Key concepts

The few ideas you need to understand how Opaque works.

Copy Markdown

Shroud

Depositing $OPA into the pool. The transaction is public: your address and the amount are visible. In return, a note is added to the pool.

Note

A private record of value. The chain stores only a commitment to it and an encrypted copy that the owner can read. Nobody else can see the owner or the amount.

A note commits to its owner's key, a random value, a blinding value, an asset id and an amount.

Commitment

A hash of the note's contents. It goes into the note tree. It proves a note exists without saying anything about it.

Nullifier

A value derived from a note when it is spent. The pool records every nullifier it has seen and rejects a repeat, so a note cannot be spent twice. A nullifier cannot be linked back to the note it came from by anyone who does not hold the owner's key.

Note tree and root

All commitments live in one Merkle tree. A root is a fingerprint of the tree at a moment in time. The pool remembers the last 64 roots, so a proof built against a recent root still works while the tree grows.

Proof

A zero-knowledge proof that you own the notes you are spending, that they are in the tree, that the nullifiers are computed correctly, and that value is conserved. It reveals none of the notes.

Exit

Taking value out of the pool to a public address. The recipient and the amount are public. Which notes it came from is not.

Asset id

Every note carries an asset id inside the commitment. Today the only asset is $OPA, id 1. The field is kept so a later pool version could add assets without a new circuit.

Share-based notes

$OPA notes count vault shares. When fees are donated to the vault, a share is worth more $OPA, which is how private holders earn.

Guardian

An address that can pause new shrouds. It cannot pause spends or exits, cannot move funds and cannot change any parameter.