USDCERC-20 tokenThe public ERC-20 token. Deposits pull it from the wallet; withdrawals pay it back out.
Token Bridge0 USDC lockedHolds the USDC backing all private Merces balances. It only releases tokens for a withdrawal message settled on the Hub.
Merces Proxyverifies client proofsThe L1 entry point. It checks each client’s ZK proof that the encrypted action is well-formed, then queues it on the Hub. It never sees private balances.
Private Settlement DomainThe L1 contract that orders Merces messages into numbered namespace blocks and finalizes each block once 2 of 3 MPC nodes sign its new state root.root —State root of block #0not read yet
queueMessages waiting for the next namespace block: encrypted actions and bridge deposits going in, settled payouts waiting to be claimed.empty
finalizedBlocks the Hub has finalized, oldest first. Each one executed the queued actions and stored a new state root; a rejected action leaves the root unchanged.reading…
Alice · wallet0 USDCA normal L1 account. Its USDC balance is public.
Bob · wallet0 USDCA normal L1 account. Its USDC balance is public.
↓ next blockqueued actions, in orderThe Hub groups the queued messages (deposits, encrypted transfers and withdrawals) into the next namespace block, which the MPC nodes execute in order. It counts as finalized only once its new state root is signed.↑ new state rootproven & signed by MPCA commitment to all Merces balances after a block. The MPC nodes prove the block was executed correctly and sign the new root; the Hub stores it, so anyone can verify the state without learning any balance.What L1 observers seePublic: who submits, deposit and withdrawal amounts, the payout address. Hidden: transfer amounts and receivers, all Merces balances.
TACEO Merces · privateAliceVisible only to Alice
BobVisible only to Bob
MPC node 1Three independent nodes, each holding one share of every balance. No single node learns a balance or transfer amount.MPC node 2Three independent nodes, each holding one share of every balance. No single node learns a balance or transfer amount.MPC node 3Three independent nodes, each holding one share of every balance. No single node learns a balance or transfer amount.
Balances stay secret-shared; MPC nodes compute on shares and prove each block.Alice
Bob
Pick an action
Click a button to watch the tokens move step by step.