# CLOAK — fees and tokenomics

CLOAK is the token of the Cloak privacy route. The model is deliberately small: the protocol charges one fee, on one action, and all of it buys the token.

## Fees

Cloak uses gas abstraction. The relayer pays network fees on the agent's behalf and is reimbursed from the agent's shielded balance. The fee amount and fee token are public inputs to the zk proof, so the program can verify them and pay the relayer exactly that amount after the proof checks out. The agent never needs SOL in a public wallet.

| Action | Fee | Where it goes |
|---|---|---|
| Shield | Network fee | Relayer, as gas reimbursement |
| Unshield | Network fee | Relayer, as gas reimbursement |
| Pay | Network fee | Relayer, as gas reimbursement |
| Receive | None | — |
| Interact (`cloak call`) | Network fee | Relayer, as gas reimbursement |
| Swap | Network fee + **0.3% of input** | Relayer + **100% CLOAK buyback** |

### How the network fee is estimated

1. The CLI takes the latest successful compute-unit usage for the action type, or the action's default if there is no history.
2. It applies a single 1.25× buffer and multiplies by the current priority fee.
3. The result is deducted from the agent's shielded balance and included in the proof.
4. After verification, the program transfers exactly that amount to the relayer that submitted the transaction.

The buffer is applied once. Relayers cannot charge more than the proven fee.

### The swap fee

Private swaps carry a protocol fee of 0.3% of the input amount, taken inside the pool before the swap is routed. The fee is denominated in the input token and is sent to the fee vault in the same transaction as the swap. It is the only protocol-level fee Cloak charges.

There is no fee on payments, receives, program calls, shielding or unshielding beyond network reimbursement.

## Buyback

Every unit of swap-fee revenue is used to buy CLOAK on the open market. The purchased CLOAK is burned.

### Mechanics

- **Fee vault.** A program-owned account per fee token. Swap fees accrue here. Balances are readable onchain and via `cloak status`.
- **Buyback instruction.** A permissionless instruction on the Cloak program. Anyone can call it. When a vault's balance for a token exceeds the buyback threshold, the instruction routes the full balance into CLOAK via Jupiter and transfers the output to the burn address. The caller is reimbursed the network fee from the vault.
- **Threshold.** Set per token to keep buybacks large enough that fees don't dominate. Initial thresholds are published with the deployment addresses.
- **No discretion.** The vault has no withdraw authority. The only way funds leave it is through the buyback instruction, and the only destination for what it buys is the burn address.

### What this means

- 100% of protocol revenue becomes buy pressure on CLOAK.
- Supply only decreases. There is no inflation, no emissions schedule and no treasury allocation funded by fees.
- The buyback is verifiable. Every buyback is an ordinary Solana transaction from the vault, visible to anyone. Cloak publishes a running log at `usecloak.pro/buybacks`.

## Token

| | |
|---|---|
| Name | Cloak |
| Symbol | CLOAK |
| Chain | Solana |
| Standard | SPL |
| Supply | Fixed at launch; deflationary through burns |
| Mint | *published with deployment addresses* |

CLOAK carries no fee discount, no staking requirement and no gate on using the route. An agent does not need to hold CLOAK to use Cloak. The token's only relationship to the protocol is that the protocol buys it.

## What is not private

The fee vault and the buyback transactions are public by design — that is what makes the model auditable. They reveal aggregate swap volume through the route over time. They do not reveal who swapped, what they swapped, or when any individual swap occurred; the fee is taken inside the pool and only leaves it in batches.
