EIP-7605 · ZK-UTXO · Groth16

Private tokens on any EVM chain

Balances and transfers hidden behind zero-knowledge proofs. Only commitments and nullifiers ever touch the chain.

How it works

01
Deposit ETH

Send ETH to the private pool. A ZK note is minted to your local key — nothing about your balance is published on-chain.

02
Swap privately

A single transaction atomically proves note ownership and swaps into PRIV tokens. The prover runs fully in your browser.

03
Redeem anytime

Reveal your note preimage to redeem the underlying ETH directly from the contract. No custodian, no bridge, no account model.

No trust required

Frontend on IPFS
Proofs run in your browser
Escape hatch without the UI
Exportable notes
Ownerless contracts
Open source

Properties

No account model

Funds live in UTXO notes, not addresses. There is no on-chain link between sender and receiver.

Shielded AMM

The pool tracks reserves with a Poseidon hash. Prices are public; who swapped and how much is not.

Browser prover

Groth16 proofs are generated locally in WASM. Your private key never leaves your device.

Non-custodial

No relayer, no operator. Contracts are ownerless after setup. Redeem directly from the contract.

Composable

Any ERC20 can be wrapped into a pERC20. Pools can be paired with any note token.

Open spec

Based on EIP-7605. The note schema, circuit constraints, and contract interface are fully documented.

Stack

Circom 2Groth16PoseidonBabyJubJubSolidityFoundrysnarkjsNext.jsethers.jsIPFSENS
pERC20 is a proof of concept. Circuits and contracts are unaudited — do not use with real funds.