Key concepts
The few ideas you need to understand how Opaque works.
Shroud
Depositing $OPA into the pool. The transaction is public: your address and the amount are visible. In return, a note is added to the pool.
Note
A private record of value. The chain stores only a commitment to it and an encrypted copy that the owner can read. Nobody else can see the owner or the amount.
A note commits to its owner's key, a random value, a blinding value, an asset id and an amount.
Commitment
A hash of the note's contents. It goes into the note tree. It proves a note exists without saying anything about it.
Nullifier
A value derived from a note when it is spent. The pool records every nullifier it has seen and rejects a repeat, so a note cannot be spent twice. A nullifier cannot be linked back to the note it came from by anyone who does not hold the owner's key.
Note tree and root
All commitments live in one Merkle tree. A root is a fingerprint of the tree at a moment in time. The pool remembers the last 64 roots, so a proof built against a recent root still works while the tree grows.
Proof
A zero-knowledge proof that you own the notes you are spending, that they are in the tree, that the nullifiers are computed correctly, and that value is conserved. It reveals none of the notes.
Exit
Taking value out of the pool to a public address. The recipient and the amount are public. Which notes it came from is not.
Asset id
Every note carries an asset id inside the commitment. Today the only asset is $OPA, id 1. The field is kept so a later pool version could add assets without a new circuit.
Share-based notes
$OPA notes count vault shares. When fees are donated to the vault, a share is worth more $OPA, which is how private holders earn.
Guardian
An address that can pause new shrouds. It cannot pause spends or exits, cannot move funds and cannot change any parameter.