Independent concept / Version 0.2

Receive the
payment.
Not the financial
history.

A proposed private funding layer for payments to X Money users. Separating the payment from the wallet behind it.

Research proposal · 26 September 2026

+
+
TORNADO.MONEY / SOURCE PRIVACY
CONCEPT
V. 0.2
A PAYMENT. NOT A PUBLIC HISTORY.
Source-private

Funding by design

Proof-authorized

Verify the right to spend

Provider-settled

Approval required

01 / THE PROPOSED DESIGN

Private funding.
Verifiable authorization.

Prove the right to make a payment,
without publishing which deposit funded it.

CONCEPTUAL PAYMENT FLOW
DESIGN PROPOSAL
01 / FUND

The deposit stays. The link is the question.

A sender would fund a payment with a supported crypto asset. A privacy contract records a commitment to a valid claim. The research objective is to avoid a reliable public link from that deposit to a later payout.

The original deposit remains visible on its underlying public chain.
01

Fund a private claim.

A proposed privacy contract holds supported assets and records commitments. The deposit remains visible on its public chain.

02

Authorize with a proof.

A proof establishes a valid, unspent claim. Authorization binds the amount, destination, fee ceiling, and expiry.

03

Settle through a provider.

An approved provider would handle conversion and delivery. The recipient receives a payment, not the sender’s crypto asset.

02 / THE TRUST MODEL

Private.
From whom?

Privacy needs a defined boundary.
Here is the disclosure model the paper proposes.

ObserverExpected visibilityTarget / limit
RecipientPayment amount, status, receipt, and required originator fields.Original funding wallet should not be exposed by the payment itself.
Public observerPublic deposits, contract activity, amounts, and timing.No directly disclosed deposit-to-payout link; statistical inference remains a risk.
OperatorsInformation needed for authorization, support, and delivery.Exact access is not yet specified. Link reconstruction cannot be ruled out.
Settlement providerConversion, payout, identity, and funding records.Source secrecy from an accepting provider is not promised.
X Money / bankRecipient account and payment-service information.Outside the public-chain privacy objective. No anonymity is promised.

Proposed boundaries, not verified system behavior. No anonymity from X or payment providers is promised.

03 / RESEARCH BEFORE RELEASE

Prove the privacy.
Then prove the payment.

A design to investigate.
Clear conditions to validate.

01 / VALIDATION GATE

Specify the claim.

Define the observers, exposed information, custody boundaries, and success criteria before testing.

02 / VALIDATION GATE

Validate the private funding.

Complete the contract and proof specifications, independent security review, and privacy assessment.

03 / VALIDATION GATE

Validate the recipient experience.

Confirm provider approval and test delivery, rejection, reconciliation, costs, and privacy failures.

04 / VALIDATION GATE

Decide if the claim survives.

If payment information still reveals the wallet, narrow the claim. Evidence determines what can be promised.

No end-to-end implementation, measured result, or launch date is claimed.

Research stage

04 / QUESTIONS & CLARITY

The details
matter.

What the proposal does—and does not—claim.

TORNADO.MONEY / WHITE PAPER V0.2

A payment should arrive.
Your history shouldn’t.

Read the white paper