Shielded notes on Solana

A private balance on a public chain.

Charon holds value in notes only you can spend. Your device builds the proof, the program checks it and the key never leaves you.

Why it exists

A public chain remembers the whole path.

On Solana, amounts, addresses and timing sit in the open. Follow one payment and you can usually find the one before it. A wallet is not a balance. It is a history.

Hiding that on a server does not fix it. Whoever builds the proof holds the spend key and whoever holds the key can spend the note. Privacy is the machine the proof is made on.

How it works

A pool of notes.
Your balance, without the trail.

Deposit into a note. Spend it by proving you own a note in the tree that has not been spent without showing which one.

01

The key stays on your device

Proofs are built in the browser. The witness, the blinding values, and the spend key are never posted to a server.

02

The chain checks a proof, not the note

The program verifies a Groth16 proof on BN254 against seven public signals. It never learns which leaf was spent.

03

One prover, everywhere

The browser and the program tests run the same Rust prover, so there is no second implementation to drift from the circuit.

04

SOL and SPL, as notes

Deposits become commitments in one tree. A nullifier spends each note once. Tokens use the same shape as SOL.

Early access

Take a place on the near shore.

Leave an address to hear when Charon goes live. A withdrawal to a public address is still public, Charon hides the path that led to it.

The early listOne note when Charon opens.