Emergency exit (ragequit)

Every gate needs a door.

Emergency exitragequit — withdraws a note to a public address without proving association membership. No list, no authority and no service can stop it. It is the guarantee that makes everything else in proof of innocence a censorship lever rather than a custody lever: whatever the approved set says, your funds come back to you.

When you'd use it

  • Your funds' origin has been revoked — rightly, or by mistake.
  • The ASP has stopped publishing roots, so no recent root exists to prove against.
  • You simply want out and don't want to depend on any of the above.

Outside those cases, a normal withdrawal is strictly more private and costs the same. Use the emergency exit when a normal reveal won't go through.

The cost, stated plainly

A normal withdrawal keeps the origin hidden. This one publishes it.

The exited note's origin label is written on-chain, in the clear. That label is the deposit the money descends from — a deposit that is itself public. So an observer can connect that exit to that deposit, and to every other exit of the same lineage.

In practice: the emergency exit deanonymises the lineage you exit. It is a one-way trade — your money for the privacy of that particular chain of funds. It is your safety net, and you should know what it costs before you pull it.

What it does not reveal: your spend key, your other notes, your other origins, your balance, or anything about payments you made inside the pool.

What else is visible

  • The destination address and the amount — the same as any withdrawal. The money is public now either way.
  • That the exit was an emergency exit rather than a normal one, since it's a different on-chain action.

How to use it

  1. Open Withdraw / Reveal and enter the destination address and amount.
  2. Tick "Emergency public exit (ragequit)".
  3. Confirm. The button reads "Emergency exit (forfeit privacy)".

You can send to any address you choose — it is bound into the proof, so nothing can redirect it, but it is not restricted to the address you originally deposited from.

Things to know

  • It spends a single note and does no combining. The note you exit has to already cover the amount plus the fee. For a token exit it spends the token note plus a SOL note for the fee, and both of those origins are published.
  • It works for SOL and for any token.
  • The fee is the same as a normal withdrawal. No penalty for using it.
  • Prefer self-submitting if you can, so the exit isn't also correlated with a relayer's timing.
  • Exiting a note in full needs no room in the note tree. A full-value exit leaves no change note, so the program skips the append entirely — the escape hatch keeps working even if the pool's tree were completely full. A partial exit still writes a change note, so exit the whole note if you want that guarantee.

Revocation · Association sets · Withdraw · Limitations

results matching ""

    No results matching ""