is the clearest evidence yet of institutional capital moving from single-vault experimentation toward a repeatable, multi-curator confidential-yield product line.
Why Now
Institutional capital's core objection to public DeFi has always been informational: every position, every rebalance, every unwind is visible in real time to anyone watching the mempool. A 2025 empirical study of Ethereum sandwich attacks ("Sandwiched and Silent," Mancino & Rezzoli) quantifies just how costly and persistent this exposure is — and, more importantly, shows that the industry's existing workaround (private transaction routing) is not a real fix. Between November and December 2024 alone, the paper confirms 117,581 public sandwich attacks and a further 2,932 private-path sandwich attacks affecting 3,126 victim transactions, with $409,237 in victim losses and $293,786 in attacker profit — and a single bot responsible for roughly 65% of all private-path frontrunning. Private routing itself concentrated 50.1% of all Ethereum transactions by February 2025, up from 31.8% a year earlier — meaning the industry's main defense against information leakage is itself becoming a centralized chokepoint rather than a genuine privacy guarantee.
For institutions, the stakes go beyond MEV: a visible position is a visible trading strategy, a visible cost basis, and a visible compliance exposure. Confidential DeFi reframes the problem at the settlement layer instead of the routing layer — encrypting the balance itself rather than hoping no one is watching the mempool.
Landscape: Four Competing Approaches
Confidential DeFi is not one technology; it is four cryptographic approaches converging on the same category, each with different tradeoffs:
FHE (Fully Homomorphic Encryption) — computes directly on encrypted data without ever decrypting it.
Zama, the largest live FHE deployment, reports its underlying scheme rests on lattice cryptography, which is inherently post-quantum resistant unlike ZK or TEE-based approaches.
The tradeoff has historically been computational overhead, but Zama's Q2 2026 reports that the protocol reached 1,000 confidential transfers per second on standard GPUs — a milestone arrived roughly a year ahead of its internal roadmap.
ZK (Zero-Knowledge Proofs) — proves a transaction is valid without revealing its contents, and underpins the largest current deployments by TVL: Railgun ($96.5M) and historically
Aztec Connect (now near zero TVL).
ZK shielded pools face a structural auditability tradeoff: following a June 2026 vulnerability disclosed in Zcash's Orchard shielded pool, once assets are shielded under a pure ZK design, third parties generally cannot independently verify that shielded supply matches underlying deposits.
MPC (Multi-Party Computation) — splits computation and key material across multiple parties so no single party sees the full data. It underpins institutional custody/wallet infrastructure — Zama cites Bron, a self-custody wallet combining MPC with native confidential-token support, as a partner — more than base-layer settlement today.
TEE (Trusted Execution Environments) — relies on hardware-isolated enclaves to process data privately. DefiLlama tracks
Oasis Sapphire, a TEE-based confidential EVM chain, at just $175.5K in TVL, down 96% year-over-year — the weakest traction of the four approaches in tracked DeFi TVL today, though TEEs remain in active institutional use for custody and off-chain compute.
Use Case Deep Dive: Steakhouse's Confidential Prime USDC Vault on Morpho
The most advanced live implementation of confidential yield today runs on Morpho, curated by Steakhouse Financial — and it is now the template being replicated across four more curators. The Steakhouse Confidential Prime USDC vault, live since June 2026, uses the same collateral set and credit strategy as Steakhouse's existing public Prime USDC vault on Morpho (cbBTC, wstETH markets), with one difference: it accepts confidential USDC as the deposit asset. Deposits are batched every 24 hours before being routed into the underlying Morpho strategy; an observer can see the batch total but not any individual depositor's balance or position.
The Steakhouse Confidential Prime USDC vault's growth curve is the clearest read yet on institutional appetite for confidential yield. From a standing start at launch in mid-June 2026, the vault reached $25.5M in deposits by the end of the month — enough to place it among the top-10 USDC vaults on Morpho by TVL, paying 8–13% APY including incentives. Growth continued through the vault's 12-week incentive program, peaking near $40M roughly seven weeks after launch — consistent with the program's own design, which front-loaded the largest yield boosts into the first two weeks and tapered them steadily through a "mid pulse" and "late pulse" phase.
By September 11, 2026, DefiLlama's independent tracking put the vault at $33.5M in TVL, earning a 7.2% base APY — a pullback of roughly 16% from the ~$40M peak, in line with what the incentive structure would predict: as the boosted-yield phases wind down, the vault's marginal APY compresses back toward its native ~7% rate, and some yield-sensitive capital rotates out. The trajectory is a rise, a peak tied to incentive design, and a partial settling — not three competing numbers, but one consistent growth-and-normalization curve for the first live confidential-yield product at scale.
For context on the venue itself: Morpho carries $9.6B in total TVL (+21.8% over 30 days) and Steakhouse Financial curates $3.0B across its vault suite — so even at its $40M peak, this vault represented well under 1% of either platform's TVL. The significance isn't scale yet; it's that a fully confidential vault, running the exact same credit strategy as its public counterpart, sustained real deposits through a full incentive cycle on infrastructure institutions already trust.
Metrics: Shielded TVL as a Category Benchmark
DefiLlama's privacy category is the closest existing proxy for a category-wide "shielded TVL" metric, currently standing at $892.4M in TVL across 38 tracked protocols. It is, however, a blunt instrument today: it mixes anonymity mixers with compliance-oriented confidential-DeFi infrastructure, and each protocol's own TVL methodology is not standardized to a shared "value currently shielded" definition.
Zama separately reports its own shielded Total Value Locked (TVL) metric, and the two-quarter trajectory is worth showing rather than a single snapshot: shielded TVL peaked at $123M in Q1 2026 (driven by a $120M ZAMA token public sale shielded within three days) but stood at a $39.6M snapshot at the end of Q2 2026, up 15% quarter-on-quarter from Q1's own end-of-quarter level.
Underlying, more durable shielded balances (from vaults, stablecoins, and tokens) are growing steadily — Q2's cumulative shielded volume reached $415.5M year-to-date, up 44% quarter-on-quarter, with 10,900 wallets holding shielded assets, up 17% quarter-on-quarter.
Zama's Q2 report also breaks TVL down by asset class as of June 30, 2026: stablecoins ($14.1M), tokens ($6.8M), vaults ($18.8M), and RWAs ($52.2K) — which sum to roughly $39.75M.
Adoption
Several signals point to maturation rather than one-off experimentation.
Curator breadth: Five curators — Steakhouse Financial, Armitage by Wintermute, Flowdesk, RockawayX, Bitwise — spanning stablecoin, RWA, and BTC-collateral strategies, describing confidential entry as a natural extension of existing curated strategies rather than a new product line.
Standards convergence: ERC-7984, the confidential token standard, was developed jointly by Zama and OpenZeppelin. It now sits at the center of the Confidential Token Association (CTA) — an industry group whose stated mission is 'a common framework for encryption-based onchain confidentiality,' co-founded by three organizations: Zama, OpenZeppelin, and Inco.
Zama's Q1 2026 report notes the standard is already integrated into OpenZeppelin's Contracts library, the most widely used smart-contract toolkit in Ethereum development.
Institutional participants: GSR (OTC market maker) settled an OTC trade confidentially via Zama's protocol, Bron executed what Zama describes as the world's first confidential payroll on Ethereum mainnet in December 2025, and T-Rex Ledger who chose Zama to become confidentiality layer for the upcoming tokenisation project for Apex Group ;
Dfns, enterprise wallet infrastructure, integrated the confidential token standard natively in Q2 2026.
Distribution ecosystem: access points beyond the Zama app itself — Zerion, Utila, Yield.xyz — and incentive layers — Pendle, Merkl — are part of the same expansion. The category is being built with distribution partners from the outset rather than as a single-app product.
Risks and Open Questions
The category faces three structural risks that apply regardless of which cryptographic approach wins.
Fragmentation: FHE, ZK, MPC, and TEE implementations are not interoperable — a confidential USDC balance on one system cannot move to another without unshielding first, fragmenting liquidity across incompatible privacy silos.
Standardization risk: ERC-7984 is gaining adoption, but it is one proposal among several possible confidential-token designs, and its long-run dominance is not assured.
Regulatory uncertainty: programmable/selective-disclosure compliance is a design goal across every approach in this category, but no jurisdiction has yet defined a clear regulatory treatment for onchain confidential assets, leaving institutional adopters to build on infrastructure whose compliance status could shift.
A fourth, technical risk is auditability: Zama's own report argues that ZK-shielded systems, following the June 2026 Zcash Orchard disclosure, can lose the ability to verify that shielded supply matches deposits — a category-wide concern for any pure ZK shielded-pool design, though this framing comes from a competing FHE vendor and should be read as an interested-party claim rather than a neutral technical audit.
Outlook
Three triggers would move confidential DeFi from emerging to mainstream:
Additional institutional entrants beyond the current OTC/custody/curator set;
A compliance standard actually converging across jurisdictions rather than merely being proposed;
A second major curator ecosystem — beyond Morpho — adopting confidential vaults at comparable scale.
The expansion to 16 vaults across five curators is itself a strong signal on the first count, showing that curators beyond Steakhouse (Wintermute's Armitage, Flowdesk, RockawayX, Bitwise) will adopt confidential rails once one proof point exists on infrastructure they already trust.
The next signal to watch is whether a curator ecosystem outside Morpho — a different lending/vault venue entirely — replicates this pattern within the next 12 months, and whether the swap layer (Zama Swap Protocol) sees comparable adoption to the vault layer once it has a full quarter of reported volume.
APPENDIX: Methodology
TVL and category figures for DefiLlama-tracked protocols (privacy category total, Railgun, Zama, Privacy Pools, Aztec Connect, Oasis Sapphire, Morpho, Steakhouse Financial, and the Steakhouse Confidential Prime USDC vault) are drawn from DefiLlama's warehouse as of September 11, 2026. Figures attributed to Zama's Q1 2026 and Q2 2026 Shielded Reports, and to the September 15, 2026 press release, are self-reported by Zama and its named partners and are labeled as such throughout; reconciliation deltas between these sources and DefiLlama's independent tracking were computed directly from the source figures and are marked as derived. The MEV/private-routing statistics in Section 2 are drawn from "Sandwiched and Silent" (Mancino & Rezzoli, 2025).
Data as of September 11, 2026. Source: DefiLlama, plus Zama's Q1 2026 and Q2 2026 Shielded Reports and the September 15, 2026 press release (self-reported, labeled), and "Sandwiched and Silent" (Mancino & Rezzoli, 2025).