← app.e404.site

Handbook · shielded notes on Bitcoin L1

How to mint E404

E404 is a shielded token whose entire state is derived from data published in Bitcoin blocks. This is the complete guide: what it is, how the mint works step by step, and what the chain does and does not reveal about you.

Lot size
10,000E404 per lot
Approved rate
0.00001BTC per lot
Open rate
0.00003BTC per lot
Max supply
210M5M per mint cap

If you only read one box

  1. Create a wallet on app.e404.site and write the 24 words down offline.
  2. Approved? Connect X on the mint page to claim the lower rate.
  3. Send BTC to your own bc1q address, plus a little for the network fee.
  4. Choose your lots, open an invoice, pay from the wallet.
  5. Wait three confirmations. Minting then starts on its own — keep the tab open.

Check whether you were approved at e404.site/check before the mint opens.

Contents
  1. 01 What E404 is
  2. 02 Rates & caps
  3. 03 The mint, end to end
  4. 04 Step by step
  5. 05 Approved rate
  6. 06 What is public
  7. 07 How it works
  8. 08 After the mint
  9. 09 Roadmap
  10. 10 Troubleshooting
  11. 11 Limits

01 — Premise

A private ledger that settles on Bitcoin

Every ordinary Bitcoin transaction is a permanent public record of who paid whom and how much. E404 keeps the settlement and drops the disclosure: value moves as encrypted notes carried inside ordinary Bitcoin transactions, proven correct by zero-knowledge proofs.

No soft fork, no sidechain, no bridge, no custodian. Bitcoin orders and timestamps the bytes; it never validates them and is never asked to. Meaning is assigned by anyone who replays those bytes under the same rules — which is why two independent indexers reading the same chain reach identical state.

What this means for you

Nobody can see your balance, who you paid, or how much — not other users, not the node, not anyone reading the Bitcoin chain. Your keys never leave your browser.

02 — Rates & caps

What a lot costs

E404 is minted in lots of 10,000. There are two prices: approved applicants pay a third of the open rate.

TierPer lotYour capMax spend
Approved 0.00001 BTC 100 lots · 1,000,000 E404 0.001 BTC
Open 0.00003 BTC 500 lots · 5,000,000 E404 0.015 BTC

Caps are per wallet and counted across every invoice you open. Total supply is 210,000,000 E404, with a protocol limit of 5,000,000 per single mint.

Approved is a price, not a guarantee

Being on the approved list lowers what you pay. It does not reserve supply. Minting is first come, first served until the supply is gone.

03 — The mint, end to end

What actually happens

Five stages. You do three of them; the node and your own browser do the rest.

YOU NODE BITCOIN 1 · create wallet 24 words 2 · fund it send BTC to bc1q… 3 · pay invoice one click 5 · prove in browser automatic one-time address per invoice 4 · 3 confirmations ≈ 30 minutes pays unlocks relayer publishes the envelope · pays the fee 934 bytes in a taproot witness proof E404 in your wallet only you can read it
You create a wallet, fund it and pay. Everything after the third confirmation happens on its own — the proof is built in your browser, and the relayer pays the Bitcoin fee so none of your coins ever sit in the same transaction as your envelope.

04 — Step by step

Minting, in order

  1. 01

    Create a wallet on the site

    Open the app and choose Create wallet. You get 24 words and set a password. One seed produces both halves: your shielded balance and an ordinary Bitcoin bc1q address.

    There is no extension to install and no third-party wallet to connect. The seed is encrypted on your device; the password is never transmitted.

  2. 02

    Write down the 24 words, offline

    They are the only way to recover the wallet, and they restore both your Bitcoin and your shielded balance. Your password cannot be reset and nobody can recover it for you.

  3. 03

    Claim your rate, if you are approved

    On the mint page, choose Connect X. If that account is on the approved list, the wallet you are holding at that moment is bound to it and you pay the approved rate. The approval follows the account, not the address you applied with — so a brand-new wallet is fine.

  4. 04

    Fund your Bitcoin address

    Copy the bc1q address from your dashboard and send BTC to it. Send a little more than the mint costs so there is room for the network fee.

    Your deposit shows its progress as it confirms: seen, then buried block by block.

  5. 05

    Choose how much, and open an invoice

    Pick the number of lots. The page shows the total in BTC and dollars before you commit. Opening an invoice reserves a one-time deposit address that belongs to that invoice alone — which is how the node knows the payment was yours.

    An invoice stays open for 60 minutes.

  6. 06

    Pay

    Press Pay from your wallet and it builds, signs and broadcasts in one step. You can also send the exact amount from anywhere else to the address shown — but it must be the exact amount, to that address, before the invoice expires.

  7. 07

    Wait for three confirmations

    Roughly 30 minutes. The page shows the count as it climbs. Three blocks is the point at which a payment is settled rather than merely seen — a transaction still in the mempool can be replaced.

  8. 08

    Minting starts by itself

    There is no button. The moment the payment settles, your browser builds the zero-knowledge proof and hands the envelope to the relayer, which publishes it to Bitcoin and pays the fee.

    Your E404 appears in your dashboard once the envelope is in a block.

Keep the tab open while it finishes

The proof is built in your browser — that is what stops the relayer ever holding your keys — so the final step needs the page open. If you close it, nothing is lost: reopen the mint page with the same wallet and it picks the unfinished purchase back up.

05 — Approved rate

How the approved list works

Applications were made with a verified X account, so the X account — not a wallet address — is the durable identity. Proving the account is the whole check.

your X account on the approved list sign in binding one account · one wallet neither can be multiplied the wallet you hold new one is fine prices 0.00001 BTC instead of 0.00003
One X account binds to one wallet, and the address is uniquely indexed — so a single account cannot whitelist many wallets, and many accounts cannot pile onto one wallet to multiply an allocation.

You can check whether you were approved before the mint opens, from the application site's eligibility page. It shows your card and the answer; looking changes nothing.

06 — What is public

Exactly what the chain reveals

A mint is the one moment value enters the pool, so the amount and ticker are public — supply has to be auditable. After that, nothing about your holdings or transfers is.

Visible to everyone

  • That an envelope occurred, and when
  • Its size in bytes
  • Opaque nullifiers and commitments
  • Mint amounts and ticker

Never revealed

  • Who owns a note
  • Your balance, at any time
  • Sender and receiver of a transfer
  • The amount transferred
  • Which token moved
  • Which earlier note was spent

Uniform size does the rest: every transfer is exactly 921 bytes, so length never leaks what happened. A mint is 934, because it carries the ticker and amount.

What still leaks

Timing. The chain shows that somebody published an envelope at a given moment. Uniform sizes hide the contents, not the fact that a transaction happened or when.

07 — How it works

Notes, nullifiers and the carrier

There are no accounts and no balances on chain. There are notes — sealed records of value, token and owner. Only a hash of each note is ever published, appended to an append-only tree.

note · private value · token · owner hashed commitment a leaf on the tree public the shielded pool every proof references a recent root your balance is computed in your browser nullifier published when spent + your key unlinkable to the leaf
The commitment enters the pool; the nullifier retires it. Nothing on chain connects the two — only your key derives one from the other, which is how double-spending is prevented without revealing which note was spent.

How the bytes reach Bitcoin

The envelope rides in a taproot script path. One transaction commits to the payload, a second reveals it into the witness — where bytes are discounted four to one and relay under default policy everywhere.

commit funds a taproot output spent by reveal · the witness 934 bytes of envelope discounted 4× as witness data a Bitcoin block ordered, timestamped, never validated
The relayer funds and broadcasts both transactions from its own coins. That is what keeps your Bitcoin out of the same transaction as your envelope — the link the rest of the protocol works to cut.

Read a real one

This is an actual E404 mint, confirmed in block 969,163. Open it on any block explorer and check every figure below — the whole point of settling on Bitcoin is that you do not have to take this page's word for it.

190196d1015b3bd5dcd6a272970766a90fa597409b00e1c8d8ed2e302a5274f8

INPUT 1 taproot input 1,027 sat funded by the relayer reveals WITNESS — 1,086 B, charged at a quarter rate signature 64 B tapscript · 981 B the 934-byte envelope 86% of everything in this transaction control block 33 B OUTPUT OP_RETURN · 0 sat 8 zero bytes — carries nothing WHERE THE MONEY WENT 1,027 sat in, 0 sat out — the entire input became the miner fee no change, no recipient, not one satoshi of user money in this transaction SIZE 1,156 raw bytes · 70 of them outside the witness billed as 341.5 vB — 3.4× less chain space than its raw size
Every number here is read from the confirmed transaction, not illustrative. The envelope is 86% of the bytes and sits entirely in the witness, which Bitcoin charges at a quarter rate.

This is how that transaction's Flow diagram renders on a block explorer — the value entering on the left, and nothing coming out on the right.

Block explorer flow diagram: one input band enters from the left, narrows across the width, and terminates with no recipient; a small marker at the lower right is the zero-value OP_RETURN output.
The band is the entire 1,027 sat input. It narrows to nothing because there is no recipient and no change — every satoshi became the miner fee. The small marker at the lower right is the OP_RETURN, carrying zero. A normal payment would show the band splitting into outputs; this one has nowhere to split to.
FieldValueWhat it tells you
Block969,163Confirmed, not pending
Inputs1 · taproot · 1,027 satOne coin, put up by the relayer
Witness64 B + 981 B + 33 BSignature, script, control block
Envelope934 BInside the 981-byte script
Outputs1 · OP_RETURN · 0 satEmpty marker — the data is not here
Fee1,027 satThe whole input; nothing came back
Size1,156 B raw / 341.5 vBThe witness discount, applied
Fee rate3.0 sat/vBAn ordinary rate, not a premium

Four things this transaction proves

  • No user coin is anywhere in it. One input, funded by the relayer, entirely consumed as the fee. Nobody's payment, change or address appears — so there is nothing here to link a mint back to the person who paid for it.
  • The data is in the witness, not the OP_RETURN. The single output is an OP_RETURN holding eight zero bytes and no payload. Anyone claiming this is OP_RETURN stuffing can read the script item and see 934 bytes sitting somewhere else entirely.
  • The discount is the reason this is affordable. 1,156 raw bytes are billed as 341.5 vB, because witness data counts a quarter. Publishing the same payload outside the witness would cost roughly 3.4× more chain space.
  • It reveals nothing about the holder. Amounts, owner and token are sealed inside those 934 bytes. Bitcoin stored them and ordered them; it never looked inside, and neither can anyone reading the chain.
Why a relayer is safe to use

The proof commits to every byte of the envelope. The relayer transmits it but cannot alter a recipient, an amount or a ciphertext — change one byte and the proof stops verifying. Its only power is refusal, which you see immediately.

08 — After the mint

The market

Trading opens when the mint sells out. Until then the book is readable but closed — orders are refused by the node, not merely hidden by the page.

When it opens it is a signed limit order book settled in Bitcoin, with no custody at any point. Orders are intents, not deposits: your coins and your notes stay yours until a trade settles. A trade is two legs between two people — the Bitcoin leg, which the node verifies against the chain, and the shielded leg, which it cannot see and only the receiver can attest to.

That asymmetry is the protocol working, not a gap in it. If the node could verify the shielded leg, the shielded leg would not be private.

09 — Roadmap

What comes after the mint

Two things are built and running: the shielded pool, and the order book that opens when the mint sells out. Two more are intended. They are stated here as direction, not as a promise of delivery or of returns — nothing below is shipped, and dates are not being given.

pool + mint live on mainnet order book opens at sellout launchpad intended fee sharing intended · unsolved fee sharing has nothing to share until the book has volume SHIPPED NOT BUILT
The dependency is the point: fee sharing is downstream of a market that trades. Building it first would distribute nothing.

Launchpad — shielded tokens for anyone

The protocol already carries a deploy operation alongside mint and transfer: a ticker, a maximum supply and a per-mint limit, published as an envelope like any other. E404 was issued through exactly that path.

A launchpad is the interface around it — letting anyone deploy a token whose holders and transfers are private by default, without writing an envelope by hand. The consensus rules need no change; this is tooling on top of a capability the pool already has.

Fee sharing — and the problem it has to solve first

The market charges 2% on a trade, and that currently goes to the treasury. The intent is for E404 holders to receive a share of it.

There is an honest difficulty here, and it is worth naming rather than glossing: the protocol cannot see who holds what. That is the entire point of it. A conventional distribution walks a list of holders and pays each one — but there is no such list, no addresses to pay, and no way to snapshot balances without dismantling the privacy that makes the token worth holding.

So it cannot be a payout. The workable shape is a claim: a holder proves in zero knowledge that they held at least some amount at a past anchor, and draws a proportional share — without revealing who they are, what they hold, or which notes were theirs. That is a real circuit to design and audit, not a configuration change.

Read this as intent, not as a return

Neither feature exists today. Nothing here is a promise that E404 will produce income, appreciate, or distribute anything, and no date is being committed to. Anyone deciding what to pay for a lot should price what is running now — a shielded pool and a mint — and treat everything in this section as unbuilt.

10 — Troubleshooting

Common questions

I paid but nothing happened.
Payments need three confirmations, roughly 30 minutes. The page shows the count as it climbs. If it shows nothing at all, check you sent the exact amount to the invoice's own address.
I closed the tab mid-mint.
Nothing is lost. Reopen the mint page with the same wallet and it picks the unfinished purchase back up. The final proof has to run in your browser, so it resumes when you return.
I sent the wrong amount.
Underpaid invoices show how much is still owed — send the difference to the same address before it expires. Overpayments and expired invoices are recoverable; ask before opening a second invoice.
My transaction is stuck.
Use speed up on the pending payment in your dashboard. It publishes a replacement paying a higher fee to the same recipient for the same amount; the difference comes out of your change.
Can I mint from an exchange withdrawal?
Yes, if the exact amount reaches the invoice address in time. Exchanges are slow and often deduct a fee from the amount sent, so paying from your own wallet is safer.
I lost my password.
Restore from your 24 words and set a new one. Without the words, nothing can be recovered — by anyone.
Does connecting X give anyone access to my wallet?
No. The sign-in proves which account you control and nothing else. It cannot move funds, and the access token is used for a single lookup and then discarded.
Why does my balance only appear on one device?
Because your keys live in that browser, not on a server. Restore the same 24 words elsewhere and the same balance appears.

11 — Limits

What we don't claim

A privacy protocol that oversells itself gets people hurt. These are real and stated plainly.

  • The trusted setup is one contribution. A multi-party ceremony has not been run. Whoever held that material could forge proofs. This is the most important open item.
  • No third-party audit of the circuit or the settlement logic.
  • Ciphertext consistency is not proven in-circuit. A malformed ciphertext is detectable by the receiver but is not constrained by the proof.
  • No peg-out. Notes do not convert back to BTC through the protocol. The market is the only exit, and it settles person to person.
  • Timing metadata persists. Uniform sizes hide contents, not that you transacted.
Already proven on mainnet

Deploy, mint, private transfer, a complete market trade with the fee verified on chain, and a treasury sweep — all executed end to end with real Bitcoin, never on a testnet.