Skip to content

Veilix Protocol ​

A non-custodial privacy protocol on Solana. You deposit tokens into a shared pool, keep a secret note, and later withdraw some or all of that note to a different address. A zero-knowledge proof authorizes the withdrawal without revealing which note is being spent. A relayer submits the withdrawal, so the recipient address is not the transaction signer.

Private. Non-custodial. Any amount.

This book explains how the Veilix protocol works: deposits, notes, withdrawals, fees, and relayers. It is the public description of the protocol.


What changed from the fixed-denomination design ​

Earlier pools only accepted a menu of fixed sizes. Veilix does not. Each asset has one shielded tree, and a note can hold any amount up to that tree’s deposit cap.

Earlier fixed poolsVeilix now
AmountChosen from a denomination listAny positive amount, up to the tree cap
PoolOne tree per denominationOne tree per asset
SpendThe whole noteThe whole note, or part of it
RemainderNoneA new change note
Note formatLegacy notesvx2-… notes
Withdrawal feeA single relayer percentRelayer fee plus an on-chain platform fee

Legacy fixed-denomination notes cannot be spent on the current program.


The idea in one pass ​

  1. Deposit. Address A sends SOL or a supported token into the pool and receives a secret note. The chain stores a commitment, not the secret.
  2. Hold. The note sits in the same tree as every other note of that asset. You can leave it there for as long as you want.
  3. Prove. Your device builds a zk-SNARK that says “I know the secret behind one unspent note in this tree,” without saying which note.
  4. Withdraw. A relayer submits that proof. The program checks it, marks the note spent, pays the recipient, and — if you withdrew only part of the note — inserts a change note for the rest.

The deposit signer and the withdrawal recipient are different addresses, and the proof does not connect them.


One program, one tree per asset ​

Deposits, partial withdrawals, and Private Send all use the same program and the same asset trees. An observer cannot tell, from the program alone, whether a note was created to sit in a wallet or to pay someone.

Supported assets:

AssetDecimalsWhere
SOL9Mainnet and devnet
VEILIX9Mainnet and devnet
USDC6Mainnet and devnet
wBTC8Mainnet
wETH8Mainnet

Each asset has its own treasury and its own Merkle tree. SOL notes never mix with USDC notes. Inside one asset, every note shares one anonymity set.


Where to start ​

I want to…Start here
Understand why public transfers leakThe Privacy Problem
See how Veilix breaks the linkVeilix’s Approach
Follow a deposit and a withdrawalDeposit and Withdrawal
Understand amounts, change, and feesAmounts and Fees
See what is still publicWhat Each Party Can See
Send privately from an appPrivate Send
Protect a noteNote Security