5. Trust
the setup is Ethereum's
No setup was made for this protocol. Its proofs are KZG commitments against Ethereum's own powers of tau, from the EIP-4844 ceremony and its 141,416 contributions: a proof can be forged only by someone who knows tau, and tau is known only if every one of those contributors kept their share. This page lets you check that instead of reading it. Every check below runs in your browser, against mainnet, with nothing from this site taken on faith but the code you can read.
5.1.The Setup Is Ethereum's
The page picks a random polynomial of degree 2,055, commits to it with all 2,056 setup points the prover uses, opens it at a random point, and asks mainnet's point-evaluation precompile (address 0x0a, EIP-4844) to check the opening. Every Ethereum client runs that precompile with the ceremony's [tau]2 built in, so it accepts only if each point is the matching power of the ceremony's tau; a single wrong point fails it, but for a chance below 1 in 2240. Then the page sends the same opening with its value off by one, to show the precompile is really checking.
5.2.The File
The points come from trusted_setup.txt, the file the c-kzg-4844 library ships to Ethereum's clients. The page hashes the copy it serves, checks that each prover point is the file's own, that the verifier's [tau]2 is the file's G2 point 1, and that a pairing ties that point to the prover's [tau]1: one tau on both sides.
- trusted_setup.txt, sha256, publishedd39b9f2d047cc9dca2de58f264b6a09448ccd34db967881a6713eacacf0f26b7
5.3.The Circuit
One spend circuit, PS-PLONK over BLS12-381: five wires, custom gates for the Poseidon rounds, the nibble range checks and the four-way Merkle step, and every polynomial opened at one random point and its neighbour. The verifying key is 17 commitments; its digest, which the verifier contract holds as a constant and every proof's transcript begins with, is recomputed here from them.
- rows used, of1,428 of 2,048
- public inputs11
- proof2,912 bytes
- verifying key digestnil
- recomputed herenil
5.4.The Contracts
The code at each address, read from mainnet and hashed with the slots its constructor fills (its immutables) zeroed, as the compiler leaves them, against the hash of the code compiled from the published source. The Poseidon constants live as the code of their own data contract, and are hashed whole. Last, the Server is asked which verifier, Poseidon, token and Meter it calls.
| contract | bytes | sha256, immutables zeroed | on chain |
|---|---|---|---|
| nil | |||
5.5.A Proof, Checked Here
A sample spend proof, verified in this browser with the same algebra the on-chain verifier runs: the transcript, the constraints at a random point, and one pairing for the batched openings. Then again with one public amount changed, which must fail. Once the contracts exist, the same proof is also sent to the verifier on mainnet.