ProtocolCore release 0.1.0

Unshield

Unshield proves note authorization, marks a nullifier spent, and transfers the note's full value to a public recipient.

Unshield converts a shielded note into a public SPL token transfer. The user supplies a Groth16 proof, an accepted Merkle root, the note amount, a nullifier and the recipient. Core verifies the statement, creates the canonical spent-nullifier PDA and transfers the note's value from shielded custody to the recipient's classic SPL token account.

Public inputs

The 10 public field inputs are, in circuit order: domain; pool high/low limbs; asset high/low limbs; root; nullifier; amount; recipient high/low limbs. Root sequence and tree generation are also passed as program instruction arguments and checked against the selected TreeState root history.

The recipient is bound into the proof and the destination associated token account is checked against that public address. The Unshielded event emits pool, asset, amount, recipient, nullifier, generation and root sequence.

Payer and privacy

The transaction payer is not required to own the note. In a sponsored transaction the relayer can be the payer while the recipient remains separately public. A relayer does not receive the spend secret through the standard transaction format.

The input note's public amount, destination address, transaction timing, pool and nullifier are observable. Unshield is a public exit boundary, not an invisible token transfer.

The SDK consumes a complete note for Unshield; the current v0.1.1 API does not split one note into a smaller withdrawal. Private Send uses this same primitive with an arbitrary recipient.

PreviousPrivate SwapNext Private Send
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.