Research
Privacy research notes
Encryption hides what a note holds. It does not stop timing, amounts or habits from pointing at the person behind it. These notes take one leak at a time, show it in a small model you can play with, and describe how Oarkel might close it. The models are illustrations with their assumptions written underneath; none of the numbers is read from a live pool.
01
Every root dates your note
The root a proof refers to quietly tells everyone roughly when the spent note was created.
Read the note: every root dates your noteNotes that could be yours
24
Your note
#24 (red)
Model: 36 notes in insertion order. Naming a root reveals the note already existed by then. 02
Round exits blend in
An exact withdrawal amount is a fingerprint. Restricting exits to round values makes them common.
Read the note: round exits blend inExact exit (fingerprint)
12,347.81
Grid exit (shared)
10,000
Stays shrouded
2,347.81
An exit of 12,347.81 is close to unique on the chain. An exit of 10,000 looks like every other exit of 10,000.
Model: exits restricted to one significant digit (m × 10^k). The remainder stays in a note. 03
Exits that leave together
Paying every exit at a shared boundary removes the timing link between a request and its payout.
Read the note: exits that leave togetherRequests (proof submitted)
Payouts (visible on chain)
Distinct request times
9
Distinct payout times
1
Model: nine exit requests arrive during one epoch. With batching, all are paid at the epoch boundary. 04
Refreshing old notes
Spending a note into a fresh one of equal value stops age from being a signal.
Read the note: refreshing old notes0-1920-3940-5960-7980-99100+Old notes form a thin, distinctive tail. A note that has sat untouched for months is easier to single out when it finally moves.
Model: 48 notes by age in days. A refresh spends an old note into a new one of the same value. 05
Counting the real crowd
The number of notes in the pool is not the privacy you get. What an observer can rule out matters more.
Read the note: counting the real crowdNotes in the pool
12,000
Plausible senders
12,000
Effective anonymity
13.6 bits
Model: 12,000 notes. Each open leak divides the plausible senders by an assumed factor (40, 12, 6, 25). 06
Lookups that leave no trace
Reading the same record the same way every time reveals which record you care about.
Read the note: lookups that leave no traceReads so far
0
Distinct slots touched
0
Model: 8 storage slots. The wanted record always sits in slot 6; an observer sees which slot is touched.