Skip to content

LibraryPrivacy2023Design paperCorpus record

Namada: shielded transfers beside a public chain

Namada. Namada.

Namada publishes a shielded set for transfers, with a public chain around it, so privacy is a pool users enter rather than a property of every action.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

Namada publishes a shielded set for transfers, with a public chain around it, so privacy is a pool users enter rather than a property of every action.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
4

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    A shielded pool next to a public chain leaks at the boundary. The boundary is the design, not an embarrassment to skip.

  2. Claim 02 · Paper model

    The proposal

    Namada publishes a shielded set for transfers, with a public chain around it, so privacy is a pool users enter rather than a property of every action.

  3. Claim 03 · Paper model

    The mechanism

    Entering and exiting the shielded set is visible as an amount crossing. Transfers inside are the part the docs claim are hidden.

  4. Claim 04 · Paper model

    The bound

    No anonymity-set size is stated here.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    A shielded pool next to a public chain leaks at the boundary. The boundary is the design, not an embarrassment to skip.

    Model

    What has to hold

    You are reading Namada's docs. A cube or a mascot is not the mechanism.

    Falsifier

    What would retire it

    Which parts of a transaction are public by design?

  2. 02 The proposal

    Observation

    What the study says

    Namada publishes a shielded set for transfers, with a public chain around it, so privacy is a pool users enter rather than a property of every action.

    Model

    What has to hold

    You are reading Namada's docs. A cube or a mascot is not the mechanism.

    Falsifier

    What would retire it

    Which parts of a transaction are public by design?

  3. 03 The mechanism

    Observation

    What the study says

    Entering and exiting the shielded set is visible as an amount crossing. Transfers inside are the part the docs claim are hidden.

    Model

    What has to hold

    You are reading Namada's docs. A cube or a mascot is not the mechanism.

    Falsifier

    What would retire it

    What consensus does the document say orders these transactions?

  4. 04 The bound

    Observation

    What the study says

    No anonymity-set size is stated here.

    Model

    What has to hold

    You are reading Namada's docs. A cube or a mascot is not the mechanism.

    Falsifier

    What would retire it

    Which parts of a transaction are public by design?

03 Sequence

One action, as an operating tape

  1. 01Entering and exiting the shielded set is visible as an amount crossing. Transfers inside are the part the docs claim are hidden.
  2. 02A validity predicate or equivalent rule decides which transactions are legal. The predicate is public even when the amounts are not.
  3. 03The consensus assumption is the chain's validator set. Shielding does not replace it.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    Namada publishes a shielded set for transfers, with a public chain around it, so privacy is a pool users enter rather than a property of every action.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A public fee payment can deanonymise a user even when the transfer is shielded. Read how fees are paid.

  2. What actually moves

    The cut

    A validity predicate or equivalent rule decides which transactions are legal. The predicate is public even when the amounts are not.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A public fee payment can deanonymise a user even when the transfer is shielded. Read how fees are paid.

  3. What a later deployment may change

    The cut

    The consensus assumption is the chain's validator set. Shielding does not replace it.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading Namada's docs. A cube or a mascot is not the mechanism.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

This is not Penumbra's spec and not Zcash's.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

A shielded pool next to a public chain leaks at the boundary. The boundary is the design, not an embarrassment to skip.

What the design proposes

  • Entering and exiting the shielded set is visible as an amount crossing. Transfers inside are the part the docs claim are hidden.
  • A validity predicate or equivalent rule decides which transactions are legal. The predicate is public even when the amounts are not.
  • The consensus assumption is the chain's validator set. Shielding does not replace it.

How the mechanism is specified

  • Entering and exiting the shielded set is visible as an amount crossing. Transfers inside are the part the docs claim are hidden.
  • A validity predicate or equivalent rule decides which transactions are legal. The predicate is public even when the amounts are not.
  • The consensus assumption is the chain's validator set. Shielding does not replace it.

What this page does not treat as proven

  • No anonymity-set size is stated here.
  • A public fee payment can deanonymise a user even when the transfer is shielded. Read how fees are paid.
  • This is not Penumbra's spec and not Zcash's.

Why the desk still reads it

Namada publishes a shielded set for transfers, with a public chain around it, so privacy is a pool users enter rather than a property of every action.

09 Lexicon

Terms, opened into the record

Shielded set
The pool of notes whose amounts are hidden from the public ledger.
Boundary
The enter and exit actions. They are visible and they matter.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.