Skip to main content

Comparisons

How does zkCoins compare to other privacy and scaling approaches — and what, precisely, makes it different?

Where zkCoins sits​

zkCoins is an implementation of two whitepapers:

  • the Shielded CSV construction by Jonas Nick (Blockstream), Liam Eagen (Alpen Labs), and Robin Linus (ZeroSync) — eprint 2025/068;
  • the original zkCoins concept, prototyped as ZeroSync/ZKCoins.

The project at zkcoins.app does not compete with these papers — it realizes them, with every load-bearing deviation registered in the Paper-Deviation Analysis. It claims no invention of the underlying scheme; its contribution is bringing the design to a running node, wallet, and the off-chain transport/recovery layer needed to operate it. Where this page says "zkCoins", read "the Shielded CSV scheme as realized by zkCoins v1, registered deviations included".

The differentiator is a combination, not a single property​

Privacy alone is not new. Decentralization alone is not new. Even privacy + decentralization together is not new — Monero and Zcash have shipped both for years. What is rare is a specific triple:

  • Bitcoin-anchored — settles on Bitcoin L1, with no own chain, token, or consensus to bootstrap. It inherits Bitcoin's decentralization instead of building a new one.
  • Shielded — a real anonymity set with ZK unlinkability, not merely "data kept off the public chain".
  • Trustless — correctness enforced by cryptography and Bitcoin, with no trusted operator, mint, or federation.

Almost every related protocol nails two of the three and misses the third:

Protocol(s)Bitcoin-anchoredShielded (anon-set)TrustlessMisses
Monero, Zcash, Penumbra, Namada, Firo, Iron Fish✗ own chain✓✓not Bitcoin — own security budget/token
RGB, Taproot Assets✓✗ counterparty sees full provenance✓no anonymity set
Cashu, Fedimint✓✓ (blinded)✗ custodial / federatednot trustless
Railgun, Aztec, Tornado Cash✗ Ethereum, on-chain data✓~not Bitcoin, on-chain data
Liquid, Statechains / Mercury✓~ / ✗✗ federationfederated
Shade✗ Secret Network✓ (via TEE)~privacy via trusted hardware, not ZK
zkCoins (Shielded CSV)✓✓✓—
Spec design vs. shipped implementation

The trustless corner is fully specified: every node rebuilds the public nullifier accumulator from Bitcoin alone, while each private CoinProof remains content-addressed, independently verifiable, and retained under the store-everything invariant plus the §4.3 recovery-discoverable overlap for recovery (spec §3.6–§3.7, §4.5–§4.6).

Footprint figures in the tables below quote the normative spec design — a ~64-byte half-aggregated nullifier per transition (~16 vB), constant in the transition's input count (spec §3.8).


Deep dives​

vs. RGB​

Both use Client-Side Validation on Bitcoin, but serve different purposes.

zkCoins (Shielded CSV)RGB
FocusPrivate paymentsSmart contracts + tokens
PrivacyFull against the public-chain observer (global anonymity set); bounded counterparty residuals (D-17–D-19, Risks)Limited (history revealed to counterparty)
Proof sizeConstant (independent of history)Grows with transaction history
On-chain footprint~64-byte half-aggregated nullifier per transition (~16 vB), constant in input count (spec §3.8)Commitment in a host TX; off-chain consignment grows
Smart contractsNoYes (zk-AluVM, Turing-complete)
DeFi/LendingNot yetPossible (bilateral)
Complementary, not competing

zkCoins for the payment layer (privacy + scalability), RGB for programmable logic (lending, tokens). Both use Client-Side Validation on Bitcoin L1.

vs. Taproot Assets​

The closest "assets on Bitcoin via CSV" cousin, from Lightning Labs.

zkCoins (Shielded CSV)Taproot Assets
ValidationClient-Side Validation + ZKClient-Side Validation (Merkle proofs)
PrivacyFull shield (anonymity set)Transparent — proofs reveal asset, amount, lineage to the counterparty
Data availabilityPrivate CoinProof off-chain (store-everything + §4.3 recovery-discoverable overlap, no fixed replica count); public nullifiers on BitcoinUniverse servers (off-chain proof archives)
AnchorBitcoin TaprootBitcoin Taproot

Taproot Assets shares the Bitcoin anchor and the off-chain-data model, but has no shielding — it is the "Bitcoin + decentralized, but not private" corner of the triangle.

vs. Lightning Network​

zkCoins (Shielded CSV)Lightning
LayerL1 (Client-Side Validation)L2 (payment channels)
PrivacyFull (ZK proofs)Good (onion routing)
InteractivityReceiver must be reachableRouting path required
CapacityBounded by Bitcoin L1 (one ~64-byte nullifier per transition, ~16 vB)Theoretically unlimited
Offline receiveNoNo

Lightning and Shielded CSV are complementary; CSV assets could theoretically flow through Lightning channels.

vs. Zcash​

zkCoins (Shielded CSV)Zcash
BlockchainBitcoin (existing)Own chain
Consensus changeNone neededOwn consensus
Privacy modelMandatory for CSV usersOptional (~10-20% usage)
ZK systemPlonky2 (cyclic recursion, FRI)Halo2
Trusted setupNoneEliminated since NU5
On-chain footprint~64-byte half-aggregated nullifier per transition (~16 vB)Full transaction

Zcash is the conceptual parent of the commitment/nullifier shield. The key divergence: Zcash secures its own chain; zkCoins inherits Bitcoin's.

vs. Monero​

zkCoins (Shielded CSV)Monero
BlockchainBitcoinOwn chain
Privacy approachZK proofsRing signatures + Stealth + RingCT
Anonymity setAll coins ever createdRing of 16 decoys
Scalability~64 B per transition on-chain (~16 vB), constant in input count~2-3 KB per TX
Statistical attacksDecoy-selection analysis: not applicable (no decoys, full anonymity set); per-block transition count and inscription timing remain publicly visible (Risks)Possible (decoy-selection analysis)

vs. CoinJoin​

zkCoins (Shielded CSV)CoinJoin (Wasabi/JoinMarket)
Anonymity setAll coinsRound participants only
Amounts hiddenYesNo (equal-output)
CoordinatorNoneRequired
On-chain analysisAmount/decoy-based analysis not possible (no decoys, all amounts hidden); per-transition count, inscription timing, and (toward a repeatedly reused publisher) the pre-anchor Pkᵢ of each hand-off remain visible (Risks)Difficult but not impossible
CostOne ~64-byte nullifier per transition (~16 vB)Multiple UTXOs (expensive)
Regulatory riskLow (no coordinator)High (coordinators prosecuted)

vs. Silent Payments (BIP352)​

zkCoins (Shielded CSV)Silent Payments
GoalFull transaction privacyReceive-only privacy
Amounts hiddenYesNo
Transaction graph hiddenYesNo
ComplexityHighModerate

Silent Payments solve a different problem (reusable addresses) and could serve as a receive mechanism for Shielded CSV in the future.


The wider landscape​

The protocols below all rhyme with zkCoins on at least one axis. They are grouped by how they relate, with the one difference that matters most for each.

Client-Side Validation on Bitcoin (the closest family)​

Off-chain data, on-chain commitment, validation by the client.

ProtocolWhat it isKey difference from zkCoins
Shielded CSVThe construction zkCoins implements— (the basis, not a competitor)
RGBCSV smart contracts + tokens on BitcoinNo anonymity set; counterparty sees full provenance
Taproot Assets (repo)Assets in a Taproot tree, universe serversTransparent — no shielding
Single-use seals (Peter Todd)The primitive RGB / TA build onA building block, not a payment system

Shielded ZK value transfer (on their own chains)​

Private and decentralized — but each runs its own chain, token, and security budget.

ProtocolWhat it isKey difference from zkCoins
ZcashShielded pool, note commitments + nullifiersOwn chain (the model zkCoins borrows, on Bitcoin)
MoneroRing signatures + RingCT + stealth addressesOwn chain; decoy-ring privacy, not a ZK anonymity set
PenumbraShielded Cosmos zone (private DEX/staking)Own PoS chain
NamadaMulti-asset shielded pool (MASP), CosmosOwn PoS chain
Iron FishAccount-based shielded L1Own chain
FiroLelantus Spark, one-time addressesOwn chain
ZanoConfidential L1 with auditable walletsOwn chain
AleoPrivate-by-default L1, ZK execution (snarkVM)Own chain; general computation

Privacy on smart-contract chains​

Shielded, but on Ethereum-class chains with on-chain data.

ProtocolWhat it isKey difference from zkCoins
Railgun (repo)Shielded pool as an EVM smart contractEthereum; on-chain data; depends on that chain
AztecZK privacy L2, private contracts (Noir)Ethereum L2; not Bitcoin
Tornado CashFixed-denomination mixer (commitment/nullifier)Ethereum; mixer, not a payment system; sanctioned

Client-data / stateless ZK rollups​

Mechanically the nearest non-Bitcoin relatives: the client holds the data, the chain holds a commitment.

ProtocolWhat it isKey difference from zkCoins
Intmax / Intmax2Stateless ZK-rollup, client-held data, minimal on-chain footprintEthereum-anchored; privacy is not the primary goal
Plasma (historical)Off-chain state + on-chain commitments + fraud proofsFraud-proof model, not ZK; largely superseded

Bitcoin asset overlays (on-chain data, no privacy)​

The historical "issue assets on Bitcoin" lineage. Data is on-chain and transparent.

ProtocolWhat it isKey difference from zkCoins
Omni Layer (ex-Mastercoin)OP_RETURN asset metadata; carried early USDTOn-chain data, no privacy, no CSV
Counterparty (XCP)Assets + DEX encoded in Bitcoin transactionsOn-chain, transparent
Colored Coins / Open AssetsTag specific satoshis as assetsEarliest, fully transparent
Ordinals / Runes / BRC-20Inscriptions and Runes for issuanceOn-chain data, no privacy

Off-chain Bitcoin value / Chaumian ecash​

Off-chain value with a Bitcoin peg; privacy via blind signatures rather than ZK.

ProtocolWhat it isKey difference from zkCoins
CashuChaumian ecash (blinded bearer tokens)Custodial — the mint holds the funds
FedimintFederated Chaumian ecashFederated custody (threshold of guardians)
ArkOff-chain Bitcoin via shared VTXOsNot asset/privacy focused; liquidity-provider dependent
Statechains / MercuryOff-chain transfer of UTXO ownershipRelies on a federation/entity; weak privacy

Confidential, but a different trust model​

ProtocolWhat it isKey difference from zkCoins
LiquidConfidential Transactions sidechainFederated (functionaries), not trustless
MimbleWimble (Grin / Beam)CT + cut-through, no persistent addressesOwn chain; CoinJoin-style privacy, no anonymity set
Shade (repo)Privacy DeFi on Secret NetworkPrivacy via TEE/SGX (trusted hardware), not ZK/CSV

Bitcoin privacy landscape (2025/2026)​

TechnologyPrivacy levelStatus
Shielded CSVFull against the public-chain observer; bounded counterparty residuals (D-17–D-19)
Silent Payments (BIP352)Receive-onlyNear production
PayJoin (BIP77/78)Send-privacyProduction
CoinJoinMedium (statistical)Under regulatory pressure
Lightning (BOLT12)Good (routing)Production

Shielded CSV is the most ambitious privacy solution for Bitcoin. Silent Payments are the pragmatic short-term choice; Shielded CSV is the long game on the Bitcoin · Shield · Trustless triangle.