Skip to content

Styx Protocol · Changelog

Styx v2 changelog

Devnet onlyStyx v2 has run on Solana devnet since 2026-10-07. Test SOL, no real funds. Not externally audited. v1 stays on devnet as the fallback and will not go to mainnet. · In English

Styx v2 has run on Solana devnet at styx.cash since 2026-10-07, 10:11 Paris time. Devnet only: test SOL, no real funds, no mainnet deployment. Not externally audited. v1 stays deployed on devnet as the fallback and will not go to mainnet.

Each line names the test or the devnet record behind it. Tests and records live in our repository, which has been private since 2026-10-02; the transactions are public on Solana devnet.

What v2 adds over v1

  • Any amount. v1 moved fixed notes of 0.1, 1 or 10 SOL. v2 pays any amount up to 10 SOL from one private balance, filled by deposits in ten sizes from 0.005 to 5 SOL. Backed by: the pool settings written on devnet on 2026-10-04 (deployment record, section 5) and 30 payments of 0.12 SOL on 2026-10-05 (deployment record, section 8).
  • Your wallet does not sign your payments. Our relayer signs and pays each pool transaction, so a reader of the chain sees the relayer, not your wallet. Backed by: the fee payer of every measured pool transaction is the relayer key (launch log p03-pay-ohttp, 2026-10-07; WP10d transaction shapes, 2026-10-06).
  • A new verifier, checking every proof in full on chain. p01_stark_verifier_v2, deployed on devnet on 2026-10-04, checks each proof over the transactions our relayer submits: 60.7 per payment on average over 30 payments (2026-10-05). The hash is Poseidon2 with a four-element fingerprint, and the challenges come from a cubic extension field: the design answer to v1's findings F2 and F52. Backed by: the deployment record, sections 3 and 8; MAINNET-BUDGET, section 3.
  • Pay a Styx address. A static address you can share. A payment to it is sealed for you with post-quantum encryption, ML-KEM-768, combined with X25519; every record on chain has the same size and shape. Backed by: pool-core e2e.test.ts; web StyxAddress.test.tsx; a browser payment to a Styx address on 2026-10-07.
  • Payment requests and payment links. A request lets someone pay into your private balance, the amount set by you or by the payer. A link works like cash: whoever holds it claims it, with no wallet; the sender sees when. Backed by: pool-core wp10e.test.ts and claim.test.ts; one link paid and claimed on devnet on 2026-10-07 (deployment record, WP10e section E).
  • Clickable share links. A payment request, a Styx address or a payment link is shared as an https link to styx.cash/pay; the payment itself sits after the #, a part of the address the browser never sends to a server. Backed by: web payLink.test.ts, ShareLinks.test.tsx and PayLinkPage.test.tsx; a preview run on 2026-10-07, 14:22 to 14:32Z.
  • Withdraw to any Solana address, from 0.0016 SOL, on a 0.0001 SOL grid. Backed by: two browser payouts to fresh addresses on 2026-10-07, 23.3 s and 24.4 s from the click.
  • A private balance that opens by itself. Connecting asks for two signatures, one for your keys and one that unlocks the copy kept encrypted in your browser; neither sends a transaction or costs anything. The balance syncs in the background. You write down 24 words when the app reminds you, and those words alone restore it. Backed by: pool-core easy.test.ts and recoverable.test.ts (a words-only recovery, end to end); web PlugAndPlay.test.tsx; browser runs on 2026-10-07.
  • Sends leave at once. No send waits for a crowd. Below 20 people since your own deposits, the app says in one line that the receiver could match the payment by its time. Backed by: pool-core point82.test.ts; a browser payment from an empty private balance on 2026-10-07, 134 s from the click with no crowd.
  • Your own withdrawals keep their guard, for at most about 10 minutes. To the wallet you connected, a wallet you withdrew to before, or a wallet that funded your deposits: the app warns when the amount would match a payment you received and offers a different amount. If few others withdrew since you were paid, or few people deposited since your deposits, it waits for them, at most 8 to 12 minutes after the click (drawn at random), then sends anyway. Backed by: pool-core point82.test.ts, point84.test.ts, wp10f.test.ts, wp10e.exitShift.test.ts and wp10e.exitShift.wallet.test.ts; web OwnWithdrawal.test.tsx; the browser run of 2026-10-07.
  • Deposits go one at a time. Several deposits at once from one wallet would show the amount, so a wallet deposits one size at a time: within an hour of a deposit it waits, and a top-up that needs several sizes makes one now and the next ones 1 to 6 hours apart. A send that one deposit covers leaves after that deposit. Backed by: pool-core wp10f.wallet.test.ts and topup.test.ts; web FreeAmountTopUpRequest.test.tsx.
  • Your v1 notes move into v2. Held notes of the 0.1, 1 and 10 SOL pools count in your balance and move into v2 when a send needs them. Backed by: pool-core migrate.test.ts; a migration on devnet on 2026-10-05 (deployment record, section 6d).
  • A private route for your IP address. On styx.cash this site relays your payment as a sealed message (Oblivious HTTP): it sees your IP address, not the payment; our worker sees the payment, not your IP address. Backed by: pool-core ohttp.test.ts; a payment through it on 2026-10-07, 32.5 s (launch log p03-pay-ohttp).
  • No IP address reaches Helius. The app reads the chain, sends your deposits and waits for your payments through this site; your browser opens no connection to Helius. The reads go sealed to our worker once the worker offers its read route; until then this site passes them on in clear and sees your IP address and what is read, and the line before you send says which. Backed by: pool-core ohttpRead.test.ts and pollLogs.test.ts; web v2ReadRoute.test.ts and v2OhttpReadRelay.test.ts; two browser runs on 2026-10-07 with 0 requests from the page to Helius or another RPC host, one sealed through a local read gateway, one on a preview through the site's plain read proxy.
  • Abuse limits that cost no SOL. An anonymous proof of work on every submission, an on-chain reservation of the notes being spent, and a relayer budget with a stop-loss read from the chain. Backed by: pool-core pow.test.ts, budget.test.ts and precheck.test.ts, and the litesvm reserve.test.ts on the real programs; the adversarial runs on devnet of 2026-10-06 (deployment record, WP10c section C).

Fees and limits (devnet, set on 2026-10-04)

  • Deposit: 1 % of each deposit to the Styx treasury, plus the Solana fee of the deposit (0.000005 SOL) and 0.000000469 SOL to the pool's fee pot.
  • Payment or withdrawal: 0.00065 SOL from your private balance. The relayer pays the Solana fees.
  • At most 10 SOL per payment. Ten deposit sizes, 0.005 to 5 SOL.
  • A fresh deposit can be spent once the pool's next checkpoint includes it: one every 750 slots, 179 s at the devnet slot time measured on 2026-10-05 (238.4 ms).

Measured speed (devnet)

  • 30 payments from a funded balance through our hosted worker, 2026-10-06: median 20.0 s, p90 33.0 s, from the click to the landing. This was before the private route was on.
  • One payment through the private route, 2026-10-07: 32.5 s.
  • Two payouts to fresh Solana addresses, 2026-10-07: 23.3 s and 24.4 s.
  • One payment from an empty private balance, one deposit included, 2026-10-07: 134 s. It left 108 s after the click, once a checkpoint held its deposit. The receiver's app showed it 156 s after it landed.

What changed for v1 users

  • The app shows one private balance with Send, Receive and Subscriptions. The Shield tab and the fixed amounts are gone.
  • Notes of the closed 100, 500 and 1,000 SOL pools cannot move into v2. The Advanced section keeps the recovery tools.
  • Subscriptions are parked for deeper work (2026-10-07): new subscriptions are not available; subscriptions you already hold keep running.
  • Nothing is lost on chain: a v1 deposit and a v1 withdrawal landed after the v2 upgrade (deployment record, sections 7 and 9d).

Known limits

  • Devnet only. Not externally audited.
  • Timing. Sends leave at once. When few people deposited since your deposit, a receiver who knows the amount and the minute could match your payment to your deposit by its time. The app says so before you send; v2 does not protect you against this in quiet periods.
  • On devnet, most of the crowd you hide in is our own test wallets.
  • The sender of a payment link sees when it is claimed.
  • Who sees your IP address: this site, when it relays a payment or a chain read; Helius sees only our servers. Until our worker offers its read route, this site also sees what the app reads, your deposit wallet's own history included. Your wallet extension may contact its own servers when it shows you a transaction to sign. Styx runs both the relay and the worker, so the private route splits what each server sees; it does not hide you from Styx itself. There is no Tor address yet.
  • Your own records are hidden under keys derived from your private balance's random secret. That hiding rests on the hash function: it is computational, not unconditional.
  • Internal attack tests on 2026-10-07 matched some test payments in small crowds: by their timing, which the line above states; by one deposit split into two sizes at the same second, since fixed (one deposit at a time, above); and by withdrawal times when few people withdraw, which the 10-minute wait narrows without closing: when few others withdraw, a withdrawal that leaves at its limit can still be matched by its time. They also saw link claims use 11 to 13 more compute units than payments on two samples; over 20 of each on the real programs the bands overlap (litesvm, 2026-10-07, pool-core wp10f.cu.test.ts). A new test round follows.