# Overview zk.money is an open source, self-custodial wallet that lets people send and receive crypto privately. zk.money is built on the Aztec Network. The Aztec Network is a fully private, fully programmable network on top of Ethereum. Therefore, your zk.money transactions do not show your balance, amounts, or participants for any transactions that happen inside of zk.money. You also pay no Ethereum gas on payments inside zk.money, although sending a deposit from Ethereum into zk.money requires Ethereum gas, and these deposit transactions from Ethereum are public (as are all Ethereum transactions). Because zk.money is non-custodial and powered by immutable smart contracts, any crypto held in zk.money wallets remains completely under the user's control. No one can spend or move funds in zk.money, apart from the user themselves. There is no privileged admin role in the system and there is no centralized zk.money server whatsoever with admin keys to move funds. ## Before you start If you lose your passkey, you lose the wallet. zk.money holds no copy of your passkey, and there is no escrow. No one can restore your account if the passkey is lost. Every deposit, payment, and withdrawal will initially be restricted to be below $2,500. Each deposit address is single-use. Take a fresh one for every payment you receive, so the payments into your wallet cannot be linked to each other. ## High-level glossary There is a larger glossary at [Glossary](/docs/glossary). This is a high-level overview of important terms. **[zk.money](/docs/glossary#zkmoney)** is the name of the wallet. zk.money can be run as a web wallet at the zk.money domain, or as a [locally-run desktop app](/docs/desktop). The same passkey gives you access to the same wallet on a different device. **[Oxide](/docs/glossary#oxide)** is a protocol that runs "alongside" the Aztec Network. It provides an independent layer of security against vulnerabilities in the Aztec Network's proving system. It is built on AWS Nitro Enclaves and works by having the user simulate the Aztec Network transaction. Oxide is a separate protocol from zk.money, and every role in it is permissionless. zk.money runs the default enclave and resolver, but anyone, including you, can run their own and point the wallet at it. **[Aztec Network](/docs/glossary#aztec-network)** is the decentralized and private network on which your notes and zk.money balance ultimately live. --- # FAQ ## What is zk.money? zk.money is an open source, self-custodial wallet that lets people send and receive crypto privately, available in your browser or as a locally-run desktop app. Your funds are held privately on the [Aztec Network](/docs/glossary#aztec-network), so balances, amounts and history are not published on a public chain. Users can deposit from Ethereum, pay people via their [tags](/docs/glossary#tag), share [payment links](/docs/glossary#payment-link), and withdraw back to Ethereum at any time. As a completely self-custodial wallet, users hold their own keys, and there is no privileged admin role in the system. ## Is this the same zk.money as before? Same name, but a new product on a new architecture. The original zk.money was a private DeFi app on Aztec Connect, which stopped accepting deposits in 2023 and shut down in March 2024. Accounts and funds do not carry over. ## What network is zk.money built on, and which tokens can I use? zk.money runs on the [Aztec Network](/docs/glossary#aztec-network), a privacy-focused Layer 2 on Ethereum. Transactions are proven on your device before they are sent, so your keys never leave your device. Initially, the system supports DAI, with more tokens to be added over time, but you can deposit USDC, USDT, or DAI directly, and they will be swapped to DAI as they are deposited. Withdrawals go back to Ethereum mainnet. ## Who can see my payments? Deposits and withdrawals to Ethereum are public by design, as they would be for any Ethereum transaction. Within the zk.money system, no one can see your transactions. Amounts, sender, recipient and balances are private on the [Aztec Network](/docs/glossary#aztec-network), and that includes zk.money itself; no operator can see or redirect your funds. The only other thing that is public by design is your [tag](/docs/glossary#tag), so people can pay you to your tag, but knowing your tag does not allow anyone to see your transaction history whatsoever. ## Is my tag private? Your [tag](/docs/glossary#tag) is a public handle, so people can pay you by name. Everything you do with it stays private: your amounts, your balance, your payment history, and who you transact with. Tags are first come, first served. Pick any name that is not taken; a small number of names are reserved by the zk.money team. ## Why does zk.money say a name is reserved? A small number of names are reserved by the zk.money team, and the sign-up flow will not issue them. A reserved name can be claimed only by messaging the zk.money account on X, [@zk_money](https://x.com/zk_money), from the X account whose handle exactly matches the reserved tag. If the handle matches, you are sent a claim link for that tag. Every other tag is first come, first served. ## Can zk.money freeze my account or block my funds? No. Nobody can spend or take your funds; only you control them. Individual operating roles within zk.money can go down or refuse service, but your existing balance can still be withdrawn. Deploying a [portal contract](/docs/glossary#oxide-portal) renounces administrative ownership of it, so nobody holds admin power over a portal. Portals can be frozen by anyone if the Aztec Network migrates to a new rollup instance, but a [freeze](/docs/glossary#freeze) only stops new deposits from coming in, and does not stop funds coming out (for example, for a migration to the new rollup). [Oxide](/docs/glossary#oxide) is open source, so anyone can run an Oxide instance. ## Is there a seed phrase? What if I lose my passkey? No seed phrase, and no separate key to write down. Both your [keys](/docs/passkeys#two-keys) come from your passkey. When you sign in, the wallet works out your secret key and keeps it, unencrypted, in your browser's storage until you sign out, so a refresh, a new tab or closing the browser does not ask for your passkey again. The secret key shows your balance and history, but it cannot move your funds; see [Trust model](/docs/trust). Backing up your passkey (iCloud Keychain, Google Password Manager or 1Password) is what backs up your account. A passkey on a security key has no backup: lose the key and you lose the wallet. If you lose a device, signing in with the same passkey on a [supported setup](/docs/passkeys#which-passkeys-work) restores your funds. If the passkey is gone everywhere, no one can reconstruct it. ## What is a payment link? A [payment link](/docs/glossary#payment-link) holds funds: you lock an amount, share the link, and whoever you send it to claims it with their passkey. They do not need a zk.money account beforehand. Each link has a claim window you choose (1, 7 or 30 days) and a refund window that opens the moment you create it. If it is not claimed, you can take the funds back at any time. While a direct link is claimable, anyone who has it can claim it, so treat it like cash. A link can never be both claimed and refunded. A request link is the reverse: it asks someone to pay you and gives them a deposit address, so it holds no funds until they send. ## Can I receive funds from someone who does not use zk.money? Yes. Anyone can send DAI, USDC or USDT to your Ethereum [deposit address](/docs/glossary#deposit-address) from any wallet or exchange, like a normal transfer. They do not need a zk.money account, and the deposit is swept into your private balance automatically. Each deposit address is single-use, so get a fresh one for every payment. Only transactions originating from, or withdrawing to, Ethereum are public. There are two ways to skip handing out an address. Send a [request link](/docs/glossary#payment-request), and whoever opens it pays you from there. Or, in an Ethereum wallet that uses ENS CCIP, someone can type your [tag](/docs/glossary#tag) as bob.zk.money and the resolver derives a fresh deposit address behind it, so the payment reaches you privately. ## How do I refund a payment link? Until somebody claims a [payment link](/docs/glossary#payment-link) you can take the funds back: cancel it before the expiry, or reclaim it after. A link is never both claimed and refunded — the first of the two to land is the only one that counts. [Receive and send](/docs/receive-and-send) has the windows, the timing, and what a refund needs. ## What if I pay the wrong person? Payments are final. zk.money shows you the resolved recipient before you confirm, so check carefully. To pay someone you do not fully trust, send a payment link instead. If they never claim the payment link, you get the funds back. ## Does zk.money charge fees? There is a small fee on deposits and withdrawals, taken out of the total deposited or withdrawn amount. Part of each fee goes directly towards topping up a standalone [fee-paying contract](/docs/glossary#fee-paying-contract) that covers network fees for everyone using zk.money, which is why what you do inside zk.money is free: up to 100 transactions a day, with no account data collected. The rest pays the Ethereum gas of moving your funds in and out. The free cover is subject to change in the future. A deposit costs $0.35 and a withdrawal costs $0.20; [Limits](/docs/limits) breaks both down. Claiming a [tag](/docs/glossary#tag) costs $4.90, and an additional $0.10 goes to that contract. That $5 comes out of your first deposit, which must be at least $15 in USDC, USDT or DAI, so $15 in DAI leaves you with $10 (USDC and USDT are swapped to DAI on the way in, so the exact figure moves with the swap rate). You can waive the $4.90 tag fee in the sign-up flow if you're eligible: prove that you own a wallet from the prior zk.money system that sunset in 2024, or get one person to claim a zk.money tag through your share link. A first deposit of at least $5 is still required, and you'll pay $0.60 in fees, so $5 in DAI leaves you with $4.40. --- # Get started You can think of your account as consisting of a passkey and a tag name, like `bob.zk.money`. ## Passkey A passkey is a credential that your device or password manager holds. You unlock it with your face, your fingerprint, a PIN, or a security key. It is what proves the wallet is yours, and it should never be given out. It gives you two keys, one for your funds and one for your privacy; see [Your two keys](/docs/passkeys#two-keys). zk.money works with a passkey saved in iCloud Keychain, Google Password Manager or 1Password, or kept on a YubiKey 5 security key. [Passkeys](/docs/passkeys) explains how to reach yours on each device and what to do when it does not work. If you lose every device and credential that can produce your passkey, you lose the wallet. There is no escrow and no reset. Read [Trust model](/docs/trust) before you put funds into zk.money. ## Your tag Your tag is the name people pay you by, like `bob.zk.money`. You can pick any name that is not already taken. A small number of names are reserved; see below. Claiming a tag records it alongside your account address as a public pair on Ethereum, **although no one can see the transfers, amounts, or participants in the transactions that occur on the zk.money system, inside of the Aztec Network.** See [Privacy](/docs/privacy). ## Reserved names A small number of names are reserved by the zk.money team, and the sign-up flow will not issue them. If you type one, zk.money tells you it is reserved. A reserved name can be claimed only by messaging the zk.money account on X, [@zk_money](https://x.com/zk_money), from the X account whose handle exactly matches the reserved tag. If the handle matches, you will be sent a claim link for that tag. Reserved names are the only exception. Every other tag is first come, first served; see [Trust model](/docs/trust). ## What you need to get started - A phone that keeps passkeys in iCloud Keychain, Google Password Manager or 1Password, or a YubiKey 5 security key. See [Which passkeys work](/docs/passkeys#which-passkeys-work). - A first deposit of at least $15 in USDC, USDT or DAI. Claiming a tag costs $4.90, and an additional $0.10 goes to the fee-paying contract, so $15 in DAI leaves you with $10. USDC and USDT are swapped to DAI on the way in, so the opening balance also moves with the swap rate; see [Limits](/docs/limits). - The sign-up flow has two ways to waive the $4.90 tag fee. With it waived, a first deposit of at least $5 is still required, and you'll pay $0.60 in fees to cover registration, so $5 in DAI leaves you with $4.40. 1. Prove that you own a wallet from the prior zk.money system that sunset in 2024. 2. Get one person to claim a zk.money tag through your share link. ## How to get started 1. Navigate to the sign-up flow. 2. You type the tag you want. 3. You create a passkey. On a phone, you confirm with your face or fingerprint, or tap your security key. On a computer, you scan a QR code with your phone and confirm there, or use your security key. zk.money does not accept a passkey saved on the computer itself at sign-up. 4. You send a first deposit of at least $15 in USDC, USDT or DAI, and pay the Ethereum gas on it. $5 of it covers the tag and the fees, so $15 leaves you with $10. If your tag fee is waived, zk.money asks for $5 instead. 5. Your tag becomes active. The claim usually settles in about one minute. zk.money tells you when it takes longer. ## Troubleshooting failed sign-ups If a sign-up does not finish, one of these is usually the cause: - **You canceled the sign-in, or about an hour passed.** The claim expires. Start again. - **The tag is taken.** Someone claimed it first. Choose another. - **The tag is reserved.** zk.money will not issue it in sign-up. If it matches your X handle, see Reserved names above; otherwise choose another. - **You used a different passkey than the one that started the claim.** The claim is bound to the passkey that opened it, so zk.money refuses the new one. Start again with the original passkey. - **Your claim is still in flight.** Deposit addresses become available once it settles. - **zk.money refused your passkey.** See [Problems at sign-up](/docs/passkeys#sign-up-problems). For problems signing in, see [Problems at sign-in](/docs/passkeys#sign-in-problems). ## Keeping access to your wallet Keeping your passkey is keeping your wallet. No one in the system can restore it for you. Do these things today: - Make sure your passkey provider syncs your passkey to more than one device. - If your passkey is on a security key, keep the key safe. It holds the only copy. - Test the sign-in on a second device before you put in a large amount. - Keep your passkey provider account safe. That account is now the root of your wallet. The same passkey will give you access to the same wallet, and your payment history, on a different computer. Until your tag is active, a different browser may not find your wallet; see ["No wallet for this passkey"](/docs/passkeys#no-wallet-found). --- # Deposit You can get funds into zk.money by sending USDC, USDT, or DAI on Ethereum to a new deposit address. That includes the deposit that claims your tag, which any of the three covers. ## What you need - An active tag. Your first deposit is the one that claims it — see [Get started](/docs/get-started). - USDC, USDT or DAI on Ethereum, in a wallet you control. - ETH in that wallet, for L1 gas costs. Gas inside zk.money is covered for you; see [Limits](/docs/limits). ## How to get funds into zk.money 1. **Open the deposit screen.** Your device computes a new deposit address each time, on its own, without asking any server for it. Do not save a deposit address, and do not reuse it. A second payment to the same deposit address lowers your privacy. zk.money publishes the address on the Aztec Network so a relayer knows to watch it, and shows you the deposit fee before you send anything. 2. **Send the funds from your Ethereum wallet.** Send USDC, USDT or DAI to the deposit address, and pay the L1 gas on this transaction. 3. **A relayer picks the transaction up.** It deploys the address and moves the funds into the shared pool, paying the Ethereum gas itself. USDC and USDT are exchanged for DAI through Curve. 4. **Your balance goes up once Ethereum's message settles on Aztec.** zk.money records the deposit before then, but you cannot spend it until it settles. Deposits should take a few minutes. After 30 minutes without a transaction confirmation, zk.money treats the deposit as late and offers you the exit described in Troubleshooting below. ## What a deposit costs A deposit costs $0.35. Of that, $0.25 goes to the relayers who move your deposit into zk.money, to subsidize their Ethereum gas, and $0.10 tops up the fee-paying contract. The deposit screen shows the $0.35 as a single number before you send. Note that USDC and USDT are swapped to DAI on entry, so the Curve exchange rate applies as well. ## What to watch for - **Each deposit must stay below $2,500.** All deposits share a daily system limit as well. Read [Limits](/docs/limits) for more details. - **Every visit to the deposit screen makes a new address.** Do not save one, and do not use one twice. A second payment lowers your privacy. - **Send only USDC, USDT or DAI, on Ethereum.** Other tokens, and tokens on other networks, may not be recoverable. ## Troubleshooting failed deposits If a deposit does not arrive, one of these is usually the cause: - **No relayer picked up the transaction.** After 30 minutes, a "Sweep now" option becomes available, which allows you to send the transaction from your own Ethereum wallet and pay the gas. The [tip](/docs/glossary#tip) goes to you. - **The amount is at or below the deposit fee, or above the cap, or the address was used before.** zk.money marks the deposit recoverable, and you send the funds back out to an Ethereum address that you provide. - **The deposit is larger than the space left in the shared daily limit.** The Ethereum transaction fails and your funds stay at the deposit address. They are not lost. Try again later, or send them back to an Ethereum address you control from the activity list. Every exit above needs your own Ethereum wallet and Ether for gas. These exits are in the web wallet and in zk.money Desktop. If none of these is it, Settings in the web wallet has Report a bug, and a place to send feedback. --- # Receive and send Your tag is how people pay you inside zk.money. You can also open a payment request, so someone pays you a set amount. To send funds, you pay another tag directly, or you send a payment link to someone who has no zk.money wallet. ## How to receive funds There are three ways to be paid inside of zk.money: hand out your tag, request payment from a contact, or share a generic request link. Someone outside of zk.money can pay you by depositing tokens into a fresh deposit address for you — see [Deposit](/docs/deposit). **If the name resolver stops.** The resolver turns `yourtag.zk.money` into a deposit address for someone paying you from an outside Ethereum wallet. While it is down they cannot look up your tag, so give them the deposit address from your Receive screen instead. Payments inside zk.money are unaffected. The resolver can never return a wrong address: Ethereum verifies the proof behind every resolution. ### Give someone your tag Anyone with a zk.money account can pay you using your tag. You never have to share a hexadecimal `0x` address, just your tag. ### Ask a contact for a payment Asking a contact for an amount sends the request to their tag over XMTP, the messaging network zk.money uses for requests. They answer it with a normal payment, or they decline. Nothing moves until they pay. ### Share a request link A request link asks for an amount. You share it anywhere, and whoever opens it can pay, with or without a zk.money account. It carries no funds; it only asks. ## How to send funds ### To a zk.money tag 1. **Enter the tag and the amount.** You can add a short note. 2. **Confirm with your passkey.** Your device makes the proof, which takes about a minute. 3. **zk.money submits the payment.** Your tag and your note go with it, so the other person can see who paid and what for. The funds are theirs as soon as the transaction lands. Two things to watch for: - **Payments are final.** Check the recipient zk.money shows you before you confirm, because nothing can reverse a payment once it lands. To pay someone you do not fully trust, send a payment link instead. If they never claim it, you get the funds back. - **Each payment must stay below $2,500.** Read [Limits](/docs/limits) for more details. ### To someone who does not have a zk.money wallet Send a payment link. An open link pays whoever opens it; an email link pays only the person who signs in to Google or Apple with the address you enter. 1. **Choose the amount and a claim window** of 1, 7 or 30 days, 30 by default. For an email link, enter the address too. 2. **Confirm with your passkey.** The funds move into an escrow on Aztec, and zk.money shows you the link once the transaction lands. 3. **Send the link.** The other person opens it and claims. They do not need a zk.money account: they can claim into a zk.money balance, or straight out to an Ethereum address. An email link also asks them to sign in with Google or Apple. Creating a link and claiming one each need a proof of about one minute. An email claim also downloads a large proving file the first time, so a slow connection makes it slower. One thing to watch for: - **Whoever holds an open link holds the funds.** Treat an open link like cash, and send it over a channel you trust. ### Refunding a payment link Until somebody claims a link you can take the funds back, and both kinds of link work the same way. A link is never both claimed and refunded. The first of the two to land is the only one that counts. Before the expiry, cancel the link from your activity list and the funds return to you. The holder can still claim during that time, and the first transaction to land wins, so zk.money stops offering the cancel about half a minute before the expiry, to leave your refund time to land. After the expiry, reclaim the link from your activity list. Nobody can claim it any more, so there is nothing to race and no deadline. The expiry is the claim window you chose, which opens about two minutes after you create the link. Your refund window opens the moment you create the link and closes at that same expiry; you cannot set it separately. You can refund from any browser you sign in to: zk.money finds your links again from the network. ## Troubleshooting failed payments If a payment or a claim does not go through, one of these is usually the cause: - **The tag does not resolve.** Check the spelling. - **The enclave or the proof fails.** zk.money shows an error you can report. Try again. - **Sponsored fees are unavailable.** zk.money pays the network fee on your payments. They stop while the contract that funds it is empty, and while the Aztec Network's fee is higher than that contract will pay. Try again later. - **A claimer signs in with a different address than the one you entered on an email link.** zk.money refuses the claim. - **The proving file does not load on an email claim.** The claim cannot finish. Try again on a better connection. If none of these is it, Settings in the web wallet has Report a bug, and a place to send feedback. --- # Withdraw You can get funds out of zk.money by providing an Ethereum address. Your zk.money balance goes down, and that amount, less the fees below, arrives at that address on Ethereum. ## How to get funds out of zk.money 1. **Enter the Ethereum address and the amount.** Predicate screens the address first, and a blocked address stops the withdrawal here, before anything moves. See [Limits](/docs/limits) for how address screening works. 2. **Confirm with your passkey.** The Oxide enclave co-signs, your device computes a zero-knowledge proof of the withdrawal, and the amount leaves your balance on the Aztec Network. 3. **The funds are released to your address on Ethereum.** The Aztec Network proves the block on Ethereum, and a relayer sends the transaction that releases the funds and takes the [tip](/docs/glossary#tip). The address you entered is fixed when you confirm, so nobody can send the funds anywhere else. A withdrawal usually takes about an hour from that proof. zk.money tells you when a stage is taking longer than that. ## What it costs A withdrawal costs $0.20, and the address you entered receives the rest — $0.10 for the Ethereum transaction that releases your funds on the portal side, and $0.10 to top up the fee-paying contract. ## What to watch for - **Nothing warns you if the amount is over the cap.** zk.money warns you before a deposit that is too large, but not before a withdrawal. One over $2,500 fails when you make it. - **Withdrawals need a live Oxide enclave to co-sign.** zk.money runs one by default, so there is nothing for you to set up. If none is running, withdrawals wait until one is. See [Trust model](/docs/trust). ## Troubleshooting failed withdrawals If a withdrawal does not arrive, one of these is usually the cause. In every case your funds are still yours. - **Predicate blocked the withdrawal address, or could not answer.** zk.money refuses the withdrawal before anything moves. Your funds stay in your zk.money balance. - **The amount was at or below the fees.** zk.money does not check this before you send, so the transaction is submitted and then fails. Your funds stay in your zk.money balance. - **Nobody took the release job.** Your funds have left your zk.money balance and are waiting on Ethereum. After one hour, zk.money offers to let you send that last transaction yourself, with your own gas, and you keep the tip. If none of these is it, Settings in the web wallet has Report a bug, and a place to send feedback. --- # Limits ## Which tokens The portal holds one token: **DAI** on Ethereum. You can deposit DAI, USDC or USDT, including for the deposit that claims your tag. USDC and USDT are swapped to DAI on the way in. You cannot deposit any other token. Deposits come from Ethereum only. A token on any other chain cannot reach a deposit address. ## How much you can move Every deposit, every payment and every withdrawal must stay below **$2,500**. The cap is on each transaction, not on your balance. You can hold more than that, and move it in separate transactions. Only deposits warn you first — zk.money stops a deposit that is over the cap before you send it, while a payment or a withdrawal over the cap fails when you make it. Deposits also share one limit of **$50,000 per day, across all users**. Every deposit draws from the same bucket, and it fills again as time passes. There is no daily reset, and no share reserved for you. If a deposit is larger than the space left, zk.money does not check before it tries and the Ethereum transaction fails. Your funds stay at the deposit address and are not lost. Try again later, or send them back to an Ethereum address you control from your activity list. The caps exist for two reasons. They hold down the loss in the failure described on [Trust model](/docs/trust). They are also a launch safeguard, while the system is new. ## What it costs **The tag.** Claiming a tag costs $4.90, and an additional $0.10 goes to a fee-paying contract. The total of $5 comes out of your first deposit. You can waive the $4.90 tag fee in the sign-up flow if you're eligible; see [Get started](/docs/get-started). If your tag claim fee is waived, you'll pay $0.60 in fees in your first deposit. **Deposits.** A deposit costs $0.35. Of that, $0.25 goes to the relayers who move your deposit into zk.money, to subsidize their Ethereum gas, and $0.10 tops up the fee-paying contract. **Withdrawals.** A withdrawal costs $0.20 — $0.10 for the Ethereum transaction that releases your funds on the portal side, and $0.10 to top up the fee-paying contract. **The swap.** If you deposit USDC or USDT, the deposit contract swaps it to DAI through Curve. You pay the price of that swap. The swap sets no price floor. You take the market price at that moment, whatever it is. A deposit of 100 USDC does not necessarily become 100 DAI. **Network fees inside zk.money.** No network fees are paid in zk.money today. You get **100 free transactions per day**. A payment, a withdrawal, a payment link and a cancel each use one transaction. Sponsorship is not guaranteed. It stops while the fee-paying contract is empty, and while the Aztec Network's fee is higher than that contract will pay. You cannot pay a network fee out of your balance instead, so your transactions wait until sponsorship resumes. **Ethereum gas.** You pay the gas on your own deposit transaction. You pay gas again only if you do a job yourself: "Sweep now" on a late deposit, the last transaction of a withdrawal that no relayer finalizes, or sending a failed deposit back to an address you control. There is no charge beyond the amounts above. The free fee cover is subject to change in the future. There is no date for when it ends. ## Address screening Ethereum addresses are screened against a sanctions policy using Predicate. The check runs offchain. The wallet you deposit from and the address you withdraw to are both screened. The check runs as you type an address, and again when you confirm, before anything is spent. A blocked address stops you there. - A blocked deposit wallet reads: "This wallet can't be used to deposit. Connect a different one." - A blocked withdrawal address reads: "This address can't receive withdrawals." - If the service does not answer, the wallet says it could not verify the address and offers Retry. It does not let you continue. The relayer applies the same policy when it finishes a withdrawal on Ethereum. A blocked address means the relayer does not act. The contract holds no list of addresses. The screening is a policy applied by the zk.money frontend and the relayer. ## Changing the limits The caps cannot be raised without a new portal contract. They are fixed in the portal contract when it is deployed, and nothing can change them afterwards. A new limit therefore needs a new portal contract, and it needs you to choose to move your funds to it. The caps are expected to grow as the system spreads across more operators. There is no set date for when the caps will be changed. --- # Trust model What each party in the system can and cannot do to your funds. For who can see what, see [Privacy](/docs/privacy). For how you get your funds out if a service stops, see [Exiting zk.money](/docs/exit). ```text your device operators chains +---------------+ +---------------------+ +--------------------+ | passkey | | Oxide enclave | | Aztec Network | | your keys |<--->| fee-paying contract |<--->| your private notes | | private | | Oxide relayer | +--------------------+ | execution | | Oxide resolver |<--->| Ethereum | +---------------+ | Aztec node | | portal, registry | +---------------------+ +--------------------+ ``` ## What zk.money protects against No zk.money or Oxide service holds your [signing key](/docs/passkeys#two-keys). Every service in the system can refuse to participate in your transaction, but no service can move your funds for you. The contracts on Ethereum cannot be changed once they are deployed. There is no upgrade function. There is no function that lets any person take your funds out of the portal. The last Ethereum step of a deposit and of a withdrawal is open to everyone. zk.money builds that transaction for you, and you can send it yourself. The signing enclave is also open to everyone. Anyone can register an enclave on the portal contract. See "If every operator stops operating" on [Exiting zk.money](/docs/exit). The public chain does not show your balance. It does not show the amount of a payment inside zk.money. The same passkey gives you the same wallet on a different computer. Your accounts do not live in the browser. ## The parties in the system and what they can do **Oxide enclaves.** An enclave is a program running in a sealed server, and it co-signs every token operation, so each send and each withdrawal needs a signature from one. There is no single enclave and no privileged operator. The portal on Ethereum registers any enclave that proves it runs the approved software on AWS Nitro hardware, any number may register, and nobody can stop you registering yours. You need an AWS account, an Ethereum account with gas, and command-line work, so it is not a button in the app, and AWS must still attest honestly. zk.money Desktop then points your wallet at your own enclave. **Every exit from the Aztec Network needs a signature from a live enclave registered on the portal.** A normal withdrawal needs one, and so does each of the three refund routes that exist after a freeze. If no registered enclave is running, nobody exits until one runs again. **The fee-paying contract.** You do not pay network fees inside zk.money. A contract on the network pays them for you. If that contract runs empty, your transactions stop until it is topped up again, and you cannot pay a fee out of your own balance instead. **The Oxide relayer.** It moves a deposit from its arrival address into the network, and finishes a withdrawal on Ethereum. It can only delay you. Both jobs are open to anyone, and the web wallet has a button for each. You pay the Ethereum gas and collect the fee the relayer would have taken. A withdrawal you finish yourself still needs an enclave signature. **The Oxide resolver.** The resolver derives a deposit address for a person who pays your tag from outside zk.money. Your wallet does not use it; your wallet derives your address on your device, so a resolver that stops reaches only those outside payers. The resolver can never return a wrong address: Ethereum verifies the proof behind every resolution. See [Receive and send](/docs/receive-and-send). **The Aztec node.** Your wallet reads the network and sends transactions through an Aztec node hosted by zk.money. If that node is unavailable, your wallet cannot read or send until it uses another one, and zk.money Desktop lets you enter a different node address. **The account service.** It authorizes new tag registrations, so it can stop a new account but not one you already have. **The screening service.** It can block the Ethereum address you withdraw to. The portal holds no list of addresses and accepts a signed withdrawal to any address; the screening is a policy the wallet and the relayer apply. See [Limits](/docs/limits). **The service that publishes the contract addresses.** It can point your wallet at the wrong contracts, and nothing signs that list today. The portal has no owner. Deploying it approves one enclave software version and renounces ownership, so that version is fixed for the life of the portal. Nobody can freeze the portal on demand. Anyone can freeze it once the Aztec Network has moved to a new rollup, and a freeze is permanent. It stops new deposits and fixes the portal to the state it had at the freeze. Funds still come out. A withdrawal that left your balance before the freeze still finishes, and a balance still on the Aztec Network comes back through three refund routes on the portal, one each for your notes, for a deposit that was swept but never claimed, and for a deposit that never arrived. Each refund needs a proof from your wallet and an enclave signature, and anyone can send the bundle to Ethereum for you. ## What breaks if zk.money is attacked **The contracts cannot change.** They are fixed at deployment. Nobody can upgrade them or alter their rules. **The software can change.** Whoever controls how zk.money reaches you — the code repository, the web deployment, or the domain — could push a version that asks you to sign something harmful. A bad version cannot take your signing key, but you would be signing the transaction yourself, so fixed contracts do not help. Read what you sign. **You can run it yourself.** zk.money Desktop serves the wallet from your own computer, and its endpoint settings take any Aztec node, Ethereum RPC or enclave. Every Ethereum step is open to you as well. You can register your own enclave, sweep your own deposit, and finish your own withdrawal. **A theft would need two failures at once.** A hostile enclave operator on its own cannot spend your funds, because your signing key never leaves your passkey. Taking funds out of the portal needs a soundness fault in the Aztec Network *and* a compromised enclave at the same time. ## Losing your passkey **If you lose your passkey, you lose the wallet.** Both your [keys](/docs/passkeys#two-keys) come from the passkey and from nothing else. zk.money holds no copy, there is no escrow, and no one can restore your account. zk.money works out your secret key from your passkey each time you sign in, and holds it in your browser, unencrypted, until you sign out. Someone who gets it, for example through a harmful browser extension or by using your computer, can see your balance and history, and read or send messages as you. They still cannot move your funds. That needs your signing key, which never leaves your passkey. Sign out when you finish on a computer you share. --- # Passkeys Your passkey is your zk.money account. This page explains the two keys it gives you, which passkeys work, how to reach yours from each device, and what to do when something goes wrong. ## Your two keys Your passkey gives zk.money two keys: one for your funds and one for your privacy. - **Signing key.** Approves every payment. It is the passkey's own key, and it never leaves your passkey. Your account accepts only this key, and it is built into your account's address. - **Secret key.** Reads your balance and your payment history. Your passkey makes it with the [WebAuthn PRF extension](https://www.w3.org/TR/webauthn-3/#prf-extension), which gives a secret value that only this passkey can produce. zk.money keeps it in your browser until you sign out; see [Trust model](/docs/trust) for what that means. ## Which passkeys work zk.money works with a passkey saved in: - iCloud Keychain (Apple Passwords) - Google Password Manager - 1Password - a YubiKey 5 security key It refuses other passkey managers, such as Bitwarden, Proton Pass, LastPass or Windows Hello. zk.money has not tested that they give the same secret key on every device, and a secret key that changes would lock you out of your wallet. A password manager syncs your passkey to your other devices, and that sync is your backup. A security key holds the only copy: lose the key and you lose the wallet. ## Reaching your passkey **On a phone**, use the passkey saved on that phone, or a security key. Plug the key in, or hold it to the phone, only after the browser asks for it. A key that is already plugged in may not be found. **On a computer, at sign-up**, the passkey is made on your phone (scan the QR code) or on a security key. zk.money does not accept a passkey saved on the computer itself at sign-up. **On a computer, at sign-in**, the browser offers whatever it can reach: - a copy of your passkey on this computer: iCloud Keychain on a Mac, Google Password Manager in a Chrome signed in to the same Google account, or the 1Password browser extension - your phone, through the QR code - a security key For zk.money Desktop, see [How to run the desktop app](/docs/desktop). ## Problems at sign-up When zk.money refuses a passkey at sign-up, the passkey has already been saved. See [A passkey is left over](#leftover-passkey) before you try again. ### "That passkey provider isn't supported" The passkey was saved in a manager zk.money does not accept. Pick one from [Which passkeys work](#which-passkeys-work) and sign up again. ### "Use your phone or a security key" You are on a computer, and the passkey was saved on the computer itself. Sign up again and choose the QR code option, or use a security key. ### "This passkey can't be backed up" The passkey was saved somewhere that keeps it on one device only, so losing that device would lose the wallet. Use a password manager that syncs, or a security key. ### "Try a different passkey manager" Your passkey manager did not give zk.money your secret key. Use another one from [Which passkeys work](#which-passkeys-work). ### "This device can't use that security key" The security key gave no secret key on this device. Known causes: an iPhone older than iOS 26.4, a YubiKey Bio, or an Android phone with out-of-date Google Play services. Update the device, or use a YubiKey 5 on another device. ### "Update this browser, or use Chrome" On a Mac, signing up needs Safari 26 or later, or Firefox 139 or later. Older versions can still sign in. Safari updates apart from macOS, in **System Settings > General > Software Update**. Or sign up in Chrome, or on your phone. On an iPhone, zk.money needs iOS 18.4 or later, and shows a warning on older versions. Update iOS in Settings, or use another device. ### A passkey is left over A website cannot reliably delete a passkey, so a refused sign-up usually leaves one behind. It opens nothing and is safe to delete: in your password manager, or with YubiKey Manager for a security key. ## Problems at sign-in ### The browser does not offer your passkey, or says "Passkey not on this device" A browser can only offer a passkey it can reach. If yours is on your phone, choose the QR code option and scan it with the phone. Turn on Bluetooth on both devices and keep both online. If no QR code appears, look for "More options" or "Use a different device". Closing the QR window instead makes zk.money say "Passkey not on this device". On a Mac, Chrome can use iCloud Keychain only if you allow it in **System Settings > Privacy & Security > Passkeys Access for Web Browsers**. If no option appears at all, update your browser. ### Your Google Password Manager passkey does not appear A passkey in Google Password Manager belongs to the Google account it was saved under, often the one on your phone. Chrome on a computer offers it only when that Chrome is signed in to the same Google account. If you use a sync passphrase, Chrome needs it first, and it may ask for your Google Password Manager PIN or your Android screen lock the first time. A passkey you just made can take a few minutes to reach the computer. Scanning the QR code with your phone may also need a Chrome signed in to that account. iCloud Keychain passkeys do not depend on Google. ### The 1Password extension gives no secret key Some versions of the 1Password browser extension answer without your secret key, and zk.money shows "Try a different passkey manager". Update the extension, or choose the QR code option and use the 1Password app on your phone. ### Your Mac's passkey does not open your wallet On macOS 26.0 to 26.3, or 15.6.1 to 15.7.4, a Mac's copy of a passkey made on an iPhone can give the wrong secret key. This is an Apple bug, fixed in macOS 26.4 and 15.7.5. zk.money refuses the wrong secret key, so nothing is lost, and may say "This computer is returning the wrong key". Choose **Show passkeys** and use your iPhone (scan the QR code) or a security key, or update macOS. ### "No wallet for this passkey" The passkey you used did not open a wallet zk.money can find. - You may have picked a different passkey. Choose **Show passkeys** and pick another, or type your tag on the sign-in screen so zk.money asks for the passkey that tag uses. - Until your tag is active, a different browser may not find your wallet. Sign in on the browser you signed up on. ### "Passkeys unavailable on this site" Your passkey belongs to `auth.zk.money`, which lists the zk.money sites allowed to use it. This message means the browser refused the passkey request on this site, on the website or in zk.money Desktop. - If the message says zk.money needs iOS 18.4 or later, update iOS in Settings, or use another device. - Otherwise, a password manager's browser extension may have blocked the request. Turn off the extension's passkey option for this site, or use another browser. An out-of-date browser can also refuse, so update it. If it still fails, contact support. --- # Privacy This page describes the privacy model for zk.money. For more information, see the [Privacy Policy](/privacy-policy). In general, what happens inside zk.money is private. Whatever crosses the edge of the system, into and out of Ethereum, is not private. Every Ethereum transaction works that way; it is not particular to zk.money. ## Who can see your funds **An enclave can never spend your funds, and nobody can read what it sees.** Your wallet encrypts each operation to the enclave, and the enclave opens it inside a sealed server only to co-sign it. Co-signing is what it checks the operation for; it never receives your [signing key](/docs/passkeys#two-keys). The company running the machine around the enclave sees only encrypted bytes and their sizes, never your balance and never your payments. **A payment between two zk.money users is not public.** No amount and no name reaches a public chain. **A payment link carries nothing to a web server.** Everything a link holds sits after the `#` in the address, which a browser never sends to a server. An email link names a Google or Apple address, and the claimer's browser proves that address with a zero-knowledge proof, so the address itself stays offchain. **Ethereum is public.** Funds enter from an Ethereum address and leave to an Ethereum address. Those amounts and addresses are public. The tie between a deposit address and you is not, because that address comes from a shared secret. **The tag-to-address link is public.** The AccountRegistry on Ethereum holds your Aztec address, your Ethereum account address, and a public key. Your tag is stored as a hash, so an address cannot be turned back into a tag. But anyone who knows or guesses your tag can compute that hash and read your addresses. Treat your tag as public. **Your messaging address is public and permanent.** zk.money publishes an XMTP binding on Ethereum when it creates your account, every time, with no setting to turn it off. You can overwrite the value, but you cannot erase the history. **Two services see slightly more than the chain does.** The Aztec node your wallet reads from can tell that one account is behind a set of note requests, which links those requests to each other. When someone outside zk.money pays your tag, the resolver sees that sender's network address, your tag and address, and the amount. Neither one sees your balance, and neither can move anything. ## What you can do about it - **Your tag is public, and so is the address behind it.** Anyone who knows your tag can look up your Aztec address. They cannot see your balance, your payments, or who you pay. But if you pick a tag people already associate with you, they can tell the account is yours. - **Deposits and withdrawals are visible on Ethereum**, like any other Ethereum transaction: the address, the amount and the time. If you deposit from an exchange account in your name, that exchange knows you funded zk.money. If you withdraw to an address already tied to you, the destination is tied to you. - **A deposit and a withdrawal of the same size, close together, invite a guess**, even though no contract links the two. - **Do not use a deposit address twice.** ## What zk.money services keep zk.money's services see operational metadata — a deposit-address request, a tag claim, a rate-limit counter — and never your balance or what a payment inside zk.money says. The account service that signs your tag claim keeps a hash of the name, the account address it was issued to, a nonce, the signature it issued, and timestamps. It also keeps rate-limit counters keyed by a hashed client identifier, which expire with their window. The web wallet is a static site with no server of its own. It sends usage events to zk.money's analytics only if you turn them on, and the deposit and screening events never carry an address. An error report is different. You choose to send one, and it goes whether or not analytics is on. A report can quote your tag or an address in its free text, and it travels under its own identifier, so it cannot be joined to your usage events. --- # Exiting zk.money None of the services from the [Trust model](/docs/trust) can take your funds, but each one can stop being available on its own accord. Your way out of the zk.money system does not depend on any individual service staying operational, since the published code, the local copy of your wallet in zk.money Desktop, and the open registries on Ethereum exist. Below are the four routes out, easiest first. You only need the next one down if the one above it is unavailable to you. ## 1. The normal withdrawal You start the withdrawal and sign it. An enclave co-signs, and a relayer sends the last transaction on Ethereum. See [Withdraw](/docs/withdraw). ## 2. If the relayer stops You send the last Ethereum transaction yourself. zk.money builds it for you. See "Troubleshooting failed deposits" on [Deposit](/docs/deposit) and "Troubleshooting failed withdrawals" on [Withdraw](/docs/withdraw). ## 3. If the zk.money website disappears Use zk.money Desktop. It runs the wallet from your own computer, and it uses the same passkey. It needs Google Chrome. See [How to run the desktop app](/docs/desktop). In zk.money Desktop you can point the wallet at a different Ethereum RPC, a different Aztec node, and a different enclave, from the wallet's settings or the app's own settings page. It is the local exit you can use today. ## 4. If every operator stops operating, including every Oxide enclave You register your own enclave. The portal contract accepts a registration from any address. The contract checks a proof from AWS Nitro Enclaves. The proof must show that the software measurement of your enclave is one the portal already approves. The contract also refuses debug mode. So you cannot register modified software, and a hostile operator cannot sign an invalid operation. You need an AWS account and a machine type that supports Nitro Enclaves. You must build an image that measures to the approved version. You must send the registration to Ethereum as a set of transactions, because the proof check is too large for one transaction, and you pay the gas for all of them. Then you point zk.money Desktop at your own enclave. No registration command is published here, because none has yet been run against the build you would register. For how to start the enclave software on your own server, see [How to run an enclave](/docs/run-an-enclave). --- # Glossary Terms used across these docs, in alphabetical order. **AccountRegistry.** The contract on Ethereum that holds your Aztec address, your Ethereum account address, and a public key. **Aztec Network.** The private network that holds your notes and your balance. **Curve.** Where the deposit contract swaps USDC or USDT to DAI. **Deposit address (SIPA).** A Segregated Incoming Payment Address: a fresh Ethereum address for funds coming in. It shows nothing about you, and each deposit uses a new one. **Enclave.** A sealed server that co-signs every token operation — a transfer within the Aztec Network, a withdrawal to Ethereum — so the token contract can trust a statement about notes it cannot read. Anyone can run one. **Fee-paying contract.** A standalone contract that covers network fees for everyone using zk.money, so you never need to hold gas. Deposits and withdrawals top it up. **Freeze.** A permanent stop on an Oxide portal, open to anyone once the Aztec Network has moved to a new rollup. It stops new deposits and fixes the portal to the state it had at the freeze. Balances come back through the refund routes, each of which needs a proof from your wallet and an enclave signature. **Note.** A private record of value on the Aztec Network. **Oxide.** A protocol that runs "alongside" the Aztec Network, providing an independent layer of security against vulnerabilities in the Aztec Network's proving system. It is separate from zk.money, and every role in it is permissionless: the portal on Ethereum, the token contract on the Aztec Network, the enclaves that co-sign every token operation, and the relayer and resolver roles around them. Anyone can run any of these roles. **Oxide portal on Ethereum.** Holds the DAI on Ethereum while the Aztec side holds your private claim on it. **Oxide relayer.** Moves a deposit from its arrival address into the network, and finishes a withdrawal on Ethereum. Both jobs are open to anyone. **Oxide resolver.** Derives a deposit address for someone who pays your tag from outside zk.money. **Passkey.** Your zk.money account. It gives you two keys: a signing key that moves your funds and a secret key that reads your balance and history. See [Your two keys](/docs/passkeys#two-keys). **Payment link.** A web link that carries a payment. **Payment request.** An ask for an amount. It carries no funds and touches no contract. **Predicate.** The service that screens Ethereum addresses against a sanctions policy. The check runs offchain. **Secret key.** The key your passkey makes to read your balance and payment history. It cannot move funds. See [Your two keys](/docs/passkeys#two-keys). **Signing key.** Your passkey's own key. It approves every payment and never leaves your passkey. See [Your two keys](/docs/passkeys#two-keys). **Sweep.** Moving a deposit from its arrival address into the shared pool. **Tag.** A name you choose. Your tag and your account address are a public pair on Ethereum. **Tip.** The part of a deposit or withdrawal fee that pays whoever sends the Ethereum transaction. A relayer takes it; do that job yourself and you keep it. **XMTP.** The messaging network zk.money uses for payment requests and for finding a contact. It does not carry payments. A transfer's tag and memo travel on the Aztec Network, inside the transaction. **zk.money.** The wallet: the web wallet and zk.money Desktop. --- # How to run the desktop app zk.money Desktop runs the zk.money wallet on your own computer. A Chrome window opens showing the wallet, and you sign in with the same passkey you use on zk.money. Your accounts and your funds are the same. The only thing that changes is where the website is served from. For how the app makes your passkey work without the real website, see [How the desktop app works](/docs/how-it-works). ## What you need - The [zk.money desktop wallet installed](https://download.zk.money). - Google Chrome. The app uses the Chrome you already have installed, and other browsers do not work. - Your passkey, reachable from this computer. It does not have to be stored on it. ## How to use it 1. **Open zk.money Desktop.** A Chrome window appears showing the wallet. 2. **Sign in with your passkey.** Use the same one you use on zk.money. 3. **Close the window when you have finished.** Nothing keeps running in the background. ## Where your wallet data is stored In the app's own data folder on your computer, separate from your normal browser. Deleting the app or its data does not affect your funds. They live on the network, and signing in with your passkey brings back your accounts, balances and payment history. ## What to watch for - **Only install official releases.** The app carries a full copy of the wallet, so a tampered copy could act as the real wallet and take your funds. Never download it from a third-party website, and check the file you got against its published fingerprint before you open it. - **One window at a time.** The wallet locks its local database while it runs. Do not open extra tabs on the wallet, and do not open the app twice. - **The first launch starts fresh.** The app keeps its wallet data separate from your normal browser, so there is nothing there the first time you open it. Signing in with your passkey restores your accounts. - **Anything involving your Ethereum wallet happens in your regular browser.** Some actions need a signature from an Ethereum wallet such as MetaMask, which lives in your normal browser rather than in this app. When one comes up, the app opens a page there showing what you are about to approve. Approve it and close the tab, and the app picks the result up on its own. ## Reaching your passkey Your passkey has to be reachable from this computer, but it does not have to be stored on it. The app's Chrome starts signed out of Google and without extensions. Pick the option that matches where your passkey lives. - **iCloud Keychain.** On a Mac it is offered automatically. Allow Chrome to use iCloud Keychain the first time it asks, then confirm with Touch ID. On any other computer, choose the QR code option and scan it with your iPhone. If Touch ID does not open your wallet, see [Your Mac's passkey does not open your wallet](/docs/passkeys#mac-wrong-key). - **Google Password Manager.** On a Mac, sign the app's Chrome in to the Google account that holds the passkey, as described under Troubleshooting below. See also [Your Google Password Manager passkey does not appear](/docs/passkeys#google-password-manager). - **1Password.** Choose the QR code option and scan it with your phone, where the 1Password app holds your passkey. On a Mac, signing the app's Chrome in to Google can bring your 1Password extension with it; unlock it, and it can offer your passkey. If it gives no secret key, see [The 1Password extension gives no secret key](/docs/passkeys#1password-extension). - **A hardware security key.** Plug it in. The phone and security-key options work everywhere. On Linux, which has no built-in passkey storage, use one of them or Google Password Manager. [Passkeys](/docs/passkeys) covers the rest. ## Verifying your download Every release publishes a file called `SHA256SUMS`, a list of fingerprints with one per installer. Checking the fingerprint proves the file on your disk is byte-for-byte the published one, and was not corrupted or tampered with on the way. Download `SHA256SUMS` from the [official GitHub releases page](https://github.com/aztec-labs-eng/zkmoney-public/releases/latest/download/SHA256SUMS), separate from the website the installer came from. Put it in the same folder as the installer, usually Downloads, then run the command for your platform. **macOS**, in Terminal: ``` cd ~/Downloads shasum -a 256 --check --ignore-missing SHA256SUMS ``` You should see the file you downloaded followed by `OK`. **Linux**, in a terminal: ``` cd ~/Downloads sha256sum --check --ignore-missing SHA256SUMS ``` You should see the file you downloaded followed by `OK`. **Windows**, in PowerShell: ``` cd ~\Downloads Get-FileHash "zkmoney-desktop-windows-setup.exe" ``` Open `SHA256SUMS` in Notepad and compare the long code PowerShell printed with the one next to your file's name. The whole string must be identical, and upper or lower case does not matter. If the check says `FAILED`, or the codes differ, do not open the installer. Delete it and download it again from the official download page. ## Pointing the wallet at a different service The wallet talks to a few services on the internet: an Ethereum RPC, an Aztec node, and an enclave. If one is unavailable, you can name a replacement, such as an Ethereum RPC from another provider. Change them in the wallet, as on the website: **Settings > Advanced > Endpoints**, or **Endpoints** at the top of the page before you sign in. If the wallet cannot start, its error screen offers **Change endpoints**. Save, and the wallet reloads on the new addresses. Leaving a field empty keeps the built-in address. The app also has a settings page with the same fields, plus the contract configuration. Open it in one of these ways: - **Automatically.** If the app finds at startup that it cannot load zk.money's configuration, it opens the settings page instead of the wallet, with a message explaining what failed. - **macOS.** While the app is running, right-click the zk.money Desktop icon in the Dock and choose **Endpoint Settings**. - **Windows and Linux.** While the app is running, click the zk.money icon in the system tray, next to the clock. On Windows it may be hidden behind the **^** arrow. The menu item is unavailable for a moment while the app starts or relaunches. On the settings page, click **Save & relaunch wallet**. If you set addresses in an earlier version of the app, enter them again: they are not carried over. Only use addresses from a source you trust. Never paste one a stranger sent you. Whoever runs an Aztec node you use sees your IP address and can tell which transactions your wallet sends and receives, but not what is in them. ## Troubleshooting the desktop app If the app does not work, one of these is usually the cause: - **Nothing opens, or the app cannot find Chrome.** Install Google Chrome and open the app again. Edge, Firefox and Safari do not work, because they cannot offer your zk.money passkey the way Chrome does. - **Chrome opens but does not ask for your passkey.** See [The browser does not offer your passkey](/docs/passkeys#not-offered). - **A passkey saved in Google Password Manager does not appear.** The app's Chrome starts signed out of Google, so it cannot see it. On a Mac, sign the app's Chrome in: click the wallet window, choose **Chrome > Settings** in the menu bar, then **You and Google**, and sign in to the account that holds the passkey. See [Your Google Password Manager passkey does not appear](/docs/passkeys#google-password-manager) for what Chrome may ask next. - **Your passkey works, but your accounts do not appear.** This copy of the app may target a different network than your wallet does. Check that the release you installed matches your wallet and is up to date. Otherwise, see ["No wallet for this passkey"](/docs/passkeys#no-wallet-found) and, on a Mac, [Your Mac's passkey does not open your wallet](/docs/passkeys#mac-wrong-key). - **The page shows an error or never finishes loading.** Close the Chrome window, quit the app, and open it again. If it still fails, restart your computer and try once more. --- # How the desktop app works **zk.money Desktop** is a locally-running version of zk.money. The **zk.money website** is the hosted wallet you reach in a browser at the `zk.money` domain. zk.money Desktop runs the same wallet on your own computer, using the passkey you already created on the website, so your funds stay reachable while the website is down. Nothing zk.money Desktop sets up is permanent. Launching the app starts a local web server and a dedicated Chrome profile, and closing the wallet window shuts both down. There is nothing to configure. ## Why zk.money Desktop serves the wallet at `wallet.zk.money` A passkey belongs to the site that created it. Yours belongs to `auth.zk.money`, which publishes a short list of the zk.money sites allowed to use it. The wallet at `wallet.zk.money` is on that list. Chrome offers your passkey only to a site on the list, which stops any other site from asking for it. So zk.money Desktop serves the wallet at `wallet.zk.money`, from your own computer. Three pieces make that work: - the wallet is bundled inside zk.money Desktop and served from your own machine, - Chrome resolves `https://wallet.zk.money` to that local server, - zk.money Desktop issues an HTTPS certificate for the server, and tells Chrome to trust that one certificate. All of this is scoped to the Chrome profile zk.money Desktop opens. Your DNS, your operating system and your everyday browser are untouched, and the zk.money website is unchanged. Chrome still reads the list from the real `auth.zk.money`, over the internet. ## What zk.money Desktop does at launch 1. **Issues an HTTPS certificate** for `wallet.zk.money`. The certificate is generated in zk.money Desktop's data folder, and no public certificate authority signs it, because the certificate never leaves your computer. 2. **Tells Chrome to trust that one certificate**, by its fingerprint, rather than turning certificate checking off. 3. **Starts a web server** for the bundled wallet. The server accepts connections from your own computer only. 4. **Serves the wallet over that certificate**, so the connection is real HTTPS rather than a warning you click through. 5. **Resolves `wallet.zk.money` to that server**, for this Chrome profile alone, so Chrome loads your local wallet instead of the website. 6. **Opens a dedicated Chrome profile**, which starts without your extensions, cached files, cookies or old service workers. Signing it in to Google can bring your extensions in; see [How to run the desktop app](/docs/desktop). Your wallet data lives in this profile, separate from your normal browsing. 7. **Shuts the server down when you close the window.** Nothing keeps running in the background. ## What reaches the internet Every page, script and image comes from the copy bundled inside zk.money Desktop, and no website assets are fetched from the internet. An internet connection is still needed for the wallet to do its actual job of reading your balances and sending transactions on the network. At launch zk.money Desktop also asks the zk.money website for its configuration (which contracts to talk to), but every build ships with a copy of that configuration, and falls back to the bundled copy when the website is unreachable. Chrome also reads the passkey list from `auth.zk.money`, and that has no bundled copy. ## zk.money Desktop never handles your passkey Your passkey never leaves where it is kept, whether that is iCloud Keychain, Google Password Manager, 1Password or a security key. The wallet asks your authenticator for the same operation the zk.money website asks for, and your authenticator applies the same checks it always does. Like the website, the app keeps your [secret key](/docs/passkeys#two-keys) in its own browser storage until you sign out. --- # How to run an enclave Every send and withdraw transaction on zk.money needs a signature from an [Oxide enclave](/docs/trust). No operator can move your funds, and no privileged admin role exists in the system. **However, an operator like an Oxide enclave or a [relayer](/docs/glossary#oxide-relayer) can go offline, so this page tells you how to run the enclave software yourself if need be.** **This is an advanced operation, and you do not need to do this to use zk.money on web or on desktop.** It is written for developers (or their agents) and assumes you already know something about AWS, Ethereum, and the Aztec Network. Running your own enclave enables you to [exit zk.money](/docs/exit) in the event that every enclave operator stops running. Running an enclave costs you AWS fees, and registering it costs gas on Ethereum and fees on Aztec. An enclave must be registered to the portal contract on Ethereum and the token contract on the Aztec Network (steps 5 to 7 below). ## What you need - An AWS account. - An EC2 instance type that supports Nitro Enclaves, launched with the enclave option turned on. The Oxide fleet uses `c5.xlarge`: 4 vCPUs and 8 GiB of memory, of which the enclave gets 2 vCPUs and 5 GiB. - Amazon Linux 2023 on that instance. ## How it fits together ```text your computer your EC2 instance +------------------+ +-----------------------------------------------+ | zk.money Desktop |---->| tee-proxy -> socat -> enclave (oxide-tee) | | | HTTP| :8080 :5001 vsock port 5000 | +------------------+ +-----------------------------------------------+ ``` The enclave has no network. It answers only on a vsock port. `socat` connects that port to a TCP port on the instance, and the Oxide proxy puts an HTTP endpoint in front of it. The proxy only moves bytes. Every request is sealed to the enclave's own key, so the proxy cannot read it. ## Prepare the instance `nitro-cli` is the AWS Nitro Enclaves command-line tool. It reads an enclave image file (EIF) and shows its measurements, and it starts, lists and stops enclaves on the instance. Install it before step 1, together with `socat`, Node.js 24 and git for the proxy, and `jq` for reading a measurement: ```text sudo dnf install -y aws-nitro-enclaves-cli aws-nitro-enclaves-cli-devel socat \ nodejs24 nodejs24-npm git jq sudo usermod -aG ne "$USER" # then log out and in again # Give the enclave 2 vCPUs and 5 GiB, then start the allocator. printf -- '---\nmemory_mib: 5120\ncpu_count: 2\n' | sudo tee /etc/nitro_enclaves/allocator.yaml sudo systemctl enable --now nitro-enclaves-allocator ``` The `ne` group lets your user run `nitro-cli` without `sudo`. The allocator sets aside the CPUs and memory the enclave gets, so the instance cannot use them. ## 1. Pick the image Pick an image from the table in "Enclave images" at the end of this page. For the network the wallet uses now, take the row marked **Current**. Download `oxide-tee.eif` and its `measurements.json` onto the instance, and check both. ```text IMAGE= # …/enclaves/ curl -fsSO "$IMAGE/oxide-tee.eif" curl -fsSO "$IMAGE/measurements.json" sha256sum oxide-tee.eif # must equal the SHA-256 in the table nitro-cli describe-eif --eif-path oxide-tee.eif | jq -r .Measurements.PCR0 ``` The PCR0 that `describe-eif` shows must equal the PCR0 in the table and in `measurements.json`. The PCR0 is the measurement of the enclave software. The portal registers only enclaves whose PCR0 it already approves, so you do not have to trust this page or the download. A changed image has a different PCR0 and cannot register. ## 2. Start the enclave ```text nitro-cli run-enclave --eif-path oxide-tee.eif --cpu-count 2 --memory 5120 --enclave-cid 16 nitro-cli describe-enclaves # State must be RUNNING, Flags must be NONE ``` The enclave makes its keys when it starts and keeps them only in its memory. If it stops, its keys are gone, and a new start is a new enclave that must be registered again. ## 3. Connect the enclave to a TCP port ```text socat TCP-LISTEN:5001,reuseaddr,fork,bind=127.0.0.1 VSOCK-CONNECT:16:5000 ``` Keep it running, for example in its own terminal or as a service. ## 4. Start the proxy The proxy is a small Node.js program with no runtime dependencies. Its source is in the zk.money public repository at [`vendor/oxide/yarn-project/tee-proxy`](https://github.com/aztec-labs-eng/zkmoney-public/tree/main/vendor/oxide/yarn-project/tee-proxy). ```text git clone --recurse-submodules https://github.com/aztec-labs-eng/zkmoney-public.git cd zkmoney-public/vendor/oxide/yarn-project/tee-proxy npm install npx tsc -p tsconfig.json node dest/proxy.js # listens on :8080, forwards to 127.0.0.1:5001 ``` `OXIDE_PROXY_HTTP_PORT`, `OXIDE_PROXY_TCP_HOST` and `OXIDE_PROXY_TCP_PORT` change the defaults. Check that it answers: ```text curl http://127.0.0.1:8080/health # prints OK ``` `/health` tells you only that the proxy runs. The enclave's own endpoint is `/rpc`. ## 5. Get the registration data Registration needs the enclave's attestation: a document from AWS Nitro, signed by the AWS root certificate, that holds the enclave's PCR0 and a hash of its two public keys. The enclave answers one request without encryption, `getAttestation`. Every request to `/rpc` is one frame: a 4-byte big-endian length, then the JSON body. ```text cat > get-attestation.mjs <<'JS' const body = Buffer.from(JSON.stringify({ method: 'getAttestation' })) const frame = Buffer.concat([Buffer.alloc(4), body]) frame.writeUInt32BE(body.length, 0) const res = await fetch('http://127.0.0.1:8080/rpc', { method: 'POST', headers: { 'content-type': 'application/octet-stream' }, body: frame, }) process.stdout.write(Buffer.from(await res.arrayBuffer()).subarray(4)) JS node get-attestation.mjs > attestation.json ``` The reply is `{ "ok": true, "result": { "attestation": …, "userData": { … } } }`: - `attestation` is the Nitro attestation document (COSE_Sign1), encoded as base64. It carries the certificate chain (`cabundle` and `certificate`), the signed payload and its signature. Decode it with `Buffer.from(result.attestation, 'base64')`. - `userData` holds the four key coordinates you register: `publicKeyX` and `publicKeyY` (the secp256k1 key the enclave signs with) and `encPubKeyX` and `encPubKeyY` (the P-256 key requests are sealed to). The enclave's Ethereum address is derived from the secp256k1 key. The enclave takes its attestation once, when it starts, and the portal refuses an attestation that is more than one hour old. Send the `registerTee` transaction of step 6 within one hour of starting the enclave. If you miss it, restart the enclave and begin again. ## 6. Register on Ethereum Send these transactions to the `portal` address of the deployment, from the table below or from the deployment's entry in Oxide's manifest. Anyone can send them, and you pay the gas. Verifying the attestation is too large for one transaction, so the portal verifies it in stages and caches each result: 1. `verifyTeeCACert(cert, parentCertHash)` for each certificate in `cabundle` after the first one, which is the AWS root, in order. `parentCertHash` is the keccak256 of the certificate before it. 2. `verifyTeeClientCert(cert, parentCertHash)` for the enclave's own `certificate`, with the keccak256 of the last `cabundle` certificate. Its own keccak256 is the `leafCertHash` of step 4. 3. `verifyTeeAttestationHash(attestationTbs)`, the signed payload of the COSE_Sign1 document. 4. `verifyTeeAttestationSig(attestationTbsKeccak, signature, leafCertHash)`. 5. `registerTee(attestationTbs, signature, publicKeyX, publicKeyY, encPubKeyX, encPubKeyY)`. Each staging step has a read function (`isTeeCertStaged`, `isTeeAttestationHashStaged`, `isTeeAttestationSigStaged`), so you can skip a step a previous attempt already did. `registerTee` fails unless `isPcr0Approved` is true for the image's PCR0, which is true for every image in the table that a deployment uses. On success it emits `TEEAdded` with a `messageKey` and a `leafIndex` for step 7. ## 7. Approve the signer on Aztec `registerTee` also sends a message from Ethereum to Aztec. When that message is ready, call `consume_signer_registration(pub_key_x_hi, pub_key_x_lo, pub_key_y_hi, pub_key_y_lo, message_leaf_index)` on the deployment's `l2Token` contract. The key arguments are `publicKeyX` and `publicKeyY`, each split into its high and low 128 bits, and the last one is the `leafIndex` from `TEEAdded`. Any Aztec account that can pay the fee can send it. Wait until the transaction is in a checkpointed block: a block that is only proposed can still be dropped, together with the transaction. The helpers that split the attestation into the values above, `getCertStagingEntries` and `decodeAttestationTbs`, are in [`vendor/oxide/yarn-project/oxide-lib/src/attestation`](https://github.com/aztec-labs-eng/zkmoney-public/tree/main/vendor/oxide/yarn-project/oxide-lib/src/attestation). ## 8. Point zk.money Desktop at it Open the endpoint settings page of zk.money Desktop, and set **Enclave URL** to the `/rpc` address of your proxy. The wallet runs on an HTTPS page, so the address must be HTTPS or a local one. The simplest way is an SSH tunnel from your computer, which keeps the proxy off the internet: ```text ssh -N -L 8080:127.0.0.1:8080 ec2-user@ ``` Then use `http://localhost:8080/rpc`. The wallet checks the enclave's attestation before it seals anything to it, so a wrong address fails closed. ## Enclave images One row for each deployment on this network, with the published image its portal approves. **Current** marks the deployment the wallet uses now.
--- # How to run a relayer A [relayer](/docs/glossary#oxide-relayer) is an operator in the zk.money system that moves a deposit into the network and releases a withdrawal back out to Ethereum, paying the Ethereum gas for both so that a user does not have to. No operator can move your funds, and no privileged admin role exists in the system. **However, an operator like an [Oxide enclave](/docs/trust) or a relayer can go offline, and zk.money does not run relayers, so this page tells you how to run one yourself if need be.** **This is an advanced operation, and you do not need to do this to use zk.money on web or on desktop.** It is written for developers (or their agents) and assumes you already know Docker, Ethereum, and the Aztec Network. A relayer pays the Ethereum gas on every transaction it sends, out of an account you fund and control, and earns the fees on the work it does first. ## What you need - Docker. - An Ethereum RPC URL. For `l1-operations` it must support `eth_simulateV1`; the relayer checks at startup. Do not use a Flashbots URL here. - An Aztec node URL. The Aztec v5 mainnet RPC also needs an API key. - A dedicated Ethereum account, funded with ETH for gas. This account pays the gas and receives the rewards. - The deployment manifest and the portal address of the deployment you want to serve. Both are given below. The relayer keeps its cursors and transaction state in `/data/oxide-relayer-{portal}.sqlite3`. Always mount `/data`, or replacing the container loses that state. ## What a relayer does A relayer runs one or more **modes**. Enable them with `--modes`, comma-separated. The default is `l1-operations`. Every mode uses the same signer. | Mode | What it does | Reward | Who should enable it | | --- | --- | --- | --- | | `l1-operations` | Executes the Ethereum transactions users request from the Aztec Network, such as sweeping a deposit or releasing a withdrawal. | The payout of each operation, in DAI. | Everyone. | | `fpc-funding` | Converts the fees the portal collects into fee juice for the contract that pays network fees inside zk.money. | A bounty in DAI. | Everyone. | | `epoch-proofs` | Asks your Aztec prover node to prove withdrawals early, then claims the prover tips. | Prover tips and the prover subsidy, in DAI. | Operators who run an Aztec prover node. Needs extra prover setup; see below. | ### How `l1-operations` works A user's action on the Aztec Network publishes an L1 operation: an Ethereum call, a payout token, and a condition such as "after the epoch of this withdrawal is proven". When the condition holds, the relayer screens the addresses, simulates the call, and executes it through the `OperationExecutor` contract. That contract reverts if the payout does not cover the gas. To release a withdrawal, the relayer also gets a signature from the deployment's enclave. ### How `fpc-funding` works Every deposit and withdrawal pays a small fee into the `FPCFunder` contract. The relayer calls it to swap those fees into fee juice and bridge them to the fee-paying contract on the Aztec Network. The bounty rises from 0.01% to 10% over the 24 hours after the last call. Only one call per Ethereum block succeeds. ### How `epoch-proofs` works When the prover tips and subsidy pay for an early proof, the relayer asks your prover node to prove the epoch up to the latest checkpoint, then claims the tips. The portal pays only if your prover node is set up for it: - Set `PROVER_NODE_PROOF_SUBMISSION_TARGET_ADDRESS` to the `firstProverProofSubmitter` address in the manifest. - Set `PROVER_ID` on the prover node to the relayer signer's address. Unset, the prover ID is the address of the prover node's publisher key, and the tips go nowhere. ## How transactions are submitted - **Ethereum mainnet.** The relayer submits through Flashbots Protect. Protect drops reverting transactions and keeps them out of the public mempool. `--flashbots-block-range` (default `5`) sets the Protect drop window. - **Sepolia.** The relayer submits to the public mempool through your RPC URL, so that RPC must accept transactions. A transaction that is included and then reverts still costs gas. `--flashbots-block-range` only sets the local expiry; expiring does not cancel a transaction or free its nonce. ## Run on staging Staging is Sepolia plus Aztec v5. The current deployment is `v12`, selected by its portal address. ```bash docker pull azteclabs/oxide-relayer:1.0.0 docker run --rm -it \ --name oxide-relayer-staging \ -v relayer-data:/data \ -e L1_PRIVATE_KEY=0x<64-hex-character-private-key> \ -e READ_L1_RPC_URL=https:// \ -e AZTEC_NODE_URL=https://testnet-v5.rpc2.aztec-labs.com \ -e AZTEC_NODE_API_KEY= \ azteclabs/oxide-relayer:1.0.0 \ run \ --deployment-env-manifest https://d1g9k2awa2mp7i.cloudfront.net/staging.v4.json \ --portal 0x12E9Bf217CF5566Bb82253C54400798205E1bE62 \ --signer env \ --modes l1-operations,fpc-funding \ --l1-min-priority-fee-gwei 1 ``` Set `--l1-min-priority-fee-gwei 1` on Sepolia. The default of `0.1` suits mainnet, but Sepolia builders order transactions by tip. ## Run on production Production is Ethereum mainnet plus Aztec v5. The current deployment is `v6`, selected by its portal address. The manifest is `https://d1ylrbyes5g693.cloudfront.net/prod.v4.json`. This example uses a keystore signer; the Signer section below says why. ```bash docker pull azteclabs/oxide-relayer:1.0.0 docker run -d \ --name oxide-relayer-production \ --restart unless-stopped \ -v relayer-data:/data \ -v /host/path/keystore.json:/run/secrets/relayer-keystore.json:ro \ -v /host/path/keystore-password:/run/secrets/relayer-keystore-password:ro \ -e READ_L1_RPC_URL=https:// \ -e AZTEC_NODE_URL=https://canonical.mainnet.rpc.aztec-labs.com/ \ -e AZTEC_NODE_API_KEY= \ azteclabs/oxide-relayer:1.0.0 \ run \ --deployment-env-manifest https://d1ylrbyes5g693.cloudfront.net/prod.v4.json \ --portal 0xdf410ad448A0f7165181FBdB32f8896f4a0d9449 \ --signer keystore \ --keystore /run/secrets/relayer-keystore.json \ --keystore-password-file /run/secrets/relayer-keystore-password \ --modes l1-operations,fpc-funding ``` The Aztec v5 mainnet RPC requires an API key, set with `AZTEC_NODE_API_KEY`. If you do not have one, ask the Oxide team, or run your own Aztec RPC. ## Signer **`--signer env`** reads the raw key from `L1_PRIVATE_KEY` (or the variable named by `--private-key-env`). Use it only on staging and for short-lived tests. **`--signer keystore`** reads an Ethereum V3 JSON keystore. Use it for anything longer-lived, and always on production. Give the password in a file with `--keystore-password-file`; a Docker run with no terminal cannot prompt for it: ```bash docker run --rm \ -v relayer-data:/data \ -v /host/path/keystore.json:/run/secrets/relayer-keystore.json:ro \ -v /host/path/keystore-password:/run/secrets/relayer-keystore-password:ro \ \ run \ \ --signer keystore \ --keystore /run/secrets/relayer-keystore.json \ --keystore-password-file /run/secrets/relayer-keystore-password ``` Never pass a secret as a command-line flag: other processes on the host can read the command line. Use a mounted file, or `--env-file`, which keeps the value out of the `docker run` line too. For production, pin the image. `azteclabs/oxide-relayer:1.0.0` is the current release; to fix the exact artifact, pin by digest. ## Submission policy Before it submits anything, the relayer simulates the transaction and estimates its gas, and it skips work whose reward does not cover that gas. **`--allow-unprofitable`** turns those checks off for `l1-operations` and `fpc-funding`. It does not affect epoch proofs. It is fine on staging with test ETH. On mainnet it can spend real ETH on gas that no reward pays back. For epoch proofs, set `--early-proof-proving-cost-per-checkpoint` to your off-chain proving cost. It and `--early-proof-min-profit` are USD amounts scaled by 10^18, and `--early-proof-min-profit-margin-bps` is in basis points of the reward. All three default to `0`. ## Dry run and emergency stop Add `--disable-submission`, or set `DISABLE_SUBMISSION=1`, and the relayer signs nothing and broadcasts nothing. `fpc-funding` and `epoch-proofs` do not start. `l1-operations` keeps finding and recording work, but does not screen, simulate or submit it. ## Address screening `l1-operations` always screens the target, the payout token, and every address in the simulation logs against the OFAC SDN list. A match blocks that operation permanently. That is narrower than what the wallet does. The wallet screens addresses through Predicate before a deposit or a withdrawal; see [Limits](/docs/limits). The examples above configure only the OFAC check, so a relayer run that way does not apply the wallet's policy. To apply it, set `--predicate-api-key` (or `OXIDE_RELAYER_PREDICATE_API_KEY`), `--predicate-verification-hash` and `--predicate-chain`. With all three set, Predicate screening runs in addition to the OFAC check. ## Check your configuration `run --help` lists every option with its environment variable and its default. If the environment sets a value, help shows that as the default. Secrets show as ``, and RPC URLs show only their origin, because providers put API keys in the path: ```bash docker run --rm --env-file relayer.env azteclabs/oxide-relayer:1.0.0 run --help ``` At startup the relayer logs its version, then `Starting relayer` with the resolved configuration, redacted the same way. ## Troubleshooting - **`missing required config`.** Check `--deployment-env-manifest`, `--portal`, the Ethereum RPC (`--read-l1-rpc` or `READ_L1_RPC_URL`) and the Aztec node (`--aztec-node` or `AZTEC_NODE_URL`). - **`no deployment with portal`.** Pick a portal address from the manifest's `deployments` array. - **Manifest validation error.** Your portal's entry must conform to schema v4, or the relayer does not start. - **`Not watching a deployment`.** The relayer cannot read an older deployment in the manifest, so it does not relay for it. Expected on production, where older deployments use a previous manifest format. - **`eth_simulateV1` error at startup.** Use an Ethereum RPC that supports it. - **`keystore signer requires --keystore-password-file`.** Mount a password file; Docker cannot prompt. - **A mode is enabled but submission is disabled.** Expected when you use the kill switch. - **Work deferred as `unprofitable`.** Expected under the default policy. On staging you can use `--allow-unprofitable`; on mainnet that flag can spend real ETH on work that does not pay. ## Configuration reference Every flag has an environment variable, and a flag overrides its variable. `run --help` prints the same list. ### Deployment and endpoints | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--deployment-env-manifest` | `OXIDE_DEPLOYMENT_ENV_MANIFEST_URL` | | Deployment manifest URL. | | `--portal` | `OXIDE_PORTAL` | | Portal of the manifest deployment to run. | | `--read-l1-rpc` | `READ_L1_RPC_URL` (fallback `L1_RPC_URL`, `ETHEREUM_HOST`) | | Ethereum read RPC. `l1-operations` needs `eth_simulateV1`; Sepolia also submits here. Must not be Protect. | | `--aztec-node` | `AZTEC_NODE_URL` (fallback `OXIDE_AZTEC_NODE_URL`) | | Aztec node URL. | | No flag | `AZTEC_NODE_API_KEY` (fallback `OXIDE_AZTEC_NODE_API_KEY`) | | Aztec node API key. Required for the Aztec v5 mainnet RPC. Secret. | ### Modes | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--modes` | `OXIDE_RELAYER_MODES` | `l1-operations` | Comma-separated modes. | | `--prover-node-url` | `OXIDE_RELAYER_PROVER_NODE_URL` | | Prover node RPC used to request early epoch proofs. Required by `epoch-proofs`. | ### Signer | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--signer` | `OXIDE_RELAYER_SIGNER` | `env` if the private key variable is set, otherwise `keystore` | Signer backend: `env` or `keystore`. | | `--private-key-env` | `OXIDE_RELAYER_PRIVATE_KEY_ENV` | `L1_PRIVATE_KEY` | Variable holding the raw Ethereum private key. | | `--keystore` | `OXIDE_RELAYER_KEYSTORE` | | JSON keystore path. | | `--keystore-password` | `OXIDE_RELAYER_KEYSTORE_PASSWORD` | | JSON keystore password. Secret. | | `--keystore-password-file` | `OXIDE_RELAYER_KEYSTORE_PASSWORD_FILE` | | File containing the keystore password. | | No flag | `L1_PRIVATE_KEY` | | Raw private key for `--signer env`, unless `--private-key-env` names another variable. Secret. | ### State | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--state` | `OXIDE_RELAYER_STATE_PATH` | `/data/oxide-relayer-{portal}.sqlite3` | SQLite state path. `{portal}` expands to each worker's portal. | ### Submission policy | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--disable-submission` | `DISABLE_SUBMISSION` | `false` | Disable signing and broadcasting. | | `--allow-unprofitable` | `OXIDE_RELAYER_ALLOW_UNPROFITABLE` | `false` | Submit L1 operations and FPC funding even when unprofitable. Does not apply to epoch proofs. | | `--l1-min-priority-fee-gwei` | `OXIDE_RELAYER_L1_MIN_PRIORITY_FEE_GWEI` | `0.1` | Floor for the priority fee. A higher market tip still wins. | | `--flashbots-block-range` | `OXIDE_RELAYER_FLASHBOTS_BLOCK_RANGE` | `5` | Protect drop window on mainnet. On Sepolia, the local expiry (12 s per block). | ### Screening | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--sdn-url` | `OXIDE_RELAYER_SDN_URL` | `https://sanctionslistservice.ofac.treas.gov/api/PublicationPreview/exports/SDN.XML` | OFAC SDN list that `l1-operations` screens against. | | `--predicate-api-key` | `OXIDE_RELAYER_PREDICATE_API_KEY` | | Predicate API key. With the hash and chain, adds Predicate screening to the OFAC check. Secret. | | `--predicate-verification-hash` | `OXIDE_RELAYER_PREDICATE_VERIFICATION_HASH` | | Predicate managed policy id, sent as `verification_hash`. | | `--predicate-chain` | `OXIDE_RELAYER_PREDICATE_CHAIN` | | Predicate chain name, e.g. `ethereum-mainnet`. | ### Epoch-proof policy | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--early-proof-min-profit` | `OXIDE_RELAYER_EARLY_PROOF_MIN_PROFIT` | `0` | Minimum partial-epoch proof profit, USD scaled by 10^18. | | `--early-proof-min-profit-margin-bps` | `OXIDE_RELAYER_EARLY_PROOF_MIN_PROFIT_MARGIN_BPS` | `0` | Minimum profit margin, in basis points of the reward. | | `--early-proof-proving-cost-per-checkpoint` | `OXIDE_RELAYER_EARLY_PROOF_PROVING_COST_PER_CHECKPOINT` | `0` | Off-chain proving cost per checkpoint, USD scaled by 10^18. | ### Advanced tuning The defaults suit most operators. Change these only to reduce RPC load or to debug. | Flag | Environment variable | Default | Description | | --- | --- | --- | --- | | `--l1-operations-poll-interval-ms` | `OXIDE_RELAYER_L1_OPERATIONS_POLL_INTERVAL_MS` | `10000` | Interval between L1 operation poll cycles. | | `--fpc-funding-poll-interval-ms` | `OXIDE_RELAYER_FPC_FUNDING_POLL_INTERVAL_MS` | `60000` | Interval between FPC funder bounty checks. | | `--l1-operations-retry-backoff-ms` | `OXIDE_RELAYER_L1_OPERATIONS_RETRY_BACKOFF_MS` | `30000` | Backoff before re-checking a deferred L1 operation. | | `--l1-operations-max-retries` | `OXIDE_RELAYER_L1_OPERATIONS_MAX_RETRIES` | `10` | Failed executor simulations before an L1 operation is dropped. | | `--log-scan-window` | `OXIDE_RELAYER_LOG_SCAN_WINDOW` | `1000` | Blocks per `eth_getLogs` call in the balance watcher's transfer scan. | --- # Privacy Policy Last updated: 15 September 2026 Obsidion Labs Limited (“Obsidion Labs,” “we” or “us,” or “our”) respects your privacy and is committed to protecting it through our compliance with this Privacy Policy. This Privacy Policy describes the types of information we may collect from you or that you may provide when you access or use the Services and our practices for collecting, using, maintaining, protecting, and disclosing that information. If you’re a resident of the United Kingdom, California, Washington, or Nevada or from the European Economic Area (“EEA”), you should read this Privacy Policy and the applicable sections below. Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. By accessing or using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, you must not access or use the Services. This Privacy Policy may change from time to time (see “Modifications to this Privacy Policy” Section below). Any changes to this Privacy Policy will be effective immediately upon posting the updated Privacy Policy unless otherwise stated or as required by applicable law. Your continued use of this Services after we make changes is deemed to be acceptance of those changes to the fullest extent permitted by applicable law, so please check the policy periodically for updates. Terms not defined in this Privacy Policy shall have the meanings as set forth in Obsidion Labs’s Terms of Use, which can be found at [https://docs.zk.money/terms](/terms). We are committed to maximizing privacy through mathematics rather than mere promises. By leveraging zero-knowledge proofs (“ZKPs”), the Services are architected to execute cross-chain asset transfers without exposing public transaction links between your source and destination addresses. The core function of our Services rely on zero-knowledge cryptography. This architectural choice ensures that: - Your sensitive transaction details are never revealed on-chain. - Your private inputs never leave your local environment. ## I. Scope of Privacy Policy This Privacy Policy applies to all aspects of our Services as well as to information we may collect offline and on-chain. The Services may link to or incorporate websites or content hosted and served by others over which we have no control, such third-party websites, online properties, platforms, social media, or systems, which are each governed by the privacy policies and business practices of third parties. You understand and agree that Obsidion Labs is not responsible for the security, privacy, or business practices of any third party. This Privacy Policy applies to information we collect: - through communications between you and the Services; - in email, text, or other electronic correspondences and interactions between you and us; - automatically as you use or access the Services; and - through third-party applications and links. ## II. Information We Collect We collect the following categories of information in connection with your use of the Site and the Services: - **User Information.** We collect information by which you may be personally identified, such as name, e-mail, location information, social media information (including, but not limited to, X handles), other identifier by which you may be contacted online or offline (including, but not limited to, cookie identifiers, usage details, other tracking technologies), and any other personal information that you provide to us. - **Wallet Connection Information.** When you voluntarily connect a publicly available blockchain wallet address to access the Services, we process that public address to enable wallet connection, surface on-chain positions and activity, and facilitate on-chain interactions you initiate. We do not have access to your private keys or seed phrase and cannot initiate transactions on your behalf. - **Technical and Device Information.** We and our Third-Party Services may automatically collect technical information when you access the Site, such as IP address (which may be truncated or anonymized where configured), browser type, operating system, device type, language preferences, referring URLs, internet connection, and diagnostic information. We use this information to maintain security, prevent fraud and abuse, measure performance, and debug issues. - **Fees.** With respect to any paid feature (if and once available), we (or our third-party payment processor) collect information necessary to process your transaction, such as your name, billing address, email address, and/or payment card details. Payment card information is collected and processed directly by our third-party payment processor and is not stored on our servers. We retain records of transactions, subscription tier, billing cycle, and payment history to manage your handle, process renewals or cancellations, provide receipts, prevent fraud, and comply with tax and accounting obligations. - **Referral Program Information.** If you participate in our referral programs, we may collect information necessary to attribute and credit referrals, including the identities of the referring and referred handles. - **Usage Data.** We may collect information about your interactions with the Site and the Services, such as pages viewed, features used, links clicked, time and duration of visits, and referral sources. We use this information to operate, maintain, and improve the Services, including user experience and performance. - **Location Data.** We may derive coarse location information from IP addresses or similar signals to enforce geographic restrictions, such as blocking access from jurisdictions where use of the Services is not permitted under our Terms of Use. - **On-Chain Data.** We may surface publicly available on-chain information associated with your connected Wallet or other electronic wallet, including transaction hashes, amounts, timestamps, positions, block proposals submitted by builders (block headers, bid amounts, builder identities), block contents for verification purposes, MEV-Boost configuration details from validator connections, and funding or fee activity. - **Cookies and Similar Technologies.** We and our third-party infrastructure and analytics providers may use cookies, pixels, web beacons, and similar technologies to collect and store the types of information described above. Further information can be found in the “Cookie Policy” Section below. ## III. Use of Personal Information We use the personal information that we collect: - to present our Services and its contents to you; - to make our Site and Services more intuitive and easier to use, we use device data, cookies and other information that you may provide; - to provide relevant marketing including providing you with information about events or services that may be of interest to you; - to provide you with notices about your account, including expiration and renewal notices; - to carry out our obligations and enforce our rights arising from any contract entered into between you and us; - to carry out any other business purpose for which the information was collected; - in any other way we may describe when you provide the information; and - to fulfill any other purpose for which you provide it. We may also use automated technologies to collect information about your equipment, browsing actions, and usage patterns. The information we obtain in this manner may include your device IP address, identifiers associated with your devices, types of devices connected to our services, web browser characteristics, device characteristics, language preferences, referring/exit pages, clickstream data, and dates and times of visits to our Site and Services. The information we collect through cookies and similar technologies helps Obsidion Labs: (1) remember your information so you will not have to re-enter it; (2) understand how you use and interact with our products and website; (3) measure the usability of our products and website and the effectiveness of our communications; and (4) otherwise manage and enhance our Services and Site, and help ensure they are working properly. We may create aggregated, de-identified and/or anonymized data from your personal information and other individuals whose personal information we collect. We make personal information into de-identified and/or anonymized data by removing information that makes the data identifiable to you. We may use this aggregated, de-identified and/or anonymized data and share it with third parties for our lawful business purposes, including to analyze and improve the Site, Services, and promote our business, and to train our artificial intelligence models and for other machine learning purposes; We may also collect transaction-related information (such as preferred means of payment, billing information, billing address, and/or a history of purchases through our Site). Your browser may tell you how to be notified when you receive certain types of cookies or how to restrict or disable certain types of cookies. Please note, however, that without cookies you may not be able to use all of the features of our Site. ## IV. Marketing Choices You have control regarding our use of personal information for direct marketing. In certain markets, you will need to expressly consent before receiving marketing. In all markets, you can choose to not receive marketing communications at any time. If you no longer wish to receive marketing communications from Obsidion Labs, or remain on a mailing list to which you previously subscribed, or receive any other marketing communication, please follow the unsubscribe link in the relevant communications or contact us as specified below. ## V. How We Share Your Information We may disclose personal information that we collect or you provide as described in this Privacy Policy: - to our subsidiaries and affiliates; - with vendors, consultants and other service providers who need access to such information to carry out work on our behalf; - in response to a request for information if we believe disclosure is in accordance with any Applicable Law, regulation or legal process, or as otherwise required by any Applicable Law, rule or regulation; - to comply with any court order, law, or legal process, including to respond to any law enforcement, government, or regulatory request; - if we believe your actions are inconsistent with our user agreements or policies, or to protect the rights, property and safety of us or any third-party; - in connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition of all or a portion of our business to another company; - with your consent or at your direction; and - we may also share aggregated or de-identified information, which cannot reasonably be used to identify you. ## VI. Cookie Policy We may use cookies and similar tracking technologies (“Cookies”) to automatically track user activity. Cookies help us authenticate requests, remember preferences, enhance performance and security, and understand how the Site is used. Cookies are small pieces of data placed on your computer, phone, or other device that you use to access the Services. A banner or other tool will be presented to you to make decisions about Cookies that are not strictly necessary. You also have the ability to manage Cookies through your personal browser settings. Please be aware that disabling certain Cookies may impair Site or Services functionalities. ## VII. Artificial Intelligence Artificial intelligence (“AI”) technologies, such as those provided by our AI platform providers, OpenAI, Anthropic, Google, and AWS are used to operate the chat and/or user input/prompt features that you can use to communicate with us and/or input your prompts and other data through the Site or Services. WE ADVISE AGAINST SHARING PERSONAL INFORMATION IN CHATBOT INTERACTIONS. ## VIII. Legal Bases for Processing (For EEA and other Users) **Specific Provisions for EU-Residents.** This Section VIII applies to you, if you are from the European Union. Obsidion Labs adopted the following provisions, to comply with the EU 2016/679 Directive General Data Protection Regulation (“GDPR”), pursuant to which Obsidion Labs will be considered as a “Data Controller” with respect to our use of personal information of resident of the European Union. **Legal Basis.** We base our processing of any personal information as “Data Controllers” based on the following lawful grounds: Obsidion Labs relies, primarily, on your consent to the terms of this Privacy Policy as a legal basis for processing any personal information related to you or communicating any other promotional material and collecting and using your personal information when it is necessary for one of the legitimate uses set out in Section III above, which we believe are not overridden by your fundamental rights. We may process your personal information to comply with a legal obligation and to protect our users’ vital interests. If, at any time, you wish to exercise your rights in accordance with the provisions provided by law (including as provided under this Section and Section XIV of this Privacy Policy) you may send us an email to [company@obsidion.xyz](mailto:company@obsidion.xyz) and request: access your personal information together with information about how, and on what basis, such information is being processed. Should you desire to receive such information in a different format than the one that was provided to you, you can contact us via [company@obsidion.xyz](mailto:company@obsidion.xyz) and we shall use commercially reasonable efforts to accommodate your request, if applicable; rectify any of the personal information being held when such information is inaccurate; to delete or restrict access to your personal information in limited circumstances as described under the GDPR. Please note that if we need to delete any personal information related to you, as per your request, it can take time until we completely delete residual copies of such data from our servers and backup systems. Exercising this right will not affect the lawfulness of any previous processing activities based on consent that was lawfully obtained before its withdrawal and to obtain and reuse your personal information for your own purposes across different services, as part of your right to data portability. Please note that you have the right to complain to a Data Protection Authority about our collection and use of your Personal Information. For more information, please contact your local data protection authority in the European Economic Area (“EEA”). If you have any concerns with respect to our methods of processing any personal information related to you, or if you wish to withdraw your consent, for any reason, kindly let us know by sending an email to [company@obsidion.xyz](mailto:company@obsidion.xyz). If you reside in a country from the EEA, then, by agreeing to the terms of this Privacy Policy, you agree to Obsidion Labs sharing your personal information outside of the EEA. These transfers are subject to special rules under data protection laws. If this happens, we will ensure that the transfer will be compliant with data protection law and all personal information will be secure. Our standard practice is to use ‘standard data protection clauses’ which have been approved by the European Commission for such transfers. Obsidion Labs shall not charge you for requesting to exercise any of the aforementioned rights. Please also note that we cannot change, edit or delete information that is stored on a public blockchain. ## IX. Transfer of Personal Information to Other Countries We may transfer your personal information to countries outside of your country of residence, including, but not limited to the UK, as well as the United States. Personal information is not processed outside of the countries listed in this Privacy Policy. If you access the Site or Services from outside the jurisdiction where our servers are located, you consent to the transfer and processing of your information in accordance with this Privacy Policy and at your own risk, recognizing that the level of protection in such jurisdictions may be different from that of your home jurisdiction. ## X. State Privacy Rights If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia, you may have certain rights in relation to the personal information we collect from you. However, these rights are not absolute, and we may decline your request as permitted by law. These rights include: - Right to know whether or not we are processing your personal data; - Right to access your personal data; - Right to correct inaccuracies in your personal data; - Right to request the deletion of your personal data; - Right to obtain a copy of the personal data you previously shared with us; - Right to non-discrimination for exercising your rights; and - Right to opt out of the processing of your personal data if it is used for targeted advertising (or sharing as defined under California’s privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects (“profiling”). Depending on the state you live in, you may also have the following rights: - Right to access the categories of personal data being processed (as permitted by applicable law, including the privacy law in Minnesota); - Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in California, Delaware, and Maryland); - Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in Minnesota and Oregon); - Right to review, understand, question, and correct how personal data has been profiled (as permitted by applicable law, including the privacy law in Minnesota); - Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including the privacy law in California); and - Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including the privacy law in Florida). To exercise these rights, please contact us at: [company@obsidion.xyz](mailto:company@obsidion.xyz). If you are a California resident, you have the right to request that Obsidion Labs disclose the specific personal information and categories we have collected about you. To request this information, please contact us at: [company@obsidion.xyz](mailto:company@obsidion.xyz). You can also request to have your personal information deleted that has been collected about you. To submit a deletion request, please contact us at: [company@obsidion.xyz](mailto:company@obsidion.xyz). We may not be able to accommodate a request if we believe that it would violate any law or legal requirement. ## XI. How We Protect Your Information Protecting your information is important to us. We maintain administrative, technical and physical safeguards designed to protect against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use of Personal Information. ## XII. How Long We Retain Your Information We strive to keep your personal information only for the period of time needed for legitimate business purposes. In certain circumstances, however, legal or regulatory obligations may require us to retain records for a longer time than we otherwise would. ## XIII. Children’s Information The Site and Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from individuals under the age of 18. If you believe that an individual under the age of 18 has provided us with Personal Information, please contact us, and we will take appropriate steps to delete such information where feasible. ## XIV. Your Rights If you are resident in countries with applicable data privacy laws you have the right, subject to certain exceptions, to request a copy of the personal information we are processing about you, to require that any incomplete or inaccurate personal information is amended, to request that we delete your personal information (although we may not be able to delete certain data due to legal or other obligations), to object to the use of your personal information or to withdraw consent. You may also have a right to lodge a complaint with the local data protection authority if you believe that we have not complied with the applicable data protection laws. You may also contact us to address and resolve concerns you may have about our use of your Personal Information. Please contact us at [company@obsidion.xyz](mailto:company@obsidion.xyz). ## XV. Modifications To This Privacy Policy We may update this Privacy Policy from time to time including in response to changing legal, technical, or business developments. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Policy changes if and where this is required by applicable data protection laws. You can see when this Privacy Policy was last updated by checking the last updated date displayed at the top of this Privacy Policy. It is your responsibility to check the last updated date. ## XVI. Third-Party Services, Applications, and Websites Certain Third-Party Services, websites, or applications you use, or navigate to or from our Site or Services or made available by using our Site or Services may have separate user terms and privacy policies that are independent of this Privacy Policy. We are not responsible for the privacy practices of these Third-Party Services or applications. We recommend carefully reviewing the user terms and privacy policy of each Third-Party Service, website, and/or application prior to use. ## XVII. Data Security **Our Security Safeguards.** We have established commercially reasonable safeguards to protect the information we collect from loss, misuse, and unauthorized access, disclosure, alteration and destruction, but we cannot guarantee that your information will never be disclosed in a manner inconsistent with this Privacy Policy (e.g., as a result of unauthorized acts by third parties that violate Applicable Law, or our or our affiliated providers’ policies). Please be aware that despite our efforts, no data security measures can guarantee 100% security. While we strive to use commercially acceptable means to protect your personal information and data, we cannot guarantee its absolute security. Any natural or legal person who processes the data on behalf of Obsidion Labs may have access to your personal information or data. These third-party vendors collect, store, use, process and transfer information about your activity on our platform in accordance with their respective privacy policies. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, OBSIDION LABS DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, REGARDING THE SECURITY OF YOUR PERSONAL INFORMATION, AND SHALL NOT BE LIABLE FOR ANY UNAUTHORIZED ACCESS TO, DISCLOSURE OF, ALTERATION OF, OR DESTRUCTION OF YOUR PERSONAL INFORMATION, EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW. ANY LIMITATIONS OF LIABILITY SET FORTH IN THE TERMS OF USE ARE INCORPORATED HEREIN BY REFERENCE. **Your Obligations.** You may log in to your account using third-party credentials or by connecting a digital asset wallet. We may use authentication technologies to register or authenticate you and enable you to use the Site. You are responsible for preventing unauthorized access to your Wallet, other electronic wallet, account, and personal information by appropriately safeguarding all credentials and access methods associated with your use of the Services and the Site, including passwords, private keys, seed phrases, recovery codes, and access to your computer, device, and browser, and by logging out or disconnecting your wallets when you have finished using the Services or the Site. We are not responsible for any lost, stolen, or compromised credentials or access methods, or for any unauthorized activity conducted through your account or connected wallet. ## XVIII. Governing Law This Privacy Policy shall be construed in accordance with and governed for all purposes by the substantive laws of the British Virgin Islands without regard to conflicts of law provisions. The exclusive jurisdiction for all disputes will be in the British Virgin Islands, and you and the Company each waive any objection to such jurisdiction and venue. ## XIX. Contact Us If you have any questions about this Privacy Policy, please contact us via [company@obsidion.xyz](mailto:company@obsidion.xyz). --- # Terms of Use Last updated: 15 September 2026 Please read the following Terms of Use (the “Terms”) carefully before using, interacting with or accessing the website at zk.money (the “Site”), and the tools, products, and services (provided through desktop applications, mobile applications, or otherwise), including any and all content, features, functionality and all information submitted through them (together with the Site, the “Services”). These Terms constitute a binding agreement between you, whether personally or on behalf of an entity you represent (“you,” “your,” or “user”) and Obsidion Labs Limited (“Obsidion Labs”, “we”, “us”, “our”). Your viewing, access and use of, or interaction with, the Services constitutes your agreement to these Terms and our [Privacy Policy](/privacy-policy), and any other additional terms and conditions and policies referenced herein or made available by us or through our Services. You understand that these Terms govern all aspects of your relationship with Obsidion Labs. If you do not agree to be bound by these Terms, you must not access, view, interact with or use the Services. NOTICE: THESE TERMS CONTAIN A BINDING INDIVIDUAL ARBITRATION AGREEMENT AND CLASS ACTION WAIVER IN SECTION 18. THIS AFFECTS THE REMEDIES AVAILABLE TO YOU AND YOUR RIGHTS WITH RESPECT TO ANY “DISPUTE” BETWEEN YOU AND OBSIDION LABS AND MAY REQUIRE YOU TO RESOLVE DISPUTES IN BINDING, INDIVIDUAL ARBITRATION, AND NOT IN COURT. PLEASE READ THIS ENTIRE AGREEMENT, INCLUDING THAT SECTION, CAREFULLY. ## 1. Changes to these Terms We may update, amend, alter, or modify these Terms at any time in our sole discretion. All changes are effective immediately when we post them, and apply to all access to and use of the Services thereafter. Your continued access or use of any of the Services following such changes to these Terms shall indicate your acknowledgement of and your agreement to be bound by them. You are expected to visit this page periodically to review these Terms so that you are aware of any changes. If you do not agree to the amended Terms, you must stop using the Services. ## 2. Eligibility The Services are intended only for users who are eighteen (18) years of age or older. By accessing or using any of the Services, you represent that you are at least 18 years of age and have the full right, power, and authority on behalf of yourself or the entity that you represent to bind yourself and comply with these Terms. You may not access, view, interact with or use the Services if you are a resident of the United Kingdom. ## 3. zk.money The Services may provide you with access to certain functionalities including the use of oxide and zk.money (collectively “zk.money”). zk.money is a non-custodial, permissionless software infrastructure that users can use to enable digital transactions, including stablecoins such as DAI, cryptocurrencies, tokens, and other blockchain-based assets (collectively, “Digital Assets”). ### Key Infrastructure Components **Oxide Protocol.** Oxide is a protocol that runs "alongside" the Aztec Network that provides an independent layer of security against vulnerabilities in the Aztec Network's proving system. It requires that users simulate the Aztec Network transaction they intend to perform, such as a transfer within the Aztec Network or a withdrawal to Ethereum, and send the results of that simulation to an AWS Nitro Enclave which returns a signature attesting to the validity of the operation If the Aztec Network suffers a liveness failure and the underlying portal is frozen, users can exit directly to the Ethereum portal. Anyone can run an enclave. See for a technical description of the Oxide protocol. Oxide is composed of the following key components: - **Oxide Enclaves.** verify transaction inputs and outputs against the Aztec state as a second-factor of authorization. Oxide Enclaves never receive users’ signing keys. - **Provers.** Provers are generic provers of Aztec blocks. **zk.money Protocol.** zk.money is a non-custodial private Digital Asset protocol that runs on top of Oxide. zk.money is composed of the following key components: - **ENS Handles.** Users may set up ENS handles through oxide, which includes setting up an ENS CCIP subdomain. - **Segregated Incoming Payment Address (“SIPA”) Resolver.** Notifies the user and relayers when a payment arrives. The Resolver never holds funds and cannot redirect users’ transactions. - **Credentials.** Users’ credentials may be setup through an authenticator that supports pseudo-random function (“PRF”), including, but not limited to, Passkey, Apple’s native implementation, and 1Password. - **Links.** Users have the ability to send Digital Assets through links using recipients’ smart contract addresses or ENS handles (the “Links”). Recipients may claim sent Digital Assets by proving ownership of that identifier. Users will also be able to send links that may be claimable by anyone with the link and also use links to receive Digital Assets. Obsidion does not custody Digital Assets or control Links’ intended recipient. - **Requests.** A user may request that a certain amount of Digital Assets be paid. These requests are sent to a contract via XMTP or as a shareable link. For further information on zk.money, please refer to (“zk.money docs”). In case of any inconsistencies between zk.money as described in these Terms or zk.money docs, the zk.money docs shall prevail at all times. ### Key Features of zk.money - **Non-custodial.** zk.money is non-custodial and self-directed. Obsidion Labs does not custody or control users’ Digital Assets, nor does it have access to or hold private keys. We are not a counterparty to transactions that are conducted through zk.money. We cannot access, transfer, recover, reverse, or freeze your Digital Assets on your behalf. You are solely responsible for correctly identifying intended recipients of your Digital Assets. - **Non-controlling.** - zk.money smart contracts are not upgradeable at the discretion of Obsidion Labs, or any other party. Where any upgrade mechanism exists, it: (a) is limited to security patches, bug fixes, and infrastructure enhancements; (b) requires multisig authorization and cannot be exercised unilaterally by any single party; and (c) does not give any party the ability to access, freeze, seize, or redirect user funds. - zk.money functions solely as infrastructure. Obsidion Labs is not a party to, or required to execute or facilitate, any transfer between users; transfers occur directly between users through the operation of software. - Relayer functionality, where used, may be operated by independent third parties, including users themselves. Obsidion Labs does not operate a relayer, control relayer selection, or profit from relayer activity. - **Transaction Limits.** Transactions conducted through immutable smart contracts and associated with zk.money may be subject to limits on transaction volume, value, and frequency (the “Transaction Limits”). The per-transaction Transaction Limits on deposits, transfers, and withdrawals are capped at two thousand five hundred dollars (US$2,500) per transaction. Daily Transaction Limits for aggregate deposits are capped at fifty thousand dollars (US$50,000) per day. These transaction limits are coded into the zk.money smart contracts and are not changeable. ## 4. Intellectual Property Ownership You acknowledge and agree that all legal right, title and interest in the Services and their contents, features, and functionality (including, but not limited to, all information, software, text, displays, images, video, and the design, selection, and arrangement thereof) and other third-party content, are/may be owned by Obsidion Labs, its licensors, or other providers of such material and are protected by the British Virgin Islands and international copyright, trademark, patent, trade secret, and other intellectual property or proprietary rights laws. Subject to your compliance with these Terms, we hereby grant you a limited, personal, non-exclusive, nontransferable, non-assignable, non-sublicensable, revocable license to use the Services for the limited purpose it is provided to you, solely in accordance with these Terms. This license is effective until terminated. We may terminate or suspend any or all portions or features of the Services at any time and for any reason or for no reason with no liability to you. Except for the limited license provided in this Section, nothing in these Terms grant you any right, title, or interest in or to any intellectual property rights in or relating to the Services. There are no implied licenses granted under these Terms unless expressly stated in these Terms. By using the Services, you grant us a limited, non-exclusive, sublicensable, worldwide royalty free license to use, copy, modify and display any content you provide to us or that you post on or through any of the Services solely for our business purposes, including but not limited to the purpose of providing the Services for so long as is necessary to do so. Obsidion Labs and zk.money’s name, and all trademarks, logos, taglines, service names, designs, and slogans on the Services are trademarks of Obsidion Labs or its affiliates or licensors. You must not use such marks without our prior written permission. All other trademarks not owned by us that appear on the Site are the property of their respective owners, who may or may not be affiliated with, connected to, or sponsored by us. ## 5. No Responsibility for Wallets or Digital Assets You may be required to connect your self-custodial, self-hosted digital asset wallet (“Wallet”) in order to access the Services. You acknowledge and agree that we cannot control, provide guarantees for, or access your Wallet, Digital Assets, or its private keys and that you are solely responsible for your Wallet security and familiarizing yourself with it and its safety and security features, including any private keys and passwords associated therewith. You should consult the terms of service provided by your Wallet provider to understand your rights and responsibilities as they relate to your Wallet. This also means that we are unable to assist with transactions: please be vigilant in interacting with Ethereum or Aztec or any other immutable blockchain technology. You are solely responsible for transactions involving your own Digital Assets, and we expressly disclaim any liability for any losses or changes in value of your Digital Assets in connection with your use of the Services. ## 6. Acknowledgement and Assumption of Risk Blockchains and their attendant technologies involved in using any Services are novel, technologically complex, and involve inherent risk, protocol upgrades and other technological mechanisms may contain bugs or security vulnerabilities that may result in loss of functionality and ultimately of funds, and the Services involve technological innovations such that the results of usage of or interaction with them depend on factors beyond our control, including but not limited to network health, congestion, latency, incentives, user configuration settings, operation of third party software or hardware, wallet or account compatibility, protocol upgrades or forks, the activities of searchers, block builders and others. You acknowledge and agree that there are risks associated with using the Services. You should also familiarize yourself with the risks involved with transacting on blockchain networks, including but not limited to smart contract vulnerabilities, front end vulnerabilities, hacks, phishing attacks, social engineering attacks, risks of losing access to Digital Assets due to loss of private keys, Digital Asset volatility, and transaction irreversibility. You understand that like any other software, the Services could be at risk of third-party malware, hacks or cybersecurity breaches. You agree that it is your responsibility to monitor your Digital Assets, Wallet, and account regularly and confirm their proper use and deployment consistent with your intentions. We do not and cannot guarantee the security, performance, or reliability of the protocol, or any associated blockchain networks, protocols or tools. We do not authorize, control, or endorse the purchase or sale of Digital Assets and are not liable to you for any losses that you may incur in connection with purchasing or selling Digital Assets. ## 7. Representations You represent and warrant that (i) you are solely responsible for (a) properly configuring and using the Services and for taking appropriate action to secure your data and devices when doing so, including without limitation, financial information, Digital Assets, authentication service passwords and data (e.g., Passkeys), and private keys, (b) verifying the details of any transaction submitted through the Services, (c) verifying recipient information (including, but not limited to, ENS handles, smart contract addresses), and (d) withholding, filing, collecting, reporting, and remitting all taxes, duties and other governmental assessments associated with your Digital Assets and activity in connection with the Services; (ii) you have read and understand these Terms; (iii) you are eighteen (18) years of age or older; (iv) you have the financial and technical sophistication to properly use, access and interact with the Services and that you understand the inherent risks of blockchain technology, Digital Assets, and smart contracts, among other related technologies; (v) you do not have a right against us to request a refund for any Digital Asset; (vi) you are using and accessing the Services on your own initiative and are responsible for compliance with all laws, including your local laws; (vii) all use and interaction of the Services is entirely at your own risk; (viii) the Services may not be available without interruption or for any particular duration, and we shall not be responsible for any losses, damages, costs, expenses, lost opportunities or other harm suffered by you in connection with any interruption or termination of the Services; (ix) you are solely responsible for any fees relating to transactions on any blockchain, including any transaction (or "gas") fees. You further acknowledge and agree that use of the Services may carry financial risk. You understand that blockchains and the applications built thereon are inherently risky and highly experimental by their nature and could result in the loss of the full amount supplied, and that Digital Assets are neither deposits of or guaranteed by any bank nor insured by the FDIC or by any other government agency. Transactions entered into in connection with Ethereum, Aztec, or other blockchains are irreversible and final. You acknowledge and agree that you will access and use the Services at your own risk. The risk of loss in transacting in Digital Assets can be substantial. You further represent that: - your access to the Services is not (1) prohibited by and does not otherwise violate or assist you to violate any domestic or foreign law, rule, statute, regulation, by-law, order, protocol, code, decree, or another directive, requirement, or guideline, published or in force that applies to or is otherwise intended to govern or regulate any person, property, transaction, activity, event or other matter, including any rule, order, judgment, directive or other requirement or guideline issued by any domestic or foreign federal, provincial or state, municipal, local or other governmental, regulatory, judicial or administrative authority having jurisdiction over us, you, the Services, or as otherwise duly enacted, enforceable by law, the common law or equity (collectively, "Applicable Laws"); or (2) contribute to or facilitate any illegal activity. You represent and warrant that you will comply with all Applicable Laws, and you will not use the Services if the laws of your country, or any Applicable Law, prohibit you from doing so; and - you and for the duration of the time that you use the Services, (a) will not be the subject of economic or trade sanctions administered or enforced by any governmental authority or otherwise designated on any list of prohibited or restricted parties; (b) will not be in contravention of any laws and regulations pertaining to anti-money laundering or terrorist financing; (c) will not be included on the List of Specially Designated Nationals and Blocked Persons maintained by the U.S. Treasury Department’s Office of Foreign Assets Control (“OFAC”) or on any sanctions list of the United Kingdom Foreign, Commonwealth & Development Office (“FCDO”) and/or pursuant to the European Union (“EU”) regulations; (d) will not be located, ordinarily resident, organized, established, operationally based, or domiciled in the United Kingdom or the State of New York (USA); (e) will not be located, ordinarily resident, organized, established, operationally based, or domiciled in Cuba, Iran, North Korea, the Crimea, Donetsk and Luhansk Regions of Ukraine, or any other country or territory in which sanctions imposed by the United Nations (whether through Security Council or otherwise), OFAC, the EU or FCDO apply, or otherwise pursuant to sanctions imposed by the U.N., OFAC, FCDO, or the EU; and (f) will not be engaged in the business of offering illegal or controlled products or services including, without limitation, firearms, explosives, dangerous materials, drugs, pornography, illegal gambling, human trafficking, wildlife trade, products and services derived from endangered or threatened species or other activities which may be considered illegal, dangerous or harmful; and (g) shall not and will not allow restricted persons to use a virtual private network (e.g., a VPN) or other means to inappropriately/evasively access any of the Services. If you do not meet the aforementioned requirements, you must immediately cease accessing or using the Services. ## 8. Fees The zk.money protocol funds its sponsorship of your network transaction fees through a small deduction taken automatically as part of transaction flows (the “FPC Funding Fee”). The FPC Funding Fee may be deducted by the underlying smart contracts as part of the transaction itself; it is not billed to you separately. Depending upon your transaction path, FPC Funding Fees may be deducted from transfer amounts through self-service and relayer-swept transactions. Certain transactions may be eligible for network fee sponsorships through fee juice balances. Changes to any fee structure should be expected over time. ## 9. Access and Use; Prohibited Conduct To access the Services, you may be asked to provide certain registration or other information. It is a condition of your use of the Services that all of the information you provide in connection with the Services is correct, current, and complete. You also agree to pay us any applicable fees we may charge in connection with your use of the Services. If you choose or are provided with a username, password, or any other information as part of our security procedures, you must treat such information as confidential, and you must not disclose it to any other person or entity. Your account is provided through blockchain-based smart contracts and is not controlled by us. You also acknowledge that your account is personal to you and agree not to provide any other person with access to the Services or portions of it using your username, password, or other security information. You agree to notify us immediately of any unauthorized access to or use of your username, password, or any other breach of security. We may suspend or terminate your account and your ability to use the Services or portions thereof for failure to comply with the Terms. When registering for the Services, you may be asked to select a user registration handle. User registration handles are not guaranteed and are not owned by you. Obsidion Labs reserves the right to revoke, suspend, or terminate any user handle. Your use of a registration handle may be contingent upon your subscribing to paid subscriptions. You acknowledge and agree that any data provided to you through the Services is for your internal use only, and may not be directly resold or sublicensed to third parties. You agree to access, use or otherwise interact with the Services only in an authorized, proper and appropriate manner and in accordance with these Terms and with all Applicable Laws. You agree, in connection with the Services, not to: - violate the Terms; - violate any Applicable Laws or regulations through your access to or use of the Services; - share any information with us or through the Services in violation of any law. - exploit the Services for any unauthorized purpose, or use them in a malicious way that is either illegal or causes negative impact to the network; - harvest or otherwise collect information from the Services for any unauthorized purpose; - use the Services in any manner that could disable, damage or impair them or otherwise interfere with them in any way; - sublicense, sell, or otherwise distribute the Services, or any portion thereof; use any data mining tools, robots, crawlers, or similar data gathering and extraction tools to scrape or otherwise remove data from the Services; - use any manual process to monitor or copy any of the material on the Site or that is included in the Services or for any unauthorized purpose without our prior written consent; - interfere with or compromise the integrity, security, or proper functioning of any computer, server, network, personal device, or other information technology system, including, but not limited to, the deployment of viruses, trojan horses, worms, logic bombs, or other material which is malicious or technologically harmful to the Services, attempt to gain unauthorized access to, interfere with, damage, or disrupt any parts of the Services; or attack the Services via a denial-of-service attack or a distributed denial-of-service attack or otherwise attempt to interfere with the proper working of the Services; - seek to circumvent a usage or capacity limit of any of the Services; - defraud any person or entity, including but not limited to providing any false, inaccurate, or misleading information in order to unlawfully obtain the property of another; - copy, modify, or create derivative works based on the Services; - submit or share information that contains misrepresentations, inaccuracies, false statements, or defamatory, offensive, obscene, racist, indecent, abusive, harassing, violent, or otherwise objectionable content; - violate any Applicable Law, rule, or regulation concerning the trading of securities, derivatives, or commodities or violates any applicable sanctions or trade embargo laws; - violate any Applicable Laws or regulations through your access to or use of the Services; - violate any other Applicable Law, contract, intellectual property right or other third-party right or commit a tort; or - any attempt to reverse engineer, disassemble, decompile, decode, adapt, or otherwise attempt to derive or gain access to any component of the Services, in whole or in part. In the event that you use a Services in a prohibited manner or for any other reason we determine, in our sole discretion, we may investigate or take any other action we deem necessary, including but not limited to taking action to terminate your ability to use or access the Services or bringing legal action against you if your use or access of the Services results in harm or damage to us, to rectify the prohibited conduct or any consequences resulting therefrom and we may consult and cooperate with law enforcement authorities where and when we deem appropriate or necessary, in our sole discretion. ## 10. Termination We may, at any time and at its sole discretion, suspend, terminate, deactivate, and delete your access to all or any part of the Services with or without notice to you for any reason or for no reason at all, including without limitation if: (i) you breach any provision of these Terms; or (ii) you infringe any intellectual property rights of Obsidion Labs or any third party. We reserve the right to take necessary legal action in connection with suspected illegal or unauthorized use of the Services, including but not limited to obtaining a court order, reporting such activity to law enforcement or other applicable regulatory authority. ## 11. Third-Party Information or Services The Services may be integrated with or otherwise give access to applications, services, websites, tools, technology, data, operations, features or resources that are provided or otherwise made available by third parties (“Third-Party Services”), including without limitation, authentication services (e.g., Passkeys), Ethereum network, the Aztec network, stablecoin issuers, Github, Domain registrar and DNS, AWS (including AWS Nitro), Ethereum Name Service, Uniswap, Curve, and TRM Labs. If the Services contain links to such Third-Party Services, they are provided for your convenience only. We have no control over the content of those sites or resources, and accept no responsibility for them or for any loss or damage that may arise from your use of them. If you decide to access Third-Party Services integrated with or linked to the Site or any Services, you do so entirely at your own risk and subject to the terms and conditions of use, privacy policies, or other agreements with those third parties that are applicable to those Third-Party Services, which we do not control and otherwise may have no relationship with. Please review any applicable terms, policies or agreements of Third-Party Services prior to engaging with them. We reserve the right to withdraw linking permission without notice. We have no control over and are not responsible for such Third-Party Services, including the accuracy, availability, reliability, verification or completeness of information or content shared by or available through Third Party Services, or the privacy practices of such services. Your use of Third-Party Services is directly between you and that third party, and you acknowledge and agree that we are not responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with your use of or reliance on any Third-Party Services. ## 12. Feedback You may voluntarily post, submit or otherwise communicate to us through any means, including through the Site and third-party channels (e.g., Discord), with questions, comments, suggestions, ideas, original or creative materials or other information in connection with the Services (collectively, “Feedback”). By posting or submitting any Feedback to us, you hereby irrevocably grant to Obsidion Labs a worldwide, perpetual, irrevocable, royalty-free, and fully sublicensable license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform and display such Feedback (in whole or in part) in any media and to incorporate the Feedback into other works in any format or medium now known or later developed. You understand that Obsidion Labs may treat Feedback as nonconfidential. ## 13. Reliance on Information You acknowledge and agree that all information displayed, presented on, or provided through the Services is for informational and educational purposes only and should not be construed as legal, financial, investment, or tax advice. We do not warrant the accuracy or completeness of such information. The availability of certain Digital Assets through the Services does not constitute an endorsement or solicitation or a recommendation to purchase such Digital Asset(s). We are a software provider and do not endorse any Digital Assets that are displayed or otherwise made available through the Services. Any fee figure presented before confirmation is an estimate and may vary from the amount actually paid. ## 14. Disclaimers and No Warranties We make no representation or warranties about the completeness, quality, functionality, accuracy, reliability, security or availability of the Services. We reserve the right to modify, suspend, or discontinue any feature or functionality of the Services at any time with or without notice to you, and we shall not be liable to you or to any third party should we exercise such rights. The technologies on which the Services rely may be subject to sudden changes and we cannot and do not guarantee that your access to or use of the Services will be uninterrupted or error free. You assume all risks related thereto. We make no claims that the Services or any of its content is accessible or appropriate in your country. We do not have any maintenance, update, or support obligations with respect to any of the Services. You agree that our updates to any of the Services may change the requirements necessary to use such Services, and you agree that in such an event you are responsible for any necessary actions, including but not limited to updating software or hardware to access and use such Services. To the fullest extent provided by law, we will not be liable for any loss or damage caused by a distributed denial-of-service attack, viruses, or other technologically harmful material that may infect your, or any end user’s, computer equipment, computer programs, data, or other proprietary material due to your use of the Services or information obtained through the Services or to your downloading of any material posted on it, or on any website linked to it. YOU ACCEPT THE INHERENT SECURITY RISKS OF PROVIDING INFORMATION AND DEALING ONLINE OVER THE INTERNET, YOU AGREE THAT WE HAVE NO LIABILITY OR RESPONSIBILITY FOR ANY BREACH OF SECURITY. YOU EXPRESSLY UNDERSTAND AND AGREE THAT YOUR ACCESS TO AND USE OF ANY OF THE SERVICES IS AT YOUR SOLE RISK, AND THAT ACCESS TO ANY OF THE SERVICES IS PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS. TO THE FULLEST EXTENT PERMISSIBLE PURSUANT TO APPLICABLE LAW, WE HEREBY DISCLAIM ALL WARRANTIES OF ANY KIND EITHER EXPRESS OR IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT AND ALL WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE. WITHOUT LIMITING THE FOREGOING, NEITHER OBSIDION LABS NOR ANYONE ASSOCIATED WITH OBSIDION LABS REPRESENTS OR WARRANTS THAT THE SERVICES OR INFORMATION OBTAINED THROUGH THE SERVICES WILL BE ACCURATE, RELIABLE, ERROR-FREE, FREE OF HARMFUL COMPONENTS, OR UNINTERRUPTED, THAT DEFECTS WILL BE CORRECTED, THAT OUR SERVICES OR THE SERVER THAT MAKES THEM AVAILABLE ARE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS, OR THAT THE SERVICES OR INFORMATION OBTAINED THROUGH THE SERVICES WILL OTHERWISE MEET YOUR NEEDS OR EXPECTATIONS. THE FOREGOING DOES NOT AFFECT ANY WARRANTIES THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW. All third-party materials are provided “AS IS” and any representation or warranty of or concerning any third-party materials is strictly between you and the third-party owner or distributor of such third-party materials. WE DO NOT HAVE ANY CONTROL, MANAGEMENT OR ADMINISTRATIVE CAPABILITIES OVER AZTEC, ETHEREUM, OR ANY OTHER BLOCKCHAIN AND ARE NOT RESPONSIBLE FOR YOUR TRANSACTIONS THEREON. FOR THE AVOIDANCE OF DOUBT, ETHEREUM AND AZTEC IS NOT PART OF THE SITE OR THE SERVICES MADE AVAILABLE BY US UNDER THESE TERMS OR OTHERWISE. WE EXPRESSLY DISCLAIM ANY LIABILITY FOR LOSSES OR DAMAGES ARISING FROM OR RELATING TO YOUR INTERACTION WITH, OR ACTIONS TAKEN ON, ETHEREUM, AZTEC, OR ANY OTHER BLOCKCHAIN NETWORK, WALLET, OR OTHER ELECTRONIC WALLET, THROUGH THE SERVICES OR OTHERWISE, INCLUDING BUT NOT LIMITED TO ANY LOSSES, DAMAGES OR CLAIMS ARISING FROM: LOST PASSKEYS, LOST PASSWORDS, MALFUNCTION, NETWORK CONGESTION, NETWORK FAILURE, CONSENSUS FAILURES, SERVER FAILURE, EXPLOITS, FORKS, NODE ISSUES, NETWORK CONGESTION, CONSENSUS FAILURES, CHAIN REORGANIZATIONS, FEE SETTINGS, USER ERROR, INCORRECT RECIPIENT DATA, INCORRECT TRANSACTION DATA, VALIDATOR BEHAVIOR, EXECUTION SPEED, LANDING TIME, TRANSACTION ORDERING, MAXIMAL EXTRACTABLE VALUE OUTCOMES, THIRD-PARTY SMART CONTRACT BEHAVIOR, SOFTWARE BUGS, ERRORS, SIMULATION INACCURACIES, DOWNTIME, TECHNICAL FAULTS IN THE BLOCK BUILDING OR SUBMISSION PROCESS, OR DATA LOSS. ## 15. Indemnification To the fullest extent permitted by Applicable Law, you agree to indemnify, defend and hold harmless Obsidion Labs and our licensors, and each of our and their respective employees, officers, directors, agents and representatives (individually and collectively, the “Obsidion Labs Parties”) from and against all liability for monetary damages, contractual claims of any nature, economic loss (including direct, incidental or consequential damages), loss of income or profits, fines, penalties, exemplary or punitive damages, and any other injury, damage, or harm, including reasonable attorney's fees (collectively, "Damages") that relate in any way to any demand, claim, regulatory action, proceeding or lawsuit, regardless of the cause or alleged cause, whether the allegations are groundless, fraudulent, false or lack merit and regardless of the theory of recovery ("Claims" and each, a "Claim") arising out of or relating to: (i) your access to or use of the Services; (ii) violation or breach of the Terms or violation of Applicable Law by you, your customers, users, employees, agents and other associated persons; (iii) a dispute between you and any third party; (iv) your alleged or actual infringement or misappropriation of any third party's intellectual property or other rights; and (v) your Feedback. In the event we receive a third party subpoena or other compulsory legal order or process associated with Claims described in (i) through (v) above, then, in addition to the indemnification set forth above, you will reimburse us for the time, effort and expenditures we expended responding to such matters at our then-current hourly rates as well as our reasonable attorneys' fees. If you are obligated to indemnify us, then you agree that we will have the right in our sole discretion, to control any action or proceeding and to determine whether we wish to settle and if so, on what terms, and you agree to fully cooperate with us in the defense or settlement of such Claim. ## 16. Limitation of Liability TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL OBSIDION LABS AND THE OTHER OBSIDION LABS PARTIES WILL BE LIABLE FOR DAMAGES OF ANY KIND, UNDER ANY LEGAL THEORY, ARISING OUT OF OR IN CONNECTION WITH YOUR USE OF OR INABILITY TO USE THE SERVICES, ANY WEBSITE LINKED TO THEM, ANY CONTENT MADE AVAILABLE IN CONNECTION WITH THE SERVICES, INCLUDING ANY DIRECT, INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO, EMOTIONAL DISTRESS, LOSS OF REVENUE, LOSS OF PROFITS, LOSS OF BUSINESS OR ANTICIPATED SAVINGS, LOSS OF USE, LOSS OF GOODWILL, LOSS OF DATA, AND LOSS OF OTHER ASSETS, WHETHER CAUSED BY TORT (INCLUDING NEGLIGENCE), BREACH OF CONTRACT, OR OTHERWISE, EVEN IF FORESEEABLE. TO THE FULLEST EXTENT PROVIDED BY LAW, IN NO EVENT WILL THE COLLECTIVE LIABILITY OF OBSIDION LABS AND THE OTHER OBSIDION LABS PARTIES, TO ANY PARTY (REGARDLESS OF THE FORM OF ACTION, WHETHER IN CONTRACT, TORT, OR OTHERWISE) EXCEED THE GREATER OF ONE HUNDRED U.S. DOLLARS (US $100.00) OR THE TOTAL AMOUNT YOU PAID OBSIDION LABS TO USE THE SERVICES IN THE TWELVE (12) MONTHS PRIOR TO THE DATE OF AN INITIAL CLAIM MADE AGAINST US. THE FOREGOING DOES NOT AFFECT ANY LIABILITY THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW. ## 17. Release To the fullest extent permitted by Applicable Law, you hereby release Obsidion Labs and the other Obsidion Labs Parties from, and hereby waive and relinquish, each and every past, present, and future dispute, responsibility, liability, claim, controversy, demand, right, action or cause of action of every kind and nature and/or damages (actual and consequential) of every kind and nature, known and unknown (including claims of negligence), that arises directly or indirectly to, the Services (including any user content, interactions with, or act or omission of, other users of the Services or any third-party websites, links, ads, and advice or feature alerts provided). IF YOU ARE A CALIFORNIA RESIDENT, YOU HEREBY WAIVE YOUR RIGHTS UNDER CALIFORNIA CIVIL CODE § 1542, WHICH PROVIDES: “A GENERAL RELEASE DOES NOT EXTEND TO CLAIMS WHICH THE CREDITOR DOES NOT KNOW OR SUSPECT TO EXIST IN HIS OR HER FAVOR AT THE TIME OF EXECUTING THE RELEASE, WHICH IF KNOWN BY HIM OR HER MUST HAVE MATERIALLY AFFECTED HIS OR HER SETTLEMENT WITH THE DEBTOR.” ## 18. Dispute Resolution and Binding Arbitration PLEASE READ THE FOLLOWING SECTION CAREFULLY BECAUSE IT REQUIRES YOU TO ARBITRATE CERTAIN DISPUTES AND CLAIMS WITH OBSIDION LABS AND LIMITS THE MANNER IN WHICH YOU CAN SEEK RELIEF FROM US. NO CLASS OR REPRESENTATIVE ACTIONS OR ARBITRATIONS ARE ALLOWED UNDER THIS ARBITRATION PROVISION. IN ADDITION, ARBITRATION PRECLUDES YOU FROM SUING IN COURT OR HAVING A JURY TRIAL. **No Representative Actions.** You agree that any dispute arising out of or related to these Terms or any of the Services is personal to you and Obsidion Labs and that any dispute will be resolved solely through individual action, and will not be brought as a class arbitration, class action or any other type of representative proceeding. **Arbitration of Disputes.** Except for claims or disputes in which you or Obsidion Labs seeks injunctive or other equitable relief for the alleged infringement or misappropriation of intellectual property, you and Obsidion Labs waive your rights to a jury trial and to have any other claim or dispute arising out of or related to these Terms (collectively, “Disputes”) resolved in court. Instead, for any Dispute that you have against Obsidion Labs you agree to first contact Obsidion Labs and attempt to resolve the claim informally by sending a written notice of your claim (“Notice”) to Obsidion Labs by email at [company@obsidion.xyz](mailto:company@obsidion.xyz). The Notice must (a) include your name, residence address, email address, and telephone number; (b) describe the nature and basis of the Dispute; and (c) set forth the specific relief sought. If you and Obsidion Labs cannot reach an agreement to resolve the Dispute within thirty (30) days after such Notice is received, then either party may submit the Dispute to confidential, binding arbitration. The arbitration shall be administered in the British Virgin Islands by the BVI International Arbitration Centre under the BVI IAC Arbitration Rules and conducted by a single arbitrator. The arbitrator may conduct only an individual arbitration and may not consolidate more than one individual’s claims, preside over any type of class or representative proceeding or preside over any proceeding involving more than one individual. The arbitration will allow for the discovery or exchange of non-privileged information relevant to the Dispute. The arbitrator, Obsidion Labs, and you will maintain the confidentiality of any arbitration proceedings, judgments and awards, including information gathered, prepared and presented for purposes of the arbitration or related to the Dispute(s) therein. The arbitrator will have the authority to make appropriate rulings to safeguard confidentiality, unless the law provides to the contrary. Any dispute must be filed within one year after the relevant claim arose; otherwise, the Dispute is permanently barred, which means that you and Obsidion Labs will not have the right to assert the claim. **Opt-Out.** You have the right to opt-out and not be bound by the arbitration provisions set forth in this Section 18 by sending written notice of your decision to opt-out to [company@obsidion.xyz](mailto:company@obsidion.xyz). The notice must be sent to Obsidion within thirty (30) days of your first registering to use the Services or agreeing to these Terms, whichever comes first; otherwise, you shall be bound to arbitrate disputes on a non-class basis in accordance with these Terms. If you opt-out of only the arbitration provisions, and not also the class action waiver, the class action waiver still applies. You may not opt-out of only the class action waiver and not also the arbitration provisions. If you opt-out of these arbitration provisions, Obsidion will also not be bound by them. If any portion of this Section 18 is found to be unenforceable or unlawful for any reason, (a) the unenforceable or unlawful provision shall be severed from these Terms; (b) severance of the unenforceable or unlawful provision shall have no impact whatsoever on the remainder of this Section 18 or the parties’ ability to compel arbitration of any remaining claims on an individual basis pursuant to this Section 18; and (c) to the extent that any claims must therefore proceed on a class, collective, consolidated, or representative basis, such claims must be litigated in a civil court of competent jurisdiction and not in arbitration, and the parties agree that litigation of those claims shall be stayed pending the outcome of any individual claims in arbitration. Further, if any part of this Section 18 is found to prohibit an individual claim seeking public injunctive relief, that provision will have no effect to the extent such relief is allowed to be sought out of arbitration, and the remainder of this Section 18 will be enforceable. ## 19. Governing Law and Venue Any dispute arising from these Terms will be governed by and construed and enforced in accordance with the laws of the British Virgin Islands without regard to conflict of law rules or principles that would cause the application of the laws of any other jurisdiction. Any dispute between the parties that is not subject to arbitration will be resolved in the courts of the British Virgin Islands. ## 20. Severability If any provision or part of a provision of these Terms is unlawful, void or unenforceable, that provision or part of the provision is deemed severable from these Terms and does not affect the validity and enforceability of any remaining provisions. ## 21. Force Majeure You acknowledge and agree that we will not be liable for failures or delays in providing Services or other non-performance caused by events including but not limited to strikes, insurrection, riot, civil unrest, war, fires, utility, or power failures, equipment failures, changes in law, cyberattacks, denial of service attacks, non-performance of our vendors or suppliers, acts of God, pandemic or epidemic events, or other causes over which we have no reasonable control. We will make reasonable efforts to limit the effect of any of those events and start or restart the Services as soon as those events have been fixed. ## 22. Miscellaneous The failure of Obsidion Labs to exercise or enforce any right or provision of these Terms will not operate as a waiver of such right or provision. All waivers must be in writing to be effective. These Terms reflect the entire agreement between the parties relating to the subject matter hereof and supersede all prior agreements, representations, statements and understandings of the parties. The section titles in these Terms are for convenience only and have no legal or contractual effect. Use of the word “including” will be interpreted to mean “including without limitation.” Except as otherwise provided herein, these Terms are intended solely for the benefit of the parties and are not intended to confer third-party beneficiary rights upon any other person or entity. If any provision of these Terms is found to be invalid, illegal, or unenforceable, such provision shall be modified so that it is valid and enforceable to the maximum extent permitted by law and the remaining provisions of the Terms will continue in full force and effect. Your relationship to Obsidion Labs is that of an independent contractor. Nothing in these Terms shall be construed to create any association, partnership, joint venture, employment, agency relationship, or any other fiduciary relationship between you and Obsidion Labs for any purpose. These Terms, and your rights and obligations herein, may not be assigned, subcontracted, delegated, or otherwise transferred by you without Obsidion Labs’s prior written consent, and any attempted assignment, subcontract, delegation, or transfer in violation of the foregoing will be null and void. Obsidion Labs may freely assign these Terms. Obsidion Labs will not be liable for any failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control, including acts of God, natural disasters, pandemics, war, terrorism, civil unrest, governmental action, labor disputes, internet or telecommunications failures, or third-party service outages. These Terms are for the sole benefit of you and Obsidion Labs and do not create any third-party beneficiary rights in any other person or entity. Any notices or other communications provided by us under these Terms will be given: (i) via email; or (ii) by posting to the Services. For notices made by email, the date of receipt will be deemed the date on which such notice is transmitted. You agree that communications and transactions between us may be conducted electronically. Any provisions of these Terms that by their nature should survive termination (including, without limitation, provisions regarding intellectual property, indemnification, disclaimers, limitation of liability, release, dispute resolution, and feedback) will survive termination. ## 23. Contacting Us Please contact us at [company@obsidion.xyz](mailto:company@obsidion.xyz) with any questions about these Terms.