The basics
Do I need a new wallet?
No. zkSVM works with the Solana wallet you already have. Your shielded keys are derived from it, so there is nothing new to install or back up.
Is my SOL leaving Solana?
No. The pool is a Solana program, and the SOL sits in an account that program controls. There is no bridge and no second chain.
Who runs the pool?
Nobody. The program has no admin key, no pause switch and no allowlist. Creating the pool takes no parameters and gives its creator no powers.
Where does the yield come from?
From Jito's stake pool. When you shield with Earn as jitoSOL, your SOL is staked and you hold jitoSOL inside the pool, which is worth more SOL every epoch. See Earn while shielded.
How do I get my SOL back?
Unshield. An earning balance is redeemed on the way out and arrives as ordinary SOL — more than you put in, by whatever it earned, less Jito's 0.1% withdrawal fee. See Unshield.
What does it cost?
The normal Solana network fee, plus about 0.00095 SOL for every note you spend. The protocol fee that comes with $ZKSVM applies to earning balances, never to private transfers. Details in Fees and costs.
Is there a token?
Yes — $ZKSVM, with a supply of one billion. Part of the protocol's fees buys it back and burns it, and staking $ZKSVM earns a higher rate than the pool's base yield. You do not need it to use the pool. See The $ZKSVM token.
Paying and being paid
What is the difference between a zks… address and my Solana address?
Both can receive private payments. A payment to your shielded address arrives in your balance by itself and leaves no public trace. A payment to your Solana address has to be claimed, which shows that your address claimed something. Hand out the shielded address when you can.
Can I pay someone who has never used zkSVM?
Yes — send to their ordinary Solana address and give them the claim code. The address does not even need to exist yet.
I sent to the wrong address. Is it gone?
If it was a returnable payment — the default for Solana addresses — no. Nobody can collect it without that address's signature, and after the return date you take it back.
I lost the claim code I was given.
Ask the sender for it again. For a returnable payment they can copy it at any time from their Sent, not yet claimed list. And if a code is ever truly lost, a returnable payment goes back to the sender, who can simply pay you again.
Is a claim code dangerous to share?
No. Collecting takes a signature from the address that was paid. The code only identifies the note.
Privacy
What can people see?
Deposits and withdrawals, with their amounts. Not what happens in between, and not the link between a deposit and a withdrawal. See Staying private.
Can the recipient see who paid them?
Not from the payment. A shielded payment carries an amount and nothing about its source.
Can anyone see my balance?
No. Your notes are indistinguishable from everyone else's. When you need to show something, prove a balance reveals a floor you choose and nothing more.
Under the hood
Where are proofs made?
In your browser. Your keys and your notes never leave it; the app talks to a Solana RPC node and to nothing else.
Why does the app download so much the first time?
Proving keys. Each kind of operation has one, between 8 and 16 MB, and your browser caches them after first use.
Why does syncing read the whole pool?
Because asking a server "which notes are mine?" would tell the server which notes are yours. Reading everything reveals nothing.
Which tokens are supported?
SOL and jitoSOL in the app. Underneath, a note can hold any SPL token, and transfers never show which one they move.