One skill.
Total privacy.

Cloak is a zero-knowledge privacy route for AI agents on Solana. Your agent keeps its wallet and its keys. It just stops leaving a trail.

$ curl -fsSL https://usecloak.pro/skill.md -o .claude/skills/cloak/SKILL.md

Live on Solana  ·  Read the spec

Agent keys stay here
Privacy route shielded pool · zk proof · relayer
Solana sees a fresh address
$ cloak
> agent.pay(recipient, 25 USDC)

Right now, every agent is transacting in public.

Every observer, watching the same address.

An agent holds a wallet. It pays for an API call, swaps some tokens, mints something, pays a sub-agent for work. All of it lands on one address, permanently, for anyone to read.

That isn't only the agent's problem. It's a problem for whoever the agent works for. Their treasury, their strategy, their counterparties, the shape of their task graph — all of it reconstructable from a block explorer.

Cloak puts a route in between.

Today AgentWalletSolana
With Cloak AgentPrivacy routeSolana

How the route works.

  1. 1

    Shield

    The agent deposits SOL or SPL tokens into the shielded pool and gets back a private note — a commitment that only its spending key can use. This deposit is the one public link to the agent's wallet.

  2. 2

    Prove

    To act, the agent generates a zk-SNARK on its own machine proving it owns an unspent note of at least the right amount, without saying which one. One to three seconds on ordinary hardware.

  3. 3

    Relay

    A relayer submits the transaction and covers network fees. The destination sees funds arriving from an address with no history. The pool sees a valid proof. Neither sees the agent.

  4. 4

    Receive

    Incoming payments land on one-time stealth addresses derived from the agent's viewing key. Each payer gets a different destination, so none of them can be tied together.

What an agent can do through it.

Each capability is one command. The agent calls it the same way it calls any other tool, and gets JSON back. Funds never leave the agent's control; relayers can submit transactions but can't spend notes.

cloak shield

Shield

Move funds from the agent's wallet into the pool. This is the one public step, so the skill does it ahead of time and in round amounts.

ok shielded 1.5 SOL · note n_8f2c…
cloak pay

Pay

Settle invoices, API bills and bounties from the pool. The recipient gets the money and nothing else.

ok relayed · recipient sees a fresh address
cloak receive --stealth

Receive

Hand out a new one-time address to every payer. They each see a different destination; the agent sees one balance.

ok stealth address 3Ff…kP1 · one use
cloak swap

Swap

Trade through Jupiter from inside the pool. No visible intent before the trade, so nothing to sandwich.

ok 2.5 SOL → 410.94 USDC · via jupiter
cloak call

Interact

Call any program from a throwaway session key funded by the pool. Mint, stake, vote. The program sees the session key, not the agent.

ok session key funded · executed · swept
cloak viewkey

Disclose

Hand a read-only viewing key to an operator or auditor when you need to. Private from the world, not from the owner.

ok viewing key exported · read-only

Installed like an agent, not an app.

People install apps and extensions. Agents install skills. Cloak ships as one markdown file that tells an LLM agent exactly how to shield, prove, relay and receive — the commands, the JSON it gets back, the rules to follow, and what to do when something fails.

It works with the agent's existing keypair. Proofs are generated in the agent's own runtime and never leave the machine.

# add the skill to your project
mkdir -p .claude/skills/cloak
curl -fsSL https://usecloak.pro/skill.md \
  -o .claude/skills/cloak/SKILL.md

# then, in a session
> /cloak pay 7xKX…9fQ 25 USDC
ok  note selected      0.9 SOL → 25 USDC
ok  proof generated    1.8s
ok  relayed            4Gw…Cua7
ok  recipient sees     fresh address, no history

Swap fees buy the token. All of them.

Routing a payment, a receive or a program call through Cloak costs nothing beyond the network fee the relayer pays on the agent's behalf. Private swaps carry a 0.3% protocol fee. Every unit of it is used to buy CLOAK on the open market, and the CLOAK it buys is burned.

There is no treasury cut, no team share and no discretionary spend. The fee vault is a program account anyone can read, and the buyback is a permissionless instruction anyone can trigger once the vault crosses its threshold.

Read the tokenomics →
ActionFeeWhere it goes
Shield / unshieldNetwork fee onlyRelayer, as gas reimbursement
PayNetwork fee onlyRelayer, as gas reimbursement
ReceiveNone—
InteractNetwork fee onlyRelayer, as gas reimbursement
Swap0.3% of input100% CLOAK buyback, then burned

Where it gets used.

Agent-to-agent payments
Sub-agents pay each other for work without exposing the organisation's treasury or how its tasks are split up.
Autonomous trading
Run a strategy without announcing it to every MEV bot watching the mempool.
Pay-per-call APIs
Buy inference, data and compute with x402-style micropayments that don't fingerprint the buyer.
Personal agents
An assistant that transacts on someone's behalf without publishing that person's financial life.
Other networks
Solana today. The route itself is chain-agnostic, so the same skill can front other networks as they're added.

Questions.

Is this a mixer?

No. A mixer pools funds and relies on obfuscation. Cloak is a shielded pool with zero-knowledge proofs: every spend is proven valid cryptographically, nothing is "mixed", and owners can disclose their own history to an auditor with a viewing key.

Does the agent give up custody?

No. Notes can only be spent with the agent's spending key. Relayers submit transactions; they cannot move funds.

Where are proofs generated?

Locally, in the agent's runtime, with a small WASM prover bundled in the CLI. Typical proof time is one to three seconds.

What does it cost?

Network fees, paid out of the shielded balance so the agent never needs a public gas wallet. Swaps add a 0.3% protocol fee, all of which buys and burns CLOAK. Nothing else is charged.

What doesn't it hide?

The deposit into the pool is public. Amounts are visible to whoever receives them. And privacy depends on the size of the anonymity set — the skill tells the agent to check it before making promises to the user.

Autonomy isn't autonomy
if someone's always watching.

Install the skill hello@usecloak.pro