Messari hosted a public AMA with Zcoin Founder, Reuben Yap in the Messari community group. This is a transcript of the conversation.
Messari: Reuben, thanks so much for joining the channel today to chat about Zcoin a little bit. We have a lot of good questions in the queue, so this should be fun.
Thanks for being here.
Reuben Yap: Glad to be here! And thanks everyone for submitting questions!
Messari: Before we dive into some submitted questions, can you give us a brief overview of your background, the conception of Zcoin, and where the team has developed to date?
Yap: Sure, Zcoin is a privacy focused cryptocurrency and we started in September 2016. We have a unique method of providing privacy which allows users to burn coins and then redeem them later for brand new ones that don't have any previous transaction history.
It started out as the first implementation of Zerocoin but we have since developed new privacy protocols such as Sigma (which has been deployed in July this year) and upcoming Lelantus which has gotten a lot of interest even from other projects. We have been totally launched on mainnet since 2016 as well and were also the first coin to implement Dandelion++ routing which hides IP addresses.
Cool adoption stories are our blockchain being used for the world's first large scale political election on the blockchain in Thailand with over 127,000 voters nationwide casting their votes on Zcoin's blockchain, and also recently we opened the opportunity to spend Zcoin at over 5 million merchants in Thailand with integration with Promptpay.
As for my background, I started in in Bitcoin I think in late 2012/early 2013 and was the first merchant in Malaysia to accept Bitcoin. I ran a VPN business to combat censorship in my country. I was a corporate lawyer for ten years before joining Zcoin full time.
Messari: The first question is pretty simple but a very important one: “Why is financial privacy important? And how do you plan on educating users on the need for it?”
Yap: Great question, financial privacy is actually a pretty basic right and it's recognized in law. This is why banks aren't supposed to simply give out your details or share with third parties. It’s also one of the most intimate parts of our life.
We are judged by how much we own, and by taking a look at the way someone spends, you can also get a pretty good idea of who he/she is. (Probably why Facebook wants us to use Libra so much).
However in a decentralized currency, these protections are mostly not present except in privacy coins. With advancing blockchain analysis tools or even AI assisted ones, it has become relatively trivial to ascertain someone's crypto holdings or what he spent or where he got it from. A typical easy example also with cryptocurrency payments are if I pay someone for coffee with Bitcoin from an address that has a 100 btc, the coffee seller now knows I have at least 100 btc and that's really none of their business.
Messari: But in the market of privacy, there are a lot of teams building for greater anonymity tools and services. So, in that context, our next question: “What do you think Zcoin’s advantages are in its privacy technology?”
Yap: Sure, first of all our burn and redeem method is quite unique and it allows transaction links between addresses to be completely broken, not merely obfuscated. We use zk proofs to do this but unlike let's say Zcash, our constructions do not rely on trusted setup, have a simple construction and use well understood cryptography.
Because what reveals our information are the relationships of transactions between addresses and the flow of money. If you can break this, then you can provide a very high degree of privacy. A way to illustrate the difference between obfuscation and transaction link breaking such as done in Monero or MW coins, is a lift example. If i want to let out a fart, and i'm the only person in a lift, everyone knows it's me. However if I drag other people who want to fart or just some innocent bystanders into the lift and farts happen, it becomes unclear who farted what. That's how obfuscation methods like RingCT, MW work in a obviously oversimplified way of course.
Messari: Sure, that makes sense though. And it's a great transition into a couple questions we have on that exact comparison—Zcoin compared to a couple other privacy coins and protocols.
Yap: It works in general, but when you have repeated tx, this sometimes can breakdown as you're hiding in a relatively small crowd. Your anonymity set is those in the lift with you. But with Zcoin it's like farting and having your fart disappear and then choosing when for it to smell. Maybe let's say one year in the future, so yoru anonymity set isn't just with the people in the lift. but anyone who entered the lift before.
Messari: On that note, can you break down a bit more how Zcoin compares to other privacy alternatives?
First: “How does Zcoin’s privacy technology differ from other piracy coins such as Zcash or Monero?”
And second: “What do you think of Decred’s privacy protocol that was just announced?”
Yap: Let's deal with Zcash first, it has really great anonymity and amazing performance, quick verification times and small proof sizes.
Its main problem with Zcash is that its current construction is quite complex using arithmetic circuits and experimental cryptography that some has dubbed 'moon math'. I think what they're doing is great though and has lots of flexibility but it does introduce many potential failures and makes it so complex that only a few people in the world actually get it completely. This isn't a good thing and acts as an effective security through obscurity as illustrated when Zcash had a potential inflation bug that was live for 2 years despite multiple audits etc.
It also uses something called trusted setup meaning that there's an initial setup phase where you need to trust was carried out properly. It's kinda like in Lord of the Rings you are trusting that someone destroyed the 'one ring'. If the ceremony and the initial key was not destroyed properly, coins can be counterfeited invisibly. This has been mitigated somewhat but it's still not a great thing especially in a technology that's all about not having to trust, but to verify.
With Monero it's the leading privacy coin right now and has a great rich history and community around it, but its anonymity set per tx is still rather low with current technology since it uses ring sizes of 11. Monero is actually currently looking at Zcoin's technology Lelantus right now as a candidate to see if there are ways it can be used to increase its anonymity. Its method of hiding in a crowd also has some problems that are too long to go into here. It's good for today and they are making efforts to try and mitigate them. Remember blockchain history is forever and you need long lasting privacy.
Messari: Got it—makes sense. And what of Decred?
Yap: I'm a bit perplexed at the 'secret development' of Decred for their privacy solution which kinda goes against the spirit of decentralized governance but some would maybe disagree here. Their privacy tech is nothing new it's a form of mixing which requires active participants who want to mix and actually this can be done with Bitcoin as well. Requiring active participants is a real big problem esp for an alt coin and drastically reduces privacy or plausible deniability. It's okay but doesn't really offer the same type of privacy as more privacy focused coins.
Disclosure I hold quite a bit of Decred though and love what they're doing.
Messari: A lot of privacy development finds its product-market fit because of Bitcoin's inferior on-chain privacy features. The next question asks about the future of privacy coins when / if Bitcoin adds similarly robust privacy features:
“Will there be a place for privacy coins if Bitcoin gets (proper) privacy?”
Yap: This is an excellent question and a common one. However I actually think this is rather unlikely. Privacy has a price, and it's often a huge one. Many solutions impact on scalability. But more importantly they impact on supply auditability especially for those that hide transaction amounts. Bitcoin already has had two big inflation bugs. If amounts were hidden, it would have been a lot harder to detect some of them. I also don't know how it would affect adoption of Bitcoin with governments being antsy about it, so I think it's highly unlikely for Bitcoin to offer high levels of privacy.
Messari: Our next question is about this merchan adoption / acceptance of Zcoin in Thailand: “I saw recently that Zcoin is accepted at 5m merchants in Thailand, how does this work?”
Yap: So this is pretty cool our founder Poramin Insom has one of the few exchange licenses in Thailand to do crypto to fiat conversions. Promptpay is actually Mastercard technology but it's been really pushed hard by the government such that usually when you sign up for a bank account there you also get a Promptpay account. Promptpay is quite a simple system it's basically a QR code that ties to your bank account and ID. Over half the population of Thailand has a Promptpay account and 5 million merchants also use it. Our integration allows a seamless conversion from Zcoin to Thai baht to be settled directly to the merchant.
It's not a perfect solution as it's still centralized and doesn't really offer privacy and still requires bank accounts....but i think crypto adoption has to happen in stages and getting people using and having merchants comfortable in accepting it (without any risk since they receive thb) really opens the doors
Messari: I want to transition to a couple more technical questions.
First: “How is Sigma Protocol going?”
And second: “I just want to hear about Lelantus!”
Yap: It's fully deployed and we're seeing a good take up with over 90k coins that have been anonymized using our Sigma protocol mechanism. We hope to see this number go up a lot more especially when we launch our new GUI which will prompt people to burn (anonymize) their idle coins. Lelantus is actually our own innovation and was the work of our team and our cryptographer Aram Jivanyan.
We were originally trying to find a way to replace zkSNARKs in Zcash's setup with bulletproofs but hit a dead end there as we couldn't get desirable performance. We turned back to the Sigma protocol and found a way to introduce a new innovation to allow it to burn and redeem arbitrary amounts.
In Sigma you still have to burn in fixed denominations (think of the different values of paper notes). This can lead to some types of timing analysis due to the combinations of the different denominations. With Lelantus this is done away completely and you can burn any arbitrary amount and redeem any partial or full amount. You can read more here at lelantus.io. Both Monero and Beam have working or almost working proof of concept code for Lelantus to see how it can be integrated into their own privacy systems. So I think it's quite a breakthrough.
Messari: One more: “Are there plans to make atomic swaps easier / integrated into the GUI client?”
Yap: Not in the immediate roadmap. For this to happen I think there needs to be a rich dex or decentralized p2p market but we haven't really seen this happen at scale yet. Perhaps in the future. We have more pressing concerns like making Zcoin itself more easy to use and mobile development with full privacy support. Backend capability is all ready though and maybe we can plug into those integrations if it makes sense.
Messari: Can you give any insight on a Zcoin re-brand?
Yap: So we've went down this discussion before many times. I think our own internal team often groans when we talk about it. We talk about it for months, can't find a solution and then bam still stuck with Zcoin. A lot of our community members are actually fond of the Zcoin name. Personally, I do really think we need a rebrand and we're midway in an engagement with an expert to help us with this. Mainly because everyone thinks we're some Zcash fork (which we aren't) or associate us with the troubled Zerocoin protocol. First impressions count.
Messari: Speaking of Zcash earlier...
“Zcash recently having a lot of discussions about extending their development fund, Zcoin has a similar model, what are your thoughts on this?
Yap: Mmm there are some ongoing discussions both on the rebrand and also the extension of the dev fund past 2020 (when it expires) on our forums at forum.zcoin.io. To look at it with retrospect it may have been rather naive to think that we can survive off donations after 4 years at this level of adoption. Monero and Grin can do it but it's a much more competitive market now and it's not without its troubles. We already saw the issues that can happen with Litecoin. Community seems overwhelmingly positive for an extension of a dev reward (not founder's reward) of any number that I've seen being tossed around between 10% to even 20% but we're still deep in discussion. The governance model is particularly hard to solve especially in the era of SEC scrutiny so we have to tread carefully if we start thinking about on-chain governance. [1] [2] But whatever it is, I think the team has internally committed to having Zcoin in a very good state whatever the decision is by the time the rewards end. Let's just hope for a better market soon so we can more rapidly deploy!
Messari: Looking forward to Q3 and Q4 2019 and beyond, what does the near-term future look like for Zcoin?
Yap: So we post regular updates on our developments. The next few months are really focused on improving Zcoin's usability and accessibility. For e.g. mobile development and a new GUI along with tidying up our code base. We have also some really cool features coming up like smart asset capability with Sigma privacy features and we have some parties keen to build their own stable coins on us with privacy features which I think is going to be a unique feature. There's also ongoing Lelantus research work where we are trying to improve it further.
On the adoption side, we're really focusing on improving our fiat pairings and our liquidity options which I think you will see in the next few weeks as well. Along with allowing Zcoin for more DeFi stuff like being used as collateral for loans, etc.
Messari: One more question I skipped over: “Will Zcoin implement a Proof-of-Service for Znodes, similar to what Dash uses, to ensure that Znodes are fully participating in the ecosystem?”
Yap: Sure we're already more than halfway through integrating the latest Dash masternode code which greatly improves their reliability and security. Chain locks that prevent against 51% attacks are also great. There are some parts that we took out such as the Sporks code which allows stuff to be turned off and on (which isn't great for decentralization). We have some further ideas to leverage the masternodes but still at a conception stage.
On a side note, we're really pushing to expand our community especially in non-English speaking areas. We can build the most amazing tech but it's pointless if people don't use it so we're really focused on bringing Zcoin to the masses and increasing its utility be it spendability, creating your own tokens or using it to move or hold money privately. Who knows maybe a rebrand is also needed to achieve this. We're doing quite well with our multiple language channel Telegram groups that have grown quite rapidly.
Messari: As we're approaching the one-hour mark, I really appreciate your time, Ruben. This has been super fun and insightful. Before we conclude, is there anything you want to mention that we haven't discussed here? And where can we best follow Zcoin's progress and continue the conversation's we've had here?
Yap: Thanks for having me! There is @zcoinproject where we are super active and our news channel at @zcoinofficial. Our website is at zcoin.io and Twitter @zcoinofficial along with all the other usual non privacy protecting social media
Messari: Perfect. Thanks again, Ruben! It's been very fun.
Yap: Always a pleasure, I'll stick around a bit to answer any other questions also.