Private amounts
Range, balance and booleanity over lattice commitments, proved in one protocol so the cost does not grow with the number of amount bits. The client proves; the node only verifies.
8 of 10 milestones
- 2026-07-16Direct range proof chosen over folding
- 2026-07-16Booleanity, range and balance unified into one protocol
- 2026-07-17Prover and verifier end to end
- 2026-07-18Prover compiled to wasm, in-browser round trip
- 2026-07-19Production parameters
- 2026-07-23Zero-knowledge tail closed
- 2026-08-10Wallet scan over RPC
- 2026-08-12Throughput re-measured against current proof sizes
- openProof size reduction
- openPrivacy lane in the browser wallet