A confidential transaction hides the amount of a payment. We covered the cryptography behind that recently: Pedersen commitments seal the value, Bulletproof range proofs keep it sound, and a Schnorr kernel proves the transaction balances. What was missing was the on-ramp and off-ramp. You could move value privately once it was already private, but there was no permissionless way to make your own plaintext QBC private in the first place, or to bring it back out.
That gap is now closed. There are three operations, all permissionless, all non-custodial, and all authorized by post-quantum signatures: shield, confidential transfer, and unshield. Together they let anyone privatize their own balance, transact with amounts hidden, and cash out to any address, with the mathematics rather than an operator guaranteeing that nothing is created or destroyed along the way.
Shield: make your balance private
Shielding takes a normal, public UTXO and turns it into a confidential note.
When you shield, your wallet does three things. First it picks a fresh secret blinding
factor and builds a Pedersen commitment to the UTXO's value: C = v times H plus r times G.
That commitment is what goes on chain in place of a number. Second, it builds a small
zero-knowledge proof, an "opens to V" proof, that the commitment commits to exactly the
value of the UTXO being spent and nothing else. Third, it signs the whole thing with your
post-quantum (ML-DSA-87) key to authorize spending the plaintext UTXO.
The chain then verifies all of it before anything moves: the Dilithium signature against the key registered for that address, and the open proof against the public value of the UTXO. Only if both check out does it burn the plaintext UTXO and mint the confidential note. Because the note is proven to commit to exactly the value burned, shielding can neither create nor destroy QBC. Plaintext in equals private out.
The "opens to V" proof is worth a second look, because it is what makes shielding sound.
Subtract V times H from the commitment C and, if the commitment really is to V, what
remains is r times G, a commitment to zero value with a blinding only you know. A Schnorr
signature over that point proves you know r, which proves the commitment is to V and not
to some larger amount. No range proof games, no trusted setup, just a short proof the chain
checks in microseconds.
Confidential transfer: move with the amount hidden
Once value is in the confidential pool it can move privately. A confidential transfer consumes existing notes and creates new ones, with every output carrying a Bulletproof range proof and the whole transaction balanced by a Schnorr kernel. An observer sees commitments, proofs, and a signature, never who paid whom how much. This is the part we detailed previously, and it is unchanged: the new work is the shield and unshield that bracket it.
Unshield: cash out to any address
Unshielding is the mirror of shielding. You reveal the value of a note and provide the same "opens to V" proof for it. That proof does double duty: it fixes the value being revealed, and it authorizes the spend, because only the owner of the note knows the blinding needed to produce it. The chain verifies the proof, burns the note, and mints a plaintext UTXO of that value to whatever destination you choose. Private in equals plaintext out.
Spending a note removes it, so a note cannot be unshielded twice, and it cannot be both transferred and unshielded. Double-spends of confidential outputs are prevented the same way they are for ordinary outputs: the output is consumed.
Where the work happens, and why it is trustworthy
All of the heavy cryptography, the elliptic-curve commitments, the range proofs, and the open and kernel proofs, runs natively in the protocol on fixed generators. The wallet that builds a proof and the chain that verifies it use the exact same generators, so they agree byte for byte, and every validator checks every proof independently and deterministically. There is no trusted setup anywhere in the system, and there is no party that can quietly mint or seize confidential value. The invariant is enforced by math that anyone can run.
It is also worth being precise about custody. The blinding factor that hides your amount is generated in your browser and never leaves it. The relay that broadcasts your transaction verifies your proofs and pays the outer transaction fee, but it never sees a secret and cannot move your funds. Authorization is your post-quantum signature and your knowledge of the blinding, nothing else.
Built into the wallet
All three operations are available directly in the native wallet. There is a confidential panel with a clear choice: Shield to make a balance private, or Unshield to bring a note back to plaintext, alongside an explanation of what each does. Your private notes are kept in your own browser, since only you should ever hold the blindings that unlock them. The same wallet signs everything with the post-quantum key it generated for you, so a confidential payment is quantum-resistant from the moment you create the note to the moment the chain finalizes it.
What this adds up to
QBC now offers the full confidential lifecycle as a first-class, permissionless feature: privatize your own QBC, transact with the amount hidden, and cash out, with post-quantum signatures on every step and zero-knowledge proofs guaranteeing soundness. No custodian, no trusted setup, no separate mixer to trust. Public by default, private by choice, and the choice is yours to make on every transaction.