Zeeka saysPedersen commitments live in a group as C = g^v·h^r — perfectly hiding, and homomorphic: multiplying two commitments commits to the sum of their values.
A Pedersen commitment is C(v, r) = g^v · h^r, where v is the value, r is a random blinding factor, and g, h are group generators whose relative discrete log is unknown. The blinding makes it perfectly hiding; binding rests on nobody knowing the discrete log of h base g. Its killer feature is being homomorphic: C(v1,r1)·C(v2,r2) = C(v1+v2, r1+r2).
That lets you prove things about sums of hidden numbers — for example, that the inputs of a confidential transaction equal its outputs — without revealing any amount. Pedersen commitments are the backbone of confidential transactions and range proofs (Bulletproofs). The demo verifies the homomorphic identity in a toy order-11 group.
Power-ups you unlock
C(v, r) = g^v · h^r with a random blinding factor r
Hiding is perfect; binding rests on the discrete log of h base g
Homomorphic: C(v1,r1)·C(v2,r2) = C(v1+v2, r1+r2)
Prove sums (inputs == outputs) without revealing amounts
Backbone of confidential transactions and range proofs
The Collision attacks — common mistakes
Knowing the discrete log of h base g — breaks binding
Reusing the blinding factor r across commitments
Forgetting exponents are reduced mod the group order
Assuming homomorphism extends to multiplying values (it does not)
Boss battleOver a toy order-11 group, verify that C(4,7)·C(5,9) equals C(4+5, 7+9).