Skip to content

whitepaperPrivacy2014

Zerocash: Decentralized Anonymous Payments from Bitcoin

Zerocash. Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer, Madars Virza.

The 2014 paper that showed how a payment ledger can hide sender, receiver and amount, while still letting the network check that coins were not created or double-spent. Zcash is an implementation of this line of work, not a co-author of the paper.

The problem the paper names

Zerocoin hid the link between mint and spend but left amounts and the surrounding Bitcoin transaction largely in the clear, and the proofs were heavy. Zerocash asks for a ledger where the payment itself is the private object.

What the design proposes

  • Coins are commitments. Spending reveals a nullifier, not the coin.
  • A succinct zero-knowledge proof shows that the inputs exist, the amounts balance, and the nullifiers are new.
  • The public chain checks the proof and the nullifier set. It does not learn the values.

How the mechanism is specified

  • Pouring transforms old coins into new coins. The proof attests to conservation of value.
  • Nullifiers give double-spend detection without identifying which coin moved.
  • The construction depends on a structured setup. Who ran that setup is a separate trust question the paper states rather than dissolves.

What this page does not treat as proven

  • The paper is not a description of today's Zcash network, its circuits, or its upgrade history.
  • It does not argue that shielded payments are appropriate for every regulated flow.
  • Performance figures in the paper are for the construction as evaluated then, not a promise about later provers.

Why a venture studio still reads it

When a studio venture wants private settlement between known businesses, Zerocash is the reference for what 'the chain checks conservation without seeing the amount' actually requires: a nullifier set, a proof, and an honest account of the setup.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.