Skip to content

LibraryPrivacy2020Design paperCorpus record

Semaphore: Zero-Knowledge Signaling on Ethereum

Semaphore. Kobi Gurkan, Koh Wei Jie and Barry Whitehat.

A member of a group proves they are some member, and posts a signal, without showing which member. A nullifier stops the same member signalling twice in the same context. The 2020 proposal is a base layer for voting and similar uses. It is not itself a mixer, and later versions changed the circuits.

Semaphore lets a member of a group post a signal without revealing which member they are. A nullifier, tied to an external value the application chooses, stops the same member signalling twice in that context. The 2020 proposal is a base layer. It is not a mixer, and a group is only as meaningful as the process that admitted its members.

The five-minute read

Membership, not identity

The proof shows the signer knows a secret whose commitment is in the group. It does not show which commitment. Eligibility and identity are separated on purpose.

The nullifier is the double-signal lock

The same identity and the same external nullifier always produce the same nullifier. The contract rejects a repeat. A new external nullifier is a new ballot, or a new context.

The group is an input

If an attacker can insert commitments, the attacker is a member. Zero knowledge does not repair admission.

Applications are above this layer

The proposal discusses voting, reporting and mixers as things that could use the primitive. This reading stops at the primitive. It is not a design for hiding a transfer.

One action, walked through

  1. A user generates an identity and the group stores a commitment.
  2. The user later proves membership and publishes a signal plus a nullifier.
  3. The verifier checks the proof against the current group and the external nullifier.
  4. A second proof with the same nullifier is rejected.
  5. Changing the external nullifier starts a fresh context, which may be what the application wants for a new round.

The argument, unpacked

Version the circuits

Semaphore's later deployments replaced trusted setups, trees and proof systems. The 2020 PDF is the origin of the signalling shape. It is not an audit of a current contract.

Anonymity is inside the group

The set that protects the user is the set of members. A group of three is a group of three. The paper cannot enlarge it.

What has to be true

  • Admission to the group matches the application's intent. The proof will not check a passport, a payment, or a person.
  • The external nullifier is chosen by the application and is not reused across contexts that were meant to be separate, or separated when they were meant to be linked.
  • The verifier uses the group root the prover used. A stale root is a different group.
  • Later circuit changes are out of scope unless named.

What happened after the paper

Semaphore is the citation for 'signal as a member, once per context' on Ethereum. Zerocoin is the earlier coin-shaped version of commitment, nullifier and membership. Do not describe either one as a complete privacy policy for an organisation.

What to check before you use the idea

  • Who can insert a member?
  • What is the external nullifier for this application?
  • How large is the group at the moment of the signal?
  • Which Semaphore version is deployed, versus this 2020 proposal?

Terms

External nullifier
An application-chosen value that, together with the identity, fixes the nullifier and therefore the context in which a member may signal only once.
Signal
The message a member publishes alongside the membership proof. The proof does not vouch for the message being true.

The problem the paper names

A public vote shows who voted. A fully anonymous post can be stuffed by outsiders. Semaphore wants the middle: eligibility without identity, and a way to limit one person to one signal.

What the design proposes

  • An identity is a secret. The group holds a commitment to it.
  • A signal is accompanied by a proof of membership and a nullifier derived from the identity and an external nullifier.
  • The same nullifier cannot be used twice. A different external nullifier is a different context.

How the mechanism is specified

  • The proof is zero knowledge about which commitment was used. The group still learns that the signal came from a member.
  • The external nullifier is how an application defines 'once'. A vote and a second vote are separated by that choice, not by the user's name.
  • The proposal lists mixers and anonymous organisations as applications that could be built on top. Listing them is not building them.

What this page does not treat as proven

  • Membership is only as honest as the process that added the commitment. A group of sock puppets proves nothing about people.
  • The 2020 circuits are not the later Semaphore deployments. Cite the version you mean.
  • This page is a reading of a signalling design. It is not a guide to hiding a payment.

Why a venture studio still reads it

Ask what the group is, who inserts members, and what the external nullifier is for this application. If those three are vague, the proof is not yet a vote, a credential, or anything else.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.