open app →

docs

basics · privacy · screening · advanced · fees · addresses

three actions, one private balance

Your public wallet exists at the edges. Private notes exist in the middle.

depositETH or a whitelisted token. The deposit is public; the net amount becomes an encrypted note.
tradeEnter an amount. Permissionless solvers quote offchain and your browser follows the best valid net output.
withdrawRedeem notes only to your connected wallet. The withdrawal is public and cannot be redirected.

q: does a solver hold my funds?
a: No. The pool holds assets. A solver temporarily receives only the exact proved sell amount inside an atomic settlement call.

q: is my private wallet onchain?
a: No. It is a local key hierarchy used to decrypt and spend notes. There is no persistent private-wallet address onchain.

q: can I withdraw to another address?
a: No. This intentionally avoids arbitrary private transfers. Withdrawals pay only the public wallet bound to the notes.

q: can I trade every token?
a: Trade outputs may be arbitrary non-blocked token contracts. Direct deposits accept only assets enabled by the pool.

q: what must I back up?
a: The encrypted private-wallet file and its passphrase. You need both to restore your private balance, plus access to your original deposit wallet to withdraw. Losing either recovery factor can make the balance inaccessible.

q: what is the fee?
a: Deposits, trades, and withdrawals each charge 0.5% of the asset received from that action.

privacy model

actionvisiblenot included
depositwallet, asset, amount, commitmentviewing + spending secrets
tradesolver, assets, amounts, proof, nullifierswallet address, note owner
withdrawwallet, asset, amount, proof, nullifiersviewing + spending secrets

privacy is more than calldata. nostr relays can observe RFQ pair, amount, timing, selected solver and network metadata. RPC providers can observe reads and tx submission. use reviewed network privacy and avoid uniquely identifying patterns.

deposit screening

New deposits go through an admission check before they enter the pool. The pool contract requires a short-lived signed approval for each deposit, including calls made outside this website.

Only your public wallet address is used for the check. Your note secrets and private keys stay on your device.

The check applies only to deposits. Trading, withdrawals, recovery, wallet connection, and browsing do not require it. If admission is paused or unavailable, new deposits stop; existing withdrawal access remains intact.

Admission criteria can change over time. Withdrawals always stay bound to the original depositing wallet.

protocol + security model

zero-knowledge proofs (groth16 zk-snarks)

veil uses Groth16 zk-SNARKs for private trade authorization verified onchain. Each note commits to its asset, amount, spending authority, chain, and pool in a Poseidon Merkle tree. Trade proofs establish ownership and conserve value without including the note owner in public trade inputs. Trade assets, exact amounts, and nullifiers remain public; nullifiers prevent double-spends. Output notes are encrypted for recovery. A private wallet is not an onchain address.

decentralized solver auction

Changing the amount broadcasts an RFQ through several Nostr relays under a fresh one-time key. Independent solvers calculate routes offchain and return encrypted, EIP-712-authenticated quotes. The first valid response appears immediately; a better net output replaces it automatically. There is no solver registry or preferred routing venue.

permissionless settlement boundary

The proof binds the selected solver contract and exact amounts. The pool gives that contract only the proved sell amount during a settlement call. The solver owns its router calls and approvals and must return the proved gross buy amount before the callback ends. The pool stores no adapter or router address. Failed checks revert the complete call tree.

token and hostile-code policy

Direct deposits require governance-enabled assets. Trades can receive any deployed token that is not blocked. Reentrancy locks, bounded return data, measured balance deltas, code-change checks, and per-asset accounting defend pool custody, but no protocol can make malicious, upgradeable, frozen, rebasing, or economically worthless token code safe.

fees and fee-on-transfer assets

The immutable fee is 50 basis points on each action's output: the private deposit note, private trade buy note, or public withdrawal payment. A taxed deposit uses the pool's actual measured receipt. A taxed withdrawal can deliver less to the wallet because the token itself taxes the outgoing transfer; the protocol accounts for its own balance decrease atomically.

fees

0.5% on each action’s output. Depositing, trading, and withdrawing each incur a protocol fee. The fee is fixed in the current pool design.

  1. Starting value$1,000.00
  2. After deposit$995.00
  3. After one trade≈ $990.03
  4. After withdrawal≈ $985.07

About 1.49% across the full cycle, assuming unchanged asset prices. This illustration excludes network costs, solver economics, slippage, and token transfer taxes. Actual fees round down in the asset’s smallest unit.

addresses

only trust addresses published here. verify on the explorer before interacting.

contractaddressrole
OpenOcean Router0x6352a56caadC4F1E25CD6c75970Fa768A3304e64 ↗external venue used by one reference solver, not a protocol dependency
WETH0x0Bd7D308f8E1639FAb988df18A8011f41EAcAD73 ↗deposit asset
USDG0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168 ↗deposit asset