Repository navigation
Releases: DarkWalletRH/dark-contracts
Release list
Dark Contracts 1.0.4: Audit package
Audit package. No contract or circuit changes: the deployed bytecode is unchanged and still reproduces from this release byte-for-byte.
Commit under review: 1ffe0d46c38603b612b165c54de403a5002a0fa6
Start here
- AUDIT.md: scope (2,488 hand-written lines plus 7,395 generated verifier lines), how to tie this commit to the deployed contracts on both chains, deployments and governance, build and test commands, known issues and accepted risks, and where we would like you to look hardest.
- docs/DARK-CB-1.md: the protocol specification the code cites as
§n, with dated implementation notes wherever the deployed code differs from the text. - docs/THREAT-MODEL.md, docs/INVARIANTS.md, docs/MUTATIONS.md, docs/CIRCUITS-REPORT.md: contract threat model, invariants I1–I15 and their tests, the mutation report (44/44 killed), and circuit measurements.
Changes
- The design documents above, published for the first time.
- AUDIT.md includes a reproduction of the timelock's bytecode (OpenZeppelin
TimelockController), alongside the existing pin checks for the vault, registry, verifiers and libraries. - The mutation runner's report is gitignored, and its out-of-scope rows are described accurately.
Dark Contracts 1.0.3: Corrected mutation harness
Test and tooling release. No contract or circuit changes: the deployed bytecode is unchanged and still reproduces from this release byte-for-byte.
Changes
- The mutation harness (
contracts/script/mutate.mjs) now runs an unmutated baseline first, copies everything the suite needs into its scratch tree, and counts a mutant as killed only when a test assertion fails; a mutant that fails to compile is reported separately as invalid. The previous harness could report a mutant as killed because of a setup error. - Re-run on the corrected harness: 44 mutants, 44 killed, 0 survived, 0 invalid. Four new mutants exposed a gap, now covered by new tests in
contracts/test/DarkVault.t.sol. - Depends on Dark SDK 0.4.3.
Dark Contracts 1.0.2: Documentation release
Documentation release. No contract or circuit changes: the deployed bytecode is unchanged and still reproduces from this release byte-for-byte.
Changes
- Comments and tool headers rewritten to state what each check guarantees; stale references and internal labels removed.
circuits/VERSIONS.tomldescribes the toolchain pins accurately and drops an unused block.circuits/toolsdeclares its own dependencies and ships a lockfile.- The npm package depends on Dark SDK 0.4.2.
Dark Contracts 1.0.1: Audit package
Audit package. No contract or circuit changes: the deployed bytecode is unchanged and still reproduces from this release byte-for-byte.
Changes
- Public CI: contract tests, circuit tests, generated-verifier tests, the verifier ↔ circuit tie, and deployed-bytecode reproduction on every push.
- npm package
@darkwalletrh/dark-contracts: ABIs, the deployment record and the verifier pins for integrators. - Every mainnet contract is source-verified on Blockscout as an exact match.
- Documentation: trust model, repository layout, build and test instructions, how to reproduce the deployed bytecode.
- Comments cleaned up.
Dark Contracts 1.0.0: Mainnet launch
Mainnet launch.
Deployment
The contract and circuit source of 0.9.0, unchanged, deployed to Robinhood Chain mainnet (chain id 4663) at block 75151289:
| Contract | Address |
|---|---|
DarkVault |
0xeD7a0c6899a6AC94Aea7A5b2F8f24a948042DA9C |
DarkKeyRegistry |
0x2E245135FD561965CC546c14C23C9162f36d9C87 |
DarkTimelock (owner, 48 h) |
0xADbF7E3cf5418BeAC10BcDD3BBD9a51dc19EBC54 |
- Owner: the timelock, whose only proposer, executor and canceller is a 2-of-3 Safe. The deployer holds no role.
- Guardian: a 1-of-2 Safe that can pause deposits and transfers and tighten caps, nothing else. Withdrawals can never be paused.
- Launch caps (USDG): max deposit 1,000; max inflow per account 2,500; max transfer 1,000; total value locked 50,000.
Changes
DeployDarkMainnet.s.soldeploys against the real USDG with the launch caps and refuses the wrong chain, a Safe that is an EOA, an owner Safe one key can operate, and any verifier or library that does not match its pin.- The verifier deploy recipe is shared with the bytecode check, so what is deployed and what is verified cannot drift apart.
- The bytecode check covers every deployed chain: fourteen contracts across mainnet and testnet.
Dark Contracts 0.9.0: Hardened testnet release
The reviewed, hardened testnet release of Dark's on-chain components.
Contents
DarkVault: deposit, apply-pending, private transfer and withdraw over twisted-ElGamal ciphertexts; caps with immutable hard ceilings; a guardian that can pause and tighten caps, nothing else; an owner that acts only through a 48-hour timelock. No proxy, nodelegatecall, no upgrade path. Withdrawals can never be paused.DarkKeyRegistry: immutable, ownerless key registry proven withdark_register.DarkGrumpkin: clean-room Grumpkin arithmetic, differentially tested against@noble/curves.- Circuits:
dark_register,dark_transfer,dark_withdraw,dark_disclose_rangein Noir (UltraHonk, keccak transcript, zero-knowledge on), with the generated Solidity verifiers.
Deployment
Deployed to Robinhood Chain testnet (chain id 46630) on 2026-09-20. Addresses are listed in the README.
Assurance
- Hardened after internal adversarial review rounds covering the contracts, the circuits and the deployment process. An independent audit is the next step.
- The runtime codehash of every deployed verifier and library is pinned; the deploy script refuses anything that does not match.
scripts/check-verifier-bytecode.mjsrebuilds the deployed verifiers and their libraries from source and compares the bytecode byte-for-byte; the vault and the registry are pinned by codehash.- Dark's contracts, circuits and deployment record are MIT OR Apache-2.0; the bb-generated verifiers are Apache-2.0.