Own stocks.
Quietly.
Shielded pools for tokenized stocks on Robinhood Chain. Nobody sees what you hold. Auditors can still prove every exit is clean.
Your share becomes one of 1,284.
Every deposit is the same size and the same shape. Which one is yours is known only to you.
Nobody can tell which one is yours.
The pool is the anonymity set. Nothing on chain links a note to the deposit that made it.
It leaves to an address that never touched it.
The proof says only this: one clean share left. Not whose, not which.
Three moves.
- 1
Deposit one share.
Approve, deposit. Your browser writes a bearer note and keeps it. The note is the share; nothing about it is sent anywhere.
- 2
Let it settle.
- 3
Withdraw to a fresh address.
AAPL
Apple Inc., one share.
Privacy for the holder. Proof for the auditor.
Every withdrawal proves membership in the global tree and in the association set of clean deposits, bound to the same leaf. Nobody can tell which deposit it was. Everybody can tell it was a clean one.
| Who | Learns about the deposit | Learns about the withdrawal | Can link the two | Knows the exit is clean |
|---|---|---|---|---|
| The public | One share entered the pool | One share left, to a fresh address | No | Yes, by proof |
| Robinhood Chain | The same as the public | The same as the public | No | Yes, by proof |
| The curator | Which deposits it admits to the set | Nothing more than the public | No | It defines the set |
| An auditor | Everything the public sees | Everything the public sees | No | Verifies every exit against the association set |
| The recipient | Nothing | Their own | No | Yes, by proof |
| You | Yours | Yours | Only you | Yes |
Privacy Pools design by Buterin, Illum, Nadler, Schär and Soleimani; implementation forked from 0xbow. The curator’s policy is public from day one: deposits are admitted by default and filtered only when flagged.