Security

Security model

Cowl is non-custodial and private by construction. Here is exactly what each part guarantees — and what it deliberately cannot do.

Guarantees

  • ZK shielded pool. Balances and trades live inside zero-knowledge proofs. The explorer sees commitments and nullifiers, never amounts or addresses.
  • Compliance at the boundary. Tainted funds can’t enter the pool in the first place.
  • Relayer can censor, not seize. Relayers pay gas and may drop a transaction, but never read amounts, move funds, or deanonymize you. Route around a bad one.
  • Selective disclosure. View keys are read-only and scoped. There is no switch that makes an account public.
  • Non-custodial keys. Your keys stay on your device; no service can move your funds.

Threat model

AdversaryWhat they get
Block explorer / chain watcherCommitments and nullifiers — no amounts, assets, or links to you
MEV botNothing to front-run; orders are proofs, not public intents
Malicious relayerCan only ignore you; cannot read or move funds
Deposit-boundary observerDeposit amount and timing — mitigate with good hygiene at the edge
Testnet-first
Cowl is testnet-first and pre-audit for public networks. Do not commit mainnet funds until the protocol is audited and live. See the disclaimer.