Trusted setup
Production Groth16 parameters were generated in a single-party setup; the toxic-waste assumption and MPC work are explicit.
The production Private Swap and Unshield circuits use frozen Groth16 parameters generated in a single-party trusted setup. The release did not use a multiparty computation ceremony.
Groth16 setup has toxic-waste material: if an adversary retained or obtained the setup secret, they could potentially create proofs that do not correspond to a valid witness. The setup manifest says setup secret material was not intentionally persisted. That is not an independently verifiable proof that toxic waste was destroyed or never compromised.
What is frozen
The production PK/VK artifacts and VKs embedded in the Core binary are pinned by the release manifests and hashes. The SDK verifies the production prover binary identity and exact PK size/hash before proving. This protects artifact consistency; it does not remove the setup assumption.
Required trust reduction
An independently verifiable production MPC ceremony is a trust-minimization requirement before unrestricted production/Mainnet use. Until then, users and integrators must explicitly accept the single-party assumption.
Artifact identities and circuit sizes are listed in Production parameters and Validation evidence.