Comparison / September 2026

Three privacy coins.
Three different bets.

Nightfall, Monero and Zcash all hide money. They do not hide the same things, they do not prove the same facts, and they do not ask you to trust the same people.

Not a ranking No pricesLimits in view

What each one is betting on

Nightfallprove the total
Monerohide everyone equally
Zcashprove without showing
English / protocol facts as of September 2026

01 / Thesis

The same problem, three answers

A public ledger is a bank statement that never forgets. Privacy coins exist because that is a hostile default for ordinary payments.

Bitcoin, Ethereum and almost every transparent chain publish amounts, addresses and the full payment graph. Anyone can reconstruct salaries, donations, exchange withdrawals and the rest of a life. Nightfall, Monero and Zcash all refuse that default. They refuse it with different mathematics, different monetary rules and different ideas of what “private” is allowed to mean.

Nightfall · 2026

Hide the books. Still prove the total.

Amounts and addresses never appear. Every block mixes its payments. Nodes still check one public equation: no coin exists that was never mined.

Monero · 2014

Hide everyone the same way, every time.

Privacy is mandatory. Each spend hides among decoys. There is no transparent mode to opt into, and therefore no transparent minority to isolate.

Zcash · 2016

Prove a statement without showing the data.

Zero-knowledge proofs can hide sender, receiver and amount completely — when a payment is shielded. Transparent payments still exist, and they look like Bitcoin.

02 / Snapshot

At a glance

One table cannot replace the chapters below. It can stop the most common mix-ups.

Question Nightfall Monero Zcash
Privacy defaultMandatory. No transparent path.Mandatory. No transparent path.Optional. Shielded or transparent.
Hides amountsYes — Pedersen commitmentsYes — RingCTOnly in shielded pools
Hides addressesYes — one-time stealth keysYes — stealth addressesOnly when shielded
Hides the graphMixed inside each block, not erasedProbabilistic: real spend among 15 decoysShielded: no public graph. Transparent: full graph.
Anonymity set todayOther payments in the same block. The live network is small.Protocol-scale after years of use. Ring size 16 per input.The shielded pool you are in — only as large as the people who opted in.
Supply you can proveYes: Σ UTXO − Σ excess = (minted − burned)·GNo public conservation equation. Independent checkers exist; they replay the chain.Transparent totals are public. Shielded pools publish a balance; a circuit bug can mint undetected until a turnstile or audit.
Trusted setupNoneNoneSprout and Sapling needed one. Orchard / Halo 2 does not. Implementation bugs remain a separate risk.
Premine / foundersZero. Genesis is empty.Zero.Founders’ Reward: 20% of block rewards for the first four years, about 10% of the 21 million cap.
Hard cap90 million. Scheduled issuance ends at 89,999,999.25. No tail.No cap. Tail emission of 0.6 XMR every ~2 minutes.21 million, Bitcoin-like halvings.
Block time~15 seconds~2 minutes~75 seconds
Proof of workNighthash-v2 (Argon2id, 32 MiB)RandomX (CPU)Equihash
View / discloseView key + one-payment receiptsView key (incoming; outgoing needs extra data)Viewing keys and payment disclosure, designed for selective compliance
Independent auditNot established. Internal review only.Multiple public reviews over a decade.Heavy research attention. A shielded-circuit soundness bug was disclosed in 2026.
Language / formRust. Own L1.C++. Own L1.Rust / C++. Own L1, Bitcoin-descended.

Two rows decide almost every argument that follows. Nightfall and Monero both refuse a transparent mode. Zcash does not. Nightfall is the only one of the three whose consensus checks a global conservation equation on hidden amounts. That is a real difference. It is not a certificate that the cryptography cannot fail.

03 / Construction

How privacy is actually built

“Private” is not one mechanism. It is three different machines that happen to share a marketing category.

Monero — a crowd of 16

1 of 16
The verifier learns that one ring member was spent. It does not learn which. The teal mark is only for this drawing — on chain they are identical.

Zcash — two worlds

transparent Alice → Bob 12.5 ZEC public graph shielded proof only no public graph
A shielded payment can hide everything. A transparent one hides nothing. The anonymity set is only the people who chose the sealed side.

Nightfall — the block is the mix

one block, one sorted bag in in in in out out out out
Payments lose their original grouping. An observer cannot read which input paid which output from the block alone. A quiet block is a small crowd.

Monero: plausible deniability

Monero is a CryptoNote descendant. Recipients get stealth addresses, so the published destination is a one-time key. Amounts are commitments (RingCT) with Bulletproofs+ range proofs. The sender is hidden by a ring signature: the real spent output sits among 15 decoys pulled from the chain. The ring size is fixed at 16 for every transaction so that nobody stands out by choosing a larger or smaller crowd.

That is plausible deniability, not a mathematical erasure of the spend. Chain-analysis research has spent years on decoy selection. The honest description is: an outside observer cannot prove which of the 16 was spent. They can still form probabilities. Full-chain membership proofs (FCMP++) are the planned next step: prove membership in the entire output set instead of a ring of 16. Until that ships and is used, the ring is the construction.

Zcash: a proof instead of a crowd

Zcash started as a Bitcoin fork with an extra mode. A shielded payment carries a zk-SNARK: a short proof that the rules were followed, without revealing the notes involved. Inside a well-used shielded pool that is a stronger statement than a ring of 16. There is no public “this input, that output” to analyse.

The catch is behavioural, not cryptographic. Transparent addresses still exist. They publish amounts and a graph the way Bitcoin does. Privacy is as large as the shielded share, and as fragmented as the number of pools (Sprout, Sapling, Orchard, then Ironwood in 2026). Unified addresses try to default toward the most private option both sides support. They cannot force a counterparty who wants a transparent payment.

Nightfall: confidential amounts, aggregated blocks

Nightfall looks more like Grin or Litecoin MWEB than like Zcash, and more like Monero than like Bitcoin for addresses. Amounts are Pedersen commitments on Ristretto. Each output carries a 64-bit Bulletproof. Recipients are paid to a one-time key derived from a shared secret; the nf1 address never appears on chain. Kernels carry a Schnorr signature on a second generator, which is the statement “these amounts cancel.”

Then the block itself is flattened. Inputs, outputs and kernels are merged and sorted. A block is not a list of transactions. That is a CoinJoin that nobody can skip. It is not Mimblewimble cut-through: spent-and-created components stay, because this design needs them for non-interactive ownership. A block with one payment is not a large anonymity set. Nightfall says so in the whitepaper rather than implying otherwise.

04 / Threat model

What an observer can still learn

Hiding amounts and addresses is meaningful. It is not the same as defeating every observer.

Observer Nightfall Monero Zcash
Passive chain reader No amounts, no addresses. Sees fees, timing, coinbase flags and the mixed block. No amounts, no addresses. Sees rings, fees, timing and key images. Sees everything on transparent payments. Sees almost nothing inside a shielded one, plus pool totals.
Payment counterparty Knows that payment, the address you shared, and anything said out of band. The same. The same — and a transparent counterparty sees the public graph around you.
First-hop peer / ISP Stem/fluff plus Tor by default. Clearnet fallback if Tor is down, and the node says so. Dandelion++ is deployed. Network observation remains a research surface. Depends on wallet and network. Shielded cryptography does not hide IP addresses by itself.
Light-API operator Can misreport balances and withhold payments. Cannot spend without the key. Can see requests. Remote nodes have the same display-trust problem if you do not run your own. The same, plus transparent history is already public.
Compromised device No general protection. Keys, history and backups can leak. The same. The same.

05 / Inflation

Can anyone print coins in secret?

Confidential amounts create a second problem: if you cannot see the numbers, how do you know the money supply is real?

This is the axis where the three designs part most sharply, and the one Nightfall was built around.

Nightfall: an equation every node checks

Σ UTXO commitments − Σ kernel excesses = (total minted − total burned fees) · G
Group elements on the left, integer accounting on the right. If someone minted a coin from nothing, the equation breaks and every validating node sees the break.

The equation is useful only together with range proofs (so a negative amount cannot mint value), excess signatures (so publishing the publicly computable difference is not enough), input authorization and correct emission rules. Nightfall’s first public chain, v4, had a “balance proof” that compared a value against a recomputation of the same public inputs. That proved nothing. The chain was thrown away. The current construction adds the knowledge checks. Passing tests still do not replace an outside review of the cryptography.

The website’s supply figure is a node’s reported result. Independent verification means running a validating client, not reading a webpage.

Monero: conservation without a public total

RingCT also uses Pedersen commitments and range proofs. What it does not publish is a single chain-wide excess that any observer can check against minted supply. The supply is an accounting consequence of emission plus the assumption that the cryptography and the implementation are sound. Independent projects replay the chain and count. That is real work, and it is not the same as a consensus invariant that every node re-derives from group elements.

Monero had an inflation bug in 2017. It was found and patched. The episode is why “hidden amounts, therefore hidden inflation” is a serious question rather than a smear. A decade without a repeat is evidence of engineering care. It is not a proof that none is possible.

Zcash: pool totals, circuit soundness, turnstiles

Transparent ZEC is as auditable as Bitcoin. Shielded pools publish a balance: value in minus value out. If the proving circuit is unsound, an attacker can mint notes that verifiers accept, and the pool total will not tell you until the counterfeit tries to leave — if it ever does.

That is not a hypothetical from 2016. In May 2026 a soundness flaw in the Orchard circuit was disclosed. It had been live since 2022. It could have allowed undetectable counterfeit notes. Developers halted Orchard, patched it, and in July 2026 activated Ironwood: a new pool with a turnstile, so that value leaving the old pool cannot exceed value that entered. There is no public evidence the bug was exploited. The lesson stands: a zero-knowledge construction is only as good as the circuit and the review, and “no trusted setup” did not make implementation bugs impossible.

06 / Primitives

Different cryptographic bets

Established primitives reduce the invention surface. How they are composed is still the security question.

Nightfall Monero Zcash
GroupRistretto over Curve25519Ed25519 / Curve25519 familyJubjub / Pallas / Vesta (Halo 2 era), historically BCTV14/Groth16 curves
CommitmentsPedersenPedersen (RingCT)Note commitments inside the circuit
Range / value proofsBulletproofs, 64-bit, one per outputBulletproofs+Encoded in the SNARK
AuthorizationSchnorr on one-time keys + kernel excess on HCLSAG ring signatures + key imagesSpend proofs inside the SNARK; nullifiers stop double-spends
HashingBLAKE3, domain-separatedKeccak / related CryptoNight-era hashesCircuit-friendly hashes (Poseidon and predecessors)
Trusted setupNoneNoneHistoric for Sprout/Sapling. Orchard uses Halo 2 without one.

Zcash’s proving systems are the most ambitious. When they work, they hide more of the graph than a ring or a mixed block. They are also the most expensive to get wrong, as 2026 showed. Monero and Nightfall stay with discrete-log assumptions and linear constructions that a larger set of cryptographers have kicked for longer. Nightfall still has a composition that nobody outside this project has audited.

Nightfall’s experimental Bitcoin swaps once added secp256k1 and a cross-curve proof on top of the native payment system. They were withdrawn before 1.0.0 and the entire surface — crate, dependencies and second curve implementation — is gone from the build. What remains is one curve and one payment system.

07 / Work

Who can produce the next block

Privacy is worthless on a chain a handful of miners can quietly reorganize.

Nightfall

Argon2id, 32 MiB per hash

Nighthash-v2 is memory-hard by construction. The wallet mines on a laptop; there is no pool to join. The design aims to make ASICs uneconomic. It does not prove GPUs have no edge, and it does not claim mining is profitable. Difficulty retargets every block (LWMA-1, 90 blocks). Fifteen-second blocks are a target, not finality.

Monero

RandomX, years of CPU practice

RandomX is a specialized CPU-friendly PoW with a much longer field history. Mining is widely distributed compared with GPU/ASIC coins. Block time is about two minutes. Hashrate and exchange access still concentrate in the real world; RandomX is not a political guarantee.

Zcash

Equihash

Equihash was meant to be memory-hard. ASICs arrived anyway. Block time is about 75 seconds. Hashrate is an industrial market. Privacy of payments and industrial mining are separate questions; a shielded coin can still have a concentrated miner set.

Nightfall’s 500-block rewind bound and compiled checkpoint (height 25,000 in 0.9.5) are client policy. They constrain which forks a shipped node will adopt. They do not make a 15-second block irreversible, and they are a trust decision, not magic finality. Monero and Zcash have their own reorg realities at much larger hashrates. A young CPU chain is the easier one to overpower. That belongs in the comparison even if it is uncomfortable.

08 / Issuance

Money rules, written in integers

Fair launch, premine and tail emission are not privacy features. They are the politics of the money.

Nightfall Monero Zcash
Cap90,000,000. Terminal issuance 89,999,999.25. No tail.No cap. After the main curve, 0.6 XMR per 2-minute block forever (~1% and falling).21,000,000.
Initial subsidy6 NIGHT / 15 s, halving every 7,500,000 blocks (~3.6 years)Smooth curve, then tailBitcoin-like halvings; ~1.5625 ZEC / 75 s after the 2024 halving
Fees during subsidyBurned. Circulation falls by the burn.Paid to minersPaid to miners
Fees after subsidyPaid to the miner. Not minted, not burned.Tail continues, so this case does not ariseMiners live on fees once issuance ends
Premine0. Empty genesis, enforced in code.0.Founders’ Reward, then a development fund, then a coinholder lockbox. Not a fair launch.
Unit1 NIGHT = 1e8 darks1 XMR = 1e12 piconero1 ZEC = 1e8 zatoshis

Monero’s tail emission is a deliberate security-budget choice: miners keep getting paid after the main curve, so the chain does not gamble that fees alone will buy enough work. Nightfall and Zcash take the Bitcoin bet — a ceiling, then fees. Nightfall burns fees while a subsidy exists, then hands them to miners without minting extra. That is a different long-run stock of coins, not a promise that the fee market will be enough.

Zcash’s Founders’ Reward is the original sin Monero and Nightfall refused. About 10% of the 21 million cap was allocated through block rewards over four years to founders, employees, advisers and early investors. Later development funding continued as a protocol slice. In 2025–2026 that mandate moved toward a coinholder-controlled lockbox. Whatever one thinks of paying researchers, it is not a fair launch, and Nightfall’s empty genesis is a different political fact, not a personality trait.

A fair launch also does not guarantee a fair distribution. Early information, hardware and attention still matter. Nightfall’s first public genesis was discarded because v7 minted too fast. The coins on that chain are not these coins.

09 / Disclosure

What you can prove without handing over the spend key

Private money that cannot be shown to an accountant is private money that some people cannot use. The question is how much you have to reveal.

Nightfall

View key and receipts

nfview1 scans and opens matching outputs. It cannot spend. A receipt opens one commitment and is signed by the address’s spend key. Recovery words are never a receipt format.

Monero

View key, incoming-first

A view key sees incoming payments. Outgoing amounts need extra wallet data. Subaddresses keep one seed and many public faces. There is no first-class one-payment receipt in the Nightfall sense.

Zcash

Viewing keys as a product

Shielded viewing keys and payment disclosure were designed so a holder can prove a payment to an auditor without making the whole chain public. That is why some institutions tolerate Zcash and not Monero.

All three

A view key is not a session token

It is continuing access to financial information, including future matching payments. It is not revocable the way a website password is. Do not paste it into a group chat.

Nightfall’s receipts are the narrowest of the three native tools: one output, not a running feed. A verifier still needs chain evidence that the output was included and remains unspent. The receipt alone is not a court stamp and not a balance certificate.

10 / Propagation

The chain is not the only leak

A perfect output construction still has a first hop, a wallet process and a way to find peers.

Monero deployed Dandelion++ so a new transaction takes a stem path before it is fluffed to the wider network. Nightfall uses a Dandelion-class stem/fluff on locally originated transactions (configured stem probability 90%, embargo then fluff). Those papers’ formal guarantees do not automatically transfer to a particular implementation. Topology, adversarial peers and fallback behaviour all matter.

Nightfall turns Tor on by default (127.0.0.1:9050). If the proxy is down, the node falls back to clearnet and tells the user. Onion destinations never take that fallback. Monero wallets can be used over Tor; it is not the same as a node that treats Tor as the ordinary path. Zcash privacy at the network layer depends on which software you run; the SNARK does not hide your IP.

Browser wallets are a separate trust story on all three, where they exist. Nightfall’s web wallet keeps keys in the browser and reads the chain through a remote light API. A hostile node can lie about balances. Node access alone does not reveal the spending key. First-party JavaScript on a shared origin can. That is why a separate wallet origin is being stood up, and why the 24 words — not browser storage — are the backup.

11 / People

Who wrote the rules, and who can change them

No mint key is not the same as no human influence. Software still has maintainers.

Nightfall

No company, visible operator

No foundation that owns a printer. No VC allocation. Releases, seeds and the website are still operational facts. Checkpoints, client policy and the compiled seed list are trust decisions. The current genesis is the second public one in a month of 2026. That history is published on purpose.

Monero

Community, no firm

No company, no founders’ reward. Funding is donations and community crowds. Core development is slow, public and conservative about consensus changes. That culture is part of the privacy product: fewer scheduled “upgrades” that split anonymity sets.

Zcash

Research orgs, protocol funding

Electric Coin Company, the Zcash Foundation, Shielded Labs and others. Development was paid from the block reward for most of the coin’s life. That bought cryptography and also created a political argument that still has not ended. Several independently funded groups responding to the 2026 bug is the other side of the same structure.

Nightfall is a settlement coin. It does not ship a general-purpose VM, a custodial bridge or wrapped NIGHT. Monero is the same kind of object: money. Zcash is money plus a long experiment in optional disclosure and, increasingly, institutional wrappers. Those are different products wearing the same “privacy coin” label.

12 / Evidence

Age, audits, and what is still missing

A twelve-year coin and a twelve-week coin are not comparable on “has this been attacked.”

2014

Monero launch. Mandatory privacy, long adversarial attention, large live anonymity set.

2016

Zcash launch. Trusted setup, then Sapling, then Halo 2, then a 2026 circuit incident.

2026

Nightfall v8 genesis. Second public chain. Internal review, no independent audit.

Monero’s advantage that no whitepaper paragraph can erase is time: wallets, node operators, decoy-selection papers, exchange cat-and-mouse, and a culture that treats privacy as non-negotiable. Its disadvantage is the ring, the lack of a public supply equation, and tail emission if you wanted a hard cap.

Zcash’s advantage is the proving system — when you are actually in a current shielded pool — and a disclosure story that some counterparties will accept. Its disadvantages are optional privacy, a founders’ allocation, historic trusted setup, and the demonstration that a SNARK circuit can be unsound for years.

Nightfall’s advantage is the combination Monero and Zcash each only half-own: mandatory hiding and a conservation equation, with a fair genesis and CPU-first mining. Its disadvantages are listed in public because hiding them would be the opposite of the project: a small anonymity set, no outside audit, unsigned builds, a browser wallet that trusts a node, a second genesis, and no direct route in or out — the atomic swap that would have been one was withdrawn before 1.0.0 rather than shipped unaudited.

13 / Use

When each one is the honest pick

If a page tells you there is a single winner, it is selling. These are the conditions under which each design is the one that matches the job.

Pick Nightfall if

  • You want amounts and addresses hidden by default, with no transparent fallback.
  • You want every node to check that supply still matches what was mined.
  • You want an empty genesis and no founders’ cut.
  • You will run or build the client, write down 24 words, and accept a young network.
  • You will not call it untraceable.

Pick Monero if

  • You want the anonymity set that already exists: years of mandatory private payments.
  • You accept a ring of 16 as plausible deniability, not graph erasure.
  • You accept tail emission as the price of a permanent miner budget.
  • You want a project that has survived a decade of exchanges, papers and hostile attention.
  • You do not need a public, one-line supply equation.

Pick Zcash if

  • You specifically need zero-knowledge proofs and selective disclosure.
  • You will actually use shielded payments, not the transparent default.
  • A 21 million cap and a Bitcoin-like issuance story matter to you.
  • You accept a founders’ allocation and research orgs funded from the protocol.
  • You understand that a circuit bug can hide inflation until a turnstile catches it.

You can also pick none of them. Transparent coins are simpler to audit, list and confiscate. That is the trade. Nightfall’s job is to make the private side inspectable enough that “just trust us, the amounts are fine” is no longer the pitch.

14 / Scope

Sources, dates and what this page is not

Nightfall facts are pinned to protocol 8 / wallet 0.9.5. Monero and Zcash facts are the public protocol as of September 2026.

  1. Nightfall whitepaper, English edition, 8 September 2026
  2. Nightfall protocol spec (v8)
  3. Nightfall privacy statement
  4. Nightfall internal security review, 8 September 2026
  5. Monero technical specification — ring size 16, RandomX, tail emission
  6. Ironwood: auditing the Orchard pool’s supply (June 2026)
  7. Orchard soundness disclosure, May–June 2026
  8. Bünz et al., Bulletproofs (2018)
  9. Halo 2 and the removal of Zcash’s trusted setup for Orchard

This page is an editorial comparison from the Nightfall site. It is not an independent audit of Monero or Zcash, not investment advice, and not a claim that Nightfall is “more private.” No official price, listing or return is asserted for any of the three. Figures such as shielded-supply percentages move; the structural facts (optional vs mandatory, ring vs proof vs aggregation, premine vs empty genesis) are the ones that last.