Docs / The proof circuit
Protocol
The proof circuit
A single circuit handles transfers and exits alike.
On this page
What a proof says
- Each spent note appears in the tree under the named root.
- The prover holds the key that owns each input note.
- Each published nullifier is computed correctly from its input note.
- Inputs equal outputs plus the public exit amount plus fees, for the same asset.
- Every output commitment is well formed.
- The recipient, relayer and relayer fee match the transaction, through a hash of that data.
Proof system
Written in Noir, the circuit spends two notes into two new ones. Your browser proves it with UltraHonk (Barretenberg) in a web worker, in about four seconds. Hashes are Poseidon. There is no project-specific trusted setup: UltraHonk uses the public Aztec Ignition reference string. The on-chain verifier, HonkVerifier, is generated from the circuit with its verification key fixed in code. Every value is on the parameters page.