LibraryPrivacy2020Design paperCorpus record
Zether: Towards Privacy in a Smart Contract World
Zether. Benedikt Bünz, Shashank Agrawal, Mahdi Zamani and Dan Boneh.
Zether is a contract for confidential transfers and confidential anonymous transfers, with balances as commitments and a proof that the spend is well formed.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
A private-payments pitch on a public chain is this shape or it is a trusted operator. Ask what the contract verifies and what an observer still sees.
The five-minute read
The defect
A public contract ledger publishes amounts and addresses. A private payment that leaves that ledger has to be a new chain, or a contract that hides the amount inside a proof.
The proposal
Zether is a contract for confidential transfers and confidential anonymous transfers, with balances as commitments and a proof that the spend is well formed.
The amount is hidden. The proof is what the contract checks.
Anonymity among a set is a further mode, not the same as confidentiality of the amount.
The bound
This is not a deployed mixer and not an instruction for hiding funds.
One action, walked through
- Lock a balance in the contract.
- Transfer by publishing a proof and updating commitments.
- The contract accepts the proof or it does not. It does not see the amount.
- Who is in the anonymity set?
The argument, unpacked
What the paper is for
A private-payments pitch on a public chain is this shape or it is a trusted operator. Ask what the contract verifies and what an observer still sees.
What happened after
Later systems changed the proof system. The split between a public verifier and a hidden amount is the idea that stayed.
What has to be true
- This is not a deployed mixer and not an instruction for hiding funds.
- The anonymity set is whoever is in the contract, not 'the chain'.
- A bug in the statement being proved is a bug in the privacy.
What happened after the paper
Later systems changed the proof system. The split between a public verifier and a hidden amount is the idea that stayed.
What to check before you use the idea
- What is hidden: the amount, the sender, or both?
- Who is in the anonymity set?
- What does a failed proof reveal?
Terms
- Commitment
- A published value that binds an amount without showing it.
- Anonymity set
- The accounts the sender could be.
The problem the paper names
A public contract ledger publishes amounts and addresses. A private payment that leaves that ledger has to be a new chain, or a contract that hides the amount inside a proof.
What the design proposes
- The amount is hidden. The proof is what the contract checks.
- Anonymity among a set is a further mode, not the same as confidentiality of the amount.
- The contract still lives on a public chain. The proof is public.
How the mechanism is specified
- Lock a balance in the contract.
- Transfer by publishing a proof and updating commitments.
- The contract accepts the proof or it does not. It does not see the amount.
What this page does not treat as proven
- This is not a deployed mixer and not an instruction for hiding funds.
- The anonymity set is whoever is in the contract, not 'the chain'.
- A bug in the statement being proved is a bug in the privacy.
Why a venture studio still reads it
A private-payments pitch on a public chain is this shape or it is a trusted operator. Ask what the contract verifies and what an observer still sees.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
