Why Lethenymous
Compare transparent AMMs, fully private-pool designs, and the public-pool/private-path model used by Lethenymous.
On a conventional public AMM, pool state and the trader's wallet are visible together. A fully private pool can hide more state, but requires a different liquidity and accounting model. Lethenymous takes a narrower approach: keep the CPMM and its liquidity public, and use shielded notes plus proofs to obscure which wallet controls a position.
Three design points
| Design | Pool and reserves | User-to-position relationship | Main tradeoff |
|---|---|---|---|
| Public AMM | Public | Directly connected to the transaction's signer and token accounts | Simple composability and auditability, with publicly linkable wallet activity. |
| Fully private pool | Depends on the protocol | Designed to hide more transaction state | Requires private liquidity/accounting and a larger privacy-critical surface. |
| Lethenymous | Public CPMM state | Shielded-note ownership is proved in zero knowledge | Amounts, pool state, transaction timing and public boundaries remain visible. |
Why preserve public liquidity?
The pool remains a normal constant-product market. Reserves can be inspected, liquidity providers hold LP tokens, and ordinary Public Swaps remain available. Private Swap settlement uses those same LP vaults while shielded custody holds the assets backing notes. The two vault classes are separate.
This avoids treating public liquidity as if it were secret. The privacy claim is specific: spend authorization and the direct wallet-to-private-position path are obscured by commitments and proofs, subject to metadata correlation and the release's public fields.
Tradeoffs
- Swap direction and amounts are public in the current statement and event data.
- Shield source wallets and Unshield recipients are public at their respective boundaries.
- Transaction existence, fee payer, pool reserve changes, commitments, roots and spent nullifiers are public.
- Privacy depends on activity volume, amount uniqueness, timing, wallet practices and RPC/network metadata.
- Public liquidity remains composable, while user-level note state requires secure local storage and recovery practices.
Continue with the CPMM model, public-data boundary and privacy model.