Security

Trust model

What the team cannot do, what is promised, and what is not proven yet.

Copy Markdown

What we will not do

  • No admin keys over funds. The core is immutable.
  • No upgradeable proxies on the pool.
  • No pausing of withdrawals. The guardian can only pause new deposits.
  • No hidden team allocation or unlabeled team activity.
  • No claim that Opaque hides deposits or withdrawals. Shroud and exit amounts and addresses are public. It hides what happens between them.
  • No yield promises. Yield comes from fees and can be zero.

What the team can and cannot do

CanCannot
Pause new shrouds, through the guardianPause spends, exits or donations
Choose parameters before deploymentChange any parameter after
Receive the team share of trade fees, once the harvester existsMove or freeze anyone's notes

Invariants

These are the properties the pool must always keep. They are being turned into Foundry invariant tests.

  1. The unspent note value never exceeds the pool's backing.
  2. A nullifier can be spent once.
  3. Only a known root can be spent against.
  4. The exit amount never exceeds the value of the spent notes minus fees.
  5. The guardian cannot move or freeze funds.

Stage caps

Deposit caps rise on a fixed on-chain schedule, set at deployment. The numbers are not decided yet.

Bounty

Public, and scaling with the size of the pool.

Honest labeling

Any seeded liquidity, team deposit or test activity is labeled as such on the site and in the dashboard.

What is not proven yet

The code is unaudited. The verifier is not generated. Spends are not bound to a wallet key. See Threat model.