tacit
open ceremony
Trusted setup.
The EVM side of Secret Sats: the same private notes and the same address, for ETH and other EVM assets on Ethereum, Base and Robinhood Chain, with every transaction proved on your own device. Its proving key comes from one public ceremony: each contribution mixes in fresh randomness, and the key is sound as long as a single contributor kept theirs secret.
·contributions
Contribute in your browser →
A few minutes. No wallet needed. Contribute as often as you like.
How it works
- Your browser fetches the circuit and setup file while you wait in line, then the current key, about 125 MB in all, and checks every earlier contribution.
- It mixes in randomness that never leaves your browser, then uploads the new key. A wallet's public key, or one kept in your browser, is recorded with it.
- When the ceremony closes, a Bitcoin block hash is mixed in as a public beacon. Anyone can then verify the whole transcript, and the pool's contracts deploy at addresses already published.
Where it fits
- The confidential pool
- Tacit's confidential DeFi zone: one shielded note across Bitcoin and Ethereum for private swaps, lending, liquidity and the bridge, all settled by one general-purpose prover in shared batches.
- Special-purpose pools
- A pool that does one thing uses a small fixed circuit, so users prove their own spends in seconds and no prover ever sees an amount. Secret Sats does private payments in sats on Bitcoin. This pool mirrors it in wei: one frozen circuit (two notes in, two out, 44,414 constraints) serves ETH and other EVM assets on Ethereum, Base and Robinhood Chain, under the same keys and the same address.
- Together
- They extend Tacit V1 rather than replace it. A confidential-pool note can move into this pool and back, and a standing private address takes deposits from any wallet or exchange on a chain the pool is on.