LibraryPrivacy2014Design paperCorpus record
Zerocash: Decentralized Anonymous Payments from Bitcoin
Zerocash. Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer, Madars Virza.
The 2014 paper that showed how a payment ledger can hide sender, receiver and amount, while still letting the network check that coins were not created or double-spent. Zcash is an implementation of this line of work, not a co-author of the paper.
Zerocash makes the payment itself private: the chain checks that value was conserved and not double-spent, without learning the sender, the receiver, or the amount.
The five-minute read
Zerocoin left too much in the clear
It hid which mint funded a spend. It did not hide the amount, and the proofs were heavy. Zerocash asks for the payment, not just the link, to be the private object.
Coins are commitments
A coin is not a row that says who owns what. It is a commitment to a value and a key. Spending does not point at the old coin. It reveals a nullifier.
One proof carries the conservation law
A succinct zero-knowledge proof says the inputs exist, the amounts balance, and the nullifiers are well formed. Nodes check the proof. They do not learn the values.
Nullifiers are the double-spend list
Each coin can produce one nullifier. The chain stores the set of revealed nullifiers. A second spend of the same coin collides. The list does not say which coin it was.
The setup is a named trust
The construction needs structured parameters. Whoever knows the toxic waste can forge value. The paper states that. It does not dissolve it.
One action, walked through
- A holder of old coins runs a pour: new coins are committed, and the secrets of the old coins stay off the chain.
- The pour computes a nullifier for each input coin and a commitment for each output coin.
- A proof attests that the input coins existed in the commitment tree, the values balance, and the spender was allowed to spend.
- The chain appends the output commitments, stores the nullifiers, and rejects the transaction if a nullifier is already present or the proof fails.
- The recipient scans for notes they can open. The public ledger shows that a valid pour happened, not who paid whom.
The argument, unpacked
Conservation without inspection
A public chain usually enforces 'inputs equal outputs' by reading both sides. Zerocash enforces it inside a proof. That is a different engineering object. If the proof system is unsound, the chain will accept counterfeit value and have no row to inspect. Soundness is the monetary policy.
The nullifier set is the whole privacy budget
Double-spend detection has to live somewhere. Putting it in a set of anonymous markers is what makes the design work. Anything that links a nullifier back to a commitment, including a bug or a too-small set of notes, collapses the privacy the proof was bought to provide.
Shielded is not the same as appropriate
The paper shows a way for a ledger to hide a payment. It does not argue that every regulated flow should be shielded, and it does not describe a viewing key policy for auditors. A venture that needs selective disclosure has to add that policy on purpose. It is not in the headline.
What has to be true
- The common reference string was generated so that no one retained a trapdoor. A ceremony is a social procedure, not a theorem.
- Users actually move value inside the shielded pool. A transparent note next to a shielded proof is a different system.
- The note commitment tree is available to wallets that must prove membership.
- Proof generation is cheap enough for the user who is supposed to pay, and verification is cheap enough for every node.
What happened after the paper
Zcash is an implementation of this line of work, not a co-author of the 2014 paper. Circuits, the move toward the Halo proving system, and the network's upgrade history are later facts. Performance numbers in the paper are for the construction as evaluated then. They are not a promise about current provers.
What to check before you use the idea
- Who ran the setup, and what is destroyed at the end of it?
- Is the pool the user pays from actually shielded, or only advertised as private?
- Where does a viewing key sit if a business must show one payment to an auditor?
- What does a node store forever: commitments, nullifiers, or the notes themselves?
Terms
- Pour
- The operation that consumes old private coins and creates new ones, with a proof that value was conserved.
- Nullifier
- A unique marker revealed when a coin is spent, so it cannot be spent again, without identifying the coin.
- Succinct proof
- A short proof that a large statement is true. Nodes check the short proof rather than replaying the private data.
- Structured setup
- Parameters the proof system needs. Knowledge of the secret behind those parameters can break soundness.
The problem the paper names
Zerocoin hid the link between mint and spend but left amounts and the surrounding Bitcoin transaction largely in the clear, and the proofs were heavy. Zerocash asks for a ledger where the payment itself is the private object.
What the design proposes
- Coins are commitments. Spending reveals a nullifier, not the coin.
- A succinct zero-knowledge proof shows that the inputs exist, the amounts balance, and the nullifiers are new.
- The public chain checks the proof and the nullifier set. It does not learn the values.
How the mechanism is specified
- Pouring transforms old coins into new coins. The proof attests to conservation of value.
- Nullifiers give double-spend detection without identifying which coin moved.
- The construction depends on a structured setup. Who ran that setup is a separate trust question the paper states rather than dissolves.
What this page does not treat as proven
- The paper is not a description of today's Zcash network, its circuits, or its upgrade history.
- It does not argue that shielded payments are appropriate for every regulated flow.
- Performance figures in the paper are for the construction as evaluated then, not a promise about later provers.
Why a venture studio still reads it
When a studio venture wants private settlement between known businesses, Zerocash is the reference for what 'the chain checks conservation without seeing the amount' actually requires: a nullifier set, a proof, and an honest account of the setup.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
