The first trustless, permissionless wrapped Monero. Verify real XMR transactions on-chain without revealing your secrets.
Built for privacy, designed for everyone. Zero-knowledge proofs make trustless bridging possible.
Generate proofs in under 1 second with only ~1,167 constraints using our hybrid architecture
Ed25519 DLEQ proofs verified on-chain ensure your transaction secret never leaves your device
Built-in double-spend prevention with transaction hash tracking for full transparency
Successfully verified real Monero mainnet transactions on Base Sepolia testnet
Deploy on any EVM chain - currently live on Base Sepolia with Arbitrum mainnet planned
All proofs and transactions verifiable on-chain with full audit trail
Four simple steps to bridge your Monero trustlessly
Compute R = r·G, S = 8·r·A, and P = H_s·G + B off-chain using @noble/ed25519
Generate discrete log equality proof proving knowledge of r without revealing it
Create zero-knowledge proof binding all witness values with Poseidon commitment
Smart contract verifies both DLEQ and PLONK proofs, then mints wrapped XMR
Join the future of privacy-preserving cross-chain transfers