Five independent failure domains.
Circuit, verifier, setup or implementation flaws could create or steal shielded value.
A Byzantine threshold may censor, halt or reorder transactions even without breaking proofs.
Key compromise, adapter bugs or external issuer failure can break asset backing.
IP, timing, amount boundaries and deposit/withdraw patterns may reduce the anonymity set.
Upgrade, pause or treasury powers may be abused if thresholds, delays and scope are weak.
Malicious wallets, backups or remote provers can bypass otherwise sound protocol privacy.
Every trust boundary gets a separate control.
Authority is narrow, delayed and observable.
A pause may stop new shielded transitions while preserving proof verification and user exit paths whenever technically safe. Emergency power is not an administrative viewing key.
Shielded values reduce visibility—not ordering power.
Standard EVM transactions remain observable and exposed to familiar ordering strategies.
Values and recipients are hidden, but arrival time, fee and nullifier presence remain visible.
Encrypted submission, batch ordering, proposer commitments and measurable inclusion policy.
Mainnet requires evidence, not confidence.
State transition, circuits, asset adapters and governance authority documented.
Separate reviewers for consensus, circuits, Solidity contracts and bridge custody.
Fault injection, chain halt, stale roots, reorgs, prover failure and mass exit.
Severity matrix, protected disclosure path and funded payout commitments.
Validator ceremony, key rotation, recovery and public artifact verification.
Named roles, decision thresholds, communication templates and postmortem policy.
