New on Pli: zk-SNARK amount proofs.
Sometimes a third party needs to know *something* about a payment request — an escrow checking it's under a limit, a marketplace checking it matches the price, an accountant checking a bracket.
Until now that meant opening it. Address, exact amount, memo: all exposed.
Now you can prove the amount is inside a range — and nothing else.
→ Every pli carries a hidden commitment to its amount
→ You pick a range: "at most 5 ZEC"
→ Your browser builds a zero-knowledge proof in ~1 second
→ Anyone can verify it against the sealed pli. No passphrase. Nothing opened.
Amount out of range? The proof can't be made. That's the point.
PLONK over BN254, public Powers of Tau setup — no trusted setup of ours. Proving happens client-side; nothing is uploaded.
Same family of math that powers Zcash itself.
https://t.co/i9588gl3yd
CA: 0x28627e1c96ccb7cd77c66832660976730d644496
What Pli won't do.
× Accept transparent addresses. t1/t3 payments are public on-chain — sealing the request would be theatre. It refuses.
× Save a weak passphrase. 600,000 key-derivation rounds slow a dictionary attack. They don't stop one. Use the generator.
× Enforce expiry on-chain. The payer's browser checks it. Good against stale links, not against someone who edits the page.
× Touch your funds or keys. It only ever handles a receiving address. Nothing to steal, nothing to custody.
A privacy tool that doesn't tell you where it stops isn't one.
https://t.co/i9588gl3yd
Old links don't haunt you.
A payment request you sent in March is still sitting in someone's inbox. Still valid. Still pointing at your address.
Pli requests expire: 1 hour, 24 hours, 7 days — your call.
The expiry is sealed *inside* the pli, next to the address. Nobody can read it, strip it or extend it without the passphrase.
Honest limit: it's enforced by the payer's browser, not the network. It kills forgotten links — not a payer who rewrites the page. We'd rather tell you.
https://t.co/i9588gkvIF
Even the size is a secret.
Encryption hides what a message says. It doesn't hide how long it is — and length leaks. A short request is a small payment with no memo. A long one is an invoice with details. Traffic analysis 101.
Pli pads every request with random noise up to the next 512 bytes *before* encrypting it.
A coffee and a salary look identical on the wire.
It's a small detail. Privacy is made of small details.
https://t.co/i9588gkvIF
CA: 0x28627e1c96ccb7cd77c66832660976730d644496
Your shielded tx is private.
The payment request you DM'd? Address, amount, memo — all readable.
Pli seals it in your browser. No server. No cookies. Shielded addresses only.
https://t.co/CbrCMfCuqm 🔒
$ZECPLI
Count the servers.
0 servers see your request — it's encrypted before it leaves your browser
0 cookies, trackers or analytics
0 third-party requests — there's a live counter on the page, watch it stay at 0
0 transparent addresses accepted — shielded only, or it's theatre
Privacy tools should be checkable. Open devtools. Look.
https://t.co/i9588gkvIF
How Pli works — three moves, nobody in the middle:
01 — You seal. Address, amount, memo → ZIP-321 request, padded with random noise, encrypted with AES-256-GCM. All in your browser.
02 — You send two things. The link over any channel. The passphrase over another. Neither is enough alone.
03 — They open & pay. Their browser decrypts, checks expiry, draws the QR. Their wallet pays shielded.
No account. No install. No server ever sees the request.
https://t.co/i9588gkvIF
Base64 is not encryption.
A standard zcash: payment link carries your address and amount in plain text. The memo? Base64 — anyone can decode it in one click.
Your messenger, your inbox, every backup and screenshot in between can read who gets paid, how much, and why.
Pli turns that into a sealed blob. Same request. Nothing to read.
https://t.co/i9588gkvIF
Your shielded tx is private.
The payment request you DM'd? Address, amount, memo — all readable.
Pli seals it in your browser. No server. No cookies. Shielded addresses only.
https://t.co/CbrCMfCuqm 🔒
$ZECPLI
Your shielded Zcash tx is private.
The payment request you sent before it? Not even close.
Your address, the amount, the memo — sitting in plain text in a DM, an inbox, a screenshot, a backup. Every hop that carries it can read it.
Introducing Pli 🔒
Sealed payment requests for Zcash.
→ Type your shielded address, amount & memo
→ Pli encrypts all of it in your browser (AES-256-GCM, 600k-round PBKDF2)
→ Share one link. Send the passphrase another way.
→ The payer breaks the seal, scans the QR, pays shielded.
What the messenger sees: a blob of noise, padded so even its size says nothing.
No server. No cookies. No third-party requests — there's a live counter on the page, it stays at 0.
Transparent t-addresses are rejected. Shielded only, or it's theatre.
Requests expire. Old links don't come back to haunt you.
Free. Live now. Nothing to install.
🌐 https://t.co/i9588gkvIF
$ZECPLI
CA: 0x28627e1c96ccb7cd77c66832660976730d644496
Ask for ZEC. Leak nothing.