Security

Threat model

What Opaque protects against, and the gaps that are known today.

Copy Markdown

What it protects

  • Your balance and your payments inside the pool. An observer cannot see who owns a note, how much it holds, or who paid whom.
  • Your funds from the team. No admin can move or freeze notes.

What it does not protect

  • The edges. Deposits and withdrawals are public.
  • Habits. Matching amounts and timing, reusing addresses and linking yourself elsewhere. See Staying private.
  • A small crowd. Privacy grows with the number of notes. Early on, there are few.
  • Your network. Your RPC provider sees your requests.

Known gaps today

GapStatus
No auditThe code is unaudited
No generated verifierThe verifier has not been produced or tested end to end
No wallet-key bindingAnyone who learns a note key can spend its notes. The binding is planned
Proof system is not post-quantumA future quantum attacker could forge proofs. The hash-based parts are not affected. See Research
Ciphertexts live on-chain foreverToday they depend on classical key exchange. A hybrid scheme is proposed
Fee keeperSoon: an automated keeper routes trade fees into the vault
Gas costA private exit is expensive and may exceed public bundler limits

Reporting

Report a vulnerability through the contact in SECURITY.md. A public bounty is planned.