A proof is one control. Safe withdrawal also requires the browser, proving files, public inputs, verifier, pool, RPC state, recovery material, and submission path to agree on one runtime.
Read current status first
Treat every recovery export as spend authority. Lost secrets, disclosed recovery material, and an approved wrong recipient are irreversible.
Start with the boundary you care about
- See what remains public before making a privacy claim.
- Protect recovery authority as bearer spend authority.
- Audit the trust chain from runtime selection through settlement.
- Read the audit report for the reviewed snapshot, findings, and limits.
- Read what the proof checks before relying on Groth16 acceptance.
- Report a vulnerability without publishing recovery material, witnesses, or a live exploit.
Assets at risk
Who the system relies on
Critical invariants
- No withdrawal succeeds without a valid proof for the selected chain, pool, verifier, and positional public statement.
- A nullifier is accepted at most once.
- Deposits, private outputs, public exits, and fees preserve pool solvency.
- Recovery material reconstructs only the commitment and runtime it actually binds.
- Artifact trust starts from an independent pin outside the fetched manifest, setup record, WASM, and zkey set.
- Future relayer authority stays limited to the proof-bound call.
- Private witness material stays inside the trusted client boundary.