Skip to content

Research

Privacy research notes

Encryption hides what a note holds. It does not stop timing, amounts or habits from pointing at the person behind it. These notes take one leak at a time, show it in a small model you can play with, and describe how Oarkel might close it. The models are illustrations with their assumptions written underneath; none of the numbers is read from a live pool.


  1. 01

    Every root dates your note

    The root a proof refers to quietly tells everyone roughly when the spent note was created.

    Notes that could be yours

    24

    Your note

    #24 (red)

    Model: 36 notes in insertion order. Naming a root reveals the note already existed by then.
    Read the note: every root dates your note
  2. 02

    Round exits blend in

    An exact withdrawal amount is a fingerprint. Restricting exits to round values makes them common.

    Exact exit (fingerprint)

    12,347.81

    Grid exit (shared)

    10,000

    Stays shrouded

    2,347.81

    An exit of 12,347.81 is close to unique on the chain. An exit of 10,000 looks like every other exit of 10,000.

    Model: exits restricted to one significant digit (m × 10^k). The remainder stays in a note.
    Read the note: round exits blend in
  3. 03

    Exits that leave together

    Paying every exit at a shared boundary removes the timing link between a request and its payout.

    Requests (proof submitted)

    Payouts (visible on chain)

    Distinct request times

    9

    Distinct payout times

    1

    Model: nine exit requests arrive during one epoch. With batching, all are paid at the epoch boundary.
    Read the note: exits that leave together
  4. 04

    Refreshing old notes

    Spending a note into a fresh one of equal value stops age from being a signal.

    0-1920-3940-5960-7980-99100+

    Old notes form a thin, distinctive tail. A note that has sat untouched for months is easier to single out when it finally moves.

    Model: 48 notes by age in days. A refresh spends an old note into a new one of the same value.
    Read the note: refreshing old notes
  5. 05

    Counting the real crowd

    The number of notes in the pool is not the privacy you get. What an observer can rule out matters more.

    Notes in the pool

    12,000

    Plausible senders

    12,000

    Effective anonymity

    13.6 bits

    Model: 12,000 notes. Each open leak divides the plausible senders by an assumed factor (40, 12, 6, 25).
    Read the note: counting the real crowd
  6. 06

    Lookups that leave no trace

    Reading the same record the same way every time reveals which record you care about.

    Reads so far

    0

    Distinct slots touched

    0

    Model: 8 storage slots. The wanted record always sits in slot 6; an observer sees which slot is touched.
    Read the note: lookups that leave no trace