LibraryPrivacy2018Design paperCorpus record
Confidential Assets
Range proofs. Andrew Poelstra, Adam Back, Mark Friedenbach, Gregory Maxwell and Pieter Wuille.
Confidential assets put an asset tag beside a Pedersen commitment so a transaction can balance in several assets without publishing which output is which asset or how much.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
A privacy coin that hides the amount and still prints the asset name has done half of this design.
The five-minute read
The defect
Confidential transactions hide amounts. They do not, by themselves, say what asset moved.
The rule
Confidential assets put an asset tag beside a Pedersen commitment so a transaction can balance in several assets without publishing which output is which asset or how much.
How it is put together
A commitment binds an amount and blinds it. An asset tag is a separate generator. The balance equation has to hold per asset, in the group, without opening the commitments.
Where the claim stops
The paper is not deployed bitcoin.
One action, walked through
- Spend outputs by revealing the blinding factors only to the people who must see them.
- The network checks the homomorphic sum is zero.
- A range proof stops a negative amount from creating value.
- Does the balance equation hide the asset or only the amount?
The argument, unpacked
Why it is still on the desk
A privacy coin that hides the amount and still prints the asset name has done half of this design.
After the text
Liquid and later confidential-asset chains cite this construction. Bitcoin mainnet did not adopt it.
What has to be true
- The paper is not deployed bitcoin.
- It does not hide the transaction graph.
- Asset tags and amount commitments solve different leaks.
What happened after the paper
Liquid and later confidential-asset chains cite this construction. Bitcoin mainnet did not adopt it.
What to check before you use the idea
- Does the balance equation hide the asset or only the amount?
- Who can open the commitment?
- What stops a negative value?
Terms
- Asset tag
- A group element that marks which asset a commitment is about.
- Pedersen commitment
- A commitment that adds, so amounts can be checked without being shown.
The problem the paper names
Confidential transactions hide amounts. They do not, by themselves, say what asset moved.
What the design proposes
- A commitment binds an amount and blinds it.
- An asset tag is a separate generator.
- The balance equation has to hold per asset, in the group, without opening the commitments.
How the mechanism is specified
- Spend outputs by revealing the blinding factors only to the people who must see them.
- The network checks the homomorphic sum is zero.
- A range proof stops a negative amount from creating value.
What this page does not treat as proven
- The paper is not deployed bitcoin.
- It does not hide the transaction graph.
- Asset tags and amount commitments solve different leaks.
Why a venture studio still reads it
A privacy coin that hides the amount and still prints the asset name has done half of this design.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
