Maximum-privacy coin

Amounts hidden, recipients hidden — proven against a single global anonymity set.

Unfortunately, not fast

We trade speed for privacy. On purpose — and we won't apologize for it.

100% fair distribution

Every coin is mined. No pre-mine, no sale, no insiders.

No dev coins

Zero founder allocation. Not a single coin set aside.

100% open

Open protocol, open source, open to everyone.

Minable

Earn OBX with CPU proof-of-work (RandomX) — no special hardware.

Staking of rewards

Stake your OBX any time — earn yield, unstake whenever you want.

Join the community & start mining

Run a node, mine OBX, and help the network grow.

How Obscura compares

Privacy without the trade-offs

Obscura is engineered to close all three gaps at once — a global anonymity set, no trusted setup, and constant-size state — with a built-in post-quantum path. Here is how that stacks up against the field.

ObscuraStrengthWeakness / gap
Feature Obscura (OBX) Monero Zcash Mimblewimble (Grin/Beam) Bitcoin
Privacy modelGlobal anonymity set + zk-STARK shielded spendSmall ring signatures + RingCTzk-SNARK shielded pool (global for shielded tx)Confidential Transactions (Pedersen)Transparent / pseudonymous
Anonymity set sizeGlobal — the entire unspent-output set via a dynamic accumulator; grows with every new coinSmall fixed ring per tx (~16 decoys)Global for shielded transactionsWeak / none (transaction-graph analysis possible)None (addresses & amounts visible)
Sender unlinkabilityFull cryptographic — zk-STARK membership proof + recipient-secret nullifierPlausible deniability via rings (heuristic de-anonymization attacks exist)Full in shielded poolNone (graph links survive)None
Recipient privacyFull — dual-key stealth addresses + recipient-secret nullifierFull (stealth addresses)Full in shielded poolMinimal (no traditional addresses)None (addresses visible on-chain)
Amount confidentialityFull — Pedersen commitments or in-field STARK confidential amountsFull (RingCT)Full in shielded poolFull (Pedersen confidential transactions)None (amounts visible)
Trusted setup requiredNo — class-group accumulator of unknown order + transparent zk-STARKNoYes — original Sapling ceremony (later versions improved; historically required)NoNo
State size / scalabilityConstant-size — dynamic accumulator + succinct STARK proofs + intrinsic PoR pruningGrowing (full chain + key images + rings)Growing (Merkle tree for shielded pool)Compact via Mimblewimble cut-throughGrowing (full UTXO set)
Proof system / technologyTransparent zk-STARK (Goldilocks field, FRI, Poseidon) + BBF accumulatorLinkable ring signatures + Bulletproofszk-SNARKs (Groth16 / later)Pedersen commitments + range proofsECDSA + SHA-256 (no privacy proofs)
Proof size & verify costConstant / succinct (~592 KB prove, ~12 ms verify)Grows linearly with ring sizeConstant & smallSmall / compactN/A (no privacy proofs)
Post-quantum pathYes — built-in v2 migration (IWOTS+ hybrid signatures, ML-KEM-768 stealth, lattice commitments, Merkle accumulator); STARK already hash-basedNo (primarily EC-DLP)No (pairings + EC)No (primarily EC-DLP + Pedersen)No (ECDSA + SHA-256)
Consensus mechanismNakamoto PoW (RandomX — ASIC-resistant) + Proof-of-RetrievalNakamoto PoW (RandomX)Nakamoto PoW (various algorithms)Nakamoto PoWNakamoto PoW (SHA-256)
Block time120 seconds~120 seconds (target)~75 seconds (varies)~60 seconds (Grin)~10 minutes
Emission schedule~18.4M cap + perpetual 0.6 OBX/block tail (smooth decay)Monero-style tail emission21M cap with founders' reward (declining)Tail-emission model (Grin)21M hard cap with halvings → 0 subsidy
Chain compaction / pruningIntrinsic — PoR + periodic snapshots + automatic body pruningFull chain retained (pruning optional, not consensus-enforced)Full chain retainedStrong built-in cut-through compactionFull chain retained (optional pruning)
Cross-chain atomic swapsYes — trustless scriptless adaptor-signature swaps, live with Nano/XNO (no bridge, no custodian)External / limitedVia wrapped tokens or bridgesLimited / externalVia HTLCs or external bridges / wrapped tokens
Private staking / yieldYes — Confidential Vaults (private yield from a bounded incentive pool, no new supply)No built-in (external services)No built-inNo built-inNo built-in (PoS chains have it)
Implementation languagePure Go (CGO-free) — single static binary + embedded desktop UIC++ (multiple implementations)C++ (multiple implementations)Rust (Grin) / C++ (Beam)C++
Status (July 2026)v1.1 whitepaper + running reference implementationLive mainnet since 2014Live mainnet (shielded + transparent)Live mainnets (Grin & Beam)Live mainnet since 2009
Key strengthCloses all three gaps at once — global anonymity set + no trusted setup + constant-size state + post-quantum pathStrong privacy, but a small/rationed anonymity set and chain bloatGlobal shielded set, but historically required a trusted setupExcellent compactness, but no cryptographic sender unlinkabilityBaseline transparent money — no native privacy
Key weaknessNewer project (reference implementation shipping)Small anonymity set + heuristic decoy selection enables de-anonymizationTrusted-setup risk (toxic waste) + larger proofs historicallyTransaction-graph analysis possible despite confidential amountsCompletely transparent — full linkability & amounts visible
flowchart TB

subgraph WAL["WALLET · build and prove"]
  direction LR
  W1["Transparent
Pedersen + Schnorr"]:::wal W2["Confidential ZK
hidden amounts"]:::wal W3["Unlinkable
recipient-secret nullifier"]:::wal W4["zk-STARK anon spend
transparent · no trusted setup"]:::wal W5["Vault
private staking"]:::wal W6["Cross-chain swaps
XNO scriptless · BTC HTLC (disabled)"]:::wal W7["Post-quantum
ML-KEM-768 stealth"]:::wal end subgraph MEM["MEMPOOL · admit"] direction LR M1["Parallel proof verify"]:::wal M2["Value conservation"]:::wal M3["Shared nullifier set"]:::wal M4["Bounded · fee-priority"]:::wal end subgraph P2P["P2P MESH · censorship-resistant"] direction LR N1["Self-discovering
PEX + addr-me"]:::net N2["Eclipse-resistant
/16 group caps"]:::net N3["Tor · .onion
Dandelion++"]:::net N4["Seedless"]:::net end subgraph MIN["MINER · full node by protocol"] direction LR R1["Proof-of-Retrievability
k challenges on retained span"]:::min R2["Memory-hard PoW
epoch seed · LWMA"]:::min R3["Paced to block time"]:::min end subgraph VAL["VALIDATION · every node"] direction LR V1["PoW + difficulty + MTP"]:::min V2["PoR vs stored headers"]:::min V3["Per-tx proofs
STARK · PQ"]:::min V4["Conservation + nullifier"]:::min V5["Header roots match"]:::min end subgraph ST["STATE · constant-size, committed"] direction LR S1[("Class-group accumulator
all coins · constant-size")]:::sta S2[("Nullifier set")]:::sta S3[("Epoch-sharded
Poseidon tree")]:::sta S4[("PQ anonymity accumulator")]:::sta S5[("Vaults · swaps · incentive pool")]:::sta end HDR["HEADER · Acc·Null·CM·PQ·PoR roots
bound by PoW"]:::sta CH[("CANONICAL CHAIN")]:::sta PR["Pruning by design
3-tier · snapshot sync · miners too"]:::sta XC[("Cross-chain order book
OBX↔XNO (live) · OBX↔BTC (planned)")]:::net STOP(["✗ cannot mine"]):::stop WAL ==>|"signed tx + STARK proof"| MEM MEM ==>|"Dandelion++ gossip"| P2P P2P ==>|"select ≤ 1000 txs"| MIN MIN ==>|"mined block"| VAL VAL ==>|"apply · atomic · reorg-safe"| ST ST ==>|"5 roots + NumTxs"| HDR HDR ==> CH CH ==> PR S3 -.->|"recent CMRoot = spend anchor"| W2 S3 -.-> W3 S5 -.->|"confidential yield"| W5 W6 <--> XC W7 -.-> S4 CH -.->|"broadcast block"| P2P CH -.->|"fork-choice: most-work + hash tie-break + partition recovery"| CH PR -.->|"snapshot serves new nodes"| P2P R1 -.->|"can't prove retained span"| STOP classDef wal fill:#08313a,stroke:#00e6c3,color:#dffbf5; classDef net fill:#1e1640,stroke:#8b6cff,color:#ece7ff; classDef min fill:#3a1426,stroke:#ff7ad9,color:#ffe6f6; classDef sta fill:#3a2e0b,stroke:#ffc15e,color:#fff3dc; classDef stop fill:#2a0f12,stroke:#ff5a5a,color:#ffd9d9;
Solid arrows = a transaction's path · dotted = cross-links · zoom to read every box