What is a nullifier?
A nullifier is a unique value published when a private note is spent. It lets the chain reject a second spend of the same note without revealing which note was spent.
The double-spend problem
On a public ledger, stopping a double spend is easy because every coin is visible. In a shielded pool the chain cannot see which note is being spent. So every note has a nullifier, derived from the note and its owner’s secret key. Spending publishes the nullifier, the contract records it, and any later spend with the same nullifier fails.
Why it does not give the note away
Without the owner’s key, nobody can compute which commitment a nullifier belongs to. Observers see that some note was spent, never which one.
In Redacted
In Redacted a nullifier retires each spent note forever, so a note can be spent only once, and the mark it leaves points to no note in particular.
Architecture →Related terms
Sources: Zcash protocol specification
Updated October 7, 2026. All terms