Skip to content
Cryptographic base
- Field: BN254 scalar field. Embedded curve: Grumpkin.
- Hash: Poseidon2 everywhere, with a domain tag as the first input of
every hash. Domain tags are
u32 constants in protocol/lib/core,
mirrored in the reference crate and pinned by generated tests.
- Signatures: Schnorr over Grumpkin (wallet spend auth, FI vouching).
- Encryption: ECDH on Grumpkin + ChaCha20-Poly1305 for envelopes (§4.11).
- Proof system: UltraHonk (Barretenberg) with recursion for
W. Three
flavors are in play and the toolchain pins each:
- Policy proofs (verified only inside
W): Poseidon2-transcript
("recursive") flavor.
- Wrapper and main proofs (verified on chain): Keccak-transcript
zero-knowledge flavor. Non-ZK UltraHonk proofs leak witness-derived
commitments and are never published.
W is universal across policies because Barretenberg pads proof size
to a constant log n. weld build asserts this property of the pinned
bb; a toolchain that drops it is a protocol version.
- Circuit compilation via
nargo; key generation and proving via bb.
Versions are pinned in flake.nix and recorded in every manifest so any
VK hash is reproducible by a third party.
- Amounts are
u128, not Field. Range-checked once at note creation.
Rules use native comparisons.
- Salt rule. Every commitment whose preimage has low entropy carries a
random salt: params (§5.4), state (§5.5), attestations (§5.6),
vk_root
(§4.6). A public commitment to a guessable value is treated as a leak.