sotto

Devnet preview: test tokens have no value.Get Devnet SOL How Sotto works

SolanaPrivacy PoolsBurn to speak

Pass it under your breath.Burn it to be heard.

Sotto is the currency of quiet rooms. Zip it and nobody can tell which deposit paid. Burn it and the whole square hears you.

How it works

Three steps, and nobody can connect them.

  1. 1

    Zip

    Move tokens or SOL from your wallet into the pool. In your browser you get a private note; on-chain, only a deposit.

  2. 2

    Wait

    The pool checks the deposit in a few minutes. The longer you wait, the more people zip after you, and the bigger the crowd you hide in.

  3. 3

    Unzip

    Send any part to any address. Your browser proves you own a note without saying which; a relayer pays the fee, so the recipient needs nothing.

Live on the network

Every number on this page can be recomputed from the chain. Nothing is hidden, except who you are.

…
Tokens zipped
…
Tokens burned
…
Notes an unzip hides among
…
Messages spoken

Latest burns

All messages ›

No one has spoken yet. Be the first.

Why Sotto

Privacy is normal. Only thieves have to worry.

Paying someone used to leave no record anyone could search. On a public chain it leaves one for everyone, forever. Sotto gives the old default back, with no backdoor and no list of users: it only keeps known hacks and thefts out of the crowd. Who sees what

Private by proof

Unzipping proves in your browser that you own an approved note, without saying which. Built on 0xbow's Privacy Pools and their production trusted setup.

Loud by burn

Every message burns tokens for good. The supply only shrinks, and the loudest voices are the ones that paid the most.

Exit always open

Whatever the vetting service decides, the wallet that zipped can always take its note back. Upgrades wait 48 hours behind a multisig.

Future-proof

Built for the day the curves break.

Quantum computers, or mathematics found with the help of AI, may one day break the elliptic curves most of crypto relies on. Sotto is built so that day does not undo your privacy. What it would and would not mean

Nothing to decrypt later

Your notes are never stored on-chain, not even encrypted: they come from your 12 words, and your browser finds them itself. There is no ciphertext waiting for a future machine.

Proofs that tell nothing

The proofs are perfectly zero-knowledge: they say nothing about which deposit you spend, even to someone who can break any curve. Your past unzips stay unlinkable.

A brake on the pool

What a broken curve could threaten is the pool's funds, so the program caps how much can leave per hour and can pause private withdrawals. Ragequit never stops.

Don't trust, verify

Every claim comes with a way to check it.

  • Source on this site

    The full history of the programs, services and this site: download it here, no account anywhere.

  • Verifiable builds

    Rebuild the programs and the site yourself: same bytes, same hashes.

  • Upgrades wait

    2 of 3 multisig signers and a time lock before any program change.

  • Exit always open

    Ragequit needs only your words, your wallet and any RPC. Not us.

  • Public vetting

    Every approval and revocation, with its reason, on-chain root included.

  • Audit, honestly

    Internal so far, and labelled as such; independent audit before large deposits.

How to check each one yourself

Ready to go quiet?

Read how it works, then zip your first tokens.