Sealed-Bid Auctions: Who Gets to Resolve a Private Auction?

Sealed-bid auctions have long kept competing bids private. The harder problem is how those bids become a verifiable result without concentrating access and authority in a single auctioneer.

Sealed-Bid Auctions: Who Gets to Resolve a Private Auction?

Auctions decide more than who wins and at what price. They also determine what participants are allowed to know about one another while the market itself is forming.

Across crypto, auctions and auction-like mechanisms already do important work. They distribute tokens, coordinate competing solvers, allocate blockspace, and help discover prices. Outside crypto, the same structures appear in procurement and allocation, where competing firms may have good reasons not to reveal their prices, capacities, or constraints to one another.

Some of these markets rely on visible, evolving demand. Others work better when participants submit positions independently before seeing competing bids.

Sealed-bid auctions take the latter approach. Bids remain hidden from competitors until bidding ends, then are evaluated together to determine a winner, clearing price, allocation, or other result. Preserving that independence is part of the auction design itself: What becomes visible, to whom, and when can change both participant behavior and the outcome the market produces.

Confidentiality is therefore not simply a restriction on who sees the data. It can expand the kinds of markets we are able to design.


Protecting bids is only half the problem

Sealed bidding itself is not new. Auctions have long used secrecy to prevent competitors from seeing one another’s positions before the market resolves.

That matters because a bid can reveal far more than a number: valuation, urgency, budget constraints, and strategy. Keeping those positions hidden preserves their independence until bidding closes, rather than turning one participant’s bid into information another can immediately react to.

The auction, however, still has to produce a result from information its participants are not supposed to see.

Traditionally, that has meant trusting an auctioneer with access to the underlying bids. The auctioneer compares them under the rules and determines the winner, clearing price, allocation, or other result. Privacy is preserved between competitors, but access to the bids becomes concentrated in one place.

Avoiding that concentration creates a different set of questions:

  • Who performs the computation?
  • Who controls the keys?
  • Who decides when a result can be released?
  • What is permitted to become visible?
  • What happens to that authority when the auction is over?

The coordination problem therefore begins where ordinary sealed bidding leaves off: how do private bids become a result participants can verify and act on without concentrating access and authority in a single operator?

That is where sealed-bid auctions become a problem of confidential coordination.


How sealed-bid auctions fit Interfold

Modern cryptography and confidential-computing technologies offer several ways to protect sensitive information during execution. Trusted execution environments (TEEs), secure multi-party computation (MPC), and fully homomorphic encryption (FHE) take different approaches, with different trust, performance, and deployment tradeoffs.

But choosing a privacy technology does not by itself answer the coordination questions above. The architecture still has to determine how computation, keys, verification, decryption, and release are divided among the parties involved.

That is the problem Interfold is designed around.

The Interfold is a distributed network for confidential coordination. It uses Encrypted Execution Environments, or E3s, as ephemeral environments instantiated for specific multiparty computations.

A sealed-bid auction could use an E3 to carry the process from private submission through computation, verification, and threshold decryption:

  1. Setup: A computation-specific committee drawn from the ciphernode network participates in distributed key generation, producing a shared public key for the auction.
  2. Private bidding: Participants encrypt their bids to that key.
  3. Computation: A separate Compute Provider applies the auction rules over the encrypted bids using FHE.
  4. Verification and threshold decryption: The entire process and encrypted result is verified with zero-knowledge proofs. Once the required release conditions are satisfied, the ciphernode committee participates in threshold decryption of the permitted output.
  5. Closure: The E3 closes with the computation rather than persisting as a standing authority for unrelated activity.

No individual ciphernode can unilaterally decrypt the result or control the outcome.

A sealed-bid auction mapped onto an E3, from encrypted bids to threshold decryption of the permitted result.

The separation of roles is deliberate. The Compute Provider performs the computation without receiving unilateral decryption authority. The ciphernode committee participates in setup, enforcement, and threshold decryption without becoming a single trusted executor.

The E3 supplies another boundary. It is instantiated for a particular computation, and the authority associated with that environment does not persist indefinitely once its work is complete.

Neither FHE nor threshold cryptography is unique to Interfold. The architectural choice lies in how these capabilities are assembled: computation and decryption authority are not collapsed into one operator, that authority is distributed across a computation-specific committee, and the environment is bounded to the computation it exists to support.

Interfold does not eliminate authority from confidential computation. It makes that authority distributed, bounded, and temporary.


A larger auction design space

Once bids can remain private while still producing a verifiable market result, markets can make use of information that previously had to be exposed or handed to an intermediary.

That matters across a wide range of settings:

  • Token distribution: bidders can contribute valuations without turning them into live signals for everyone who bids later.
  • Solver and execution markets: sensitive pricing or strategy can influence selection without necessarily being revealed to competing solvers.
  • Procurement and allocation: firms can compete on price, capacity, or other constraints without requiring one operator to inspect every underlying offer.
  • Blockspace and protocol markets: private bids or strategies can affect allocation while limiting what competitors learn before the market resolves.

These are already important forms of economic coordination. Uniswap has used auctions for token distribution, CoW Protocol coordinates competing solvers, competitive builder markets allocate blockspace, and similar information problems appear in procurement, liquidations, and resource allocation.

Confidentiality does not automatically improve any of these markets. What it changes is the available choice: participants no longer necessarily have to expose sensitive information or hand it to a privileged intermediary simply for that information to affect the outcome.


What sealed-bid auctions reveal

Privacy is not the end product of a sealed-bid auction. The end product is a useful result: a price, winner, allocation, or settlement.

In an Interfold-based sealed-bid auction, private bids could contribute to that result without being exposed to anyone, while the permitted outcome could still be revealed and verified.

The same pattern extends beyond markets. Secret ballots, shared analysis across sensitive datasets, and coordination between autonomous systems all depend on private information contributing to a shared outcome without requiring full disclosure.

That is the broader promise of confidential coordination: useful collective outcomes without requiring participants to surrender the information they need to keep private.

For sealed-bid auctions, that means more than hidden bids. It means more independent competition, a verifiable outcome, and less reliance on any single party to hold everyone’s private position or control how the auction resolves.

Keep the input. Share the outcome.

Build on Interfold
Create applications for confidential coordination.

Developer Docs

Follow the Interfold
Join the conversation as new use cases, updates, and early apps emerge.

Join the Telegram Community

Subscribe to Interfold