Why PrivacyPad
On Solana, a memecoin is a public diary. The wallet that created it, where that wallet’s money came from, every buy, every sell, every fee claim and every wallet that touched it are readable by anyone, forever, and a whole industry of trackers turns that into profiles: this dev, their last five coins, their main wallet, the exchange they cash out on.
PrivacyPad is for launching and trading without writing yourself into that diary. It is anonymous in the plain sense: no account, no e-mail, no sign-up, and no wallet connected to launch a coin. A launch is a secret you keep; a trader is a set of wallets in your browser that nothing ties to you.
Shielded is Zcash’s word. Zcash shields a payment by proving it is valid without showing who sent it, who received it or how much. PrivacyPad pairs every coin with a privacy coin (ZEC or XMR) and funds every trading wallet from a shielded pool that works the same way, so your money reaches the chain without a trail behind it. When the site says “shielded balance”, it means exactly that: funds inside the pool, where the chain cannot tell whose they are.
None of this hides the coin or the trades. They are on-chain like any other. What disappears is the line from them to you.
What Solana leaks
Everything on Solana is public by design. For a trader or a dev, that means:
- Every balance. Know one address and you see every token it holds, and the whole history of how it got them.
- Every link between wallets. A transfer, a shared fee payer, a co-signature or a rent refund ties two wallets together for good, and so does a wallet’s very first funding.
- Every creator. pump.fun names the wallet that created a coin, and the creator fees flow to an address tied to it.
- Every pattern. Same amounts, same minute, same parent: analysts group wallets without any direct transfer between them.
- Off-chain, your IP. RPC providers, wallet extensions and the sites you connect to see your IP next to the addresses you use.
A fresh wallet does not fix it: the moment you fund it from your main wallet or from an exchange, the two are one. The problem is not the wallet, it is the money going into it.
Zcash and shielding
Zcash is a blockchain with two kinds of address. Transparent addresses (starting with t1 or t3) work like Bitcoin: everything is public. Shielded addresses (zs1…, and unified addresses u1… that include one) keep sender, receiver and amount encrypted. A zero-knowledge proof shows the network that the payment balances and spends nothing twice, without showing what it is. Only the owner, or someone the owner gives a viewing key, can read it.
The coins inside Zcash’s shielded pool form one crowd: a payment out of it could come from any of them. The bigger the crowd, the stronger the privacy. That idea, a crowd of indistinguishable notes and a proof instead of a trail, is what “shielded” means everywhere on this site.
ZEC on Solana is a bridged version of ZEC: an ordinary SPL token with 8 decimals like Zcash itself. On Solana it is as public as any other token. PrivacyPad uses it for three reasons:
- Every PrivacyPad coin is paired with a privacy coin on pump.fun, ZEC or XMR (as wXMR) at the launcher's choice, so trading fees and profits are in that coin from the first trade.
- You never need to hold it: you trade in SOL, and each buy routes SOL to ZEC to the coin in one transaction (a sell, the other way).
- ZEC can leave Solana for Zcash itself, where it can be shielded for real. The router pays out to Zcash, and from there your own wallet shields it.
What ZEC does not do on its own: holding ZEC in a Solana wallet is not private. The privacy comes from how wallets are funded and emptied, which is the rest of this page.
How each leak is closed
- The creator wallet
- Usedpump.fun shows who created a coin. Trackers list that wallet's every launch, every sell, every past rug, and flag it on the next coin.
- FixA wallet generated for the coin creates it. It has never held anything of yours and never will.
- LeftEveryone can see the coin was made on PrivacyPad. That is the point: every PrivacyPad creator looks the same.
- The funding trail
- UsedExplorers show who funded a wallet first. Followed back a few hops, the trail usually ends at your main wallet or at an exchange withdrawal with your name on it.
- FixThe creator wallet is paid by a cross-chain router, and trading wallets by the shielded pool. Neither trail goes further back.
- LeftThe router knows both ends of your launch deposit. Paying from an exchange account still tells that exchange.
- Bundles and clusters
- UsedWallets funded from one parent, or at the same minute, are drawn as one bubble. Bundle and insider flags scare buyers off.
- FixEach trading wallet is paid by the pool, which pays thousands of wallets. There is no common parent to draw.
- LeftWallets funded seconds apart with similar amounts can still be guessed at. Spread them out.
- Creator fee claims
- UsedClaiming fees sends them to the creator, and from there people follow them to wherever they are spent or cashed out.
- FixFees are split on-chain at creation. Your share is paid out through the router in ZEC or XMR, or goes to the holders.
- LeftThe payout address is known to the router, and to PrivacyPad (encrypted). Use a fresh one.
- Your whole portfolio
- UsedKnow one wallet and you see all its tokens, entries, exits and PnL. Copy-traders follow it; large holders become targets.
- FixA trading wallet only ever holds what you traded from it, and nothing ties it to you or to your other wallets.
- LeftThe trades of one wallet are linked to each other. Use several wallets if that matters.
- Timing and amounts
- UsedNo transfer needed: 1.2345 SOL leaving one wallet and 1.2345 arriving in another a minute later is a link.
- FixThe pool breaks the direct path, and its fee changes every amount.
- LeftRound, unique or immediate amounts still stand out. Vary them and let time pass.
- Fee payers and co-signers
- UsedThe wallet that pays a transaction's fee, or co-signs it, is tied to it for good.
- FixPool withdrawals are sent by the pool's relayer, and each trading wallet pays its own fees with SOL from the pool.
- LeftNothing.
- Rent refunds
- UsedClosing a token account returns its rent to an address you pick. Pick your main wallet and you have linked the two.
- FixClosed accounts refund the trading wallet itself; what leaves it goes back through the pool.
- LeftNothing, as long as funds leave through the pool.
- Your IP address
- UsedEvery read and every trade goes through an RPC provider that sees your IP next to the wallets you look at.
- FixThe desk's reads and trades go through PrivacyPad's server. The provider sees our server, not you.
- LeftThe pool's relayer sees your IP when you deposit or withdraw, and PrivacyPad's server sees it while it relays. Use a VPN or Tor.
- Connecting a wallet
- UsedConnecting to a site gives it your address and your IP at once, and it can keep both.
- FixLaunching needs no wallet at all. Trading needs your own wallet once, to deposit into the pool.
- LeftThat one deposit is public: your wallet sent this much into the pool.
What an observer sees
| On-chain, anyone can see that | pump.fun | PrivacyPad |
|---|---|---|
| The launcher's wallet is the coin's creator | Visible | Hidden |
| The launcher's other coins and trades are one click away | Visible | Hidden |
| The deposit that paid for the coin leads back to the launcher | Visible | Hidden |
| The creator fees land on an address tied to the launcher | Visible | Hidden |
| A buyer's main wallet appears next to the coin | Visible | Hidden |
| A buyer's other holdings and PnL are one click away | Visible | Hidden |
| Several wallets of one buyer are grouped as a bundle | Visible | Hidden |
What stays visible, as on any launchpad: the coin, its creator wallet (generated, not yours), its trades, and the trading wallets that made them.
The whole path
Three things break the link between you and your coin: a wallet generated for the coin, a private router on both ends, and trading wallets funded from a shielded pool.
you ──any coin, any chain──▶ private router ──0.05 SOL──▶ fresh wallet
(NEAR Intents) │
│ one v1 transaction:
│ create + fee split
▼
you ◀──────── ZEC or XMR ──────── private router ◀──fees── coin on pump.fun
paired with ZEC or XMR
you ──one deposit──▶ shielded pool ──▶ trading wallet ──buy / sell──▶ coin
▲ │
└────────────── back to the pool ─────────────┘
transactions that contain both your wallet and the coin: noneLaunching a coin
- Describe the coin: name, ticker, image, creator fee, and where the fees go. No wallet is connected and nothing is signed.
- You receive a secret, shown once. Only its hash is stored. It is the only way back to your launch.
- Pay the deposit of 0.05 SOL in whatever you hold, on whatever chain. A private cross-chain router (NEAR Intents) gives you a one-time deposit address and delivers exactly 0.05 SOL to a wallet generated for the coin. On Solana, that SOL comes from the router, not from you.
- Within a minute that wallet creates the coin on pump.fun, paired with ZEC or XMR, and writes its fee split, in one version 1 transaction. Both exist together or not at all.
The more distant your deposit is from Solana, the better: another asset on another chain says less than SOL from a Solana wallet, and a wallet you have never used publicly says less than your main one.
Sponsored launches. At times PrivacyPad pays for launches: the form then says so, and the deposit is gone. The coin's wallet is funded by PrivacyPad's own sponsor wallet instead of the router, which shows only that PrivacyPad launched it. A first buy is still paid by you.
First buy, optional. Add an amount of SOL to buy your own coin in that same transaction, so nobody buys before you. It is added to the deposit (plus 0.01 SOL for the buying wallet's own costs) and bought from a wallet generated for it, not from the coin's wallet. Once the coin is live, your launch screen imports that wallet into your burners with your secret, and PrivacyPad then erases its copy of the key. On-chain the wallet is plainly the first buyer, as any dev buy is; nothing ties it to you, and what you sell from it can go back into the shielded pool like any burner.
Where the fees go
Every trade of the coin pays a creator fee, between 0.5% and 3%, in the coin's pair (ZEC or XMR). At creation the coin gets a pump.fun fee-sharing config, which splits those fees on-chain: 75% to your side, 25% to the platform. The split is enforced by pump.fun’s program and cannot be changed after launch.
Your side 75% · platform 25%
Your side is one of two, chosen at launch:
- Pay me. Your share collects in the coin’s wallet. From $5, a payout opens by itself and is paid in a privacy coin, your choice at launch: ZEC, delivered by the router to your Zcash address, or XMR, as wrapped Monero (wXMR) on Solana. The router does not carry Monero, so for XMR it delivers SOL to a one-time wallet that buys wXMR on Meteora and sends it to your Solana address, with its last SOL. On Solana, the fees are seen leaving for the router, and nowhere after that: the one-time wallet is paid by the router, not by the coin.
- Pay my holders. Your share goes to the coin’s pump.fun holder-rewards account, from which pump.fun pays holders in the coin's pair. One percent of the fees goes to the coin’s own wallet to pay for those payouts, converting a little to SOL when it runs low, and everything it does not spend is forwarded to the holders as well: they receive their share minus what paying them actually costs. You receive nothing and give no address, which also leaves nothing to trace on the way out.
Trading privately
Every coin’s page has a trade box. You trade in SOL, from burners: wallets that live in your browser, encrypted with a passphrase, funded from your balance in the shielded pool. Nothing ties a burner to you.
- Open your wallets with a passphrase. The site can generate one for you; it never leaves your browser, and neither do the keys it protects.
- Deposit once, in anything: send SOL to your deposit address from any wallet or exchange, or another coin through an anonymous router, or sign a deposit with your wallet. It lands in your balance as SOL. That deposit is public; where the funds go next is not. The balance is held in Privacy Cash, a shielded pool on Solana, under a key kept in your vault.
- Create burners ahead of time, from the Wallets screen, or let a buy fund one in the same click: the pool pays it, so its first funds come from the pool, not from you. A burner needs about 0.016 SOL at least (the pool’s minimum withdrawal and its fee).
- Buy in SOL, sell any share or an exact number of tokens, from one burner or from all of them at once. Each trade is one transaction: SOL to ZEC on Orca's ZEC/SOL pool, then ZEC to the coin, or back. No aggregator is asked for a route, so no third party learns which wallet trades what. Trades are signed in your browser and relayed by our server, so your IP never reaches an RPC provider.
- Keep as many burners as you like: reuse one, give each coin its own, or regenerate one (its SOL goes back through the pool to a fresh burner). Trades from one burner are linked to each other, never to you.
- Send burners back to your balance, and withdraw it to any address, whenever you want.
Only PrivacyPad coins trade here. Coins trade on their bonding curve and, once they graduate, on their PumpSwap pool, from the same box.
Inside the shielded pool
The pool works like Zcash’s shielded pool, on Solana. A deposit becomes a note: a commitment, a fingerprint that hides the amount and the owner, added to a public tree of every note ever made. To spend notes, your browser builds a zero-knowledge proof that you own notes somewhere in that tree, and publishes their nullifiers so they cannot be spent twice. The proof says nothing about which notes they are.
- Deposits are public. The chain shows your wallet sending an amount into the pool. That is the one place you appear.
- Withdrawals are sent by a relayer. The receiving wallet signs nothing and needs no SOL, so no fee payer ties it to anyone. The chain sees the pool paying a wallet, as it pays thousands of others.
- Your notes are yours. They are encrypted to a key derived in your vault. PrivacyPad never holds it and cannot spend or even see your shielded balance.
- The crowd is what protects you. On 30 September 2026 the pool’s ZEC side held about a thousand notes and its SOL side over 800,000. A small crowd is easier to pick someone out of: vary amounts and timing, and let time pass between funding a wallet and trading.
What it does not protect
Privacy tools fail quietly when their limits are not known. These are PrivacyPad’s:
- What you say off-chain. Announcing a coin from an account tied to you, posting a trading wallet’s address, or paying out to an address you use elsewhere undoes everything above.
- A distinctive amount. The pool’s SOL side is busy, but a distinctive amount at a distinctive time can still be matched by anyone patient.
- The parties in the middle. The router, the pool’s relayer and PrivacyPad each see a part of the picture, listed above. None sees all of it, but each could be compelled or compromised.
- The operator. PrivacyPad holds each coin wallet’s key; that is what lets you launch without signing. The fee split is on-chain and cannot be changed, but the coin wallet’s own funds are in PrivacyPad’s hands.
- Your device. Trading keys live in your browser. Malware there, or a lost passphrase, cannot be fixed from our side.
- One wallet, many trades. Everything a single trading wallet does is linked. Separate wallets keep separate stories.
Good habits
- Pay the launch deposit from a wallet or chain you have never linked to your name.
- Give payouts a fresh address. For Zcash, shield the funds from your own wallet as soon as they land; for wXMR, unwrap it to Monero.
- Deposit into the pool in round amounts, and do not withdraw the same amount right after.
- Let time pass between depositing, funding a wallet and trading.
- Use a fresh trading wallet for anything you do not want linked to your other trades.
- Use a VPN or Tor. The pool’s relayer and our server otherwise see your IP.
- Keep your launch secret and your wallets’ backup file offline, with the passphrase apart.
What it costs
- Launch deposit
- 0.05 SOL, most of it left in the coin’s wallet to pay for its payouts
- Platform share
- 25% of creator fees, none of your trades
- Holders mode
- 1% of creator fees pays for the payouts; what it does not spend goes to holders
- Trading
- no fee from us; deposits into the pool are free, each withdrawal costs 0.35% plus 0.0005 ZEC (or 0.006 SOL)
Glossary
- Anonymity set
- Everyone an action could have come from. The pool's privacy is the size of its crowd of notes.
- Bundle
- Several wallets that trackers group as one buyer, usually because one wallet funded them all.
- Commitment
- A note's public fingerprint in the pool: it proves the note exists without showing its amount or owner.
- Creator wallet
- The wallet pump.fun names as a coin's creator. On PrivacyPad, one generated for the coin.
- Fee-sharing config
- pump.fun's on-chain record of who receives a coin's creator fees, and in what shares. Written at launch, fixed after.
- Holder rewards
- pump.fun's account that pays a coin's fees out to its holders.
- Note
- A piece of your shielded balance. Deposits create notes; withdrawals spend them.
- Nullifier
- A mark published when a note is spent, so it cannot be spent twice, without revealing which note it was.
- Relayer
- The service that sends pool withdrawals and pays their fees, so the receiving wallet does not have to.
- Router
- NEAR Intents: swaps and moves assets between chains through one-time deposit addresses.
- Shielded
- Hidden by a zero-knowledge proof: valid for everyone to check, readable only by its owner.
- Shielded balance
- What you hold inside the pool. Only your vault's key can see or spend it.
- Trading wallet
- A wallet in your browser, funded from the pool, used to trade. Also called a burner.
- t-, z-, u-address
- Zcash addresses: transparent (t1, t3, public), shielded (zs1), and unified (u1, which can include a shielded one).
- Vault
- Your trading wallets and pool key, encrypted in your browser with your passphrase.
- Viewing key
- A Zcash key that lets someone read your shielded payments without being able to spend them.
Questions
Why not just make a fresh Phantom wallet?
A fresh wallet is only fresh until you fund it. The first transfer into it, from your main wallet or an exchange, links the two for good. PrivacyPad's wallets are funded by a router or by the shielded pool, which is the part a fresh wallet cannot do alone.
Is ZEC on Solana private?
No. On Solana it is an ordinary token and every balance is public. ZEC matters here because the shielded pool accepts it, fees accrue in it, and it can move to Zcash, where it can be shielded.
Is this a mixer?
PrivacyPad itself never holds your trading funds. The shielded pool is Privacy Cash, an independent protocol on Solana; your notes there are encrypted to a key only your browser holds, and PrivacyPad can neither see nor move them.
Can PrivacyPad see my trades?
It relays them, so it sees each trade, the trading wallet it came from and your IP while it passes through, and stores none of it. It never sees your passphrase, your keys or your shielded balance. Requests from one IP could be grouped by whoever runs the server, which is one more reason to use a VPN or Tor.
Can people tell a coin was launched on PrivacyPad?
Yes. The creator wallet's pattern is recognisable, and that is fine: it says the coin came from PrivacyPad, not who launched it.
What if I lose my secret?
Then the launch and its rewards are unreachable for good. There is no account, no e-mail and no reset. Download it and keep it somewhere you will still have it in six months.
What if I forget my wallets' passphrase?
The trading wallets, the shielded balance, and what they hold are lost. Keep the encrypted backup file, and the passphrase, somewhere safe.
Can I be paid to a shielded Zcash address?
Not directly. Zcash payouts reach transparent t-addresses only. Shield the funds from there with your own wallet.
Can the operator run off with the fees?
The split is written into pump.fun's program at creation, and payouts are routed automatically. The operator holds the coin wallet's key, which is what makes a launch possible without you signing anything.