E404

protocol // v0

How it stays dark

Hidden

  • ■Sender
  • ■Receiver
  • ■Amount
  • ■Which token (in private transfers)
  • ■Which note was spent
  • ■Who paid the Bitcoin fee

Public

  • □That an envelope was published, and when
  • □Its size (always 921 bytes for a transfer)
  • □Minting into the pool: ticker and amount (not who received it)
  • □Token deploys: ticker, max supply, per-mint limit
  • □The relayer's own Bitcoin transactions

The mechanism

  1. 01 NotesA balance is a set of notes: “this key owns v of token t”. Only a hash of each note (its commitment) is published, as a leaf in a Merkle tree.
  2. 02 NullifiersSpending a note publishes its nullifier, a tag only the owner can compute: H(nf_key, rho, position). Reusing one is impossible, and it can't be linked back to the note.
  3. 03 ProofEvery envelope carries a Groth16 proof: the spent notes are in the tree at a recent block, you own them, the nullifiers are right, and value in equals value out. Nothing else is revealed.
  4. 04 EncryptionNew notes are encrypted to the receiver (ECDH to their address key → HKDF → ChaCha20-Poly1305). Wallets scan every leaf and keep what they can open.
  5. 05 BitcoinBitcoin only stores and orders the envelopes, carried in a taproot witness. No soft fork, no sidechain, no bridge.
  6. 06 ReplayIndexers replay envelopes in block order with fixed rules. Any two honest indexers reach the same state; anyone can run one.

Against the Shielded Bitcoin paper

Notes (v, d, r_seed), rho = H(r_seed), sk_eph = H_eph(r_seed)as in the paper
Nullifier bound to tree positionas in the paper
Anchor = block height, window W = 100, K_min = 1as in the paper
h_body binds the whole envelope as a public inputas in the paper
Replay order: parse → h_body → anchor → nullifiers → proof → atomic updateas in the paper
Keys: sk_spend → nf_key, vk_in → sk_view; vk_out from sk_masteras in the paper
Diversified addresses (d, pk_d = sk_view·G_d)as in the paper, plus an owner tag the circuit checks
Sender recovery: one batched AEAD under vk_outas in the paper
Fixed arity 2 → 2 with paddingpaper's recommended future standard
Relayer pays fees (no fee wallet to cluster)paper's fee-vault direction
Leaf = note commitment (not H(…, ciphertext))simplified: ciphertext correctness is not proven in-circuit
Poseidon / BN254 / Groth16circuit-friendly choices for the paper's generic H
Tokens instead of BTCno peg-in/out needed: the indexer defines supply

Known limits