Threat model
Adversaries
| Adversary | What they see today | What they see on Intelena |
|---|---|---|
| Block explorer / wallet tracker | Full balance and history per address | Aggregate pool flows only; no per-user balance or history |
| Copy trader | Positions and entries in real time | Nothing — crossed trades never hit a public pool |
| MEV / front-running bot | Pending order size and direction | Fragmented, jittered pieces from fresh addresses; crossed volume never enters the mempool as a swap |
| Stop hunter | Resting triggers and limit levels | Encrypted triggers that reveal nothing until filled |
| Network observer | IP ↔ address correlation via RPC | Queries proxied through the relayer network |
Trust assumptions
| Party | Can | Cannot |
|---|---|---|
| Relayers | Delay or refuse service | Steal funds, decrypt notes, or forge proofs. The emergency exit removes them from the withdrawal path entirely. |
| Oracle | Determine the midpoint price for dark crossing | Affect custody. Manipulation would affect crossing price for a pair, not ownership. |
| Association-set curator | Decide which deposit sources are approved | See who spends, or block a spend that already has a valid proof. |
| ZK circuits | Enforce ownership, non-double-spend, and set membership | Be trusted blindly — soundness depends on the proving system and circuit correctness, to be independently audited before mainnet. |
Invariants
- Funds can always exit. The emergency exit works with every relayer offline.
- No plaintext balances anywhere. Notes are decrypted only on your device.
- No double spend. Every spend publishes a nullifier bound to the note.
- Residual exposure is disclosed. The public leg is minimized and fragmented, not eliminated — and the Leak Score shows it before you sign.
Audits
Circuit and contract audits will be published before mainnet, together with a responsible-disclosure policy.