IntroductionCore release 0.1.0

How it works

Follow assets from a public wallet through Shield, shielded notes, Private Swap and Unshield.

The lifecycle combines public token transfers with privately authorized note spends. Every on-chain action remains visible; the proof hides the note witness, not the transaction.

Lifecycle at a glance

Wallet
  ↓ Shield
Shielded Note
  ↓ Private Swap
New output note + optional change note
  ↓ Private Swap, Private Send, or another operation
Unshield to a public recipient

Shield transfers classic SPL tokens from a public token account into Shielded Custody and appends a commitment. The event exposes the depositor, asset and note amount. Privacy begins after this visible entry; it does not erase the entry transaction.

Private Swap

The client selects an available note, reconstructs its Merkle witness, computes a public CPMM quote, and asks the production prover for a Groth16 proof. The program verifies the proof, rejects an already-spent nullifier, settles public LP-vault and shielded-custody transfers, then appends the output and optional change commitments.

Both note values are public in the current statement. What is not provided publicly is the input note commitment preimage, spend secret, randomness or path used to authorize it.

Exit or recipient transfer

Unshield sends the value of a complete note to a public recipient token account. The current SDK-level Private Send is an Unshield to an arbitrary recipient, so it reveals the recipient and amount.

Who pays?

The user can submit directly, or prepare a transaction for the hosted relayer. In a relayed private operation, Fee Payer ≠ Trader: the relayer signs as fee payer, but does not receive note spend authority. See Relayer overview.

PreviousWhy LethenymousNext Current release
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.