The transaction pipeline against the infrastructure that runs each stage
Seven stages — discovery, diligence, negotiation, contracting, ordering, settlement, enforcement — each against what runs it conventionally, what runs it in Muster, and who still observes something. Ordering and enforcement are left unassessed.
STAGE, AND WHAT LEAKS
CONVENTIONALLY, AND WHO RUNS IT
WHAT RUNS IT HERE
WHO STILL SEES, AND WHAT
01
Discovery
counterparties,
intent
A platform directory, an order book, a group chat.
"Add contact" is a request to a server whose whole
business is knowing the edges of that graph — and
which can be compelled to produce them.
No directory, so no lookup.
The address is minted locally and
handed over out of band. Nothing
is resolved, so nobody is asked.
The store node: which topics this
client subscribes to, and when.
The contact graph, pseudonymously.
The bootstrap is unauthenticated.
02
Diligence
address history,
identity graph
Block explorers, and the surveillance firms that
graph the chain for a living. The lookup is itself
a record — of what you checked, and when, logged
against your address at the edge.
Nothing.
There is no diligence surface in
this build. Calling that "closed"
because we do no lookups would
be the overclaim.
Nobody — because the stage does
not happen, not because it is
protected. An absent feature and
a closed leak look identical from
outside, and are not the same.
03
Negotiation
size, terms,
reservation price
RPCs, quote infrastructure, hosted chat. For a
multisig, a transaction service where the operator
— and often anyone with the URL — sees the
proposal, the signer set and the timing, all
before anything reaches a chain.
Inside the encrypted room.
No coordination service anywhere
in it. Approvals are ordinary
messages, authenticated by the
room — but not by the chain.
That a conversation is active,
and when. Not what was proposed,
who agreed, or how many.
The threshold is enforced by the
room, never by the zone.
04
Contracting
frontend and
signing context
A web frontend served fresh on every visit, and
blind signing: the signer approves opaque calldata,
or a hash they have no way to reconstruct
independently. This is the norm, not the failure.
A native, local-first client.
No web frontend, no ambient
leakage. But the signing context
is not verifiable — the client
does not re-derive what it signs.
Nothing new leaves the room here.
The gap points inward: you cannot
check what you are agreeing to.
F-4 and FS-6 specify the check;
it is not built.
05
Ordering
pending order
flow
A public mempool. Everything pending is visible to
anyone who watches, which is what MEV is built on
— and the node you submit through learns your
network origin at the same moment.
Not assessed.
Needs the zone's own answer on
mempool visibility and sequencer
behaviour. Guessing it here would
be the failure this figure avoids.
Known: no network-origin
protection, because there is no
mixnet. The zone learns that a
transfer happened, and when.
The rest is not established.
06
Settlement
balances,
approvals
The public ledger and every indexer reading it,
permanently and in the open. This is the stage
privacy work concentrates on — shielded amounts,
mixers, stealth addresses.
Shielded at both ends, by default
on the private rail.
Four rails are offered; each states
on its receipt what it disclosed.
The private one takes ~7 minutes.
That a transfer happened, and
when. That is the floor on every
rail, including the private one.
On a testnet with two users the
anonymity set is as small as it gets.
07
Enforcement
identifiable
operators
Whether a block producer can be named, and
therefore leaned on. Anonymous randomised
selection is the standard; a permissioned
sequencer set is not. Almost nobody argues
about this stage at all.
Not assessed.
The testnet runs against a single
named sequencer, which by that
standard points one way — but the
production model is unconfirmed.
Whoever can compel the operator,
if the operator is identifiable.
Unconfirmed for production, and
so left blank rather than filled
in with something plausible.
inside the room, on your device
what an outside party learns
a gap, or a refusal to score