Skip to content
Docs / The proof circuit

Protocol

The proof circuit

A single circuit handles transfers and exits alike.


On this page

What a proof says

  • Each spent note appears in the tree under the named root.
  • The prover holds the key that owns each input note.
  • Each published nullifier is computed correctly from its input note.
  • Inputs equal outputs plus the public exit amount plus fees, for the same asset.
  • Every output commitment is well formed.
  • The recipient, relayer and relayer fee match the transaction, through a hash of that data.

Proof system

Written in Noir, the circuit spends two notes into two new ones. Your browser proves it with UltraHonk (Barretenberg) in a web worker, in about four seconds. Hashes are Poseidon. There is no project-specific trusted setup: UltraHonk uses the public Aztec Ignition reference string. The on-chain verifier, HonkVerifier, is generated from the circuit with its verification key fixed in code. Every value is on the parameters page.