What protects your funds, and what doesn’t yet.
Darkpool is unaudited beta software. This page explains who controls what, which risks remain, and how the code was tested, without overstating any of it.
No independent audit yet. The Ethereum mainnet launch will be an unaudited beta. Deposits are capped (5 ETH on the ETH pool) to limit what is at risk while the code is young.
Tests, Ethereum-fork rehearsals and automated analysis show specific behaviour; they do not establish production safety. Only deposit what you can afford to lose.
No owner. No upgrade path.
The pool contracts have no owner, no proxy and no upgrade function. Nobody, including the Darkpool team, can take notes, change the proof verifier, or alter the rules after deployment.
The flip side: bugs cannot be patched in place. A fix means deploying new contracts at new addresses and moving funds explicitly. That is why the beta starts with deposit caps.
Every spend is proven
The pool checks the proof, a recent Merkle root and unused nullifiers before moving any value.
Every operation is bound
Recipients, amounts, token, fee and minimums are part of what the proof and signatures cover.
One narrow role, with no power over exits.
A deposit guardian exists so the beta can limit risk. It can only affect how much new value enters a pool, and it can renounce the role permanently.
| Action | Guardian |
|---|---|
| Change the cap on new deposits | Can |
| Set or replace deposit screening | Can; a replacement takes effect after a 2 days notice |
| Transfer or renounce the role | Can |
| Block private transfers | Cannot |
| Block withdrawals or direct exits | Cannot |
| Take or freeze notes | Cannot |
| Change the verifier or upgrade contracts | Cannot |
Sanctioned deposits are refused. Exits are never blocked.
Deposits from sanctioned addresses are refused. The check looks at the visible depositing address; it is screening, not a proof of where funds came from, and funds forwarded through another address are judged by that address. Screening applies to deposits only. It never affects private transfers, withdrawals or exits, so a faulty screen can at worst pause new deposits.
An optional association-set “proof of innocence”, which would let you prove your funds came from a set of deposits excluding known bad actors, is .
A courier that can’t open the envelope.
The relayer submits transactions and pays gas. It cannot change the recipient, amounts, token or minimum outputs, because those are bound by the proof and your signed order. Signatures also bind a nonce and deadline, and used nullifiers and digests prevent replay.
Before signing, the relayer simulates the transaction and quotes its fee; the signed gas ceiling cannot exceed that quote. Signed transactions are written to a durable journal before broadcast and retried unchanged.
Risks that remain
- Availability. A relayer can refuse or delay service. You can always exit directly from the chain.
- Metadata. The relayer sees your requests and IP address.
- Ordering. Signed minimums protect your price, but orders do not prevent public-mempool MEV or guarantee ordering.
- Gas spikes. If network fees rise above the quote, a fresh quote is needed.
Groth16 setup, and where it stands.
Groth16 proofs need a one-time setup. If every participant in the setup colluded or kept their secret, they could forge proofs. It is sound as long as at least one contributor was honest and destroyed their secret.
Darkpool’s circuit-specific phase 2 builds on the public Perpetual Powers of Tau and was finalized with an Ethereum block-hash beacon. So far, the phase-2 contribution came from a single build machine. A multi-party ceremony is in progress. Until it completes, the setup should not be treated as independently trusted.
Proving files are checked
The wallet downloads the circuit’s proving files and checks each
one against its published hash before use. A tampered file is
refused. The proving files are published under
/app/proofs/, and the ceremony transcript is part of
the published source archive.
Your seed is the master key.
The browser holds the seed and derived keys. The locked wallet and backups are encrypted with your password (PBKDF2 and AES-GCM).
Keep the seed offline
Write down the 24 words. Never type them into a website, chat or form other than the wallet itself.
Encrypted backups
A backup is only as strong as its password. Use a long, unique one.
Device risk
A malicious extension, a phishing copy of the site or a compromised device can steal an unlocked seed. Check the address bar: darkpool.website.
Code Darkpool does not control.
Ghost trades rely on Stockereum’s markets; Private Swap and Private Yield rely on Uniswap v3 and Lido’s wstETH. Their contracts, and the behaviour of the tokens being traded, are outside Darkpool’s control. A token with transfer fees, freezes or unusual rules can prevent an exit from a ghost wallet. Adapters check the exact market they expect, but that does not make an arbitrary token safe.
EIP-7702 installs a fixed delegate on a ghost wallet for Ghost Sell. That delegation can remain installed after a transaction; this is different from upgrading a pool.
Evidence, not an audit.
These checks were run during development. They are useful evidence about specific behaviour and are not a substitute for independent review.
| Property | How it was exercised |
|---|---|
| Ownership, conservation and ranges in proofs | Real-proof scenarios against the circuit |
| Caps, custody, root history, reentrancy and exits | Contract tests, including custody fuzzing |
| Screening preserves exits; only the guardian configures it | Contract screening and authorization tests |
| Recipient, minimum and operation cannot be redirected | Integration tamper checks |
| Ghost Buy delivers at least the signed minimum | Real Groth16 proof and a Stockereum purchase on an Ethereum mainnet fork |
| Ghost Sell re-shields with no ETH in the fresh wallet | Real EIP-7702 sale on an Ethereum mainnet fork |
| Idempotent requests and replay rejection | Relay integration and on-chain replay checks |
| Seed restores notes and ghost wallets | SDK and integration recovery checks |
| USDC decimals handled natively | Real USDC deposit on a mainnet fork, plus browser checks |
The full source, build scripts and licences are published: download the source archive.