Getting started
SHUSH is a privacy transfer project on Solana. The current public site is pre-launch. Real SOL and USDC transfers must work on mainnet before the $SHUSH token launches. The application will become available after deployment and verification.
- Shield: connect a supported public wallet and deposit SOL or a supported token into a shared pool. The deposit is visible.
- Send: pay a SHUSH receive address from your private balance. The browser makes a zero-knowledge proof and the relayer submits it.
- Withdraw: return funds to a public Solana address. The withdrawal amount and destination are visible.
A SHUSH receive address is different from a public Solana address. Never send a normal wallet transfer directly to a receive address.
Privacy has boundaries.
The proof system hides private note ownership and internal payment amounts. It does not make all blockchain activity invisible.
| Hidden inside the pool | Still public or observable |
|---|
| Who owns a private note | Deposit amount and depositing wallet |
| Amounts in private payments | Withdrawal amount and destination |
| A direct public-wallet signature on relayed payments | Pool choice, timing, transaction fees, IP and other network metadata |
Timing, distinctive amounts, small pools, and external information can link activity. The public RPC and hosted relayer observe traffic. SHUSH does not promise untraceability. Trading $SHUSH on pump.fun is public.
Your keys. Your responsibility.
Your recovery phrase derives the keys that spend your private notes. The browser stores an encrypted backup. Keep the phrase offline and protect the password you use to unlock it. Losing the phrase can permanently lose access.
The pool program holds the funds. Its proof checks enforce ownership, conservation and replay protection. The admin can list pools and change fees; a guardian sets deposit limits. Program upgrades are a separate trust assumption until the upgrade authority is revoked. Software bugs, device compromise, relayer downtime and RPC outages can affect availability or cause loss.
Enter a recovery phrase only into the verified SHUSH wallet on the correct domain. SHUSH support will never ask for it.
A quote before you confirm.
The default protocol policy targets a $0.10 base fee plus 0.25% of public deposit or withdrawal amounts, charged in USDC at utility launch. After the token launches, the fee token changes to $SHUSH. Private payments pay the base protocol fee. Prices and configured fees can change.
Depositors pay the protocol fee from their token account. For a relayed payment or withdrawal, the relayer pays the configured fee token and recovers its charge from the transferred asset. Network fees, account rent and relayer costs are additional. The wallet shows the actual quote and enforces a maximum fee.
During the USDC phase, protocol fees go to the treasury and no token burns are active. In the planned $SHUSH phase, half of the protocol fee burns and half goes to the treasury. Changing the fee token does not require redepositing existing private funds.
Two planned burn engines.
Protocol burns: after the token launch and fee transition, the pool program charges $SHUSH and burns half during each operation. The earlier USDC phase has no burns.
Creator fee buybacks: the intended split is 50% team and 50% buyback. Before graduation, the deployer claims creator fees and the bot forwards the buyback share. This depends on the bot, its keys and reliable forwarding. After graduation, the owner configures pump.fun's payout split. Correct configuration and first distribution still need verification.
Each buyback is designed to buy and burn the purchased tokens in one transaction. Automated operation depends on available SOL, the bot and the dedicated signing wallet. Burns do not guarantee price appreciation.
A normal SOL launch uses pump.fun's published creator fee schedule, rather than a fixed 3% creator tax. Check the actual schedule at launch.
The burn dashboard reads supply from the mint and classifies finalized transaction receipts. Supply reductions without a classified receipt may appear as other burns.
Where SHUSH stands.
The implementation exists in the Veilport repository and has passed local Solana transfer and buyback rehearsals. These are local tests with throwaway assets. They do not establish production readiness or constitute an independent audit.
- Public token and program launch: pending.
- Deployed devnet rehearsal and independent security review: required before opening mainnet utility.
- Production RPC, database, relayer and keeper provisioning: pending.
- Mainnet utility must pass transfer and recovery checks before the token launch. Graduation payouts and recoverable fee forwarding are separate token-stage prerequisites.
Only use published, verified deployment addresses when the project launches. Current site assets and preview routes do not identify a mainnet deployment.