SecurityCore release 0.1.0

Known limitations

Current v0.1.0 scope, privacy caveats, trusted setup, rollover coverage and operational risks.

The current release is a controlled Devnet deployment, not unrestricted Mainnet readiness. The following limitations are part of the product boundary:

Privacy and asset scope

  • Amount privacy is not provided. Shield, Private Swap and Unshield expose amounts in current events/statements.
  • Transactions, pool reserves, direction, commitments, roots, nullifiers, fee payers, timestamps and public recipients remain observable.
  • Timing, unique amounts, wallet reuse, small activity sets and RPC/network metadata can correlate activity. Perfect anonymity or untraceability is not claimed.
  • Only classic SPL Token is supported. Token-2022 and extensions are unsupported; SOL is represented through Wrapped SOL, not native SOL instructions.

Security and operations

  • Production Groth16 setup is single-party, not MPC. Toxic-waste non-retention/non-compromise is assumed.
  • The relayer is centrally hosted on Devnet, process-local controls are not durable across instances and it is not independently audited.
  • RPC availability/privacy, local prover supply-chain, wallet/NoteStore custody and upgrade authority remain trust boundaries.
  • Losing both seed and encrypted note backups can prevent recovery. Random private-swap output preimages are not recoverable chain-only if all local copies are lost.
  • If a process terminates during proving before submission, its reserved note remains unresolved until reconciliation; timeout alone does not release it.

Coverage limits

The real Devnet release gate validated a 4095→4096 cross-page transition. It did not execute organic Gen0→Gen1 rollover at 65,535/65,536 leaves. That is an explicit scale-stress coverage limitation, not a demonstrated protocol defect.

The controlled Devnet gate lists zero known unresolved critical, high or medium findings within its release scope. That is not equivalent to an independent external audit or a production safety guarantee.

See Validation evidence for the complete evidence summary and exact transaction measurements.

PreviousUpgrade authorityNext Validation evidence
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.