Documentation
How Sotto works
A meme currency with privacy built in. Zip it to move quietly, burn it to be heard. This page explains everything a holder needs; the technical specification lives in the repository.
Overview
Every token is a normal Solana token you can trade anywhere. On top of that, Sotto adds three things:
Zip & unzip
Your wallet
Zip 1,000
commitment 0x7a…
Shared pool
Many notes
yours hides among them
Fresh address
Unzip 400
proof · nullifier 0x3c…
Zipping stores a commitment, a cryptographic fingerprint, of your deposit. Unzipping proves, with a zero-knowledge proof made in your browser, that you own some approved deposit, without saying which. You can unzip part of a note; the rest becomes a new note only you can spend.
The design is 0xbow's Privacy Pools, with their audited circuits and production trusted setup, unchanged.
Tip · For real privacy: wait a while after zipping, don't unzip the exact amount you zipped, and unzip to a fresh address.
Burn to speak
Burning destroys tokens for good: the supply shrinks. Every message is ranked by what it burned; the loudest voices lead the Burns page.
Public
Burned from your wallet. The message shows your address.
Anonymous
Paid from a zipped note through the relayer. Nobody learns who spoke.
Doorstep
Every wallet has a door. Burn tokens there to be heard by its owner, and optionally leave a gift. Knock publicly from your wallet, or anonymously from a zipped note. The owner receives the gift without learning who sent it.
Doors can be opened by address or by .sol name. Names are resolved in your browser and the page always shows the address the gift will go to. Check it before you knock.
Launchpad
A creator approved by the ASP opens a raise in SOL. Backers contribute from their zipped SOL notes, so nobody can tell which deposit paid. When the raise closes, the launchpad creates the coin on pump.fun and buys it with the whole raise in the same transaction: no sniper, and not the creator either, can buy before the backers.
Backers' tokens unlock linearly over the period the creator chose (1 to 365 days) and are delivered automatically to a fresh address derived from your 12 words, one per contribution. If the raise ends below its minimum, or nobody closes it within 3 days, every backer is refunded automatically to that address. During the beta a launch raises at most 20 SOL.
Creators pass the ASP too: the same screening as a deposit, a week of wallet history, one open launch at a time, and no other token's name. Every decision is public on the ASP page.
Quantum vault
A place to keep SOL and tokens that no elliptic-curve key guards: not your wallet's, not ours. Only a hash-based one-time signature (Winternitz over Keccak, with a checksum) can move what a vault holds, and its keys come from your 12 words through hashes alone. A quantum computer, or a mathematical break of the curves, would not reach it.
Send to your vault's address (or unzip straight to it). To spend, the page signs with the vault's key and your wallet approves two transactions; your wallet only pays the fees and cannot move the vault's funds. Each key signs once: what you do not send moves to your next vault, and anything sent later to an older address can be moved on to it.
Your own AI agent
Already use an AI agent (Claude, Cursor or any app that speaks MCP)? Connect it to Sotto and ask it in your own words: “zip 0.5 SOL”, “send 0.2 SOL privately to …”, “what is raising on the launchpad?”. It runs on your computer: the proofs are made there, and your wallet key and 12 words stay there. The agent plans; it sends only with your yes.
- Your yes, not the model's. Before anything moves your app asks you in its own dialog, with the pool, the recipient and the amount; the model can neither answer it nor skip it. An app that cannot ask you (MCP elicitation) can read balances and pools, but cannot send.
- A daily limit per pool, counted on your computer, and warnings when an unzip would be easy to link to your zip.
- Keys locked with your passphrase. The agent's 12 words and wallet key are kept encrypted. To open them it shows a link to a page on your own computer, where you type the passphrase: it never passes through the chat. They close again after 30 minutes without use.
What we honestly think
An AI agent is the least private way to use Sotto, and we would rather say so than sell it as more than it is.
- The model's company hears you. What you tell an agent (amounts, recipients, timing) goes to whoever runs the model and may stay in its logs. That is exactly the link the pool exists to hide. For a send that should stay private, use this site or the in-browser assistant: they keep it between you and the chain.
- Unlocked keys open every note. The 12 words reach all the notes they made, not only what the agent may spend. While they are unlocked, malware on your computer could take them, and the daily limit binds the agent, not a thief. Give it a wallet of its own (and so its own 12 words) holding only what it may use.
- Your yes is only as strong as your app. We send only after your app has asked you in its own dialog. An app that answered such questions by itself, or a plugin that did it for you, would defeat it.
- A checksum proves less than it seems. It shows the file matches this site, not that this site is honest: compare it with a build from the source or a copy you trust elsewhere.
So why offer it? Because we respect the people who bring AI to security work: auditing code, finding bugs before attackers do, watching networks for the next exploit. Agents are becoming how many of them work, and Sotto should be usable there on honest terms. It is a tool for people who weigh these trade-offs themselves, not the way we recommend to use Sotto.
- Install Node.js 20 or newer.
- Download sotto-mcp.mjs and check it against SHA256SUMS (
sha256sum sotto-mcp.mjs); it is built from the source code. - In a terminal, lock the agent's keys under a passphrase (it asks with hidden input and writes an encrypted file):
node sotto-mcp.mjs init - Add it to your app's MCP servers, with your own path:
{
"mcpServers": {
"sotto": {
"command": "node",
"args": [
"/path/to/sotto-mcp.mjs"
],
"env": {
"SOTTO_SITE": "https://this-site",
"SOTTO_DAILY_LIMIT": "sol=1,sotto=100000"
}
}
}
}Only the public parts are sent: to this site, what its own pages send (proofs, never keys); to the Solana network, signed transactions.
Your zip key
- 1
Sign
Your wallet signs a fixed message. Nothing is sent anywhere.
- 2
Derive
The signature becomes 12 words: your zip key. Same wallet, same words, every time.
- 3
Keep
Write the words down. They restore your notes on any device.
Fees and where they go
| Action | Fee | Goes to |
|---|---|---|
| Trading on pump.fun | creator fee | Treasury multisig |
| Zip | 0.5% | Treasury, for vetting and operations |
| Unzip, anonymous speech or knock | ≈ 1% | Relayer, who pays the network fees |
| Speech and knocks | the burn | Destroyed forever |
| Gifts | None | The door's owner |
The treasury funds relayer gas, deposit vetting, audits, infrastructure and bug bounties. Its address is public.
Security
No backdoor to the pool
No instruction lets anyone move pooled tokens except a valid unzip or a ragequit: not the team, not the admin.
Upgrades wait 48 hours
Program upgrades need 2 of 3 multisig signers and a 48-hour time lock, so you can leave before any change lands. The plan is to freeze the pool after the audit.
Tested like an attacker would
Real-proof tests for every rule, and a fuzzer that runs millions of random and hostile operations against the exact binaries that ship.
Safe tokens only
The pool refuses tokens that can be frozen, taxed on transfer, or moved by a permanent delegate.
Small limits until an independent audit
The audit so far is internal. Until an outside firm has checked the code, each deposit is capped at 1 SOL and the whole pool at 50 SOL. The caps rise only after 30 quiet days, and only with 2 of the 3 multisig signers. Taking your own deposit back is never capped.
Bugs pay
Half of every zip fee goes into a public security fund. It pays whoever finds a bug first (up to 10% of the funds a critical bug puts at risk) and then pays for the independent audit. No name or account needed: an address is enough.
Found a vulnerability? See the security policy for the rules and rewards. Contact details are also embedded in every program as security.txt.
Why privacy, and who sees what
For most of history, paying someone or talking to them left no record anyone could search. Public blockchains turned that around: every payment is visible to everyone, forever, and software now reads it all. Sotto gives back the old default for one thing, money and the words you burn it for, without a backdoor and without a list of users to hand over.
Privacy matters most to people whose lives differ from the norm in some way, and anyone can become one of them later. That is why the pool does not ask who you are. It only keeps known hacks and thefts out of the crowd: the people who cannot hide here are the ones who stole, and they are the only ones.
To tell a stolen haul from an ordinary deposit, the ASP learns what is normal in the pool from its own deposits, as security teams do when they baseline behaviour (UEBA), and lets what stands out wait before it is approved. It reads only what a deposit shows on chain anyway, never the withdrawals, so it can say that a deposit is unusual, never where its money went. With more use the baseline has more to learn from, and its picture of normal gets sharper.
The safest data is data nobody collects. Here is what each party can see, checked against the code:
| Who | What they can see |
|---|---|
| Everyone | The chain is public. A zip shows your wallet, the amount and the time. An unzip shows the recipient, the amount and the time, never which deposit paid. Public speeches and knocks show the wallet; anonymous ones show no author. Every burn and gift amount is public. |
| The relayer | Ours, or another one you pick. It sees what it sends for you: the recipient and amount of an unzip, the text of a speech or knock. It cannot tell which note paid. It sees your IP address while it answers, keeps it in memory for a minute to limit abuse and never writes it down. It records only the transaction it sent, which is public anyway. |
| The vetting service | Only the chain: which wallet deposited, when, and where its funds came from. Every decision it makes is published with its reason. Where its rules page names a sanctions provider (TRM Labs), that provider is asked about each depositing wallet, an address the chain shows anyway, and about nothing else. GMGN is asked about each launch creator's history and, where the rules page says so, about each depositing wallet's trading (both addresses the chain shows anyway); never about withdrawals. |
| This website | The pages you load, like any website. Its logs leave out IP addresses. Your IP address is matched to a country in memory, only to keep the site closed in the few regions it may not serve and to make deposits and launches from a few more wait an hour (IP geolocation by DB-IP); neither is stored. Before a deposit the site tells the vetting service which wallet is about to deposit; from those regions, that wallet's address and the time are kept a day. No cookies, no analytics, no scripts from anyone else. To find your notes your browser downloads everyone's deposits and checks them itself, so no server learns which ones are yours. |
| Only you | Your 12 words and zip key (stored encrypted on this device), your notes, the proofs your browser makes, and the assistant's plans. |
| Your wallet and its network provider | Your IP address, your wallet address and the transactions your wallet sends, such as a zip or a ragequit. An unzip goes through the relayer, so your wallet sends nothing for it. Some wallets also preview transactions on their own servers before you sign. |
To leave even less: unzip to a fresh address, wait until more people have zipped after you (the unzip page counts them), unzip part of a note or a round amount, and open this site through a VPN or Tor Browser at its standard level, so neither the network provider nor the relayer sees your own IP address.
Moderation
Speeches and knocks are written to the blockchain and stay there for good: nobody can delete or change them, us included. What this site can choose is what it shows. It hides the text of a message only under the five rules below, says so in the message's place, and lists every case in a public register, like the vetting service's decisions.
M1Sexual content involving minors
Hidden at once and reported to the authorities.
M2Doxxing
Someone's private personal data without their consent: a home address, a phone number, identity documents, private photos.
M3Threats against a person
A credible threat of violence, or a call to harm a specific person.
M4Scams aimed at users
Fake Sotto links, fake escape kits, requests for someone's words or keys.
M5A court order
An order that binds the operator of this site. We publish that it came and what it hid, unless the order itself forbids that.
Never hidden: opinions, politics, insults, criticism of Sotto, jokes, adverts and spam (the burn is the price of spam). Nothing is hidden because it is unpopular, because someone complained loudly or because someone paid.
The relayer does not moderate. It sends every message it is given, unread and unchanged, so the rules apply to what this site displays, not to what can be said. Other frontends and the chain itself still show a hidden message.
Report a message, or appeal a decision, at abuse@staging.sotto.cash. A decision names the rule and gives a short reason that does not repeat the hidden content; a reversal is published the same way. The register's history is part of the published source.
The register is at /api/moderation and in the published source (infra/moderation/hidden.json).
Verify it yourself
Don't trust, verify. Every claim on this site comes with a way to check it without asking us: our proof of work, and the proof that the concept holds.
The source is here, on this site
Download it from this site, no account anywhere, and build it yourself. See Source code.
The programs on-chain are that code
Build them with
scripts/verifiable-build.sh(the Solana Foundation's container, pinned by digest) and compare withsolana-verify get-program-hash <program id>. The hashes are published with every release; two independent builds give the same bytes.Nobody can change them quickly
solana program show <program id>shows the upgrade authority: a Squads v4 multisig (2 of 3, with a 48-hour time lock on mainnet). Squads itself was rebuilt from its audited source and matches its frozen on-chain program.Your exit does not depend on us
Ragequit is a program instruction, not a service. The escape kit finds your notes from on-chain events with only your 12 words, your wallet and any RPC, and takes them back. See If Sotto disappears.
Every vetting decision is public
The ASP transparency page lists every approval, rejection, revocation and reinstatement with its reason and blocklist version; each published set rebuilds the exact root stored on-chain.
The numbers are real
Everything on Analytics comes from the chain through a public index; the pool's vault always equals the unspent notes, which anyone can recount from the events.
This website is the code
/release.json names the commit and the hash of every file; a rebuild of that commit gives identical files.
It has been attacked, on purpose
Devnet campaigns run every attack we could think of (all failed with the expected error), a 16-hour soak relayed 1,072 private withdrawals without a product failure, and a fuzzer ran tens of millions of hostile operations. The audit so far is internal, by the same AI-assisted team that wrote the code, and says so; an independent audit comes before large deposits.
- privacy_pool
- FtCop5gv5KpmoDc9Wzv6qHu3FpyMr5ydCWa2rbx5A1Wd
- broadcaster
- 7zq1iYfcgoz3yqv8XMyvbbjLpYQqiVaiCQTsagZPBaT6
- doorstep
- 3v98B3du8iytDv7MDHjkLD1xQMnd2BZjRuaNtadoDM7F
- token mint
- 3ahHy95Tc6i2yc7997WfRR7V6MW7CxbDTn8eYFpM6baU
Source code
The code of the programs, the circuits, the SDK, the services and this website is published here, with every release, as one snapshot of the commit that was built. It is open source: our code under Apache-2.0, the in-browser prover under GPL-3.0 (third-party licences).
- sotto-source.tar.gz
The source, as an archive.
- sotto.bundle
The same, as a git repository.
- SHA256SUMS
Hashes of both files.
git clone https://staging.sotto.cash/source/sotto.git sotto # straight from this site # or download: sha256sum -c SHA256SUMS, then git clone -b source sotto.bundle sotto cd sotto && pnpm install && pnpm build # then scripts/verifiable-build.sh
What is in it: everything needed to build, verify and audit Sotto: programs, circuits and their artifacts, SDK, services, website, tests, build and verification scripts, design decisions and the technical reports this site cites. What is not: our internal planning, operating and test-infrastructure notes, which are not needed for any of that. The snapshot has no history and no names: it is the code, nothing about us.
If Sotto disappears
Your funds are in a program on Solana, not with us. Three ways out, from easiest to the one that needs nothing from us at all:
1 · Every day: the button
Get my funds out takes your notes back to the wallet that zipped them, in a few clicks.
2 · Our servers are down, this site still loads
The same page reads your notes straight from the blockchain (“Read my notes from the blockchain”). It is slower, but it needs no Sotto service.
3 · This site is gone: the escape kit
One small download, made for this day. With Node.js, your 12 words and your wallet's private key it finds your notes on-chain and takes them back. It talks only to a Solana RPC. Download it now and keep it with your words. If the site is gone, so is the download.
Also: a copy on IPFS
The escape pages (this one, “Get my funds out”, Backup & recover), the kit and the source, as a copy on IPFS that needs no Sotto server. Its address is a hash of its content, so nobody can change it without changing the address; anyone can rebuild it from the source and get the same address. The address is published here at launch.
- sotto-escape-kit.tar.gz
The kit (~2 MB).
- SHA256SUMS
Its hash, to check the download.
sha256sum -c SHA256SUMS && tar xzf sotto-escape-kit.tar.gz && cd sotto-escape node sotto-escape.mjs # lists your notes, sends nothing node sotto-escape.mjs --execute # takes them back (public: links each deposit to the wallet) # faster with your own RPC: --rpc <url>
It asks for the words and the key with hidden input and never sends them anywhere. Its source is part of the published code (apps/services/src/ops/escape.ts).
Beware of fake kits
Sotto never sends the kit in a message, an email or a DM, and nobody from Sotto will ever ask for your words or your key. A kit that reaches you any other way is a tool to rob you. Before you run one, check that its hash matches in more than one place: SHA256SUMS on this page,
/release.json, the IPFS copy (whose address fixes every byte) and a kit you build yourself from the source with the public settings in /release.json, which comes out byte for byte the same.Hardware wallet? No key needed
A Ledger or Trezor cannot hand out its key, and should not. Use Get my funds out instead, here or on the IPFS copy: connect the wallet as usual and approve each ragequit on the device. The kit's key prompt is the last resort for software wallets, when no copy of the page loads.
Glossary
- Note
- A private claim on tokens in the pool. Only your zip key can spend it.
- Commitment
- The public fingerprint of a note stored on-chain. It reveals nothing about the owner.
- Nullifier
- A one-time tag published when a note is spent. It stops double spending without saying which note it was.
- Zero-knowledge proof
- A short proof, made in your browser, that you own an approved note, without revealing which one.
- ASP
- Association Set Provider: vets deposits and publishes the set of approved ones. It can delay, never take.
- Relayer
- Submits your private transaction and pays its fee, so your fresh address needs no SOL.
- Ragequit
- The public exit: the original depositor takes a note's full value back, always.
- Quantum vault
- Where SOL and tokens sit behind a hash-only one-time signature from your 12 words, out of reach of a broken elliptic curve.
- Zip key
- Your 12-word phrase. It finds and spends your notes; it never leaves your browser.
Risks
Not audited yet
The programs will be externally audited before launch. Until they are frozen, a multisig can upgrade them (with a 48-hour warning).
Services can delay, not steal
The relayer and the vetting service are run by the team. They can be slow or refuse; they can never move your tokens, and ragequit never depends on them.
Privacy is a crowd
Anonymity grows with the number of people using the pool. Unzipping the same amount right after zipping is easy to link.
A meme token
The price can go to zero. Nothing here is investment advice.
Not affiliated with 0xbow, zipcoin, or any person.
Questions
Do I need SOL to unzip?
No. A relayer pays the network fee and, if needed, the recipient's token account rent. It takes a small fee from the unzipped amount.
How long until I can unzip?
Usually after the vetting delay (minutes), once your deposit is approved. A deposit from a wallet (or a funder) first used only hours before, or one of several in an hour, waits two days, or a week for several of these, for a wallet whose deposit was refused before, or for one funder behind many depositing wallets, so funds fresh from a hack can be caught first. Your note shows when it will be checked, and ragequit works meanwhile.
Why does my wallet warn me about Sotto?
Wallets warn about sites and programs their security partners do not know yet, which is every new project. Before you approve, check three things: the site's address is exactly ours, the amount is what you typed, and the program is the Sotto program listed under Verify it yourself. Nothing Sotto asks you to sign can move funds you did not choose to move.
Is there an easier way?
The Assistant: say what you want in plain words (for example: send 2 sol to an address) or tap the choices. It plans the private way (hide now, send in two parts later, through a relayer), shows the real numbers, and your wallet approves every step. It runs in your browser; nothing you type is sent anywhere.
When should I unzip?
The unzip page offers two routes. Now: right away, and it says how good the cover is. Safer: it waits until at least ten other people have zipped after you, and the button unlocks by itself. The more people zip between your zip and your unzip, the harder it is to link them.
Can I unzip only part of a note?
Yes. You unzip any amount up to the note's value; the rest becomes a new note that only you can spend.
I lost my phrase.
Your 12 words are the only way back: the phrase is random, kept encrypted on the device you made it on, and cannot be re-created from your wallet. With the words, open Backup & recover on any device. Without them, private access to those notes is lost; the wallet that zipped can still take them back publicly (ragequit).
My deposit was not approved.
Ragequit it from the Unzip page: the wallet that zipped gets the full note value back, publicly.
Can the relayer change my message or steal my unzip?
No. The recipient, the fee, the message and the gift are sealed into your proof. Change one byte and the proof is invalid.
Where do I buy?
On pump.fun or any DEX, with the contract address from the home page. Check the address: copies exist.
Ready?
Zip quietly, or burn something and be heard.