Great work! Congrats! A few comments and food for thought below. In a nutshell, I’m not in favor of enshrining a non-general purpose and likely a temporary privacy solution on the L1. Additionally, in terms of practical privacy/plausible deniability point of view it is a very minimal (if at all) improvement over Tornado Cash-style shielded pools.
- Post-quantum security Looking ahead, one of the many reasons why EIP-7503 seems to be temporary is the lack of post-quanutm security. For wormhole to be future-proof, at least there should be a clear path towards transitioning into a post-quantum world. This perhaps should already apply to any L1 protocol upgrade.
- Plausible deniability People seem to underestimate the power of side-channels and metadata analyses on blockchains. In particular, even though the raison d’être of Wormhole would be plausible deniability, I believe, in practice it would essentially provide negligible plausible deniability. There are numerous papers analyzing the time passed between (heuristically) linked deposit and withdraw transaction in Tornado Cash. They consistently find that it follows a distribution with low means (2-3 days) and exponentially decaying tails in the distribution. See for instance, Figures 8. and 9. here or Figure 17. here. Thus, in practice, the anonymity set of a Wormhole withdraw transaction will be only a few (hundred) thousand transactions in the last few days. The situation will be dramatically worse, when one considers the particular amount correlations. (Most users will just withdraw Wormhole deposits all at once because of convenience and moderate withdraw gas costs) One could say as it was suggested by the Scroll Team to apply “a fixed denominated list of deposit amounts for simpler UX”. But such a design would essentially collapse the entire system back to a Tornado Cash shielded-pool in terms of detectability. We are back at square one.
- Non-general purpose privacy In my view, EIP-7503 would be at the level of a potential L1-enshrinement if it could provide general-purpose, programmable privacy. The current design is essentially a Tornado Cash-style privacy-enhancing technology from late 2019. In the long run, we would need a Wormhole-like privacy tool that lets us not only deposit and withdraw ether/erc20 tokens, but also allows transfers (this is already enabled by Wormhole), swaps, and ideally anything DeFi. Real anonymity set would stem from programmability. If people could use their money “inside Wormhole” then they would not be motivated to exit the system. Wormhole as an “undetectable Railgun” would be really cool. Enhanced usability and more functionalities (i.e., transfers, swaps, DeFi) will also increase adoption and the maturity of the proposal.