operator infrastructure for shielded rails

the proof layer behind
private spend.

zcash-shielded throughout. aggregates public. individual flows private. receipts anchored on mainnet. deterministic pipeline spec: v0 - implementation in progress.

open read shielded custody model
zush product zat explorer ctaz finality verify any hop
6
mainnet chains
~3,000
npm installs/mo
CC-BY-4.0
open spec
The 5 properties
1. Non-drainable
Agent transacts, never holds the full key.
Split-key custody via FROST 2-of-3. The agent signs its share; the owner holds the other. No single party can move funds alone.
zcash-ika
2. Policy-bound
Spend rules enforced on-chain, not by the agent.
Constraints live in Sui Move. The agent cannot override its own limits. Daily caps, whitelisted destinations, and withdrawal ceilings are chain-enforced.
Sui Move
3. Attested
Every action produces a Merkle receipt on Zcash mainnet.
BLAKE2b Merkle tree. Roots anchored in Orchard shielded memos. Anyone verifies: leaf, proof path, root, txid, block height. Cross-chain via EIP-152.
ZAP1
4. Remembering
Agent retains context across sessions.
persistent knowledge graph. every decision, relationship, and state transition carried forward. auditable memory, not a black box.
persistent state
5. Killable
Operator can halt the agent and secure all funds in one action.
FROST threshold signing. The kill switch revokes the agent key share, freezes all pending transactions, and attests the shutdown on-chain. The agent cannot prevent its own termination.
FROST 2-of-3
See all 5 properties in action.
open inspect verification surface
What ships inside

ZAP1 Attestation

Merkle tree commitment. Zcash mainnet anchor. Cross-chain verification via EIP-152 precompile. 712 gas per hash.

6 anchors127 leaves9 event types

Split-Key Custody

FROST 2-of-3 for BTC + ZEC signing. Honest-majority quorum. dWallet provisioning. On-chain policy via Sui Move.

zcash-ika54 exports

x402 Shielded Payments

HTTP 402 payment protocol for AI agents. Shielded ZEC via Orchard. Pay-per-call API access.

zcash-402Orchard

MCP + Agent Hooks

12 MCP tools via zcash-mcp. 14 attestation tools + 8 lifecycle hooks via openclaw-zap1. Full agent toolchain.

22 MCP tools + hooksMIT
See how attestation receipts render in Zodl wallet
Deployed on
Ethereum Arbitrum Base Hyperliquid NEAR Sui
Access Tiers
Free
$0
forever
All packages + crates
MCP + verify page
5 attestation leaves/day
GitHub support
Open access
Operator
$299
/month
Unlimited leaves
Cross-chain verification
Priority anchoring + event types
Ops channel + 99.5% SLA
Operator access
Custody
$999
/month
Managed dWallet + signing
Sui Move policy + FROST
Compliance exports + eng support
99.9% SLA + quarterly review
Custody access

Free is the trial. Paid tiers check out in shielded ZEC today. Read and verify stay open to everyone.

Recent receipts
Apr 17
CVE-2026-40881 / GHSA-xr93-pcq3-pxf8
Zebra addr/addrv2 deserialization DoS. Reporter: Zk-nd3r.
Apr 14
librustzcash PR #2278 merged
Merged as f646a111 by nuttycom into zcash/librustzcash.
Apr 14
ZecHub wiki PR #1547 merged
Add ZAP1 Attestation Protocol to Zcash Tech. Merged as e6d2b7e by zksquirrel into ZecHub/wiki.

Public record.

Open specification. CC-BY-4.0.

The verifier and attestation path are specified in public. Mining, agents, and trading can share the same receipt model without sharing customer identity data.

github.com/Frontier-Compute/shieldedvault-spec
Builder Path
open read protocol surfaces

Start from the verifier, receipt, and custody surfaces. The public docs map the current protocol edges without assuming a packaged quickstart.
spec / all packages