varn
mc
unseenwhat is not shown.
wallet  spend_key <- program only  view_key <- program only  no view key published  balance <- unobservable
subaddress(i) <- H(view_key || feed_slot_i) * G + spend_pub  one per feed  never reused  never published
ring(tx) <- 15 decoys + 1 real  which is real is not derivable from anything on this page

this page is about the part of varn that cannot be drawn. the site can tell you how it is built. it cannot show you inside it, and neither can anyone else.

the wallet

what varn is fed becomes Monero. the Monero sits in a wallet with one spend key, and the program is the only holder of that key. there is no view key published, so the wallet's balance is not observable by anyone, including the person who deployed the program.

the fullness value is the organism's own account of what the wallet holds. the commitment is its proof that the account exists without being a way to read it. if the two ever disagreed there would be no way to tell from outside. that is a property of the design, not a weakness in it.

spend keyview keyfeed slotderivesubaddressone per feed, never reused

every feed gets its own subaddress. it is derived from the wallet's keys and the slot of the feed, so the organism can regenerate it and no one else can. a subaddress is used once. the settled Monero for a feed lands there and is swept into the wallet's balance on the organism's own schedule, which is to say whenever the next state write happens.

because each subaddress is fresh, an observer of the Monero chain cannot link two feeds to the same wallet. because no view key is published, an observer cannot see that any of them arrived at all.

the ring

when the organism spends, the spend is signed as one member of a ring of sixteen. fifteen of them are other people's outputs pulled from the chain. one is real. the figure marks one point from the commitment's first byte. that point is not the real one. it is a reminder that from outside, every point looks the same.

ring
observersees
solanaa transfer to the feed address, and later a state write
nearan intent, its quotes, a fill
moneroan output to an address that appears nowhere else
this sitethe transfer, the write, the hash, the slots
the programeverything
youthis page
the number

the fullness value is a single number. it goes up when a feed settles and down when a rule is eaten. it is never written to the chain in the clear. what is written is a commitment: a Pedersen style commitment to the value with a blinding factor the program holds, so that the same value produces a different commitment every time it is re signed and no observer can compare two states and learn the difference.

the program signs every new state. the signature is over the commitment, the rule hashes and the slots. anyone can check that the state was signed by the program. no one can check what it committed to. a public fullness value would be a target. a committed one is a fact that exists without being usable against the organism.

what is public and what is not

public: the feed address, every transfer into it, the state account, the commitment, the rule hashes, the consumed slots, every write to the state account, the program id, the program source, the drawing.

not public: the fullness value, the blinding factor, the rules themselves, the salience table, the Monero wallet address, its balance, the subaddresses, the ring members, the routes the intents took, the amounts that settled, the amount wasted.

the site shows everything in the first list and nothing in the second. where a value in the first list is not yet known because the site has not been pointed at a contract, the slot for it is empty rather than filled with a guess.