CONFIDENTIAL STATE CONTINUITY · MIDNIGHT NETWORK

The State Continuity & Custody Layer for Midnight.

The Institutional State Layer for Zero-Knowledge Chains

Native asset custodians (Fireblocks, BitGo, Dfns) secure the NIGHT token, but cannot protect arbitrary Compact contract witnesses—which have zero on-chain ciphertexts to custody. MidRelay provides the confidential state continuity and threshold custody engine required for production privacy dApps.

Midnight Kachina Native2-of-3 Shamir GF(256)XChaCha20-Poly1305 AEAD
midrelay://runtime-verifier
● LIVE
Recovery Status: VERIFIED

State Restored in 42ms

1. Merkle Anchor Query9ms

HistoricMerkleTree<8, Bytes<32>> root: 0x7f4a...92b1

2. Authenticated Decryption14ms

XChaCha20-Poly1305 memo decrypted · Blake2b bound

3. Shamir GF(256) Quorum12ms

2-of-3 threshold satisfied (London + Zürich shares)

4. ZK State Proof Verification<5ms

proveHoldsState circuit verified · e(A, B) = e(α, β)

RECONSTRUCTED BALANCE: 50,000,000 USDMPLAIN LEAK: 0B

<50ms

State Verification Latency

18 / 18

Cryptographic Invariants Passing

GF(256)

2-of-3 Shamir Threshold Quorum

0-Byte

Plaintext Leakage (Ciphertext-Only)

01 / THE DUAL-LEDGER PROBLEM

Privacy changes where state lives.

On transparent chains, validator nodes replicate everything. On Midnight's Kachina dual-ledger, private state lives strictly on client hardware. This creates a silent existential vulnerability for serious dApps and regulated capital.

Transparent Chains (Ethereum / Solana / Safe / Fireblocks)

Global Validator Replication

Smart contract state is duplicated across thousands of validator nodes. If a user loses hardware, entering their BIP-39 seed phrase on a fresh device immediately restores balances.

TRADEOFF → Recovery guaranteed, but zero financial confidentiality.
Midnight Kachina Architecture

Custom Contract Witness Memory

While native Zswap shielded tokens can be trial-decrypted from seed, custom Compact contracts record zero on-chain shadows for private witnesses. Application state (roles, identity credentials, private compliance notes) lives strictly in client LevelDB.

EXISTENTIAL FLAW → Hardware loss destroys private contract state permanently.

State Scope Matrix: What Is Recoverable Today vs. MidRelay

Comparing state persistence mechanisms across transparent, shielded, and custom Compact architectures.

MIDNIGHT SPEC COMPLIANT
State DomainStorage LocationDevice Wipe RecoveryConfidentialityContinuity Status
Transparent Chains
Ethereum, Cardano L1, Solana
Global Validator Ledger (Replicated)Seed Phrase (BIP-39) restores all balancesZero (Public Ledger Exposure)Transparent
Native Shielded Tokens
Midnight Zswap (NIGHT / DUST)
On-chain encrypted note ciphertextsTrial-decryption via viewing key rescanFull ZK ConfidentialityNative Rescan
Custom Compact Contracts
Without MidRelay (Standard SDK)
Client LevelDB / IndexedDB strictlyPERMANENT LOSS · Zero on-chain preimageFull ZK ConfidentialityUnrecoverable
Compact + MidRelay Layer
State Continuity & Custody Engine
Encrypted Memos on HistoricMerkleTreeSub-50ms Deterministic Merkle Verification0-Byte Plaintext Leak · GF(256) ShamirGuaranteed Continuity

The Institutional Custody Dilemma: Beyond Token Balances

Existing custodians (Fireblocks, BitGo, Copper, Dfns) secure the native NIGHT token and transparent UTXOs—none address arbitrary Compact witness state, which has no on-chain ciphertext to custody in the first place. Asset custodians cannot protect or audit what never enters the public ledger. MidRelay complements native asset custodians by providing zero-knowledge state continuity and threshold viewing-key infrastructure for institutional assets like ShieldUSD, Fairway compliance rails, and private credit vaults.

See Banking Case Study

02 / ARCHITECTURAL SCOPE

Why the name "MidRelay".

Relaying is not just cross-chain messaging. MidRelay defines relaying as the secure transport of private cryptographic state across three boundaries where confidential data is normally destroyed or compromised:

BOUNDARY 01

Hardware Relay: State Continuity

Relays private witnesses across machine death, browser wipes, and viewing-key rotations. Deterministic verification occurs in under 50ms — reconstructed state from encrypted memos is checked against on-chain Compact Merkle commitments.

Device-to-device state sync
Browser cache wipe recovery
HistoricMerkleTree viewing roots
BOUNDARY 02

Actor Relay: Threshold Custody

Relays confidential state access between treasuries, auditors (FCA / SOC-2), and autonomous AI agents using 2-of-3 Shamir quorums over GF(256) without granting spending authority.

Scoped auditor viewing keys
Time-bound AI agent mandates
Monument Bank compliance
BOUNDARY 03

Ledger Relay: Cross-Chain Proofs

Relays verified Midnight zero-knowledge state tickets to Cardano Plutus (Aiken) and Base EVM (Solidity verifiers) for deterministic cross-chain settlement without wrapped synthetic tokens.

Midnight-to-Cardano state proof
Midnight-to-Base settlement
Recursive SNARK envelopes

03 / INSTITUTIONAL ARCHITECTURE

Cryptographic primitives engineered for institutions.

MidRelay satisfies rigorous mathematical and regulatory criteria designed specifically for the constraints of zero-knowledge dual-ledger blockchains.

Sub-50ms Zero-Doxx Rehydration

Reconstruct unspent notes and credentials from encrypted memos, verified against on-chain Compact Merkle roots using a single passphrase or a quorum of viewing keys.

Threshold Custody (GF(256))

k-of-n secret sharing across distributed guardians for FCA/tax compliance audits without exposing spending keys or private notes.

Anti-Correlation Cryptography

In-circuit assert(salt != 0) eliminates multi-transaction correlation attacks (termed 'DarkState' in our threat model), ensuring identical memos produce distinct commitments.

Developer-First SDK & CLI

Lightweight TypeScript primitives for institutional key ceremonies, secret splitting, and automated state backups.

04 / REGULATED ENTERPRISE CUSTODY

ENTERPRISE CASE STUDY: MONUMENT BANK UK

Audits without surveillance.

As outlined in Monument Bank's roadmap for Midnight (tokenized deposits → whitelisted RWAs → private Lombard lending), institutions require continuous regulatory compliance (FCA / SOC-2) and auditability without revealing confidential client positions or balance sheets to the public ledger.

2-of-3 Shamir Quorum over GF(256)

Viewing authority is split across three distinct institutional guardians with no single point of compromise.

Scoped Time-Bounded Read-Only Audits

Auditors receive mathematically restricted viewing certificates that expire automatically and convey zero transaction-signing capabilities.

Zero Public Ledger Footprint

Validators verify the state proof in <5ms without learning balance amounts, counterparty identities, or historical ledger paths.

MONUMENT BANK · GUARDIAN QUORUM2-OF-3 REQUIRED
Guardian 01: London Primary WorkstationSHARE VERIFIED

Keystore: 0x4a7f92...c8e1 · Derivation: Argon2id

Guardian 02: Zürich Cloud HSM EnclaveSHARE VERIFIED

KMS: arn:aws:kms:eu-central-1:vault-monument

Guardian 03: New York Compliance CustodianSTANDBY (OFFLINE)

Air-gapped Cold Storage · Primitive Polynomial: 0x11d

Quorum Satisfied: 2 of 3 Shares ReconstructedSPEND KEY HARD-LOCKED

05 / DEVELOPER SPECIFICATION

Explicit circuits. Zero ambiguity.

The MidRelay SDK and Compact circuits keep trust boundaries explicit. Every cryptographic parameter is strongly typed and verifiable on-chain.

import { MidRelayClient, ShamirThreshold } from '@midrelay/sdk';

// 1. Split institutional viewing authority across 3 guardians (GF(256))
const shares = ShamirThreshold.split(masterViewingKey, { threshold: 2, total: 3 });

// 2. Commit encrypted state memo to Midnight Compact contract
const tx = await client.publishMemo({
  statePayload: { balance: 50_000_000n, currency: 'USDM', vault: 'monument-uk' },
  encryptionKey: shares.deriveEncryptionKey(),
  salt: crypto.getRandomValues(new Uint8Array(32)) // Anti-correlation assertion
});

✓ Memo committed to Compact HistoricMerkleTree · Plaintext never leaves device

06 / PHASED PROTOCOL ROADMAP

Venture-scale architectural execution.

MidRelay begins where privacy blockchains are most vulnerable: the client-state lifecycle. In subsequent phases, MidRelay expands to multi-party custodians, AI autonomous agents, and cross-chain proof settlements.

PHASE 1 · DELIVERED & PREPROD READY

Core State Continuity Engine

Foundational private-witness survivability engine. Eliminates the #1 existential threat of local LevelDB erasure.

  • Compact circuits (midrelay.compact)
  • TypeScript SDK (@midrelay/sdk)
  • Institutional CLI tool
  • 18/18 Automated vitest test suites
PHASE 2 · BUILD CLUB PHASE

Threshold Custody & Agent Mandates

Multi-party viewing keys for regulated institutions and delegated time-bound capability mandates for autonomous AI agents.

  • 2-of-3 Institutional Custodian Consoles
  • Scoped auditor viewing certificates
  • AI Agent temporary spend capabilities
  • Enterprise AWS KMS / HSM integrations
PHASE 3 · ACCELERATOR & MAINNET

Confidential Multi-Sig Vaults

Confidential institutional multi-sig vaults, dark solvency verification, and recursive state relays to Cardano and EVM.

  • Confidential Multi-Sig Vaults
  • Dark Lombard Collateral Engine
  • Cardano Plutus & Base EVM Relays
  • Formal Verification of Compact Circuits

Install the MidRelay Client SDK

Start building privacy-first state continuity in minutes.