A private payment on QBC is live and you can use it now. You take ordinary QBC, shield it into a private note, move it with the amount sealed, and cash it back out to any address. It is non-custodial, the proofs are generated on your own device, and nobody, including us, can see the amounts.
What makes this different from privacy features on other chains is the threat model. We did not build privacy that works until a quantum computer arrives. We built privacy designed to outlast that day.
Three things have to hold, and all three are post-quantum
A confidential payment has to get three separate things right, and each rests on a different assumption. On QBC all three are quantum-resistant.
- The amount stays secret. Values are sealed inside commitments. Nothing on chain reveals a number, and the hiding does not depend on any assumption a quantum computer could break.
- Only you can spend. Every move is authorized by a lattice signature, CRYSTALS-Dilithium-5 (ML-DSA-87, NIST Level 5), the post-quantum standard.
- No one can print coins. The proof that a transfer balances, that nothing is created from nothing, is a hash-based zero-knowledge STARK. Its only assumption is a collision-resistant hash, which Shor's algorithm does not touch. There is no trusted setup.
Most confidential systems get the first two right and leave the third resting on the discrete logarithm assumption, which a large quantum computer breaks. That is the gap we closed: on QBC the accounting itself is quantum-secure, not just the secrecy of the amount.
How to use it
In the wallet there is a private panel with three actions.
- Shield. Pick a normal balance and move it into a private note. The proof that the note holds exactly that value is generated in your browser.
- Transfer. Spend two notes into two, sending an amount to someone with the value hidden, and keep the change as a new private note. You share three short values with the recipient privately, and they hold a spendable note that reveals nothing on chain.
- Unshield. Cash a note back out to any address. The proof is bound to that destination, so a relayer cannot redirect it in transit.
Your amounts and your blinding factors never leave your device. A relayer pays the network fee and submits the transaction, but it only ever sees commitments and an opaque proof, and it cannot move or redirect your funds. The same flow is available from the command-line wallet for anyone who prefers it.
Proven, not just evidenced
There is a distinction we hold ourselves to. Hiding an amount is one thing; being able to prove, rigorously, that the proof itself leaks nothing is another. Our live private payments now run on a proving system whose zero-knowledge is a property of the system itself, so the amount-hiding is a guarantee of the construction rather than an argument we made on top of it. It was deployed only after an independent review, first into an isolated pool where no value was at risk, then promoted to carry real value once it had been exercised in consensus.
We are also candid about what remains open. A complete formal proof for the earlier construction is work we have planned and published, and we invite scrutiny rather than asking for trust.
Open for review
Privacy you cannot inspect is privacy you have to take on faith, which is the opposite of the point. So the cryptography is public. The circuits, the verifier, the prover, the test vectors, and the empirical tests are available for anyone to read and reproduce, alongside the paper that describes the construction and its security analysis:
- Paper: the post-quantum confidential STARK construction, linked from the research page at susylabs.com.
- Code and tests: https://github.com/QuantumAI-Blockchain/qbc-confidential-zk
Public by default, private by choice, with the mathematics rather than a custodian doing the work, and built to hold against the machine that breaks everything else.