The ledger
Every contract and wallet the project runs: what it's for, who can change it, and the money moving through it. Read from Ethereum every minute.
Goes live at launch. zipcoin isn't on mainnet yet. Who controls what is below now; the numbers fill in once the contracts are live.
-
Sales tax
Every payment settles its tax in the same proof, split three ways.
- Burned
- —
- To couriers
- —
- Treasury's share
- —
-
Treasury liquidity bands
The treasury's share (ZC) goes into ZC's pool as fixed bands above the launch range only, never below it. Their fees, and any ETH the bands receive, go to the Safe.
- ZC into the bands
- —
- Fees to the Safe
- —
- ETH forwarded to the Safe
- —
-
Pool rewards
ZC pays its holders ETH. The pool's share belongs to no depositor, so a harvest sends it to the treasury.
- Harvested to the treasury
- —
-
Emerald
The wallet's assistant, paid per message from a zipped note: part burned, the rest to the treasury, which pays its bills.
- To the treasury
- —
- Burned
- —
Totals of on-chain events in the window, not people: nothing here says who paid. Not investment advice.
Who controls what
Each contract and wallet, what it does, and exactly who can change it. “No owner” means nobody can: not us, not anyone.
Where the money sits
-
The privacy pool
No ownerZipPrivacyPool
Holds every zipped ZC and the tree of notes. Coins leave only with a zero-knowledge proof, or by ragequit to the wallet that deposited them.
Who controls it. No owner. The ZC holder rewards it earns (ETH) go to a treasury address fixed at deployment.
- The Entrypoint's owner can wind it down: no new deposits, while withdrawals and ragequits keep working. It can't be undone.
- Anyone may call harvest(), which can only send the pool's ETH rewards to that fixed treasury address.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
The Entrypoint
2-of-3 SafeEntrypoint (0xbow privacy-pools-core)
The front door: takes deposits, relays withdrawals, and stores the approved-deposit (ASP) roots that private withdrawals must prove against.
Who controls it. A 2-of-3 Safe holds the owner role. The postman's key can only publish ASP roots.
- Owner Safe: upgrade the Entrypoint, register or remove a pool, change a pool's minimum deposit and fee settings, wind a pool down, withdraw Entrypoint fees. An upgrade can change anything the Entrypoint does; ragequit lives in the pool itself, so it can't be taken away by one.
- Postman: publish a new ASP root, which decides which deposits may be withdrawn privately. It can't move coins, and a depositor who isn't approved can always ragequit.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
ZC
Not a zipcoin contractThe existing ZC token (ERC-20)
The currency. zipcoin adds no new token.
Who controls it. Not a zipcoin contract. zipcoin has no power over the token.
- Address
- At launch
- On-chain now
-
Payments
No ownerZipPay
Pays a shop from a zipped note and settles the sales tax in the same proof: part burned, part to the couriers, the rest to the treasury's share.
Who controls it. No owner. The tax rate, the split and where each part goes were fixed at deployment.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Treasury liquidity bands
2-of-3 SafeZipLiquidityBands
Receives the treasury's share of the sales tax and adds it to ZC's pool as fixed one-sided ZC bands above the launch range only (never below it), by fixed rules, when a courier triggers it. Fees, and any ETH it receives, go to the treasury Safe.
Who controls it. The treasury Safe (2-of-3), within limits fixed at deployment.
- Anyone: deposit (within the caps and the minimum interval), collect fees to the Safe, claim the contract's own ETH rewards.
- The Safe only: set the caps (never above the ceilings fixed at deployment), band weights and the share of ETH passed straight to the Safe; pause; forward everything to the Safe; withdraw. Every exit pays the Safe and nothing else.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
The treasury Safe
2-of-3 SafeSafe multisig
The project treasury. It receives the bands' fees and exits and the pool's harvested ETH rewards, and pays the running costs.
Who controls it. A 2-of-3 Safe: any payment needs two of its three signers.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
Everything else
-
Shops
No ownerZipMerchants
Shops stake ZC to be listed and sign every invoice. A shop caught asking to be paid around the tax loses its stake: half to whoever caught it, half burned.
Who controls it. No owner.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Couriers
No ownerZipCouriers
Couriers bond ZC and publish an address. They carry proofs, hold them for a random while, and are paid the couriers' share of the tax. A courier that breaks a signed promise can be slashed by anyone holding the receipt.
Who controls it. No owner.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Badges
No ownerZipBadges
Lock ZC for a while to earn a tier you can prove without saying who you are. The stake goes back into the pool as a new note when the lock ends.
Who controls it. No owner.
- One slashing address was fixed once, at deployment, and can never be changed.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Anonymous posts
No ownerZipSignal
Posts from inside a group ("someone with a tier-3 badge says..."), a few per member per day, with no way to link two of them.
Who controls it. No owner, and it holds no funds.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Polls
No ownerZipPolls
Burn ZC to ask a group a question and pay members to answer. Answers are public and countable; who answered isn't.
Who controls it. No owner.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Broadcasts
No ownerZipBroadcaster
Burn ZC to be heard. The burn is the signal readers rank messages by.
Who controls it. No owner.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Doorstep
No ownerZipDoorstep
Burn ZC at someone's door, with an optional gift that can never dwarf the burn.
Who controls it. No owner.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Private sends
No ownerZipRezip
Spends a note and deposits the value again for the recipient, so the coins never leave the pool.
Who controls it. No owner.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
-
Zip addresses
No ownerZipAddressRegistry
Maps a wallet to a public encryption key, so anyone can send to it privately.
Who controls it. No owner. Each wallet manages its own entry.
- Address
- At launch
- ETH
- —
- ZC
- —
- ETH rewards waiting
- —
- On-chain now
How to read this
Every number comes from Ethereum
The ledger reads the contracts' events and balances once a minute. Each address links to Etherscan, so you can check any of it yourself.
Totals, never people
The sales tax is summed from each payment's split, and the pool's rewards from each harvest. Nothing here says who paid or who deposited.
ETH rewards waiting
ZC pays its holders in ETH. The privacy pool's share belongs to no single depositor, so anyone can harvest it to the project treasury.
Only what's live
The list shows the contracts that are public and running. Features still being built join it on the day they launch.
A Safe needs two of three
Where a Safe has powers, any action needs two of its three signers, and the powers are listed in full. The signers' count is read from the chain; their addresses aren't shown.
First-party only
This page reads one address, api.zipcoin.org, run by the project. No third parties, no cookies, and it logs nothing about who looked.
Numbers can lag the chain by a minute or two. Nothing here is investment advice.