ArchitectureCore release 0.1.0
Transaction flows
Accounts and state transitions for Shield, Public Swap, Private Swap and Unshield.
Shield
Depositor signer + source SPL account
→ classic token transfer into ShieldedState custody
→ ShieldedNoteAppended event
→ commitment appended to active TreeState / LeafPageThe source wallet and amount are public. The depositor pays any account-rent top-up needed to append to the active page when using the normal SDK path.
Public Swap
Trader signer + source token account
→ fee-adjusted CPMM quote against LP vault balances
→ input and output transfers between trader accounts and LP vaults
→ fee transfers into protocol / creator vaultsThe trader is a public signer and no zero-knowledge proof is involved.
Private Swap
Input note + accepted root + private witness
→ Groth16 proof, public statement and nullifier
→ canonical root / account / nullifier checks
→ custody input → LP input and fee vaults
→ LP output vault → shielded custody output
→ change/output commitments appended to pagesThe transaction shows the public statement, fee payer and token-account changes. The input note's spend secret, randomness and path are not transaction plaintext.
Unshield
Private note witness + proof
→ accepted root and unused nullifier check
→ shielded custody transfer
→ public recipient ATA
→ Unshielded eventThe recipient is public and bound into the proof. Private Send is an SDK product flow over this same Unshield instruction.
See Solana design and confirmation lifecycle for transaction construction and finality.
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.