See what your confidential transfer still reveals.

Solana's Token-2022 confidential transfers hide balances and amounts behind zero-knowledge proofs. Sunspot reads a transaction's structure and shows what an observer can still learn — an amount left in a log, a missing range proof, a decrypted balance written back in the clear — before it reaches mainnet.

Sunspot analyzes a structural model of a transaction, entirely in your browser. It does not decrypt, hold keys, or run the chain. A clean result is an aid to review, not a guarantee.

Confidentiality Analysis Developer Tools
Confidential Transfer Analyzer static · client-side
Pick a scenario to analyze it.

The model is a small JSON description of a transaction: the mint (and whether an auditor is set), the accounts it touches, and the ordered instructions — each of which may carry proofs, open or close a proof context, move a confidential or public amount, and expose values through sinks. The six example scenarios above are worked examples; paste your own to check a design.

Understanding the Results
01Instruction & CPI decodeThe confidential-transfer instruction flow and every CPI into the ZK ElGamal Proof program, drawn as a diagram.
02Proof completenessChecks each transfer carries all three proofs — equality, ciphertext-validity, range — in a fresh, closed context.
03Balance modelTracks the public, pending, and available balance each account moves through as the transaction runs.
04Information flowTraces confidential values to every observable sink — log, event, return, write, CPI — and tells a commitment from a leak.
05Three-observer viewShows what the public chain, an authorized viewer, and a wider audience each learn from a representative transfer.
06FindingsApplies the CT rule catalog and reports each issue — leak, missing proof, Fiat-Shamir gap, absent auditor — with a fix.
Roles & Scenarios

A confidential transfer looks the same to everyone on-chain — an opaque proof call and a ciphertext. But three people need three different assurances about it, and Sunspot answers each from the transaction's structure alone.

Role 01
Payments engineer
Ships a stablecoin transfer flow. Asks: does my transaction leak the amount anywhere — a log, an event, a receipt written back to an ordinary account — even though the balance itself is encrypted?
Sunspot traces every confidential value to its sinks and flags a leak the moment one crosses the boundary in the clear (CT-1, CT-2). Next: dry-run the transfer against a mainnet fork.
Role 02
Security auditor
Reviews a confidential-transfer program before sign-off. Asks: are all three proofs present and freshly scoped, and is any proof hand-rolled with a soundness gap?
Sunspot checks proof completeness, proof-context reuse, and the Fiat-Shamir transcript on bespoke proofs — the phantom-challenge class (CT-3, CT-4). Next: machine-checked proof wiring.
Role 03
Compliance officer
Owns selective disclosure for a regulated asset. Asks: is an auditor key configured, and is its audience exactly what policy intends — no broader?
Sunspot verifies the auditor policy and flags an absent or over-broad key against the mint's stated requirement (CT-5). Next: a verifiable compliance console.