What a Nullifier Actually Stops From Happening Twice
I checked what specifically a nullifier prevents on Dusk, since "prevents double-spending" gets said without much precision.
It stops the same shielded note from being spent more than once — nothing broader than that.
I traced how Dusk does this without revealing which note was spent. Dusk's own repository states the nullifier is computed specifically so an external observer cannot link it to any particular note. The network doesn't check the note itself against a list; it checks whether this exact nullifier has already appeared.
I confirmed the note doesn't get removed from anywhere once spent. It stays recorded in Dusk's Merkle tree of notes. Only the nullifier gets added to a separate, growing record.
That distinction matters. If notes were deleted on spend, I'd expect that to leak timing information just from watching the structure shrink. Keeping every note in place, spent or not, removes that particular signal.
I looked for whether this creates any collision risk — two different notes accidentally producing the same nullifier. I found no documented case of that in Dusk's own materials, though the guarantee rests on the same underlying cryptographic assumptions the rest of the system depends on.
So a nullifier on Dusk isn't really "marking" a note as spent in any visible sense. It's proving a spend happened, without identifying what was spent.
Does preventing double-spends this way protect more privacy than it's worth in permanent, ever-growing storage?
@Dusk_Foundation #dusk $DUSK #dusk
I checked what specifically a nullifier prevents on Dusk, since "prevents double-spending" gets said without much precision.
It stops the same shielded note from being spent more than once — nothing broader than that.
I traced how Dusk does this without revealing which note was spent. Dusk's own repository states the nullifier is computed specifically so an external observer cannot link it to any particular note. The network doesn't check the note itself against a list; it checks whether this exact nullifier has already appeared.
I confirmed the note doesn't get removed from anywhere once spent. It stays recorded in Dusk's Merkle tree of notes. Only the nullifier gets added to a separate, growing record.
That distinction matters. If notes were deleted on spend, I'd expect that to leak timing information just from watching the structure shrink. Keeping every note in place, spent or not, removes that particular signal.
I looked for whether this creates any collision risk — two different notes accidentally producing the same nullifier. I found no documented case of that in Dusk's own materials, though the guarantee rests on the same underlying cryptographic assumptions the rest of the system depends on.
So a nullifier on Dusk isn't really "marking" a note as spent in any visible sense. It's proving a spend happened, without identifying what was spent.
Does preventing double-spends this way protect more privacy than it's worth in permanent, ever-growing storage?
@Dusk_Foundation #dusk $DUSK #dusk
Worth it
100%
Too much storage
0%
6 الأصوات • تمّ إغلاق التصويت