Unaudited beta. Darkpool has had no independent security audit. The mainnet launch will be an unaudited beta with deposit caps. Read the security model

How it works

From a public deposit
to a fresh wallet.

Darkpool is a shielded pool plus a wallet that proves things in your browser. This page walks through every moving part: notes, proofs, the relayer, Ghost trades, recovery and the exit that needs nobody’s permission.

Step 1 · Shield

A deposit becomes private notes.

Shielding sends ETH or USDC from a normal Ethereum address into the Darkpool pool contract. In return, your wallet adds one or more note commitments to a public Merkle tree. A commitment is a hash of the note’s asset, amount, owner key and a random secret, so it reveals none of them.

The deposit transaction is public: anyone can see the depositing address, the asset, the amount and the time. What becomes private is everything after: which note later pays for what.

  1. Pick an asset and amount. The wallet creates the note secrets on your device.
  2. Deposit. The pool takes custody and inserts the commitment into the tree. Deposits from sanctioned addresses are refused.
  3. Your balance updates. The wallet decrypts its own notes from public events and shows them as your shielded balance.
Notes in a Merkle tree Every deposit adds a note commitment as a leaf of a public Merkle tree. A proof shows that you own one unspent leaf under the current root without revealing which leaf. PUBLIC ROOT YOUR NOTE The proof says “one of these”, never which.
Every deposit adds a leaf. Spending proves you own an unspent leaf under the current root, without saying which one.
Step 2 · Private notes

Spend without saying which note.

A shielded balance is a set of notes, like coins in a purse. To spend, the wallet consumes notes and creates new ones: one for the recipient, one for your change. Each spent note publishes a nullifier, a value that only the owner can compute. The pool rejects a nullifier it has seen before, which stops double spending without revealing which commitment was spent.

Private send moves value to another Darkpool user’s receive address, which starts with dp1.. New notes are published encrypted to the recipient’s key, so only they can find and read them. Sender, recipient and amount stay inside the pool.

Inside the pool, the protocol hides who owns which note, which notes fund an action, and the amounts and parties of private transfers. Anything that enters or leaves the pool is public. See the full privacy model.

Zero-knowledge proofs

Proofs are made on your device.

Every private action carries a Groth16 zero-knowledge proof generated in your browser, in a background worker. The proof convinces the pool contract that:

  • you own the notes being spent, and they are in the tree under a recent root;
  • the nullifiers are correct, so each note is spent once;
  • value is conserved: inputs equal outputs plus any withdrawal and fee;
  • amounts are in range, so nothing can be created from nothing;
  • the action’s public context is bound: recipient, amounts, token, fee and minimums.

Your 24-word seed never leaves your device. The proof reveals no secret. The proving files the browser downloads are checked against known hashes before use.

Trusted setup. Groth16 needs a one-time setup. Darkpool’s phase 2 builds on the public Perpetual Powers of Tau and was finalized with an Ethereum block-hash beacon. A multi-party ceremony is in progress. Details on the security page.

The relayer

Someone else submits. Nobody else decides.

If you sent a private withdrawal yourself, the address paying gas would be public and could link you. Instead a relayer submits the transaction and pays the gas, and is reimbursed from your shielded balance. You see its quote before you sign.

The relayer cannot change anything that matters. The proof binds the recipient, amounts, token and fee; signed orders bind minimum outputs and deadlines. A changed transaction fails verification on chain. What a relayer can do is refuse or delay service, and it sees request metadata such as your IP address.

Your wallet keeps a transaction journal . If a request is interrupted, it is retried with the identical signed request, never a changed one.

Life of a private action Your device builds a zero-knowledge proof and a signed request. The relayer submits it and pays gas, but cannot change it. The pool contract verifies the proof, the Merkle root and the nullifiers, then pays only the recipient, amount and token fixed by the proof. If the relayer is offline you can submit directly to the pool. Your deviceseed + Groth16 proof, made in the browser proof + signed request Relayersubmits and pays gas; cannot alter it transaction Pool contractchecks proof, root and nullifiers pays exactly what was proven Recipientaddress, amount, token fixed by the proof DIRECT EXIT
The relayer is a courier, not a custodian. The dashed path is the direct exit you can always use.
Ghost Buy

Buy into a wallet that never held ETH.

Ghost Buy is a single Ethereum transaction that withdraws from your shielded ETH balance, buys a Stockereum token and delivers it to a brand-new wallet derived from your seed. The new wallet never receives ETH, so there is no funding transfer to trace back to you.

  1. Quote. The wallet fetches a price and you choose a minimum amount of tokens.
  2. Prove and sign. Your device proves the withdrawal and signs the complete order: token, market, fresh wallet, minimum received, deadline.
  3. One transaction. The relayer submits; the router withdraws, buys and delivers. If fewer tokens than your minimum would arrive, or any step fails, everything reverts.

Public afterwards: the purchase, the fresh wallet and its token balance. Each Ghost Buy uses a new wallet index; merging fresh wallets or sending their tokens to your main wallet links them.

Ghost Buy in one transaction Shielded ETH is withdrawn under a proof, swapped on Stockereum with a signed minimum output, and the tokens are delivered to a fresh seed-derived wallet, all inside one Ethereum transaction. If any step fails, the whole purchase reverts. Your shielded ETHinside the pool ONE ETHEREUM TRANSACTION 1 · Proof-bound withdrawalamount and fee fixed by the proof 2 · Buy on Stockereumreverts below your signed minimum 3 · Deliver tokenschecked against the minimum Fresh walletpublic: holds tokens, never ETH
All three steps happen in one transaction, or none do.
Ghost Sell

Sell with no gas, re-shield the proceeds.

A fresh wallet has tokens but no ETH for gas. Ghost Sell uses EIP-7702, which lets an ordinary Ethereum account run fixed contract code for a transaction it authorized. The relayer pays the gas; the wallet’s own signature controls what happens.

  1. Sign the sale. Your device signs the token, amount, minimum ETH out, relayer fee, nonce and deadline, plus a proof for the deposit back into the pool.
  2. Sell and shield together. The wallet sells on Stockereum and deposits the guaranteed minimum proceeds into the pool as a new private note, in the same transaction.
  3. Reimburse. The relayer receives only the signed gas and service fee.

If the market fills better than your minimum, the extra ETH stays in the fresh wallet as recoverable surplus that you can sweep later. The sale and the fresh wallet are public, and the deposit is visible as coming from the fresh wallet; once inside the pool, the new note is as private as any other.

Ghost Sell in one transaction A fresh wallet holding tokens and no ETH is executed through EIP-7702 with relayer-paid gas. It sells on Stockereum with a signed minimum, deposits the guaranteed minimum proceeds back into the shielded pool as a new private note, and reimburses the relayer. Any surplus from better execution stays in the fresh wallet. Fresh wallettokens, 0 ETH · EIP-7702 ONE TRANSACTION · RELAYER PAYS GAS 1 · Sell on Stockereumreverts below your signed minimum 2 · Shield the minimumbecomes a new private note 3 · Reimburse the relayersigned gas + service fee Shielded poolguaranteed proceeds Surplus ETHstays in fresh wallet
The sale and the deposit revert together if either fails.
Private Swap

Change assets without leaving the pool.

Private Swap converts one shielded asset into another, such as ETH into USDC, through Uniswap v3 in one transaction: a proof-bound withdrawal, the swap, and a private deposit of the guaranteed minimum. Anything the swap returns above the minimum goes to a fresh, seed-recoverable wallet. It uses two proofs, so it costs roughly twice the gas of other private actions.

Private Yield uses the same path to move shielded ETH into wstETH, Lido’s staked ETH, so it earns staking rewards while staying in your private balance. Rewards are set by Lido and vary; Darkpool does not promise a rate.

The swap itself happens on a public market and is visible; which notes paid for it and who received the result are not.

Private Swap in one transaction Shielded ETH is withdrawn under a proof, swapped through Uniswap v3 with a minimum output, and the guaranteed minimum is deposited back into the pool as a private USDC note. Anything above the minimum goes to a fresh seed-recoverable wallet. Shielded ETHinside the pool ONE TRANSACTION · TWO PROOFS 1 · Proof-bound withdrawalETH goes only to the swap router 2 · Swap on Uniswap v3reverts below the minimum 3 · Private depositguaranteed minimum as a note Shielded USDCnew private note Fresh walletanything above minimum
Withdraw, swap and re-deposit, all bound by proofs.
Recovery

One phrase restores everything.

Your 24-word seed is the root of every key: the shielded account that owns notes, your dp1. receive address and every fresh ghost wallet, which are derived by index.

  • Notes

    On a new device, the wallet rescans public pool events and decrypts the notes your keys own.

  • Ghost wallets

    Fresh wallets are re-derived from the seed, and used ones are found from public events.

  • Encrypted backups

    An optional password-encrypted backup speeds up restore. The seed alone is enough.

Anyone with your seed controls all of it. Keep it offline. Darkpool will never ask for it, and no support chat, form or airdrop needs it.

Direct exit

If the relayer goes away, your funds don’t.

The relayer is a convenience. Withdrawals can always be submitted straight to the pool contract: the wallet builds the same proof locally from your seed and public chain data, and you send the transaction from any Ethereum account that has ETH for gas. That account is visible as the sender, so choose it with care.

The pool has no owner and no upgrade path, and the deposit guardian can only limit new deposits. No one can block a withdrawal or exit.

Relayed versus direct withdrawal
RelayedDirect
Who pays gasRelayer, reimbursed from your shielded balanceAny account you choose
Sender visible on chainThe relayerYour chosen account
Needs Darkpool servicesYesNo, only an Ethereum RPC
Service fee0.00003 ETHNone

See every utility and its status.

What opens with the mainnet beta, what is in testing, and what is only planned.

Utilities & status