Successor to DarkSwap · ZKDARK

Go dark with a proof.

ZK Darkpool continues the zero-knowledge pools DarkSwap built. A public deposit becomes an encrypted note. You spend it with a proof made on your own device. The pool never holds your key.

The shielded pools are a local-chain build with development proving keys. ZKDARK is the separate Solana token: swap it on PumpSwap and check the chart on DexScreener.

The ZK Darkpool mark inside a corridor of violet light, standing on a reflective floor.
One circuit. Solana, Ethereum, and Base.
Chains Solana, Ethereum, Base
Proofs Groth16 on BN254, in the browser
Notes Poseidon commitments, tree depth 26
Fee in tests 0.5% shield and unshield, cap 1%

From DarkSwap

The ZK tier, continued as its own protocol.

DarkSwap is a privacy terminal. Its live product prepares Solana-origin swaps on NEAR Intents and leaves the deposit to your wallet. Separately, DarkSwap wrote its own shielded pools and documented them as a later tier: one circuit, a Solana program, and a contract for Ethereum and Base.

ZK Darkpool is that tier. It does not replace the NEAR route, and it is not the dark pool on NEAR Confidential Intents. Those systems do not pass funds to each other. DarkSwap remains the place for the live swap. This site is the pool.

ZK Darkpool wordmark beneath the glowing mark, framed by a violet ring and dark folded metal.

What a note does

Shield, send in private, then withdraw.

Balances are encrypted notes, in the same family of designs as Zcash. Each note commits to an amount, an asset, an owner key, and a blinding value. Spending it publishes a nullifier, which marks it spent without naming the note.

  1. 01

    Shield

    A public deposit creates a note. The amount and the wallet that paid stay visible, so deposits from one wallet can be tied to that wallet. Each deposit uses a fresh one-time key. That stops the notes being linked to each other by key. It does not hide who funded them. In tests, the protocol fee applies here.

  2. 02

    Private send

    Spend up to two notes and create two, for one asset. The proof is built on your device. On a 2-core machine in tests, proving took about 2 to 5 seconds. A private send hides the amount, the asset, and the sender. There is no protocol fee on this step. A relayer can submit it inside a rate limit.

  3. 03

    Unshield

    A withdrawal to a public address. The relayer can submit it so the destination wallet does not need gas. Its fee comes out of the withdrawal and is separate from the protocol fee. If the relayer is down, or the token has no price it will accept, you submit the withdrawal yourself. That transaction pays gas and names you as the sender.

There is no swap inside the pool yet. Each transaction moves one asset. A note denominated in one asset cannot pay out another.

What stays public

The middle is hidden. The edges are not.

Someone watching the chain can see that a wallet deposited an amount, and that some address later withdrew an amount. The pool is there to make those two events harder to connect. It does not make activity invisible.

Amount and timing

An unusual withdrawal soon after a matching deposit can still be linked. Common amounts, and waiting, hide more.

Small pools

A pool only hides you in the set of notes already there. A small pool is a small crowd.

Your network

The site, the relayer, and the RPC the page reads can see your IP and when you connect. A proof does not hide that.

Your own habits

Reusing a labelled withdrawal address, or posting the details, undoes privacy the proof cannot restore.

The ZK Darkpool mark hovering over a dark pool, with violet ripples and thin traces of light.
Encrypted notes. Public deposits and withdrawals.

Architecture

Two deployments, one circuit.

The same circom circuit proves both pools. Proofs use Groth16 on BN254. Commitments, nullifiers, and the note tree use Poseidon. On Solana the pool is a native program. On Ethereum and Base it is one contract.

Built · local

SOL and listed SPL tokens on the original Token program. Token-2022 is not accepted, so a Token-2022 asset cannot be shielded in the pool as built. A spend uses about 161,000 to 172,000 compute units in local measurements.

Built · local

ETH and listed ERC-20 tokens. A shield is about 1.16 to 1.22 million gas in local measurements. A private send is about 1.32 million, and an unshield about 1.38 million. The contract has no upgrade path.

Held back

Public networks

The terminal preview DarkSwap showed was a local-development preview. Public testnets, a setup ceremony, and an independent audit come before user funds. No date is set.

Layer What it does Status
DarkSwap terminal Live private swaps from Solana through NEAR Intents. You review the quote and send the deposit yourself. Live, separate product
NEAR confidential balances A hidden balance on NEAR’s private shard. Encryption and permissioned validators, not a proof on your device. DarkSwap target, not this pool
ZK Darkpool Shielded note pools. Proofs on your device. Funds sit in the pool contract or program, spendable only with the note key. Built on local chains

Before any user funds

The gates do not move with the calendar.

DarkSwap’s own write-up holds the pools back until each of these is done, in order. ZK Darkpool inherits that order. A target date would not replace it.

A dark mountain range traced by violet network lines, with the ZK Darkpool mark rising from a peak.
Public deployment is a sequence of gates, not a switch.
  1. 01

    Public testnets

    The pools run end to end on local chains with real proofs. A public testnet is the next place other people can try the client without mainnet funds.

  2. 02

    Circuit decisions, then the fee recipient

    Two circuit changes have to be settled before a ceremony. The fee recipient is fixed at deployment, so the contracts that receive fees have to exist, and be reviewed, before the pools are deployed.

  3. 03

    Setup ceremony

    Groth16 needs a ceremony. Today’s proving keys were made for development. Whoever produced them could forge proofs. Outside contributors have to replace those keys before real value is at stake.

  4. 04

    Independent audit, then capped mainnet

    Internal reviews are not an audit. An independent audit has to finish, and its findings have to be resolved, before mainnet. The first public deployment is meant to open with deposit caps.

Solana token

ZKDARK trades on Solana.

ZKDARK is the Solana token for ZK Darkpool. Swap it on PumpSwap. The Solana chart is on DexScreener. It is separate from DarkSwap’s $DARK token, and holding it does not pay pool fees or create a yield.

Market Solana · PumpSwap

Not claimed

What this site will not imply

No live anonymity set. No audited mainnet. No custody of your key. No holder payout. No buyback. Holding a ticker does not create a claim on pool fees. Privacy from the public is not privacy from a lawful request.

Proposed

Inside the pool, a proof — not an operator — authorizes a spend. You still trust the ceremony, the client you load, the relayer if you use it, and, on Solana, the upgrade authority until it sits behind a delay or is removed.