Shielded SOL · association-set privacy
Prove where your money didn't come from.
Zcash showed the world you can move money privately. zSOL brings that to Solana — with one upgrade: your withdrawal carries a zero-knowledge proof that your deposit is not one of the flagged ones. Private, and provably clean.
Deposit pool · 132 commitments
Status, plainly: this page describes a protocol design based on published research. There is no deployed contract, no audit, and no token. Nothing here is live, and no figure on this page is a real on-chain measurement.
The lineage
Privacy grew up on Zcash. It belongs on Solana too.
Zcash spent a decade proving that shielded transactions are safe, sound, and practical — real cryptography, not a promise. But Zcash privacy is all-or-nothing: once funds are shielded, no one can tell the honest from the stolen, and that is exactly what gets private money delisted.
zSOL takes Zcash's proven shielding and adds the missing half — proof of clean origin — then runs it where fees are cheap and blocks are fast enough for the anonymity set to actually grow. Same privacy heritage; a home built for it.
Mechanism
How a withdrawal works
Deposit SOL, mint zSOL
You send SOL and publish a commitment — a hash of a secret only you hold. The deposit is public, like any Solana transaction. Nothing is hidden yet.
Choose your association set
A set is a published list of deposits somebody vouches for. Pick a broad set for a bigger anonymity crowd, a conservative one for a stronger claim.
Withdraw with a proof
You withdraw to a fresh address and publish a zero-knowledge proof: you know the secret behind some commitment in that set, and it hasn't been spent. Which deposit is yours stays private.
The nullifier closes it
Each withdrawal reveals a one-way nullifier from your secret — proving this deposit was never withdrawn before without revealing which one it is. Double-spending is impossible; linking is not.
The distinction
Why zSOL isn't a mixer
The difference isn't the cryptography — it's what the protocol lets you prove.
| Mixer | zSOL | |
|---|---|---|
| Hides your transaction graph | Yes | Yes |
| Lets you prove funds aren't from a hack | No — impossible by design | Yes, in zero knowledge |
| Honest users separable from stolen funds | No | Yes, by association set |
| An exchange can accept the withdrawal | Typically refused | The proof is the evidence |
| Value to someone laundering a hack | High — that's the problem | None. They can't produce the proof |
The last row is the whole design. A thief can deposit — nobody can stop that — but no honest set will include their commitment, so they can never withdraw with a proof anyone accepts. Privacy stops being a shield for them and stays one for everyone else.
Where this stands
Roadmap
Protocol specification
Circuit design, commitment and nullifier scheme, association-set format. Public, reviewable, unimplemented.
Reference circuits and devnet program
Groth16 circuits for membership and exclusion, an Anchor program on devnet, and published test vectors.
Independent audit and trusted setup
Circuit audit plus a multi-party trusted-setup ceremony with public transcripts. No mainnet before both.
Set-provider ecosystem
Tooling so more than one organisation publishes association sets, so no single party becomes the gatekeeper.
Questions
Straight answers
- Can zSOL be used to launder money?
- Not usefully. Laundering needs the output accepted somewhere, and the only thing that makes a withdrawal acceptable here is a proof of exclusion the launderer cannot produce. A pool with no proof attached is just a mixer, and that isn't what this is.
- Does the protocol ever see my identity?
- No. The contract verifies arithmetic over commitments. It never learns an address linkage, and there's no off-chain account, KYC step, or operator with a view of the mapping.
- What if I'm excluded from every set unfairly?
- You keep your funds — the deposit is always withdrawable to the original depositor without a set proof. You lose the anonymity, not the money. No set provider can strand your SOL.
- Why Solana and not just Zcash?
- Zcash proved the cryptography; its privacy is all-or-nothing and can't prove clean origin. Solana's cheap, fast blocks let the anonymity set grow and let a proof be verified on every withdrawal without punishing fees.
- Is zSOL a token I can trade?
- It's a claim on deposited SOL inside the pool, not a speculative asset. No separate governance token, and no reason for one — a verifier contract doesn't need one to function.
Privacy, brought home.
No email, no sign-up, no presale — that would rather defeat the point. Follow the build in the open: the spec, the code, and the working devnet program are all public.