Skip to content
LogoLogo

Notes, tree, nullifiers

commitment  = H(NOTE, asset, amount, pk_d.x, pk_d.y, rho)
nullifier   = H(NULL, nk, leaf_index)

Append-only Poseidon2 Merkle tree of depth 32 for commitments, with a root history window of R_NOTE recent roots; a nullifier set on chain. Spend arity K = 2 inputs. Initiate produces 1 change note plus a hold; resolve and reclaim each produce exactly 1 note.

There is no lock set. Inputs are nullified at initiate (§4.4), so a hold cannot be double-spent and there is nothing to release.