Last updated:
Nullmask is a zero-knowledge (ZK) privacy protocol that lets users make transactions on Ethereum Virtual Machine (EVM) blockchains private by shielding assets into a pool and transacting inside it without leaving an on-chain link between deposits and withdrawals.[1][2] Introduced on 17 March 2026 as a protocol designed and authored by cryptographer Tomas Krnak, its cryptographic architecture and technical documentation are published under his name rather than a named corporate entity.[8] The protocol is distinguished by installing as a "virtual network" inside a user's existing wallet rather than requiring a separate application, dedicated wallet, or new seed phrase.[1] Its central design claim is that spending authority never leaves the user's wallet, because shielded actions are authorized with standard Ethereum transactions.[3] The project summarizes its own purpose with the phrase "Make any wallet and any transaction private — in one click."[4]
Nullmask is a privacy layer for EVM-compatible blockchains. Users deposit, or "shield," assets into a zero-knowledge pool, conduct transfers and swaps privately within it, and later "unshield" funds to any address, with the protocol designed so that no observable on-chain relationship exists between the original deposit and the eventual withdrawal.[1][2] The protocol supports four private operations: shielded deposits, shielded transfers, shielded withdrawals, and shielded swaps.[6]
The protocol does not run its own blockchain. Instead it builds on existing layer 2 (L2) infrastructure to attach a shielded account to a user's wallet, and it treats actions on its own network as "intents for shielded actions" that are ultimately executed on the underlying EVM chains.[3] The project is tagged by third-party trackers under the "zk" and "Privacy" categories.[1][5]
Funds shielded into Nullmask are held in a UTXO-based privacy pool, a model in which balances are represented as discrete unspent outputs rather than a single mutable account balance. The pool is secured using Poseidon2 commitments and Merkle membership proofs, cryptographic structures that let the protocol confirm a deposit belongs to the pool without revealing which specific deposit it is.[6] When a user initiates an action, the protocol intercepts the transaction, generates a zero-knowledge proof on the client side, and submits it through a relayer, an intermediary that broadcasts the transaction so the original sender's identity is not exposed on-chain.[6]
Shielded Transfers allow tokens to be sent without revealing the sender, recipient, or amount on-chain. Shielded Swaps execute Uniswap V2 trades without exposing the user's identity, and private deposits and withdrawals are each validated by zero-knowledge proofs.[6] Private transfer amounts are hidden by design, which the project's analytics methodology notes means they are not included in reported volume figures.[2]
Rather than operating as a standalone application, Nullmask installs into a user's wallet as a virtual network, a one-time setup the project describes as taking about 20 seconds.[3] The virtual network uses Nullmask RPC middleware to decrypt shielded balances and to translate outgoing transactions into their shielded equivalents. This middleware can run remotely for faster onboarding or locally for what the project describes as maximum privacy.[3] Once installed, the protocol states that users can send, withdraw, and interact with decentralized applications directly from their existing web3 wallet without a separate app.[3]
The protocol is designed to work with MetaMask and any wallet compatible with EIP-1559, the Ethereum transaction fee standard, and it preserves a standard wallet user experience.[6] Nullmask uses standard 0x addresses and Ethereum Name Service (ENS) names rather than a separate shielded address scheme, and because it is backed by a wallet's existing seed, the project states no additional seed phrase must be stored.[3] It also supports hardware wallets, and the project states it provides full security without extracting spending authority from the device.[6]
A recurring theme in Nullmask's self-published design documentation is its handling of spending authority. The project contrasts its approach with other privacy solutions it names directly — Railgun, 0xbow, Hinkal, zERC20, and Zcash — which it claims rely on extracting spending authority from the wallet.[3] According to the documentation, extracting spending authority makes those approaches prone to phishing attacks and violates what it calls the fundamental principle of hardware wallets, that spending authority never leaves the device.[3]
The documentation states that Railgun and Zcash addressed this by requiring an additional signature over the shielded transaction, but that both rely on custom hash functions — it names Zcash Orchard's Sinsemilla and Railgun's "various-rate Poseidon" — which it claims require large precomputed lookup tables that are impractical for the constrained environment of a hardware wallet.[3] Nullmask instead authorizes shielded transactions with standard EIP-1559 transactions, which it states are already implemented in every hardware wallet, allowing shielded transactions from a hardware wallet with no change to the wallet's code. The project summarizes its position with the statement that "privacy wins when it stops feeling like a tradeoff."[3]
Nullmask includes built-in compliance tooling intended to limit abuse of the privacy pool. The protocol performs deposit screening and offers retrospective taint recovery through revocation keys, a mechanism the documentation presents as allowing previously accepted deposits to be traced back if they are later found to be illicit.[6] The project's analytics methodology notes that funds pending screening are excluded from reported total value locked.[2]
Nullmask's pool contracts are deployed behind an ERC1967 wrapper using the UUPS proxy pattern, so users interact with a proxy address while contract logic can be upgraded through an authorized upgrade controller.[9] At launch, upgrade permission is held by an AdminUpgradeController contract, which functions as a single upgrade admin and is initially controlled by the deployer.[9] The upgrade authority itself is upgradeable through the setUpgradeController() function, which can transfer the upgradeController role to alternative arrangements such as a timelock contract, a multisignature wallet, or a DAO governance contract, with only the current upgradeController authorized to perform this migration.[9]
Compliance-related parameters are also tied to this upgrade controller. The guard address, which is a privileged contract state variable, can be changed either by the existing guard or by the upgrade controller via setGuard(), while the verifier contracts and whitelist manager are updated through functions that require upgrade-controller approval.[9][10] The guard operates as a backend service that monitors deposits into the privacy pool and is the only address permitted to call approveDeposit() and rejectDeposit(), and with each approved deposit it publishes a revocation key pair whose public components and hash are embedded in the deposit event and commitment.[10][11] These revocation keys enable retrospective taint recovery by allowing participants to detect whether their notes are funded by a subsequently flagged deposit, prove disassociation from tainted funds, or selectively clean affected balances, with control over the revocation mechanism mediated through the guard service and the upgrade controller described in the smart-contract specification.[11][9]
Nullmask's documentation lists deployments on Ethereum, Arbitrum, MegaETH, Base, and BSC (BNB Smart Chain), and the protocol supports native ETH alongside any supported ERC-20 token.[6] The project's analytics dashboard, which reflects live operation, records the privacy pools as active on two chains: Ethereum, supporting ETH and USDT and live since 1 October 2026, and Base, supporting ETH and USDC and live since 7 October 2026.[2] The pool contract is deployed at the same address on both chains, with activity viewable through the Etherscan and Basescan block explorers.[2]
The MASK token is issued on the Solana blockchain and is tracked by data aggregators under the Solana ecosystem.[5][2] Supply figures reported by data providers differ slightly: CoinMarketCap lists a total and maximum supply of 990,994,347 MASK, which the project self-reports as a fully circulating supply, while CoinGecko lists a total supply of about 986.3 million against a maximum supply of 1 billion.[7][5] The token trades on both decentralized exchanges, including Meteora, Raydium, and Manifest, and centralized exchanges such as LBank, MEXC, and KCEX, with liquidity pools priced against SOL, USDC, and USDT.[5][7]
The token is linked to the protocol's economics through a rewards and buyback system tied to Zcash (ZEC). According to the project's dashboard, ZEC is distributed to MASK holders by StonkFun, with cumulative holder rewards of about $1.01 million recorded in early October 2026.[2] Separately, ZEC earned by the development wallet — about $514,000 in total, valued at the daily ZEC price — is used to buy back MASK, and the dashboard reports that MASK burned on-chain amounted to roughly 1.22% of the token's 1 billion initial supply.[2]
As of October 2026, available protocol documentation and smart-contract references do not describe any on-chain governance rights for MASK over the Nullmask pool contracts, where upgrade authority instead resides with the EVM-side upgrade controller contracts.[9] Public materials characterize MASK's economic role primarily through its linkage to ZEC-denominated rewards for holders and ZEC-funded buybacks that permanently burn tokens, rather than through fee-sharing mechanisms or staking-based governance over protocol parameters.[2]
The project maintains a public analytics dashboard on Dune that derives its figures by decoding the pool contracts' on-chain events on each chain since launch, combining both chains for totals while also showing per-chain breakdowns. The dashboard notes that its data is not real-time, with widgets refreshed on schedules ranging from every 30 minutes to every 6 hours.[2] In its methodology, volume is defined as the US dollar value of all shields and unshields priced at the minute of each transaction; total value locked (TVL) is the funds currently shielded in the pools, excluding unclaimed protocol fees and deposits awaiting screening; and total transfers counts all pool operations, including deposits, withdrawals, private transfers, and swaps.[2]
The protocol charges a fee of 0.5% on each deposit and 0.5% on each withdrawal, and it states that relayer gas compensation is not counted as a protocol fee.[2] From the Ethereum launch on 1 October 2026 through 8 October 2026, the dashboard recorded cumulative volume rising from about $1.07 million on the first day to roughly $15.97 million, generating cumulative fees of about $79,800.[2] Daily activity peaked on 4 October 2026 with about $3.64 million in volume and 1,000 total transfers, before declining later in the week. Base activity first appeared in the figures on 7 October 2026, contributing about $256,000 in volume that day.[2] Across both chains, the dashboard reported total platform volume of about $16.03 million and total platform fees of about $80,100.[2]
Nullmask is built as a monorepo spanning several components. Its zero-knowledge circuits use Noir, a language for writing ZK programs, together with the Barretenberg proving backend.[6] The smart contracts are written in Solidity 0.8.28 and developed with the Hardhat v3 framework and OpenZeppelin v5 libraries.[6] The frontend uses Next.js 15, React 19, and TailwindCSS 4, while backend services run on Fastify 5 and Node.js 24. The web3 integration layer uses the Viem and Wagmi libraries, persistent storage uses LMDB, and the monorepo is managed with Turborepo and the pnpm package manager, alongside code-quality tooling that includes Biome, TypeScript 5.9, and knip.[6]
The protocol's documentation is published through GitBook and is organized into sections covering an introduction to the protocol, how it works, a protocol specification detailing cryptographic algorithms and proofs, a Smart Contract Reference giving the Solidity API for deposits, transfers, and swaps, an RPC API Reference describing the JSON-RPC methods exposed by the proxy, a Developer Guide for building and running the protocol locally, and a User Guide with step-by-step instructions.[6] Each page is available in Markdown form, and the documentation can be queried programmatically through a GitBook API that returns direct answers with excerpts and sources drawn from the documentation.[6]