The audit
Cloak’s shield-pool program has been independently audited. The program live on mainnet since 2026-08-24 is built from the audited source, its proofs are checked against a verifying key produced by a public multi-party trusted-setup ceremony, and upgrades sit behind a multisig with a time lock. The full report is being prepared for publication and will be linked here. That is the whole claim. Everything below it that can be checked, you can check yourself.Verify it yourself
What protects your funds
- Proof verification on every state change. Nothing moves in the pool unless a zero-knowledge proof checks out on-chain — the chain verifies the math is right without ever seeing the details.
- Double-spend protection. Spending a UTXO publishes a nullifier: a marker that it has been used, without revealing which UTXO it was. The same funds can never be spent twice.
- Root-history validation. The program only accepts proofs built against a recent, recognized state of the pool (the last 100 Merkle roots). Proofs against stale or fabricated states are rejected.
- Per-token pool isolation. SOL, USDC, and USDT each have their own pool and their own tree. A problem in one pool cannot spill into another.
- Screening. Deposits are screened against sanctions and high-risk lists on-chain: a signed risk assessment is bound to each deposit and checked by the program. Withdrawals and swaps are screened before they are authorized. Flagged transactions are blocked, with a support path — you never notice this on the happy path.
Who sees what
Privacy isn’t hiding — it’s choosing who gets the receipt. Here is what each actor around the pool can and cannot do.What Cloak cannot do
Most protocols tell you what they can do. Here is the other half.- Cloak cannot recover a lost private balance. No backup file means no funds — by design, not by policy.
- Cloak cannot spend, freeze, or seize your funds. No custodial path exists.
- Cloak cannot hide what you do after leaving the pool. Withdraw to a KYC’d exchange account or a doxxed address, and that withdrawal is public from that point on.
- Cloak cannot un-link your past. Transactions you made before shielding stay public forever.
- Cloak cannot make a shallow pool deep. Privacy strength grows with pool activity; if very few similar deposits exist, timing and amount correlation gets easier for a chain-watcher.
- Cloak cannot protect a compromised device. Malware in your browser, or a leaked backup file, defeats everything above.
Governance
The Cloak program is upgradeable. Its upgrade authority is the Squads multisigF6HWeX5i2KjYQag6wCtxzQXeGewv6vXZihZR3EWdRL7s (3 of 4 signers, with a 1-hour time lock), so no single key can change the program and every upgrade is visible before it lands. We say this plainly because an upgradeable program you know about is safer than an “immutable” one that quietly isn’t — upgradeability is how fixes ship.
Reporting an issue
There is no public bug bounty or dedicated security inbox yet, and we won’t pretend otherwise. If you find a vulnerability, report it privately to the team before any public disclosure, either in Discord or at contact@cloak.ag.Where next
Compliance
Privacy you can prove: viewing keys, exportable reports, and how screening works.
Private balance
UTXOs, the backup file, and exactly what happens if you lose either.