ArchitectureCore release 0.1.0

Public liquidity & shielded custody

LP reserves and shielded note backing are held in distinct public token-account vaults with separate authorities and roles.

Lethenymous uses two account classes that must not be conflated:

Public AMM
LP Vault A
LP Vault B
public reserves · LP claims
Private Swap settles between custody and LP vaults
Shielded side
Custody A
Custody B
public token accounts · private note ownership

LP vaults

The pool owns token A and token B LP vaults. Their balances are the public CPMM reserves used for Public Swap and Private Swap quotes. The pool PDA signs the output-side transfers. Public swap fees also accrue to separate protocol and creator fee vaults associated with the pool.

Shielded custody

ShieldedState owns separate custody A and custody B token accounts. Shield deposits assets into custody. A Private Swap moves the input amount from shielded custody into the input-side LP and fee vaults, then moves the CPMM output from the output-side LP vault into the corresponding shielded custody account. Unshield transfers from shielded custody to the recipient.

The balances of both classes remain on-chain and publicly readable. A Shielded Note is a cryptographic claim represented by commitments and private wallet data; it is not an opaque private token account.

Why the separation matters

Shielded custody is not itself the liquidity pool, and private funds are not stored directly in LP vaults. LP vaults define market depth and reserves; custody vaults hold token backing for shielded note claims. This separation is part of the on-chain accounting model.

Settlement and account identities are described in Private Swap, Shield and Program accounts & PDAs.

PreviousSystem overviewNext Program accounts & PDAs
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.