docs_
release status
Genius contracts are deployed on BNB mainnet (chain 56). The app uses real Groth16 proofs, encrypted note recovery, live V2 quotes and a sponsored settlement relay. It does not use sample balances.
The contracts are new and have not undergone an independent security audit. Phase 1 uses the published Hermez ceremony; phase 2 has one project contribution. Ceremony record · integration tests · verify browser proofs.
deposit, trade, withdraw
Create a private wallet and save its encrypted backup. Connect a public BNB wallet to deposit WBNB or Binance-Peg USDT. Native BNB can first be wrapped into WBNB with the app's separate wrap action.
Deposits produce encrypted notes. Trades consume one note and create output and change notes. Withdrawals always return to the original deposit address. Keep your backup and passphrase: there is no key reset.
One unspent note must cover each operation; balances across notes are not merged. Proof generation happens on your device. The relay submits private trades and withdrawals without your public wallet signing those transactions.
privacy model
The target is to exclude the note owner from public trade inputs. That does not hide the assets, amounts, solver or transaction timing.
| action | visible | not included |
|---|---|---|
| deposit | wallet, asset, amount, commitment | viewing + spending secrets |
| trade | solver, assets, amounts, proof, nullifiers | note owner |
| withdraw | wallet, asset, amount, proof, nullifiers | viewing + spending secrets |
deposit controls
The pool admits two curated ERC20 tokens and has a deposit pause. Withdrawals remain available when deposits are paused. A separate Veil-style admission-screening service is not implemented.
implementation
Groth16 / BN254 proofs authorize deposits and spends. Poseidon commitments bind owner, original recipient, asset, amount, blinding and the chain/pool domain. Membership is proved in a depth-20 Merkle tree; spent nullifiers prevent duplicate use. The pool is immutable and has no administrator asset-withdrawal function.
A fixed PancakeSwap V2 adapter performs atomic settlement. The displayed output is the minimum after a 0.5% slippage allowance and the 0.5% protocol fee. Execution surplus goes to the gas-paying executor. The relay is rate-limited and budget-limited; users can call withdrawal directly if the relay is unavailable, which reveals their submitting address.
Notes use AES-256-GCM. Backup files use PBKDF2-SHA256 with 600,000 iterations and AES-256-GCM. Transfer-tax and rebasing tokens are not supported. The latest 256 Merkle roots are accepted; the tree has 1,048,576 slots.
fees
Proposed: 0.5% on the output of each action. Change the starting value to explore the full cycle at unchanged asset prices.
About 1.49% across the full cycle. Excludes gas, solver economics, slippage and token transfer taxes.
buybacks
The proposed economics reserve 65.537% of protocol fees for buybacks and burns. No Genius token, buyback executor or burn process is deployed in this release.
fee 0.5% per action buyback 65.537% of collected fees then open-market purchase + burn example $1,000,000 traded fees $5,000.00 bought+burned $3,276.85
why 65.537
A reference to 65537, a commonly used RSA public exponent: 2^16 + 1. It is a naming choice for the proposed fee split, not a privacy guarantee.
BNB mainnet contracts
Chain ID 56. Deployment receipts and runtime code hashes are published in the deployment manifest.
| contract | address |
|---|---|
| depositVerifier | 0xDd63d7156a5d64F2Cbc63ABeDc7fe27006F415AC |
| spendVerifier | 0x0c501bF5d6c80f54DBFc309ABECC61903B83274b |
| Poseidon2 | 0xF002Eb7BDa6ae8D519da31092432DEF504d08242 |
| GeniusPool | 0x3A5714855B9B0b4f62025f01F354d176Bb4DfFBa |
| GeniusV2Solver | 0xd749Dc5d4648D3F693273a444cD604494913ffa5 |