Two kinds of address
Transparent addresses (starting with t) work like Bitcoin: sender, receiver and amount are all visible to anyone. Shielded addresses keep those details encrypted on chain. Modern wallets hand out a unified address (starting with u) that bundles both kinds so the sender's wallet can pick the private route.
What a shielded payment hides
Inside a pool, a payment spends old encrypted "notes" and creates new ones. A zero-knowledge proof convinces every node the maths adds up and nothing is spent twice, without revealing who paid whom or how much.
What still shows
That a transaction happened, roughly when, its fee, how many inputs and outputs it has, and any value crossing between the transparent side and a shielded pool. Moving coins in and straight back out with the same amount can be linked by timing and size.
Sprout, Sapling, Orchard
Sprout (2016) was the first pool and is now closed to new deposits. Sapling (2018) made proofs fast enough for phones. Orchard (2022) uses the Halo 2 proof system, which needs no trusted setup ceremony.
Ironwood
The newest pool, added in a 2026 network upgrade. Funds leaving Orchard now pass through a turnstile into Ironwood, so the total in each pool can be checked and a hidden counterfeit could not keep circulating unseen.
Viewing keys
A shielded wallet can export a read-only viewing key. Whoever holds it can see that wallet's incoming (and, with a full key, outgoing) payments but cannot spend anything. It is how auditors, accountants or exchanges can be given visibility on your terms.
Turnstiles and the supply
Every time value crosses into or out of a shielded pool, the amount is public. Nodes track a running balance for each pool and refuse any block that would push one below zero. That is where the pool totals above come from.
The lockbox
Since late 2024 part of each block reward goes to a protocol lockbox for future development funding rather than to a person. It is neither ordinary transparent coins nor shielded, so it is listed on its own.
Estimate
- Logical actions
- —
- Fee
- —
- Fee in USD
- —
- Expected wait
- —
fee = 5,000 zatoshi × max(2, actions)
actions = max(t in, t out) + max(Sapling spends, outputs) + Orchard actions
wait = confirmations × live average block time