WHAT LEAKS

An honest accounting of every bit that leaves the pool.

Privacy claims are cheap. This page lists, per party, what kn:ll reveals and when. If you find a bit missing from the list, that is a bug, and we would like to know.

By party.

PARTYLEARNSNEVER LEARNS
chain observera commitment hash exists; a fill of size S at price P happened in round R (one round late)who committed, which commitments filled, side of any order, size of any unfilled order
your counterpartythey were filled S at Pwho you are, your total size, your band
committee member (one)an encrypted share of each revealany order's contents, alone
committee (quorum)the set of revealed orders for one round, inside the enclave-less MPCnothing after the round; unfilled orders are discarded, never output
kn:ll (the venue)the same as a chain observereverything else — there is no privileged view
reference price sourcenothing about the pool

By moment.

MOMENTPUBLICSEALED
you commita hash, your escrow amount (upper bound on size)side, size, band, salt
round closesreference mid for the roundall orders
cross computedproof of correct cross, list of fill amountswhich commitment each fill belongs to (revealed only to the filled party)
settlementescrow movements, aggregatedper-order mapping
one round laterthe toll: each fill's size and priceunfilled orders — forever

Known leaks we have not closed.

Escrow amount. To commit you escrow funds; the escrow is an upper bound on your size and is visible. Mitigation: over-escrow, or commit from a pooled contract. We are working on shielded escrow.

Timing. A commitment's block time is public. Batching rounds blunts this; it does not erase it.

Fill inference. If a round tolls exactly one fill and you were the only new commitment, an observer can guess. Rounds with fewer than a minimum number of commitments do not cross.

Your own RPC. The node you submit through sees your address and your commitment together. Use a relayer.