Public on MegaETH
Commitments and nullifiers are public protocol identifiers. They keep note secrets hidden while exposing their presence and timing.
Secret in the client
The trusted client handles material that must not enter logs, analytics, support channels, public issues, or arbitrary wallet prompts:- Note secret and blinding material
- Recovery note or strict JSON recovery kit
- Decrypted local note records
- Merkle path and private proof witness
- Wallet unlock authorization used for bound recovery flows
- Intermediate values used to derive commitments and nullifiers
Fixed denominations
Fixed denominations constrain supported note shapes and make accounting predictable. They can also make amount classes easier to compare. Public details still include:- Deposit and withdrawal occurrence
- Public destination and gross amount
- Timing and wallet activity
- Possible links between transactions
- MEV exposure and chain-level visibility
What the submitter changes
Relayer submission changes who pays gas and which account appears as submitter. Destination, amount, fee, nullifier, proof, and pool transaction remain public. Connected-wallet submission additionally exposes the user’s submitting account onchain. Fast MegaETH block and receipt updates improve freshness while preserving the same public transaction fields.Current privacy scope
Current privacy coverage keeps witness and recovery secrets inside the trusted client. Anonymity, unlinkability, sender privacy, receiver privacy, amount privacy, MEV protection, and chain-level transaction privacy remain outside that scope. A future claim would need to state:- The exact property and adversary
- The circuit, contracts, runtime, frontend, and operational assumptions
- The evidence connecting source, proving relation, verifier, and deployment
- Known leakage through amounts, timing, destinations, submitters, and user behavior