Trust model

This page tells you what zk.money protects and what it does not. For who can see what, see Privacy. For how you get your funds out if a service stops, see Exiting zk.money.

   your device                operators                    chains
+---------------+     +---------------------+     +--------------------+
| passkey       |     | Oxide enclave       |     | Aztec Network      |
| your keys     |<--->| fee-paying contract |<--->| your private notes |
| private       |     | Oxide relayer       |     +--------------------+
| execution     |     | Oxide resolver      |<--->| Ethereum           |
+---------------+     | Aztec node          |     | portal, registry   |
                      +---------------------+     +--------------------+

What zk.money protects against

No zk.money or Oxide service holds your signing key. Every service in the system can refuse to participate in your transaction, but no service can move your funds for you.

The contracts on Ethereum cannot be changed once they are deployed. There is no upgrade function. There is no function that lets any person take your funds out of the portal.

The last Ethereum step of a deposit and of a withdrawal is open to everyone. zk.money builds that transaction for you, and you can send it yourself.

The signing enclave is also open to everyone. Anyone can register an enclave on the portal contract. See "If every operator stops operating" on Exiting zk.money.

The public chain does not show your balance. It does not show the amount of a payment inside zk.money.

The same passkey gives you the same wallet on a different computer. Your accounts do not live in the browser.

The parties in the system and what they can do

Oxide enclaves. An enclave is a program running in a sealed server, and it co-signs every token operation, so each send and each withdrawal needs a signature from one. There is no single enclave and no privileged operator: the portal on Ethereum registers any enclave that proves it runs the approved software on AWS Nitro hardware, any number may register, and nobody can stop you registering yours. You need an AWS account, an Ethereum account with gas, and command-line work, so it is not a button in the app, and AWS must still attest honestly. zk.money Desktop then points your wallet at the enclave you name.

Every exit from the Aztec Network needs a signature from a live enclave registered on the portal. That is true for a normal withdrawal, and for all three refund routes that exist after a freeze. If no registered enclave is running, nobody exits until one runs again.

The fee-paying contract. You do not pay network fees inside zk.money. A contract on the network pays them for you. If that contract runs empty, your transactions stop until it is topped up again, and you cannot pay a fee out of your own balance instead.

The Oxide relayer. It moves a deposit from its arrival address into the network, and finishes a withdrawal on Ethereum. It can only delay you. Both jobs are open to anyone, and the web wallet has a button for each. You pay the Ethereum gas and collect the fee the relayer would have taken. A withdrawal you finish yourself still needs an enclave signature.

The Oxide resolver. The resolver derives a deposit address for a person who pays your tag from outside zk.money. Your wallet does not use it; your wallet derives your address on your device, so a resolver that stops reaches only those outside payers. The resolver can never return a wrong address: Ethereum verifies the proof behind every resolution. See Receive and send.

The Aztec node. Your wallet reads the network and sends transactions through an Aztec node hosted by zk.money. If that node is unavailable, your wallet cannot read or send until it uses another one, and zk.money Desktop lets you enter a different node address.

The account service. It can stop a new account but not one you already have: the zk.money account service signs your name claim.

Three more can stop funds you already hold. A screening service checks the Ethereum address you withdraw to; zk.money runs that check before it submits anything, and stops the withdrawal if the address fails or the service is silent. Oxide's relayer applies the same policy when it finalizes withdrawals. This is a check in the wallet and in the relayer's policy, not in the contracts: the portal holds no list of addresses, it accepts a signed withdrawal to any address, and anyone can send that last transaction. The service that publishes the contract addresses can point your wallet at the wrong contracts, and nothing signs that list today.

The portal has no owner. Deployment approves one enclave software version and then renounces ownership, so that version is fixed for the life of the portal.

Nobody can freeze the portal on demand: a freeze is open to anyone, but only once the Aztec Network has moved to a new rollup. A freeze is permanent. It stops new deposits and fixes the portal to the state it had at the freeze. It does not stop funds coming out: a withdrawal that left your balance before the freeze still finishes, and a balance still on the Aztec Network comes back through three refund routes on the portal: one for your notes, one for a deposit that was swept but never claimed, and one for a deposit that never arrived. Each needs a proof from your wallet and an enclave signature, and anyone can send the bundle to Ethereum for you.

What breaks if zk.money is attacked

The contracts cannot change. They are fixed at deployment. Nobody can upgrade them or alter their rules.

The software can change. Whoever controls how zk.money reaches you — the code repository, the web deployment, or the domain — could push a version that asks you to sign something harmful. A bad version cannot take your signing key, but you would be signing the transaction yourself, so fixed contracts do not help. Read what you sign.

You can run it yourself. zk.money Desktop serves the wallet from your own computer and points it at any Aztec node, Ethereum endpoint or enclave you name. Every Ethereum step is open to you too: register your own enclave, sweep your own deposit, finish your own withdrawal.

A theft would need two failures at once. A hostile enclave operator on its own cannot spend your funds, because your signing key never leaves your passkey. Taking funds out of the portal needs a soundness fault in the Aztec Network and a compromised enclave at the same time.

Losing your passkey

If you lose your passkey, you lose the wallet. Both your keys come from the passkey and from nothing else. zk.money holds no copy, there is no escrow, and no one can restore your account.

zk.money works out your secret key from your passkey each time you sign in, and holds it in your browser, unencrypted, until you sign out. Someone who gets it, for example through a harmful browser extension or by using your computer, can see your balance and history, and read or send messages as you. They still cannot move your funds: that needs your signing key, which never leaves your passkey. Sign out when you finish on a computer you share.