Bitmap Privacy Chain
04 / SECURITY

Trust, made explicit.

Privacy is only credible when cryptographic assumptions, validator power, bridge custody, metadata leakage and emergency authority are documented as separate risks.

THREAT MODEL UNDER EXTERNAL REVIEW

Five independent failure domains.

CRYPTOGRAPHYInvalid proof acceptance

Circuit, verifier, setup or implementation flaws could create or steal shielded value.

CONSENSUSValidator collusion

A Byzantine threshold may censor, halt or reorder transactions even without breaking proofs.

BRIDGEReserve impairment

Key compromise, adapter bugs or external issuer failure can break asset backing.

METADATATraffic correlation

IP, timing, amount boundaries and deposit/withdraw patterns may reduce the anonymity set.

GOVERNANCEPrivileged capture

Upgrade, pause or treasury powers may be abused if thresholds, delays and scope are weak.

CLIENTKey compromise

Malicious wallets, backups or remote provers can bypass otherwise sound protocol privacy.

Every trust boundary gets a separate control.

DOMAINPRIMARY CONTROLRESIDUAL RISK
Proof systemReproducible circuits, version-bound proofs, independent verifier implementationNovel cryptographic bug
Consensus21-seat BFT set, distinct Bitmap locks, BTC bond and evidence-based slashingThreshold collusion
BTC adapterRate limits, proof-of-reserve, signer separation and delayed withdrawalsCustody compromise
Client privacyLocal proving, local scan keys, optional relays and metadata warningsEndpoint correlation
UpgradesOn-chain proposal hash, timelock, independent signers and exit windowGovernance capture
OperationsPublic telemetry, runbooks, key rotation and post-incident reportsUnknown failure mode

Authority is narrow, delayed and observable.

ACTIONREQUIRED PROCESSNON-NEGOTIABLE LIMIT
Runtime upgradePublished bytecode hash + timelock + validator thresholdNo retroactive state mutation
Circuit upgradeDual-version window + audit artifact + migration toolNo silent verifier replacement
Emergency pauseNarrow multi-party authority + public reason codeCannot seize user notes
Treasury transferDestination, purpose and cap declared on-chainNo undisclosed reserve reuse
Validator rotationEligibility proof + exit/fault windowFoundation capped at six seats

A pause may stop new shielded transitions while preserving proof verification and user exit paths whenever technically safe. Emergency power is not an administrative viewing key.

Shielded values reduce visibility—not ordering power.

Public mempool

Standard EVM transactions remain observable and exposed to familiar ordering strategies.

Shielded payload

Values and recipients are hidden, but arrival time, fee and nullifier presence remain visible.

Mitigation direction

Encrypted submission, batch ordering, proposer commitments and measurable inclusion policy.

Mainnet requires evidence, not confidence.

GATE 01Specification freeze

State transition, circuits, asset adapters and governance authority documented.

GATE 02Independent audits

Separate reviewers for consensus, circuits, Solidity contracts and bridge custody.

GATE 03Adversarial testnet

Fault injection, chain halt, stale roots, reorgs, prover failure and mass exit.

GATE 04Bug bounty

Severity matrix, protected disclosure path and funded payout commitments.

GATE 05Genesis rehearsal

Validator ceremony, key rotation, recovery and public artifact verification.

GATE 06Incident command

Named roles, decision thresholds, communication templates and postmortem policy.