The detail that stopped me in Citadel’s design: the license that lets a user privately prove compliance is never fully theirs.
It is signed by the license provider, cryptographically bound to the user’s stealth address (so it cannot be transferred), and recorded in a Merkle tree that the provider can update to revoke. The user generates a zero-knowledge proof of ownership and continued membership in that tree; the service provider still decides whether the proof is accepted and whether the license remains valid.
Dusk’s own December 2023 deliverables post confirms the Citadel SDK shipped and was integrated into the web wallet ahead of mainnet. The component exists. Whether any service provider is actively issuing or revoking licenses on mainnet today remains unverified.
$DUSK K #dusk @Dusk Foundation markets financial privacy as a right. The architecture routes that right through a party who can cut access at any time.
Revocation is not a flaw; it is how the system prevents licenses from being reused or abused after issuance. It does mean the “right” functions more like a standing permission: private by default, contingent on the issuer’s continued cooperation.
What changed for me was seeing selective disclosure and revocability as a single mechanism rather than two separate features. Zero-knowledge hides what you are proving. Who decides whether you may continue proving it is a different question—and that decision currently sits with the service provider.
Still open: whether any provider has published clear revocation criteria, and whether a Citadel license has actually been revoked on mainnet since launch.
It is signed by the license provider, cryptographically bound to the user’s stealth address (so it cannot be transferred), and recorded in a Merkle tree that the provider can update to revoke. The user generates a zero-knowledge proof of ownership and continued membership in that tree; the service provider still decides whether the proof is accepted and whether the license remains valid.
Dusk’s own December 2023 deliverables post confirms the Citadel SDK shipped and was integrated into the web wallet ahead of mainnet. The component exists. Whether any service provider is actively issuing or revoking licenses on mainnet today remains unverified.
$DUSK K #dusk @Dusk Foundation markets financial privacy as a right. The architecture routes that right through a party who can cut access at any time.
Revocation is not a flaw; it is how the system prevents licenses from being reused or abused after issuance. It does mean the “right” functions more like a standing permission: private by default, contingent on the issuer’s continued cooperation.
What changed for me was seeing selective disclosure and revocability as a single mechanism rather than two separate features. Zero-knowledge hides what you are proving. Who decides whether you may continue proving it is a different question—and that decision currently sits with the service provider.
Still open: whether any provider has published clear revocation criteria, and whether a Citadel license has actually been revoked on mainnet since launch.
