Nearly all blockchains in existence use digital signature schemes for unlocking funds for expenditure, even though this primitive is overkill for that purpose. A commitment scheme suffices, as long as the opening protocol binds to the transaction. Moreover, and perhaps surprisingly, this minimally sufficient primitive can be compatible with an architecture for anonymous payments – and, incidentally, post-quantum security.