Homomorphic Encryption (HE)
Homomorphic encryption allows computation on encrypted data without decrypting it, enabling private smart contract execution and confidential DeFi.
Key Takeaways
- Homomorphic encryption lets you compute on encrypted data without ever decrypting it: the result, once decrypted, matches what you would get from running the same computation on plaintext. This enables privacy-preserving applications like confidential DeFi and encrypted on-chain voting.
- Three types exist with increasing capability: partially homomorphic (one operation), somewhat homomorphic (limited operations), and fully homomorphic encryption (arbitrary computation). Fully homomorphic encryption (FHE) was first constructed by Craig Gentry in 2009 and relies on lattice-based cryptography, making it resistant to quantum attacks.
- FHE remains 100x to 10,000x slower than plaintext computation, but hardware acceleration and optimized schemes are closing the gap. Blockchain projects like Zama's fhEVM and Fhenix are bringing confidential smart contracts to EVM-compatible chains.
What Is Homomorphic Encryption?
Homomorphic encryption (HE) is a form of encryption that allows mathematical operations to be performed directly on ciphertexts. When the result is decrypted, it matches the outcome of performing those same operations on the original plaintext data. Unlike traditional encryption, which requires decryption before any processing can occur, HE keeps data encrypted throughout the entire computation.
The concept was first proposed in 1978 by Rivest, Adleman, and Dertouzos, just one year after the publication of RSA. However, constructing a scheme that could handle arbitrary computations remained an open problem for over 30 years. In 2009, Craig Gentry published his Stanford PhD thesis, "A Fully Homomorphic Encryption Scheme," which demonstrated the first working construction. This breakthrough earned him the ACM Doctoral Dissertation Award and the Grace Murray Hopper Award.
For blockchain systems, HE addresses a fundamental tension: public blockchains require transparency for verification, but many financial applications demand privacy. HE allows encrypted data to be processed on-chain while preserving both confidentiality and verifiability, complementing other privacy technologies like zero-knowledge proofs and multi-party computation.
How It Works
At a high level, homomorphic encryption transforms data into ciphertexts that preserve algebraic structure. When you add or multiply two ciphertexts, the result is itself a valid ciphertext that decrypts to the sum or product of the original values. This property, called homomorphism, is what makes computation on encrypted data possible.
The Three Types
Homomorphic encryption schemes are classified by the range of operations they support:
| Type | Operations | Depth | Examples |
|---|---|---|---|
| Partially Homomorphic (PHE) | One operation (addition or multiplication) | Unlimited | RSA (multiplication), Paillier (addition) |
| Somewhat Homomorphic (SHE) | Both addition and multiplication | Limited circuit depth | Early lattice-based schemes |
| Fully Homomorphic (FHE) | Both addition and multiplication | Unlimited (via bootstrapping) | BGV, BFV, CKKS, TFHE |
Partially homomorphic schemes have been used for decades. RSA, published in 1977, is multiplicatively homomorphic: multiplying two RSA ciphertexts produces an encryption of the product of the underlying plaintexts. The Paillier cryptosystem (1999) is additively homomorphic. These schemes are efficient but limited to a single operation type, which restricts their usefulness for general computation.
Somewhat homomorphic schemes support both operations but only for a limited number of consecutive steps. Each operation introduces noise into the ciphertext, and after too many operations the accumulated noise corrupts the result, making correct decryption impossible.
Fully homomorphic encryption removes this depth limitation through a technique called bootstrapping, enabling arbitrary computation on encrypted data.
Bootstrapping
Bootstrapping is the key innovation that makes FHE possible. It refreshes a noisy ciphertext by homomorphically evaluating the decryption function itself. The process works as follows:
- Start with a ciphertext that has accumulated noise from prior operations
- Use an encrypted copy of the secret key (a bootstrapping key) to homomorphically decrypt the noisy ciphertext
- The output is a new ciphertext encrypting the same plaintext but with significantly reduced noise
- Continue performing operations on the refreshed ciphertext
The secret key is never exposed during bootstrapping: only an encrypted version is used. This allows unlimited sequential operations because noise can be reset after each computation step. However, bootstrapping is the most computationally expensive part of FHE, with a single bootstrap operation taking anywhere from 30 milliseconds to several seconds depending on the scheme and hardware.
Cryptographic Foundations
All modern FHE schemes are built on lattice-based cryptography, specifically the Learning With Errors (LWE) and Ring-LWE (RLWE) hardness assumptions. Given a system of approximate linear equations with small random errors, recovering the secret is believed to be computationally intractable, even for quantum computers.
This lattice foundation gives FHE an important advantage over elliptic curve cryptography: it is believed to be resistant to attacks from quantum computers. NIST's post-quantum cryptography standards (CRYSTALS-Kyber, CRYSTALS-Dilithium) share the same underlying hardness assumptions as FHE schemes.
Major FHE Schemes
Four FHE schemes dominate current implementations, each optimized for different use cases:
- BGV (Brakerski-Gentry-Vaikuntanathan, 2012): operates on exact modular integers, efficient for deep arithmetic circuits using modulus switching for noise management
- BFV (Brakerski/Fan-Vercauteren, 2012): similar to BGV with a scale-invariant design, operates on exact integers
- CKKS (Cheon-Kim-Kim-Song, 2017): the first scheme for approximate arithmetic on real and complex numbers, ideal for machine learning and statistical analysis where bounded numerical error is acceptable
- TFHE (Torus FHE, 2016): uses programmable bootstrapping that combines noise refreshing with function evaluation via lookup tables, achieving fast bootstrap times under 100 milliseconds and excelling at boolean circuits and conditional logic
A Simple Example
Consider a lending protocol that needs to check if a borrower's collateral ratio exceeds a threshold without revealing the exact balance:
// Conceptual FHE pseudocode (not a real library API)
// Encrypt the borrower's collateral and debt values
enc_collateral = FHE.encrypt(collateral_value, public_key)
enc_debt = FHE.encrypt(debt_value, public_key)
// Compute collateral ratio on encrypted values
// Neither the node nor the contract sees the plaintext
enc_ratio = FHE.divide(enc_collateral, enc_debt)
// Compare against threshold (also encrypted)
enc_threshold = FHE.encrypt(1.5, public_key)
enc_is_healthy = FHE.greater_than(enc_ratio, enc_threshold)
// Only the borrower can decrypt the boolean result
// The protocol learns the comparison outcome via
// a decryption request, not the underlying valuesUse Cases
Confidential DeFi
FHE enables DeFi protocols where transaction amounts, positions, and balances remain encrypted on-chain. Encrypted order books prevent front-running and sandwich attacks because MEV searchers cannot read pending orders. Private lending protocols can evaluate health factors and trigger liquidations without exposing individual positions. Encrypted AMM pools can process swaps without revealing trade sizes to observers, addressing the dark pool use case natively on-chain.
Encrypted Voting
On-chain governance suffers from voter influence: seeing how others vote before a proposal closes creates bandwagon effects and strategic voting. FHE allows ballots to be submitted as encrypted votes that are tallied homomorphically. The final result is decrypted only after voting closes, ensuring each vote is cast independently. This preserves the transparency of on-chain tallying while keeping individual ballots private.
Compliance-Preserving Privacy
FHE can bridge the gap between regulatory requirements and user privacy. A privacy pool using FHE could allow a compliance oracle to verify that a transaction meets KYC/AML requirements without accessing the underlying user data. The oracle performs its checks on encrypted inputs and returns an encrypted compliance attestation, never seeing plaintext identity information.
Confidential Token Transfers
FHE enables encrypted ERC-20-style tokens where balances and transfer amounts are encrypted on-chain. The Confidential Token Association, co-founded by Inco Network, OpenZeppelin, and Zama, published a Confidential Token Standard for this use case. Unlike confidential transactions that use Pedersen commitments to hide amounts, FHE-based tokens support arbitrary programmable logic over the encrypted balances.
FHE in the Blockchain Ecosystem
Zama and fhEVM
Zama is an open-source cryptography company building tools to make FHE practical. Their core product for blockchain is fhEVM (Fully Homomorphic Ethereum Virtual Machine), a framework that enables confidential smart contracts on any EVM-compatible chain. fhEVM uses the TFHE scheme for fast bootstrapping and allows developers to write Solidity contracts that operate on encrypted data types. Zama's fhEVM public testnet launched in July 2025.
Zama also released the first fully open-source hardware accelerator for FHE: a Homomorphic Processing Unit (HPU) implemented on FPGA, bundled with their TFHE-rs library.
Fhenix
Fhenix is building an FHE-powered Layer-2 blockchain for confidential smart contracts, having raised $22 million across seed and follow-on rounds. Their key product is CoFHE, an FHE coprocessor that can plug into any EVM chain to provide encrypted computation without requiring developers to have deep FHE expertise. Developers write standard Solidity with encrypted data types.
Inco Network
Inco Network is a modular Layer-1 blockchain that combines FHE with ZK proofs, TEEs, and MPC to provide a universal confidentiality layer for EVM and SVM chains. Inco raised $5 million in a strategic round led by a16z CSX in April 2025 and launched Inco Lightning on Base Sepolia. The project also co-founded the Confidential Token Association to standardize encrypted token implementations.
HE vs. Other Privacy Technologies
Homomorphic encryption is one of several cryptographic approaches to privacy on blockchains. Each solves a different aspect of the privacy problem:
| Technology | What It Does | Data During Computation | Trust Assumption |
|---|---|---|---|
| Homomorphic Encryption | Compute on encrypted data | Stays encrypted | Cryptographic (lattice hardness) |
| Zero-Knowledge Proofs | Prove facts without revealing data | Known to prover only | Cryptographic (varies by scheme) |
| MPC | Joint computation without sharing inputs | Split across parties | Honest majority among participants |
| TEE | Compute inside secure hardware enclave | Decrypted inside enclave | Hardware manufacturer |
The key distinction: ZK proofs let you prove something about data without revealing it, but the prover must know the data. HE lets a third party compute on data they never see. MPC distributes computation across multiple parties who each hold a share. TEEs rely on trusted hardware. In practice, these technologies are often combined: Inco Network uses FHE alongside ZK proofs and TEEs for different layers of its confidentiality stack.
For a deeper comparison of how zero-knowledge proofs apply to Bitcoin specifically, see Zero-Knowledge Proofs: Bitcoin Applications.
Risks and Considerations
Performance Overhead
FHE remains significantly slower than plaintext computation. Current CPU-only implementations run 1,000x to 10,000x slower than equivalent unencrypted operations. With GPU acceleration, batching, and optimized schemes like CKKS, the gap can narrow to 10x to 100x for throughput-oriented workloads. FHE-based smart contract platforms currently achieve only 10 to 30 transactions per second on commodity hardware.
Hardware acceleration is progressing rapidly. Zama's open-source HPU on FPGA, custom ASIC designs, and GPU frameworks have collectively improved FHE performance by 1,000x to 10,000x compared to implementations from five years ago. The DARPA DPRIVE program has funded hardware-software co-design projects specifically targeting FHE bootstrapping latency. Still, FHE-based systems are far from matching the throughput of conventional blockchains.
Ciphertext Expansion
FHE ciphertexts are much larger than their plaintext equivalents. A single encrypted integer may expand to kilobytes or even megabytes of ciphertext data. On a blockchain, this translates directly to higher storage costs and increased bandwidth requirements. Ciphertext expansion ratios of 10x to 1,000x are common depending on the scheme and security parameters.
Key Management Complexity
FHE introduces additional key management challenges. Beyond standard public and private keys, FHE systems require bootstrapping keys (which can be gigabytes in size), evaluation keys for specific operations, and careful key distribution protocols. In a blockchain context, deciding who holds the decryption key for shared encrypted state is itself a design challenge, often requiring threshold decryption via MPC or distributed key generation.
Maturity and Auditability
FHE implementations are relatively young compared to traditional cryptographic libraries. Fewer researchers and practitioners have audited FHE code paths, and subtle implementation bugs could compromise privacy guarantees. The complexity of FHE schemes also makes formal verification more difficult. Security parameters must be chosen carefully: too aggressive and the scheme becomes vulnerable, too conservative and performance degrades further.
Quantum Considerations
While FHE's lattice-based foundations are believed to be post-quantum secure, this has not been proven beyond reasonable doubt. Advances in quantum algorithms could potentially threaten lattice-based hardness assumptions. For more on how quantum computing affects cryptographic systems, see Post-Quantum Cryptography and the Bitcoin Threat.
Why It Matters
Homomorphic encryption represents a paradigm shift for blockchain privacy. Today, most blockchain privacy solutions require tradeoffs: you either lose composability (as with shielded pools), rely on trusted hardware (TEEs), or limit functionality to proof generation (ZK proofs). FHE offers the possibility of fully programmable, fully private smart contracts where encrypted state can be composed across protocols, the same way transparent DeFi works today.
For Bitcoin Layer-2 networks and stablecoin infrastructure, FHE could enable confidential balance tracking, private payment routing, and compliant-but-private transfers. As FHE performance improves through hardware acceleration and algorithmic advances, the technology is likely to become a foundational building block for the next generation of privacy-preserving financial infrastructure.
This glossary entry is for informational purposes only and does not constitute financial or investment advice. Always do your own research before using any protocol or technology.