Assets held in encrypted notes
Balances consist of encrypted notes. Recipient wallets identify their own notes locally. Transfers do not publish plaintext amounts or private receiving addresses.
Mint and transfer an independent private asset on Bitcoin.
Public proofs. Private transfers.
Balances consist of encrypted notes. Recipient wallets identify their own notes locally. Transfers do not publish plaintext amounts or private receiving addresses.
Zero-knowledge proofs check ownership, note membership and value conservation. Public nullifiers prevent a note from being spent twice.
Bitcoin publishes and orders the data. Independent protocol verifiers replay the history to derive the same state, without a signing committee approving each transfer.
Independent private asset · No BTC redemption promise
Your BTC wallet pays fees. Your independent private wallet controls your assets.
Pays the minting fee and Bitcoin miner fees.
Connecting reads your BTC account. It does not create or restore private wallet keys.
A real Bitcoin Core test wallet for the local transaction flow.
An independent 24-word backup. Switching payment wallets does not change asset ownership.
Each mint creates exactly 1,000 tokens in your private wallet.
Generate the proof first, then review fees and confirm payment.
Bitcoin transactions and ciphertexts are public. Transfer values and recipient notes are protected by the privacy mechanism.
| Operation | Status | Payment wallet | Miner fee | Transaction ID |
|---|
The next stop for private assets.
The market is in development. Stay tuned.
Build new possibilities with privacy.
The launchpad is in development. Stay tuned.
From the Shielded Bitcoin research architecture
to an independent private asset on Bitcoin L1.
NOIRBIT-20 is a metaprotocol for an independent private asset on Bitcoin L1. Its token symbol is NOIR。NOIRBIT-20 的部署、铸造与转移均由单笔 OP_RETURN 交易承载。
Bitcoin validates the underlying transactions and provides data and ordering. NOIRBIT verifiers check zero-knowledge proofs and issuance rules to reconstruct asset state. Bitcoin miners do not enforce NOIR’s supply cap or privacy-proof rules.
NOIR is a newly issued asset. Minting fees are not BTC collateral. The protocol currently makes no BTC peg-in or redemption promise. Miner fees are separate; Deploy and Transfer carry no additional protocol fee.
Our primary reference is the paper by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin, 《Shielded Bitcoin: Private Transfers on the Bitcoin L1》↗ (2026-09-24), along with the authors’ Companion article ↗. NOIRBIT is an independent implementation. Citation does not imply participation, endorsement or an audit by the original authors.
Value is held in encrypted notes, with separate capabilities for spending, viewing incoming payments and recovering outgoing records.
The note tree, spent markers and historical roots follow Bitcoin block order. Nullifiers are bound to note positions.
The public payload is bound to proofs of valid inputs, spending authorization, value conservation and consistency of output recipient ciphertexts.
NOIRBIT-20 deploy, mint and transfer each use a single OP_RETURN transaction.
Our additions: Deploy 资产身份、固定批次 Mint、21,000,000 上限、5,000 sats 收费以及精简二进制编码 都是本项目新增规则,并非论文原有发行标准。
Publish the protocol name, token symbol, supply cap, mint size and suite digest. The public parameter package binds the network, fee script and verification keys. Asset identity is derived from the real Deploy transaction reference and activation occurs in its containing block.
NOIRBIT-20, the operation, asset ID, ciphertext and proof define each operation.
Deploy omits duplicate fee, fee_script, genesis, start and v fields. The suite and actual chain context still bind these rules; a backend cannot arbitrarily change them.
钱包加密收款票据并生成真实证明。付款交易公开支付 5,000 sats;验证器检查费用输出、证明、发行上限与重复请求,通过后追加票据。固定铸造数量 1,000 枚公开可见。
p / op / tickasset ID / fixed issuanceout / recover / proofThe wallet selects confirmed notes and a historical anchor, then proves ownership and value conservation locally. Nullifiers, new encrypted notes, recovery ciphertext and a proof are published on-chain; plaintext transfer amounts and private receiving addresses are not.
For example, sending 300 NOIR from a 1,000 NOIR note creates a 300 NOIR recipient note and a 700 NOIR change note. In a self-transfer both are yours, so the total remains 1,000 NOIR.
p / op / tick / idanchor / nfout / recover / proofBTC payment wallet Connect an extension such as UniSat, Xverse or OKX to sign Bitcoin fee transactions. Connecting a BTC wallet does not turn its keys into private asset keys.
Independent private wallet Create and separately back up a 24-word recovery phrase. You can then switch BTC payment wallets while keeping independent control of your private assets. The phrase or an unlockable encrypted backup, together with public chain history and proof parameters, can reconstruct your notes and balance.
Proofs are generated locally. Recipients use their own viewing capability to recognize notes; verifiers need only public data, not user spending keys.
Cryptography protects transfer values and private recipient notes. The carrier transaction’s BTC inputs, fee outputs, timing, asset ID, anchor, nullifier count and ciphertext bytes remain public. The fixed mint amount is also public; not all activity is hidden or unlinkable.
当前实现采用 Groth16 研究参数,This research suite uses Signet test assets. Independent security audit and live extension acceptance remain incomplete.Mainnet is not enabled. Production parameter setup and an independent security audit are not complete. Sender recovery ciphertext is bound to the payload, while the wallet checks its decryptability by reading it back. This differs from recipient-encryption consistency enforced inside the circuit.
Routine transfers have no signing committee. Groth16 setup still has trust assumptions; the system must not be described as having none.
PIPE: The research direction has no signing committee, but PIPE witness encryption and the paper’s native BTC entry and exit mechanism are not implemented. Verification of independent NOIR asset transfers does not mean PIPE is complete.
These are NOIRBIT research protocol notes. The suite pinned by each deployment defines its exact byte encoding.