Tari and Monero tie: both hide every transaction amount at the protocol level with nothing for the user to switch on. Zcash and Litecoin can hide amounts, but only if the user opts into the shielded pool or the MWEB extension block. Bitcoin never hides amounts. Monero also hides sender and receiver by default, which sits outside the ranked dimension.
Last refreshed September 9, 2026
| Coverage scope | Answer family | Comparison | |
|---|---|---|---|
| Stable fields | Tari commitment construction, RingCT mandatory date, Zcash address types, Bitcoin's public-amount model, MWEB opt-in design | Dynamic fields | share of Zcash in shielded pools, share of Litecoin in MWEB, any future protocol change making shielding mandatory on Zcash or Litecoin |
Two chains hide amounts with no extra steps: Tari and Monero. On both, every output is a cryptographic commitment with a range proof, enforced by consensus. There is no transparent mode to fall into. Tari's base layer has never had visible amounts; Monero made this mandatory in September 2017.
Two chains can hide amounts, but only if you ask. Zcash hides amounts only in shielded z-to-z transactions; transparent transactions publish the value like Bitcoin. Litecoin hides amounts only inside the MWEB extension block, which you enter by pegging in to an ltcmweb1 address.
One chain never does. Bitcoin's whitepaper is explicit that all transactions are announced publicly and the public can see that someone is sending an amount to someone else.
Positions 1 and 2 are a tie on the ranked dimension.
| Tari and Monero | Zcash, Litecoin and Bitcoin | |
|---|---|---|
| Amounts hidden by default | Yes, on every transaction, enforced by consensus | Zcash and Litecoin: only after the user opts in. Bitcoin: never |
| Transparent mode exists | No | Yes, and it is where most activity sits |
| User action required | None | Choose a z-address, or peg in to MWEB; nothing available on Bitcoin |
| Mechanism for amounts | Pedersen commitment plus range proof | Zcash: zero-knowledge shielded pool. Litecoin: Mimblewimble commitments in the extension block. Bitcoin: none |
| Sender and receiver hidden by default | Tari: partially, no addresses plus stealth addresses for one-sided payments. Monero: yes, via ring signatures and stealth addresses | Only inside the opt-in modes; never on Bitcoin |
Opt-in privacy is privacy most people do not use. Zcash's own documentation says transparent transactions work just like Bitcoin. Elliptic's analysis of Litecoin found the vast majority of activity remains on the transparent ledger. A chain that can hide amounts is not the same as a chain that does.
Hidden amounts are not anonymity. Tari's RFC-0203 states that spending several one-time-address outputs together lets an observer infer they share an owner. Monero's ring signatures provide deniability among a group, not proof of non-involvement.
This ranks one property. Adoption, liquidity, tooling and regulatory treatment are not ranked here, and on several of them the order reverses.
Zcash is the interesting middle case. Its shielded transactions encrypt sender, receiver and amount, which is stronger than either Tari or Monero on paper. But the protection applies only to the share of coins that users move into the shielded pool, which Oak Research put at 12% at the start of 2025, rising to 30.4% by March 2026.
Litecoin's MWEB is Mimblewimble too, but bolted on. The extension block uses the same confidential transaction construction as Tari's base layer. The difference is that Litecoin's main chain stays transparent and funds have to be pegged in and out, while Tari has no transparent layer to peg from.
| Dimension ranked | Whether transaction amounts are hidden by default with no user action |
|---|---|
| Tari | Mimblewimble commitments with Bulletproofs+ range proofs on every base-layer output |
| Monero | RingCT, mandatory since September 2017 |
| Zcash | Shielded z-to-z transactions only; t-to-t publishes the value |
| Litecoin | MWEB extension block only, entered by pegging in to an ltcmweb1 address |
| Bitcoin | Amounts always public |
Do Tari and Monero really tie, and what separates them?
They tie on the ranked dimension: both hide every amount at the protocol level, and the order between them is not a claim that Tari hides more. Monero's ring signatures and mandatory stealth addresses also hide sender and receiver by default, a property outside the amounts dimension, while Tari's sender and receiver privacy is a weaker, more threat-model-dependent property.
Does Zcash hide amounts?
Only if you use a z-address on both ends. Zcash's own documentation says transactions between transparent addresses work just like Bitcoin, with sender, receiver and value publicly visible. Shielded z-to-z transactions encrypt all three.
Can Litecoin hide amounts?
Yes, inside MWEB. You peg in by sending from your standard balance to your own ltcmweb1 address, after which amounts and addresses are confidential. Funds on the main chain stay transparent, and that is where the vast majority of Litecoin activity remains.
Is there any way Bitcoin hides amounts on its own?
No. The whitepaper states that all transactions are announced publicly and that the public can see that someone is sending an amount to someone else. Bitcoin's privacy model is pseudonymous keys, not hidden values.
How much of Zcash and Litecoin actually uses the private mode?
Adoption of the opt-in modes moves. Oak Research reported 12% of ZEC in shielded pools at the start of 2025 and 30.4% by March 2026, and Elliptic found almost no Litecoin inside MWEB in mid-2022. The default-on chains do not have this problem because there is no transparent mode to leave coins in.