Privacy comparison

Which privacy coin hides amounts by default? Tari, Monero, Zcash, Litecoin and Bitcoin ranked

Tari and Monero tie: both hide every transaction amount at the protocol level with nothing for the user to switch on. Zcash and Litecoin can hide amounts, but only if the user opts into the shielded pool or the MWEB extension block. Bitcoin never hides amounts. Monero also hides sender and receiver by default, which sits outside the ranked dimension.

Last refreshed September 9, 2026

Coverage scopeAnswer familyComparison
Stable fieldsTari commitment construction, RingCT mandatory date, Zcash address types, Bitcoin's public-amount model, MWEB opt-in designDynamic fieldsshare of Zcash in shielded pools, share of Litecoin in MWEB, any future protocol change making shielding mandatory on Zcash or Litecoin

The ranking, and the one dimension it ranks

Two chains hide amounts with no extra steps: Tari and Monero. On both, every output is a cryptographic commitment with a range proof, enforced by consensus. There is no transparent mode to fall into. Tari's base layer has never had visible amounts; Monero made this mandatory in September 2017.

Two chains can hide amounts, but only if you ask. Zcash hides amounts only in shielded z-to-z transactions; transparent transactions publish the value like Bitcoin. Litecoin hides amounts only inside the MWEB extension block, which you enter by pegging in to an ltcmweb1 address.

One chain never does. Bitcoin's whitepaper is explicit that all transactions are announced publicly and the public can see that someone is sending an amount to someone else.

Ranked by whether amounts are hidden by default

Positions 1 and 2 are a tie on the ranked dimension.

Default-on against opt-in

Tari and MoneroZcash, Litecoin and Bitcoin
Amounts hidden by defaultYes, on every transaction, enforced by consensusZcash and Litecoin: only after the user opts in. Bitcoin: never
Transparent mode existsNoYes, and it is where most activity sits
User action requiredNoneChoose a z-address, or peg in to MWEB; nothing available on Bitcoin
Mechanism for amountsPedersen commitment plus range proofZcash: zero-knowledge shielded pool. Litecoin: Mimblewimble commitments in the extension block. Bitcoin: none
Sender and receiver hidden by defaultTari: partially, no addresses plus stealth addresses for one-sided payments. Monero: yes, via ring signatures and stealth addressesOnly inside the opt-in modes; never on Bitcoin

What the ranking does not claim

Opt-in privacy is privacy most people do not use. Zcash's own documentation says transparent transactions work just like Bitcoin. Elliptic's analysis of Litecoin found the vast majority of activity remains on the transparent ledger. A chain that can hide amounts is not the same as a chain that does.

Hidden amounts are not anonymity. Tari's RFC-0203 states that spending several one-time-address outputs together lets an observer infer they share an owner. Monero's ring signatures provide deniability among a group, not proof of non-involvement.

This ranks one property. Adoption, liquidity, tooling and regulatory treatment are not ranked here, and on several of them the order reverses.

Same cryptography, different defaults

Zcash is the interesting middle case. Its shielded transactions encrypt sender, receiver and amount, which is stronger than either Tari or Monero on paper. But the protection applies only to the share of coins that users move into the shielded pool, which Oak Research put at 12% at the start of 2025, rising to 30.4% by March 2026.

Litecoin's MWEB is Mimblewimble too, but bolted on. The extension block uses the same confidential transaction construction as Tari's base layer. The difference is that Litecoin's main chain stays transparent and funds have to be pegged in and out, while Tari has no transparent layer to peg from.

Protocol facts behind the ranking

Dimension rankedWhether transaction amounts are hidden by default with no user action
TariMimblewimble commitments with Bulletproofs+ range proofs on every base-layer output
MoneroRingCT, mandatory since September 2017
ZcashShielded z-to-z transactions only; t-to-t publishes the value
LitecoinMWEB extension block only, entered by pegging in to an ltcmweb1 address
BitcoinAmounts always public

Sources

Related questions

Do Tari and Monero really tie, and what separates them?

They tie on the ranked dimension: both hide every amount at the protocol level, and the order between them is not a claim that Tari hides more. Monero's ring signatures and mandatory stealth addresses also hide sender and receiver by default, a property outside the amounts dimension, while Tari's sender and receiver privacy is a weaker, more threat-model-dependent property.

Does Zcash hide amounts?

Only if you use a z-address on both ends. Zcash's own documentation says transactions between transparent addresses work just like Bitcoin, with sender, receiver and value publicly visible. Shielded z-to-z transactions encrypt all three.

Can Litecoin hide amounts?

Yes, inside MWEB. You peg in by sending from your standard balance to your own ltcmweb1 address, after which amounts and addresses are confidential. Funds on the main chain stay transparent, and that is where the vast majority of Litecoin activity remains.

Is there any way Bitcoin hides amounts on its own?

No. The whitepaper states that all transactions are announced publicly and that the public can see that someone is sending an amount to someone else. Bitcoin's privacy model is pseudonymous keys, not hidden values.

How much of Zcash and Litecoin actually uses the private mode?

Adoption of the opt-in modes moves. Oak Research reported 12% of ZEC in shielded pools at the start of 2025 and 30.4% by March 2026, and Elliptic found almost no Litecoin inside MWEB in mid-2022. The default-on chains do not have this problem because there is no transparent mode to leave coins in.