Threat model
What a public observer can see, what it cannot spend, and which private witness material must remain protected.
The public observer can read Solana account state and transaction data. The observer can see commitments, roots, amounts, nullifiers, account addresses and timing. The design's cryptographic claim is that these fields alone do not provide the private witness required to authorize a note spend.
| Observer sees | Can this alone spend a note? |
|---|---|
| Note commitment | No. It commits to hidden authorization data; it is not spend authority. |
| Merkle root | No. It identifies an accepted tree state, not a note secret. |
| Merkle path | No. Membership is not ownership authorization. |
| Nullifier | No. It is a one-time spent marker, not a secret key. |
| Public amount | No. It can aid correlation, not construct a valid spend witness. |
| Spend secret | Critical secret. Treat as authorization material and never disclose it. |
| Spend secret plus note randomness and valid note witness | Critical private witness material; can enable a valid proof and must remain confidential. |
The exact cryptographic boundary assumes Groth16 soundness, BN254 and Poseidon implementation correctness, uncompromised setup material, and correct application handling of the witness. The relayer is not trusted with note secrets, but it can observe public request metadata. The RPC provider is an availability and privacy boundary.
Operational limitations include seed or backup loss, single-party trusted setup, centralized hosted Devnet relayer, upgrade authority and RPC trust. Read Security model and Known limitations.