#dusk $DUSK @Dusk
I went back into Citadel's docs after noticing NPEX already has $300M+ of real, tokenized assets live on Dusk. That's not a testnet example anymore, so it made me want to check whether the privacy claim actually holds up under a real regulated venue, not just a whitepaper diagram.
Turns out the protocol is really two separate flows, not one.
First, a user requests a license from a License Provider, using a stealth address, so the issued license can't be linked back to the request.
Second, when the user wants to use a service, they don't resend the license. They send a zero-knowledge proof that they hold a valid one. The Service Provider only ever sees that proof, and it's the SP's own policy that decides what counts as sufficient.
Here's the part that made me pause. That proof isn't free. Citadel's own circuit for proving license ownership runs at roughly 34,800 constraints, and about half of that is just walking a Merkle tree 17 levels deep to confirm the license is actually registered.
So "prove without revealing" has a real computational cost baked into every single service request, not just a design principle on a slide.
That's a different model from "show your ID, let the platform verify everything."
It's closer to: pay a fixed proving cost once per interaction, in exchange for the venue never seeing anything but a yes or no.
What I still can't tell is whether that cost is invisible to an actual NPEX user today, wallet handles it in the background, or whether it's a real, felt delay standing between someone and a regulated trade.
I went back into Citadel's docs after noticing NPEX already has $300M+ of real, tokenized assets live on Dusk. That's not a testnet example anymore, so it made me want to check whether the privacy claim actually holds up under a real regulated venue, not just a whitepaper diagram.
Turns out the protocol is really two separate flows, not one.
First, a user requests a license from a License Provider, using a stealth address, so the issued license can't be linked back to the request.
Second, when the user wants to use a service, they don't resend the license. They send a zero-knowledge proof that they hold a valid one. The Service Provider only ever sees that proof, and it's the SP's own policy that decides what counts as sufficient.
Here's the part that made me pause. That proof isn't free. Citadel's own circuit for proving license ownership runs at roughly 34,800 constraints, and about half of that is just walking a Merkle tree 17 levels deep to confirm the license is actually registered.
So "prove without revealing" has a real computational cost baked into every single service request, not just a design principle on a slide.
That's a different model from "show your ID, let the platform verify everything."
It's closer to: pay a fixed proving cost once per interaction, in exchange for the venue never seeing anything but a yes or no.
What I still can't tell is whether that cost is invisible to an actual NPEX user today, wallet handles it in the background, or whether it's a real, felt delay standing between someone and a regulated trade.
