A proof is one control. Safe withdrawal also requires the browser, proving files, public inputs, verifier, pool, RPC state, recovery material, and submission path to agree on one runtime.

Read current status first

Treat every recovery export as spend authority. Lost secrets, disclosed recovery material, and an approved wrong recipient are irreversible.

Start with the boundary you care about

Assets at risk

Who the system relies on

Critical invariants

  1. No withdrawal succeeds without a valid proof for the selected chain, pool, verifier, and positional public statement.
  2. A nullifier is accepted at most once.
  3. Deposits, private outputs, public exits, and fees preserve pool solvency.
  4. Recovery material reconstructs only the commitment and runtime it actually binds.
  5. Artifact trust starts from an independent pin outside the fetched manifest, setup record, WASM, and zkey set.
  6. Future relayer authority stays limited to the proof-bound call.
  7. Private witness material stays inside the trusted client boundary.

Control layers

Every layer must pass in order. A receipt confirms transaction execution; frontend authenticity comes from release provenance.

Read evidence narrowly