Explore (579)Live Systems (52)Pricing
Log InGet API Key✓ Verify It Yourself
BITCOIN‑PRIVACY
Stage 05 · AnchoringSee how 32-byte anchors flow end-to-end →

The same 74 bytes, anchored on Bitcoin.

Solana-Privacy proved compliance to the regulator and privacy to the user on Solana devnet. Polygon-Privacy brings the same H33-74 attestation to EVM-native rails. Bitcoin-Privacy makes the proof permanent — one 32-byte commitment anchored via Taproot script-path (production) or OP_RETURN (alternative), on the deepest proof-of-work chain in existence.

Schedule Demo See Solana-Privacy (Live)
BITCOIN RPC · LIVE
Bitcoin mainnet RPC connectivity is live on this page — current block (updates in real time via WebSocket, courtesy of mempool.space). Public Bitcoin anchor endpoint ships when infrastructure is provisioned. Solana-Privacy is live on devnet today.
DEPLOYMENT STATUS
Bitcoin Taproot / OP_RETURN — rollout status
BITCOIN RPC LIVE — public anchor endpoint pending
Updated
Bitcoin connectivityCONNECTING…
Latest block height
Latest block hash
Mempool fee (fast) sat/vB
WebSocket subscriptionconnecting…
Target chainBitcoin mainnet (+ signet / testnet for development)
First milestoneBackend code committed (bitcoin_anchor.rs, Phase 0 keystone 19161899f)
ETA public endpointPending infrastructure provisioning
Anchor primitiveTaproot script-path (P2TR) — production. OP_RETURN (max 80 bytes, we use 32) — supported alternative.
Receipt size74 bytes (unchanged)
On-chain footprint32 bytes (Taproot commitment or OP_RETURN payload)
Batched MerkleSubstrate Claims 124–125 amortize N anchors into one Taproot output (or OP_RETURN)
PQ signaturesML-DSA-65 + FALCON-512 + SLH-DSA-128f
EXPOSURE COMPARISON
What changes when H33 is in the path on Bitcoin

Native Bitcoin

  • × Visible UTXO set
  • × Visible wallet balances
  • × Visible treasury composition
  • × Visible custody structure
  • × Visible counterparty addresses
  • × Visible transaction history
  • × Visible reserve audits
  • × Visible institutional flows

H33 Protected

  • Encrypted reserve workflow
  • Attested execution proof
  • Hidden UTXO membership
  • Proof-only balance verification
  • 32-byte OP_RETURN commitment
  • Off-chain STARK verification
  • Post-quantum attestation
  • Permanent, replay-grade evidence
ATTESTATION RECEIPT
What a verified Bitcoin attestation looks like
Identical to Solana-Privacy and Polygon-Privacy receipt structure. Same 74-byte H33-74 bundle. The anchor target swaps to a Bitcoin OP_RETURN output — one 32-byte commitment, comfortably under the 80-byte OP_RETURN ceiling. Batched anchors use a Merkle root (Substrate Claims 124–125) so N receipts share one transaction.
h33-74 attestation receipt — bitcoin (preview)
H33-74 ATTESTATION RECEIPT Receipt ID: h74_attest_bitcoin_... DAG Root: 0x... (depth: 4, nodes: 12) Proof Hash: 0x... (STARK, 128-bit PQ security) Replay Ref: replay://h33.ai/r/... Chain Anchor: Bitcoin mainnet — block [pending] · OP_RETURN Anchor TX: [txid pending] (example only — not a real txid) Commitment: 0x... (32 bytes in OP_RETURN output) Merkle Root: 0x... (batched: 1 OP_RETURN → N receipts) Example UTXO: tb1q... (bech32 sample, not a real address) SIGNATURES: ML-DSA-65: VALID (3,309 bytes — MLWE lattice) FALCON-512: VALID (666 bytes — NTRU lattice) SLH-DSA-128f: VALID (17,088 bytes — hash-based) VERIFICATION: ALL CHECKS PASSED (20/20) HATS LEVEL: Level 1 Conformance CACHEE KEY: cachee://h33.ai/c/... Replay This Attestation → Verify Independently →
TRY IT
Try Bitcoin-Privacy
LIVE · BITCOIN RPC CONNECTIVITY

Live Bitcoin mainnet block stream — proof of Bitcoin connectivity from this page.

This widget streams Bitcoin mainnet block heights, block hashes, and recommended mempool fees in real time via WebSocket — the same Bitcoin RPC path that will publish H33-74 attestations to Bitcoin OP_RETURN once the public anchor endpoint is provisioned. The Solana-Privacy demo at h33.ai/solana-privacy/#try-it generates the full STARK + PQ-signed proof flow today on Solana devnet.

BITCOIN MAINNET · connecting…
via mempool.space
Latest block height ———
Block hash
Fast fee (1–2 blocks)
Last update
Updates received 0

When the public Bitcoin anchor endpoint ships, the try-it surface will:

  • Generate an H33-74 attestation in the browser (same 74 bytes — unchanged across chains)
  • Embed the 32-byte commitment in an OP_RETURN output on Bitcoin mainnet (or signet, for testing)
  • Optionally batch N receipts into one OP_RETURN via Merkle root (Substrate Claims 124–125) to amortize Bitcoin TX cost
  • Return a mempool.space link plus the full off-chain proof bundle (STARK + ML-DSA + FALCON + SLH-DSA)
ATTESTATION PIPELINE
Five stages. 32 bytes on-chain. One OP_RETURN.
01
User Data
Encrypted inputs from custodian, treasury, or wallet
02
STARK Proof
Constraint satisfaction without reveal
03
PQ Signatures
ML-DSA + FALCON + SLH-DSA triple sign
04
Cachee Store
Full proof bundle persisted off-chain
05
OP_RETURN
32-byte commitment in a Bitcoin OP_RETURN output
32 bytes on-chain. Full proof off-chain. Three PQ families. Zero data revealed. 74 bytes total — same primitive that ships on Solana, Polygon zkEVM, and now Bitcoin.
TECHNICAL SPECS
Bitcoin target parameters
Chain (mainnet)
Bitcoin
the deepest proof-of-work chain in existence
Chain (test)
Signet · Testnet
development & integration before mainnet anchoring
Block time
~10 minutes
target inter-block interval, retargeted every 2,016 blocks
Finality
~6 confirmations
~60 minutes for practical settlement; permanence grows with depth
Anchor primitive
OP_RETURN
single output, max 80 bytes; we use 32 (room to spare)
Anchor cost
~$1–5 / anchor
typical mainnet fees; permanence priced in
Batched anchor cost
~$1–5 / N receipts
Substrate Claims 124–125: one OP_RETURN amortizes N attestations via Merkle root
Receipt
74 bytes
identical H33-74 bundle — unchanged across all chains
On-chain footprint
32 bytes
commitment payload in OP_RETURN (or Merkle root for batched)
PQ signature stack
3 families
ML-DSA-65 + FALCON-512 + SLH-DSA-SHA2-128f-simple
Proof system
ZK-STARK
Lookup STARK + AIR STARK; no trusted setup
On-chain verifier
None — by design
Bitcoin has no smart contracts. Verifier runs off-chain against the published commitment. The chain stores permanence, not logic.
DISCLOSURE BOUNDARY
What crosses the attestation boundary

NOT REVEALED

  • × UTXO set membership
  • × Wallet balance
  • × Treasury composition
  • × Custody structure
  • × Counterparty addresses
  • × Reserve audit detail
  • × Settlement timing
  • × Mining or ETF flows

ONLY REVEALED

  • Cryptographic validity
  • Compliance proof
  • Reserve sufficiency
  • 32-byte commitment
  • Verification status
  • Replay availability
  • PQ signature bundle
  • Permanent Bitcoin anchor
MULTI-CHAIN WITNESSING
Same H33-74 receipt, anchored across:
Bitcoin (RPC live)
|
Solana (devnet)
|
Ethereum
|
Polygon zkEVM
Same 74-byte primitive across every chain. Cross-chain continuity without rewriting the attestation format.
"Solana-Privacy proved compliance to the regulator and privacy to the user. Polygon-Privacy brought it to EVM rails. Bitcoin-Privacy makes it permanent — anchored to the deepest proof-of-work chain in existence."

Tornado Cash proved privacy without compliance becomes a regulatory dead end.

Polygon-Privacy proves privacy to the user while proving compliance to the regulator — post-quantum signed, replayable offline, and portable across Bitcoin, Solana, and Polygon zkEVM.

That’s the operational primitive institutional AI and RWA systems are missing.

Introducing H33-74. 74 bytes. Any computation. Post-quantum attested. Forever.
Anchored on Bitcoin, Solana, and Polygon zkEVM.

Replay any attestation. Verify independently.

Every H33-74 receipt is reconstructible from its commitment. Inspect lineage. Inspect proof. Inspect DAG. Verify signatures. On Bitcoin, the commitment lives forever in the deepest PoW chain.

Built For
Institutions building permanence on Bitcoin.
ETF Custodians
Corporate Treasuries
Mining Operations
Regulated Exchanges
Sovereign Reserves
Compliance Teams
EXPLORE
50 Live Systems 44 ZK Use Cases Solana-Privacy (Live) Polygon-Privacy

Same 74 bytes. Permanent on Bitcoin.

Compliance to the regulator. Privacy to the user. Post-quantum attestation that outlives ECDSA — anchored to the deepest proof-of-work chain in existence.

Schedule Demo

H33.ai, Inc. · Patents Pending · HATS Standard · Privacy Layer · H33-74 · Solana-Privacy · Polygon-Privacy

Same Primitive · Other Chains
The same 32-byte H33-74 attestation runs across every chain H33 ships on. One primitive, four products, no per-chain verification model.
Ethereum-Privacy Bitcoin-Privacy · YOU ARE HERE Solana-Privacy Polygon-Privacy