Successor to DarkSwap · ZKDARK
Go dark with a proof.
ZK Darkpool continues the zero-knowledge pools DarkSwap built. A public deposit becomes an encrypted note. You spend it with a proof made on your own device. The pool never holds your key.
The shielded pools are a local-chain build with development proving keys. ZKDARK is the separate Solana token: swap it on PumpSwap and check the chart on DexScreener.
From DarkSwap
The ZK tier, continued as its own protocol.
DarkSwap is a privacy terminal. Its live product prepares Solana-origin swaps on NEAR Intents and leaves the deposit to your wallet. Separately, DarkSwap wrote its own shielded pools and documented them as a later tier: one circuit, a Solana program, and a contract for Ethereum and Base.
ZK Darkpool is that tier. It does not replace the NEAR route, and it is not the dark pool on NEAR Confidential Intents. Those systems do not pass funds to each other. DarkSwap remains the place for the live swap. This site is the pool.
What a note does
Shield, send in private, then withdraw.
Balances are encrypted notes, in the same family of designs as Zcash. Each note commits to an amount, an asset, an owner key, and a blinding value. Spending it publishes a nullifier, which marks it spent without naming the note.
-
01
Shield
A public deposit creates a note. The amount and the wallet that paid stay visible, so deposits from one wallet can be tied to that wallet. Each deposit uses a fresh one-time key. That stops the notes being linked to each other by key. It does not hide who funded them. In tests, the protocol fee applies here.
-
02
Private send
Spend up to two notes and create two, for one asset. The proof is built on your device. On a 2-core machine in tests, proving took about 2 to 5 seconds. A private send hides the amount, the asset, and the sender. There is no protocol fee on this step. A relayer can submit it inside a rate limit.
-
03
Unshield
A withdrawal to a public address. The relayer can submit it so the destination wallet does not need gas. Its fee comes out of the withdrawal and is separate from the protocol fee. If the relayer is down, or the token has no price it will accept, you submit the withdrawal yourself. That transaction pays gas and names you as the sender.
There is no swap inside the pool yet. Each transaction moves one asset. A note denominated in one asset cannot pay out another.
What stays public
The middle is hidden. The edges are not.
Someone watching the chain can see that a wallet deposited an amount, and that some address later withdrew an amount. The pool is there to make those two events harder to connect. It does not make activity invisible.
Amount and timing
An unusual withdrawal soon after a matching deposit can still be linked. Common amounts, and waiting, hide more.
Small pools
A pool only hides you in the set of notes already there. A small pool is a small crowd.
Your network
The site, the relayer, and the RPC the page reads can see your IP and when you connect. A proof does not hide that.
Your own habits
Reusing a labelled withdrawal address, or posting the details, undoes privacy the proof cannot restore.
Architecture
Two deployments, one circuit.
The same circom circuit proves both pools. Proofs use Groth16 on BN254. Commitments, nullifiers, and the note tree use Poseidon. On Solana the pool is a native program. On Ethereum and Base it is one contract.
Solana
SOL and listed SPL tokens on the original Token program. Token-2022 is not accepted, so a Token-2022 asset cannot be shielded in the pool as built. A spend uses about 161,000 to 172,000 compute units in local measurements.
Ethereum and Base
ETH and listed ERC-20 tokens. A shield is about 1.16 to 1.22 million gas in local measurements. A private send is about 1.32 million, and an unshield about 1.38 million. The contract has no upgrade path.
Public networks
The terminal preview DarkSwap showed was a local-development preview. Public testnets, a setup ceremony, and an independent audit come before user funds. No date is set.
| Layer | What it does | Status |
|---|---|---|
| DarkSwap terminal | Live private swaps from Solana through NEAR Intents. You review the quote and send the deposit yourself. | Live, separate product |
| NEAR confidential balances | A hidden balance on NEAR’s private shard. Encryption and permissioned validators, not a proof on your device. | DarkSwap target, not this pool |
| ZK Darkpool | Shielded note pools. Proofs on your device. Funds sit in the pool contract or program, spendable only with the note key. | Built on local chains |
Before any user funds
The gates do not move with the calendar.
DarkSwap’s own write-up holds the pools back until each of these is done, in order. ZK Darkpool inherits that order. A target date would not replace it.
-
01
Public testnets
The pools run end to end on local chains with real proofs. A public testnet is the next place other people can try the client without mainnet funds.
-
02
Circuit decisions, then the fee recipient
Two circuit changes have to be settled before a ceremony. The fee recipient is fixed at deployment, so the contracts that receive fees have to exist, and be reviewed, before the pools are deployed.
-
03
Setup ceremony
Groth16 needs a ceremony. Today’s proving keys were made for development. Whoever produced them could forge proofs. Outside contributors have to replace those keys before real value is at stake.
-
04
Independent audit, then capped mainnet
Internal reviews are not an audit. An independent audit has to finish, and its findings have to be resolved, before mainnet. The first public deployment is meant to open with deposit caps.
Solana token
ZKDARK trades on Solana.
ZKDARK is the Solana token for ZK Darkpool. Swap it on PumpSwap. The Solana chart is on DexScreener. It is separate from DarkSwap’s $DARK token, and holding it does not pay pool fees or create a yield.
Market Solana · PumpSwap
Mint
What this site will not imply
No live anonymity set. No audited mainnet. No custody of your key. No holder payout. No buyback. Holding a ticker does not create a claim on pool fees. Privacy from the public is not privacy from a lawful request.
Who you trust on this tier
Inside the pool, a proof — not an operator — authorizes a spend. You still trust the ceremony, the client you load, the relayer if you use it, and, on Solana, the upgrade authority until it sits behind a delay or is removed.