Ethereum Foundation launches zkAPI payment system on mainnet
The Ethereum Foundation’s zkAPI payment system went live on mainnet on Thursday, October 1, giving a privacy-preserving AI billing design co-authored by Vitalik Buterin its first real-world test. The rollout reveals a 24-hour window for users to exit unspent funds without a server’s cooperation, alongside a rule that lets the protocol’s treasury claim an entire deposit if a user misses a 30-day deadline.
- Ethereum Foundation announced zkAPI’s mainnet launch on Oct. 1; the linked vault contract was created on Etherscan a day earlier, on Sept. 30.
- Escape withdrawals, which require no server sign-off, carry a mandatory 86,400-second challenge window before funds release.
- An expired active note sends its full recorded deposit to the treasury rather than the user’s remaining balance.
- 24 hrs Challenge period before an uncontested escape withdrawal finalizes and pays out
- 30 days Maximum note lifetime before unspent funds become eligible for treasury seizure
- Sept 30 Vault contract creation date, one day ahead of the Oct. 1 mainnet announcement
- Feb 11 Date Crapis and Buterin first published the zkAPI design, months before launch
The Ethereum Foundation said on Thursday, October 1 that zkAPI, a billing system for metered AI application programming interfaces, is now running on Ethereum mainnet, according to reporting by CryptoSlate. The underlying design came from Ethereum Foundation researcher Davide Crapis and co-founder Vitalik Buterin, who published the proposal on Feb. 11, approximately seven and a half months before the mainnet launch.
Open Anonymity built the mainnet implementation in partnership with the Ethereum Foundation. The software turns the February design into deployed contracts that now hold real deposits.
Announcement lists USDC credits, mainnet code shows native ETH instead
The Oct. 1 announcement describes the system’s vault as holding USDC credits. The current mainnet manifest identifies that same vault as native ETH, with balances tracked in whole gwei rather than stablecoin units, and explorer activity confirms ETH-valued deposits and payouts rather than USDC transfers.
Etherscan records show the vault contract was created on Sept. 30, one day before the Ethereum Foundation’s public announcement. CryptoSlate’s February coverage had examined the Crapis-Buterin proposal before any contract existed, meaning the mainnet deployment now gives the design’s withdrawal rights, deadlines and settlement rules practical weight for the first time.
That denomination gap matters for users. According to the project’s native billing documentation, a deposit is neither a stable dollar balance nor a swap into USDC, so its dollar value moves with ETH’s price between sessions.
Escape withdrawal skips the billing server, but a 24-hour clock starts ticking
Under the protocol, a deposit funds a “note” whose spending state is held locally by the user’s wallet and authorized through zero-knowledge proofs rather than per-request onchain transactions. Two paths exist to recover unspent funds. Mutual close requires the billing server’s signing key to clear a withdrawal, while the escape route lets a wallet exit without that signature.
Initiating an escape withdrawal removes the note from the active set and records a pending payout instead of an instant transfer. The public mainnet configuration, defined in the vault contract, sets the challenge period at 86,400 seconds, or 24 hours, during which anyone can contest a withdrawal attempted from an already-used spending state.
Each spending state carries a cryptographic nullifier that prevents reuse. A challenger who supplies an original request proof matching that nullifier can cancel the pending payout and restore the note to the active set, though a successful challenge imposes no separate monetary penalty and leaves any disputed bill unresolved.
Expired notes forfeit the whole deposit, not just leftover balance
The vault owner holds a pause switch that blocks new deposits, mutual close requests and the initiation of fresh escape withdrawals. That pause does not apply to escape withdrawals already pending finalization, to challenges, or to expiry claims, meaning a user who has already started an exit sits in a different position from one who has not.
Expiry adds a second deadline. The mainnet manifest sets a 30-day note lifetime, rounded upward to a one-day boundary by the vault code, so actual expiry can land slightly later than exactly 30 elapsed days.
Once an active note expires, the contract permits an expiry claim that sends the note’s entire recorded deposit to the treasury, a different outcome from a standard withdrawal, which pays only the proved remaining balance to the user. A note already marked pending withdrawal does not qualify for this treasury claim, and dollar-denominated usage is still converted using a pinned Chainlink ETH/USD price round, bound into the authorization at settlement time.
The setup carries its own disclosed limitation. According to the project’s setup documentation, the Groth16 circuit keys were generated by a single party with no multiparty ceremony, and the manifest labels the integration experimental and not production-audited.
The BlockWest read. Treasuries, not just users, now have a stake in how fast wallets act. Any team building on zkAPI needs operational discipline around note tracking and challenge monitoring, because a missed 30-day window or an unmonitored escape converts a user’s deposit into protocol revenue. For AI-agent treasurers prepaying for inference, that turns idle balances into a liability rather than a convenience, and it argues for automated exit tooling before adoption scales beyond early testing.
The Ethereum Foundation and Open Anonymity have not disclosed a timeline for a multiparty trusted setup ceremony or a third-party audit, both flagged as outstanding in the project’s own documentation, leaving open how much reliance early users should place on a single-party key generation before committing larger deposits.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
