+×+
Skip to content

Styx Protocol

WHO YOU PAY. WHAT YOU BUY. HOW MUCH.

Pay merchants, subscribe, send and swap on Solana.

Post-quantum proofs, stealth addresses, shielded pools. Live on devnet. Self-custody. Open source. No KYC. In active development. Not audited. Use at your own risk.

Launch App

Where we stand

Tornado Cash-style fixed-denomination pools for SOL and USDC. All deposits in a pool are the same value, so the amount you move is not distinctive. Deposits and withdrawals are NOT yet unlinkable: the unshield publishes the note commitment the deposit emitted, so anyone can match the two.

ZK Proof System

Seven STARK circuits

Post-quantum: hash-based construction not affected by Shor's algorithm; Grover's gives only a quadratic speedup, mitigated by digest size

Post-Quantum KEM

X25519 + ML-KEM-768

v2: X25519 + ML-KEM-768 (FIPS 203) hybrid ECDH, quantum-resistant

Data Structure

Poseidon + Merkle

A Merkle tree stores all commitments, allowing users to prove they have funds in the shielded pool without revealing which commitment they own. The root is stored on-chain and updated with each deposit.

Deployment

Devnet only, not audited.

WASM prover, 229,640 bytes, all 7 circuits. Runs in the browser; on a real phone the withdrawal pair (C1 + C3) was measured past the 180s worker timeout, so on-device withdrawal does not complete today

DEMO

See it in action

Traditional blockchains offer pseudonymity, not privacy.

Every transaction you make creates a permanent, public trail that can be traced back to you, forever.

Anyone can see your entire financial history

One wallet address is enough to trace every payment, your balance and who you deal with. Permanent, public, no permission needed.

Standard chain

7xK9f...8c2e sent 100 SOL

7xK9f...8c2e received 50k USDC

7xK9f...8c2e = John Smith

Identity Exposed - All history visible

Shielded pool

????...???? sent ??? SOL

????...???? received ??? USDC

Owner = Poseidon commitment

Fixed denominations - an observer sees one note, not your balance

Each pool is a set of identical notes. A withdrawal today still publishes the commitment of the deposit it spends, so the set does not hide you yet. That needs the spend circuit. These are the crowds it will give you.

  • Step 01

    CONNECT

    Create or import your Solana wallet

  • Step 02

    SHIELD

    Deposit tokens into the ZK shielded pool

  • Step 03

    TRANSFER

    Send privately via post-quantum STARK proofs

  • Step 04

    RECEIVE

    Unshield via an ephemeral signer (fee payer) + one-time recipient. Your wallet still funds the ephemeral and receives the withdrawal, so both hops stay linkable to it.

Beta · Devnet

01

Privacy Pools

Deposit into a shared pool of identical notes, so the amount you move is not distinctive.

02

ZK Proofs

No trusted setup required. STARKs are transparent (unlike Groth16's.ptau ceremony)

03

Stealth Meta-Addresses

Stealth addresses allow recipients to receive funds without revealing their public address. Each payment creates a unique one-time address using Elliptic Curve Diffie-Hellman key exchange.

04

Subscription Vaults

On-chain recurring payment vaults with configurable intervals. Retailers create vaults, subscribers deposit funds, and a crank claims payments each period. Supports both normal (public) and ZK-private subscriber modes.

05

Note Splitting

Split a high-denomination note into multiple lower-denomination notes across pools. Enables the Privacy Router to break large amounts into smaller, harder-to-trace pieces with a single ZK proof.

06

Service Registry

Merchants register on-chain, so you can subscribe to real services with no account.

Traders & whales

Move before the crowd does

Merchants

Get paid, prove it, store nothing

Builders

Ship privacy without building it

Technologies

SolanaL1 Blockchain
AnchorSmart Contracts
WinterfellSTARK Prover
PoseidonZK Hash
Merkle TreesData Structure
NullifiersAnti Double-Spend
Blake3FRI Hash
ML-KEM-768Post-Quantum KEM
Curve25519ECDH
CircomZK Circuits
ark-circomRust Prover
React NativeMobile
ExpoApp Platform
Next.jsWeb Framework
TypeScriptLanguage
DockerDeployment
SPL TokensToken Standard

Hash-based and post-quantum, not affected by Shor; only a quadratic Grover speedup

Early access

Run it on devnet and tell us what breaks.

Styx Protocol runs on Solana devnet and has not been audited. Leave your email and we tell you when there is something to try.

One confirmation email, one reminder at most, and a fresh link whenever you ask for one. Your address is deleted the moment you use the unsubscribe link.

Your email is used for one thing only: telling you when your access opens. Every email has an unsubscribe link.