Privacy Pool
The privacy pool is a contract on the Neurai chain that holds XNA and keeps a private ledger of who owns it. Ownership is recorded as notes. The chain stores only a commitment to each note and an encrypted copy that only its recipient can read. Every pool transaction carries a Groth16 zero-knowledge proof that the ledger was updated correctly. The proof reveals no owner, and for transfers inside the pool it reveals no amount either.
The pool is not a new transaction type and needs no support from the node wallet. It is a contract built from POSITRONIC script features: a UNIQUE asset that carries the pool state, AuthScript outputs with a script tree, transaction introspection, Poseidon hashing and OP_ZKVERIFY.
The privacy pool runs on testnet and regtest. Its proving keys come from a public TEST setup, so anyone could in principle rebuild the setup secrets and forge proofs. The circuits, the contracts and the wallet library have not been independently audited. Use test XNA only. Nothing is scheduled for mainnet.
How it works
| Operation | What happens | What the chain shows |
|---|---|---|
| Deposit | A transparent coin of an exact amount enters the pool and becomes a private note | The amount and the funding coin |
| Assign | One note is consumed and one to four new notes are created for any recipients, change included | That an assignment happened and how many notes it created. No owners, no amounts |
| Withdraw | One whole note leaves the pool to a transparent address | The amount and the destination |
A recipient needs no message from the sender. Each new note is published on chain, encrypted to the recipient's viewing key, and the recipient's wallet finds it by scanning the pool.
Built on POSITRONIC
| POSITRONIC feature | Role in the pool |
|---|---|
UNIQUE asset NAME#POOL | Identity of the pool. Its output carries the 32-byte state digest in the asset message field (NIP-043) |
| AuthScript script tree (NIP-044) | The contract: eight leaves, one per operation form, and no signing-key branch |
| Transaction introspection | Fixes the exact inputs, outputs, values, scripts and asset fields of every pool transaction |
OP_TXHASH (NIP-042) | Binds each proof to the transaction it was built for |
OP_POSEIDON (NIP-036) | Recomputes inside Script the hashes that the circuit uses |
OP_ZKVERIFY | Verifies the Groth16 proof over BN254 against the verification key pinned in the leaf |
| AuthScript execution budgets (NIP-046) | Bound the cost of the large contract leaves |
| Transaction v3 | Pool transactions are version 3, with an empty reference input list |
| Legacy, strict PQ and strict ECDSA outputs | Accepted for deposits, fee payment and withdrawals |
Details: Node and consensus.
Two profiles: C4 and C5
The pool contract has two TEST profiles. They share notes, operation forms, addresses and wallet derivation. They differ in what the circuit proves and what the node checks.
| C4 | C5 | |
|---|---|---|
| Testnet status | Public TEST instance in use | Public TEST instance created. First spends wait for validators and miners to upgrade |
OP_ZKVERIFY profile | 1: Groth16 | 2: Groth16 plus a public tree transition |
| Tree updates | Proven inside the circuit | Replayed by the node with Poseidon, outside the circuit |
| Proving files | 24 files, about 691 MiB | 24 files, about 167 MiB |
| In the web wallet | Live on the testnet web wallet | In the development build, selectable with a separate balance. Not deployed yet |
Moving the public tree insertions out of the circuit makes C5 proofs much cheaper. On a two-CPU x86-64 machine, including parameter loading, a T2 proof went from 9.2 s and 792 MiB with C4 to 1.9 s and 319 MiB with C5, and a T4 proof from 16.1 s and 1285 MiB to 2.9 s and 460 MiB. The spent note's ownership, its position in the tree, the amounts and the spend secret stay inside the proof.
Testnet instances
C4 · UNIQUE asset C4TESTX260930A#POOL
- Pool address:
tnc1p5cn7433mpqt6h6wswkzxjr2tgxpjtmgqmuy0tuvw9tq2kk8lttjqxvdz4w - Birth transaction at height 11,540:
6985d9a0e71cfec44b4effd86f72b08d79191bfdb14fd5238d187390f021aac2
C5 · UNIQUE asset C5TEST261001#POOL
- Pool address:
tnc1pymrr03uj3wq0224ura2zh2h2tm552m28l8t9dzmjywp56a6r3h9szm0kh4 - Birth transaction at height 14,298:
31ffde2224687cc9fb1a8cf5805f6e74b1b3c6b30f3d7579167fef8324ed7923
Sending XNA directly to a pool address does not create a note and does not credit any private balance. Always use the deposit operation of a pool wallet.
Try it
- Neurai Web Wallet, testnet. Its Privacy page works with the C4 instance and opens a private wallet from the same words as the transparent one. From there you deposit, receive on
tnzk1…addresses, assign and withdraw. Proofs are generated in the browser, inside a Web Worker, with no proving server. A built-in benchmark proves all eight forms with synthetic data and moves no coins. @neuraiproject/neurai-privacy. The JavaScript library behind the web wallet: private keys and addresses, chain scanning, proving and transaction building. See Private wallets.- Your own node. Wallets read the pool through a node with
-txindexand-spentindex. See Running a node for pool wallets.
Current limits
- One note in per transaction. A payment cannot be larger than the largest single note, and notes cannot be merged yet.
- Four notes out at most. An assignment creates up to four notes, change included.
- Whole-note withdrawals. To withdraw part of a note, split it to yourself first.
- Exact deposit coin. A deposit needs a transparent coin of exactly the deposited amount, plus a separate coin for the fee.
- XNA only. Asset pools have been tested at node level but are not exposed to wallets.
- Serialized operations. Every operation spends the single state output. Two wallets that prepare against the same state race, and the loser proves again.
In this section
| Page | What it covers |
|---|---|
| How it works | Pool instance, state and reserve outputs, the three trees, notes, encrypted records, operation forms and transaction layout |
| Node and consensus | What the contract leaf checks, OP_ZKVERIFY and its profiles, activation and node requirements |
| Private wallets | NeuraiZK/v2 key derivation, nzk addresses, scanning, recovery, the proving pipeline and the library |
| Security and privacy | What the pool hides, what stays public, trust assumptions and what must happen before funds of value |