Skip to content
Docs / Commitment tree

Protocol

The commitment tree

Where commitments are stored and how proofs refer to them.


On this page

Append-only by design

Every new commitment, from shrouds, transfers and change outputs, is appended as the next leaf of a Merkle tree of depth 24. Nothing is ever removed: spent notes stay in the tree and are excluded only by their nullifiers. That keeps an exit from revealing which leaf was spent.

Recent roots

Each insertion produces a new root. The contract keeps a ring of the 100 most recent roots, so proofs made a few blocks earlier still verify. Which root a wallet chooses can itself leak timing; see the root timing note.