How Privacy Is Preserved in RGB Protocol on Bitcoin

Every Bitcoin transaction is public, so anyone can open a block explorer and read the amounts and the addresses of every payment. In contrast, privacy in RGB Protocol on Bitcoin follows a different logic: the details of an asset transfer are retained by the parties of the transfer. For this reason, the article follows a single transfer through the eyes of four observers, stating the limits of the model.
Privacy in RGB in Brief
- On Bitcoin, an outside observer finds an ordinary transaction and, at most, a hash: no contract, no asset name, no amount.
- The sender does not learn which UTXO of the recipient holds the asset, because of the blinded UTXO.
- The recipient receives the history of the asset, because validation depends on the full history.
- A user of another contract in the same Bitcoin transaction receives a proof for their own contract only.
- However, privacy in RGB has clear limits: the next owner of an asset learns the previous owner’s UTXO and reads the earlier history.
Why Is Bitcoin Transparent by Design?
Bitcoin works as a public ledger. In fact, every node validates every transaction and keeps a copy of the data. As the RGB documentation explains, “the amounts transacted and the receiving addresses are visible to everyone, albeit pseudonymous.”
For a monetary network, public verification is certainly a strength. However, for assets such as stablecoins or collectibles, the same transparency exposes balances and payment habits to the whole world.
Where Does RGB Store Asset Data?
RGB solves the problem with client-side validation. In other words, each party only validates the part of the history that is relevant to its own assets, on its own device. As a result, Bitcoin receives only a commitment: a short hash of the data, placed inside a normal transaction.
A hash works in one direction: from the data, anyone can compute the hash; on the contrary, from the hash nobody can reconstruct the data. The original data cannot be recreated from the commitment, which means it remains private to the parties of the transfer.
For example, think of a fingerprint on a public register: the print identifies one person with certainty, while the register says nothing about the person’s life.
Privacy in RGB: Four Observers, Four Views
We can apply one example to four different observers. In our case, Alice sends Bob 100 units of a stablecoin issued on RGB. The stablecoin has millions of units in circulation, possessed by many different holders.
- The outside observer: anyone who watches the Bitcoin blockchain.
- The sender: Alice, the current owner of the 100 units.
- The recipient: Bob, the new owner of the 100 units.
- The user of another contract: a holder of a different asset, such as a collectible, with a transfer committed in the same Bitcoin transaction as Alice’s payment.
The image below sums up the view of each observer, and the next four sections follow the same order.

1. What Does an Outside Observer See on Bitcoin?
First, an outside observer sees a regular Bitcoin transaction: inputs, outputs and bitcoin amounts, like any other payment. The stablecoin transfer is reduced to a 32-byte hash, and the protocol offers two ways to place the hash in the transaction:
- Opret: the first
OP_RETURNoutput of the transaction carries the hash. The hash is therefore visible on-chain as a short string of data, 34 bytes in total. - Tapret: the hash is hidden inside the script structure of a Taproot output, with no additional footprint compared with an ordinary transaction. In fact, the documentation describes Tapret as an improvement “in terms of chain footprint and privacy of contract operations.”
With Opret, an observer can read the hash; with Tapret, instead, the hash stays out of sight. In both cases, the blockchain still reveals nothing about the stablecoin, the amount of 100 units, or the new owner.
2. What Does the Sender Know About the Recipient?
In RGB Protocol, the recipient makes the first move. First, Bob creates an invoice and sends it to Alice. The invoice gives Alice the destination of the 100 units: a Bitcoin UTXO under Bob’s control.
In general, Bob does not have to disclose the UTXO itself. Instead, his wallet adds a random number, called the blinding factor, and then hashes the result. As a consequence, Alice receives a blinded UTXO: a code that works as a destination and hides the real output. According to RGB v0.11.1 documentation, the concealed form “prevents Alice from knowing the UTXO actually held by Bob.”
Alice therefore knows the stablecoin and the amount, since she builds the transfer. However, she has no way to follow the 100 units on the blockchain afterwards.
3. What Does the Recipient Learn From the Consignment?
Afterwards, Alice sends Bob a data package called a consignment. The package contains the new transfer and the full history of the 100 units, from the creation of the stablecoin contract (the genesis) up to Bob. Bob’s wallet then checks every step against the commitments on Bitcoin. Without the full history, Bob could not prove the validity of the 100 units.
Bob therefore sees more than an outside observer, because the history of his units shows every earlier transfer and the amount. The documentation describes such data as private owned state, summed up in the phrase “someone owns, nobody knows”, and adds that the data is “revealed only if it is part of the history for validation purposes.”
Bob’s view still covers a small slice of the contract. In fact, transfers of the same stablecoin between other holders, outside the history of his 100 units, never reach his wallet.
The same rule also applies inside a single Bitcoin transaction. For example, Alice can pay Bob and two other people at once: RGB groups the three transfers into a transition bundle. Each recipient receives only the details of their own transfer: the details may be selectively revealed to different recipients. The bundle still carries a list of all the units spent by the three transfers, so no hidden transfer can spend the same units twice.
4. What Does a User of Another Contract See in the Same Transaction?
One Bitcoin transaction can carry commitments for several contracts at once, through a structure called Multi Protocol Commitment (MPC). For example, the transaction that anchors Alice’s transfer can also anchor a transfer of a different asset, such as a collectible, between two other people.
The fourth observer is one of those people. To verify their own transfer, they receive a proof for their own contract only. As a result, the rest of the structure, including the commitment for the stablecoin contract, stays out of view. The documentation states that such a design “provides a high degree of privacy.”
Where Are the Limits of Privacy in RGB?
Privacy in RGB protects asset data from the public. Between one owner of an asset and the next, the protection is weaker. In fact, the model has three main limits.
- History travels forward. Each new owner receives the earlier transfers of the asset, with their amounts. For example, Carol can read the transfer from Alice to Bob in the history of her units. The blinding of Bob’s UTXO follows the same rule: the documentation says the blinding protects the recipient “at least until the allocation is later spent again.” When Bob sends the stablecoin units to Carol, Carol’s wallet needs Bob’s real UTXO for validation, so Carol knows the output behind Bob’s blinded UTXO.
- The Bitcoin transaction remains public. RGB hides the asset data, but the anchoring transaction is still an ordinary Bitcoin transaction: inputs and outputs are public and pseudonymous, like any other payment. The visibility comes from the design of the Bitcoin blockchain, so it doesn’t concern RGB.
- The consignment needs a private route. The consignment contains the full history of the units, so anyone with a copy can read the same history as Bob. In the ideal case described by the documentation, only Alice and Bob hold the consignment. For this reason, the consignment should travel through a channel that is private to the two parties.
Overall, the accurate word for RGB is “private”: asset data stays off the public ledger, while each owner can audit the full history of a received asset.
Privacy in RGB: Frequently Asked Questions
Is RGB Protocol on Bitcoin anonymous?
RGB is private, rather than anonymous. Asset data stays off the blockchain, so the public cannot read the balances, amounts or owners of an asset. However, the Bitcoin transactions that anchor each transfer are public and pseudonymous, and each new owner of an asset can read its earlier history.
Can the sender track my asset after the transfer?
With a blinded UTXO, the sender never learns which output holds your asset. The protection lasts at least until the next transfer of the asset.
Who can see the amount of a transfer?
The sender, the recipient, and future owners whose history includes the transfer. In contrast, nobody finds the amount on the blockchain.
Which commitment method gives more privacy in RGB, Opret or Tapret?
The documentation presents Tapret as an improvement in chain footprint and privacy, because the commitment is hidden inside a Taproot output. Opret, instead, places the hash in a visible OP_RETURN output.
