01
Your browser draws two numbers
Not the server. Two random values, and only their Poseidon hash — the commitment — ever leaves your machine. The numbers are your receipt. Nobody else has ever held them, which is why nobody can give them back to you.
Public at this point: nothing. No transaction has been sent.
02
You send a fixed amount to a vault with no key
0.1, 1 or 10 SOL — three sizes and no others, because an unusual amount is a name. The vault is a program-derived address: no private key exists for it, and none ever did. Only the withdrawal path in the program can move a lamport out of it, and only against a valid proof.
Public at this point: that your address deposited this amount, and the commitment. Not what you will do with it, because that does not exist yet.
03
A fee goes to its own address
A deposit pays 0.5% on top of the amount, held on a separate account — never in the vault, which must keep exactly one denomination per deposit or the last withdrawal could not be paid. Those fees pay the relayer at withdrawal time, so a withdrawal returns the whole denomination.
Not shipped yet: this fee is written and tested, and reaches mainnet with the next deploy. Today a withdrawal pays its own relayer fee out of the amount.
04
You wait
This is the step people skip and the one that costs them. A deposit and a withdrawal minutes apart are read as one move whatever the proof says. The crowd is what hides you, and it needs time to exist — the pool page shows how many deposits are in it right now.
Public at this point: the size of the crowd. Anyone can compute it from the vault balance, so we show it rather than let you assume it is bigger.
05
Your machine builds a proof
It rebuilds the tree, then proves two things at once: that you know the secret behind one deposit in it, and that you have not spent that deposit before. Which deposit is never part of the statement. The proof runs in your browser and the receipt does not leave the page.
Public at this point: still nothing. A proof that has not been submitted is a file on your machine.
06
A relayer submits it and pays the fee
If your own wallet signed the withdrawal, the wallet that paid would be linked to the address that received, and the pool would have bought you nothing. So a relayer sends it instead. It cannot redirect the payment or raise its cut: both are public inputs sealed inside the proof, and the program refuses anything else. It can forward the transaction, or refuse. Nothing else.
What the relayer sees: the destination address and your IP at that moment. It cannot steal, but it can log. Its code is in the repository and anyone can run another one.
07
The money lands
At an address you named, with no history of yours. Both ends are public and the link between them is not hidden — it was never created, not in a database of ours, because there is no database of ours.
Both ends, as they happen
What can still go wrong
The proving key
It came from a setup run on one machine. Whoever held that machine's randomness could forge a withdrawal. This is the most serious open item on the project. It is being replaced by a ceremony open to anyone — two minutes, nothing to install — and it is safe the moment one contributor is honest and forgets what they typed.
Contribute to the ceremony ↓No external audit
An adversarial review found twelve real problems and every one of them is published, with what was fixed and what was only mitigated. That is not an audit. An audit is a paid third party with their name on a report, and there is not one yet.
Read the findings ↗The code can still be replaced
The upgrade authority exists, deliberately, because fixing the key above requires a redeploy. It sits on an offline wallet rather than on this server, so taking the machine no longer means taking the program, and it is revoked once the new key ships.
solana program show CTHg29kf7L6TNDH5TSd3tdoZfsmP39JjyQWKmPtEY1YWYour own habits
Withdrawing right after depositing links the two. Reusing the same destination links your withdrawals to each other. A nearly empty pool hides nearly nothing. The cryptography is the easy part and anyone telling you otherwise is selling something.