HOODED documentation
HOODED is a zero-knowledge shielded pool for private transfers on Robinhood Chain. Experimental
What is HOODED
HOODED lets you deposit into a shared on-chain pool and later withdraw to any address, breaking the public link between the deposit and the withdrawal. It is a faithful port of the Privacy Cash protocol (Tornado-Nova UTXO lineage).
How it works
- Notes (UTXOs). A deposit creates a secret note — an amount owned by a key derived from your wallet signature. Notes live as commitments in the pool.
- Merkle tree. Every commitment is a leaf in an incremental Merkle tree. Your browser rebuilds the tree from on-chain events to prove a note exists.
- Zero-knowledge proofs. To withdraw, your browser builds a Groth16 proof that you own an unspent note and that value is conserved — without revealing which note.
- Nullifiers. Spending a note publishes a nullifier so it can't be spent twice, without linking back to the deposit.
- Relayer. An optional relayer submits your withdrawal so the recipient needs no gas and your address stays hidden (a small fee applies).
Privacy model
Read this before using HOODED. We state the limits plainly.
- HOODED hides which deposit funds a withdrawal. That is the core privacy guarantee.
- It does NOT hide amounts, timing, or asset. Deposits and withdrawals are public transactions; only the link between them is broken.
- Self-relay reveals your address. If you submit your own withdrawal (self-relay), the transaction comes from your wallet and exposes your address. Use the relayer to avoid this.
- The relayer sees your IP and timing. Using the relayer hides your address on-chain, but the relayer service receives your network request and can observe your IP, the timing, the amount and the recipient it submits for you. Self-relay avoids trusting any relayer — at the cost of revealing your address on-chain. Neither mode is fully private; see Privacy tips.
- This is shielded privacy, not anonymity. Correlating amounts and timing can still de-anonymize careless usage — see Privacy tips.
- Not yet audited. An independent audit is on the roadmap. Until then, treat HOODED as experimental and use amounts you can afford to lose.
User guide
1. Connect
Connect a supported wallet (see Wallet compatibility). HOODED requires Robinhood Chain (chainId 4663); if your wallet is on another network the app blocks signing and offers a one-tap switch. HOODED never signs or sends on the wrong network.
2. Deposit
Enter an amount and deposit. Your browser builds a proof and creates a private note. The note (with its secret blinding factor) is stored in your browser.
3. Send (withdraw)
Enter a recipient (any address) and an amount, then choose a mode:
| Mode | Who submits & pays gas | Fee | Address exposure |
|---|---|---|---|
| Relay | The relayer (recipient needs no gas) | 0.3% of the amount, netted from your note | Your address stays hidden |
| Self-relay | You (you pay gas) | None | Reveals your address |
Fees & the Max button
Relayed sends cost 0.3% (30 bps), shown inline as you type. A single note must cover amount + fee (note consolidation is a future feature), so the Max button fills the largest value your biggest note can send: for relay that is the note minus the fee; for self-relay it is the whole note. Amounts above that are blocked with a clear message before you submit.
Privacy tips
- Withdraw to a fresh wallet you don't reuse or link to your identity.
- Avoid unique amounts. Withdrawing an oddly specific amount that matches a deposit is easy to correlate. Prefer round amounts.
- Add time between deposit and withdrawal. Immediate withdrawals are the easiest to link.
- Prefer relay — the recipient needs no gas and your address is never exposed.
- Space out activity. Batching several deposits/withdrawals at once, or reusing the same amounts, leaks patterns.
- Don't withdraw the full deposit immediately to one address — it recreates the link you were trying to break.
Wallet compatibility
HOODED derives your private shielded key from a wallet signature, and the wallet must be on Robinhood Chain.
| Wallet | Message signing (key derivation) | Status |
|---|---|---|
| MetaMask | ✓ personal_sign | Supported |
| OKX Wallet | ✓ personal_sign | Supported — verified on mainnet |
| Trust Wallet | ✗ raw message signing on this chain; typed-data fallback attempted | Not yet usable — use MetaMask or OKX |
personal_sign vs EIP-712 typed data) produce different keys. Use a single wallet consistently. Don't move a shielded balance between wallets that sign differently — the notes derived under the other method won't be visible (funds aren't lost; reconnect the original wallet to see them).Security & ceremony
Groth16 proofs are only as sound as the proving key they were built with. HOODED replaced its insecure development key with a production key from a multi-party Phase-2 trusted-setup ceremony (deterministic init → two independent contributors → a public, pre-committed drand beacon). The dev key was retired everywhere.
The full transcript, artifacts and re-verification commands are public: gitlab.com/Brouie/hoodedcash (release ceremony-v1). Anyone can reproduce the chain:
sha256sum transaction2_prod.zkey # ea2c3dcf…5905 npx snarkjs zkey verify transaction2.r1cs powersOfTau28_hez_final_17.ptau transaction2_prod.zkey # expect: #1 Tokensuit, #2 vlad, #3 final public beacon, "ZKey Ok!" curl https://api.drand.sh/52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971/public/30529000 # expect randomness f6013b22…f11a
Deployed contracts (chainId 4663): HoodedPool 0x04D06eD0…56D29, TransactionVerifier 0xa384b4EE…77221 — both verified on the block explorer.
Audit status & roadmap
HOODED has not yet been independently audited. An independent security audit is planned on the roadmap. Until it is completed, the strongest assurance available is transparency: the trusted-setup ceremony above gives verifiable, reproducible provenance, and all contracts, circuits and artifacts are public for review.
FAQ
Is HOODED audited?
Not yet. HOODED has not been independently audited; an audit is part of the roadmap. Until then, treat it as experimental and use amounts you can afford to lose.
What are the fees?
0.3% (30 bps) on relayed sends, netted from your note. Self-relay has no protocol fee — you pay network gas instead.
Can I use Trust Wallet?
Not yet — Trust Wallet can't sign the messages HOODED needs on this chain. Use MetaMask or OKX.
Where are my funds / notes stored?
Your notes live in your browser's local storage, secured by a key derived from your wallet signature. Clearing site data or switching devices can make notes unrecoverable — so use Settings → Export notes to save an encrypted backup (only the same wallet can decrypt it) and Import notes to restore it. Automatic note recovery from the wallet alone is on the roadmap.
Does HOODED make me anonymous?
No. It hides the deposit↔withdrawal link. Amounts, timing and asset are public, and self-relay reveals your address. See the Privacy model.
Which network?
Robinhood Chain mainnet (chainId 4663). The app blocks signing/sending on any other network.
Terms of Use
By accessing or using the HOODED web interface (the "Interface") you agree to these Terms.
1. Eligibility
You must be of legal age and legally permitted to use the Interface in your jurisdiction. You may not use the Interface if you are located in, or a resident of, any jurisdiction where doing so would be unlawful, or if you are subject to applicable sanctions.
2. Non-custodial, self-service software
The Interface is a non-custodial tool that helps you interact with public smart contracts. It never takes custody of your assets or keys. You are solely responsible for your wallet, keys, note data, and every transaction you authorize.
3. Prohibited use
You agree not to use the Interface for any unlawful purpose, including money laundering, terrorist financing, evading sanctions, or handling proceeds of crime, or in violation of any applicable law or regulation.
4. Unaudited software; no warranty
The Interface and the underlying protocol are experimental and unaudited, and are provided "AS IS" and "AS AVAILABLE" without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. No guarantee is made as to availability, security, or correctness.
5. Assumption of risk
You understand and accept the risks of blockchain systems and experimental cryptography, including smart-contract vulnerabilities, key/note loss, transaction irreversibility, network failures, and total loss of funds. You use the Interface at your own risk.
6. Limitation of liability
To the maximum extent permitted by law, the contributors to HOODED shall not be liable for any indirect, incidental, special, consequential, or exemplary damages, or any loss of funds, profits, or data, arising from your use of or inability to use the Interface.
7. Changes
These Terms may be updated. Continued use after changes constitutes acceptance.