Skip to content
LogoLogo

Cryptographic base

  • Field: BN254 scalar field. Embedded curve: Grumpkin.
  • Hash: Poseidon2 everywhere, with a domain tag as the first input of every hash. Domain tags are u32 constants in protocol/lib/core, mirrored in the reference crate and pinned by generated tests.
  • Signatures: Schnorr over Grumpkin (wallet spend auth, FI vouching).
  • Encryption: ECDH on Grumpkin + ChaCha20-Poly1305 for envelopes (§4.11).
  • Proof system: UltraHonk (Barretenberg) with recursion for W. Three flavors are in play and the toolchain pins each:
    • Policy proofs (verified only inside W): Poseidon2-transcript ("recursive") flavor.
    • Wrapper and main proofs (verified on chain): Keccak-transcript zero-knowledge flavor. Non-ZK UltraHonk proofs leak witness-derived commitments and are never published.
    • W is universal across policies because Barretenberg pads proof size to a constant log n. weld build asserts this property of the pinned bb; a toolchain that drops it is a protocol version.
  • Circuit compilation via nargo; key generation and proving via bb. Versions are pinned in flake.nix and recorded in every manifest so any VK hash is reproducible by a third party.
  • Amounts are u128, not Field. Range-checked once at note creation. Rules use native comparisons.
  • Salt rule. Every commitment whose preimage has low entropy carries a random salt: params (§5.4), state (§5.5), attestations (§5.6), vk_root (§4.6). A public commitment to a guessable value is treated as a leak.