Skip to main content
Atrum’s privacy claim is specific. This page draws the exact line between what is hidden and what is not, so you know precisely what you are getting.

The one-line version

Everyone sees that a bet was placed and which side it backed. Nobody sees how much, or whose.
Red is public, green is private. The dotted edge is the whole product: a bet proves it owns some note in the tree without revealing which, so the chain from your address to your position is cut there.

Step by step

1

Deposit — public

Your address and the exact amount are visible. They have to be: real collateral moves, and a transfer is visible on any public chain. No cryptography hides that.Deposits must be in fixed denominations (powers of ten), enforced on-chain. An amount nobody else uses is a name tag — see Why denominations are a consensus rule.
2

Bet — the amount is hidden

This is the step that does the work.Your bet proves it owns some note in the commitment tree without revealing which one. An observer knows a deposit is being bet, but not whose. The stake itself is encrypted and the contract adds it to a running total it can never read.Public: that a bet happened, and its side. Private: the amount, and which deposit funded it.
3

While betting is open

Odds are published from the encrypted total — deliberately coarse (1% buckets) and infrequent (at most one publication per several bets). See Why the odds are coarse.
4

Settlement — totals become public

The final pool totals are revealed exactly. This is deliberate: a pro-rata payout needs real numbers, not a rounded ratio, and it is safe because betting has closed and the outcome is known, so nobody can act on it.Individual stakes are still not revealed.
5

Redeem — nothing moves, nothing is published

A winning position redeems into a new shielded note, not to an address. No money moves and no amount is published. The link between your position and your payout is severed here.
6

Withdraw — public again

The recipient address and the amount are public. Money is leaving; a transfer is visible.What stays hidden is which note funded it, which bet earned it, and when relative to your position — you withdraw at a time of your choosing, in a fixed denomination, with the remainder kept as a private change note.

What this means honestly

Atrum provides unlinkability, not invisibility. Your deposit and your withdrawal are both public events. What is broken is the link between them, and the size of what sits in between.
It is only as strong as the crowd. With one user there is no anonymity set and nothing is private. No cryptography changes that. Timing still leaks if you are careless. Deposit 100, withdraw 100 five minutes later, and you have linked yourself regardless of what the contracts do.

Why denominations are a consensus rule

An odd deposit does not only expose its owner. Each distinct amount is its own anonymity bucket, so one non-standard deposit shrinks the set for everyone else too. That makes it a shared-safety property, and shared-safety properties belong in consensus, not in a wallet that a power user can bypass by calling the contract directly. So the contract refuses any deposit that is not on the ladder.

Why the odds are coarse

A single published ratio leaks nothing about magnitudes — yes / (yes + no) is scale-free. A sequence of ratios is a different object, because three things are already public: every bet is a visible transaction, each bet’s side is public, and settlement reveals exact totals. Each published ratio is then one equation in the running sums, and settlement supplies the absolute scale a ratio alone would not. Publish once per bet at full precision and an observer ends up with roughly as many equations as unknown stakes. Atrum bounds this two ways: by capping the number of equations (several bets must land between publications) and by degrading each from an equality into an interval (1% buckets).
Odds are therefore deliberately less precise and less frequent than they could be. That is a considered trade: sharper odds would come at the cost of the privacy they are published alongside.

Saying it accurately

Atrum is about unlinkability, not invisibility. Deposits and withdrawals are ordinary public transactions; what is hidden is the size of your position and the link between the money going in and the money coming out. The claim, precisely: your position size is hidden while you hold it, and your payout cannot be traced back to your bet.