# Umbra Cash Markdown version of https://l2beat.com/privacy/projects/umbra ## Summary - Total Value Locked: N/A - Assets tracked: 5 - Buckets tracked: 5 - Deposits 7D: 149 (+4.92% compared to the previous seven days) - Deposits 30D: 358 - Deposits Total: 25.41 K - Tracked on: Ethereum - Attributes: Any amount, Stealth addresses ### Risks - Trusted setup: No setup (sentiment: neutral). No setup: This project does not have a ZK system and thus no setup-related trust assumptions. - Exit window: Infinite (sentiment: good). The core contracts are immutable. The owner can change the toll for future payments, but cannot stop recipients from accessing payments that have already been sent. This protocol passes the walkaway test: users can fully use it if all centralized protocol participants disappear. - Privacy: Recipient privacy. Public observer: Recipient private (sentiment: good); Chain analyst: Recipient at risk (sentiment: warning); Network observer: Recipient at risk (sentiment: warning); Privileged insider: Recipient private (sentiment: good); Future adversary: Recipient exposed (sentiment: bad). - Reproducibility: Reproducible (sentiment: good). The immutable core contracts, cryptographic library, and frontend are published and can be built and run locally. ### About A stealth-address payment protocol that hides the recipient behind a fresh address for every transfer. ### Links - Website: https://app.umbra.cash - Docs: https://app.umbra.cash/faq - Repository: https://github.com/ScopeLift/umbra-protocol - Social: https://x.com/UmbraCash, https://discord.com/invite/uw4y5J2p7C - Other: https://diligence.security/audits/2021/03/umbra-smart-contracts/ - Contracts explorer (Disco): https://disco.l2beat.com/ui/p/umbra ## Protocol description Umbra Cash is a stealth-address payment protocol. A recipient registers separate viewing and spending public keys, and a sender uses them to derive a fresh address that only the recipient can control. The sender transfers ETH directly to that address or routes an ERC-20 payment through the immutable Umbra contract, which emits the encrypted data needed to access the payment. ### Privacy considerations Umbra is not a mixer and does not use zero-knowledge proofs or an anonymity pool. The sender, amount, token, and fresh receiving address remain public. Privacy comes from hiding the identity of the person controlling that address. Although not enforced by the protocol, Umbra Cash users register their public keys on StealthKeyRegistry. On one hand, this allows stealth transfers between the sender and the recipient without exchanging any data offchain. On the other hand, stealth transfer recipients are very likely to be among the registered addresses, which reduces recipient anonymity set. ## Privacy **What the protocol promises:** Hides which registered recipient a stealth payment is for. The payer knows; sender, asset, amount and where the funds go next are public. On public blockchains like Ethereum, all actions transparent by default. A privacy protocol can at best cut the link between addresses or offer privacy while deposited. The colour says whether a careful user can keep the link, amount or recipient private against that adversary: green yes, yellow only outside supported options or by accepting another leak, red no. Fields marked at risk stay private only under the condition in their note. ### Public observer Recipient private (sentiment: good) **Who:** Everyone with a block explorer and some basic tools. Sees every public onchain event, but does no correlation beyond following links. Examples: A curious counterparty, an employer, a journalist. Announcements mark each stealth payment but not the recipient whose keys were used. The registry publishes the candidate recipients and their key history. **Advice:** Withdraw to a fresh address with no ENS name or prior activity, through the token relayer so your known wallet never funds the stealth address for gas. Keep funds from different stealth addresses apart. **Sources** - [Announcement, tokenPayments and TokenWithdrawal expose the fund path](https://l2beat.com/privacy/projects/umbra#Umbra) - [StealthKeyChanged publishes recipients and key changes](https://l2beat.com/privacy/projects/umbra#StealthKeyRegistry) - [Recipient matching decrypts locally and checks the stealth address](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/umbra-js/src/classes/Umbra.ts#L704-L720) ### Chain analyst Recipient at risk (sentiment: warning) **Who:** Scrapes all public data and correlates it: timing, amounts, gas and wallet fingerprints, address clusters. Examples: Chain analytics firms, ZachXBT, data brokers. Protocol use is public once a payment is announced, which narrows the anonymity set to registered recipients. Withdrawals to registered addresses, round trips back to the sender and a shared collecting address reveal or cluster recipients; membership alone does not identify them. The client withdraws one stealth address at a time and never merges them. **Advice:** Keep withdrawal destinations separate across payments and chains, and check that timing, amounts or recurring counterparties do not reconnect them to an identified account. **Sources** - [Sections 6–7: reuse heuristics, false positives and historical evaluation](https://arxiv.org/html/2308.01703v2#S6) - [Table 2: denominator is withdrawn payments; section 7.4: no fee matches](https://arxiv.org/html/2308.01703v2#S7) - [Client warns on linked destinations, but allows proceeding](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/components/AccountReceiveTable.vue#L671-L715) ### Network observer Recipient at risk (sentiment: warning) **Who:** Sits between the user and the chain and sees web2 traffic only: RPC providers, relayers and broadcasters, indexers, ISPs. Learns IP addresses, timing, browser fingerprints, ciphertext and what becomes public. Assumes Tor to send transactions and, where the client has an RPC setting, an own node to read the blockchain. Examples: Infura or Alchemy, a Tornado relayer, a wallet vendor selling telemetry, Google captcha or analytics in the dapp frontend. On the payer's side the wallet RPC resolves the recipient, reads their registry entry and broadcasts the stealth payment seconds apart, so that provider can pair the payment with the recipient. On your side the wallet RPC receives the matched stealth-address balance batch, while a build-configured mainnet RPC looks up your connected wallet and the senders of matched payments, and withdrawal destinations are checked against ENS, POAP and Gitcoin APIs. **Advice:** Run an inspected local build with every RPC pointed at your own node and the external name and safety lookups disabled. Send broadcasts and relay requests over Tor. **Sources** - [Payer flow: registry lookup and send through the wallet provider](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/pages/AccountSend.vue#L955-L1059) - [The wallet provider wraps the connected wallet](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/store/wallet.ts#L262-L267) - [Mainnet and Polygon RPCs are configured separately from the wallet](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/utils/constants.ts#L1-L17) - [Connected-wallet name lookup uses MAINNET_PROVIDER](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/store/wallet.ts#L336-L358) - [Matched senders go to mainnet name lookup; stealth balances to wallet RPC](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/components/AccountReceiveTable.vue#L584-L626) - [Withdrawal checks send destination to ENS, POAP and Gitcoin lookups](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/utils/address.ts#L255-L319) - [Signed relay request carries stealthAddr and acceptor](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/components/AccountReceiveTable.vue#L758-L768) ### Privileged insider Recipient private (sentiment: good) **Who:** Holds a protocol operator role or receives keys or plaintext by design: upgrade admin, sequencer, decryption or view key holder, TEE vendor, association set provider, hosted prover, note registry. Examples: A compliance backdoor key, a DAO with an upgrade key, a KMS committee, an ASP operator. The contracts are immutable and give no administrator a viewing key or a way to replace registered keys without the registrant. The client matches announcements locally, so no indexer or relayer has a protocol-wide view. **Advice:** Run an inspected local build of the client instead of the hosted frontend. **Sources** - [Owner sets toll, tollCollector and tollReceiver; withdrawals require authorization](https://l2beat.com/privacy/projects/umbra#Umbra) - [Direct registration or registrant-authorized signature, no admin override](https://l2beat.com/privacy/projects/umbra#StealthKeyRegistry) - [Viewing-key decryption is local to the client](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/umbra-js/src/classes/Umbra.ts#L704-L720) - [Relay API receives signed withdrawal data, not a viewing key](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/frontend/src/utils/umbra-api.ts#L96-L111) ### Future adversary Recipient exposed (sentiment: bad) **Who:** Harvest now, decrypt later. Holds every byte ever written onchain plus any retained logs, and future cryptanalysis such as a large quantum computer that breaks elliptic-curve key exchange and pairings, but not hashes, symmetric ciphers or lattices. Examples: First well-funded insiders, then everyone in a potential post-quantum future. Each announcement stores the ephemeral public key and the encrypted scalar. A quantum computer that breaks secp256k1 decrypts the scalar against every registered viewing key and checks which spending key yields the stealth address, identifying the recipient of every past payment. **Sources** - [Announcement archives pkx and ciphertext](https://l2beat.com/privacy/projects/umbra#Umbra) - [Historical public viewing and spending keys](https://l2beat.com/privacy/projects/umbra#StealthKeyRegistry) - [ECDH-derived hash encrypts the scalar by XOR](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/umbra-js/src/classes/KeyPair.ts#L121-L157) - [Recovered scalar is checked against the receiving address](https://github.com/ScopeLift/umbra-protocol/blob/a81df24e76a0d6ab1ec79c6353e28c527b1b1a80/umbra-js/src/classes/Umbra.ts#L704-L720) ## Flows The interactive flows chart is shown on [the HTML page](https://l2beat.com/privacy/projects/umbra#privacy-flows). ## Assets Breakdown | Asset | Deposits 7D | Deposits 30D | Deposits Total | | --- | --- | --- | --- | | DAI | 0 ($0.00) | 0 ($0.00) | 173 ($804.10 K) | | ETH | 149 ($4.48 M) | 328 ($10.24 M) | 23.73 K ($118.69 M) | | USDC | 0 ($0.00) | 10 ($130.08 K) | 707 ($4.60 M) | | USDT | 0 ($0.00) | 20 ($387.91 K) | 646 ($6.49 M) | | WBTC | 0 ($0.00) | 0 ($0.00) | 162 ($11.22 M) | | Total | 149 ($4.48 M) | 358 ($10.76 M) | 25.41 K ($141.82 M) | ## Risk summary ### Funds can be lost if 1. an unsupported ERC-20, such as a fee-on-transfer or rebasing token, causes the Umbra contract's internal accounting to diverge from its token balance. ### Privacy can be lost if 1. a recipient sends funds from a stealth address to a publicly linked address or consolidates payments in a recognizable way. 2. public timing, amount, token, or ENS registration patterns let an observer narrow down the possible recipient. ### New payments can be stopped if 1. the Umbra owner sets an arbitrarily high toll for contract-routed payments. ## Upgrades & Governance Umbra has no governance process or contract upgrade mechanism. The Umbra and StealthKeyRegistry contracts are immutable. The Umbra contract has a permissioned owner that can immediately set the ETH toll charged on every contract-routed payment and change the addresses that collect and receive those tolls. Because the toll has no upper bound, the owner can effectively stop new payments through the Umbra contract at any time. The owner cannot change the payment or withdrawal logic and cannot prevent recipients from accessing payments already sent to them, so the exit window is infinite and the protocol passes the walkaway test. ## Updates Each date links the update on the HTML page, which also shows its contract diffs. ### [2026-08-17 09:44 UTC](https://l2beat.com/privacy/projects/umbra?update=73958e78) (high severity, 3 changes) 7702 delegation. ### [2026-07-31 11:57 UTC](https://l2beat.com/privacy/projects/umbra?update=7c965433) (2 changes) Initial discovery of Umbra contracts ## Permissions Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/umbra ### Ethereum #### Actors ##### EOA 1 Addresses: [0x5777Aa6F437399Af6cef2Fce0BE8D4B4eD7C7232](https://etherscan.io/address/0x5777Aa6F437399Af6cef2Fce0BE8D4B4eD7C7232) - Can interact with Umbra - set an arbitrary ETH toll that must be paid on every transfer routed through the Umbra contract ## Smart contracts ![A diagram of the smart contract architecture](https://l2beat.com/static/images/architecture/umbra.5263be65.png) Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/umbra ### Ethereum #### StealthKeyRegistry Addresses: [0x31fe56609C65Cd0C510E7125f051D440424D38f3](https://etherscan.io/address/0x31fe56609C65Cd0C510E7125f051D440424D38f3#code) Public registry that maps an Ethereum address to its two secp256k1 stealth public keys: a spending key used to derive a fresh stealth address, and a viewing key used to encrypt the transfer metadata for the recipient. #### Umbra Addresses: [0xFb2dc580Eed955B528407b4d36FfaFe3da685401](https://etherscan.io/address/0xFb2dc580Eed955B528407b4d36FfaFe3da685401#code) Main entry point of the Umbra protocol, routing all ETH and ERC-20 stealth payments. On send, it emits an Announcement event that the recipient scans to detect the payment. ETH is forwarded directly to a fresh stealth address, ERC-20s are escrowed in this smart contract. - Roles: - **owner**: EOA 1