
According to reports from crypto.news and Finextra, StarkWare has introduced Private KYC on Starknet, a demonstration that enables users to complete know-your-customer checks without providing companies with full copies of identity documents. The system utilizes zero-knowledge STARK proofs and STRK20 privacy features to confirm specific facts such as age, valid credentials, or eligibility requirements. As reported by crypto.news, the Starknet team stated that "Identity checks today ask for your whole document when they only need one fact." The system was announced Tuesday as a demo and allows users to prove specific attributes like being older than 18 or holding valid credentials without revealing full passport details or address information. According to Finextra, the prototype works by flipping the logic of how identity verification is typically done, with users scanning their passport using their phone's NFC chip and encrypting identity data to their own Starknet account rather than storing it on a third-party server.
As detailed by crypto.news and Finextra, the Private KYC process begins when users scan a passport on their phone, with the phone camera and NFC chip verifying the document's authenticity and signature by its issuing authority. Users can then encrypt identity data to a Starknet wallet and register selected attributes in a public onchain registry. According to Finextra, when a KYC check is required, the system generates a zero-knowledge proof of just the fact that matters, such as confirming the user is over 18, while name, date of birth, and document number remain sealed. The system operates on a self-custody model where users maintain control over encrypted identity data rather than sending complete files to verification platforms. As reported by Finextra, the technical architecture relies on client-side zero-knowledge proofs built with StarkWare's Stwo prover and Cairo programming language, extending the same infrastructure into identity verification that was previously used for ERC-20 tokens.
According to crypto.news and Finextra, the launch addresses growing concerns over data breach costs and personal KYC record storage. The Identity Theft Resource Center reported 3,322 U.S. data compromises in 2025, representing a 79% increase over five years. As reported by crypto.news, IBM placed the global average cost of a data breach at $4.4 million in its 2025 report. The system aims to protect users from data breaches like the 2020 Ledger breach that exposed more than 1 million email addresses, including names, phone numbers, and physical addresses. As reported by Finextra, the timing is particularly relevant given the IDmerit data breach disclosed in February 2026, which exposed a data set running to roughly 1 billion records, including approximately 203 million US records. Unlike traditional passwords or credit card numbers, biometric data cannot be changed if compromised, posing long-term security risks - if fingerprints or iris patterns are stolen, the victim is permanently vulnerable to identity theft. According to Finextra, StarkWare's architecture sidesteps this problem by design because no raw document is ever handed to a verifier, so there is no archive to steal.
According to crypto.news, Finextra, and Axis Intelligence, Private KYC builds upon Starknet's wider STRK20 privacy framework, which allows ERC-20 assets to use shielded balances and private transfers while maintaining compliance capabilities. As previously reported by crypto.news, Starknet launched STRK20 privacy for ERC-20 tokens earlier this month, enabling users to move assets between public and shielded states with zero-knowledge proofs confirming compliance with network rules. The system provides a risk-based framework rather than legal approval guarantees, with StarkWare noting that Private KYC does not remove KYC requirements but limits what companies receive when only one fact confirmation is needed. According to Finextra, STRK20, which launched in early June, introduces zero-knowledge privacy features for ERC-20 tokens, letting users shield balances and make private transfers without moving assets to a separate privacy chain.
According to crypto.news, Finextra, and Axis Intelligence, adoption of Private KYC will depend on legal review, application support, verifier trust, and security testing. The system differs from alternatives like World ID, which uses zero-knowledge proofs but faces criticism over biometric checks through iris-scanning hardware. As reported by Finextra, StarkWare's demonstration focuses on passport-based checks, phone verification, and selective disclosure through Starknet, positioning KYC data exposure at the center of privacy discussions in the cryptocurrency and blockchain sectors. The system is similar to Sam Altman's World ID (Worldcoin), which uses zk-proofs to verify humanness via iris scans on hardware orbs, but StarkWare's self-custody model aims to address concerns over centralized biometric custody. According to Finextra, StarkWare's architecture sidesteps the problem of centralized identity databases that continue to attract attackers, though the approach has not yet faced broad regulatory testing and institutions will still need to assess its legal, security, and operational controls before adoption. For now, Private KYC is a demonstration pitched at government and institutional audiences, not a live product, with the question remaining whether regulators will accept a ZK proof as a substitute for a stored document copy.