zSOL
◎ Devnet live Buy $ZSOL soon
Zcash proved private money works · now on Solana

Shielded SOL · association-set privacy

Prove where your money didn't come from.

Zcash showed the world you can move money privately. zSOL brings that to Solana — with one upgrade: your withdrawal carries a zero-knowledge proof that your deposit is not one of the flagged ones. Private, and provably clean.

1 SOL 1 zSOL 1 SOL, fresh address + proof

Deposit pool · 132 commitments

Your deposit In your association set Flagged deposit Outside your set

Status, plainly: this page describes a protocol design based on published research. There is no deployed contract, no audit, and no token. Nothing here is live, and no figure on this page is a real on-chain measurement.

The lineage

Privacy grew up on Zcash. It belongs on Solana too.

Zcash spent a decade proving that shielded transactions are safe, sound, and practical — real cryptography, not a promise. But Zcash privacy is all-or-nothing: once funds are shielded, no one can tell the honest from the stolen, and that is exactly what gets private money delisted.

zSOL takes Zcash's proven shielding and adds the missing half — proof of clean origin — then runs it where fees are cheap and blocks are fast enough for the anonymity set to actually grow. Same privacy heritage; a home built for it.

Mechanism

How a withdrawal works

  1. Deposit SOL, mint zSOL

    You send SOL and publish a commitment — a hash of a secret only you hold. The deposit is public, like any Solana transaction. Nothing is hidden yet.

  2. Choose your association set

    A set is a published list of deposits somebody vouches for. Pick a broad set for a bigger anonymity crowd, a conservative one for a stronger claim.

  3. Withdraw with a proof

    You withdraw to a fresh address and publish a zero-knowledge proof: you know the secret behind some commitment in that set, and it hasn't been spent. Which deposit is yours stays private.

  4. The nullifier closes it

    Each withdrawal reveals a one-way nullifier from your secret — proving this deposit was never withdrawn before without revealing which one it is. Double-spending is impossible; linking is not.

The distinction

Why zSOL isn't a mixer

The difference isn't the cryptography — it's what the protocol lets you prove.

 MixerzSOL
Hides your transaction graphYesYes
Lets you prove funds aren't from a hackNo — impossible by designYes, in zero knowledge
Honest users separable from stolen fundsNoYes, by association set
An exchange can accept the withdrawalTypically refusedThe proof is the evidence
Value to someone laundering a hackHigh — that's the problemNone. They can't produce the proof

The last row is the whole design. A thief can deposit — nobody can stop that — but no honest set will include their commitment, so they can never withdraw with a proof anyone accepts. Privacy stops being a shield for them and stays one for everyone else.

Where this stands

Roadmap

Now

Protocol specification

Circuit design, commitment and nullifier scheme, association-set format. Public, reviewable, unimplemented.

Next

Reference circuits and devnet program

Groth16 circuits for membership and exclusion, an Anchor program on devnet, and published test vectors.

Then

Independent audit and trusted setup

Circuit audit plus a multi-party trusted-setup ceremony with public transcripts. No mainnet before both.

Later

Set-provider ecosystem

Tooling so more than one organisation publishes association sets, so no single party becomes the gatekeeper.

Questions

Straight answers

Can zSOL be used to launder money?
Not usefully. Laundering needs the output accepted somewhere, and the only thing that makes a withdrawal acceptable here is a proof of exclusion the launderer cannot produce. A pool with no proof attached is just a mixer, and that isn't what this is.
Does the protocol ever see my identity?
No. The contract verifies arithmetic over commitments. It never learns an address linkage, and there's no off-chain account, KYC step, or operator with a view of the mapping.
What if I'm excluded from every set unfairly?
You keep your funds — the deposit is always withdrawable to the original depositor without a set proof. You lose the anonymity, not the money. No set provider can strand your SOL.
Why Solana and not just Zcash?
Zcash proved the cryptography; its privacy is all-or-nothing and can't prove clean origin. Solana's cheap, fast blocks let the anonymity set grow and let a proof be verified on every withdrawal without punishing fees.
Is zSOL a token I can trade?
It's a claim on deposited SOL inside the pool, not a speculative asset. No separate governance token, and no reason for one — a verifier contract doesn't need one to function.

Privacy, brought home.

No email, no sign-up, no presale — that would rather defeat the point. Follow the build in the open: the spec, the code, and the working devnet program are all public.