The Vision
Use Octra as a privacy middleware layer for any blockchain. Users swap ETH, SOL, or USDC into OCT via the 0xio DEX, encrypt the OCT balance using Octra’s FHE, transfer privately, then the recipient decrypts and swaps back to any token on any chain. OCT is the privacy denomination: all assets flow through it. No new wrapped tokens needed.How It Differs from Umbra
Umbra on Ethereum
Stealth addresses (ECDH). Every payment goes to a one-time address that only the recipient can link to their identity. Simple but amounts are still visible on-chain.Umbra on Solana
Full privacy via Arcium MPC: encrypted balances, mixer pool with ZK proofs, relayer network. Privacy on both the source and destination chain. End-to-end encryption.0xio Privacy Layer
FHE-encrypted transfers on Octra as a middle hop. Privacy exists only on the Octra layer; the deposit and withdrawal on ETH/SOL are public.Two Privacy Modes
Mode 1: Basic (Octra-Only Privacy)
The simplest version uses only the existing 0xio DEX + Octra FHE. Deposits and withdrawals are public, but the transfer itself is private.Mode 2: Advanced (End-to-End Privacy)
Uses mature, live privacy tech on every chain in the pipeline. Each hop is shielded by a different technology optimized for that chain.The Privacy Tech Stack (All Live, SDKs Ready)
How Each Technology Works
RAILGUN (ETH Deposits)
RAILGUN (ETH Deposits)
@railgun-community/wallet (npm, TypeScript, browser + mobile compatible)0xbow Privacy Pools (ETH Deposits with Compliance)
0xbow Privacy Pools (ETH Deposits with Compliance)
ERC-5564 Stealth Addresses (ETH Withdrawals)
ERC-5564 Stealth Addresses (ETH Withdrawals)
Umbra Privacy SDK (Solana Withdrawals)
Umbra Privacy SDK (Solana Withdrawals)
Solana Confidential Transfers (Complementary)
Solana Confidential Transfers (Complementary)
Privacy Enhancement Layers
Beyond the core tech stack, these mechanisms strengthen anonymity:1. Amount Obfuscation (Partial Withdrawals)
User deposits 1 ETH → receives encrypted OCT → withdraws as 0.3 ETH + 0.4 SOL + 0.25 USDC at different times to different addresses on different chains. Each withdrawal goes to a fresh stealth address. The FHE encrypted balance supports partial withdrawals naturally.2. Batched Withdrawals
The solver batches multiple users’ withdrawals into single transactions. Instead of “Address B withdrew 1 ETH,” it’s “The solver sent 47 ETH to 30 addresses.” Individual amounts are obscured in the batch.3. Time Delay (Anonymity Set Growth)
The longer users hold encrypted OCT, the larger the anonymity set. If 100 users deposited today and 100 withdrew tomorrow, no observer can link specific deposits to withdrawals. The encrypted OCT balance acts as a privacy buffer.4. Relayer Network (No Gas Linkage)
The relayer submits withdrawal transactions on behalf of the user. The gas cost is deducted from the encrypted OCT balance itself; the user never pays gas from the recipient address. This means the recipient address has zero prior on-chain activity, breaking the funding-pattern fingerprint. Example: User withdraws 200 OCT as ETH. Relayer fee is ~5 OCT. User receives 195 OCT worth of ETH. The relayer is compensated from the withdrawal amount, not from a separate gas payment.5. Volume
Privacy strength scales with usage. More users holding encrypted OCT on Octra → harder to correlate any single deposit to a withdrawal. Unlike mixer pools (Tornado Cash), there is no shared pool: each user has their own encrypted balance on their own Octra address. The anonymity comes from the volume of encrypted balances existing on-chain simultaneously.Why OCT as the Privacy Denomination
Instead of creating octaWETH, octaWSOL, octaUSDC (separate wrapped tokens on Octra), all assets swap through OCT:- Larger anonymity set: all privacy users hold encrypted OCT on Octra (more encrypted balances = harder to correlate)
- Existing infrastructure: DEX swap (live), encrypted OCT balances (live), private transfers (live)
- No new contracts: no octaWETH mint/burn, no per-asset bridge extensions
- OCT utility: every privacy transfer drives OCT demand
Why FHE Instead of ZK or MPC
- Encrypted arithmetic:
ct_addandct_suboperate directly on ciphertexts - No custom circuits: Unlike ZK, no per-operation circuit design needed
- Private swaps possible: AMM logic can run on encrypted order data (future)
- Any amount: No fixed denominations like Tornado Cash, and ciphertexts support partial spends
What Already Exists vs. What’s Needed
The Product: “Private Send”
A single feature in the 0xio wallet/extension:User clicks 'Private Send'
Auto-swap to OCT
Auto-encrypt
Private transfer
Recipient holds encrypted OCT
Recipient cashes out, all at once or in pieces
Private Balance: Partial Withdrawals
The recipient’s encrypted OCT balance works like a private bank account. They can withdraw any amount at any time to any address on any chain:Development Phases
Phase 1: Basic Privacy (Octra-only)
- “Private Send” UI in 0xio wallet/extension
- Auto-chain: DEX swap → encrypt → transfer
- Partial withdrawals to any chain/address
- Relayer fee deducted from encrypted balance
- Uses existing DEX + PVAC infrastructure, with no new integrations
Phase 2: ETH-Side Privacy
- Integrate RAILGUN SDK (
@railgun-community/wallet) for shielded deposits - User shields ETH → unshields to bridge → breaks sender link
- Integrate ERC-5564 stealth addresses for withdrawals via Umbra v2
- Solver sends to one-time stealth address (recipient unlinked)
- EIP-7702 delegation to solve stealth address gas problem
Phase 3: SOL-Side Privacy
- Integrate Umbra Privacy TypeScript SDK for Solana withdrawals
- Solver deposits into Umbra shielded pool → recipient withdraws privately
- Sender, recipient, amount all hidden on Solana side
- Complement with Solana Confidential Transfers (Token-2022) for amount hiding
Phase 4: Full Stack
- 0xbow Privacy Pools integration for compliance-friendly deposits
- Relayer network decentralization (multiple relayers compete)
- Batched withdrawal aggregation in solver
- Anonymity set monitoring dashboard
- Selective disclosure via PVAC viewing keys
- Noir ZK circuits for custom compliance proofs
- Privacy audit by external security firm
Comparison with Competitors
Performance Estimates
FAQ
Is this like Tornado Cash?
Is this like Tornado Cash?
Can someone trace my deposit to my withdrawal?
Can someone trace my deposit to my withdrawal?
Why not full end-to-end encryption like Umbra on Solana?
Why not full end-to-end encryption like Umbra on Solana?
What about price risk while holding OCT?
What about price risk while holding OCT?
Is this legal?
Is this legal?