# What is a zero-knowledge proof?

A zero-knowledge proof lets someone prove that a statement is true without revealing anything else, for example that they own funds and may spend them, without showing which funds or who they are.

Also called ZK proof or ZKP.

## How it works

The prover runs a computation over secret inputs and produces a short proof. The verifier checks the proof against public inputs only. If the check passes, the statement is true, and the proof reveals nothing about the secret inputs beyond that.

The idea goes back to a 1985 paper by Shafi Goldwasser, Silvio Micali and Charles Rackoff. Modern proof systems make proofs small and fast to check, so a smart contract can verify one on-chain.

## Why it matters for privacy

A public blockchain checks every rule in the open, which usually means every detail is visible. A zero-knowledge proof lets the chain enforce the rules, such as that the money exists, belongs to the spender and has not been spent before, while the details stay private.

## In Redacted

Your browser makes a zero-knowledge proof for every action. It shows that you own notes in the Reserve worth enough for the action, never which notes they are, and the contract checks every proof on-chain, in public, every time.

More: [How privacy works](https://redacted.gg/docs/using-redacted/privacy.md)

## Related terms

- [zk-SNARK](https://redacted.gg/glossary/zk-snark.md): A zk-SNARK is a zero-knowledge proof that is small, quick to verify and needs only one message from the prover, which is why blockchains can check them inside a smart contract.
- [Trusted setup ceremony](https://redacted.gg/glossary/trusted-setup.md): A trusted setup ceremony creates the public parameters that some zero-knowledge proof systems need. Each participant adds secret randomness and destroys it, and the result is safe as long as at least one participant was honest.
- [Commitment](https://redacted.gg/glossary/commitment.md): A commitment locks in a piece of data without revealing it. Later it can be opened and anyone can check that it matches, but until then it gives nothing away and cannot be changed.
- [Nullifier](https://redacted.gg/glossary/nullifier.md): A nullifier is a unique value published when a private note is spent. It lets the chain reject a second spend of the same note without revealing which note was spent.
- [Shielded pool](https://redacted.gg/glossary/shielded-pool.md): A shielded pool holds funds as private notes inside a smart contract. Deposits and withdrawals are public, but what happens inside is proved with zero-knowledge proofs and does not reveal who owns what.

Sources: [Zero-knowledge proof, Wikipedia](https://en.wikipedia.org/wiki/Zero-knowledge_proof), [Zero-knowledge proofs, ethereum.org](https://ethereum.org/en/zero-knowledge-proofs/)
---

Page: https://redacted.gg/glossary/zero-knowledge-proof/
