Stellar Private Payments tests counterparty privacy through a shielded pool

Stellar Private Payments is a Nethermind-built developer preview: a shared shielded pool hides counterparties and transfer amounts inside the pool while publishing a zero-knowledge proof and nullifier. Deposits and withdrawals remain visible; the contracts are unaudited and not approved for mainnet.

Stellar Private Payments tests counterparty privacy through a shielded pool

Stellar introduced a Developer Preview of Stellar Private Payments, a privacy primitive built by Nethermind. The contract is live on testnet, but SDF explicitly says it is still unaudited and has not been approved for mainnet. Developers are being invited to test the design before it is production-ready.

SPP uses a shared shielded pool. A deposit is visible when funds enter the pool, after which the user holds private state represented by commitments in a Merkle tree. Transfers between participants happen inside the pool, while the public ledger does not reveal who paid whom or the amount moved between them.

Every operation that spends notes publishes a zero-knowledge proof showing that the notes are valid and owned by the spender without revealing which notes they are. A nullifier is published on-chain at the same time to prevent the same state from being spent twice. When value is withdrawn, the amount becomes public again at the edge of the pool.

SDF summarizes the model as public in, private middle, public out. Verification uses Groth16 with cryptographic host functions introduced in Protocol 25 and Protocol 26. The key status remains developer preview: the privacy mechanism works on testnet but should not be treated as production-ready until audits and mainnet approval are complete.

Trust 80 Importance 64 Noise 8% Related symbol Informational material, not financial advice.