Zero-KnowledgeCore release 0.1.0

Private Swap circuit

The exact 22-element public input vector and witness relations constrained by the production Private Swap circuit.

The frozen production circuit has 14,394 constraints and 22 public field inputs. In the following order, each byte string is encoded as a BN254 field element; 32-byte public keys are split into two 128-bit limbs.

Public input order

IndexValue
0Private Swap protocol domain 0x5a4b43504d4d0003
1–2Pool public key high and low limbs
3–4Input asset mint high and low limbs
5–6Output asset mint high and low limbs
7Accepted input Merkle root
8Root sequence
9Input tree generation
10Input note nullifier
11–12Input-side and output-side CPMM reserves before settlement
13Fee tier in bps
14amount_in used by the swap
15amount_out from the CPMM
16change_amount
17Change commitment (zero field when there is no change)
18Output commitment
19Direction (0 A→B, 1 B→A)
20Circuit statement version constant 1
21Pool swap_nonce

The program derives the same vector from its accounts, instruction values and current pool nonce before invoking the verifier. The transaction does not get to supply a different reserve snapshot or public input blob.

Private witness

The witness includes input spend secret and randomness; the input commitment's 16 Merkle siblings, index and generation; then change and output spend secrets and randomness. The SDK currently creates output notes for the same wallet owner and uses fresh randomness. These secrets stay in local proving inputs and are not relayed as transaction fields.

Circuit relations

The circuit constrains:

  1. Owner commitment from the input spend-secret limbs.
  2. Input note commitment from pool, asset, amount_in + change_amount, owner commitment and input randomness.
  3. Merkle path ordering and the final root.
  4. Nullifier derivation from pool, input asset, spend secret and randomness.
  5. Fee tier membership in {100, 200, 300} and fee-adjusted integer CPMM output.
  6. 64-bit ranges for amounts/reserves and the circuit's bounded arithmetic intermediates.
  7. Change commitment when change is nonzero; output commitment for the new output amount.

Core then performs the stateful checks the circuit cannot own: live root history, canonical accounts, unused spent PDA, account-page append and SPL Token settlement. See Private Swap for the protocol-level transition.

PreviousGroth16Next Unshield circuit
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.