The idea in one paragraph
A zero-knowledge proof (ZKP) is a way for one party to convince another that a statement is true โ "this transaction is valid", "I am over 18", "these funds were not stolen" โ while revealing nothing beyond the truth of the statement. The verifier learns that, not why. On a blockchain, that means a network can check a transaction follows the rules without seeing the sender, the receiver or the amount.
Two families dominate: zk-SNARKs (small proofs, fast verification, some constructions need a trusted setup) and zk-STARKs (larger proofs, no trusted setup, quantum-resistant assumptions). Modern systems like Halo 2 remove the trusted setup from SNARKs as well.
Two uses that get confused
The same technology is used for opposite purposes, and "zk" in a project's name does not tell you which:
| Use | What the proof does | Privacy result |
|---|---|---|
| Shielded transactions (Zcash Orchard/Sapling, Railgun, Aztec) | Proves a transaction is valid while sender, receiver and amount are encrypted | Real privacy, inside the shielded pool |
| Validity rollups (zkSync, Starknet, Scroll, Polygon zkEVM, Linea) | Proves a batch of thousands of transactions was executed correctly, so Ethereum need not re-execute | None by default โ transactions are public; the proof is for scaling and cost |
| Identity credentials (proof of age, proof of residency, proof of non-sanctioned status) | Proves an attribute from a credential without revealing the credential | Selective disclosure โ the promising alternative to uploading a passport |
| Proof of reserves / solvency | An exchange proves it holds enough assets to cover liabilities without revealing addresses or customer balances | Transparency for users without exposing them |
If a project says "zk" and means the second row, it is not a privacy technology in the sense that matters here.
Where the privacy is real today
Zcash shielded pool. The oldest production deployment. Inside the Orchard pool, transactions reveal nothing but their existence. The weakness is at the edges: transparent addresses still exist, and the transfer into the pool is visible. The Zcash page and the Monero vs Zcash comparison cover the practical differences; SyntheticSwap supports BTC โ ZEC and ZEC โ USDT (ERC-20) among other pairs โ check the pair page for the address type accepted, then shield in your wallet.
Ethereum privacy layers. Railgun (a smart-contract privacy system on Ethereum and other EVM chains) and Aztec (a privacy-focused L2 rolling out in stages) bring shielded balances to EVM assets. They are real but require gas, a compatible wallet and, in Railgun's case, screening of deposits against known-illicit lists.
Monero, for contrast, does not use zero-knowledge proofs in the SNARK sense; it uses ring signatures, stealth addresses and Bulletproofs range proofs (which are zero-knowledge proofs of amount validity). The practical result โ everything hidden, by default, for every user โ is stronger than opt-in shielding, because the anonymity set is the whole chain. The privacy coins guide sets the three side by side.
Zero-knowledge identity: the alternative to KYC files
The most consequential future use is not on-chain at all. A ZK credential lets you prove to a service that you are over 18, or a resident of a permitted country, or not on a sanctions list, without giving the service your passport โ and without the credential issuer learning where you used it. The service verifies a proof; it stores no document, no face, no date of birth.
This is the technology that could make the choice between "full KYC file" and "no identity at all" less binary. Pilots exist (EU digital identity wallet specifications, several national schemes, a number of crypto-native credential projects); production adoption by exchanges is still limited. Until it arrives, the practical way to avoid the file is the account-free model: the exchange never needs a proof of anything, because it never needs to know who you are.
What zero-knowledge does not fix
- Network privacy. A shielded transaction still broadcasts from an IP address. Tor or a VPN remains necessary.
- Endpoint privacy. A light wallet that asks a server which shielded notes belong to you leaks your viewing pattern to that server. Own node or a trusted one.
- Transparent edges. Money entering a shielded pool from an identified transparent address is identified at entry. Fund the pool from a fresh address.
- Rollup privacy. A validity rollup is as public as Ethereum. Do not assume "zk" means hidden.
Frequently asked questions
Is Zcash more private than Monero because it uses ZKPs? Within the shielded pool, the cryptographic hiding is at least as strong. In practice Monero is more private for most users because there is no transparent mode to fall into and the anonymity set is everyone.
Are zk-rollups private? No, by default. Some (Aztec) are built for privacy; most (zkSync, Starknet, Scroll) are built for throughput and publish all transaction data.
Can I swap into Zcash shielded directly? Payouts generally go to a transparent address; you shield in your own wallet afterwards. Check the pair page for the accepted address type.
Does a trusted setup make Zcash unsafe? Zcash's Orchard pool uses Halo 2, which has no trusted setup. Older Sapling proofs used a multi-party ceremony that would require every participant to collude to be compromised.
Where can I use ZK identity today? Mostly in pilots. For exchanges, the practical alternative to uploading a document remains not being asked for one โ the model the no-KYC explainer describes.
BTC โ ZEC
ZEC โ USDT (ERC-20)
ETH โ XMR