RE: LeoThread 2026-03-16 23-49

You are viewing a single comment's thread:

😭



0
0
0.000
11 comments
avatar

Most decentralized payment protocols don't support these memos without users paying extra to include them, and even then they're rarely truly "encrypted" unless addresses signal the required capabilities. A few exceptions exist, such as Lightning, but those use off-chain, interactive payment protocols

0
0
0.000
avatar

They are popular in Zcash and are a strong memetic tool. That's understandable. The reality:

  • every payment must include a memo, even if unused, to preserve indistinguishability
0
0
0.000
avatar
  • memos are fixed at 512 bytes and cannot vary in size for the same reason
  • any on-chain memo could be intended for any user; the only private way to know is to fetch and trial-decrypt every memo
0
0
0.000
avatar

Historically these memos were added because SNARKs were already large and on-chain key exchanges were part of Zerocash, so the extra memo blob had little marginal cost

0
0
0.000
avatar

Any scalable version of Zcash, including Tachyon, will reduce marginal transaction size so much that conventional memos would make up the bulk of a shielded transaction's on-chain cost

0
0
0.000
avatar

There are a few ways around this. One option is off-chain payment protocols that carry encrypted memos elsewhere; these often impose UX tradeoffs or require extra infrastructure, but they allow larger memos and are preferred if feasible

0
0
0.000
avatar

Alternatively, a PIR-based approach could preserve the on-chain payment protocol and familiar UX; work on such schemes is ongoing and could be a game-changer, though limitations remain that prevent memos from being as cheap or unsustainably used as today while keeping the same UX

0
0
0.000
avatar

Finally, users could continue including memos and simply pay extra. Memos compete for capacity, and several payments can consume the same resources as a single transaction's memo. Using the chain as a broadcast medium with trial decryption would severely limit who can afford this at scale and would harm privacy by reducing indistinguishability

0
0
0.000
avatar

There's no free lunch here; every preservation path will upset someone

0
0
0.000
avatar

The guiding principle for Tachyon is to separate the shielded protocol from the payment protocol to allow flexibility in choosing the scalable option that works best. Future pools should be built this way. That accommodates any of the three approaches and is simpler to implement, which is why this part of Tachyon is being prioritized

0
0
0.000