On this page

Withdrawals & Exits

Withdraw to a public wallet and recover any private change after confirmation.

Withdraw private notes#

A withdrawal spends notes into a public recipient. Its proof covers the payout asset and amount, any private change and the relay fee. The Pool checks ownership and value conservation before sending the funds.

The payout asset, amount and recipient are visible onchain. If you submit from your own wallet, that wallet is also visible as the transaction sender.

How a private payment reaches its recipient
How a private payment reaches its recipient

Review the net payout#

Check the chain and recipient, token amount, fee and change. With vault shares, this sends shares to the public recipient; redemption into underlying assets is a separate operation. Controlled notes need their controller's current approval.

For a full-balance withdrawal, the payout and fee must fit the note's value. Show the net amount the recipient will receive before signing.

Submit from a wallet#

The direct withdrawal module runs without the relay API. It takes a locally checked proof and the user's approved terms, then checks the chain, deployment block, Pool code and verifier. It also checks the root, nullifiers and reserves and simulates the calldata before returning a wallet transaction plan.

Save the proof and a durable operation marker before the wallet prompt. Once the wallet returns a hash, keep the marker until you reconcile that transaction and recover any private change.

PathWhat you need
Relayed ordinary payoutCurrent relay fee policy and transaction status checks
Direct wallet payoutWallet gas, simulation of the submitted calldata and a saved attempt marker
Controlled-note payoutCurrent EOA, Safe or supported ERC-1271 approval
Share-token exitA checked public recipient and working token transfers

Reveal a Pending deposit's source#

This exit consumes one whole Pending deposit and publishes its original source and amount. The holder chooses the payout recipient separately; it need not be the depositor. Source disclosure carries no regulatory verdict.

The path uses a separate proof layout and requires the user to acknowledge the disclosure. Offer it as a choice, not an automatic fallback for an ordinary screened withdrawal.

If submission times out#

Check the original transaction against authenticated Pool history. Seeing unspent nullifiers now does not always mean a submitted transaction can never land. Retain its authorization until reconciliation resolves the attempt.

The direct module is a test path. To recover without the service, you also need the current deployment identity and authenticated static app and proof files. Check those before relying on this route during an outage.