A proof is one control. Safe withdrawal also requires the browser, proving files, public inputs, verifier, pool, RPC state, recovery material, and submission path to agree on one runtime.
Start here
Treat private-balance unlock signatures and any exported bearer recovery notes as spend authority. Lost secrets, disclosed recovery material, and an approved wrong recipient are irreversible.
Start with the boundary you care about
- See what remains public before making a privacy claim.
- Protect recovery authority, including wallet signatures and any exported bearer backup.
- Audit the trust chain from runtime selection through settlement.
- Read the audit report for the reviewed snapshot, findings, and limits.
- Read what the proof checks before relying on Groth16 acceptance.
- Report a vulnerability without publishing recovery material, witnesses, or a live exploit.
Assets at risk
Who the system relies on
Critical invariants
- No withdrawal succeeds without a valid proof for the selected chain, pool, verifier, and positional public statement.
- A nullifier is accepted at most once.
- Deposits, private outputs, public exits, and fees preserve pool solvency.
- Wallet or bearer recovery reconstructs only the commitment and runtime it actually binds.
- Artifact trust starts from an independent pin outside the fetched manifest, setup record, WASM, and zkey set.
- Relayer authority stays limited to the proof-bound call.
- Private witness material stays inside the trusted client boundary.

