Skip to main content

2026-09-03

· 10 min read
Kaan Kacar
Developer Advocate

Dress Code: Confidential​

I showed up in a black jacket this week, like a serious businessman here to discuss confidential tokens and privacy. Not because I own no other jackets. The agenda: instead of me talking for an hour, we were going to play a game built by SDF's new Frontier Lab team, with a stack of colleagues and ecosystem friends on the call. One piece of housekeeping first, because it was too big to skip: USDT0 is live on Stellar. The infrastructure that carries Tether's USDT to every network launched on Stellar the day before the stream — a real milestone for a chain built for payments and cross-border finance. But this meeting was about confidentiality, and about how we've only scratched the surface of confidential tokens so far. The August 6 Q&A covered the design philosophy; this week was the hands-on version.

The cast: Bri, senior developer advocate on the Frontier Lab team, who built the game. Playing: Tyler, Elliot, Raph from Lumen Loop, Boxy from Stellar Light, and Patrick, introduced by Bri as "some random guy I picked up off the street." Several people arrived in costume. Patrick's suit jacket, Halloween accessories, and riding shades were, in his words, an attempt to be confidential and undercover. He later admitted the jacket was only on because it was wrinkled and he needed it Saturday. Sweating the wrinkles out, live.

Who Ate Gerald?​

Gerald was a villager. Emphasis on was. One morning the village wakes up, Gerald has been eaten, and that's how everyone learns there's a werebear living among them. Who Ate Gerald? is an eight-player social deduction game in the Werewolf/Mafia family: everyone gets a secret role, one player is the werebear, and the village has to banish the werebear before it eats everyone.

Bri built it because she wanted a more fun way than a blog post to demonstrate the confidential token transfer flow, and to learn it herself by building with it. The caveat, stated up front: confidential tokens are still a developer preview, on testnet only, not ready for production. OpenZeppelin built the Soroban contract suite and the Noir circuits that make confidential SEP-41 tokens possible; Nethermind built the UltraHonk verifier that checks the proofs on-chain. The privacy section of the developer docs has the details, and I was pasting that link into chat all stream.

A day in the village:

  • Shop. Log in with Freighter set to testnet, pick a character, and visit two of the four shops: blacksmith, general store, butcher, chapel. Items protect you, expose other players, or just cause chaos. The chapel sells Gerald's fingers; when the eight fingers run out, his two thumbs appear, then toes. Poor Gerald.
  • Ask Maude. Every purchase is a real confidential token transfer. The whole village can see which shop you interacted with, but nobody can see what you bought or how much you spent — except the auditor. In the game that's Maude McLedger, the village fortune teller, who holds the auditor key and can read the amounts. Each player gets one private question per day: "what did Trixie buy at the blacksmith?" or "did anyone buy something from the chapel?"
  • Accuse and vote. Maude's answers become clues, bluffs, and misdirection. Maybe Raph bought a barrel of beer because it protects you from the werebear at night. Or maybe he bought it precisely so you'd think he isn't the werebear. The most-voted player is banished; an innocent villager loses their vote but keeps talking. Then night falls, the werebear eats someone, and the morning starts over with fewer villagers.

You receive 25 XLM of pocket money per day, so blowing it all on day one means no fancy items later. Bri also quietly raised the discussion timer from two minutes to ten, in case things got heated. They did.

Where the Value Actually Lives​

Before the demo, Bri gave the clearest explanation of confidential tokens I've heard so far, built on two mental models. The first: where the value sits.

  1. Regular XLM in your wallet. Public, boring, visible on any explorer. Bri's testnet account was sitting on almost 18,000 test XLM.
  2. The shared pool. The confidential token contract is a wrapper around a regular asset — XLM in the game, but any SEP-41 asset works. Every deposit puts XLM into one big pool held by the contract, and it stays there until someone withdraws. The pool's total is completely public: around 34,000 XLM on stellar.expert during the call. What is not public is how that total is split: 500 of it is Bri's, 100 is Boxy's, 10 belongs to the butcher, and you can't tell any of that from the chain.
  3. Confidential claims. Nobody inside the system carries their own pile of XLM; they carry claims on the pool. For every registered participant the contract keeps an entry with their public keys, a pending balance (OpenZeppelin's docs call it the receiving balance), a spendable balance, and which auditor they chose. When the game says Bri has 500 XLM, she really has a confidential claim on 500 XLM in the pool, and the number itself is hidden inside a Pedersen commitment: anyone can see the commitment on-chain, nobody can read the balance out of it. (Bri: "I actually don't really know what that is very much, so that's all I'm going to say about it." Honest, and correct.)

Hiding the number creates the obvious problem: what stops you from spending money you don't have? Zero-knowledge proofs. A proof says "the hidden math checks out — I had enough, I didn't create money from nowhere, and all the balances still add up" without revealing any numbers. Commitments hide the numbers; proofs make sure nobody cheats.

The Six Steps of a Confidential Payment​

The second mental model is the lifecycle, which the game displays as a checklist that lights up as you play:

  1. Register — each address registers once per wrapper contract. Bri's was already green because she has played the game, in her words, thirty million times.
  2. Deposit — public XLM goes into the pool.
  3. Merge — the sender moves their pending balance into their spendable balance.
  4. Transfer — the sender confidentially moves part of their spendable balance into the receiver's pending balance.
  5. Merge — the receiver moves the incoming claim from pending to spendable.
  6. Withdraw — the receiver exchanges part of their claim for regular XLM back in their wallet.

The first four are the sender's job, the last two the receiver's. Register, transfer, and withdraw are the steps that carry ZK proofs. And the detail that explains the whole game: deposit and withdraw are the only two points where real XLM and confidential claims trade places. Everything in between is claims changing hands inside the pool. Buy a soup bone from the butcher and the contract's public XLM balance does not move; you just privately changed who owns some of what's already in there. Boundaries public, middle private. You could watch it live in the game's on-chain activity feed: every daily "25 XLM" showed up as a public deposit plus a merge, and every purchase as a transfer with the amount marked confidential. Open one on stellar.expert and there is simply nothing to see.

Maude, the Auditor​

The auditor is the part developers trip over most, so: Maude holds a secret key whose public half sits in an on-chain auditor registry. When you register with the confidential token contract, you pick which registry entry audits you; this game's contract offers one option, so Maude audits everyone. In a real application that slot is a regulator, a compliance team, or an independent auditor — someone who legitimately needs the amounts without making them public. This matches what we worked out in the August 6 note: the auditor is chosen per account at registration, out of a registry that can hold many keys.

She is also strict. Ask something too broad or too specific and she declines. Raph burned his first question asking who the werebear was. When I tried to social-engineer her, she told me, more or less, to shine a mirror on myself. Chat's verdict: "this is what regulation has come to — psychics checking our transactions."

How the Game Went​

Bri ran a watcher screen rather than playing, so she could narrate without leaking her own role. The roster: Trixie Diamond the lamp lighter, Lawrence McDig Jones the gravedigger, a drunk named Not The Werebear, a midwife named Definitely Not Kaan, Boxy the rat catcher (very creative), Badger McPatrick the beekeeper, Chuck Roast the poacher, and a baker whose name I won't attempt to spell. Patrick turned out to be playing two characters, which raised the odds considerably.

Day one: everyone shopped (Elliot was broke within minutes), Maude answered what she felt like answering, and the village banished Lawrence McDig Jones — an innocent villager. Sorry, Lawrence. Trixie Diamond was taken in the night, except, as Boxy clarified while nobody believed him, that was a soup bone: an item that redirects an attack onto someone else. Day two: the soup bone was suddenly the most popular item in town, and the village voted out Badger McPatrick, who was indeed the werebear. Two rounds. "This was scripted," Bri insisted. Last time we played I was the werebear, kept buying the same protective item every round, Maude told everyone about my tooth sharpener, and that game lasted five minutes.

The strategy debrief was genuinely useful for understanding the design: protective items early look innocent; the tooth sharpener bypasses everyone's protections and is a near-certain werebear tell; pizza party means nobody gets banished that day, priced at 43 XLM so you can't spam it; the horseshoe nail persists all game and breaks banishment ties in your favor. And yes, you can soup-bone the werebear by accident and end the game on the spot. There is a custom animation for that. There is also one for the werebear winning, in a tutu, with champagne.

Bri kept the repo private until the stream ended so none of us could work out how to cheat with our agents. It's public now: play at gerald.stellar.buzz (Freighter on testnet), read the code at github.com/stellar-experimental/who-ate-gerald, and treat it as a real reference application for confidential token transfers. Bri also floated that she and Teague might build a "Stellar arcade." Official announcement pending, allegedly.

Closing​

Around 300 of you watched a developer meeting conducted largely in costume, and I'm obsessed. Thank you to Bri for building the game, to everyone who played, and to the viewers who put up with us. There is a serious side to confidential tokens — go read the docs — but experimenting should be fun, and this was. Next on the privacy track: Stellar Private Payments with Nethermind. See you next week.