Skip to content
LogoLogo

Prior art

Bonsai (O'Grady, Meier, Policharla; ePrint 2026/1987) is an account-based private payment scheme targeting a million operations per second: one commitment per account, no validator-side nullifiers, per-user private nullifier trees keyed by receipt position, and an operation-hiding variant in which sends and receives publish identical records.

Adopted here: uniform resolve records with a witness-selected branch (§4.4, §4.10); root history windows for anchors (§4.6); the per-party anchored state chain from a canonical empty root, and the sparse-tree insert and prefix-pruning pattern for keyed state (§5.5); key possession at registration and signed indices (§4.6, §4.8); a normative leakage profile in the style of a leakage-parameterized ideal functionality (§4.13); separation of signing authority from proving (§4.8); an explicit public fee (§4.12).

Not adopted, and why: the account model and position-as-nullifier, because Weld needs unlinkable notes across FIs and a hold that fails closed with an expiry, which Bonsai's debit-at-send receipts do not have; PARI with batch verification, because it needs a circuit-specific trusted setup and Weld's FIs compile arbitrary policies, so UltraHonk recursion is the right fit; indefinitely offline receivers, which are incompatible with deadlines.

MIP410 is prior art for the FI-vouched, hold-based regulated shielded transfer model that Weld generalizes with a programmable policy slot.

Canton / Daml is the model for the programmable workflow layer in spec/workflows.md: the hold in this document is Daml's propose-and-accept pattern with one template, and the FI policy slot is a per-stakeholder validation hook. That document maps each Canton ledger-model concept to a proof-enforced equivalent.