Zero-KnowledgeCore release 0.1.0

Why zero knowledge

The proof validates note ownership, Merkle membership and settlement constraints without exposing the authorization witness.

A shielded spend needs to establish three facts: the note was created by the protocol, the caller can authorize its spend, and the transition obeys protocol rules. Publishing the note preimage or spend secret would reveal the very link the shielded design is meant to obscure.

Zero knowledge separates a public statement from a private witness:

  • The statement contains the pool, asset direction, accepted root, nullifier, reserves, fee and public amounts or recipient.
  • The witness contains the spend secret, note randomness, Merkle path and material for new note commitments.
  • The verifier accepts only a proof that links the witness to the statement and satisfies the circuit constraints.
Public statement
  • pool and asset direction
  • reserves, fees and swap amounts
  • root, nullifier and output commitments
  • fee payer and transaction timing
Groth16VALID / INVALID
Private witness
  • spend secret and note randomness
  • input commitment preimage
  • Merkle path and leaf index
  • new note authorization material

What this does and does not hide

The proof does not reveal the spend secret or input membership path. It does reveal the public statement. In v0.1.0, Private Swap input/output amounts, direction, pool and nullifier are public. Unshield amount and recipient are public. Transaction timing, payer, RPC/network metadata and reserve changes are public.

The proof is one part of a larger state transition: Core separately checks that the root is accepted, the nullifier PDA is unused, the accounts are canonical and token settlement matches the verified statement.

For the proof system details, see Groth16, Private Swap circuit and Unshield circuit.

PreviousTree paging & archiveNext Groth16
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.