whitepaperPrivacy2013
Zerocoin: Anonymous Distributed E-Cash from Bitcoin
Zerocoin. Ian Miers, Christina Garman, Matthew Green, Aviel D. Rubin.
A 2013 proposal to add an anonymity layer on top of Bitcoin by burning a coin into a commitment and later redeeming a different coin with a zero-knowledge proof of membership.
The problem the paper names
Mixers need a trusted operator or a fragile coordination round. Zerocoin asks whether a Bitcoin-like chain can hold an accumulator of committed coins so that a withdrawal proves 'this commitment is in the set' without saying which one.
What the design proposes
- Mint: lock a base-layer coin and publish a commitment.
- Spend: prove knowledge of some unused commitment in the accumulator.
- A serial number is revealed on spend so the same commitment cannot be withdrawn twice.
How the mechanism is specified
- The accumulator is a public cryptographic set, not an off-chain tumbler.
- The proof shows membership and freshness. It does not show which mint the spend came from.
- The base chain still has to verify the proof, so cost and proof size are part of the design and not an afterthought.
What this page does not treat as proven
- This is not the Zcash protocol. Zerocash, the following year, replaces the construction.
- The paper does not claim production performance on Bitcoin as it existed in 2013.
- Trust in the accumulator parameters, and the choice of base chain, are outside the headline.
Why a venture studio still reads it
The pattern that still matters is the split between a public commitment set and a private withdrawal proof. Ventures that want 'compliant privacy' have to say where the serial number, the view key and the accumulator sit.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.