LibraryPrivacy2013Design paperCorpus record
Zerocoin: Anonymous Distributed E-Cash from Bitcoin
Zerocoin. Ian Miers, Christina Garman, Matthew Green, Aviel D. Rubin.
A 2013 proposal to add an anonymity layer on top of Bitcoin by burning a coin into a commitment and later redeeming a different coin with a zero-knowledge proof of membership.
Zerocoin lets someone burn a coin into a public commitment and later withdraw a different coin by proving the commitment is in the set, without saying which one.
The five-minute read
Mixers need a person in the middle
Someone has to hold the pool, or a group has to finish a round together. Either can fail, cheat, or simply log the mapping. Zerocoin wants that mapping to be a proof instead of a promise.
Mint is a public lock
A user locks a base-layer coin and publishes a commitment. The commitment is in a cryptographic set. The set is on the chain. There is no off-chain tumbler.
Spend is a membership proof
The withdrawal proves that some unused commitment in the set is known to the spender. It does not reveal which commitment. The chain learns that the proof is valid.
A serial number stops a second withdrawal
The spend reveals a serial number tied to the commitment. A second proof that reveals the same serial is rejected. Anonymity of the mint is not a licence to redeem twice.
This is not Zerocash
Amounts and the surrounding Bitcoin transaction stay largely visible, and the proofs are heavy. The following year's Zerocash paper replaces the construction. Do not describe Zcash as Zerocoin.
One action, walked through
- The user creates a secret and publishes a commitment to it, while locking the base coin the protocol requires.
- The commitment is added to a public accumulator, which is the chain's record of every mint that might later be spent.
- Later, the user produces a zero-knowledge proof that they know a commitment in that set, and they reveal the serial number.
- Nodes verify the proof against the current accumulator and check that the serial number has not been seen.
- A new base-layer coin is released. The chain cannot point from that coin back to the mint that funded it.
The argument, unpacked
The accumulator is the mixer
The set of commitments replaces the operator. Membership is a mathematical statement. That only helps if the proof system is sound and the parameters of the accumulator were generated honestly. The paper states a construction. It does not retire the question of who set it up.
Privacy is a gap in the link, not a private coin
A Zerocoin spend breaks the link between a deposit and a withdrawal. It does not hide how much moved, and it does not hide the Bitcoin transaction wrapped around the proof. Anyone evaluating 'anonymous payments' has to say which of those three leaks they still accept.
Cost is part of the design
The proof has to be checked by the base chain. In 2013 that cost was large. A design that is correct and too expensive to verify is not yet a payment system. The paper is honest that verification sits on the critical path.
What has to be true
- The accumulator's parameters are generated so that nobody holds a trapdoor that can forge membership.
- The base chain will accept the proof size and verification time.
- Users wait between mint and spend. A spend in the next block, from a set of one, is not anonymous.
- Serial numbers are unique and are retained for as long as the commitment set is valid.
What happened after the paper
Zerocash, in 2014, replaced the 'break one link on Bitcoin' idea with a ledger where the payment itself is the private object. Zcash is an implementation of that later line, with its own setup and upgrade history. Zerocoin remains the clearer diagram of a public commitment set plus a private withdrawal.
What to check before you use the idea
- What exactly is hidden: the link, the amount, or both?
- Who generated the accumulator parameters, and was there a trapdoor?
- How large is the anonymity set at the moment of spend, not in the marketing?
- Where is the serial number stored, and for how long?
Terms
- Commitment
- A public value that locks in a secret without revealing it. Opening the secret later must match.
- Accumulator
- A short public digest of a growing set, with a proof that some element is a member.
- Serial number
- The value revealed on spend so the same committed coin cannot be withdrawn twice.
- Anonymity set
- The commitments that could have been the one being spent. Privacy is the size and quality of this set.
The problem the paper names
Mixers need a trusted operator or a fragile coordination round. Zerocoin asks whether a Bitcoin-like chain can hold an accumulator of committed coins so that a withdrawal proves 'this commitment is in the set' without saying which one.
What the design proposes
- Mint: lock a base-layer coin and publish a commitment.
- Spend: prove knowledge of some unused commitment in the accumulator.
- A serial number is revealed on spend so the same commitment cannot be withdrawn twice.
How the mechanism is specified
- The accumulator is a public cryptographic set, not an off-chain tumbler.
- The proof shows membership and freshness. It does not show which mint the spend came from.
- The base chain still has to verify the proof, so cost and proof size are part of the design and not an afterthought.
What this page does not treat as proven
- This is not the Zcash protocol. Zerocash, the following year, replaces the construction.
- The paper does not claim production performance on Bitcoin as it existed in 2013.
- Trust in the accumulator parameters, and the choice of base chain, are outside the headline.
Why a venture studio still reads it
The pattern that still matters is the split between a public commitment set and a private withdrawal proof. Ventures that want 'compliant privacy' have to say where the serial number, the view key and the accumulator sit.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
