Security
Threat model
What Opaque protects against, and the gaps that are known today.
Copy Markdown
What it protects
- Your balance and your payments inside the pool. An observer cannot see who owns a note, how much it holds, or who paid whom.
- Your funds from the team. No admin can move or freeze notes.
What it does not protect
- The edges. Deposits and withdrawals are public.
- Habits. Matching amounts and timing, reusing addresses and linking yourself elsewhere. See Staying private.
- A small crowd. Privacy grows with the number of notes. Early on, there are few.
- Your network. Your RPC provider sees your requests.
Known gaps today
| Gap | Status |
|---|---|
| No audit | The code is unaudited |
| No generated verifier | The verifier has not been produced or tested end to end |
| No wallet-key binding | Anyone who learns a note key can spend its notes. The binding is planned |
| Proof system is not post-quantum | A future quantum attacker could forge proofs. The hash-based parts are not affected. See Research |
| Ciphertexts live on-chain forever | Today they depend on classical key exchange. A hybrid scheme is proposed |
| Fee keeper | Soon: an automated keeper routes trade fees into the vault |
| Gas cost | A private exit is expensive and may exceed public bundler limits |
Reporting
Report a vulnerability through the contact in SECURITY.md. A public bounty is planned.