protocol // v0
How it stays dark
Hidden
- ■Sender
- ■Receiver
- ■Amount
- ■Which token (in private transfers)
- ■Which note was spent
- ■Who paid the Bitcoin fee
Public
- □That an envelope was published, and when
- □Its size (always 921 bytes for a transfer)
- □Minting into the pool: ticker and amount (not who received it)
- □Token deploys: ticker, max supply, per-mint limit
- □The relayer's own Bitcoin transactions
The mechanism
- 01 NotesA balance is a set of notes: “this key owns v of token t”. Only a hash of each note (its commitment) is published, as a leaf in a Merkle tree.
- 02 NullifiersSpending a note publishes its nullifier, a tag only the owner can compute: H(nf_key, rho, position). Reusing one is impossible, and it can't be linked back to the note.
- 03 ProofEvery envelope carries a Groth16 proof: the spent notes are in the tree at a recent block, you own them, the nullifiers are right, and value in equals value out. Nothing else is revealed.
- 04 EncryptionNew notes are encrypted to the receiver (ECDH to their address key → HKDF → ChaCha20-Poly1305). Wallets scan every leaf and keep what they can open.
- 05 BitcoinBitcoin only stores and orders the envelopes, carried in a taproot witness. No soft fork, no sidechain, no bridge.
- 06 ReplayIndexers replay envelopes in block order with fixed rules. Any two honest indexers reach the same state; anyone can run one.
Against the Shielded Bitcoin paper
| Notes (v, d, r_seed), rho = H(r_seed), sk_eph = H_eph(r_seed) | as in the paper |
| Nullifier bound to tree position | as in the paper |
| Anchor = block height, window W = 100, K_min = 1 | as in the paper |
| h_body binds the whole envelope as a public input | as in the paper |
| Replay order: parse → h_body → anchor → nullifiers → proof → atomic update | as in the paper |
| Keys: sk_spend → nf_key, vk_in → sk_view; vk_out from sk_master | as in the paper |
| Diversified addresses (d, pk_d = sk_view·G_d) | as in the paper, plus an owner tag the circuit checks |
| Sender recovery: one batched AEAD under vk_out | as in the paper |
| Fixed arity 2 → 2 with padding | paper's recommended future standard |
| Relayer pays fees (no fee wallet to cluster) | paper's fee-vault direction |
| Leaf = note commitment (not H(…, ciphertext)) | simplified: ciphertext correctness is not proven in-circuit |
| Poseidon / BN254 / Groth16 | circuit-friendly choices for the paper's generic H |
| Tokens instead of BTC | no peg-in/out needed: the indexer defines supply |
Known limits
- ▸ The proving key has a single setup contribution. Until a multi-party ceremony replaces it, whoever ran it could forge proofs.
- ▸ The circuit has not been externally audited.
- ▸ Ciphertext correctness is not proven in-circuit, so a malformed note would be unspendable for the receiver.
- ▸ E404 is not redeemable for BTC. There is no peg-out; it exits by sale.
- ▸ The relayer sees your IP when you submit. Tor and more relayers come later.
- ▸ Privacy grows with the pool: minting is public, so move value around before relying on it.