Sui just pushed a test upgrade. The real privacy work already went live.
The new test release mostly helps developers. The bigger move is that Sui already put privacy cryptography inside the base chain.

CryptoVibe Desk · sui · protocols · privacy

- →Mysten Labs shipped Sui testnet protocol version 129 today, one day after the matching devnet pre-release.
- →The testnet changes are mostly client and tooling work, while mainnet version 128 already enabled Ristretto255 and bulletproofs.
- →Watch whether Sui teams build real confidential apps on these primitives, because protocol-level privacy only matters if developers use it.
- Ristretto255 → Ristretto255 is a math tool developers use to build private value systems without leaking the raw amounts.
- Bulletproofs → Bulletproofs let an app prove a hidden number is valid without showing the number itself.
- gRPC → gRPC is a way apps and servers talk to each other using structured requests.
- DKG → DKG is a process where validators create shared cryptographic keys without one party holding the whole secret.
Sui's fresh testnet release is not the main event. Mysten Labs shipped testnet-v1.75.1 today, with protocol version 129 listed in the GitHub release. It came about 25 hours after the matching devnet pre-release, according to the same release trail.
The testnet payload is mostly developer ergonomics. Linked tables now get insert_before and insert_after APIs. Binary pools get explicit bounds. State-sync archives now support Google Cloud Storage. Useful, but not the reason to care.
The real payload landed six days earlier. Mysten's July 1 mainnet-v1.74.1 release lists protocol version 128 and enables Ristretto255 group operations plus bulletproofs range-proof verification. At the contract level, that means Sui apps can now verify private value commitments using L1 primitives.
That is a serious design choice. Privacy can live as an app-level add-on, with each team carrying its own crypto assumptions. Or the base chain can expose the rails and let apps compose around them. Sui just chose the second path, for now.
The tradeoff is shared power for shared risk. If the primitive is correct, every app gets a cleaner base to build confidential transfers, private balances, or hidden-range checks. If the primitive has edge cases, the blast radius sits closer to the protocol.
There is also one testnet break worth flagging. The v1.75.1 release changes how gRPC pagination cursors are encoded. The notes say users should restart pagination from the beginning if they hit a cursor error. If you run indexers against list_transactions, list_events, or list_checkpoints, your retry path now matters.
That is a backpressure problem, not a consensus problem. Your client needs to handle cursor failure without pretending the stream is still clean. Read the release notes, not the thread.
The DKG fix also deserves attention. Mainnet-v1.74.1 corrected a protocol version that Mysten says was incorrectly modified after release to testnet. That points to validator coordination, not just code cleanup. The engineers know this; the release got a dedicated protocol bump for a reason.
So yes, v129 is a testnet rollout. But the privacy story is already live on mainnet version 128. If you're building on Sui, the question is no longer whether the chain has these primitives. Can your app use them without creating a future case where the numbers don't add up?
Mysten Labs made the right sequencing call by shipping Ristretto255 and bulletproofs before naming an app. Privacy tooling needs shared verification, not app-by-app crypto stacks.
Before the next Sui mainnet protocol bump, watch for at least one public app repo using the new Ristretto255 or bulletproofs APIs in production-facing code.
Primary links and supporting reads used by the desk for this story.
Forward this.











