Skip to main content
Status: Research & Design Phase This feature is planned for future development. The architecture builds on Octra’s existing FHE (PVAC) primitives and 0xio’s cross-chain swap infrastructure.

The Vision

Use Octra as a privacy middleware layer for any blockchain. Users swap ETH, SOL, or USDC into OCT via the 0xio DEX, encrypt the OCT balance using Octra’s FHE, transfer privately, then the recipient decrypts and swaps back to any token on any chain. OCT is the privacy denomination: all assets flow through it. No new wrapped tokens needed.

How It Differs from Umbra

Umbra on Ethereum

Stealth addresses (ECDH). Every payment goes to a one-time address that only the recipient can link to their identity. Simple but amounts are still visible on-chain.

Umbra on Solana

Full privacy via Arcium MPC: encrypted balances, mixer pool with ZK proofs, relayer network. Privacy on both the source and destination chain. End-to-end encryption.

0xio Privacy Layer

FHE-encrypted transfers on Octra as a middle hop. Privacy exists only on the Octra layer; the deposit and withdrawal on ETH/SOL are public.

Two Privacy Modes

Mode 1: Basic (Octra-Only Privacy)

The simplest version uses only the existing 0xio DEX + Octra FHE. Deposits and withdrawals are public, but the transfer itself is private.
What’s private: who sent to whom, how much, when the recipient cashes out. What’s NOT private: the deposit and withdrawal are visible on ETH/SOL. Timing + amount correlation can link them.
Basic mode is not end-to-end private. For maximum privacy, use Advanced mode or hold encrypted OCT for extended periods and withdraw in pieces to different addresses.

Mode 2: Advanced (End-to-End Privacy)

Uses mature, live privacy tech on every chain in the pipeline. Each hop is shielded by a different technology optimized for that chain.
Every hop is private. No public link between sender and receiver on any chain.

The Privacy Tech Stack (All Live, SDKs Ready)

How Each Technology Works

RAILGUN is a shielded pool on Ethereum with $4.5B cumulative volume. Users “shield” tokens into the pool, breaking the on-chain link to their address. From inside the pool, they can transfer to any address privately. 0xio uses RAILGUN for deposits: user shields ETH → unshields to the bridge contract. The bridge deposit looks like a generic RAILGUN withdrawal, not traceable to the original user.SDK: @railgun-community/wallet (npm, TypeScript, browser + mobile compatible)
Privacy Pools (backed by Vitalik, live since March 2025) add compliance to privacy. Users can prove their withdrawal belongs to a “clean” association set without revealing their full history. This lets regulated users use privacy features while proving they’re not laundering funds.Useful for institutional users who need privacy + compliance simultaneously.
Stealth addresses (ERC-5564 + ERC-6538) let the solver derive a one-time address for the recipient. Funds arrive at a fresh address that only the recipient can link to their identity. 77,000+ stealth addresses generated on Ethereum mainnet. Umbra v2 (launching summer 2026) is the primary implementation.The stealth address gas problem (fresh address has no ETH for gas) is solved by EIP-7702 delegation or RAILGUN relayers.
Umbra on Solana (powered by Arcium MPC, public launch March 2026) provides full privacy: sender, recipient, AND amount are shielded. The TypeScript SDK handles all crypto internally. The solver deposits withdrawal funds into Umbra’s shielded pool, transfers to the recipient, who withdraws whenever they want.SDK: Umbra Privacy TypeScript SDK (mainnet + devnet, browser + Node.js)
Solana’s native Token-2022 extension hides transfer amounts and balances using homomorphic encryption + ZK proofs. Already used by PayPal’s PYUSD. Addresses remain public, so use in combination with Umbra for full coverage. Useful as a fallback when Umbra is unavailable.

Privacy Enhancement Layers

Beyond the core tech stack, these mechanisms strengthen anonymity:

1. Amount Obfuscation (Partial Withdrawals)

User deposits 1 ETH → receives encrypted OCT → withdraws as 0.3 ETH + 0.4 SOL + 0.25 USDC at different times to different addresses on different chains. Each withdrawal goes to a fresh stealth address. The FHE encrypted balance supports partial withdrawals naturally.

2. Batched Withdrawals

The solver batches multiple users’ withdrawals into single transactions. Instead of “Address B withdrew 1 ETH,” it’s “The solver sent 47 ETH to 30 addresses.” Individual amounts are obscured in the batch.

3. Time Delay (Anonymity Set Growth)

The longer users hold encrypted OCT, the larger the anonymity set. If 100 users deposited today and 100 withdrew tomorrow, no observer can link specific deposits to withdrawals. The encrypted OCT balance acts as a privacy buffer.

4. Relayer Network (No Gas Linkage)

The relayer submits withdrawal transactions on behalf of the user. The gas cost is deducted from the encrypted OCT balance itself; the user never pays gas from the recipient address. This means the recipient address has zero prior on-chain activity, breaking the funding-pattern fingerprint. Example: User withdraws 200 OCT as ETH. Relayer fee is ~5 OCT. User receives 195 OCT worth of ETH. The relayer is compensated from the withdrawal amount, not from a separate gas payment.

5. Volume

Privacy strength scales with usage. More users holding encrypted OCT on Octra → harder to correlate any single deposit to a withdrawal. Unlike mixer pools (Tornado Cash), there is no shared pool: each user has their own encrypted balance on their own Octra address. The anonymity comes from the volume of encrypted balances existing on-chain simultaneously.

Why OCT as the Privacy Denomination

Instead of creating octaWETH, octaWSOL, octaUSDC (separate wrapped tokens on Octra), all assets swap through OCT: We chose OCT because:
  • Larger anonymity set: all privacy users hold encrypted OCT on Octra (more encrypted balances = harder to correlate)
  • Existing infrastructure: DEX swap (live), encrypted OCT balances (live), private transfers (live)
  • No new contracts: no octaWETH mint/burn, no per-asset bridge extensions
  • OCT utility: every privacy transfer drives OCT demand
The trade-off is price exposure: if OCT price drops while the user holds encrypted OCT, they lose value. For short hold times (minutes to hours), this is negligible. For longer holds, users accept the risk for privacy.

Why FHE Instead of ZK or MPC

Octra’s FHE is uniquely powerful because:
  • Encrypted arithmetic: ct_add and ct_sub operate directly on ciphertexts
  • No custom circuits: Unlike ZK, no per-operation circuit design needed
  • Private swaps possible: AMM logic can run on encrypted order data (future)
  • Any amount: No fixed denominations like Tornado Cash, and ciphertexts support partial spends

What Already Exists vs. What’s Needed

The Product: “Private Send”

A single feature in the 0xio wallet/extension:
1

User clicks 'Private Send'

Inputs: amount (ETH/SOL/USDC), recipient’s Octra address
2

Auto-swap to OCT

DEX solver swaps the source token to OCT on Octra (~30s)
3

Auto-encrypt

OCT balance encrypted via PVAC on Octra (instant)
4

Private transfer

Encrypted OCT sent to recipient on Octra (~10s). Amount hidden from everyone.
5

Recipient holds encrypted OCT

Recipient sees encrypted balance in their 0xio wallet. Can hold as long as they want.
6

Recipient cashes out, all at once or in pieces

When ready, withdraw any portion to any address on any chain. Hold the rest.
Steps 2-4 are automated by the solver. The user experience is: “Send 1 ETH privately” → done.

Private Balance: Partial Withdrawals

The recipient’s encrypted OCT balance works like a private bank account. They can withdraw any amount at any time to any address on any chain:
Each withdrawal is a separate DEX swap at a different time to a different address. This is the core privacy mechanism. An observer sees unrelated transactions on different chains with different amounts and timing. The link between them is hidden inside Octra’s FHE layer.
Maximum privacy: Withdraw in small, irregular amounts over days/weeks to fresh addresses on different chains. The encrypted balance on Octra acts as a privacy buffer: the longer you hold and the more you split withdrawals, the harder correlation becomes.

Development Phases

Phase 1: Basic Privacy (Octra-only)

  • “Private Send” UI in 0xio wallet/extension
  • Auto-chain: DEX swap → encrypt → transfer
  • Partial withdrawals to any chain/address
  • Relayer fee deducted from encrypted balance
  • Uses existing DEX + PVAC infrastructure, with no new integrations

Phase 2: ETH-Side Privacy

  • Integrate RAILGUN SDK (@railgun-community/wallet) for shielded deposits
  • User shields ETH → unshields to bridge → breaks sender link
  • Integrate ERC-5564 stealth addresses for withdrawals via Umbra v2
  • Solver sends to one-time stealth address (recipient unlinked)
  • EIP-7702 delegation to solve stealth address gas problem

Phase 3: SOL-Side Privacy

  • Integrate Umbra Privacy TypeScript SDK for Solana withdrawals
  • Solver deposits into Umbra shielded pool → recipient withdraws privately
  • Sender, recipient, amount all hidden on Solana side
  • Complement with Solana Confidential Transfers (Token-2022) for amount hiding

Phase 4: Full Stack

  • 0xbow Privacy Pools integration for compliance-friendly deposits
  • Relayer network decentralization (multiple relayers compete)
  • Batched withdrawal aggregation in solver
  • Anonymity set monitoring dashboard
  • Selective disclosure via PVAC viewing keys
  • Noir ZK circuits for custom compliance proofs
  • Privacy audit by external security firm

Comparison with Competitors

Performance Estimates

FAQ

Similar concept (privacy via intermediary), different implementation. Tornado Cash used fixed-denomination mixer pools on a single chain with no compliance features, and was sanctioned. 0xio uses FHE for any-amount transfers across multiple chains, with viewing key disclosure for compliance. The privacy model is also different: Tornado hid deposits in a pool, while 0xio uses homomorphic encryption on the Octra chain.
The Octra transfer itself is fully private (FHE encrypted). However, the deposit on ETH and withdrawal on ETH/SOL are public. If you deposit 1 ETH and immediately withdraw 1 ETH worth of OCT, timing and amount correlation could link them. For better privacy: hold encrypted OCT for longer, withdraw in different amounts, use multiple withdrawal addresses.
Umbra on Solana built a full MPC privacy infrastructure on a single chain. We’re cross-chain: we don’t control the source/destination chains (Ethereum, Solana). Their deposits and withdrawals are inherently public. Our FHE privacy lives on Octra as a middle layer. Full end-to-end would require privacy infrastructure on every supported chain, which defeats the purpose of using Octra as a unified backend.
Users are exposed to OCT price movement while holding encrypted OCT. For short holds (minutes), this is negligible. For longer holds (days), users accept the trade-off between privacy and price stability. Future iterations may support encrypted stablecoin-denominated balances on Octra to eliminate this risk.