← All posts
10 min read

Shield, transfer, unshield: permissionless confidential payments

Confidential transactions on QBC are now permissionless end to end: shield QBC into a private note, transact with amounts hidden, and unshield back out. All non-custodial, all authorized by post-quantum signatures.

A confidential transaction hides the amount of a payment. We covered the cryptography behind that recently: Pedersen commitments seal the value, Bulletproof range proofs keep it sound, and a Schnorr kernel proves the transaction balances. What was missing was the on-ramp and off-ramp. You could move value privately once it was already private, but there was no permissionless way to make your own plaintext QBC private in the first place, or to bring it back out.

That gap is now closed. There are three operations, all permissionless, all non-custodial, and all authorized by post-quantum signatures: shield, confidential transfer, and unshield. Together they let anyone privatize their own balance, transact with amounts hidden, and cash out to any address, with the mathematics rather than an operator guaranteeing that nothing is created or destroyed along the way.

Shield: make your balance private

Shielding takes a normal, public UTXO and turns it into a confidential note.

When you shield, your wallet does three things. First it picks a fresh secret blinding factor and builds a Pedersen commitment to the UTXO's value: C = v times H plus r times G. That commitment is what goes on chain in place of a number. Second, it builds a small zero-knowledge proof, an "opens to V" proof, that the commitment commits to exactly the value of the UTXO being spent and nothing else. Third, it signs the whole thing with your post-quantum (ML-DSA-87) key to authorize spending the plaintext UTXO.

The chain then verifies all of it before anything moves: the Dilithium signature against the key registered for that address, and the open proof against the public value of the UTXO. Only if both check out does it burn the plaintext UTXO and mint the confidential note. Because the note is proven to commit to exactly the value burned, shielding can neither create nor destroy QBC. Plaintext in equals private out.

The "opens to V" proof is worth a second look, because it is what makes shielding sound. Subtract V times H from the commitment C and, if the commitment really is to V, what remains is r times G, a commitment to zero value with a blinding only you know. A Schnorr signature over that point proves you know r, which proves the commitment is to V and not to some larger amount. No range proof games, no trusted setup, just a short proof the chain checks in microseconds.

Confidential transfer: move with the amount hidden

Once value is in the confidential pool it can move privately. A confidential transfer consumes existing notes and creates new ones, with every output carrying a Bulletproof range proof and the whole transaction balanced by a Schnorr kernel. An observer sees commitments, proofs, and a signature, never who paid whom how much. This is the part we detailed previously, and it is unchanged: the new work is the shield and unshield that bracket it.

Unshield: cash out to any address

Unshielding is the mirror of shielding. You reveal the value of a note and provide the same "opens to V" proof for it. That proof does double duty: it fixes the value being revealed, and it authorizes the spend, because only the owner of the note knows the blinding needed to produce it. The chain verifies the proof, burns the note, and mints a plaintext UTXO of that value to whatever destination you choose. Private in equals plaintext out.

Spending a note removes it, so a note cannot be unshielded twice, and it cannot be both transferred and unshielded. Double-spends of confidential outputs are prevented the same way they are for ordinary outputs: the output is consumed.

Where the work happens, and why it is trustworthy

All of the heavy cryptography, the elliptic-curve commitments, the range proofs, and the open and kernel proofs, runs natively in the protocol on fixed generators. The wallet that builds a proof and the chain that verifies it use the exact same generators, so they agree byte for byte, and every validator checks every proof independently and deterministically. There is no trusted setup anywhere in the system, and there is no party that can quietly mint or seize confidential value. The invariant is enforced by math that anyone can run.

It is also worth being precise about custody. The blinding factor that hides your amount is generated in your browser and never leaves it. The relay that broadcasts your transaction verifies your proofs and pays the outer transaction fee, but it never sees a secret and cannot move your funds. Authorization is your post-quantum signature and your knowledge of the blinding, nothing else.

Built into the wallet

All three operations are available directly in the native wallet. There is a confidential panel with a clear choice: Shield to make a balance private, or Unshield to bring a note back to plaintext, alongside an explanation of what each does. Your private notes are kept in your own browser, since only you should ever hold the blindings that unlock them. The same wallet signs everything with the post-quantum key it generated for you, so a confidential payment is quantum-resistant from the moment you create the note to the moment the chain finalizes it.

What this adds up to

QBC now offers the full confidential lifecycle as a first-class, permissionless feature: privatize your own QBC, transact with the amount hidden, and cash out, with post-quantum signatures on every step and zero-knowledge proofs guaranteeing soundness. No custodian, no trusted setup, no separate mixer to trust. Public by default, private by choice, and the choice is yours to make on every transaction.

Further reading

ShareXLinkedIn

Written by

A
Ash Brown@blockartica
Founder, SusyLabs / QuantumAI Blockchain

Building the post-quantum AI-native L1 with permissionless on-chain training cycles. Writes about consensus, attestation, and the gap between what ships and what's claimed.

Related posts

10 min read

A post-quantum cold wallet, built in private

A long look at the QV desktop wallet: a post-quantum cold-storage wallet that holds Bitcoin, Lightning and QBC behind one recovery phrase. This is a private build, not a public release, and this post explains what is in it and how we harden it before anyone trusts it with value.