LibraryPrivacy2013Design paperCorpus record
CryptoNote v 2.0
CryptoNote. Nicolas van Saberhagen.
The public design paper behind unlinkable payments. Monero adopted the construction and then replaced pieces of it. The historic library only has a third-party review of CryptoNote, not this document.
The historic library holds a third-party review (whitepaper_review.pdf), not this document.
CryptoNote hides which output was spent by signing as a group, and it stops address reuse by giving every payment a fresh destination key. Amounts stay in the clear.
The five-minute read
The ledger is the leak
Bitcoin publishes amounts between addresses people reuse. Learn one address and you can walk the graph. CryptoNote treats that public graph as the defect, not as a feature to be patched later with a mixer.
A fresh destination every time
The recipient publishes a long-lived pair. The sender derives a one-time public key for this payment only. The chain never has to show the recipient's public address.
The spend is a ring
To spend, the owner signs together with other outputs of the same denomination. The signature is valid for the set. It does not say which member moved.
Double-spends still fail
Each real output has a key image. The network rejects a second use of that image. Privacy of the signer is not the same thing as permission to spend twice.
Amounts are not hidden
Denominations are visible, which is why decoys have to match. Hiding the amount is Ring Confidential Transactions, a later paper. Do not cite this one for that.
One action, walked through
- The recipient holds a spend key and a view key, and publishes the matching public keys.
- The sender derives a one-time destination and includes a small piece of data so the recipient can recognise the output.
- The recipient scans new outputs with the view key. The sender does not learn when the coin is later spent.
- On the spend, the sender picks decoys of the same denomination and produces a ring signature over the set.
- The network checks the signature and that the key image is new. It records the key image, not the identity of the signer.
The argument, unpacked
Unlinkability and untraceability are different jobs
Unlinkability means an observer cannot tell that two payments went to the same person. Untraceability means an observer cannot tell which input in a set was the real one. The paper specifies both, with different tools. A product that does only one of them has not implemented this design.
A mixer is an admission that the format is public
A mixer takes already-published coins and tries to scramble them in a side room. CryptoNote puts the ambiguity in the signature itself, so there is no operator holding the pool. That is why the paper is hostile to optional privacy. Optional privacy marks the people who used it.
Denominations are a privacy tax
If amounts differ, a ring of mixed amounts is useless, because the amount gives the real input away. The paper therefore works in denominations. That choice leaks the amount and forces the chain to keep enough decoys in each bucket. Later confidential amounts exist because this leak was real.
What has to be true
- There are enough genuine outputs of the same denomination to fill a ring. An empty bucket has no privacy.
- Users receive payments to one-time keys. Publishing a reused address on a website undoes unlinkability for those receipts.
- The ring signature scheme is sound, and the key image is bound to the real output so a double-spend is detectable.
- Decoy selection is not so naive that the real input is obvious from timing or from how the decoys were chosen. The paper does not settle that implementation question.
What happened after the paper
Monero adopted the construction and then replaced pieces of it. Amounts moved into Ring Confidential Transactions. Ring size stopped being a small user choice and became a protocol parameter. The original ring signature was replaced. A 2013 reading does not describe today's Monero chain, and a third-party review in the historic library is not this text.
What to check before you use the idea
- Are amounts still public, and if not, which later paper hides them?
- Who chooses the decoys, and what is the fixed ring size?
- Is there a view key, and which party is expected to hold it?
- What is the double-spend token, and is it stored forever?
Terms
- One-time key
- A destination derived for a single payment, so the recipient's long-lived address does not appear on the ledger.
- Ring signature
- A signature that proves one member of a named set signed, without revealing which member.
- Key image
- A unique marker of an output, published on spend, that blocks a second spend without naming the output.
- Unlinkability
- The property that two incoming payments cannot be tied to the same recipient from the ledger alone.
The problem the paper names
Bitcoin's ledger is a public list of amounts between reusable addresses. Anyone who learns one address can walk the graph. CryptoNote treats that traceability as the defect to design against, not as a feature to be patched with mixers after the fact.
What the design proposes
- One-time destination keys so a payment address is not reused on the ledger.
- Ring signatures so a spend is signed by a set, and the real signer is not revealed.
- Untraceable transactions as a protocol property, rather than an optional mixer.
How the mechanism is specified
- A sender takes their own output and mixes it, inside the signature, with other outputs of the same denomination drawn from the chain.
- The recipient detects the payment with a private view key without the sender learning when it is spent.
- Double-spends are still rejected because each output can be consumed only once, even though the spender is hidden inside the ring.
What this page does not treat as proven
- The paper does not establish the privacy of any later coin. Ring size, decoy selection and implementation bugs decide that.
- It does not hide amounts. Monero's later RingCT work is a different paper.
- The historic file whitepaper_review.pdf is a commentary, not this text.
Why a venture studio still reads it
Useful when a venture claims 'private payments' but still plans to publish amounts and reusable addresses. CryptoNote's bar is specific: unlinkability has to be in the transaction format.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
