Two ways to be private,
on one chain.
Nocturnal hides amounts, senders and recipients — and lets you choose how. Ring signatures over a fixed ring of 16, or zero-knowledge proofs over every note the chain has ever made. Both are private, both are permanent, and proof of work runs on the CPU you already own.
What it is
A privacy coin with two value pools, both permanent. In the ring pool, amounts are hidden by Pedersen commitments with Bulletproofs+ range proofs, senders by CLSAG ring signatures, and recipients by one-time stealth addresses. In the shielded pool, a spend is an Orchard zero-knowledge proof and hides among every note ever created. Proof of work is RandomX, designed for ordinary CPUs rather than specialised hardware.
This is not optional privacy. Zcash offers a choice between private and public, and picking public publishes a transaction's sender, recipient and amount for ever. Nocturnal's choice is between two private protocols. Nobody can opt out of privacy and nobody can leak by accident; what you are choosing is which anonymity model you trust.
The cryptography is deliberately not novel. The ring pool uses the
monero-oxide crates — Monero's reviewed construction — and the shielded pool uses
Zcash's orchard, so each half can be audited by comparison against a system that
has been attacked for years. What is new here is the chain around them, and that is the part
being tested.
Confidential amounts
Pedersen commitments and aggregated Bulletproofs+ in one pool; inside the proof in the other.
Sender ambiguity
A ring of exactly 16, so the ring size is not itself a fingerprint — or a nullifier that names nothing at all.
Unlinkable recipients
One-time stealth keys with subaddresses, or diversified Orchard addresses under one viewing key.
CPU mining
RandomX, 120-second target, ~1,000,000 NOCT asymptote — and the miner picks which pool its reward is paid into.
The two pools
Ring signatures LIVE
CLSAG over 16 ring members, Pedersen commitments, Bulletproofs+. Your spend hides among decoys drawn from the chain with a recency-matched distribution. Running on the testnet now.
zk proofs BUILT, NOT YET DEPLOYED
Orchard (Halo 2, no trusted setup) with a nullifier set and a note-commitment tree. Your spend hides among every note the chain has ever made rather than a ring of sixteen. Written, tested and in the open — it reaches the testnet with the next chain reset, because it changes consensus.
How the two fit together
A transaction picks which pool it spends from, and value can move between them in either direction. A payment that stays inside the shielded pool has no ring side at all: no inputs, no outputs, no range proof. A miner picks which pool its block reward is created in, so neither pool is the only door in — nobody has to cross merely to use the mechanism they prefer.
Each pool's supply is tracked publicly and neither may go below zero, so a flaw in one pool's cryptography cannot mint coins in the other. That containment is the reason for keeping two pools rather than one.
The cost is stated rather than hidden. The amount moving between pools is public, and only for those who move it: shielding an unusual amount and later unshielding the same one links the two. A payment that stays in one pool publishes nothing but its fee. The two pools commit to value in different groups — one over ed25519, one over Pallas — and the only quantity both sides can agree on is a plain integer, which is why that amount cannot be hidden without inventing a cross-curve proof this project will not write.
There is a pool, if you would rather not mine alone:
pool.nocturnalcoin.com
— PPLNS, no pool fee, payouts settle automatically once a block is buried. Point a
miner at it with
noct-miner --address <your testnet address> --pool https://pool.nocturnalcoin.com.
Where it stands
Stated plainly, because you should not have to dig for it.
- Not launched. This is a testnet. Coins have no value and the chain will be reset.
- Unaudited. Nineteen internal review passes and one independent model review found and fixed real bugs, including an 8.79-second denial of service and a fork-choice rule that disagreed with consensus. No professional audit has been commissioned.
- 50% premine. The planned mainnet genesis mints 500,000 NOCT to the founder, half the supply parameter, earmarked for an audit, community work, marketing and running costs. That is a stated intention with no mechanism yet enforcing it — argued in full, both ways, in the whitepaper.
The full internal security review is published in the repository, including the bugs found and the conclusions that later turned out to be wrong.