Threat scenarios
Public ciphertext boundary
The pool emits a fixed-size encrypted recovery payload with each supported deposit. Everyone can copy that ciphertext and correlate it with the public deposit. Decryption still requires the matching wallet-derived key or bearer recovery root. The browser binds authenticated decryption to chain, pool, runtime, template-set hash, and bundle commitment. A wrong source, context, key, payload hash, or reconstructed commitment fails closed.Optional bearer-backup storage
If you export a bearer backup, keep at least one offline encrypted copy and use this small, deliberate backup set:- Wait for Deposit successful and Confirmed, then open Save recovery note.
- Store the exported copy outside the active browser profile.
- Record a human label for purpose and network beside the file, never by editing serialized bytes.
- Prevent cloud photo, clipboard, source-control, telemetry, and chat systems from ingesting it.
- Check that you can read the stored copy without publishing it or importing it into another site.
Multiple copies improve availability but increase disclosure surface. Keep the minimum number needed for recovery, with independent access controls.
Import validation
The client must stop before balance recovery if any of these checks fail:- Prefix, Base58 body, checksum, byte length, or strict JSON schema
- Format version supported by the selected importer
- Chain ID and pool identity
- Commitment recomputed from secret material
- Wallet unlock requirement when the recovery format uses one
- Duplicate, malformed, spent, or unsupported note state
Recovery availability
Wallet recovery remains available only while the wallet can return the same canonical signature bytes for the bound request. EIP-712 defines the signed message, while wallet implementations control signature production. A different valid signature can derive a different key. The bearer note preserves recovery when wallet software, account access, or signature reproducibility changes. If no bearer copy exists, loss of the usable wallet-derived path permanently loses the secret.Suspected disclosure
- Stop copying, pasting, uploading, or testing the exposed value.
- From a trusted environment, verify its chain, pool, commitment, and unspent state.
- If spendable, prepare a withdrawal to a new self-custody destination.
- Recheck recipient, gross amount, fee, proof-bound context, and submission route.
- Confirm the expected pool event and recorded nullifier.
- Preserve only public incident evidence; remove unnecessary secret copies.

