hackquest logo

Stealthy

Private Stablecoin Payments on Arbitrum

Videos

Tech Stack

Next
Node
Web3
Solidity
Circom
React
snarkjs
Poseidon

Description

Stealthy — Private Stablecoin Payments on Arbitrum Get paid in stablecoins. Stay unseen.

Stealthy is a non-custodial, privacy-preserving payment application built for the Arbitrum Open House Singapore Buildathon. It combines one-time stealth commitments with browser-generated zero-knowledge proofs to help users receive stablecoins without sending every payment directly to their publicly known wallet. The project supports USDG payments on Arbitrum Sepolia and Robinhood Chain Testnet.

THE PROBLEM

Public blockchain payments can expose a recipient’s balance, income, transaction history, and business relationships. Freelancers can reveal other clients. Employees can expose compensation and subsequent wallet activity. Businesses can reveal supplier relationships and treasury movements. Stealthy reduces direct exposure of the recipient’s everyday wallet while keeping payments on the selected chain.

OUR SOLUTION


Each payment creates a fresh cryptographic commitment using secp256k1 ECDH and Poseidon hashing. Funds are deposited into StealthPool against that commitment.
The recipient discovers matching payments locally using a private viewing key.
To claim funds, they generate a Groth16 zero-knowledge proof in their browser.
The smart contract verifies the proof before releasing the payment.
Viewing and spending keys are separate. A recipient can deliberately share a read-only viewing key with an accountant or auditor without granting permission to spend funds.

PAYMENT FLOW

REGISTER → SEND → SCAN → PROVE → CLAIM

1. Register Connect a wallet, sign the key-derivation message, and register the public meta-address on-chain.
2. Send Enter the registered recipient’s ordinary wallet address. The application creates a one-time commitment and deposits USDG into the pool.
3. Scan The recipient identifies incoming payments locally using their viewing key. 4. Prove The browser generates a proof showing knowledge of the spending secret and payment-specific shared secret, without revealing either.
5. Claim The contract verifies the proof, marks the note as withdrawn, and transfers funds to the proof-bound payout address.
6. Audit Recipients can share a read-only viewing key to enable incoming-payment discovery and CSV export.

WHY ZERO-KNOWLEDGE MATTERS

The contract must verify that a claimant knows the secrets opening a specific payment commitment without requiring those secrets to be published.
The circuit proves: spendPub = Poseidon(spendPriv) commitment = Poseidon(spendPub, sharedSecret) The proof binds the commitment, payout address, relayer address, and fee. A copied proof cannot be modified to redirect funds or increase the fee.
Contract-enforced note status prevents repeated claims.

TECHNICAL ARCHITECTURE

Frontend: Next.js, React, TypeScript, Tailwind CSS
Wallet integration: wagmi and viem
Cryptography: secp256k1 ECDH, HKDF-SHA256, Poseidon
Circuit language: Circom
Proof system: Groth16 over BN254
Browser proving: snarkjs and WebAssembly
Smart contracts: Solidity with OpenZeppelin components
Primary stablecoin: Paxos USDG

StealthKeyRegistry publishes recipient public keys.
StealthPool holds deposited funds and processes proof-authorised claims.
Groth16Verifier verifies withdrawal proofs on-chain.

Key derivation, payment scanning, and proof generation run in the browser. There is no separate application server holding users’ spending keys.

USDG permit support combines allowance and deposit into one on-chain transaction after a signature. ETH payments are configured on both testnets, with USDC additionally configured on Arbitrum Sepolia.

DEPLOYED CONTRACTS

Addresses recorded in the repository’s deployment files:

Arbitrum Sepolia Chain ID: 421614
StealthPool: 0xFfe0a95A1Ffd486e7f516791d5c63803a88C77b7 https://sepolia.arbiscan.io/address/0xFfe0a95A1Ffd486e7f516791d5c63803a88C77b7
StealthKeyRegistry: 0xEC3671ECE0C62e6BB7a50A4d24b77FF86a4ca7B1 https://sepolia.arbiscan.io/address/0xEC3671ECE0C62e6BB7a50A4d24b77FF86a4ca7B1
Groth16Verifier: 0xE474514770C384Cde73AaF618B4118960a0292e8 https://sepolia.arbiscan.io/address/0xE474514770C384Cde73AaF618B4118960a0292e8

Robinhood Chain Testnet Chain ID: 46630
StealthPool: 0xE474514770C384Cde73AaF618B4118960a0292e8 https://explorer.testnet.chain.robinhood.com/address/0xE474514770C384Cde73AaF618B4118960a0292e8
StealthKeyRegistry: 0x44abd6eB6091e29AC99fAea73891ffDCa5f19944 https://explorer.testnet.chain.robinhood.com/address/0x44abd6eB6091e29AC99fAea73891ffDCa5f19944
Groth16Verifier: 0xC8F99C4BbcE1Fab1Cf26B0Ef8756283D8a29252E https://explorer.testnet.chain.robinhood.com/address/0xC8F99C4BbcE1Fab1Cf26B0Ef8756283D8a29252E

INNOVATION HIGHLIGHTS

• Separate viewing and spending authority.
• Browser-generated proofs without a proving server.
• On-chain verification before funds are released.
• Proof-bound payout parameters that prevent redirection.
• Single-use commitments that prevent repeated claims.
• USDG payments with permit-based deposits.
• Read-only auditor access and CSV exports.
• Local payment discovery without a dedicated indexer.

DEMO LINKS

Live App: https://stealthyy.vercel.app

Pitch Desk : https://canva.link/6bo413t4pzxiqa2

SOURCE CODE

GitHub: https://github.com/theyuvan/Stealthy

Progress During Hackathon

Seeing discussions on Twitter about exposed wallet activity made me think about payment privacy. I brainstormed Stealthy and built it using Solidity, Next.js, and zero-knowledge proofs, with stablecoin payments on Arbitrum. My goal was simple: help people get paid without exposing their everyday wallet
Team Leader
YYuvan
Project Link
Sector
DeFiInfra