A coworker can calculate your exact salary in about thirty seconds.
They don't need HR.
They don't need to hack anything.
They only need a block explorer and some common sense.
If your company pay employees via onchain including: LlamaPay, Sablier, Superfluid, etc, every salary is a public information. The stream is visible onchain and auditable by anyone and is marketed as a feature, but is it really the feature you want?
Now picture the whole org chart laid out that way. Every raise, the moment it lands. Every contractor's rate. The exact day a new hire started, because that's when their stream opened. A competitor can read your entire payroll without sending you a single email.
There Is No Private Mode
A payment is a transaction. A transaction is a permanent, public, indexed, searchable record. That is true of payroll, and it's equally true of the invoice you paid your supplier, the retainer you sent a law firm, the bonus you wired a founder. There is no "business mode" toggle that makes a transaction private. The ledger is the product, and the ledger is open by default.
Onchain, transparency isn't something you opt into. It's the thing you'd have to opt out of, and until now, you couldn't.
The Ticket That Doxxes Your Calendar
It isn't only payroll. Watch what a single conference ticket gives away.
Devcon 8, Ethereum's flagship event, comes to Mumbai this November, and a share of its tickets are sold onchain, ETH only, starting at $349. As of this writing it holds over $100,000, across 450+ transactions, and every one of those payments is right there in the open: which address paid, how much, and exactly when.
That alone reveals who plans to be in Mumbai in November and what they spent to get there. But it gets sharper, because a large share of those payers have set an ENS primary name, the reverse record that maps a raw 0x… address back to something like alice.eth. Skim the sender list and the pseudonyms fall away: these aren't anonymous wallets, they're named people. Each one's entire onchain history, balances, trades, every other purchase, is now attached to a real identity, a real travel plan, and a real disposable income. Permanently. From one $349 ticket.
Your employees do this. Your executives do this. Each purchase clusters back to a wallet, and wallets cluster back to your company. So, no more asking for a fake sick leave from the boss :(
It Isn't One Leak. It's the Design.
If this were a single sloppy tool, you could just avoid it. It isn't. An entire industry exists to read what the chain publishes:
- Intelligence as a service. Arkham clusters wallets into named entities, "a16z," "Tesla Treasury," "Lazarus Group", and makes a treasury's every move searchable. Accounts like Lookonchain broadcast significant flows to hundreds of thousands of followers in near real time.
- Forensic graph analysis. Bubblemaps turns onchain relationships into exposés, tracing, in the case of the Edel token, 160 wallets and roughly $11 million allegedly sniped by team-linked addresses. The exact clustering that catches insider fraud reads an honest business's supplier and payroll graph just as easily.
- Treasuries in a glass box. Safe multisigs are the de-facto DAO treasury (Balancer, Sushi, Yearn, and more), holding tens of billions in assets. Every vendor payment, contractor payout, and payroll run is enumerable, and platforms like DeepDAO index thousands of these treasuries for anyone to browse.
- Grants on the record forever. Optimism's RetroPGF Round 3 paid 501 projects more than $110M in OP, with the exact amounts tied to named recipients. Who received how much, published permanently.
Different tools, one structural fact: money that moves onchain is money the world can watch.
The Cost Is Not Abstract
Line this up and the harm writes itself.
Competitive intelligence. Your pricing gets undercut because a rival reverse-engineered your margins. Your supplier gets a better offer because someone saw the invoice. Your budget gets modeled because your treasury is a live spreadsheet.
Targeted social engineering. A phisher who can see which employee just started a large salary stream knows exactly who to target, and roughly how much to ask for. Onchain wealth is a lead list for scams.
And then the part nobody wants to say out loud: physical safety.
Physical attacks on crypto holders rose 75% in 2025, 72 confirmed incidents, around $41 million taken, and "wrench attacks," violent robberies and kidnappings, have climbed roughly threefold since 2023. How do attackers choose a target? Chainalysis and others point to the same source: public blockchain records paired with onchain analytics that make big holders easy to find.
On-chain financial exposure is a target list. For a business, that list has names on it, your executives, your best-paid people. What looks like a transparency feature is, in aggregate, a doxxing engine.
The Fix Isn't "Be More Careful"
Here is the good news, and it's the whole point of this piece: you cannot out-discipline a public ledger, but you can change what the ledger records.
Careful address hygiene doesn't help, because the protocols that hold state, payroll streams, treasuries, ticket contracts, remember you on purpose. The mechanism is the problem: payments are transactions, and transactions are public. So fix the mechanism.
Platus is a composable private account layer for Ethereum and EVM chains. It closes each leak you just read about, and it does so without changing how you pay people.
Stealth addresses with persistent state. Your business publishes one address to be paid at. Under the hood, every payer sends to a fresh, one-time stealth address that no outside observer can link to you, or to each other. There is no repeated counterparty, no cluster to map, no pattern for an analytics firm to name. The receive address stays recognizable to you and your payers; to everyone else, it's noise.
Amounts and counterparties are never plaintext. Every note is encrypted twice, C_enc for the recipient and C_out for the sender's own records. The salary, the invoice value, the identity of who paid whom: none of it appears onchain in the clear. Not to a competitor. Not to a bot. Not even to a third party who happens to know both wallet addresses.
And it stays sealed, even against a computer that doesn't exist yet. This is the part that matters most for a business, because business records are long-lived. A payroll stream or a supplier invoice encrypted today with classical ECDH is exactly what a "harvest now, decrypt later" adversary wants: record the ciphertext now, wait five or ten years for a cryptographically relevant quantum computer, then decrypt your entire historical payroll and supplier graph at once, retroactively. Platus encrypts notes with hybrid encryption, a hybrid of Baby Jubjub ECDH and ML-KEM-768. Your financial history isn't just private today. It's private permanently.
The Database Was Never the Point
Your business doesn't need a public transparency dashboard for its adversaries. It needs to pay salaries, settle invoices, and buy the occasional conference ticket, without publishing a permanent record of everything it does and everyone it works with.
Today, that record is the default. Every payment you make quietly writes another row.
It doesn't have to. Privacy that works with the tools you already use, that asks nothing of you and leaves nothing in the clear, is the version of onchain your business should have had from the start. Not a bunker. Just the plumbing, doing its job without narrating it to the world.
For a deep dive into the cryptography, read our technical documentation. If you want privacy that treats your business's financial history as your business, start your private journey here.
