About Nocturnal
Why it exists, what it borrows, and what it does not claim.
Why another privacy coin
Most chains are transparent ledgers: every amount and every counterparty is permanently
public. That is a poor property for money. Monero solved it well and Zcash solved it
differently, and Nocturnal does not claim to improve on either one's cryptography. It reuses
both — the monero-oxide crates and Zcash's orchard — and builds a
smaller, more readable chain around them in Rust.
Carrying both is the one design decision here that is genuinely a decision. Ring signatures and zero-knowledge proofs make different bets: a ring of sixteen is cheap, well understood and has a bounded anonymity set, while a note-commitment tree hides a spend among everything ever created but rests on a much larger pile of mathematics. Rather than pick for you, Nocturnal runs both permanently, tracks each pool's supply separately so a flaw in one cannot mint coins in the other, and states what moving between them costs.
The goal is a codebase one reviewer can hold in their head. The consensus layer is a few thousand lines, each module documents the reasoning behind it, and the security review is published in full rather than summarised.
What it borrows
Cryptographic primitives are never hand-rolled here. The chain depends on:
monero-clsagfor CLSAG ring signatures and key imagesmonero-bulletproofsfor Bulletproofs+ range proofsmonero-primitivesandmonero-generatorsfor commitments and generatorscurve25519-dalekfor the ring pool's group arithmeticorchardfor the shielded pool: the Halo 2 Action circuit, note encryption, nullifiers and ZIP-32 key derivationincrementalmerkletreefor the note-commitment tree, at the same versionorcharditself uses- RandomX for proof of work, via the reference C++ implementation
Hashing is original Keccak-256, not NIST SHA-3. That is the same choice Monero made, and a distinction that silently breaks compatibility if you get it wrong.
Two things about the shielded side are worth naming. There is no trusted setup: Halo 2
needs no ceremony whose participants have to be believed, unlike the Groth16 construction
Sapling uses. And the circuit is pinned to the fixed post-NU6 version — every
orchard release up to 0.13.1 is withdrawn because the original Action circuit was
unsound, and the wire format carries no circuit field at all, so a transaction cannot ask for
a different one.
What it does not claim
- Not audited. Internal review is an argument, not evidence. It is published so that it can be disagreed with.
- Not novel cryptography. If you want new primitives, this is the wrong project.
- Not network-level anonymity. Transactions relay over Dandelion++, which frustrates naive origin tracing but is not Tor. Run over Tor if that is your threat model.
- Not immune to global timing analysis by an observer who can watch the whole network.
- Not equal privacy in both pools. A ring of sixteen is a ring of sixteen; a note-commitment tree grows. Early in a chain's life the shielded pool's anonymity set is small, and a pool with three notes in it hides very little however good the proof is.
- Not private about crossings. Moving value between the pools publishes the amount. That is inherent to the two pools committing to value in different groups, not an implementation shortcut.
Naming
The project is Nocturnal and the unit is NOCT. Every crate, binary and path is
spelled noct*: noct-core, noctd,
/var/lib/noct. Same thing abbreviated, not a second project. The short form
appears in consensus-visible constants, so renaming it would change the chain itself.