Nullifier

Prove it.Once.

Nullifier brings the private proofs of Vitalik Buterin's Snowmoon to Ethereum. Lock $NULL to hold a mark, then prove at any gate that you belong and carry enough weight, without showing which wallet is yours. Each proof leaves a nullifier, so the same mark never passes the same gate twice.

Supply
777,777,777
Burned
0
Ethereum block
...

Present a pass

This is your mark as a gate sees it: no holder, no wallet, one punch per gate. Try the same gate twice.

Pick a gate and present the pass. Then present it at the same gate again.

What the chain sees

    One set.
    Many gates.

    A mark is a private note hidden among thousands of others in one public set. Using it reveals a fingerprint tied to one gate. Never the note, and never the wallet that made it.

    1. I

      Enter

      Lock $NULL and add a commitment to the set. The commitment is a hash of a secret only you hold. The chain sees a new leaf, not a name.

    2. II

      Blend in

      Others enter after you. The bigger the set grows, the harder it is to tell which leaf is yours.

    3. III

      Prove

      At a gate, a zero-knowledge proof shows your leaf is in the set and your weight clears the bar. Send it from any fresh address.

    4. IV

      Nullify

      The proof carries a nullifier made from your secret and the gate. The gate records it. Try again and the same nullifier comes out, so it is refused.

    Commitment

    C = H(secret, weight)

    Public when you enter. It says nothing about you.

    Gate nullifier

    N = H(secret, gate)

    Public when you prove. Same gate, same N. Different gates, values nobody can link.

    Mark nullifier

    S = H(secret, "spend")

    Public when you spend. Once it is recorded, the mark is gone everywhere.

    Show it, or spend it

    Reputation means something when using it costs you. Every mark can be used two ways, and each gate decides which one it asks for.

    Show

    Prove the mark at one gate. It survives and can show at other gates, but never twice at the same one. One person, one vote, one claim.

    Reveals
    Gate nullifier N
    Mark after
    Still in the set
    Cost
    Gas only
    Linkable
    No, each gate sees an unrelated value

    Spend

    Use the whole mark at once. It leaves the set for good and part of its lock burns. A vouch someone paid for is a vouch people believe.

    Reveals
    Mark nullifier S
    Mark after
    Gone everywhere
    Cost
    10% of the lock burns
    Remainder
    90% to any address after 72 hours

    The gate line

    A gate is any place that needs to know someone qualifies, exactly once, and nothing else. Anyone can open one by burning 1,000 $NULL and setting a scope, a minimum weight, a mode and a closing time.

    Show line
    Council voteWeight 1 or more

    Every mark votes once. Nobody sees how any wallet voted.

    Fair dropWeight 2 or more

    Claim to a fresh address, one claim per mark, untraceable to the wallet that entered.

    Tunnel accessWeight 3

    Join a private room. It knows every member qualified, never who they are.

    Carry forwardIssues a mark

    Pass it and add a fresh mark to the set, unlinkable to the old one.

    Spend line
    Vouch roundWeight 1 or more

    Stand behind someone's work. Each vouch spends a mark, so it means something.

    SignalWeight 2 or more

    Post a report with weight and no name. A false one gets its nullifier refused for good.

    RetiredEnd of the line

    The mark leaves the set. A tenth of its lock burns and the rest goes to any address you name after 72 hours.

    In Snowmoon, a proof says yes and nothing more.

    In Snowmoon, Vitalik Buterin's 32-chapter novel released in September 2026, the city-state of Veridia lives beside the Arctic Empire, a state that records what its people buy, say and where they go. Veridia holds together because its citizens can prove things about themselves, their age, their right to ride transit or enter a city zone, without handing over the data behind the proof.

    A nullifier is the small piece that makes that work. A proof alone could be replayed a thousand times. A proof with a nullifier can be used once per purpose and still says nothing about who made it. Nullifier turns that piece into a public mechanism anyone on Ethereum can use.

    Nullifier is an independent project inspired by the novel. It is not made or endorsed by Vitalik Buterin.

    Three fares

    $NULL is the lock behind every mark and the fee behind every gate. Locking it makes a mark costly to fake. Burning it makes a spend believable.

    Weight only says "at least"

    A proof never reveals your fare. A Full mark passes a weight 1 gate without telling the gate it is Full, so bigger holders hide among smaller ones. Exiting returns the whole lock to any address after 72 hours, with nothing burned.

    Burns come from three places: gate openings at 1,000 $NULL each, appeals at 500 $NULL each, and spent marks at 10% of the lock.

    Network
    Ethereum mainnet
    Ticker
    $NULL
    Supply
    777,777,777 $NULL
    Burned so far
    0 $NULL
    Contract

    Ticket office

    Your secret comes from a wallet signature, so the wallet that signed can always rebuild it. Keep the note private. Whoever holds it can use the mark.

    Window 1

    Make your note

    1. Connect the wallet you will lock $NULL from.
    2. Sign the Nullifier message. Nothing is sent and no gas is paid.
    3. Your secret and commitment are built from that signature, here in the page.
    Your note appears here after you sign.
    Window 2

    Lock and enter

    Pick a fare. Entering approves the lock, then adds your commitment to the set.

    Your $NULL
    Connect a wallet
    Marks in the set
    Opens with the registry

    Asked at the window

    What exactly does a gate learn?

    That a valid mark from the set, with at least the gate's weight, was used here, and the nullifier for that use. Not which leaf, not which wallet entered it, not what else that mark has done.

    Why can't I use a mark twice at one gate?

    The nullifier is a hash of your secret and the gate's scope. Every proof you make at that gate produces the same value, and the gate refuses a value it has already recorded.

    Can two gates compare notes and find me?

    No. Your nullifier is different at every gate, and without your secret nobody can tell that two values came from the same mark.

    What should I send proofs from?

    A fresh address, or a relayer. Proving from the wallet that entered the set still works, but it tells everyone which leaf is yours.

    What if I lose my note?

    Sign the same message with the same wallet and the page rebuilds it. If the wallet is lost too, the mark cannot be used.

    Can I leave without spending?

    Yes. An exit proof removes your mark and returns the full lock to any address after 72 hours. Exiting reveals the mark nullifier, like a spend, but nothing burns.