#dusk $DUSK @Dusk Your Proof Never Leaves Your Device. Your Trust Doesn't Have To Either."
I used to assume zero-knowledge proofs were something a server generated for you — you send data, a backend crunches the math, you get a verified transaction back. Convenient, but it means trusting whatever machine is doing the crunching.
Hedger, Dusk's privacy engine for DuskEVM, doesn't work that way. The proof itself is generated in-browser, on the user's own device, in under two seconds. Nothing about the private inputs — balances, amounts, identities — ever gets sent to a server to be proven. The math happens locally, and only the finished proof, not the underlying data, goes on-chain.
At first that read as a performance stat. Looking closer, it's a trust boundary. Server-side proving means a company's infrastructure technically sees your unencrypted data at some point, even briefly, even if they promise not to log it. Client-side proving removes that step entirely — there's no server in the loop that could see it, log it, or leak it, because it never had it.
The trade-off is real too: client-side proving depends on the user's own device and browser being capable and uncompromised. A malicious browser extension or a compromised device becomes the weak point instead of a server. Dusk moved the trust problem, it didn't delete it — just relocated it from a company's servers to hardware individual users don't fully control either.
Maybe the real question for regulated finance isn't "server or device" but which one institutions are actually more willing to be accountable for
$EVAA
I used to assume zero-knowledge proofs were something a server generated for you — you send data, a backend crunches the math, you get a verified transaction back. Convenient, but it means trusting whatever machine is doing the crunching.
Hedger, Dusk's privacy engine for DuskEVM, doesn't work that way. The proof itself is generated in-browser, on the user's own device, in under two seconds. Nothing about the private inputs — balances, amounts, identities — ever gets sent to a server to be proven. The math happens locally, and only the finished proof, not the underlying data, goes on-chain.
At first that read as a performance stat. Looking closer, it's a trust boundary. Server-side proving means a company's infrastructure technically sees your unencrypted data at some point, even briefly, even if they promise not to log it. Client-side proving removes that step entirely — there's no server in the loop that could see it, log it, or leak it, because it never had it.
The trade-off is real too: client-side proving depends on the user's own device and browser being capable and uncompromised. A malicious browser extension or a compromised device becomes the weak point instead of a server. Dusk moved the trust problem, it didn't delete it — just relocated it from a company's servers to hardware individual users don't fully control either.
Maybe the real question for regulated finance isn't "server or device" but which one institutions are actually more willing to be accountable for
$EVAA