Shielded balances and transfers. Front-running bots, on-chain sleuths, and strangers all see the same thing: nothing.
Private transfers settle in seconds. No bridges to trust, no wrapped tokens to hold — Sombra is just Solana with a privacy layer.
Lattices, not elliptic curves. Hard to break — today and after.
Your payload is wrapped in authenticated encryption, keyed by a Kyber-768 shared secret. One-time use, per UTXO. Only the receiver can read it.
A RISC0 zkVM proves you own the inputs and the values balance — without revealing them. STARKs are hash-based, so the proof itself stays hard under quantum attack.
The proof and ciphertext land on Solana. Attesting nodes verify and commit a finalization vote. Ownership is never signed — only proven.
Solana is fast and cheap — and radically transparent. Every transfer, every wallet, every position, visible forever. Sombra wraps your activity in a zero-knowledge envelope, so the chain sees that something happened, but not what, not how much, and not between whom.
Adversaries are harvesting encrypted traffic today, waiting for tomorrow’s quantum computers to run Shor’s algorithm and break elliptic-curve keys. Sombra ships NIST-standardized lattice cryptography right now — Kyber-768 for key exchange, RISC0 STARKs for ownership proofs. No elliptic curves to break, no signatures to forge.
| Property | Sombra | Tornado | Zcash |
|---|---|---|---|
| Quantum-safe | Kyber-768 | No — ECC | No — ECC |
| No nullifiers | Yes | No | No |
| Signature-free | Yes | No | No |
| Proof system | STARK | SNARK (ECC) | SNARK (ECC) |
| Multi-token | Any SPL token | Fixed denominations | ZEC only |
| Amount privacy | Yes — per-UTXO | Fixed only | Yes — shielded pool |
Early access to the shadow.