ProtocolCore release 0.1.0

Shielded Note model

A note's actual fields, domain-separated owner commitment, public leaf commitment, and encrypted recovery payload.

A note is the wallet-side record needed to spend a committed position. The Core Note fields are:

FieldMeaning
protocol_versionNote encoding version; the frozen value is 2.
domainProtocol domain value 0x5a4b43504d4d0003.
poolPool public key.
assetClassic SPL mint public key.
amountNote amount in raw token base units.
owner_commitmentPoseidon commitment to the spend secret.
randomnessSecret per-note entropy that makes commitments distinct.

The public Merkle leaf is the note commitment. The serialized 145-byte note plaintext is not placed in the tree. Shield emits a 186-byte authenticated encrypted payload for wallet-side recovery; the event separately exposes the note amount.

Spend secret and owner commitment

The SDK derives spendSecret from the wallet seed with HKDF-SHA256. It splits the 32-byte secret into two 128-bit big-endian limbs and hashes them with the owner domain:

ownerCommitment=Poseidon3(OWNER_DOMAIN,spend_secrethi,spend_secretlo)ownerCommitment = Poseidon3(OWNER\_DOMAIN, spend\_secret_{hi}, spend\_secret_{lo})

The owner commitment is part of the note preimage; the spend secret itself is not public. The circuit proves knowledge of the secret that opens the owner commitment.

Note commitment

Pool, asset and randomness are split into high/low 128-bit limbs. Starting with the note commitment domain, Core folds each value in order using Poseidon2:

state₀ = NOTE_COMMITMENT_DOMAIN
stateᵢ₊₁ = Poseidon2(stateᵢ, fieldᵢ)
field order = pool_hi, pool_lo, asset_hi, asset_lo,
              amount, owner_commitment, randomness_hi, randomness_lo

Domain separation prevents the same field sequence from being interpreted interchangeably as a tree hash, owner commitment or nullifier. See Poseidon and domains.

Why a public commitment is not spend authority

A commitment is a leaf identifier and a binding to hidden values. It is not a signature or secret key.

The SDK's Note type also stores the local leaf index, generation, encrypted payload and state (available, reserved, submitted or spent) for wallet operation management. Those wallet fields are not part of the public note commitment.

PreviousPrivate SendNext Nullifiers
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.