Skip to content

Secret Notes ​

The note is the spending credential. The on-chain commitment is not. This page is about the note string, the sealed copy, and the difference between them.

The string ​

text
vx2-<amount in hex>-<spending key in hex>-<blinding in hex>

Token notes append -<mint>. SOL notes do not.

Example shape, with the secrets shortened:

text
vx2-16345785d8a0000-a1b2…-c3d4…

That first hex field is the amount in base units. Treat the whole string as cash. There is no identity check on top of it. There is no recovery phrase inside the protocol if every copy is gone and no sealed output was written.

Legacy notes from the fixed-denomination pools use a different prefix. They do not parse as vx2 notes, and the current program cannot spend them.

What is inside ​

From the string a client recomputes:

  • the spending public key, Poseidon(privateKey)
  • the commitment, Poseidon(amount, publicKey, blinding, mint)
  • after the leaf index is known, the nullifier

The string does not contain the leaf index. The index comes from the tree, by looking up the commitment.

The sealed copy ​

A second copy can sit on-chain as ciphertext next to the commitment. Sealing uses a secret-box over the amount, spending key, and blinding. The key is derived by signing veilix:notes:v1 with the wallet and hashing that signature.

Properties of that seal:

  • It is optional on a deposit. Turn it on when the same wallet should be able to scan later.
  • Change notes are sealed when that key is already loaded at withdrawal time.
  • The ciphertext does not identify the wallet. Opening it requires the signature.
  • A scan decrypts locally and checks that the opened note matches the commitment. A random blob that fails the box, or a note that does not match the leaf, is discarded.

There is also a per-wallet notes account (notes_v2) that can store additional sealed entries written by the wallet. The scan used to rebuild a balance reads the encrypted outputs on the tree leaves. Keep a note string as well if you need a backup that does not depend on that wallet being able to sign.

Display ​

Interfaces should truncate the middle of each segment when showing a note, and they should avoid putting the full string in logs, analytics, or support tickets. A pasted note in a chat is a spent note waiting to happen.