Why private money
Cash in your pocket does not announce to the world how much you hold, who paid you or what you bought. Most blockchains do the opposite: every balance and every payment is published forever, readable by anyone, and easy to link to a person once a single transaction is tied to their identity.
GENORYN restores the properties of cash to digital money. Payments are verified by everyone, but their contents are visible only to the people involved. That is not a loophole — it is the default for every transfer, because financial privacy protects ordinary people from theft, discrimination, profiling and coercion.
Privacy is not a crime. It's a right.
Shielded notes
GENORYN has no accounts and no public balances. Value lives in notes: small encrypted records that say "this amount belongs to this receiver." When you are paid, the sender creates a new note encrypted to your receiving identity using one-time key material. Repeated payments to you do not publish a stable destination.
Your wallet finds your money by trial-decrypting every note in every block on your own computer. Notes it can open are yours; the rest are noise. Because this happens locally, there is no server to ask "what is my balance?" — and therefore no server that could leak it.
Commitments and nullifiers
If everything is encrypted, how does the network stop someone from spending the same money twice? Two public values make it work:
- A note commitment is published when a note is created. It goes into a large Merkle tree (32 levels deep) of all notes ever made. It reveals nothing about the amount or owner.
- A nullifier is published when a note is spent. Only the owner can compute it, it is unique to that note, and it cannot be linked back to the commitment by anyone else.
Every node keeps the set of all nullifiers. A transaction that reveals a nullifier already in the set — in the chain or in the mempool — is rejected. So double spending is impossible, yet nobody learns which note was spent.
Zero-knowledge proofs
Each transaction carries a Halo 2 proof — a few kilobytes of mathematics that convince every node of statements like these, without revealing the underlying data:
- the notes being spent exist in the commitment tree at a recent anchor;
- the spender knows the keys that authorize them;
- the nullifiers are computed correctly;
- inputs equal outputs plus the public fee — no money is created.
Halo 2 needs no trusted setup ceremony: there is no secret "toxic waste" that someone could use to forge coins.
Keys and addresses
Your 24-word recovery phrase derives three distinct kinds of capability:
- Spend authority — signs spends. Never leaves your wallet.
- Full viewing capability — decrypts your notes to show balance and history. Stays local.
- Receiving identity — the address you share (it starts with
gnr1on mainnet). It never appears on chain.
The wallet file is encrypted with Argon2id and XChaCha20-Poly1305, and it locks after five minutes without input. Lose the password but keep the phrase, and you can restore. Lose both, and no one — by design — can recover the funds.
Proof of work
Blocks are produced by miners competing to find a RandomX hash below a target. RandomX runs a random program in a virtual machine that suits the large caches and branch predictors of general-purpose CPUs, so a laptop can take part.
The chain everyone follows is the valid one with the most accumulated work. Difficulty adjusts every block so that blocks arrive about every 60 seconds no matter how many miners join. Read the exact formulas on the Mining page.
A finite supply
There will never be more than 21,000,000 GNR — and because the mainnet treasury share is burned, at most about 20,789,999.99995 can ever circulate. New coins enter only through block rewards on an exact integer schedule: blocks 1–500 pay a fixed early subsidy of 1,000 GNR each, and from block 501 the normal reward halves every four years. There was no premine, there is no mint transaction, no admin key and no way for anyone — including developers — to create more.
The early subsidy goes to whoever mines those first blocks. At launch the only known miner is run by the project operator, so the operator may receive most or all of those 500,000 GNR (about 2.38% of the cap) and early holdings may be concentrated. See the Mining page for the full disclosure.
Wait — if amounts are hidden, how can anyone audit the cap? Because issuance is the one thing that is public: miner and treasury rewards and all fees are visible numbers in every block, and the proofs guarantee that shielded transfers can neither create nor destroy value.
Fees
Every ordinary transfer pays a positive, public fee to the miner who includes it — at least 0.00001 GNR. The wallet suggests Economy, Standard and Priority at 1×, 2× and 5× the minimum. Miners order transactions by fee per byte. Fees move existing value; they are not new issuance.
Confirmations and finality
A sent payment waits in the mempool until a miner includes it in a block. Each further block buries it deeper; reversing it would require redoing all that work faster than the rest of the network. That is probabilistic finality — strong after several confirmations, but never instant. The wallet shows the exact confirmation count.
Payment proofs
Sometimes you need to prove a payment — to a merchant, an auditor or a court. The wallet can export a proof for a single output: whoever receives it learns that output's recipient and amount, and can check it against the chain. Nothing else is revealed: no spending key, no other outputs, no wallet-wide view key.
Usernames
Instead of a long address you can share @name. Names live on the blockchain: the first valid registration wins, names never expire, and every node derives the same table. The price is burned (1,000 GNR for 3–4 letters, 100 for 5–6, 10 for 7+), which makes squatting expensive. A name points to a separate receiving address of your wallet, and payments to it stay shielded. Check any name on the Names page.
The limits of privacy
Honest limits are part of the design. Read the full threat model.