ProtocolCore release 0.1.0

Shield

Shield deposits classic SPL tokens into shielded custody and appends a public commitment for a private note.

Shield converts a public token deposit into a shielded note. The depositor chooses an asset in the pool, amount, owner commitment and note randomness. The program derives the note commitment, transfers tokens into the separate custody vault and appends the commitment to the active Merkle tree.

State transition

  1. The depositor signs and pays the transaction fee.
  2. Core checks that the selected mint and token accounts match the pool and use classic SPL Token.
  3. Core charges a 5 bps Shield fee to the protocol fee vault, rounded down in base units.
  4. The exact note amount moves to the corresponding shielded custody account.
  5. A depth-16 Merkle leaf is appended and ShieldedNoteAppended is emitted.

The note commitment includes the pool, asset mint, amount, owner commitment and randomness. The event includes the asset and amount, commitment, encrypted note payload, root, generation and leaf index. The encrypted payload is for wallet recovery; its presence does not hide the public amount field.

Privacy boundary

The depositor and entry amount are public at Shield time. Afterward, a spend proves ownership of a note without revealing the owner secret or membership path. The pool, reserves, transaction, timestamp, commitment and other event fields remain public.

The SDK's ShieldedWallet.shield({ pool, mint, amount }) derives randomness and commitments locally, encrypts the note payload, prepares the archive append and stores the note in the configured NoteStore. See SDK Shield.

PreviousPublic SwapNext Private Swap
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.