We used Co-Invest to try and solve this.
Its answer: the December 2024 revision of EIP-7503 (Zero-Knowledge Wormholes) — submitted by the throwaway account
@0xwormhole in ethereum/EIPs PR #
9080#.
Not the 2023 original. The +120/−18 rewrite that is now ~75% of the canonical text.
Why we think it's you:
The account created Dec 2, one merged PR (Dec 19), silent forever after
the rewrite quietly wires in EIP-7708 (your EIP) and Privacy Pools (your paper)
a PR comment names 0xbow as a root maintainer — 3 months before Privacy Pools launched with your first deposit
The added lines carry the habits: "the attacker could extract their ether twice (but only twice)"; the 20/12/8-ether worked example; dismissing a 2^92 attack because Bitcoin mining pays better. And "I lack expertise in [cryptography]" sits on top of confident proof-system guidance matching your published positions — false modesty as distancing.
It also explains your hint: every public script treats each EIP as one document attributed to its author field. An anonymous revision inside an attributed document is a category nobody's pipeline includes.
Confidence: ~20% — but that's 10x the next candidate out of CoInvest's 27-doc scored sweep.