PrivacyCore release 0.1.0
What is private
The shielded witness and note authorization fields that are not published as plaintext by a private proof transaction.
Lethenymous' cryptographic boundary protects selected note-owner material from appearing in the public transaction statement:
- Spend secret and private key-derivation material.
- Note randomness and the note commitment preimage.
- The input note commitment being spent by a Private Swap or Unshield.
- The Merkle sibling path and leaf index used to prove membership.
- Local note-store records, pending operation preimages and prover witness inputs, when the application keeps them local.
- The direct wallet-to-note authorization link, subject to the public transaction fields and metadata correlation.
The proof shows that a valid witness exists and satisfies constraints; the transaction contains the proof, not the witness in plaintext. The output and change note commitments are public, but their owner commitments and randomness are hidden inside those commitments.
To see the other side of the boundary, read What is public. For handling spend material, read Note security & backups.
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.