Using Redacted

Reserve and Spending

Updated 1 October 20265 min read

Your private wallet has two balances, the Reserve and Spending. That is the whole model, so there is no gas to manage, no wrapped tokens and nothing else to keep track of.

Your private wallet has two balances A public wallet deposits into the private Reserve and can withdraw from it. The Reserve and Spending move funds between them with zero-knowledge proofs, and Spending trades, swaps, stakes and borrows across all of Rujira. Your private wallet Public wallet Your visible address Private Reserve Shared and shielded. Your funds rest here as private notes. Private Spending Your private account, where DeFi happens. All of Rujira Trade, swap, stake, borrow. deposit withdraw zero-knowledge proofs

The Private Reserve

The Reserve is a shared space where every user's deposits live together. Your share of it takes the form of cryptographic notes that only your keys can decrypt, sitting among everyone else's notes, with no address or account entry attached.

That shared group is what protects you. When you later move funds out, you prove with a zero-knowledge proof that you own a note in the Reserve without revealing which one, so the link between your deposit and your later activity is never written anywhere. It works a bit like the vault room of a private bank, where everyone's boxes are in the same room and an observer can see people come and go without learning whose box is whose.

Private Spending

Spending is your personal private account. It is a smart-contract account created for you through the same proof system, with no visible tie to your public wallet, and it is where DeFi happens. From it you can trade on the orderbook, swap between coins of different chains, stake, lend, borrow and bid on liquidations. Positions belong to this account, and the account answers to your proofs, with no public address in control of it.

You move funds from the Reserve to Spending when you want to act, and back to the Reserve when you want them to rest among everyone else's notes. Returning funds mints fresh notes. With the node network, your own money comes back into the Reserve at once, while money someone else sent to your Spending account waits like a deposit (see Returns from Spending).

Returns from Spending A node traces where the money in a Spending account came from. Your own money comes back to the Reserve at once, including every gain your positions make in the share you put in and payments straight from another Redacted user's Reserve. Money that someone sends from outside Redacted waits like a deposit, and a mixed return is split so that your part comes back at once and the rest waits. Coins tied to known hacks or sanctions lists, or that cannot be checked, do not enter the Reserve. They stay in the Spending account, and the app offers to send them straight back to their sender. While incident mode or a deposit pause is on, returns wait for everyone. Your own money comes back at once What came from your Reserve, every gain your positions make in the share you put in, and payments straight from another Redacted user’s Reserve. Money someone else sent waits Coins someone sends to your Spending account’s address from outside Redacted enter the Reserve through the same wait as a deposit. A mixed return is split Your own part is back at once. The rest waits. Known hacks and sanctions lists Coins tied to them, or that cannot be checked, stay in your Spending account. The app offers to send them straight back to their sender. A node checks It traces where the money came from and confirms your own part in a signed statement, public on-chain. A return it cannot confirm waits like a deposit. Spending account Holds your own money, and anything others send to its address. The Reserve Private notes of all users, held together. it stays in the Spending account While incident mode or a deposit pause is on, returns wait for everyone, your own money included.

Sending coins to their own chain

Coins from other chains, such as BTC and ETH, live in your private balance as secured assets on THORChain, so a swap between coins of different chains settles inside THORChain and the result lands in your Spending account. Direct payouts from Spending to another chain are switched off at launch and follow in an upcoming update. Until then, BTC and ETH leave in two public steps. You withdraw the coin to a THORChain address of yours, and from that address you send it out with a SECURE- withdrawal to your Bitcoin or Ethereum address, which turns the secured asset back into the native coin. Both steps are public on THORChain, so a fresh THORChain address keeps your main wallet out of it.

The tx-less experience

After you sign in once, every trade, transfer and withdrawal is authorized by a proof that your browser generates locally and hands to a relayer. The relayer carries it on-chain and pays the network fee, so your wallet is never asked to sign again and there are no popups or gas top-ups. You get real on-chain execution with the feel of a web app.

How an action runs without a wallet popup You click Confirm. Your browser builds a zero-knowledge proof and hands the sealed action to a relayer. The relayer submits it to THORChain and pays the network fee, and when it is done your wallet has never signed anything. You Your browser A relayer THORChain Click “Confirm” Builds a zero-knowledge proof Hands over the sealed action Submits it, pays the fee Done. Your wallet never signed.

Every action is atomic, which means it runs completely or not at all and your funds are never caught halfway through a trade. The proof fixes everything about the action, including the amounts, the destination, the fee and even which relayer may submit it and until when. The relayer only delivers it and can't change what you authorized or spend anything on its own.

One account, everywhere

Your private account is a single identity. You can open it on a desktop, on a phone or in a fresh browser after losing your laptop, and it rebuilds from the chain and your keys alone. The app shows one active account at a time, and restoring a backup reopens the same identity instead of creating a copy.

Continue with How the privacy works, Fees or the architecture.