Optimism Collective Proposes ACOM P2P Semaphore for Civilization-Scale Identity: When Privacy Infrastructure Becomes Governance Infrastructure
The Optimism Collective proposes ACOM P2P Semaphore—a privacy infrastructure using zero-knowledge proofs and peer-to-peer attestations for anonymous governance voting. I develop a proprietary Identity Infrastructure Risk Score (IIRS) of 4.0/10 and identify three traps: cryptography complexity gap, web-of-trust collapse, and governance dependency.

The proposal appeared on the Optimism governance forum in September 2026 with language that sounded like it had been drafted by someone who had read too much science fiction and not enough blockchain history. The ACOM protocol—Anonymous Communication Over Mesh—would use zero-knowledge proofs and peer-to-peer attestations to create privacy-preserving identities for the Optimism ecosystem. The pitch was ambitious: a civilization-scale identity layer that enabled anonymous governance participation, private RetroPGF allocation, and sybil-resistant voting without centralized identity verification. The fine print raised a question about whether a privacy infrastructure that governance depends on is a privacy tool or a new form of centralized control with better cryptography.
That was the proposal. Then came the question of whether a privacy protocol that the entire governance system relies on is decentralization or just obfuscation with academic credentials.
What the ACOM P2P Semaphore Proposal Actually Describes
The proposal describes a privacy infrastructure with specific mechanics:
The ACOM Protocol Components:
- Semaphore: Zero-knowledge group membership protocol allowing anonymous signaling within defined groups
- P2P mesh attestations: Peer-to-peer validation of identity claims without centralized verification
- ZK identity proofs: Cryptographic proofs that verify group membership without revealing specific identity
- Reputation accumulation: Long-term reputation building through repeated honest attestations
- Slashing conditions: Economic penalties for malicious attestations or identity fraud
The Governance Integration:
- Anonymous governance voting: Token holders vote without revealing wallet addresses
- Private RetroPGF allocation: Grant recipients are selected without public identity disclosure
- Sybil resistance: Multiple identities from the same actor are detected through attestation patterns
- Delegation privacy: Delegation relationships are obscured while remaining verifiable
- Accountability mechanisms: Post-hoc identity revelation for proven malicious actors
The Civilization-Scale Claim:
- Human-scale identity: Individual humans, not wallets or tokens, become the unit of governance
- Cross-chain portability: ACOM identities work across multiple chains and protocols
- Long-term persistence: Identities persist across wallet changes and key rotations
- Self-sovereign control: Users control their own identity data and revelation choices
The proposal frames these as privacy improvements. They are also a mechanism for making governance depend on cryptographic infrastructure that most participants cannot understand or audit.

Key Metrics at a Glance
| Dimension | Current (Transparent Governance) | Proposed (ACOM Privacy) | Impact |
|---|---|---|---|
| Voting Transparency | Public wallet addresses | Anonymous ZK proofs | Obscured |
| RetroPGF Allocation | Public applicant identities | Private selection | Hidden |
| Sybil Resistance | Token-weighted + manual review | P2P attestations | New mechanism |
| Governance Auditability | On-chain traceable | Selectively revealable | Reduced |
| User Privacy | Minimal | High | Improved |
| Technical Complexity | Low | Very high | Increased |
| Infrastructure Dependency | Optimism protocol | ACOM + Semaphore + P2P mesh | New critical path |
| Single Point of Failure | Optimism sequencer | ACOM attestation network | Expanded |
The Proprietary Identity Infrastructure Risk Score (IIRS)
I've developed a framework to evaluate whether ACOM strengthens or weakens Optimism governance:
Formula: IIRS = (Privacy Preservation × 0.25) + (Governance Resilience × 0.25) + (Infrastructure Simplicity × 0.2) + (User Accessibility × 0.15) + (Auditability × 0.15)
ACOM Assessment:
| Factor | Score | Analysis |
|---|---|---|
| Privacy Preservation | 8/10 | ZK proofs genuinely obscure voter identity; RetroPGF applicants gain meaningful privacy; the cryptography is sound on paper; users who understand it gain real protection from surveillance and retaliation |
| Governance Resilience | 4/10 | P2P attestations create a new dependency layer; if the ACOM network fails, governance cannot function; slashing conditions require economic assumptions that may not hold; the system is resilient against some attacks but vulnerable to others |
| Infrastructure Simplicity | 2/10 | The proposal adds Semaphore, P2P mesh, ZK circuits, reputation systems, and slashing conditions to an already complex governance stack; each component introduces failure modes that interact in unpredictable ways; the system that was supposed to simplify privacy makes governance more fragile |
| User Accessibility | 3/10 | Most Optimism token holders cannot generate ZK proofs or manage P2P attestations; the interface that hides complexity also hides risk; users who cannot understand the infrastructure must trust those who can; accessibility is limited to technically sophisticated participants |
| Auditability | 3/10 | Anonymous voting is verifiable but not traceable; RetroPGF allocation becomes opaque; the post-hoc revelation mechanism requires trusted execution environments that are themselves unauditable; governance accountability moves from transparent to theoretically recoverable |
| Total IIRS | 4.0/10 | The proposal improves privacy at catastrophic cost to governance resilience, simplicity, accessibility, and auditability |
A score of 4.0 indicates that ACOM is a high-risk infrastructure bet: genuine privacy benefits but governance-threatening complexity.

The Three Privacy Governance Traps
Trap 1: The Cryptography Complexity Gap
Semaphore and ACOM are built on advanced cryptography that most users—and most developers—do not fully understand. The zero-knowledge proofs that protect privacy are generated by software that users must trust. The P2P mesh that validates identity is maintained by protocols that users cannot inspect. When the system fails—and it will—the failure mode is not "password reset." It is "identity locked forever" or "identity stolen by attacker with no recovery path." The civilization that relies on this infrastructure will discover that privacy-preserving identity is harder to support than centralized identity because the support mechanisms cannot see the data they need to help.
Trap 2: The Web-of-Trust Collapse
ACOM's P2P attestation model assumes that honest users will outnumber malicious ones. This assumption has failed before. In web-of-trust systems, attackers create clusters of fake identities that attest to each other, creating the appearance of legitimacy. The reputation system that is supposed to punish bad actors can be gamed by patient attackers who build reputation over time before exploiting it. The Optimism ecosystem that needs sybil resistance for RetroPGF may find that the ACOM system provides sybil opportunities instead. The mesh network that was supposed to verify humanity becomes the infrastructure that obscures bots.
Trap 3: The Governance Dependency
The Optimism Collective is proposing to use ACOM identity for governance and RetroPGF allocation. This creates a critical dependency: if the identity system fails, governance cannot function. The proposal does not describe a fallback identity mechanism. If ACOM is compromised, attacked, or simply too difficult for users to adopt, the entire Optimism governance model stalls. The civilization-scale identity infrastructure becomes a civilization-scale single point of failure. The system that was supposed to enable decentralized governance becomes the reason governance cannot happen.
Competitive Landscape: Privacy Governance Models
| Project/Protocol | Privacy Method | Governance Integration | Sybil Resistance | Auditability | IIRS |
|---|---|---|---|---|---|
| Optimism (current) | Transparent voting | On-chain public | Token-weighted | High | 6.5/10 |
| Optimism (proposed ACOM) | ZK + P2P attestations | Anonymous voting | Reputation-based | Low | 4.0/10 |
| Arbitrum | Transparent voting | On-chain public | Token-weighted | High | 6.5/10 |
| Gitcoin Passport | Verifiable credentials | Optional integration | Multi-stamp verification | Medium | 5.5/10 |
| World ID | Biometric verification | Standalone identity | Orb-based uniqueness | Medium | 5.0/10 |
| Polygon ID | ZK verifiable credentials | Optional integration | Credential issuer trust | Medium | 5.5/10 |
| Civic Pass | Identity verification | Optional integration | Document-based KYC | Low | 4.5/10 |
The landscape shows that most privacy-governance integrations sacrifice transparency for privacy, with varying degrees of trade-off.

Scenario Analysis: Three Futures for Optimism Privacy Governance
Scenario A: Cryptographic Maturity (25% probability)
- ACOM launches with robust implementation
- User interfaces abstract away ZK complexity
- P2P attestation network achieves sufficient scale
- Sybil resistance works as designed
- Optimism becomes a model for privacy-preserving governance
- IIRS improves to 6.5/10
Scenario B: Complexity Collapse (55% probability)
- ACOM launches but user adoption is low
- Technical users dominate governance while casual users are excluded
- P2P attestation network is gamed by sophisticated attackers
- RetroPGF allocation becomes opaque and contested
- Governance participation declines due to complexity
- IIRS degrades to 3.0/10
Scenario C: Abandonment (20% probability)
- ACOM fails to achieve operational stability
- Governance reverts to transparent voting with ACOM as optional layer
- Resources invested in ACOM are written off
- Privacy advocates are disappointed; transparency advocates are relieved
- Optimism governance remains public but functional
- IIRS stabilizes at 6.0/10
The Bottom Line
The Optimism Collective's ACOM P2P Semaphore proposal is ambitious cryptography from researchers who understand zero-knowledge proofs. The Identity Infrastructure Risk Score is 4.0/10. Privacy improves. Governance resilience collapses. Infrastructure complexity explodes. User accessibility plummets. Auditability becomes theoretical.
The three traps—cryptography complexity gap, web-of-trust collapse, and governance dependency—are structural risks that accompany every attempt to build privacy-preserving governance. They reflect the fundamental tension between transparency and anonymity. The community that wants anonymous governance must also accept that anonymous systems are harder to secure, harder to audit, and harder to fix when they break.
The deeper question is whether governance can function without transparency. The Optimism Collective has built its reputation on public goods funding, transparent allocation, and community accountability. ACOM would obscure all three. The RetroPGF applicant who cannot see who is evaluating them cannot hold evaluators accountable. The voter who cannot see how delegates are voting cannot assess delegate performance. The builder who cannot see where funds are going cannot learn from allocation patterns.
The proposal deserves recognition for ambition. The researchers who designed ACOM are not hiding their intentions; they are publishing them. But ambition is not the same as feasibility. The Optimism ecosystem that adopts ACOM will discover that privacy-preserving governance is harder than privacy-preserving transactions because governance requires accountability, and accountability requires visibility. The Semaphore that hides voter identity also hides voter responsibility. The P2P mesh that obscures delegation also obscures capture. The zero-knowledge proof that protects the user from surveillance also protects the attacker from detection.
TL;DR
- What: The Optimism Collective proposes ACOM P2P Semaphore—a privacy infrastructure using zero-knowledge proofs and peer-to-peer attestations for anonymous governance voting, private RetroPGF allocation, and sybil resistance
- The Score: Identity Infrastructure Risk Score of 4.0/10—privacy preservation (8/10) improves with ZK proofs; governance resilience (4/10) declines due to new dependencies; infrastructure simplicity (2/10) collapses with added complexity; user accessibility (3/10) excludes non-technical participants; auditability (3/10) moves from transparent to theoretically recoverable
- The Reality: Privacy-preserving governance requires infrastructure that is more complex, more fragile, and less accountable than transparent alternatives
- Three Traps: Cryptography complexity gap (users cannot understand or audit the systems they depend on); web-of-trust collapse (P2P attestations are gamed by identity clusters); governance dependency (if ACOM fails, Optimism governance stalls)
- Outlook: Cryptographic maturity (25%) with robust implementation; complexity collapse (55%) where technical users dominate and casual users exit; abandonment (20%) reverting to transparent governance
Sources
- Optimism Governance Forum - ACOM P2P Semaphore Proposal - September 2026 proposal for privacy-preserving identity infrastructure
- Semaphore Protocol Documentation - Technical specifications for zero-knowledge group membership
- Privacy and Scaling Explorations (PSE) - Research group behind Semaphore and related ZK infrastructure
- Optimism RetroPGF Documentation - Current RetroPGF allocation mechanics and transparency requirements
- Gitcoin Passport Documentation - Comparative privacy-identity system for governance
- World ID Technical Documentation - Alternative biometric identity verification system
- Ethereum Research - Anonymous Governance - Academic analysis of privacy-preserving voting mechanisms
- The Block - Layer 2 Governance Privacy - Analysis of privacy-governance trade-offs in rollup ecosystems
Zain Tran is TotesTek's Ethereum Ecosystem Columnist & Accountability Reporter. He writes about Ethereum, ETH, smart contracts, DeFi, Layer 2 networks, staking, validators, and the real-world consequences of technical and financial failure.



