Skip to content

LibraryPrivacy2020Design paperCorpus record

Zether: Towards Privacy in a Smart Contract World

Zether. Benedikt Bünz, Shashank Agrawal, Mahdi Zamani and Dan Boneh.

Zether is a contract for confidential transfers and confidential anonymous transfers, with balances as commitments and a proof that the spend is well formed.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

A private-payments pitch on a public chain is this shape or it is a trusted operator. Ask what the contract verifies and what an observer still sees.

The five-minute read

The defect

A public contract ledger publishes amounts and addresses. A private payment that leaves that ledger has to be a new chain, or a contract that hides the amount inside a proof.

The proposal

Zether is a contract for confidential transfers and confidential anonymous transfers, with balances as commitments and a proof that the spend is well formed.

The amount is hidden. The proof is what the contract checks.

Anonymity among a set is a further mode, not the same as confidentiality of the amount.

The bound

This is not a deployed mixer and not an instruction for hiding funds.

One action, walked through

  1. Lock a balance in the contract.
  2. Transfer by publishing a proof and updating commitments.
  3. The contract accepts the proof or it does not. It does not see the amount.
  4. Who is in the anonymity set?

The argument, unpacked

What the paper is for

A private-payments pitch on a public chain is this shape or it is a trusted operator. Ask what the contract verifies and what an observer still sees.

What happened after

Later systems changed the proof system. The split between a public verifier and a hidden amount is the idea that stayed.

What has to be true

  • This is not a deployed mixer and not an instruction for hiding funds.
  • The anonymity set is whoever is in the contract, not 'the chain'.
  • A bug in the statement being proved is a bug in the privacy.

What happened after the paper

Later systems changed the proof system. The split between a public verifier and a hidden amount is the idea that stayed.

What to check before you use the idea

  • What is hidden: the amount, the sender, or both?
  • Who is in the anonymity set?
  • What does a failed proof reveal?

Terms

Commitment
A published value that binds an amount without showing it.
Anonymity set
The accounts the sender could be.

The problem the paper names

A public contract ledger publishes amounts and addresses. A private payment that leaves that ledger has to be a new chain, or a contract that hides the amount inside a proof.

What the design proposes

  • The amount is hidden. The proof is what the contract checks.
  • Anonymity among a set is a further mode, not the same as confidentiality of the amount.
  • The contract still lives on a public chain. The proof is public.

How the mechanism is specified

  • Lock a balance in the contract.
  • Transfer by publishing a proof and updating commitments.
  • The contract accepts the proof or it does not. It does not see the amount.

What this page does not treat as proven

  • This is not a deployed mixer and not an instruction for hiding funds.
  • The anonymity set is whoever is in the contract, not 'the chain'.
  • A bug in the statement being proved is a bug in the privacy.

Why a venture studio still reads it

A private-payments pitch on a public chain is this shape or it is a trusted operator. Ask what the contract verifies and what an observer still sees.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.