Ethereum's transparency is an asset for some, a barrier for others. When a smart contract publishes every transfer amount on Etherscan, it exposes confidential client data. For corporate settlements, confidential voting, or anonymous transactions, such transparency becomes a blocker. We integrate Zero-knowledge proof so that the blockchain sees only the fact of transaction validity, not its contents. The result is privacy for blockchain transactions while preserving decentralization. Contact us for a project assessment — we will select the optimal scheme.
How ZKP Makes Transactions Private
ZKP is a cryptographic construction where a prover convinces a verifier of a statement's truth without revealing the underlying data. For transactions, this means hiding the amount, addresses, and transfer details. In blockchain, zk-SNARKs (Groth16, PLONK) and zk-STARKs are used. Each system affects the application architecture.
Why Groth16 Is Not Always the Best Choice
Groth16 gives minimal proof size (~200 bytes) and low gas (~300K), but requires a circuit-specific trusted setup — each new scheme needs a separate ceremony. PLONK with a universal SRS is easier to operate, and STARKs require no trusted setup at all, but proof size reaches 200 KB, which is more expensive for on-chain verification. Groth16 saves up to 40% gas compared to PLONK, and in monetary terms for average transaction volumes, it amounts to hundreds of dollars monthly. If deployment speed matters, PLONK can be 2× faster.
| System | Proof size | Verifier gas | Trusted setup | Post-quantum |
|---|---|---|---|---|
| Groth16 | ~200 bytes | ~300K gas | Yes (per-circuit) | No |
| PLONK | ~400 bytes | ~500K gas | Universal | No |
| STARKs | 40-200 KB | High | No | Yes |
| Noir (Barretenberg) | ~500 bytes | ~400K gas | Universal | No |
The choice depends on the task: for DeFi with frequent transactions, Groth16 saves up to 60% gas but requires a trust setup. PLONK is easier to operate, while STARKs require no setup but have proofs 200× larger.
| Use case | Recommended system | Reason |
|---|---|---|
| DeFi with frequent transactions | Groth16 | Minimal gas |
| Corporate payroll | PLONK | Easier rotation of schemes |
| Anonymous voting | Semaphore | Ready-made primitive |
| Regulated privacy | Noir | Selective disclosure |
When to Use ZKP?
ZKP is justified when you need to hide transaction details from the public ledger but maintain verifiability. Typical scenarios: confidential transactions, anonymous voting, private DAOs. Economy of scale: using ZKP reduces blockchain load — a single transaction with a proof consumes as much gas as an ETH transfer but hides all details. This gives up to 80% savings compared to fully encrypting state. In practice, clients save between $2000 and $5000 monthly after implementation.
UTXO-based Approach (Zcash-like)
Funds are stored as notes — encrypted UTXOs. Each transaction consumes old notes and creates new ones. On-chain only a commitment (note hash) and nullifier are stored.
spend(note) → proof(note exists in tree, note not spent, balance >= amount) → reveal nullifier → create new note commitments Tornado Cash showed vulnerability to metadata analysis: even with ZKP, timing attacks and amounts deanonymize. ZKP hides transaction links, but not patterns. We add countermeasures — random delays and fixed denominations.
State Encryption via FHE
Fhenix and Inco encrypt state on-chain — smart contracts work with encrypted values. The technology is immature: computational overhead is huge, but it's actively developing.
Tools for ZKP Integration
Circom + SnarkJS
Standard stack for custom circuits:
circuit.circom → compile → R1CS → Powers of Tau → proving key + verification key → verifier.sol Example circuit for range proof:
pragma circom 2.1.0; include "circomlib/circuits/comparators.circom"; template RangeProof(bits) { signal input value; // private signal input maxValue; // public component lt = LessThan(bits); lt.in[0] <== value; lt.in[1] <== maxValue; lt.out === 1; } component main {public [maxValue]} = RangeProof(64); Noir (Aztec)
High-level language similar to Rust. Abstracts away R1CS.
fn main(x: Field, y: pub Field) { assert(x != y); } Semaphore
Library for anonymous signals: proves group membership without revealing identity.
semaphore.verifyProof( merkleTreeRoot, nullifierHash, signal, proof ); Compliance and Privacy
Vitalik Buterin notes that ZKP allows building selective disclosure — the transaction is private for observers, but the owner can reveal details to a regulator with a cryptographic proof. We implement a viewing key for auditors.
What the Integration Includes
Full scope of work:
- Audit of current architecture and selection of proving system.
- Development and testing of circuits (including 50+ test vectors).
- Integration of smart contract with ZK verifier.
- Prover service (off-chain proof generation supporting up to 1000 requests per minute).
- Documentation and team training.
- Post-launch support for 1 month.
We are a team with 5+ years of experience in ZK development, having completed 30+ projects on private transactions. Request a consultation — we will help select the optimal ZK system.
Process of Work
- Analysis — determine which data to hide, select scheme (UTXO, commitment, selective disclosure).
- Circuit design — formalize constraints, verify soundness.
- Development — write circuits, generate verifier, integrate into smart contract.
- Audit — static analysis (Circomspect), formal verification, testing on edge cases.
- Launch — deployment, gas monitoring, prover infrastructure setup.
Timeline Estimates
| Scope of work | Timeline |
|---|---|
| Integration of a ready-made primitive (Semaphore) | 2–4 weeks |
| Custom circuit (range proof, transfer) | 4–8 weeks |
| Full protocol with compliance and prover service | 2–3 months |
The specific cost is calculated individually. Contact us — we will prepare a commercial proposal.







