Eigen RadarAI
Analysis

Buterin tests private AI advice and finds limits in speed and data sharing

Vitalik Buterin used a local model, zkAPI payments and Tor routing to seek diet and exercise suggestions from remote AI models while limiting disclosure of his health and travel information. He said remote input improved the advice. His personal experiment also exposed difficulties in separating requests, choosing what to share and running the local model quickly enough. The setup demonstrates his attempt to protect several routes to identification, rather than a verified guarantee of anonymity.

Artificial Intelligence··Night
A closed laptop sits on a wooden home desk beside a bowl of vegetables and grains, with dumbbells on a shelf behind.

Advice drawn from personal information

Vitalik Buterin wanted diet and exercise suggestions informed by his own health and travel information, while limiting what remote AI providers learned about him. Blockonomi and U.Today describe his October 4 self-experiment: a model running on his own machine coordinated calls to more capable remote models. He said the additional knowledge improved the recommendations. This was an account of his personal setup and experience, with unresolved weaknesses, rather than a generally available service or an independent test of whether strangers could identify him.[1], [2]

The local coordinator was Qwen 3.8 Flash Next. Instructions in a skill file guided when it should ask remote models for help and how to compose a request containing less personal information. The local model wrote those questions itself. That step aimed to limit recognition through the user's phrasing as well as through explicit personal details. Buterin still found the request-writing methods in need of improvement. Sending less context could also reduce how much useful, personalized help the remote model was able to provide.[1], [2]

Payment and connection add other identity links

The other two protections addressed information outside the question itself. Buterin used zkAPI to separate payment authorization from his identity, and Tor to route connections with network and IP-address privacy in mind. Blockonomi and U.Today describe the combination of these three layers. Each targeted a different potential link: what the model was told, who paid and where the connection came from. Buterin accessed zkAPI through a command-line tool wrapped with Tor. He nevertheless considered Tor poorly suited to keeping individual requests from being linked, and questioned whether it gave enough privacy for this use.[1], [2]

Speed remains part of the difficulty

The local model’s speed was another constraint. Blockonomi reports Buterin’s estimate of roughly 20 to 30 tokens per second, compared with the more than 100 he thought would begin to feel fast. He also estimated that Tor latency was 10 to 100 times higher than it could be. These are his observations of the setup, not comparative measurements across all devices or networks. Useful remote advice, minimal disclosure and quick responses remained competing demands in the experiment. The recommendations he received did not settle his concerns about request linking or the information selected for each remote call.[1]

References

  1. News sourceBlockonomiVitalik Buterin tests three layers of privacy for personal AI requests↩1↩2↩3↩4
  2. News sourceU.TodayVitalik Buterin tests a privacy setup for personalized AI recommendations↩1↩2↩3