Appearance
What Each Party Can See
Veilix hides the link between a deposit and a later withdrawal. It does not hide the deposit, and it does not hide the withdrawal. This table is the practical version of that sentence.
On a deposit
| Fact | Depositor | Everyone else |
|---|---|---|
| Depositor address | Yes | Yes. They signed. |
| Asset and amount that entered the treasury | Yes | Yes |
| New commitment | Yes | Yes |
| Spending key, blinding, note string | Yes | No, unless the note was copied or the ciphertext was opened |
| Encrypted output | Ciphertext they can open, if they sealed it | Ciphertext only |
A deposit is a public payment into the treasury plus a new leaf. The privacy starts after that leaf exists, when later spends do not point back at it.
On a withdrawal
| Fact | Sender of the note | Relayer | Recipient | Everyone else |
|---|---|---|---|---|
| Which note was spent | Yes | No | No | No |
| Nullifiers | Yes | Yes | Yes, on-chain | Yes |
| Amount leaving the pool | Yes | Yes | Yes | Yes |
| Fee and relayer account | Yes | Yes | Yes | Yes |
| Recipient address | Yes | Yes | Yes | Yes |
| Change commitment | Yes | The commitment only | No | The commitment only |
| Change note secret | Yes, if they saved it or can decrypt | No | No | No |
| That the recipient signed | No | No | No | No. The relayer signed. |
The recipient learns that they were paid a certain amount of a certain asset. They do not learn which deposit funded it, and they do not receive a note.
The indexer and the relayer
Both see the public proof payload, because they have to transport it. They do not receive the note string on the withdrawal path. They cannot match a nullifier to a commitment any better than any other observer.
The indexer also stores every leaf, including ciphertext. Holding the leaves does not reveal who owns them.
What still correlates
Cryptography removes the explicit pointer. It does not remove side channels:
- Amount. A withdrawal of an unusual size shortly after a deposit of that size is suggestive. Partial withdrawals and change notes exist so the public amount does not have to copy the deposit.
- Time. A deposit and a withdrawal in the same quiet minute are easier to pair than the same pair separated by many other notes.
- Asset. Trees are separate. A wBTC withdrawal can only come from the wBTC tree, which may be a smaller set than SOL.
- Behavior. Using the same recipient, the same relayer, and the same time of day across many payments builds a pattern outside the proof.
- The note itself. Anyone you show the note string to can spend it and can see its amount.
Shielded balance
No account on-chain sums “this wallet’s Veilix balance.” That sum exists only where the notes can be opened: in the user’s saved notes, or in a scan of ciphertexts with the wallet encryption key. An observer can sum the treasury. They cannot assign slices of it to wallets.