Why ephemeral
One reused address makes income public. Stealth addresses fix the cryptography; most leaks come after. Here is the problem in numbers.
The problem: one address, every payment
An Ethereum address is permanent and public. Once someone links it to you, through an invoice, an ENS name, an exchange withdrawal or a post, they can read:
- every payment you ever received, with amounts and dates;
- who paid you, and how often;
- your balance today, and how it changed.
Banks keep this information private by default. On Ethereum it is public by default, and most people make it worse by reusing one address for everything.
The standard fix exists
Stealth addresses solve the receiving side. With ERC-5564, a sender derives a brand-new address for every payment from a meta-address you publish once. No two payments to you share an address, and nobody without your viewing key can tell that they belong together.
Stealth payments have been usable on Ethereum since Umbra launched in 2021 with its own contracts. ERC-5564 later turned the idea into a standard, and its Announcer and the ERC-6538 registry now sit at the same address on Ethereum, Arbitrum, Base, Optimism and Polygon.
Why it is not enough yet
Stealth addresses hide where a payment lands. They do nothing about what you do next. We re-ran the method of a 2023 study on every Umbra and ERC-5564 payment ever made on Ethereum:
| Measure | Value |
|---|---|
| Stealth addresses analysed | 25,645 |
| Withdrawn addresses traced (H1 or H2) | 38.97% (9,749 of 25,017) |
| First paid in 2021 and traced | 71.1% |
| First paid in 2025 and traced | 12.12% |
| Single withdrawals in a collector cluster (H3) | 45.68% |
Almost every trace came from one habit: withdrawing to the address that registered the stealth keys, which accounts for 9,709 traced withdrawals. The trend is improving, but one payment in eight is still traced in 2025. The full study is in 4 in 10.
What ephemeral changes
ephemeral treats the moment funds move as part of the privacy design, not as the user's problem.
- The safe path is the default. The client blocks your key wallet as a destination, has no sweep-all button and warns before a round trip to the payer. See Withdraw without leaking.
- The leaks are measured in public. The scanner is open source and prints aggregate numbers only, so anyone can check whether things improve.
- Paying you privately needs nothing special from the sender. Private names (planned) will resolve to a fresh address in any wallet that resolves ENS names.
- It stays a standard. No new contracts sit between sender and receiver. Payments work with every ERC-5564 wallet, and keep working without us.
Why now
In May 2026 Vitalik Buterin called a single global address “a norm we have to break”, when backing Kohaku's feature that gives users a new address for every app (source). That covers where you go. Shielded pools such as Privacy Pools and Railgun cover what you send. The place you get paid is still one public address for most people. ephemeral is built for that side.
ephemeral is independent. It is not affiliated with the Ethereum Foundation, Kohaku or any project named on this page, and the quote above is context, not endorsement.