Skip to main content

What is and is not hidden

zk-pad hides who controls the beneficiary's money and where it finally goes. It does not hide trading, and it cannot hide what a coin's creator chooses to advertise.

Summary table​

InformationPublic?Notes
The coin, its pool, its fee F and its quote tokenPublicTokenLaunched event
The creator's launch addressPublicThe sender of the launch transaction
Every trade, trader address and amountPublicLike any DEX trade
Holders and balances of the coinPublicStandard ERC20
The dev buyPublicDevBuy event
Fees generated, and the protocol / beneficiary amountsPublicAuditable by design
The beneficiary idPublicAn opaque 32-byte hash
The beneficiary id's balancesPublicbalanceOf(id, asset)
Who the beneficiary is (stealth key)HiddenKnown only to the creator and whoever they gave the claim link to
Who the beneficiary is (social escrow)Hidden from the chainEvery attestor of the committee can decrypt the hint on its own (threshold 1), so each of them knows
Who the beneficiary is (public social recipient)PublicThe platform account is named in a plaintext hint, with an attestor-signed label. Its per-account totals across coins are public.
The wallet of a public social recipientHiddenBound to a fresh signing-only key; exits are shielded only (relayer and UI refuse direct claims)
What the coin's name, ticker, image and description sayPublicOften names the beneficiary. zk-pad cannot hide what the creator writes.
The beneficiary's walletHiddenThe stealth key is never funded and never sends a transaction
That a claim happened, its amount, asset, time, relayer and relayer feePublicClaimed event
A direct claim's destination addressPublicUse a fresh address
A Railgun claim's 0zk addressHiddenOnly the recipient's Railgun wallet can read the note
What happens to a shielded note afterwardsHiddenSubject to Railgun's anonymity set on BSC
The stealth owner addressPublic once registeredRevealed in the registration calldata. It is a throwaway key that never holds funds.
Social escrow bind: the new owner key and timelockPublicBindProposed / BindFinalized events
The beneficiary's IP addressVisible to the relayer, attestor and RPC you contactUnless you use Tor or a similar network. Services keep no per-user logs, but you are trusting that.
Which id you looked upHiddenThe SDK downloads every id's balances and nonces (fetch-everything) and filters locally; the web app makes no id-specific RPC reads (consolidation prices come from one fixed batch of unit oracle quotes, the same for every visitor)
Your claim link or stealth keyHidden from serversKept in the URL fragment, which browsers never send. Claim-kit files get random names, and search boxes refuse pasted keys and claim links instead of putting them in a URL.

Who can learn what​

PartyCan learn
Anyone watching the chainEverything marked Public above
The creator (stealth key)The beneficiary's identity (they chose them) and, until the beneficiary rotates the key, the ability to claim
The creator (social escrow)Which account the escrow is for (they chose it). Cannot claim.
A relayerYour IP and timing (unless you use Tor), and the claim contents, which become public anyway
Each attestorWhich accounts have escrows (each one decrypts hints alone); which account logged in to bind
Railgun list providers (PPOI)The shield transaction and the relayer address that sent it
The zk-pad protocol teamNothing beyond the above, unless they also run a relayer or attestor

Common misunderstandings​

  • "Nobody knows who the coin is for." Only true if the creator did not say so. A coin called "Donate to @alice" is clearly about Alice. zk-pad hides her wallet and her spending, not the coin's message.
  • "Railgun makes the payout invisible." The shield is visible: amount, time and beneficiary id. What is hidden is the destination 0zk address and later activity, and only as well as the BSC Railgun anonymity set allows.
  • "The amounts are secret." No. Fee accruals and claims are public on purpose, so anyone can audit them.
  • "Direct claims are private." Only if you claim to an address that has never been and will never be linked to you.