Your funds. Your keys. Your exit.
• Keys are made on your device and never reach our servers
• The vault only pays out against a proof only you can make
• No admin key can freeze or move funds, and withdrawals can never be paused
No other privacy swap offers this!!
Private trading, fully yours 👓
We are happy to announce our entry to the ZECATHON
100K PRIZE!
Our entry based on @Zcash requirements.
WHAT IT DOES
VisionSwap is a live, non-custodial shielded pool on Solana mainnet (https://t.co/CVUz7poxcU), built on Zcash's note/nullifier model. Users shield SOL, then privately send to any address, buy/sell any token into fresh unlinked wallets, run limit/DCA/take-profit/stop-loss orders, and schedule payments for a random moment.
WHY IT DOES NOT LEAK
- Balances are Poseidon note commitments in an on-chain Merkle tree. A spend reveals only a nullifier, never which note or deposit it came from.
- Groth16 proofs (BN254) are generated in the browser. Spending and viewing keys never leave the device; the server can't spend.
- The proof binds recipient, amount and fees, so the relayer that submits it can't change or steal anything, and the user's wallet never signs or pays for the spend.
- Payouts arrive as a plain SOL transfer from a one-time address derived from the user's key, so nothing points back to the pool user.
- Output notes are encrypted to their owner; history is revealed only with an optional viewing key.
- Timing: random-moment payments and paced, amount-varied multi-wallet actions.
Public by design (like Zcash t->z / z->t): the deposit address and amount, and withdrawal amounts and recipients.
WHAT IS REAL vs MOCK
Everything is real; there are no mocks. Anchor program VSwJY1r9S7nNUyvBzWYr1rBkEMyTAjDFGtixxLGpmt6 verifies Groth16 proofs on-chain on mainnet; Circom circuits; Perpetual Powers of Tau phase 1 plus phase-2 contributions sealed with a Bitcoin block beacon; a production relayer, indexer and deposit screening (sanctions checks on depositors and the wallets that funded them); real user transactions; open source.
zkSNARKS presents ZECATHON — a $ZEC privacy hackathon.
The goal is simple: put real resources behind people building useful technology on Zcash. Bring new builders in, support the ones already here, and help turn strong ideas into products people can actually use.
$100K prize pool. Submissions are open for the next 30 days.
https://t.co/qKPaKmHRxU 👇
VisionSwap is open by design 🔓
Anyone can build on our Solana program. Proofs are made on your device and verified on-chain, and your keys never leave it.
And every deposit is screened at the door. No hackers or criminals can hide their misdeeds.
Screened at the door. Every deposit is checked against sanctions lists, along with the wallets that funded it. A flagged deposit can only ever go back to where it came from. Need to show where your funds came from? Download a statement with your viewing key.
The proofs already aren’t made on our servers!!
Each proof is made in the user’s own browser, and the Solana program checks it on-chain. Our servers never see the secret keys and can’t make or change a proof.
A Solana program itself can’t create a proof, for two reasons. Building one needs the user’s secret keys, which must never leave their device. It’s also far too heavy to compute on-chain. Programs only verify proofs, which is exactly what ours does.
Yes, the VisionSwap program is open source and anyone can call it directly. The app makes the zero-knowledge proofs on your own device, tracks your private notes, and relays so your wallet never shows up. Your keys never leave your browser, and once you’re in the pool you can always withdraw straight through the program, even without our servers. The only step that always goes through us is screening new deposits.
You can build with us by seeing the Docs!
https://t.co/yWjbZwQVbN
Unfortunate and hard for the victims we wish @vanishTrade a speedy recovery.
However we would like to clarify why this wont happen with https://t.co/fEkR82yUV7
What happened to Vanish:
according to their own post, an attacker got an API key for the signing service that holds Vanish’s pool funds. With that key they bypassed its rules and moved about $335k out of the pools. The basic weakness is that a server-side key could move pooled money, so leaking the key was enough.
Why VisionSwap is built differently:
pool funds can only move with a zero-knowledge proof made in the user’s own browser. There’s no server key that unlocks the pool, so that exact attack doesn’t apply.
There is always new ways to build security and old ways that get attacked.
Welcome to the new age with VisionSwap.
On 20 September at 18:58 UTC, Vanish suffered an exploit in it's private swap functionality, abused by attackers leading to a loss of ~$335,000. The exploit was limited to Vanish pools, connected wallets are not at risk. A full snapshot of every account balance has been taken. User remediation is next to be announced.
Our silence since the incident has been painful but staying quiet was imperative to the incident investigation, which we're carrying out with law enforcement, security and forensics teams. The protocol has been paused while deeper investigation and security hardening are being completed. We're grateful for user and partners patience during this time.
What happened:
• An API key for Vanish's signing service was compromised, enabling attackers to create transactions that bypassed signing policies and account balance verification.
• Abusing this, attackers routed protocol assets to an external destination, returning zero to Vanish accounts.
��� Vanish used signing policies to restrict activity incase of potential compromises, however attackers reverse-engineered the exact structure of legitimate transactions, leading to the abuse and exploit.
• Following reported issues, our team activated the @0xGroomLake incident response after our internal validation of an incident.
Next steps:
• Deeper investigation and cooperation with law enforcement, forensics and security partners.
• Protocol security hardening updates, further restricting whitelisted actions of all protocol functions.
• Affected user remediation procedure and service reactivation to be announced.
Past this, we're putting our full attention on completing our ZK systems: open-source, verifiable code where no human error or key can touch funds.
Thank you for sticking with us through this.
We wish everyone a safe and private experience on Solana, truly feel for the victims. https://t.co/LIpHEz3qBP is open and VisionSwap is built differently: pool funds can only move with a zero-knowledge proof made in the user’s own browser. There’s no server key that unlocks the pool, so this exact attack doesn’t apply.
Did you know VisionSwap is the first privacy swap tailored to active traders?
Trading:
private limit buys, DCA, multi-step take-profit, stop-loss and trailing stops;
editing live orders without re-approving;
private trades of any token;
tokens landing in a wallet you own.
Payments:
exchange-safe private payouts;
payments at a random moment;
one-step send from the wallet;
private payment links;
shielding by QR code from any exchange, and accounts with no wallet at all.
Trust:
the take-it-back waiting room;
screening that also checks who funded the wallet; for compliance
the built-in exposure checker;
statements with viewing keys;
fees capped in the program itself: verifiable on the Solana Mainnet
if youre on Solana and haven't thought about @HeliusPrivacy, I humbly guarantee you will fall behind your competitors and your users' wants
ZK at Solana scale is a hell of a challenge, but we've done it and it will change Solana permanently
get in touch
🔑 Wild Connection Room Expansion
🔑 Team 135
🔑 @VisionSwapSol
🔑 What is VisionSwap:
It`s a Zkproof fully private trading or transferring technology on Solana for any token. What is cool they have worked on it for months, and there is no token yet, so the old-school build first then launch a CA.
Core features:
- A private balance the chain can't read. Shield SOL into a zero-knowledge pool so nobody can see how much you hold or when you move it, with proofs made on your own device and keys that never leave your browser.
- Buy and sell Solana tokens privately. Every buy runs from a fresh wallet funded from your private balance, so nothing on-chain ties the tokens to the wallet you deposited from, and every sale sends the SOL straight back into your private balance.
- Pro orders that run on their own. Limit buys, DCA, take-profit in up to 4 steps, stop-losses and trailing stops keep working even with the page closed, and limit buys and take-profits never fill worse than your price.
- Payments your wallet never appears in. A relayer sends each private payment, with the recipient and amount sealed inside the proof so nobody can redirect it. Schedule a payment for a random moment, pay up to 20 people at once, or share a payment link that lands in your private balance.
No wallet needed. Start with a QR deposit from any wallet or exchange, or sign in with a passkey using your face or fingerprint, and every deposit is screened against sanctions lists before it joins the pool.
Welcome to my room