Skip to content

LibraryPrivacy2019Design paperCorpus record

Ouroboros Crypsinous: Privacy-Preserving Proof-of-Stake

Ouroboros Crypsinous. Thomas Kerber, Aggelos Kiayias, Markulf Kohlweiss and Vassilis Zikas.

Crypsinous combines a stake lottery with a private transaction ledger so the leader proof and the transfers do not reveal the stake and the amounts in the way a public chain does.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

A private stake chain has to answer two questions this paper separates: who can extend the chain, and what the payment revealed.

The five-minute read

The defect

A stake chain publishes who was eligible to produce a block if the leader election is a public function of the stake.

The proposal

Crypsinous combines a stake lottery with a private transaction ledger so the leader proof and the transfers do not reveal the stake and the amounts in the way a public chain does.

Leader privacy and transaction privacy are different leaks.

The construction uses zero-knowledge proofs over the stake and the coins.

The bound

This is not Cardano's deployed privacy and not a mixing instruction.

One action, walked through

  1. A party proves it won the slot without showing the stake in public.
  2. A transfer is a private state update with a proof.
  3. The ledger rules still have to reject a double-spend.
  4. Are amounts hidden?

The argument, unpacked

What the paper is for

A private stake chain has to answer two questions this paper separates: who can extend the chain, and what the payment revealed.

What happened after

Deployed stake chains mostly kept public leader schedules. That is a refusal of this property, not an implementation of it.

What has to be true

  • This is not Cardano's deployed privacy and not a mixing instruction.
  • The proofs are only as strong as the relation.
  • Leader privacy fails if the implementation publishes the key anyway.

What happened after the paper

Deployed stake chains mostly kept public leader schedules. That is a refusal of this property, not an implementation of it.

What to check before you use the idea

  • Is the slot leader hidden?
  • Are amounts hidden?
  • What is still public in the block header?

Terms

Leader privacy
An observer cannot tell who was eligible from the block alone.
Private ledger
Transfers that do not publish amounts and identities.

The problem the paper names

A stake chain publishes who was eligible to produce a block if the leader election is a public function of the stake.

What the design proposes

  • Leader privacy and transaction privacy are different leaks.
  • The construction uses zero-knowledge proofs over the stake and the coins.
  • It is a protocol paper, not a wallet.

How the mechanism is specified

  • A party proves it won the slot without showing the stake in public.
  • A transfer is a private state update with a proof.
  • The ledger rules still have to reject a double-spend.

What this page does not treat as proven

  • This is not Cardano's deployed privacy and not a mixing instruction.
  • The proofs are only as strong as the relation.
  • Leader privacy fails if the implementation publishes the key anyway.

Why a venture studio still reads it

A private stake chain has to answer two questions this paper separates: who can extend the chain, and what the payment revealed.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.