mainnet-betaOpen app →Veil never holds your keys, and its program won't move funds without a valid proof from them. Here is how it's tested, where review stands, and what you can check on-chain yourself, right now.
What's done, and what happens before deposit caps are lifted.
Reviewed by a reviewer with no part in writing the code. Every finding was fixed before release and is covered by a regression test.
309 checks across 6 suites, including real zero-knowledge proofs replayed against the on-chain program.
End-to-end runs against a copy of mainnet with the real Jupiter and Jupiter Lend programs: shield, private swap, private lending, exit.
Scope: On-chain program, circuit, relayer. The audit package (source hashes, scope, invariants) is ready.
A multi-party ceremony that is secure if any single participant is honest. The kit is built and tested.
Per-token caps, a multisig admin with two-step handover, and a preflight that refuses launch until every check passes.
Every suite runs on each release; tap one to see what it covers. Last run Oct 3, 2026 · build a797f9a.
Each guarantee is exercised against the real program with hostile inputs that must be refused. We publish what is guaranteed, not how anyone might try to break it.
A note leaves a one-time marker on-chain when spent; any second attempt is refused by the program.
2 scenarios verifiedEvery public detail of a transaction is recomputed by the program and bound into the proof. Change anything and it no longer verifies.
2 scenarios verifiedRecipients and relayer fees are fixed by your proof. Nobody in between can redirect them.
1 scenario verifiedEach trade or lending position gets its own escrow and signer, must pay out at least your minimum, or refunds you in full.
7 scenarios verifiedProtocol fees can never exceed 1%, are tracked apart from user funds, and can only be swept to the treasury.
3 scenarios verifiedAdmin powers are narrow, can’t move user funds, and change hands only when the new holder accepts.
6 scenarios verifiedTokens with features that could endanger a shared vault are rejected when a vault is opened.
1 scenario verifiedEmpty transactions are refused and each token’s vault has a beta cap.
2 scenarios verifiedOutsiders can’t stop your spends or withdrawals by tampering with addresses ahead of time.
2 scenarios verifiedGenerated and encrypted in your browser; proofs are built there too. Relayers and indexers only ever see public data.
The admin can pause and set limits, but no instruction lets anyone move notes without the owner's proof.
Swaps and lending run only through allowlisted programs, each confined to its own escrow.
Anyone can run a relayer or an indexer. Clients verify the Merkle root themselves.
Read straight from the Solana RPC in your browser, not from our servers.
Found something? Please report it privately before telling anyone else, so users stay safe while it's fixed. A dedicated security contact opens with the mainnet beta.