zipcoin Source

How it works

Privacy

How a shared pool and a zero-knowledge proof keep who paid private, and where the limits are.

How zipping works

Only Gladias and the restaurant knew that a 10.5 zipcoin order had been made.

Snowmoon, chapter 6

On a public blockchain, every payment is normally visible to everyone, forever. Zipcoin gets the novel's privacy by letting everyone share one pool, so a payment can prove it's backed by real coins without saying whose.

  1. Zip

    You move ZC into one shared pool. The deposit itself is public, like walking into a crowded square: people see you arrive.

  2. Join the crowd

    Inside, your coins become a note among everyone else's. Each note is a secret only its owner holds.

  3. Spend with a proof

    To pay, your wallet makes a zero-knowledge proof, a short piece of math that shows you own some note in the pool without saying which. The amount is public; who paid is not.

  4. The merchant and the tax are paid

    One proof pays the shop and the sales tax at once. The tax splits on the spot: part is burned, part pays the couriers, the rest goes to a treasury.

Why a bigger crowd hides everyone

A proof says, in effect, β€œone of these notes is mine.” In a pool of ten notes, that narrows it to ten people. In a pool of ten thousand, it narrows it to almost nothing.

That's why every feature here spends from the same single pool. Every meal, send, burn and vote makes the crowd bigger, and hides everyone else a little better.

The postman

A shared pool shouldn't become a hiding place for stolen money. So new deposits wait for the postman, a service that screens them and publishes the list of approved deposits on a fixed schedule. When you spend, your proof also shows that your note is on that list.

The postman can't take anyone's coins. If it never approves a deposit, the owner can always withdraw it publicly. That's called a ragequit.

Our pool: 0xbow Privacy Pools, tuned for ZC

Zipcoin runs its own instance of 0xbow's Privacy Pools. Its privacy comes from that design: zero-knowledge proofs, association sets (the postman's list of approved deposits) and ragequit. 0xbow's contracts are open source, and 0xbow publishes audit reports for its upstream contracts and circuits.

We add one deliberately small extension. ZC pays its holders rewards in ETH, and ZC sitting in an ordinary privacy pool would leave those rewards unclaimed for good. Our pool can claim them, anyone can trigger the claim, and the ETH goes straight to the project treasury (a multisig). The extension never touches deposits, balances or the anonymity set: the pool's accounting is unchanged.

The pool's notes stay where they are, while the ETH that ZC pays the pool travels out to the project treasury. the pool, unchangedtreasuryETH