We just rewrote the Cowl roadmap.
Seven eras. From a shielded pool on Robinhood Chain to private markets in every pocket. You will not find a single date on it, because an era opens when the one before it is finished, not when a quarter rolls over.
Era 00 already landed. The shielded pool foundation is deployed to testnet with deposits proven end to end, the note cryptography is locked on Poseidon2 and UltraHonk, and $COWL trades on mainnet. The CLI is there if you want to touch it today.
The flagship arrives with Era 01. Private send and receive, private revenue-split, hidden balances. Value that lives inside Cowl goes private for the very first user rather than the thousandth.
Then it opens up. Compliant disclosure with auditor-scoped view keys. A gasless relayer network. Shielded execution with front-run protection. An SDK so any app can embed Cowl privacy. Then Cowl in every pocket.
Read the whole thing.
https://t.co/Vn4teoWTY0
The Cowl app is almost here.
One screen. Pick a pair and the swap routes straight through the shielded pool. Your size and your timing stay off the explorer, and your wallet never shows up as the counterparty.
https://t.co/f1YqlCzSAO
The full private loop is done. Shield, send, trade, unshield, all live on Robinhood Chain testnet, all settling inside the ZK shielded pool where the explorer never learns your size or your timing.
The gasless relayer is live too, on by default. You spend from a fresh note, the relayer pays the gas and broadcasts it, and the chain logs the relayer instead of you. Nothing traces back.
That was the hard part. It works today, in the terminal.
Now comes the part everyone can hold. We are building the Cowl web app, private trading in a few clicks, the same shielded core with none of the terminal. Shield, trade, and disclose from a screen.
And the people who show up early matter most. If you are here now, using Cowl and shaping where it goes, you are building this protocol with us. Early contributors get rewarded in $COWL. You were here before the crowd, and that counts.
Gas is the tell almost nobody thinks about.
When you unshield or trade, some wallet has to pay the gas and broadcast it. If that wallet is yours, the chain logs you as the sender, and the move you wanted private just signed your name.
A relayer removes your name. It takes the spend you already proved, submits it from its own wallet, and pays the gas so your wallet never shows up as the one paying. The proof locks in the recipient, the relayer, and the fee before it leaves your machine, so a relayer can redirect nothing. It sends exactly what you proved, or it gets rejected.
The payoff is concrete. A withdrawal can land on a fresh address holding zero gas, and the chain sees the relayer paying, never you.
On Cowl this is live and on by default. Install the CLI and your boundary moves route through it automatically, gasless. Anyone can run one too, so the relayer set only grows.
https://t.co/vS2pmYbt7p
Shield, send, trade, unshield. The full private loop closes today, running on Robinhood Chain testnet.
Cowl CLI 0.6.0 ships cowl trade, the piece it was all building toward. You name a token and the amount you want, and the CLI settles a private swap in one atomic transaction. Your funds leave the ZK shielded pool, route through real liquidity, and come back as a fresh note only your keys can open. Size, timing, the shape of your book, none of it hits the explorer.
This is the part that matters for $COWL. Cowl is not a token hunting for a product. The product is here and it works on chain, and $COWL is the token built to capture it, through a fee model of buyback & burn and staking. Shipping is the bull case, and Cowl just shipped.
npm:
https://t.co/FjeEyfIzWl
The first private trade, settled on chain:
https://t.co/LwZxDpWCcC
All eight contracts, addresses and ABIs:
https://t.co/PUZqYUVwnr
Your portfolio is private now. Shield, send private, unshield, all live on Robinhood Chain testnet. Amounts, assets, owners never hit the public ledger.
Every spend is a ZK proof, settled onchain.
ShieldedPool 0xf9F825f2D6d8509c78baaa587694f74672C32A59
https://t.co/PUZqYUVwnr
See exactly what the pool logs, and what it hides.
https://t.co/9ZahpCJ7Mv
Do not take my word for any of it. Point cast at https://t.co/wPneLTra9H and run:
cast call 0x5DE68a552cf7CcE72d4CC7C1918278B42171809b 'verifier()(address)'
That returns the verifier the pool actually calls. Match it against the address above yourself.
The shielded pool is live on Robinhood Chain testnet.
Real contract, real deposits. cowl shield builds a ZK proof on your machine in under a second, and the pool verifies it onchain before a single wei moves. The prover ships inside the CLI. You install nothing else.
Your deposit is visible. That is what compliant means. What nobody can follow is the link from that deposit to whatever you do next.
Spend circuits are next. Then your exits go dark too.
Fair question came in already. Here is the receipt.
ShieldedPool
0x5DE68a552cf7CcE72d4CC7C1918278B42171809b
HonkVerifier
0x72890b8f6f92428949eC84F88FB09718Af9D0328
First deposit, leaf #0
0xc300c1ac66a87910ddb8b170c78f64c859104580712aa8a7a16a7feddd190edb
Chain id 46630. 3,755,706 gas, nearly all of it the proof verification. That is what honest ZK costs on an EVM today.
Robinhood built a feature to hide your trades from your own family:
https://t.co/keRqaI4fPa
Then put every trade on a public blockchain, visible to the whole world:
https://t.co/RxvTgDbz5R
Hide from grandma. Expose to 8 billion strangers.
COWL fixes the part they skipped. Private by default, provable on demand 👁️
Cowl's shielded pool produced its first real proof this week, and almost none of that was our own work.
The shield circuit is written in @NoirLang. 169 UltraHonk gates. Barretenberg from @aztecnetwork proves it in 55ms and hands back a Solidity verifier on the way out. We fed that exact proof to that exact verifier inside the EVM and it held.
Building privacy used to mean a year of cryptography before you could ship anything. These teams collapsed that into an afternoon.
@NoirLang made circuits something we can actually read
@aztecnetwork gave us Barretenberg and the verifier it emits
@paradigm keeps Foundry sharp enough to catch what we missed
@wevm_dev builds viem, which makes every chain call in our CLI
@paulmillr maintains noble, the curve work we would have gotten wrong
@ZKPassport shipped poseidon2 bit exact with the prover on the first try
That last one saved us the most. Our notes hashed with circomlib Poseidon, fine on paper and brutal inside a circuit, 6792 ACIR opcodes for one commitment plus a Merkle path of depth 20. Poseidon2 does identical work in 127. We caught it before a single note touched a chain.
None of these people owe us anything. They shipped it open, and every protocol after them gets privacy cheaper for it. Thank you.
ShieldedPool.sol is green across 11 tests. It lands on Robinhood Chain testnet 46630 next, an @arbitrum Orbit L2 where @RobinhoodApp brought tokenized stocks onchain.
The team tried to break the Cowl CLI. 74 checks, eight issues found, all eight closed.
The worst one had your stealth meta-address and your shielded payment address ending in the same bytes. Publish both and you are linkable. In a privacy tool.
https://t.co/5ZlqtvKYUC
The $COWL token page is live.
Price, liquidity, 24h volume, holders and the contract address in one place, pulled from DexScreener and Robinhood Chain every 30 seconds. No more digging through Telegram replies to find the right CA.
Robinhood Chain, ID 4663. ERC-20, 1,000,000,000 supply.
Trade unseen. Stay compliant.
https://t.co/kuTMedtg5V
Cowl now has a working shielded portfolio.
Shield a position from the CLI and it becomes a note. The commitment is hashed with Poseidon and lands in a Merkle tree, and spending it later reveals only a nullifier. Private trades and private sends run on the same machinery, so your size and direction stay out of view. Your view key sits ready for whoever has the right to ask.
All of this runs locally today. The cryptography is real. The pool contract is not deployed yet, and the CLI tells you that on every command.
We're taking the shielded pool onto Robinhood Chain testnet now, then running the whole flow onchain for real.
Why we built Cowl around a shielded pool, not another wallet.
Robinhood Chain shipped on July 1 with almost everything a serious market needs. Tokenized stocks trading around the clock in 120+ countries. 100ms blocks. Chainlink CCIP and Data Streams and Data Feeds live on day one. Uniswap and 1inch and Lighter there from the start. The testnet cleared 200 million transactions before any of it went live, and 13,900 contracts landed in the first week of mainnet.
This is not an experiment. It is a functioning market.
It shipped with no privacy at all.
Not weak privacy. None. Read the docs. There is no ZK, no shielded pool, no confidential transfer, nothing announced and nothing pending. Your positions settle on a public explorer exactly like any other EVM chain, except what is sitting in the open now is your equity book.
It goes past public. Chainalysis screens every token transfer on thechain, and it did not stop at screening. Reactor is there too, the investigation product, the one that draws your transaction paths as a graph and walks individual transfers back to a counterparty. TRM runs alongside it. Robinhood Chain did not merely leave your book visible. It shipped with the tooling to read it already installed.
Then the sequencer. One of them, run by Robinhood, ordering transactions first come first served. Set the decentralization argument aside, because for tokenized equities the problem is simpler and worse than that: a single party sees your order before it settles.
And people are already working it. Stalkchain published a guide on how to follow wallets on Robinhood Chain. Wallet stalking there is not a future risk somebody is warning about. It is a tutorial.
Put it together and here is your real position as a trader. You are trading actual equities, on a fast chain, with your entries and exits and P&L published in real time to anyone curious enough to look, screened as they land, and visible to the sequencer a beat before they settle. Nobody is doing anything wrong here. This is just what the chain does by default, to everyone on it.
That is the gap. It does not close by moving to a fresh address, because the deposit funding that address is public too.
Cowl closes it.
Shield your USDG or your tokenized stock and the balance moves into a ZK shielded pool and leaves the explorer. What stays on-chain is a commitment, not a number anyone can read. You receive into a stealth address derived under ERC-5564, so funds arriving for you carry no path back to your main wallet. You trade through a gasless relayer, so your address never enters the mempool and the sequencer gets nothing of yours to order ahead of.
Your view key is the only thing that turns any of it back into readable history, and it never leaves your keystore.
Now the part people assume we skipped. Robinhood Chain is compliance first, and we did not build against that. We built for it. Selective disclosure means you hand your view key to an auditor or a regulator and they read exactly what they are owed, in full, while nobody else reads anything. You stay answerable. You just stop broadcasting to the crowd while you are.
A chain that screens every transfer and a trader who keeps positions private are not in conflict. Cowl is the proof.
Where we are: Robinhood Chain testnet. Stealth addresses and view keys work today. The shielded pool and private trading go through a full audit before mainnet.
Hide from the public. Not from the law.
Read the docs at https://t.co/JfzAa9o6BJ
CLI Repo for early testing https://t.co/fslCI8IuyI
Under the hood: how Cowl shields a trade.
Trade onchain and the explorer sees all of it. Your size and your entries, timestamped in public. Front-runners and copy-traders read it live and trade against you.
Here is how we kill that.
Shield a position and it becomes a note. A private record of amount, token, and owner. We hash it into a commitment with Poseidon over the BN254 field and drop it into a Merkle tree of every shielded balance.
Spending a note never reveals the note. It reveals one nullifier: a marker that says this note is spent, with zero link back to the commitment. Double spends die. Your history stays dark.
The note is encrypted to the recipient view key. They scan the shielded pool, find what is theirs, and their shielded portfolio adds up locally. None of it touches the public explorer. A private send and a private receive are the same move: inputs nullified, outputs minted, and the value always balances.
The math is not a promise. It is a Noir circuit. It proves you own the inputs, the Merkle path checks out, and the amounts add up, without showing any of it. No per circuit ceremony. The verifier lands on Robinhood Chain and the same notes settle there.
And when the law asks, you hand over a view key. Selective disclosure. You prove what you did without broadcasting it to everyone trading against you.
Cowl is live on Robinhood Chain testnet, and we are deep in test and dev.
The demo runs in the terminal: a shielded identity, a fresh stealth address that receives funds unlinkable to your main wallet, and a real transaction confirmed on-chain in seconds. Your view key stays local for selective disclosure and no one else.
In the CLI right now we are building and testing private trade, a shielded portfolio, and private send and receive, all moving through the shielded pool.
The terminal comes first. A web app follows, then mobile. Same shielded core, more ways to reach it.
Testnet first, hardened before mainnet. Verifiable on the block explorer.
Tx ->
https://t.co/zTI9PFUtbm
4/4
Where we are right now. Cowl runs on Robinhood Chain testnet, not mainnet.
Wallets and stealth addresses and view keys work today. The shielded pool and private trading are still under test, and the contracts go through a full audit before any of it reaches mainnet.
Privacy that holds real money is not something you rush. We would rather ship it right than ship it early.
Testnet is open now. Mainnet comes after the audit clears.
Read the docs at https://t.co/4A0yZya1EY
Getting started with Cowl takes a few minutes. You set it up once, and from then on your trades run private by default.
Step 1 Create Your Shielded Identity
Cowl generates a stealth address and a view key that belong only to you. The stealth address receives funds without tying them to your public wallet, so nothing on the explorer points back to who you are. The view key stays in your hands. It is what you later show an auditor under selective disclosure, and no one sees it until you decide they should. You do this once.
Step 2 Shield Your Assets
Move your tokenized stocks or USDG into the ZK shielded pool. The deposit confirms on Robinhood Chain, then your balance leaves the explorer for good. From here your holdings sit behind the shield instead of out in the open, size and positions included.
1/4
3/4
The CLI is live. Cowl runs from your terminal today.
npm i -g @cowlprotocol/cli
cowl init creates an encrypted keystore, an ed25519 view key, and points you at Robinhood Chain testnet. Your keys never leave ~/.cowl, sealed behind a passphrase you choose.
The privacy primitives already work:
cowl address derives a fresh ERC-5564 stealth address, an unlinkable destination so funds sent to you cannot be traced to your main wallet.
cowl viewkey show prints the public view key you hand to an auditor for selective disclosure, and to nobody else.
cowl balance and cowl send read and move native and ERC-20 value directly on Robinhood Chain.
Shielding and private trades stay gated until the shielded pool contracts deploy. When they land, cowl shield and cowl trade come online in the same terminal, under the same keys.