PrivacyCore release 0.1.0
Metadata leakage
Amount uniqueness, timing, wallet reuse, RPC metadata and small activity sets can weaken the practical privacy boundary.
Zero-knowledge protects the witness, but observers can combine public fields with external information. The release does not claim perfect anonymity or untraceability.
Correlation channels
- Timing: an observed deposit followed quickly by a distinctive swap or withdrawal can be correlated.
- Unique amounts: the current public statement exposes amounts. Rare values can act as fingerprints across entry, swap and exit events.
- Wallet reuse: using the same wallet for deposits, relayer requests, public swaps and unrelated Solana activity creates external links.
- Small activity sets: a sparse pool or low-volume time window gives observers fewer plausible candidates.
- Reserve deltas: public pool reserves and custody token balances expose settlement changes and can narrow candidate operations.
- Network and RPC metadata: an RPC operator may see source network address, request timing and queried accounts. The relayer sees request origin and the submitted public transaction.
- Recipient behavior: Unshield and Private Send reveal the destination token account and can be linked to later activity.
Practical mitigations
Avoid reusing addresses across unrelated contexts, do not treat a relayer as a network-anonymity service, avoid publishing exact operation timing, and understand that amount choices remain public. These practices reduce some metadata links; they do not add protocol-level amount privacy.
See the threat model for the observer capability boundary.
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.