Special report · Private compute
The vault never opened. The answer came out proven.
Pay from a shielded ZEC note. Encrypt your question on your own device. Get back an answer and a sealed receipt that proves the model ran, without saying who asked.
Special report · Private compute
Pay from a shielded ZEC note. Encrypt your question on your own device. Get back an answer and a sealed receipt that proves the model ran, without saying who asked.
Hushroom is a private AI network where the payment, the prompt and the person cannot be connected. You pay from a shielded ZEC note. Your prompt is encrypted on your device and sent straight into a GPU enclave: sealed hardware that even its operator cannot look inside.
What comes back is the answer, plus a sealed receipt. The receipt proves that the named model really ran inside a real enclave and was paid for. It does not show what you asked, or who paid.
Enclaves reduce who you have to trust. They do not remove it, and the threat model will say so plainly. Stake $ZZZ for daily compute, issued as blind notes. The pair is ZZZ/VVV.
Everything here is a demonstration. Nothing is live, nothing is advice, and no affiliation with any other project is implied.
| Receipt | Model | State |
|---|---|---|
| a41f…c09e | sample-llm-7b | Sealed |
| 07be…5d31 | sample-llm-70b | Sealed |
| e92c…18a6 | sample-vision-3b | Sealed |
Placeholders:Stake $ZZZTrade ZZZ/VVVFollow on X
Explainer · Three facts
Who paid, what was asked and what ran sit in the same row of someone else's database. Here they are cut apart before they ever meet.
A shielded note was spent. The nullifier proves it was spent once, not by whom.
Encrypted on your device. Only the enclave can read it, and then it forgets.
The enclave signs which model ran and what it output, as a hash.
Plate 1 · Dissection
Every answer comes back with one of these. It proves the compute happened. It says nothing about who asked. Open it for one person and only that person can read it.
Opened for: Journalist
Prompt
“Draft a quiet resignation email”
Answer
Subject: Notice of resignation. Dear team, I am writing to let you know I will be leaving my role…
Output hash matches 0x1df3…4dd0. Payer: still hidden. Everyone else still sees SEALED.
model The hash of the exact weights that ran. Change one weight and this changes.
quote The enclave's signed attestation. The hardware vouches for the build it runs.
out The hash of the answer. It proves this answer, without containing it.
nf The payment nullifier. It proves a note was spent once and cannot be traced to the payer.
time When the enclave signed. Outside the quote window, verification fails.
disclosure Who can read the prompt. By default, nobody. A viewing key changes that for one person.
Open it for one person
Sealed. A viewing key is generated on your device and shared with one person only.
Stocks page · Receipts
Illustrative feed
| No. | Model | Out hash | Time | Verified✓ |
|---|
You can count it. You can check it. You cannot read it. Click a row to recompute its hash.
Staking · Intended model, not live
Stake $ZZZ and the network mints you a handful of compute notes every day, issued blind. Spend one per request. The operator sees a valid nullifier. It never sees the staker.
Intended model not live · not advice
1,000 $ZZZ
Notes per day: 4. Illustrative ratio of one note per 250 $ZZZ. Not a promise, not a yield.
Lock tokens once. There is no API key to leak and no account to link.
Each day your stake mints notes, issued blind, so even the issuer cannot match note to staker.
The operator checks a nullifier: proof the note is unspent, not proof of who held it.
| Question | Keyed staking | Blind compute notes |
|---|---|---|
| Links your wallet to your usage | Yes. One API key. | No. Each note is unlinkable. |
| What the provider sees | Key, volume, timing. | A valid nullifier. |
| Revocation | Revoke the key. | Notes expire daily. |
Memory · In memoriam
Chat memory is kept as encrypted notes that only your key opens. Burn the key and the enclave signs a tombstone: the notes cannot be decrypted there again, by anyone, including you.
Sample memories, written for this page.
Day 1: arrive, walk the old town, book the ferry. Day 2: the museum, a long lunch…
Dear Alex, I have been meaning to write about the flat, and what I would like to change…
Is it normal that the headache comes back after coffee? Questions to ask at the appointment…
Key present. Notes readable by you.
In memoriam
Notices
None received. All keys present.
A tombstone proves the key was destroyed in the enclave and the notes cannot be decrypted there. It cannot prove you never took a screenshot.
Supply side · Written by us
No. 01
Confidential-computing capable cards, such as GPU TEEs. Paid per job in shielded ZEC. Apply with an attestation, not a CV.
No. 02
You verify attestation. You serve. You get paid. That is the whole job, and the whole point.
No. 03
You only ever see nullifiers. There is no customer file to keep, lose or subpoena.
Intended model
Bad attestations forfeit stake. Not live. Described here so operators know the terms before there are any.
What you can run · Sample models
Every programme runs sealed. The names are samples; no real model list exists yet.
Commentary · The token
Stake $ZZZ and you get blind compute notes: a daily allowance of private requests, issued so that the issuer cannot tell which staker received which note. That is the whole job of the token on this page. Access to private compute, paid in advance.
The pair is ZZZ/VVV. Customers pay each request from a shielded ZEC note. Fees flow to the operators who ran the job and, in the intended model, to a stake pool and a buyback. Nothing is live. There is no price, no pool and no contract here.
What it does not do: it does not make a model smarter, it does not remove the need to trust an enclave's hardware vendor, and it is not an investment recommendation. Any figure on this site is a sample.
No price. No pool. No contract. Only a demonstration.
The desk
No split is stated because none is set. Not advice.
Legal notices · Honest ones
Prompt content. Answer content. The payer. The link between a stake and its use.
That you used the network at all. Timing is visible at your IP, so use Tor or a VPN. The size class of your request. The model you chose, because it is in the receipt.
You trust the chip vendor's attestation and the published build. Side channels exist. Intended mitigations: pinned builds, reproducible measurements, rotating enclaves, slashing for bad attestations.
An earlier draft of this page said “anonymous”. The right word is unlinkable.
Nothing here can stop a person from copying what they can read. Provable forgetting covers the enclave, not your own screen.
No real enclave, payment or proof runs on this site. It is a demonstration. Not affiliated with Zcash, ECC or any AI provider. Not advice.
Colophon
Printed by no one. Distributed blind. Hushroom Nº 001.
$ZZZ · pair ZZZ/VVV · CA: placeholder · X: placeholder
Ledger rows, models and figures shown are illustrative. Not live. Not advice. Not affiliated with Zcash, ECC, Venice or any AI provider. Enclaves reduce who you have to trust; they do not remove it.
Resealed
Page 12 / 12
Page 12 / 12 · Resealed