LibraryPrivacy2021Design paperCorpus record
RAILGUN: shielded balances inside a smart-contract system
RAILGUN. RAILGUN.
RAILGUN publishes shielded balances for tokens: a user deposits into a private balance and later transacts with proofs, rather than with a single fixed-denomination pool only.
A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.
RAILGUN publishes shielded balances for tokens: a user deposits into a private balance and later transacts with proofs, rather than with a single fixed-denomination pool only.
- Evidence
- Primary paper
- Re-measured
- No
- Assumptions
- 3
- Records linked
- 2
01 Claim ledger
What the paper is allowed to say
Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.
Claim 01 · Paper model
The defect
A shielded balance system has a note state. If the docs do not say what the proof hides, do not assume it hides the sender, the amount, and the token.
Claim 02 · Paper model
The proposal
RAILGUN publishes shielded balances for tokens: a user deposits into a private balance and later transacts with proofs, rather than with a single fixed-denomination pool only.
Claim 03 · Paper model
The mechanism
Deposits move tokens into the contract and create a private note. Transfers update notes. Withdrawals reveal a public recipient.
Claim 04 · Paper model
The bound
This note states no anonymity set.
02 Three cuts
Observation, model, falsifier
A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.
01 The defect
Observation
What the study says
A shielded balance system has a note state. If the docs do not say what the proof hides, do not assume it hides the sender, the amount, and the token.
Falsifier
What would retire it
Which host chain and which proof system does that page name?
02 The proposal
Observation
What the study says
RAILGUN publishes shielded balances for tokens: a user deposits into a private balance and later transacts with proofs, rather than with a single fixed-denomination pool only.
Falsifier
What would retire it
What does a withdrawal reveal?
03 The mechanism
Observation
What the study says
Deposits move tokens into the contract and create a private note. Transfers update notes. Withdrawals reveal a public recipient.
Model
What has to hold
No price, supply, yield, or adoption figure is added by this desk.
Falsifier
What would retire it
What does a withdrawal reveal?
04 The bound
Observation
What the study says
This note states no anonymity set.
Falsifier
What would retire it
What does a transfer proof hide, in the page you opened?
03 Sequence
One action, as an operating tape
- 01Deposits move tokens into the contract and create a private note. Transfers update notes. Withdrawals reveal a public recipient.
- 02The proof system and the token list are different objects. A token the contract cannot represent is outside the design.
- 03Adaptations for private DeFi calls, if documented, compose extra circuits. Each circuit is a new disclosure risk.
04 Load-bearing
The argument, and where a pitch drops it
What the name has to mean
The cut
RAILGUN publishes shielded balances for tokens: a user deposits into a private balance and later transacts with proofs, rather than with a single fixed-denomination pool only.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
A later client, parameter or reward formula is a different object from this paragraph.
What actually moves
The cut
The proof system and the token list are different objects. A token the contract cannot represent is outside the design.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
This is not Zcash's chain. It is a contract system on a host chain.
What a later deployment may change
The cut
Adaptations for private DeFi calls, if documented, compose extra circuits. Each circuit is a new disclosure risk.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
A later client, parameter or reward formula is a different object from this paragraph.
05 Register
What has to be true
Model · Not re-measured
You are reading RAILGUN's documentation. A wallet skin is not the circuit.
Model · Not re-measured
The document is the one at the source URL. A marketing page with the same brand is not this text.
Model · Not re-measured
No price, supply, yield, or adoption figure is added by this desk.
06 Divergence
What happened after the paper
This is not Zcash's chain. It is a contract system on a host chain.
A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.
07 Pre-mortem
What to check before you use the idea
- 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.
08 Anatomy
The paper, in the order a builder needs
The problem it names
A shielded balance system has a note state. If the docs do not say what the proof hides, do not assume it hides the sender, the amount, and the token.
What the design proposes
- Deposits move tokens into the contract and create a private note. Transfers update notes. Withdrawals reveal a public recipient.
- The proof system and the token list are different objects. A token the contract cannot represent is outside the design.
- Adaptations for private DeFi calls, if documented, compose extra circuits. Each circuit is a new disclosure risk.
How the mechanism is specified
- Deposits move tokens into the contract and create a private note. Transfers update notes. Withdrawals reveal a public recipient.
- The proof system and the token list are different objects. A token the contract cannot represent is outside the design.
- Adaptations for private DeFi calls, if documented, compose extra circuits. Each circuit is a new disclosure risk.
What this page does not treat as proven
- This note states no anonymity set.
- It does not say the system hides activity from a sequencer or a relayer.
- This is not Zcash's chain. It is a contract system on a host chain.
Why the desk still reads it
RAILGUN publishes shielded balances for tokens: a user deposits into a private balance and later transacts with proofs, rather than with a single fixed-denomination pool only.
09 Lexicon
Terms, opened into the record
- Shielded balance
- A note held by the contract. It is not an ordinary token balance.
- Private transfer
- A proof that updates notes without naming them on the public call data, if the docs actually claim that.
10 Repository
Every linked record on this page
Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.
Concepts
Papers
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
