Dusk Network: The Vault Doesn't Explain Itself

I've seen enough confidential security contracts to know the signer never gets the full picture. The vault holds the actual terms — encrypted balances, counterparty identities, the clauses that would tell you whether you're signing something reasonable or something reckless. What reaches the signer is a proof. The proof says the state transition is valid. It says nothing about whether it's wise.

I've watched people click approve on math they can verify and content they can't see. Every single time. The whole XSC standard depends on this holding — that people will keep authorizing state changes to a vault whose contents are, by design, none of their business until an auditor with the right disclosure key comes asking.

That's not a technical detail. It's a behavioral test.

Because the system isn't really being tested for whether zero-knowledge proofs check out — they always do, that's the point of a proof. It's testing whether the humans holding signing keys will keep trusting a green checkmark over their own read of the situation. Selective disclosure was built to protect the vault from the world. Nobody built anything to protect the signer from the vault.

What happens the first time the proof is valid and the outcome isn't?

#dusk @Dusk $DUSK