Security
Trust model
What the team cannot do, what is promised, and what is not proven yet.
Copy Markdown
What we will not do
- No admin keys over funds. The core is immutable.
- No upgradeable proxies on the pool.
- No pausing of withdrawals. The guardian can only pause new deposits.
- No hidden team allocation or unlabeled team activity.
- No claim that Opaque hides deposits or withdrawals. Shroud and exit amounts and addresses are public. It hides what happens between them.
- No yield promises. Yield comes from fees and can be zero.
What the team can and cannot do
| Can | Cannot |
|---|---|
| Pause new shrouds, through the guardian | Pause spends, exits or donations |
| Choose parameters before deployment | Change any parameter after |
| Receive the team share of trade fees, once the harvester exists | Move or freeze anyone's notes |
Invariants
These are the properties the pool must always keep. They are being turned into Foundry invariant tests.
- The unspent note value never exceeds the pool's backing.
- A nullifier can be spent once.
- Only a known root can be spent against.
- The exit amount never exceeds the value of the spent notes minus fees.
- The guardian cannot move or freeze funds.
Stage caps
Deposit caps rise on a fixed on-chain schedule, set at deployment. The numbers are not decided yet.
Bounty
Public, and scaling with the size of the pool.
Honest labeling
Any seeded liquidity, team deposit or test activity is labeled as such on the site and in the dashboard.
What is not proven yet
The code is unaudited. The verifier is not generated. Spends are not bound to a wallet key. See Threat model.