Shielded tokens
On Midnight, tokens are public by default. NIGHT is one of them. A public token is spent from a named address, and anyone reading the ledger can see who sent what to whom. AMP Finance holds only shielded tokens, on both sides of every loan, and refuses anything else.
- A shielded token hides who holds it; amounts stay public
- Each supported asset has its own shielding contract, backed one for one
- Shielding names the public address; unshielding names the payout address
- The shielded twin carries an s prefix: sNIGHT, sUSDC
- Shield in advance and hold a balance rather than shielding per transaction
Why everything is shielded
Put a public token anywhere in a loan and the privacy is gone in one transaction. The moment a lender's public tokens go into an offer, the offer and the lender's address are on display together. Shield one side and the other still gives it away: a borrower's public collateral would name the borrower just as surely.
A shielded token is one whose holder is hidden. The ledger records that the token exists and, when it is held by a contract, how much it is worth. It does not record which wallet holds it or which wallet spent it. Because every amount lent, borrowed, repaid, held as collateral or returned moves as a shielded token, no wallet address ever appears in a market. The ledger shows that an offer exists and that a loan was drawn from it. It cannot show who posted the offer or who drew the loan. Privacy lays out exactly where that line falls.
Each asset AMP Finance supports has its own shielding contract. It swaps the public token for a shielded twin, one for one, and keeps the public token in reserve until someone swaps back. Both versions are the same asset in the same amount; what changes is who can see it move.
Backed one for one
| Shield 100 | Receive 100 of the shielded twin |
| Unshield 100 | Receive 100 of the public token |
| Reserve | Never less than the shielded tokens in circulation |
| Fees, admin, pause | None in the contract |
| One contract per asset | So a problem with one asset can never touch another |
The Shield page shows, for each token, how much is in reserve and how much shielded supply is out, with a badge that reads Fully backed when the reserve covers the supply. Nobody can pause a shielding contract, skim from it, or change what it does.
Shielding a token
- Open the Shield page and choose the token. Only tokens with a shielding contract on this network are listed.
- Enter the amount. The maximum is the wallet's public balance of that token.
- Review. The confirmation shows what is sent, what is received, and the rate, which is always 1 to 1.
- Approve in the wallet. The shielded tokens arrive in the same wallet when the transaction confirms.
Shielding is the one action on AMP Finance that names a public address. The ledger shows that a given address shielded a given amount of a given token at a given time. Nothing the wallet does afterwards with the shielded tokens is tied back to that address, as long as the two are not lined up by amount and timing.
If the wallet window is dismissed or the connection drops mid-way, check the wallet's shielded balance before shielding again. A retry after a successful first attempt shields the amount a second time.
Unshielding a token
- Open the Shield page and switch to Unshield.
- Choose the token and the amount, up to the wallet's shielded balance.
- Choose where the public tokens go. The field defaults to the connected wallet's own public address, and any valid address can be entered.
- Review and approve. The public tokens arrive at the payout address when the transaction confirms.
The address that receives the public tokens is written on the ledger together with the amount. That is unavoidable: a public token has to go to a public address. So choose an address that is acceptable to have linked to this withdrawal. What is not recorded is where the shielded tokens came from.
Unshielding is one transaction with nothing to claim afterwards. If it does not go through, the shielded tokens are still in the wallet.
Keeping a shielded balance
Shielding is the moment a public address appears on the ledger. Everything done with shielded tokens afterwards is unlinked from it. The distance between the two is what an observer has to close, and the easiest way to give them nothing is to keep that distance wide.
Shield in advance and hold. A wallet that shields 5,000 sUSDC on Monday and posts an offer for 1,200 sUSDC on Thursday gives an observer nothing to line up: the amounts differ and the timing is unrelated. A wallet that shields 1,200 and posts 1,200 within the same minute has drawn the line itself.
Do not round-trip the same amount. Receiving a loan of exactly 1,000 and unshielding exactly 1,000 soon after ties the withdrawal to the loan by arithmetic. Keep the balance shielded for the next loan, or unshield a different amount at a different time.
Busier is safer. Privacy on AMP Finance grows with how much is going on. When many wallets shield, lend, borrow and repay in the same hour, any one action is one among many. When one loan is drawn in an afternoon, the shield that preceded it stands out. Holding a shielded balance across several loans is the individual version of the same idea.
Holding shielded tokens does not hide amounts. Every offer's size, every loan's principal and collateral, and every repayment are public figures on the ledger. What stays hidden is who they belong to.