I can prove I know a secret without telling you what it is
And so can your wallet. This is not encryption — and the difference is the whole point
Last week I watched someone prove, to a stranger, that they could tell two otherwise identical balls apart — red from green — while the stranger physically could not. The proof took four minutes, involved zero words about the balls’ colors, and left the stranger completely unable to say which ball was which.
That is a zero-knowledge proof, and if you stop reading here and keep only one sentence, keep this one: a zero-knowledge proof transmits the fact that something is true, while transmitting none of the thing itself. It is not hiding data by scrambling it. It is proving without revealing — and those are two different animals.

The two-balls trick: what “zero-knowledge” actually means
Imagine a color-blind friend. You have two balls, identical in every way except one is red and one is green. To your friend, they are indistinguishable. You claim you can tell them apart.
The friend — call him the verifier — wants proof. But he doesn’t want to learn which is which; he just wants to know you can tell. So he does this: he holds both balls behind his back, either swaps them or doesn’t, brings them forward, and asks, “did I swap them?”
If you can genuinely see color, you answer correctly every time. If you’re guessing, you’re right only half the time. After, say, twenty rounds, the probability a guesser survives is (1/2)^20 — about one in a million. The friend is now convinced you can see the difference, and he still has no idea which ball is red. You’ve proved the ability without revealing the color.
That’s the entire genre. Every zero-knowledge system, from Zcash to zk-rollups, is a fancier version of this: the verifier keeps asking questions whose correct answers are trivial if you hold the secret, and near-impossible to fake if you don’t.

The cave: why “you can’t just be lucky” is a hard rule
There’s a second analogy that makes the other property click, and it’s worth the detour. It’s usually told as Ali Baba’s cave: a ring-shaped cave with a single entrance and a magic door at the back. The prover claims to know the password to the door.
The verifier doesn’t want the password — he wants proof the prover knows it. So the verifier waits at the entrance while the prover goes in and picks a path, left or right. Then the verifier walks to the entrance and shouts “come out the left side” (or the right). If the prover truly knows the password, he can open the magic door and come out whichever side is demanded. If he’s faking, he’s only correct half the time — the half where the demanded exit matches the path he chose.
Repeat it enough times and the verifier is convinced, without ever learning the password.
The cave teaches the property called soundness: a cheating prover can’t pass, except by vanishingly small luck. The balls teach zero-knowledge: the verifier learns nothing but the truth of the statement. Put them together and you have the two halves of the whole trick.
The three properties, stated like a spec
Because this is crypto and crypto runs on specs, the concept is formally pinned down by three properties. A proof system is “zero-knowledge” only if it has all three:
You’ll notice something uncomfortable here: “zero-knowledge” is a security property you must prove you have, not a feature you assume. A proof can be complete and sound and still leak your secret if it’s badly designed. This is why Zcash’s original setup was done in a “ceremony” with dozens of participants — if any one of them had cheated, the whole thing could have leaked. More on that below. (Zcash is the biggest live user of this trick; I wrote about its NU7 upgrade here.)
Where you’ve already met zero-knowledge proofs
You have almost certainly used one without knowing it. The two places they show up in production:
| System | What it proves | The trick |
|---|---|---|
| Zcash | A shielded transaction is valid, and the sender has the funds | Proves validity without revealing sender, receiver, or amount |
| zk-rollups | Thousands of transactions executed correctly off-chain | Posts one tiny proof to Ethereum instead of all the data |
And here’s the fork in the road that every explainer rushes past: zk-SNARK vs zk-STARK. Both are zero-knowledge proof systems, and they differ in one sentence each:
- 1) zk-SNARK — “Succinct Non-interactive Argument of Knowledge.” Small proofs, fast to verify, but the original design needs a trusted setup: a secret parameter that, if leaked, breaks soundness. That’s the ceremony I mentioned.
- 2) zk-STARK — “Scalable Transparent Argument of Knowledge.” Bigger proofs, but no trusted setup, and the math (hash functions instead of elliptic-curve pairings) is widely considered more resistant to quantum computers.
The practical difference is a trade-off, which is exactly the kind of thing worth knowing before you repeat a slogan: SNARKs are cheap to verify, STARKs are trust-free. Neither is “better” in a vacuum.

Zero-knowledge doesn’t mean “private by default.” It means “private if you can prove you built it that way.”
If you remember nothing else from this piece, remember this: zero-knowledge is not encryption. Encryption hides a message so only the holder of a key can read it back. Zero-knowledge proves a statement while the message never travels at all. One is a locked box; the other is a trick where the box never leaves your hand — and the audience still walks away certain of what’s inside it.
Concept and examples follow the standard formulations in Goldwasser, Micali and Rackoff’s 1985 paper and later interactive-proof literature; the cave and two-balls analogies are the field’s canonical teaching examples. Not an endorsement of any specific coin.
(The End)






