NIGHTFALLCOIN
Live on mainnet · CPU mineable · no premine

Money that refuses
to snitch.

Every public blockchain turns your salary, your rent and every donation you make into a permanent record anyone can read. Nightfall hides the amounts and the addresses — and still lets you prove nobody printed a coin.

0 premine 90,000,000 hard cap fees burn, then pay miners CPU mineable
BLOCKS
—
from the seed
DIFFICULTY
—
LWMA · ~15s
NETWORK SUPPLY
— NIGHT
of 90,000,000 max
Mined—
Burned in fees—
Checking the chain…

Every node re-checks that no coin exists which was never mined. The raw figures are at /network.json — height, difficulty, supply. No addresses, on that endpoint or anywhere else.

Not “100% anonymous”

Amounts and addresses are hidden. The transaction graph is mixed inside every block, not erased. We will not claim otherwise.

This is the second genesis

v4 had a balance proof that proved nothing. v7 minted almost everything too early. We published both failures and started over.

No outside audit yet

The cryptography was written and reviewed by the same people. Passing tests is not an outside review.

Three things you would normally have to dig for. The complete list of what is missing · Why we reset

Start here

Your wallet. Your choice.

Choose by how you want to use Nightfall — and how much you want to verify yourself.

Desktop

Core wallet

Send, receive, run a full node and mine from one app. Stores the chain locally and applies the client's validation and checkpoint rules.

Get Core
Phone, tablet & browser

Web wallet

No installation. Your keys stay in this browser; a node supplies chain data. Back up your recovery words before receiving NIGHT.

Open web wallet
Understand first

Check the trade-offs

Read how Nightfall differs from Monero and Zcash, or open the current security review. No price promises and no safety score.

Compare the coins
Verifiable supply

A supply you can verify yourself

Hidden amounts still need accountable supply. Nightfall's consensus checks a balance equation across unspent outputs and transaction kernels, alongside signatures and range proofs. Run your own node to check the chain; the website displays a node's reported result.

Σ UTXO − Σ kernel excess = (minted − burned) · G

Sum every unspent output, subtract every transaction kernel, and the result must equal exactly the coins that were legitimately mined minus the fees that were burned — and, after the subsidy ends, not minted as extra. This invariant is one safeguard, not a substitute for correct cryptography, validation or an independent security review.

supply_proof… OK

Bulletproof range proofs

Every output carries a zero-knowledge proof that its hidden amount is a real number between zero and 2⁶⁴. Without it, a negative amount would mint value while the books still appeared to balance.

Schnorr excess signatures

Each transaction proves knowledge of a secret with respect to a second generator. That is only possible if the amounts cancel exactly — it is the mathematical statement "I created no money".

A fee you can audit

The fee is the one public number in a transaction, deliberately. Today it is burned, and anyone can check the burn instead of taking it on faith. Once the last subsidy is paid, that same visible fee goes to the miner who found the block. Neither case mints anything.

Privacy

Nothing to read, nothing to leak

Privacy here is not a mode you switch on. There is no transparent path to fall back to, because there is no transparent path at all.

Every block is a CoinJoin

A block does not store a list of transactions. Every payment in it is merged into one flat, sorted set of inputs and outputs, so an observer cannot tell which input paid which output. Not an optional mixer you remember to use, not a service that takes a cut — it happens to every payment, in every block, whether you asked or not.

Prove what you choose, to whom you choose

Hand an accountant a view key and they see every amount and memo you send or receive — and nothing else. It is structurally incapable of moving a coin. Need to prove a single payment instead? A receipt opens exactly one output and leaves the rest of your wallet shut.

Amounts are commitments, not numbers

What lands on the chain is a Pedersen commitment — a point on an elliptic curve that mathematically binds the sender to a value while revealing nothing about it. Only you and the recipient know what moved.

Your address never appears

Every payment generates a fresh one-time key derived from a shared secret. Two payments to the same address share no visible field — not even the sender can link them afterwards.

No admin, no freeze, no keys

There is no mint authority, no blacklist, no pause switch. Not as a policy — the capability simply does not exist in the protocol, and a fair genesis with zero allocations is enforced in code.

Encrypted memos, constant length

Attach a note to a payment; only the recipient can read it. Every payload is padded to the same size, so even the length of what you wrote gives nothing away.

Your payment does not shout

A transaction is handed to one random peer before the rest of the network hears it, so the node that relays it first is not obviously its origin. Tor is on by default; if it is down the node falls back to clearnet and tells you.

Mining

Built so a laptop still matters

Nighthash-v2 is Argon2id: producing a single hash requires 32 MiB of randomly-addressed memory. Purpose-built hardware would need that much fast RAM per parallel core, which is exactly where the economics of an ASIC stop working.

Open the wallet and press Start mining

There is no pool to join, no configuration file, no separate miner to install. The wallet runs a full node inside itself and uses every CPU core but one.

Peers connect themselves — just never mine without them

The wallet dials the network on startup and there is nothing to enter. It matters because two miners who never meet build two separate chains from the same genesis, and the lighter one is discarded when they finally connect. So if the wallet ever says No peers — mining solo, something is in the way — a firewall, a dead proxy, no connection. Fix that before you leave the machine running for hours.

The heaviest chain wins — always by work

Chain selection compares cumulative proof of work, never block count. Difficulty retargets every single block over a 90-block weighted average, so the network absorbs hashrate swings in minutes.

Rewards mature, then they are yours

Block subsidies unlock after 1,440 blocks, roughly six hours. The delay protects you from reorganisations — the coins are already yours, just not spendable yet.

Parameters

No treasury. No investors. No original sin.

Every coin that will ever exist has to be mined. There was no allocation to a team, a foundation or a fund — the genesis block contains nothing, and the code refuses to start if it ever does.

90,000,000Max supply
0Premine
15sBlock time
6NIGHT / block

Emission

6 NIGHT per block, halving every 7,500,000 blocks (~3.6 years). Half the supply in the first era, 89 million around year 23. After the subsidy ends, fees go to miners. The August 2026 chain that minted 20 NIGHT is buried — those coins are not these coins.

Cryptography

Ristretto throughout. Blake3 for hashing, Bulletproofs for range proofs, Schnorr for signatures, XChaCha20-Poly1305 for payloads, Argon2id for proof of work. No trusted setup, anywhere.

Written in Rust

Workspace crates, no unsafe code in the consensus path, and a regression suite that replays the six real attacks against the previous protocol version and asserts every one of them now fails.

Download

One app. Node, miner and wallet.

The Core Wallet runs a complete node inside itself. No server to trust, no third party watching your balance, nothing to configure.

macOS · Apple Silicon
M1 – M4 · macOS 11+
Download 1.0.5
macOS · Intel
macOS 10.15 Catalina+
Download 1.0.5
Windows
64-bit · Windows 10+
Download 1.0.5
Linux · x64
Debian / Ubuntu · or any systemd box
Download nightfalld
Phone, tablet & browser
Nothing to install · runs in any modern browser
Open the web wallet
The technical foundation

Read the Nightfall whitepaper

Private payments, verifiable supply and explicit trust boundaries. Twenty chapters, with implementation sources and open risks.

English edition · 8 September 2026 · Software 1.0.4
The builds are unsigned — what you will see

macOS refuses a normal double-click: right-click the app → Open → Open, once. Windows shows SmartScreen: More info → Run anyway. On a phone or tablet there is nothing to sign and nothing to install — the web wallet runs in the browser and can be added to the home screen.

Code signing certificates are issued to a company. There is no company here, which is the same reason there is no premine.

Verify what you downloaded

Compare the file you got against the published checksum before you run it:

Or skip the question entirely and build it yourself from source — that is the point. A one-command node install is on the build page.

Before you begin

A few things worth knowing

The essentials before creating a wallet or sending your first payment.

Which wallet should I use?

Core runs on your computer with a local node and mining tools. The web wallet works on phones and desktops without an installation, but relies on a remote node for balances and chain data. Both need a safe backup. Compare the download options.

What should I back up?

Write down the wallet's 24 recovery words and keep them offline and private. Never send them to support or enter them on another website. Browser storage can be cleared or lost; it is not a backup. On a shared or compromised device, another person or malicious software may access your keys.

Why is a payment or mining reward not spendable yet?

A submitted payment is not confirmed until the chain includes it. Newly mined rewards also have a maturity delay. Let your wallet finish syncing, check its transaction status and avoid sending again just because a balance has not refreshed. The network page shows the node's latest reported chain state.

What happened to atomic swaps?

They were withdrawn before 1.0.4 and removed from the wallet. Nightfall has no script language, so a NIGHT lock cannot refund itself on a timer the way a Bitcoin lock can — which left a permanent-loss case no implementation could remove. Shipping that without an independent audit was not a trade worth making. No consensus rule changed and no user funds were ever at risk: the feature was blocked on mainnet in every published build.

What this is not, yet

A privacy project that hides its weaknesses is a privacy project you should not use. Here is everything currently missing, in plain language.

  • Not 100% anonymous, and we will not say that. Amounts and addresses are hidden. The graph is mixed inside a block, not erased. Tor is on by default; if it is down, the node falls back to clearnet and says so.
  • No independent audit established. Passing tests are not an outside review. The updated internal review of 8 September 2026 separates tested safeguards from open risks.
  • This is the second public genesis in a month. v4 was unsound. v7 was too front-loaded. We published both failures. A third silence would be worse than a reset.
  • No official price, no listing, no premine. Mine it or receive it. A ticker we invented would be a lie.
  • The browser wallet trusts a node for what it shows. A hostile node can misreport payments and balances; node access alone does not provide your spending key. Malicious first-party JavaScript or a compromised device can expose browser-stored keys. Keep the 24 recovery words offline.
  • There is no phone or tablet app. The sideloaded Android and iOS builds were withdrawn: an unsigned package that has to be installed around the app store is a bad habit to teach people who are about to hold money. On a phone or tablet, use the browser wallet.

The previous protocol version had a balance proof that proved nothing — anyone could have minted unlimited coins. We found it, published the full analysis, threw the chain away and started over. Read the current review · v4 audit.