Enygma Retail

Quantum-private payments for people and apps

Rayls Enygma Retail is deployed on the Rayls Public Chain, bringing private payments, swaps and auctions to people, wallets and apps. Hide amounts and counterparties, choose how much to reveal, and stay private even from future quantum computers.

People, wallets and apps
Sender
Other usersCan’t see the payment
Recipient
Rayls EnygmaOn the Rayls Public Chain
shared view key
Auditor
A payment goes from the sender to the recipient through Rayls Enygma on the Rayls Public Chain, which checks it is valid without learning who paid whom, how much or in which asset. Other users see nothing, and an auditor sees only what a user chooses to share. Enygma transactions pay their network fee in $RLS.
ML-KEM
post-quantum encryption, standardised by the US National Institute of Standards and Technology (NIST), protects every user’s view key
4 levels
of recipient privacy, from naming the recipient to revealing nothing at all
$RLS
pays the gas, the network fee, for every Enygma transaction on the Rayls Public Chain

The problem: On a public blockchain, everyone can see your payments

Most public blockchains are transparent by design: anyone can look up who paid whom, how much and when, and the record never goes away. That is fine for a public ledger, but not for everyday payments that should stay between the people involved.

Most public blockchains

Every payment is public

  • Sender visible
  • Recipient visible
  • Amount visible

Anyone can look it up, for ever

Rayls Enygma

Private payments

  • Sender hidden
  • Recipient hidden, to the level you choose
  • Amount hidden

The chain still checks every payment is valid

On a normal public blockchain, anyone can see who paid whom and how much, and the record never goes away. Enygma keeps the same shared, verifiable chain but seals the details, so only the people involved can read them.

The solution: Each user decides how much to reveal

Enygma encrypts every payment with post-quantum keys, then lets people choose their privacy. In retail Enygma, the sender decides how widely to hide who a payment is for, from naming the recipient outright to revealing nothing at all. More privacy means more data for wallets to download, so each user picks the balance that suits them.

  • None

    The recipient is named. The amount stays hidden.

  • Subset

    The recipient is hidden among a few chosen decoys.

  • Rift

    Anyone could be the recipient, except people you rule out.

  • Private

    Nobody can tell who the payment is for.

Dark dots show who could be the recipient. The sender picks a level for each payment, and at every level the amount and asset stay encrypted.

Three private primitives

Payments, asset exchange and auctions, each settled onchain without exposing the parties or the amounts.

Payments

Private payments

Move tokenised money between accounts without publishing who paid whom or how much, with a verifiable proof that nothing was created or spent twice.

Settlement

Private delivery-versus-payment

Swap a tokenised asset for payment in one atomic settlement: both legs complete or neither does, and the asset, price and parties stay confidential.

Markets

Private auctions

Auction an asset without exposing the bids to the rest of the network, and deliver it against the winning payment in the same settlement.

$RLS, the gas token for Enygma transactions

$RLS is used only to pay the gas for Enygma transactions: private payments, swaps and sealed bids. Gas is the small fee a blockchain charges to process a transaction. Everything else on the Rayls Public Chain still pays its gas in $USDr, the chain’s standard gas token, pegged 1:1 to the US dollar. The demo works the same way: before you confirm any private action, it shows the network fee in $RLS.

How Enygma Retail compares

Enygma Retail against the privacy tools people use today, compared on what they hide, how much you can choose to reveal and what you can share with an auditor.

Scroll sideways to compare →

  Rayls Enygma RetailZero-knowledge (ZK) privacy with a post-quantum view key for every user RailgunZK shielded pool for Ethereum-compatible (EVM) chains ZcashPrivacy coin with zero-knowledge shielded transactions ZamaFully homomorphic encryption (FHE): computing on encrypted data Tornado CashFixed-denomination mixer
Hides amounts
Yes, in commitments
Yes, inside the pool; shielding and unshielding are public
Yes, in shielded transactions; transparent ones are public
Yes, balances and amounts encrypted with FHE
No, fixed public denominations
Hides who paid whom
Yes, at a privacy level each user chooses
Yes, inside the pool
Yes, when both sides use shielded addresses
No, sender and recipient addresses stay visible
Partly, breaks the deposit-to-withdrawal link only
Choose how much to reveal, per payment
Yes, four levels, from naming the recipient to revealing nothing
No, one privacy model for every shielded transfer
Partly: each payment is shielded or transparent, with nothing in between
No, amounts are always encrypted and addresses always visible
No
Recorded data safe from a future quantum computer
Yes, every user’s view key uses ML-KEM, the NIST post-quantum standard
No, notes encrypted with elliptic-curve (Ed25519) key exchange
Partly: note encryption uses elliptic curves, so a quantum attacker who knows your address could read notes sent to it; ML-KEM is planned
Yes, lattice-based FHE, which Zama describes as post-quantum
No, elliptic-curve based
Who can read your payments
Only you and the recipient, with your view keys; no decryption committee
Only holders of your viewing key
Only holders of your viewing key
A threshold key-management network decrypts on request: 9 of its 13 nodes must cooperate
Only the holder of the deposit note
Share with an auditor
Share one transaction, or your whole view key; it can never move funds
Share a wallet-wide viewing key; optional Private Proofs of Innocence, showing funds do not come from a list of flagged addresses
Share a full viewing key, which reveals your whole history; it can never spend
Per-value access rules set by each contract
Can only prove that one deposit links to one withdrawal
Private swaps
Yes, atomic swaps: both sides settle together or not at all
Private DEX swaps through contract calls; no delivery-versus-payment primitive
No, ZEC only today; shielded assets are planned for the NU7 upgrade
Encrypted swaps can be built as contracts; no delivery-versus-payment primitive
No, deposit and withdraw only
Private auctions
Yes, sealed bids settled against the winning payment
No native primitive
No native primitive
Yes, sealed-bid auctions
No
EVM compatible
Yes, deployed on the Rayls Public Chain, an EVM chain
Yes, contracts on Ethereum, Polygon, Arbitrum and BNB Chain
No, Zcash is its own chain
Yes, Solidity contracts on existing EVM chains
Yes, contracts on Ethereum and other EVM chains
Proof system
Groth16 zero-knowledge proofs
Groth16 over BN254
Halo 2 (Orchard) and Groth16 (Sapling)
TFHE, plus proofs of correct encryption
Groth16 over BN254

Terms used. ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) is a post-quantum way for two parties to agree a secret key, standardised in 2024 by NIST, the US National Institute of Standards and Technology; it rests on lattice maths that quantum computers are not known to break. A view key lets its holder read payments but never move funds. Groth16 is a widely used type of zero-knowledge proof, and BN254 is the elliptic curve it runs on. Ed25519 is an elliptic-curve scheme, the kind of classical cryptography a large quantum computer could break. TFHE is the fully homomorphic encryption scheme Zama uses. A shielded pool is a shared contract where tokens are held privately; shielding and unshielding are the deposits and withdrawals. A mixer pools deposits so withdrawals cannot be traced back to them. A DEX is a decentralised exchange. Halo 2 is the zero-knowledge proof system of Zcash’s newest shielded pool, Orchard; Sapling is its older pool, and transparent Zcash addresses are public, like Bitcoin’s. The EVM (Ethereum Virtual Machine) runs Ethereum-style smart contracts, so Solidity code and Ethereum tools work unchanged.

None of these systems yet uses a quantum-secure proof system: all five rely on proofs that keep data private but are not quantum-secure against forgery. Moving Enygma to a quantum-secure proof system is on its roadmap.

Based on each project’s own public documentation as of September 2026: Railgun privacy system, Private Proofs of Innocence, Zama Protocol litepaper, Tornado Cash on L2BEAT, Zcash viewing keys, ZIP 2005, ZIP 226 (Zcash Shielded Assets) and Railgun on L2BEAT.

Cutting-edge research, published in the open

Enygma is designed in the open: presented at two leading academic security conferences, IEEE Security and Privacy and Financial Cryptography, free to read on the IACR Cryptology ePrint Archive (the open archive of the International Association for Cryptologic Research), and open source. Every paper describes a quantum-private design, in which payer, payee and amount stay hidden even from an adversary with a quantum computer.

  1. May 2024
    IEEE Symposium on Security and Privacy · poster

    Rayls: A Novel Design for CBDCs

    The design for central bank digital currencies (CBDCs) is first presented publicly at one of the flagship conferences in computer security.

  2. 2025
    CoDecFin (Coordination of Decentralized Finance) workshop at Financial Cryptography 2025 · ePrint 2025/1639

    Rayls: A Novel Design for CBDCs Quantum-private

    Yaksetig and Xu. Private, auditable transfers between institutions, hidden inside anonymity sets (groups of possible participants), with post-quantum key agreement so that a quantum adversary cannot learn payer, payee or amount.

  3. 2025
    Financial Cryptography in Rome 2025 · ePrint 2025/1638

    Rayls II: Fast, Private, and Compliant CBDCs Quantum-private

    Yaksetig, Pereira, Yang, Nejadgholi and Xu. The current institutional design, with proof generation cut from about four seconds to 408 milliseconds (under half a second) on a Mac mini.

  4. Today
    Rayls documentation · open source

    ML-KEM replaces CSIDH

    Key exchange is how two parties agree a secret key. For auditor keys it now uses ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism), the post-quantum standard published in 2024 by NIST, the US National Institute of Standards and Technology, built on lattice maths that quantum computers are not known to break. It replaces CSIDH (Commutative Supersingular Isogeny Diffie–Hellman, pronounced “seaside”), an earlier, more experimental post-quantum method used in the papers. The proof circuits and smart contracts are open source.

Try Enygma on the Rayls Public Chain

Send, swap and bid privately in the demo, with real post-quantum encryption and gas paid in $RLS, then read how Enygma works in the docs.

Questions about Enygma

Is Enygma quantum-safe?

Enygma is quantum-private: even an adversary with a quantum computer cannot infer the payer, the payee or the amount of a transfer. Key agreement, the step where two parties agree a secret key, is post-quantum. In retail Enygma, every user's view key is an ML-KEM key. ML-KEM, short for Module-Lattice-Based Key-Encapsulation Mechanism, is a way to agree a secret key that quantum computers are not known to break, standardised in 2024 by NIST, the US National Institute of Standards and Technology. In institutional Enygma, auditor key exchange uses ML-KEM too. The zero-knowledge proofs currently use Groth16, a widely used proof system, which keeps transactions private but is not yet quantum-secure against forgery; moving to a quantum-secure proof system is on the roadmap.

What does the chain actually see?

Commitments, nullifiers and zero-knowledge proofs. The amount sits inside a commitment, a sealed value the chain can check but not read. The nullifier is a one-time marker that stops the same funds being spent twice. The zero-knowledge proof shows the transfer balances, all without revealing who paid whom or how much.

Where is Enygma live today?

Enygma Retail is deployed on the Rayls Public Chain, the permissionless, Ethereum-compatible (EVM) chain anyone can use, and that is where the demo runs. Enygma transactions there pay their gas, the network fee, in $RLS; every other transaction on the chain pays in $USDr, its standard gas token. Institutional Enygma is in production in the Rayls Sovereign chains institutions run. The retail design is described in a forthcoming paper.

What is the difference between retail and institutional Enygma?

Retail Enygma is note-based, with money held as sealed digital notes, and built for end users: every user holds an ML-KEM view key to find and read payments and a separate spend key to move funds, chooses their own level of privacy, and can pay, swap or bid privately. Institutional Enygma is account-based, like a bank ledger, and built for banks, central banks and market infrastructures that settle with each other. See the Enygma Institutional page for that edition.