01 — Premise
A private ledger that settles on Bitcoin
Every ordinary Bitcoin transaction is a permanent public record of who paid whom and how much. E404 keeps the settlement and drops the disclosure: value moves as encrypted notes carried inside ordinary Bitcoin transactions, proven correct by zero-knowledge proofs.
No soft fork, no sidechain, no bridge, no custodian. Bitcoin orders and timestamps the bytes; it never validates them and is never asked to. Meaning is assigned by anyone who replays those bytes under the same rules — which is why two independent indexers reading the same chain reach identical state.
Nobody can see your balance, who you paid, or how much — not other users, not the node, not anyone reading the Bitcoin chain. Your keys never leave your browser.
02 — Rates & caps
What a lot costs
E404 is minted in lots of 10,000. There are two prices: approved applicants pay a third of the open rate.
| Tier | Per lot | Your cap | Max spend |
|---|---|---|---|
| Approved | 0.00001 BTC | 100 lots · 1,000,000 E404 | 0.001 BTC |
| Open | 0.00003 BTC | 500 lots · 5,000,000 E404 | 0.015 BTC |
Caps are per wallet and counted across every invoice you open. Total supply is 210,000,000 E404, with a protocol limit of 5,000,000 per single mint.
Being on the approved list lowers what you pay. It does not reserve supply. Minting is first come, first served until the supply is gone.
03 — The mint, end to end
What actually happens
Five stages. You do three of them; the node and your own browser do the rest.
04 — Step by step
Minting, in order
-
01
Create a wallet on the site
Open the app and choose Create wallet. You get 24 words and set a password. One seed produces both halves: your shielded balance and an ordinary Bitcoin
bc1qaddress.There is no extension to install and no third-party wallet to connect. The seed is encrypted on your device; the password is never transmitted.
-
02
Write down the 24 words, offline
They are the only way to recover the wallet, and they restore both your Bitcoin and your shielded balance. Your password cannot be reset and nobody can recover it for you.
-
03
Claim your rate, if you are approved
On the mint page, choose Connect X. If that account is on the approved list, the wallet you are holding at that moment is bound to it and you pay the approved rate. The approval follows the account, not the address you applied with — so a brand-new wallet is fine.
-
04
Fund your Bitcoin address
Copy the
bc1qaddress from your dashboard and send BTC to it. Send a little more than the mint costs so there is room for the network fee.Your deposit shows its progress as it confirms: seen, then buried block by block.
-
05
Choose how much, and open an invoice
Pick the number of lots. The page shows the total in BTC and dollars before you commit. Opening an invoice reserves a one-time deposit address that belongs to that invoice alone — which is how the node knows the payment was yours.
An invoice stays open for 60 minutes.
-
06
Pay
Press Pay from your wallet and it builds, signs and broadcasts in one step. You can also send the exact amount from anywhere else to the address shown — but it must be the exact amount, to that address, before the invoice expires.
-
07
Wait for three confirmations
Roughly 30 minutes. The page shows the count as it climbs. Three blocks is the point at which a payment is settled rather than merely seen — a transaction still in the mempool can be replaced.
-
08
Minting starts by itself
There is no button. The moment the payment settles, your browser builds the zero-knowledge proof and hands the envelope to the relayer, which publishes it to Bitcoin and pays the fee.
Your E404 appears in your dashboard once the envelope is in a block.
The proof is built in your browser — that is what stops the relayer ever holding your keys — so the final step needs the page open. If you close it, nothing is lost: reopen the mint page with the same wallet and it picks the unfinished purchase back up.
05 — Approved rate
How the approved list works
Applications were made with a verified X account, so the X account — not a wallet address — is the durable identity. Proving the account is the whole check.
You can check whether you were approved before the mint opens, from the application site's eligibility page. It shows your card and the answer; looking changes nothing.
06 — What is public
Exactly what the chain reveals
A mint is the one moment value enters the pool, so the amount and ticker are public — supply has to be auditable. After that, nothing about your holdings or transfers is.
Visible to everyone
- That an envelope occurred, and when
- Its size in bytes
- Opaque nullifiers and commitments
- Mint amounts and ticker
Never revealed
- Who owns a note
- Your balance, at any time
- Sender and receiver of a transfer
- The amount transferred
- Which token moved
- Which earlier note was spent
Uniform size does the rest: every transfer is exactly 921 bytes, so length never leaks what happened. A mint is 934, because it carries the ticker and amount.
Timing. The chain shows that somebody published an envelope at a given moment. Uniform sizes hide the contents, not the fact that a transaction happened or when.
07 — How it works
Notes, nullifiers and the carrier
There are no accounts and no balances on chain. There are notes — sealed records of value, token and owner. Only a hash of each note is ever published, appended to an append-only tree.
How the bytes reach Bitcoin
The envelope rides in a taproot script path. One transaction commits to the payload, a second reveals it into the witness — where bytes are discounted four to one and relay under default policy everywhere.
Read a real one
This is an actual E404 mint, confirmed in block 969,163. Open it on any block explorer and check every figure below — the whole point of settling on Bitcoin is that you do not have to take this page's word for it.
190196d1015b3bd5dcd6a272970766a90fa597409b00e1c8d8ed2e302a5274f8
This is how that transaction's Flow diagram renders on a block explorer — the value entering on the left, and nothing coming out on the right.
OP_RETURN, carrying zero. A normal payment would show the band splitting into outputs;
this one has nowhere to split to.
| Field | Value | What it tells you |
|---|---|---|
| Block | 969,163 | Confirmed, not pending |
| Inputs | 1 · taproot · 1,027 sat | One coin, put up by the relayer |
| Witness | 64 B + 981 B + 33 B | Signature, script, control block |
| Envelope | 934 B | Inside the 981-byte script |
| Outputs | 1 · OP_RETURN · 0 sat | Empty marker — the data is not here |
| Fee | 1,027 sat | The whole input; nothing came back |
| Size | 1,156 B raw / 341.5 vB | The witness discount, applied |
| Fee rate | 3.0 sat/vB | An ordinary rate, not a premium |
Four things this transaction proves
- No user coin is anywhere in it. One input, funded by the relayer, entirely consumed as the fee. Nobody's payment, change or address appears — so there is nothing here to link a mint back to the person who paid for it.
-
The data is in the witness, not the OP_RETURN. The single output is an
OP_RETURNholding eight zero bytes and no payload. Anyone claiming this is OP_RETURN stuffing can read the script item and see 934 bytes sitting somewhere else entirely. - The discount is the reason this is affordable. 1,156 raw bytes are billed as 341.5 vB, because witness data counts a quarter. Publishing the same payload outside the witness would cost roughly 3.4× more chain space.
- It reveals nothing about the holder. Amounts, owner and token are sealed inside those 934 bytes. Bitcoin stored them and ordered them; it never looked inside, and neither can anyone reading the chain.
The proof commits to every byte of the envelope. The relayer transmits it but cannot alter a recipient, an amount or a ciphertext — change one byte and the proof stops verifying. Its only power is refusal, which you see immediately.
08 — After the mint
The market
Trading opens when the mint sells out. Until then the book is readable but closed — orders are refused by the node, not merely hidden by the page.
When it opens it is a signed limit order book settled in Bitcoin, with no custody at any point. Orders are intents, not deposits: your coins and your notes stay yours until a trade settles. A trade is two legs between two people — the Bitcoin leg, which the node verifies against the chain, and the shielded leg, which it cannot see and only the receiver can attest to.
That asymmetry is the protocol working, not a gap in it. If the node could verify the shielded leg, the shielded leg would not be private.
09 — Roadmap
What comes after the mint
Two things are built and running: the shielded pool, and the order book that opens when the mint sells out. Two more are intended. They are stated here as direction, not as a promise of delivery or of returns — nothing below is shipped, and dates are not being given.
Launchpad — shielded tokens for anyone
The protocol already carries a deploy operation alongside mint and
transfer: a ticker, a maximum supply and a per-mint limit, published as an envelope like any
other. E404 was issued through exactly that path.
A launchpad is the interface around it — letting anyone deploy a token whose holders and transfers are private by default, without writing an envelope by hand. The consensus rules need no change; this is tooling on top of a capability the pool already has.
Fee sharing — and the problem it has to solve first
The market charges 2% on a trade, and that currently goes to the treasury. The intent is for E404 holders to receive a share of it.
There is an honest difficulty here, and it is worth naming rather than glossing: the protocol cannot see who holds what. That is the entire point of it. A conventional distribution walks a list of holders and pays each one — but there is no such list, no addresses to pay, and no way to snapshot balances without dismantling the privacy that makes the token worth holding.
So it cannot be a payout. The workable shape is a claim: a holder proves in zero knowledge that they held at least some amount at a past anchor, and draws a proportional share — without revealing who they are, what they hold, or which notes were theirs. That is a real circuit to design and audit, not a configuration change.
Neither feature exists today. Nothing here is a promise that E404 will produce income, appreciate, or distribute anything, and no date is being committed to. Anyone deciding what to pay for a lot should price what is running now — a shielded pool and a mint — and treat everything in this section as unbuilt.
10 — Troubleshooting
Common questions
- I paid but nothing happened.
- Payments need three confirmations, roughly 30 minutes. The page shows the count as it climbs. If it shows nothing at all, check you sent the exact amount to the invoice's own address.
- I closed the tab mid-mint.
- Nothing is lost. Reopen the mint page with the same wallet and it picks the unfinished purchase back up. The final proof has to run in your browser, so it resumes when you return.
- I sent the wrong amount.
- Underpaid invoices show how much is still owed — send the difference to the same address before it expires. Overpayments and expired invoices are recoverable; ask before opening a second invoice.
- My transaction is stuck.
- Use speed up on the pending payment in your dashboard. It publishes a replacement paying a higher fee to the same recipient for the same amount; the difference comes out of your change.
- Can I mint from an exchange withdrawal?
- Yes, if the exact amount reaches the invoice address in time. Exchanges are slow and often deduct a fee from the amount sent, so paying from your own wallet is safer.
- I lost my password.
- Restore from your 24 words and set a new one. Without the words, nothing can be recovered — by anyone.
- Does connecting X give anyone access to my wallet?
- No. The sign-in proves which account you control and nothing else. It cannot move funds, and the access token is used for a single lookup and then discarded.
- Why does my balance only appear on one device?
- Because your keys live in that browser, not on a server. Restore the same 24 words elsewhere and the same balance appears.
11 — Limits
What we don't claim
A privacy protocol that oversells itself gets people hurt. These are real and stated plainly.
- The trusted setup is one contribution. A multi-party ceremony has not been run. Whoever held that material could forge proofs. This is the most important open item.
- No third-party audit of the circuit or the settlement logic.
- Ciphertext consistency is not proven in-circuit. A malformed ciphertext is detectable by the receiver but is not constrained by the proof.
- No peg-out. Notes do not convert back to BTC through the protocol. The market is the only exit, and it settles person to person.
- Timing metadata persists. Uniform sizes hide contents, not that you transacted.
Deploy, mint, private transfer, a complete market trade with the fee verified on chain, and a treasury sweep — all executed end to end with real Bitcoin, never on a testnet.