blindhop
Network-layer privacy for Polkadot light clients, routing smoldot traffic through the Nym mixnet so nodes can't link transactions to your IP. Co-built.
- date
- stack
- rust nym mixnet smoldot substrate websockets vite
- code
- github.com/BlindHop/BlindHop
- live
- demo.blindhop.wtf
Substrate light clients connect straight to full nodes, which exposes the user’s IP address. An ISP, a network observer or a malicious node can tie transactions and queries to a real identity.
BlindHop wraps smoldot’s WebSocket traffic and sends it through the Nym mixnet instead: 500+ mix nodes, Sphinx packets and cover traffic, with no trusted setup, trusted hardware or chain fork. A privacy slider lets users pick None (direct), Fast (2-hop) or Full (5-hop).
smoldot → blindhop-proxy → Nym mixnet → blindhop-exit → Substrate full node
(the node sees the exit's IP, not yours)
My part
I co-built BlindHop with a small team. My work focused on making it reliable and safe enough to run in public:
- Proxy correctness: routed each mixnet reply back to the request that sent it, stopped dropping messages on empty batches, removed a panic on the Nym client, and made Fast and Full modes actually route differently
- A hardened exit: limited what it forwards, handled requests concurrently with a cap on in-flight work, compressed large replies, kept its Nym address stable across restarts, and made it restart itself when the mixnet stops delivering
- Security: the proxy refuses WebSocket connections from unlisted browser origins, the demo never sends queries from the user’s own IP, and dependencies are audited in CI
- Deployment: build and install scripts plus a hardened systemd unit for the exit server
- Live demo: a browser client on the Nym Wasm SDK, so anyone can try it with zero setup
Rust (edition 2024) workspace with proxy, exit and common crates, cargo fmt and clippy in
CI, and a Vite demo.