How Ghost works.
Ghost is a memecoin launchpad on BNB Smart Chain where positions can be invisible. Every token trades on a Uniswap V4 bonding curve priced in BNB that any wallet, DEX front-end or bot can swap against from the first block. The vault is the shielded route: you buy by funding it, which turns your tokens into shielded notes; you sell or claim by proving in zero knowledge that you own a note. Your wallet never holds the token and no address is linked to a position.
At a glance
| Chain | BNB Smart Chain (56) |
|---|---|
| DEX | Uniswap V4, LP fee 0, tick spacing 200 |
| Base asset | Native BNB |
| Supply | 1,000,000,000, all minted into one locked curve position |
| Start → graduation | set on the factory, in BNB (about $2.5k → $45k FDV) |
| Max per wallet | 5% of supply, enforced on the token and on the vault |
| Platform fee | 1% of every swap, in BNB |
| Creator tax | 0–10% buy / sell, in BNB, split 30 / 70 with the protocol |
| Snipe tax | 99% at launch, decays to 0% within 3 seconds |
| Note sizes | 1M, 5M, 25M tokens; up to 16 notes per transaction |
Shielded notes
A note is a commitment Poseidon(nullifier, secret, amount) inserted into a per-token Merkle tree inside the vault. When you buy, the vault swaps BNB for exactly the tokens your notes add up to and inserts one leaf per note. The chain sees that someone bought that many tokens; it does not see which notes belong to which funding wallet beyond the fact that it paid.
Your nullifier and secret are derived from one wallet signature over a fixed message, so there is nothing to back up: connect the same wallet, sign once, and the site rebuilds your notes by scanning the tree. The signature never leaves your browser and the seed lives only in this tab's session.
Fixed note sizes are what make the set anonymous: a 5M note spent tomorrow could have come from any 5M note ever bought. Picking odd sizes would make you recognisable, so the vault only accepts the three denominations.
Selling and claiming
To spend a note your browser produces a Groth16 proof that it knows a leaf in a recent root of the tree, reveals the note's nullifier hash (so it cannot be spent twice) and binds the proof to the recipient, relayer fee, minimum output and mode. The vault verifies the proof and either sells the tokens back into the curve and pays BNB to the recipient (sell), or, after graduation, transfers the plain ERC-20 (claim).
Submit through the relayer and the transaction comes from the relayer's wallet, paid out of the proceeds; your address is not on chain at all. Submit yourself and the spend is still unlinkable to your buy, but the submitting wallet is visible. Either way the proof is computed locally; the relayer only forwards calldata it cannot alter.
The curve and graduation
Each launch opens a Uniswap V4 pool of native BNB against the token with one one-sided position holding the whole supply, owned by an immutable locker. Buying moves the price up the curve; when the pool crosses the graduation price the hook latches graduated, a milestone shown on the token page. Nothing migrates: the same pool, the same locked position and the same vault keep working. Liquidity is never withdrawn.
Shielded and public trades share one pool, so the shielded anonymity set is the pool's unspent notes of the same size. The price you see on the shielded panel is computed from the pool's state in your browser.
The 5% wallet cap
Anonymity is only worth something if the holder set is wide. Two rules keep it that way: a single funding wallet may shield at most 5% of the supply per token, and the token itself refuses any transfer that would leave a non-infrastructure address above 5%. Graduating therefore needs at least sixteen different funding wallets, and no claim, DEX buy or transfer can concentrate supply afterwards.
Fees, all in BNB
- 1% platform fee on the BNB leg of every swap, including the vault's.
- Creator tax, fixed at launch (up to 10% each way), charged on the same leg; 70% to the protocol, 30% to the creator.
- Snipe surcharge of 99% decaying to 0% over the first three seconds, paid to the protocol; the creator's own first buy is exempt.
- Relayer fee, quoted per spend, taken from the output.
Taxes accrue in the locker and anyone may trigger claimFees; it always pays the creator's payout wallet and the protocol recipient, in BNB.
Trust model
- The locker, hook, token and vault are immutable; nobody can pause, upgrade or withdraw liquidity.
- The factory owner can change the launch fee, the curve bounds for future launches and the protocol fee recipient — nothing about existing pools.
- The zero-knowledge verifier was generated from a development trusted setup. Until the public multi-party ceremony completes, treat the shielding as beta.
- The relayer sees your spend calldata, which contains no identifying information; the worst it can do is refuse to submit.