LibraryPrivacy2015Design paperCorpus record
Confidential Transactions
Confidential Transactions. Gregory Maxwell.
Hide the amounts on a Bitcoin-style transaction with Pedersen commitments, and use range proofs so a commitment cannot stand for a negative number. The graph of who paid whom stays visible.
Confidential Transactions hide amounts inside Pedersen commitments and prove the amounts are in range, so the ledger can check that inputs still equal outputs without learning the numbers.
The five-minute read
Only the amount is hidden
The note does not hide the graph of outputs. An observer can still see that this input was spent to those outputs. They cannot see how much moved, apart from a public fee if there is one.
Commitments must balance
Pedersen commitments add. The verifier checks that output commitments sum to input commitments. A mismatch is an inflation bug. A match reveals no values.
Range proofs stop the underflow
A commitment to a negative output would mint value and still balance. The range proof is what makes the hiding safe. Omit it and the scheme is broken.
Later systems split the idea
Liquid used confidential amounts on a Bitcoin-like graph. Monero's RingCT combined the commitments with ring signatures. Neither deployment is the 2015 note.
One action, walked through
- The sender picks amounts and random blinds, and publishes a commitment for each output.
- A range proof is attached so each committed amount is in a permitted interval.
- The sender proves they know the openings of the inputs they are spending.
- Nodes check the proofs and the homomorphic balance.
- The recipient, who knows the blind and the amount, can later spend the output. The network never needed the amount in the clear.
The argument, unpacked
Hiding and binding are different
Hiding means the observer does not learn the amount. Binding means the sender cannot open the same commitment to two amounts. A scheme that is only hiding is an inflation bug waiting for a second opening.
Privacy marketing collapses three papers
CryptoNote hides the signer among decoys and leaves amounts public. Zerocash hides more of the graph. Confidential Transactions hide the number. A white paper that says privacy without saying which of the three is not yet a design.
What has to be true
- The discrete logarithm problem is hard in the group used for the commitments.
- Range proofs are sound. A forged range proof is a licence to print.
- Blinding factors are actually secret. A reused or leaked blind reveals the amount.
- Fees, if public, are accounted for in the balance equation. Forgetting the fee breaks conservation.
What happened after the paper
Bulletproofs replaced the bulky range proofs this note relied on. Liquid shipped confidential amounts. RingCT took the commitment into a ring. The 2015 design remains the right citation for amount hiding on a visible graph, and the wrong citation for unlinkability.
What to check before you use the idea
- Are amounts hidden, or only counterparties?
- Is there a range proof on every committed value?
- Does the balance equation include the fee?
- Which later proof system compresses the range proof?
Terms
- Pedersen commitment
- A commitment to a number that can be added to other commitments without opening them.
- Range proof
- A proof that the hidden number sits between two bounds, so it cannot be negative or absurd.
The problem the paper names
A public amount lets an observer price a payment, target a wallet, and match deposits. Maxwell's note hides the number while still letting the network check that inputs and outputs balance.
What the design proposes
- Commit to each amount. Publish the commitment, not the amount.
- Homomorphism: the commitments of the outputs should sum to the inputs, plus an explicit fee if the fee is public.
- A range proof stops a commitment to a huge number that underflows.
How the mechanism is specified
- Pedersen commitments are binding and hiding under the discrete-log assumption. The binding is what stops you changing the amount later.
- The verifier checks a linear relation on commitments. It never learns the values if the proofs are honest.
- Addresses and the transaction graph are still on the page. This paper is not CryptoNote and not Zerocash.
What this page does not treat as proven
- Hiding amounts does not hide counterparties.
- Range proofs in the original form are large. Bulletproofs are a later compression.
- Liquid and RingCT borrowed the idea. Neither is this note.
Why a venture studio still reads it
If a product says confidential, ask whether the amount, the sender, or the recipient is hidden. This paper answers only the first.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
