Shielded intents

The unit of work: an encrypted trade intent bound to a note commitment.

A shielded intent is a tuple (sell, buy, amount, minOut, deadline, recipient) encrypted to the settlement circuit's public key and bound to a note commitment cm. The wallet produces a Halo 2 proof that the intent is well-formed and funded without revealing any of its fields.

Lifecycle

StepProvable / publicHidden
1. ConstructNothingAll intent fields, wallet balance
2. Commitcm, proof of well-formedness, fee bondAssets, amounts, recipient
3. AuctionEncrypted bids, bid countRoute candidates, prices
4. SettleNullifier nf, net state transitionIntermediate hops, link to sender

The intent expires at deadline; an unfilled intent's note can be reclaimed by revealing its nullifier through a refund path, which is indistinguishable from a filled one to outside observers.