Skip to main content

Privacy Pool

The privacy pool is a contract on the Neurai chain that holds XNA and keeps a private ledger of who owns it. Ownership is recorded as notes. The chain stores only a commitment to each note and an encrypted copy that only its recipient can read. Every pool transaction carries a Groth16 zero-knowledge proof that the ledger was updated correctly. The proof reveals no owner, and for transfers inside the pool it reveals no amount either.

The pool is not a new transaction type and needs no support from the node wallet. It is a contract built from POSITRONIC script features: a UNIQUE asset that carries the pool state, AuthScript outputs with a script tree, transaction introspection, Poseidon hashing and OP_ZKVERIFY.

Testnet only, TEST parameters

The privacy pool runs on testnet and regtest. Its proving keys come from a public TEST setup, so anyone could in principle rebuild the setup secrets and forge proofs. The circuits, the contracts and the wallet library have not been independently audited. Use test XNA only. Nothing is scheduled for mainnet.

How it works​

Funding coinexact deposit amountLegacy, PQ or ECDSApublic: amount, addressdepositD0 · D1privacy pool · private ledgerassignT1 – T4note Aowner hiddennote → Bobamount hiddennote → Carolamount hiddenchange → Aamount hiddenwithdrawwhole notePayout addressreceives the note valueLegacy, PQ or ECDSApublic: amount, addressOn chainstate digest · note commitments · nullifiers · encrypted note records · reserve total · one Groth16 proof per operation
OperationWhat happensWhat the chain shows
DepositA transparent coin of an exact amount enters the pool and becomes a private noteThe amount and the funding coin
AssignOne note is consumed and one to four new notes are created for any recipients, change includedThat an assignment happened and how many notes it created. No owners, no amounts
WithdrawOne whole note leaves the pool to a transparent addressThe amount and the destination

A recipient needs no message from the sender. Each new note is published on chain, encrypted to the recipient's viewing key, and the recipient's wallet finds it by scanning the pool.

Built on POSITRONIC​

POSITRONIC featureRole in the pool
UNIQUE asset NAME#POOLIdentity of the pool. Its output carries the 32-byte state digest in the asset message field (NIP-043)
AuthScript script tree (NIP-044)The contract: eight leaves, one per operation form, and no signing-key branch
Transaction introspectionFixes the exact inputs, outputs, values, scripts and asset fields of every pool transaction
OP_TXHASH (NIP-042)Binds each proof to the transaction it was built for
OP_POSEIDON (NIP-036)Recomputes inside Script the hashes that the circuit uses
OP_ZKVERIFYVerifies the Groth16 proof over BN254 against the verification key pinned in the leaf
AuthScript execution budgets (NIP-046)Bound the cost of the large contract leaves
Transaction v3Pool transactions are version 3, with an empty reference input list
Legacy, strict PQ and strict ECDSA outputsAccepted for deposits, fee payment and withdrawals

Details: Node and consensus.

Two profiles: C4 and C5​

The pool contract has two TEST profiles. They share notes, operation forms, addresses and wallet derivation. They differ in what the circuit proves and what the node checks.

C4C5
Testnet statusPublic TEST instance in usePublic TEST instance created. First spends wait for validators and miners to upgrade
OP_ZKVERIFY profile1: Groth162: Groth16 plus a public tree transition
Tree updatesProven inside the circuitReplayed by the node with Poseidon, outside the circuit
Proving files24 files, about 691 MiB24 files, about 167 MiB
In the web walletLive on the testnet web walletIn the development build, selectable with a separate balance. Not deployed yet

Moving the public tree insertions out of the circuit makes C5 proofs much cheaper. On a two-CPU x86-64 machine, including parameter loading, a T2 proof went from 9.2 s and 792 MiB with C4 to 1.9 s and 319 MiB with C5, and a T4 proof from 16.1 s and 1285 MiB to 2.9 s and 460 MiB. The spent note's ownership, its position in the tree, the amounts and the spend secret stay inside the proof.

Testnet instances​

C4 · UNIQUE asset C4TESTX260930A#POOL

  • Pool address: tnc1p5cn7433mpqt6h6wswkzxjr2tgxpjtmgqmuy0tuvw9tq2kk8lttjqxvdz4w
  • Birth transaction at height 11,540: 6985d9a0e71cfec44b4effd86f72b08d79191bfdb14fd5238d187390f021aac2

C5 · UNIQUE asset C5TEST261001#POOL

  • Pool address: tnc1pymrr03uj3wq0224ura2zh2h2tm552m28l8t9dzmjywp56a6r3h9szm0kh4
  • Birth transaction at height 14,298: 31ffde2224687cc9fb1a8cf5805f6e74b1b3c6b30f3d7579167fef8324ed7923
caution

Sending XNA directly to a pool address does not create a note and does not credit any private balance. Always use the deposit operation of a pool wallet.

Try it​

  • Neurai Web Wallet, testnet. Its Privacy page works with the C4 instance and opens a private wallet from the same words as the transparent one. From there you deposit, receive on tnzk1… addresses, assign and withdraw. Proofs are generated in the browser, inside a Web Worker, with no proving server. A built-in benchmark proves all eight forms with synthetic data and moves no coins.
  • @neuraiproject/neurai-privacy. The JavaScript library behind the web wallet: private keys and addresses, chain scanning, proving and transaction building. See Private wallets.
  • Your own node. Wallets read the pool through a node with -txindex and -spentindex. See Running a node for pool wallets.

Current limits​

  • One note in per transaction. A payment cannot be larger than the largest single note, and notes cannot be merged yet.
  • Four notes out at most. An assignment creates up to four notes, change included.
  • Whole-note withdrawals. To withdraw part of a note, split it to yourself first.
  • Exact deposit coin. A deposit needs a transparent coin of exactly the deposited amount, plus a separate coin for the fee.
  • XNA only. Asset pools have been tested at node level but are not exposed to wallets.
  • Serialized operations. Every operation spends the single state output. Two wallets that prepare against the same state race, and the loser proves again.

In this section​

PageWhat it covers
How it worksPool instance, state and reserve outputs, the three trees, notes, encrypted records, operation forms and transaction layout
Node and consensusWhat the contract leaf checks, OP_ZKVERIFY and its profiles, activation and node requirements
Private walletsNeuraiZK/v2 key derivation, nzk addresses, scanning, recovery, the proving pipeline and the library
Security and privacyWhat the pool hides, what stays public, trust assumptions and what must happen before funds of value