Private trading (stage 2).
Status: we have built and tested the building blocks of private trading, with development proving keys, on a local test chain only. None of it is deployed or usable yet. A trusted-setup ceremony and a security audit are still pending. Everything on this page describes work in progress and how it is designed to work, not a running product.
What you can use today is unchanged: the shielded pool for moving BNB, and dark pools (stage 1), which hide the wallet behind a trade but not its amount, coin or timing.
Where it stands
- Not deployed. No stage-2 contract exists on BNB Chain or on its testnet. There are no addresses to publish.
- Development keys. The proving keys come from a single local setup by the operator. They are for testing and will never be deployed.
- No trusted-setup ceremony yet. The procedure is written; the ceremony has not run.
- No audit. Two internal review passes have been done: one of the circuits and contracts, one of the app, relayer and keeper code. Each fixed what it could and left some findings open for decisions. Neither is an audit.
- Nothing to use. The app screens, the relayer and the Epoch Coordinator software are written, but none of it runs anywhere you can reach. The app screens stay hidden until a deployment exists, and they have not yet been tried in a browser.
What has been built and tested
All of the following was tested with development keys, against mocks and a local test chain, never against the live contracts.
- Circuits. Four zero-knowledge circuits exist and pass their tests with real proofs: multi-asset notes (BNB and coins in one shielded pool), trade intents with a hidden amount, claims that are not linked to the trade they come from, and the proof that opens a batch by revealing only its total.
- Contracts. The contracts exist and pass their tests against mocks and the development verifiers: a multi-asset shielded pool, batch auctions per coin and direction that trade against the live curve as a single account (so fees, the pair tax and the $ZKBNB buyback are unchanged), and private planting of new coins.
- Software around them. The relayer, the Epoch Coordinator, the pool feed that wallets sync from, and the wallet code in the app exist and pass their unit tests. One scripted run on a local test chain took two test wallets through shielding, a batched private buy, its opening, a claim, a private sell, an unshield and a Coordinator key rotation. That was a local test, not a deployment.
How it is designed to work
This is the design, not a running product. Your buy or sell joins a batch for that coin and direction. The chain sees the batch total, not your share of it. A relayer submits your intent, so your wallet is not on the transaction. When you claim your result later, the claim does not reveal which coin, batch, direction or amount it came from.
What it will not hide
- Shields and unshields: the wallet, amount and time of every shield, and the recipient, size, time and relayer of every unshield. Standard sizes only soften this.
- Batch totals and the number of intents, per coin and direction. A batch with one participant on a side publishes that participant's amount exactly, so amounts are only hidden among other honest traders in the same batch, and quiet coins hide little.
- Timing: the time of every transaction, and the ten-minute window each proof was made in.
- Relayer addresses. The relayer you use sees your IP address, timing and the public inputs; the web host sees request logs.
- Coin creation, and the pool's total holdings of each coin.
- Which coin an in-pool coin transfer moves (not its amount, sender or recipient).
- Amounts that are credited in the open, such as creator-fee payouts, harvests paid from a public wallet and moves from the current shielded pool.
Trust in stage 2
Batches are opened by an Epoch Coordinator that zkBNB runs. It holds a key that could decrypt the amount of each private intent and link private trades by the same person. Its software only decrypts batch totals and the key is meant to rotate daily, but that is a promise about our software, not something the chain enforces. The encrypted amounts stay on the chain for good, so anyone who ever obtained one of those keys could read every intent sent under it. So stage 2 does not make amounts private from zkBNB itself. Replacing that single key with a threshold committee is planned for stage 3, which is design only today.
Still to do before anyone can use it
- A trusted-setup ceremony for the four circuits, and verifiers exported from its keys.
- An external security audit, and fixes for the open review findings.
- Tests against the live contracts, a testnet deployment, then a mainnet deployment.
- Running the relayer and the Epoch Coordinator on separate machines, and trying the app screens in a browser.
Until all of that is done, treat this page as a progress report. We will update it, and the trust model, when something changes.