Roadmap

The honest current state — what runs today, and what comes next.

One circuit. Six chains, nine networks, three contract stacks — Anchor on Solana, Solidity, and Rust/WASM on Stylus. Two of those networks are mainnets.

Shipped — Solana mainnet

  • Shielded pool (deposit + withdraw), Groth16 / BN254, per-nullifier double-spend guard
  • Immutable verifier — OtterSec-verified, upgrade authority renounced (can never change)
  • Unlinkable withdraw via reference relayer; 1% fee, the sender pays it in their own tokens
  • Post-quantum encryption everywhere (ML-KEM-768) — every memo, envelope and address
  • Stealth payments — the recipient scans the chain with their own secret, nothing handed over
  • Encrypted memo addressed to an auditor — auditable by choice, per deposit
  • Hidden amounts — USDC and USDT (Token-2022 Confidential Transfers): the chain hides the number too
  • Client-side proof in the browser (~2 s, secret never leaves the tab); X25519 view-tags for fast scans
  • Public trusted-setup ceremony at ceremony.tidex6.com — open contributions, publicly verifiable transcript
  • Reproducible build + live /verify — confirm the browser code is the open source
  • Per-deposit revoke / refund — reclaim a deposit the recipient never withdraws
  • MCP server — an AI agent paid through it autonomously on mainnet

Shipped — one rail, six chains, nine networks (September 2026)

  • The same circuit, the same envelope, the same reader key on every chain — one proof system, one UX
  • Arc (Circle) — mainnet, 18 September 2026: verifier, registry and both pools deployed unchanged; Arc's BN254 precompiles were checked on the live chain before deploying. First end-to-end payment on mainnet three days later — deposit, proof in the browser, withdrawal, 43 seconds
  • Hidden amounts on EVM — any amount sealed inside the commitment, on six of the seven networks; the recipient withdraws the full amount that was sent
  • Arbitrum Stylus — verifier, Poseidon, pool and registry rewritten in Rust as WASM contracts; live on Robinhood Chain testnet (tokenized stocks) and Arbitrum Sepolia; reproducible builds, cargo stylus verify passes; verify fix sent upstream
  • Solidity — the same contracts on Whitechain Sepolia, Base Sepolia, HyperEVM and Arc
  • EVM relayer — the recipient withdraws without holding gas, and the relayer takes nothing at the exit: the sender already paid the 1% on top, as its own sealed note to the treasury
  • Chain-aware client: pick the chain and network once for the whole site, and a transaction is refused if the wallet is on a different chain than the page
  • USDG (Paxos Global Dollar) — its own pools on Robinhood Chain and Arbitrum Sepolia, chosen with a token button next to the amount; on Solana devnet through our confidential wrapper (wUSDG), full send-and-receive run on 24 September

Shipped — the fee pays the system's own bills

  • The sender pays 1% on top and sees the exact total before signing — the recipient always gets the amount that was typed
  • The fee is collected privately: its own sealed note to the treasury's reader key, indistinguishable on chain from any other payment in the pool
  • A treasury of its own, on the server — not a person's wallet. Robots collect the fee notes on EVM and on Solana, and top up the relayer's gas from the treasury. Every step is public: tidex6.com/treasury
  • On Arc the loop closes with no swap at all — gas there is USDC, the same token the pools move and the fee is charged in
  • On Solana the fee buys its own gas: below a threshold the next fee is swapped to SOL through an aggregator, and the transaction is checked against a whitelist before our key signs it
  • On the remaining EVM chains gas is ETH or HYPE while the fee is USDC — the treasury tops the relayer up from gas it holds; swapping fees into that gas comes with mainnet liquidity. The numbers, including what does not work yet

Now — autumn 2026

  • 1. Public trusted-setup ceremony for the note format v2 circuits at ceremony.tidex6.com — it needs independent contributors: one honest contribution makes the setup safe, so the more people join, the better. Then a fresh immutable verifier everywhere; until that day the pools carry a development key and no real money goes behind them
  • 2. USDG on Solana mainnet — a note format v2 pool for the Paxos dollar, after the ceremony
  • 3. Hidden amounts everywhere, including at the edge — balances encrypted with ElGamal on the Baby Jubjub curve, so the amount stays hidden when money comes in and goes out, not only inside the pool. Live on Arbitrum Sepolia since 2 October; Solana and the other chains next
  • 4. Wallet screening — money from sanctioned wallets does not enter a pool: the deposit and the payout address are checked against a sanctions list. Only the address is checked, no identity. It is what escrow needs — both sides of a deal know the money is clean
  • 5. Businesses: private contracts and escrow — private payments between corporate wallets, and agreements with obligations: funds locked under the terms of a deal and released by an arbiter, visible only to the parties

Next

  • Amount and fee in one transaction — one pool call that takes both notes, instead of the three wallet prompts a hidden-amount payment needs today
  • Regulated / multi-auditor pools — a pool-level viewing key for a regulator: sees every transaction, cannot freeze or stop anything
  • Real money on the mainnets — the contracts are deployed and verifiable, the switch is the ceremony, not the code
  • Proof of Innocence / association sets — prove funds are clean without revealing who you are
  • Time-scoped auditor keys — grant a viewing key for one period (e.g. one tax year), not forever
  • Relayer hardening — HSM keypair, cold multisig, federated discovery across independent relayers
  • Timing defences — random timelock so deposit↔withdraw timing can't be correlated
  • Revoke in the UI — the on-chain refund exists; add the button

Later — 2027 and beyond

  • Shared anonymity pool — one crowd across every integrating app, stronger privacy for all
  • Post-quantum spender signature (Falcon) — research spike
  • Persistent browser prover — cache the proving key across calls for even faster proofs