On this page

Migrate to Fuyu

Withdraw from another privacy protocol into a new Fuyu note on the same chain.

How migration works#

Migration withdraws assets to a receiving contract, which deposits them for your selected Fuyu account. It creates a new note. Source commitments, keys and proof systems remain with the source protocol, and its anonymity set stays separate from Fuyu's.

The source withdrawal and Fuyu deposit are publicly linkable. They must settle on the same chain. A mainnet withdrawal cannot fund a Sepolia destination through this flow.

Pending, Active and Settled notes
Pending, Active and Settled notes

Source routes#

The catalog contains tuples for Tornado Classic, Privacy Pools v1 and v2, current zk.money Oxide and legacy zk.money or Aztec Connect. Each tuple describes a particular source deployment. Check whether its client can execute the intended withdrawal before offering the route.

Availability is checked per route. Native assets, token denominations and source fees need different receipt checks. Async releases must reach Ethereum first, and historical wrapper shares need handling in their own units.

Source familyCheck before withdrawal
Tornado ClassicThe denomination and authorized recipient and fee
Privacy PoolsThe version's processor, proof files and receipt checks
Current zk.money OxideWhether its executor can release the intended asset
Legacy Aztec ConnectWhether the historical client and recovery work and value reaches Ethereum
Wrapper-share outputsShare units and support for any separate underlying conversion

Prepare the destination#

Select the Fuyu account and final asset. Review the net value, source fees, gas, public linkage and recovery address. Save an intent identifying the destination Pool, owner commitment, receiver terms and block used for that review.

Deploy the receiver and verify its creation receipt before displaying its address to the source client. Keep source notes and credentials in that client; the Fuyu API should not receive them.

Complete the deposit#

Follow the source transaction until its assets arrive at the receiver. Complete the Fuyu deposit, check its profile, policy and note events, then wait for the selected account to recover the note. That recovery marks completion.

Save the full journal before any wallet prompt. Wrong tokens, late transfers, cancellations and remainders must remain recoverable through the receiver's saved terms. They can go only to the fixed recovery address or private account specified there.

Before offering a route#

Live source-funded acceptance is still incomplete. Each source route needs a compatible Fuyu destination, a deployed receiver factory and a successful withdrawal through the actual source client, followed by Fuyu note recovery.

If a prerequisite is missing, explain it before asking the user to withdraw. A protocol name in the catalog alone is not enough to enable migration.