Evaluating Unlink?

Security

Unlink never receives your spending key. Private spends require your authorization and a Groth16 proof verified onchain. Unlink’s protocol contracts and ZK circuits have completed a formal independent review, with an additional audit in progress. See the audit register below. For security reviews and diligence requests, email hello@unlink.xyz.

Security Model

How Unlink Protects Your Funds

Authority

Every spend is bound to your intent.

For transfers and withdrawals, the SDK verifies the prepared operation before requesting a signature. That signature is bound to the intended recipients and value, so it cannot authorize a different spend.

Enforcement

Proofs are verified onchain.

Private spends require a Groth16 proof. Unlink’s contracts verify that proof and enforce nullifier uniqueness so the same note cannot be spent twice. The proof binds the spend to the pool, chain, current Merkle root, consumed notes, and newly created commitments.

Recovery

Recovery is designed into the protocol.

The protocol includes a recovery path outside the standard relayer flow, reducing dependence on a single broadcaster when normal submission is unavailable. A valid signature and proof remain required, so recovery does not bypass authorization or protocol checks.

Ongoing Security Practices

Security Between Audits

Proving Artifact Integrity

Released proving artifacts are versioned, checksum-verified, and checked for drift from their circuit source before use.

Continuous Testing

Shared cryptographic vectors and contract invariants test consistent behavior across the SDK, backend, circuits, and contracts on every relevant change.

Vulnerability Reporting

This public disclosure policy and a direct contact give researchers a clear route to report vulnerabilities and coordinate fixes.

Audits

Independently Reviewed

Independent security firms review Unlink’s protocol contracts and ZK circuits. Each engagement is listed with its scope, status, and report availability.

Independent security review register
AuditorScopeStatus / dateReport

Veridise

Smart contracts and ZK circuits
In progress
Not yet available

Verity

Smart contracts, ZK circuits, verifier, and artifact pipeline; formal verification included
Complete
Report publication pending

Report a Vulnerability

If you believe you have found a vulnerability in Unlink, contact us directly with the affected component, expected impact, and a reproducible proof of concept, failing test, or formal argument. You may also include a proposed mitigation. Please do not disclose the issue publicly before we’ve coordinated a fix.

Email hello@unlink.xyz

Scope

Reports should concern vulnerabilities across Unlink’s contracts, ZK circuits, verifier, or proving inputs that affect:

  • Fund safety
  • Proof correctness and double-spend prevention
  • Privacy and linkability
  • Unauthorized account execution, replay, or sponsorship bypass

What to Expect

Unlink acknowledges reports promptly, coordinates triage and remediation, and keeps reporters informed through the fix. Researchers reporting in good faith receive public credit with their consent, and rewards may be offered at Unlink’s discretion for significant findings. Unlink does not pursue legal action against good-faith researchers acting within this policy.

Last updated