How zipcoin works

Everything on this site runs on Ethereum mainnet. No accounts, no custody, no server-side keys to your coins. This page is written for people who want to know exactly what happens when they press a button.

What is zipcoin

In Snowmoon, Vitalik Buterin's novel set in the country of Veridia, the zipcoin is money. Payments are fully anonymized, people burn zipcoins to make a message worth reading, and sales tax flows to the government in real time.

$ZC is that currency, shipped as an ERC-20 on Ethereum. It launched on Stockereum with a fixed supply of 1,000,000,000, all liquidity in a single Uniswap v4 position owned by the launch hook, with no code path that can shrink it; no mint, no owner.

Around it, four verbs: zip (put coins, or ETH, into a privacy pool), unzip (take them out somewhere unlinked, including into a zk.money account on Aztec), speak (burn coins to publish a message that cannot be deleted), and knock (burn at someone's door, with a gift if you like). Every verb works from a zipped note, so none of them has to say who you are.

Zip: ZC or ETH

/zip deposits into a Privacy Pool and gives you a note: a claim on that amount that only your zip key can spend. Two pools:

ZC, in the zipcoin pool. Our own deployment of 0xbow's Privacy Pools contracts. Deposits are approved into the association set by our postman after a short delay, usually a few minutes. No screening beyond a blocklist; the pool is small and young, so read what is private below.

ETH, DAI, USDC or USDT, in 0xbow's pools. The same page can deposit straight into 0xbow's canonical mainnet pools: the ETH pool is the largest privacy pool on Ethereum (thousands of deposits); the USDC and USDT pools hold millions. It is their contract, their screening, their vetting fee; approval usually takes a few hours. We are only the front door, and afterwards a processooor: their pool lets any contract spend a note as long as the proof was built for that contract. Minimums are theirs: 0.01 ETH, 250 DAI, 25 USDC or USDT.

No ZC yet? Type an amount and buy & zip with ETH in one transaction. Deposits are public, like every deposit into every privacy pool; what stays private is where the note goes afterwards. Unapproved deposits can always be pulled back to the depositor (ragequit), approved or not.

Unzip: to an address, or to a zk.money tag

/unzip spends a note. Your browser builds a zero-knowledge proof that the note is yours and sits in the approved set, without saying which deposit it came from. Our relayer submits it and pays the gas, so the receiving address never has to hold ETH or touch your wallet. The recipient, the fee and everything else the transaction does are sealed inside the proof (the context): the relayer cannot redirect a single wei.

To an address. Type a fresh address or an ENS name. ZC notes arrive as ZC, ETH notes as ETH.

To a zk.money tag. Type name.zk.money. Your browser resolves the tag through zk.money's own ENS resolver and gets a fresh, single-use deposit address; only that address goes on chain, never the resolver's proof, so the recipient's Aztec account stays unlinked. The contract then sells the note for DAI on Uniswap and pays the address; zk.money's relayer credits the private balance within minutes. From a ZC note this goes through ZipTeller; from an ETH note through ZipTellerEth; from a DAI, USDC or USDT note through ZipTellerStable (DAI is paid as itself, no swap at all; USDC and USDT take one 0.01% hop). Private ETH or private stablecoins on Ethereum become private dollars on Aztec in one proof. Limits are zk.money's: DAI only, 1 to 2,500 DAI per payment, a shared daily cap. The page refuses anything outside them rather than let a payment sit uncredited.

Speak: burn to be heard

/speak burns zipcoins to publish a message of up to 280 bytes, optionally addressed with an envelope (“to: someone who ate at Beautiful Plants”). Burned coins go to 0x…dEaD and are gone; the message lives in the transaction log forever and in the book. The bigger the burn, the louder.

The floor is about $10 of ZC at today's price (the contracts themselves accept 1,000 ZC). Three ways to pay:

Public, from your wallet: your address signs the message. Anonymous, from a zipped ZC note: the book shows “anonymous” and nobody can tell which deposit paid. If you have no note yet, buy, zip & speak does it in one click: one transaction buys and zips the coins, the page waits for the approval, and the message speaks itself the moment the note is spendable. You can close the tab; the word is kept in your browser. From ETH, from a note in 0xbow's pool: the ETH buys zipcoins on their own market (paying the sales tax like any trade) and burns them with your message through the Doorstep. The book shows “anonymous, from ETH”: someone out of Ethereum's largest anonymity set.

Knock: the Doorstep

Snowmoon, ch. 20: burning zipcoins at someone's doorstep is how you prove you are someone to talk to. On /speak, add a door: an ENS name or an address. The burn is recorded at that door, and every door has a page, /door/vitalik.eth for example, collecting everything ever burned there.

Gifts. You can leave coins at the door as well: they land in that address, and if you knocked anonymously nobody knows who from. The contract requires the burn to be at least a tenth of the gift, so nobody can use doors as a free transfer. From an ETH note, the gift is left in ETH.

Farcaster. Share any cast to the zipcoin mini app and knock at its author's door in one tap; people who added the app are buzzed when someone knocks at theirs.

The bell: a letter for every knock

Every door has a bell. When someone burns at your address or ENS name, the bell writes you a letter: the words, the burn, the gift, the link to the word's page. It goes to your wallet's mailbox at <your address>@ethermail.io, which every Ethereum address has by design (claim it once at ethermail.io and everything ever sent is waiting), and to the email record of your ENS name if you published one. Public speakers get a receipt with their word's page, at most one a day. Every letter carries a link that stops them for good.

The bell also lives on XMTP as bell.zipbook.eth, for wallets that have messaging: message it door to see what has been burned at yours, today for the loudest words. The bell never mentions zips or unzips, and never says who knocked when the knock was anonymous, because it does not know.

Your zip key

Your notes are derived from a 12-word phrase, the zip key. On this site it is derived in your browser from a wallet signature, or you can paste a phrase. It never leaves the browser; the server only ever sees proofs and public events.

The derivation is the one 0xbow's SDK uses, so the phrase is portable: a Privacy Pools recovery phrase shows its ETH notes here, and a zipcoin phrase works in any Privacy Pools tooling. One key, two pools. Lose the phrase and the notes are gone; nobody, including us, can recover them.

What is private, and what is not

Public: every deposit (who zipped how much, into which pool), every burn and its message, every door and gift, every withdrawal's destination and amount, and the relayer's address on every relayed transaction.

Private: the link between a deposit and what its note later did. A withdrawal proves “one of the approved deposits in this pool”, nothing more. How private that is depends on the crowd: the ZC pool is small (dozens of notes at the time of writing), so a spend shortly after a deposit of about the same size is easy to pair by timing and amount. 0xbow's ETH pool hides you among thousands of screened deposits, at the price of their hours-long vetting. Waiting longer, spending different amounts, and more people zipping all make the crowd thicker.

The relayer sees your request (the proof, the recipient, your IP) but never your coins or your key, and the proof stops it from changing anything. zk.money's resolver sees the payer's IP, the tag and the amount. Our servers do not log lookups of tags.

Fees and where they go

Sales tax. Stockereum charges 1% per swap; 0.5% of volume reaches the zipcoin treasury in ETH, in real time, forever. Half is kept for buybacks and burns, half funds prizes, gifts and running costs; the books show every movement. Every ETH-note burn and every tag payment routes through the ZC market, so they pay the tax like any trade.

Vetting fee, 0.5% of each zip. Into the zipcoin pool, kept by our Entrypoint; into 0xbow's pool, theirs.

Relay fee, 1% of what a note spends, paid to the relayer out of the note in the note's own asset. It covers mainnet gas; the treasury subsidises part of it within a daily budget, and when that budget is spent the minimum amount rises so the fee covers gas. For ETH notes the rate adapts upward (up to the pools' 10% cap) when the note is too small for 1% to pay for gas; the page shows the exact figure before you prove anything.

Nothing else. No fee on speaking beyond the burn itself, none on gifts, none on tag payments beyond the swap.

The book, and @zipcoinbook

Everything ever burned to speak is the book: a page per day in reading order, and a front page that ranks by burn with time decay, so today's words rise over yesterday's. Every word has its own page and card, and can be echoed: a burn in reply, with or without text, that lifts the original. Echoes are the book's upvotes, and they cost something.

@zipcoinbook posts every burn above the floor to X, automatically: the message, who (or “anonymous”), the burn, the door. Team wallets are marked. It never posts zips or unzips, since their timing would help link deposits to withdrawals; links, handles and addresses in messages are stripped, and anything that looks like a scam or personal data waits for a human.

Contracts

All ours are verified on Etherscan, have no owner, and hold nothing between calls. Each of the spending contracts is a Privacy Pools processooor: the pool only checks that the caller is the contract named in the proof, and the contract decides what the coins do.

$ZC
The token. Fixed supply, no mint, no owner.
Entrypoint
Our deployment of 0xbow's Entrypoint (proxy). Deposits, association-set roots, relayed withdrawals.
ZC pool
ZipBroadcaster
Burn to speak, publicly or from a ZC note.
ZipDoorstep
Knock at a door with an optional gift; burn ≥ a tenth of the gift.
ZipTeller
Pay a zk.money tag in DAI from a ZC note.
ZipTellerEth
Pay a zk.money tag in DAI from an ETH note in 0xbow's pool.
ZipHearth
Speak or knock from an ETH note in 0xbow's pool; gift in ETH, burn in ZC.
ZipTellerStable (DAI)
Pay a zk.money tag from a DAI note in 0xbow's DAI pool, no swap.
ZipTellerStable (USDC)
Pay a zk.money tag from a USDC note, one 0.01% hop to DAI.
ZipTellerStable (USDT)
Pay a zk.money tag from a USDT note, one 0.01% hop to DAI.
ZipChanger
A ZC note delivered as ETH to a bound address: unzip as ETH; funds zkAPI clients. Experimental.
0xbow Entrypoint
0xbow's canonical mainnet Entrypoint. Not ours; we deposit through it and spend from its pool.
0xbow ETH pool
0xbow's canonical ETH Privacy Pool.
Withdrawal verifier
Groth16 verifier from 0xbow's trusted setup; secures both pools.
Ragequit verifier
Groth16 verifier from 0xbow's trusted setup.
Entrypoint implementation
0xbow's audited implementation behind our proxy.

Source: github.com/zipcoincash/zipcoin (our contracts and deployments) on top of privacy-pools-core (Apache-2.0). Proofs are built in your browser with 0xbow's SDK and checked by the same verifiers that secure their pool. Nobody on the zipcoin side can forge a proof.

For agents

Everything on this site is scriptable: npm i -g @zipcoin/agent gives a zipcoin CLI (speak, knock, zip, notes, unzip, pay a tag, read the book) and npx @zipcoin/mcp exposes the same verbs as MCP tools. Proofs are built locally; the same relayer and contracts as the site. The why and the manual: /agents.

Works with zkAPI (experimental)

zkAPI (Open Anonymity Project, with the Ethereum Foundation's dAI team) sells private AI credits: you deposit ETH into a vault on mainnet and spend it with zero-knowledge proofs, so the AI provider never learns who pays. The deposit itself is a public transaction from an address, and that is where zipcoin fits: fund the zkAPI client's address from a note, so the address that buys the credits has no history. On /unzip, send an ETH note to the funding address your zkapi-clientd shows; or send a ZC note there as ETH (Receive as ETH, through ZipChanger: the ZC is sold on zipcoin's market, unwrapped, and the ETH goes straight to the address). The client then deposits into the vault itself; its note secret never leaves your machine. Agents: zipcoin ai fund 0.02.

Experimental, and not ours: zkAPI notes expire after 30 days and the balance then goes to their operator; their vault owner can pause deposits and closes; their trusted setup is single-party and unaudited (their words); and the vault deposit costs about 6.7M gas, which the client pays. Keep amounts small. We have no partnership with zkAPI or the Ethereum Foundation; this simply works with their public contract.

Risks

Our contracts are unaudited. They are short, verified, and tested against mainnet forks, but nobody outside the team has reviewed them yet. 0xbow's pool, Entrypoint implementation and verifiers are audited; our Entrypoint proxy is upgradeable by the treasury key, which is a trust assumption until it is put behind a timelock.

Privacy is statistical. See above: a young pool and hasty timing leak more than the cryptography does.

Prices move. Tag payments and ETH-note burns swap on the open market; the proof locks in a minimum you saw on screen, and the transaction fails rather than pay less. zk.money and 0xbow are other people's systems with their own rules, limits and screening; we use them as designed, and cannot change them.

Your key is yours. No recovery, no support line that can help.

FAQ

Do I need ETH to unzip or to speak from a note? No. The relayer pays the gas and takes its fee from the note.

How long until a note is spendable? ZC: minutes. ETH in 0xbow's pool: usually a few hours, at their discretion.

Can zipcoin see my notes? No. They exist only as commitments on chain and as a phrase in your browser.

Can the relayer steal or reroute? No. Recipient, amounts and message are hashed into the proof; changing any of them makes the proof invalid. It can refuse to relay, in which case you can relay yourself or ragequit.

Where do I buy ZC? On Uniswap, or with ETH directly on /zip and /speak.

Is this affiliated with Vitalik Buterin, 0xbow or Aztec? No. Snowmoon is his novel; Privacy Pools and zk.money are their protocols; we build on them as anyone may.