LibraryPrivacy2019Design paperCorpus record
Ouroboros Crypsinous: Privacy-Preserving Proof-of-Stake
Ouroboros Crypsinous. Thomas Kerber, Aggelos Kiayias, Markulf Kohlweiss and Vassilis Zikas.
Crypsinous combines a stake lottery with a private transaction ledger so the leader proof and the transfers do not reveal the stake and the amounts in the way a public chain does.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
A private stake chain has to answer two questions this paper separates: who can extend the chain, and what the payment revealed.
The five-minute read
The defect
A stake chain publishes who was eligible to produce a block if the leader election is a public function of the stake.
The proposal
Crypsinous combines a stake lottery with a private transaction ledger so the leader proof and the transfers do not reveal the stake and the amounts in the way a public chain does.
Leader privacy and transaction privacy are different leaks.
The construction uses zero-knowledge proofs over the stake and the coins.
The bound
This is not Cardano's deployed privacy and not a mixing instruction.
One action, walked through
- A party proves it won the slot without showing the stake in public.
- A transfer is a private state update with a proof.
- The ledger rules still have to reject a double-spend.
- Are amounts hidden?
The argument, unpacked
What the paper is for
A private stake chain has to answer two questions this paper separates: who can extend the chain, and what the payment revealed.
What happened after
Deployed stake chains mostly kept public leader schedules. That is a refusal of this property, not an implementation of it.
What has to be true
- This is not Cardano's deployed privacy and not a mixing instruction.
- The proofs are only as strong as the relation.
- Leader privacy fails if the implementation publishes the key anyway.
What happened after the paper
Deployed stake chains mostly kept public leader schedules. That is a refusal of this property, not an implementation of it.
What to check before you use the idea
- Is the slot leader hidden?
- Are amounts hidden?
- What is still public in the block header?
Terms
- Leader privacy
- An observer cannot tell who was eligible from the block alone.
- Private ledger
- Transfers that do not publish amounts and identities.
The problem the paper names
A stake chain publishes who was eligible to produce a block if the leader election is a public function of the stake.
What the design proposes
- Leader privacy and transaction privacy are different leaks.
- The construction uses zero-knowledge proofs over the stake and the coins.
- It is a protocol paper, not a wallet.
How the mechanism is specified
- A party proves it won the slot without showing the stake in public.
- A transfer is a private state update with a proof.
- The ledger rules still have to reject a double-spend.
What this page does not treat as proven
- This is not Cardano's deployed privacy and not a mixing instruction.
- The proofs are only as strong as the relation.
- Leader privacy fails if the implementation publishes the key anyway.
Why a venture studio still reads it
A private stake chain has to answer two questions this paper separates: who can extend the chain, and what the payment revealed.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
