Skip to main content

Privacy

"Nobody can tell who lent to whom" is the whole promise, and it is worth being exact about what it covers and what it does not. Think of it as two layers. The first is open to everyone and shows how positions relate to each other. The second is closed and hides who is behind them. The first layer is harmless only because the second one holds.

At a glance
  • Every offer, loan, amount, date and outcome is public
  • No wallet address is attached to any of them
  • Anyone given a shielded address can list its positions, retroactively
  • Shielding names an address; unshielding names the payout address
  • One link exposes everything an address has ever done here
  • Use a separate wallet for the protocol

What is visible and what is not​

Anyone can seeNobody can see
The full terms of every offer: amount, collateral, interest, term, and how much has been drawnWho posted any offer. There is no field for a lender's identity
Every loan's amounts, due date, grace window and status, and whether each side has collectedWho drew any loan
Which offer each loan was drawn fromWhich wallet holds the token for any position
Whether a loan was repaid on time, late, or seizedAny link between a shielded address and a position
That a shield happened, the public address that did it, and the amountThe secret behind any position's identifier. The interface picks it at random and forgets it once the transaction goes through
Where an unshield paid out to, and how much

Amounts are never hidden. Tokens held by the protocol show their value on the ledger, so the size of every escrow, every collateral posting and every repayment is public.

The public layer says "offer 12 lent 500 to loan 47, which was repaid two hours late". It never says who offer 12 is. As long as the private layer holds, the public layer is a record of anonymous positions relating to each other.

That is also why the private layer is fragile. One link between an address and a position exposes not just that position but everything the address has ever done here, because the public layer connects all of it. A lender with fifty loans is a visible hub on the public layer; the only thing keeping that hub anonymous is that nobody has tied it to a wallet.

Sharing a shielded address​

This is the single most important privacy fact about AMP Finance, and it is not obvious.

Warning

Anyone who has been given a shielded address can work out every payout that address has ever received from AMP Finance: every loan drawn, every repayment collected, every collateral returned or seized, and whether each was on time. Retroactively, and for as long as the address is used.

When the protocol pays out to a wallet, the payment is shielded from anyone who does not know the recipient. But it is checkable by anyone who does hold the recipient's shielded address. Each payout can be tested against a known address with a simple yes-or-no, and every payout in the protocol's history is on the ledger to be tested. So a counterparty, an exchange, a support desk, or anyone else who has been sent a shielded address can, if they choose, list that address's entire history here.

This is a property of the platform rather than of the protocol, and it cannot be closed from the protocol's side today. Position tokens themselves are not affected by it; payouts are. An observer who has never been given the address learns nothing from the ledger.

What to do

  • Do not share a shielded address used on AMP Finance with anyone who should not be able to see its positions.
  • Use a separate wallet for AMP Finance from the one whose address is given to exchanges, friends or services. Wallets are cheap; a separate seed phrase is the cleanest separation.
  • Treat a shielded address as identifying, not as anonymous, the moment it has been handed to someone.

Known leaks and what helps​

No design of this kind is airtight. Each remaining leak is listed with what actually helps.

What leaksWhat helps
Shielding names a public address and the amount.Unavoidable. The shielding contracts are general-purpose, so shielding a token says nothing about lending. Shield once and hold a balance rather than shielding per transaction.
A shield followed at once by an offer or a loan for the same amount links the two by timing.Keep a shielded balance and act from it later.
Unshielding shows the payout address and the amount.Unavoidable. Avoid the obvious match: do not receive exactly 1,000 and unshield exactly 1,000 twenty minutes later.
Anyone given a shielded address can list every position it was paid for.Do not share an address used here. Use a separate wallet.
Finding positions sends the wallet's list of token types to a service AMP Finance operates.That list names positions, not people, and is not stored. It is sent only when the Positions page is opened with a wallet connected.
A settled loan stays on the ledger permanently.Accepted. The record names no party.
A seizure shows that a loan was not repaid.Inherent to the mechanism. It shows a position defaulted, not who held it.
A partial draw on an offer can be blocked by a stranger, at a cost to themselves, so only a draw of the full remainder goes through.No money is lost. Draw the full remainder, or, as a lender, post several smaller offers.

Fees and DUST​

Transaction fees are paid in DUST, which is shielded, so paying a fee does not reveal who paid. AMP Finance does not sponsor fees on anyone's behalf: a sponsor would see the transaction and the person, which is exactly the link the design exists to break. Everyone pays their own. Fees and transactions.

Privacy grows with activity​

Busier is safer. When many wallets are acting in the same hour, one action is one among many and timing tells an observer little. When one loan is drawn in an afternoon, the shield before it stands out. The habits above are what an individual can do; the rest comes from the protocol being used.