Privacy model
Lethenymous obscures note ownership and private authorization while leaving pool state, amounts and transactions observable.
Lethenymous protects a specific relationship: the direct path between a wallet and a private note position. Notes are represented by public commitments, while spend authorization is proved in zero knowledge. The AMM remains public.
Public: pool · reserves · transaction · statement amounts · fee payer
Private: spend secret · note randomness · input note preimage · witness pathFee Payer ≠ Trader
For a relayed private operation, the relayer can be the visible fee payer and the transaction's first protocol payer. It pays Solana fees and applicable rent. The private trader is the party whose local witness proves the input note can be spent.
The fee payer does not become the note owner by signing the transaction. The proof binds to a note witness, not to the fee payer's public key. The relayer receives the serialized public transaction and proof, not the spend secret or Merkle witness.
Trust boundary
The application and SDK handle note material; a local authenticated prover generates the proof; an optional relayer sees public transaction data and submits it; Solana verifies the proof and applies state changes. RPC providers and network observers can still observe request timing and transport metadata.
This model does not promise perfect anonymity, unlinkability against every side channel, hidden amounts, or invisible transactions. See What is private, What is public and Metadata leakage.