Avail has detailed the architecture behind ShieldTX, its privacy system designed to separate a trader’s source of capital from the accounts used to trade perpetuals on Hyperliquid. According to Avail’s technical breakdown of ShieldTX, the system combines a private-note ledger, zero-knowledge proofs, solver-funded accounts and deferred settlement to make a user’s funding trail harder for public observers to reconstruct. ShieldTX has been operating in private beta since August rather than remaining solely a research design.
The privacy boundary is narrower than making Hyperliquid itself confidential. Positions opened through ShieldTX remain publicly visible from the ephemeral account that owns them, including activity associated with that account. What public observers lose is the straightforward onchain link connecting the user’s original deposit wallet with the position-specific Hyperliquid address. That distinction makes ShieldTX a transaction-shielding architecture rather than a private version of Hyperliquid.
Nightshade Separates Deposits From Trading Accounts
At the center of ShieldTX is Nightshade, a zero-knowledge appchain using a “commit-first, prove-later” model. Users deposit USDC into an Arbitrum settlement contract and receive an equivalent private note inside Nightshade. Transactions execute with sub-second appchain latency, while multiple state transitions are later proven through SP1, compressed and ultimately wrapped into a Groth16 proof verified by the Arbitrum settlement contract. This allows Nightshade activity to execute before its corresponding zero-knowledge proof reaches final settlement on Arbitrum.
Nightshade maintains commitment and nullifier trees that track existing and spent notes. Its circuits enforce ownership authorization, asset consistency, value conservation and double-spend prevention without publishing individual note movements to public observers. Zero-knowledge proofs constrain valid state transitions, but the current privacy model does not conceal everything from ShieldTX’s own infrastructure. The sequencer presently sees note preimages and user state in plaintext, although that information is not published publicly.
That differs from privacy systems such as Confidential APT on Aptos, which encrypts balances and transfer amounts while leaving addresses visible. Other architectures, including Polygon’s private stablecoin transfers, similarly draw specific boundaries around what is hidden and who can access protected information. “Private” onchain infrastructure therefore needs to be evaluated according to its exact threat model rather than treated as synonymous with complete anonymity.
Hyperliquid Execution Remains Public
When a user opens a position through ShieldTX, their Nightshade notes enter escrow and an intent specifies a solver and fresh Hyperliquid address. The solver supplies USDC to that address, provides evidence that funding occurred and receives the escrowed Nightshade note once the system accepts that evidence. The user then trades directly through Hyperliquid’s native order book. ShieldTX changes how capital reaches the trading account without replacing Hyperliquid’s execution environment.
There is currently an explicit trust assumption in that process. Nightshade relies on an external attestation to establish that the solver funded the Hyperliquid account correctly. Avail says its intended end state is cryptographic verification of that execution instead. The designated solver also learns which position-specific address it must fund, while the Nightshade sequencer retains visibility into private note state. Avail explicitly says the current architecture does not guarantee privacy against a colluding sequencer and solver.
This limitation matters in markets where public positioning can expose trading strategies. Hyperliquid’s transparent perpetual markets already make positions, liquidations and funding conditions observable, including periods when stock and commodity perpetuals have experienced extreme funding rates. ShieldTX is designed to reduce the ability to associate those visible positions with a known trader rather than hide the market activity itself.
Avail also says data availability for a scenario in which the Nightshade sequencer stops submitting proofs has not yet been integrated, meaning the architecture should not currently be described as relying on Avail DA for that resilience property. Future work includes client-side proving, reducing what the sequencer can observe and replacing external execution attestations with stronger cryptographic verification.
ShieldTX is therefore already a functioning private-beta trading system, but its current achievement is unlinkability of the funding graph rather than fully confidential trading. Its next technical milestones will determine whether Avail can progressively remove trust from the sequencer, solver and external-attestation layers while preserving the native Hyperliquid execution that gives the product its liquidity.
