Groth16
Lethenymous uses production Groth16 proofs over BN254, verified on Solana against frozen circuit-specific keys.
Groth16 is a succinct pairing-based proof system. For a fixed circuit, a proving key (PK) lets a prover generate a proof from a public statement and private witness. A corresponding verifying key (VK) lets Core check that proof against the statement.
The proof is 256 bytes in the frozen release. It does not contain the witness in plaintext. The program calls Solana's BN254 operations to perform the pairing check using circuit-specific production verifying-key bytes embedded in the frozen binary.
The statement and witness
The statement has a fixed number and order of public field elements: 22 for Private Swap and 10 for Unshield. The witness is generated client-side and includes values such as spend secrets, note randomness and Merkle siblings. If any public value differs from the proved value, such as the fee tier, root, amount or recipient, the verification inputs do not match.
The proving key and verifying key must be a pair generated for the same circuit. The SDK's ProductionProver checks the authenticated prover executable and exact PK size/hash before generating a proof. It also returns public inputs, which the SDK independently compares with its locally encoded statement.
BN254 and on-chain verification
Both circuits use the BN254 curve and the Arkworks Groth16 implementation. The on-chain verifier checks canonical field encodings, proof length and the pairing equation. Private Swap and Unshield have separate VKs; a proof for one circuit is not valid under the other circuit's verifier.
| Circuit | Public inputs | Constraints | Proof bytes |
|---|---|---|---|
| Private Swap | 22 | 14,394 | 256 |
| Unshield | 10 | 7,147 | 256 |
Read production parameters for artifact identities and the setup status.