
Decreases the size of the range proofs of a RingCT transaction.

Greg Maxwell, Andrew Poelstra and Pieter Wuille with other researchers from the Stanford Applied Cryptography Group.

Bulletproofs does not require a trusted setup for parameter generation, but verification is more time consuming that zkSNARKS.

Rather than scaling linearly, Bulletproofs scale logarithmically to the number of outputs in a transaction making the cryptographic proof of multioutput transactions smaller.
1. What exactly do Bulletproofs do on the Monero blockchain?
Bulletproofs allows for the aggregation of range proofs within a Confidential Transaction and collectively prove their validity.
2. Who developed Bulletproofs?
Greg Maxwell, Andrew Poelstra, Pieter Wuille, and researchers from the Stanford Applied Cryptography Group developed Bulletproofs.
3. How do Bulletproofs compare to zkSNARKs?
Bulletproofs are more timeconsuming; however, they do not require a trusted setup for a system parameters generation.
4. How do Bulletproofs improve scalability of multioutput transactions on Monero?
Bulletproofs scale logarithmically and take up very little space (relative to former range proofs) which means that more multioutput transactions, which improve Monero’s obfuscation tactic, can occur thus improving Monero’s robust privacy scheme even more.
