Program identity
The proof names the exact SP1 guest whose execution is being attested.
programVkeyHash
007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1VERIFIED HERERead the exact released artifact, run its complete BN254 Groth16 verification, then see what must connect that result to a Bitcoin Cash UTXO. No clone, server, or hidden request.
{
"preflight": {
"version": 4,
"classification": "public-safe canonical frozen V4 local Groth16 proving preflight",
"caseId": "accepted",
"relationIdentity": "apnt-import-created-note-relation-v4",
"relationDomain": "bch-cloak-apnt-v0:import-created-note-relation-v4",
"semanticContractCommitment": "5745166c8ec24a8bd07ca47629271092a17304be38e2dc54d8986dc684e3f234",
"statementCommitment": "6ecb7d4927be447eb8534377fd176ff26a03c45e6f2c1ec63bd24e437bfcb747",
"settlementProjectionCommitment": "808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3a",
"proofSystem": "sp1",
"proofProfile": "sp1-v6.1.0-groth16-bn254-v4",
"proofMode": "groth16",
"prover": "local-cpu",
"networkProvingConfigured": false,
"networkCredentialsRequired": false,
"sp1CrateVersion": "6.3.1",
"sp1CircuitVersion": "v6.1.0",
"programVkeyHash": "007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1",
"guestElfSha256": "97d6ada8066ba09ef2ef8a50653ac38340a143da0c70cb508c04a7362b2fa355",
"guestElfBytes": 1099664,
"canonicalInputCodec": "APNTPIV4",
"canonicalInputSha256": "d6589e3c5dc638f6412d0dd234b07544e3674eb264b408dff144c8bf4da1cbe3",
"canonicalInputBytes": 23531,
"publicValuesCodec": "APNTIRV4",
"publicValuesLayout": "raw-APNTIRV4-235-bytes",
"publicValuesSha256": "817a73ecb25d27f62d804a8b463b49cdfa366112869e191a7a66d0a73e737f6f",
"publicValuesLength": 235,
"cashVmVerifierAvailable": false,
"privateProvingInputPersisted": false
},
"proof": {
"version": 4,
"classification": "public-safe canonical V4 SP1 Groth16 proof artifact",
"caseId": "accepted",
"relationIdentity": "apnt-import-created-note-relation-v4",
"relationDomain": "bch-cloak-apnt-v0:import-created-note-relation-v4",
"semanticContractCommitment": "5745166c8ec24a8bd07ca47629271092a17304be38e2dc54d8986dc684e3f234",
"statementCommitment": "6ecb7d4927be447eb8534377fd176ff26a03c45e6f2c1ec63bd24e437bfcb747",
"settlementProjectionCommitment": "808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3a",
"proofSystem": "sp1",
"proofProfile": "sp1-v6.1.0-groth16-bn254-v4",
"proofMode": "groth16",
"prover": "local-cpu",
"sp1CrateVersion": "6.3.1",
"sp1CircuitVersion": "v6.1.0",
"programVkeyHash": "007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1",
"guestElfSha256": "97d6ada8066ba09ef2ef8a50653ac38340a143da0c70cb508c04a7362b2fa355",
"guestElfBytes": 1099664,
"groth16VerificationKeySha256": "4388a21c687fdd5f218d7e3d13190cac4c5355818d3605fd5fb811df468ee696",
"groth16VerificationKeyBytes": 492,
"groth16PublicInputLabels": [
"program-vkey",
"masked-sha256-public-values",
"exit-code",
"recursion-vkey-root",
"proof-nonce"
],
"groth16PublicInputsDecimal": [
"222415768487493486795564065136532017683584458128510723541774616628839478449",
"668668272647433752796367916061335396573248914621718748862383398065173397359",
"0",
"83960146348496814183195590144795274058764451818716359375255161226434597714",
"0"
],
"groth16PublicInputsBigEndian32": [
"007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1",
"017a73ecb25d27f62d804a8b463b49cdfa366112869e191a7a66d0a73e737f6f",
"0000000000000000000000000000000000000000000000000000000000000000",
"002f850ee998974d6cc00e50cd0814b098c05bfade466d28573240d057f25352",
"0000000000000000000000000000000000000000000000000000000000000000"
],
"publicValuesCodec": "APNTIRV4",
"publicValuesLayout": "raw-APNTIRV4-235-bytes",
"publicValuesBytes": "41504e54495256340431006263682d636c6f616b2d61706e742d76303a696d706f72742d637265617465642d6e6f74652d72656c6174696f6e2d7634240061706e742d696d706f72742d637265617465642d6e6f74652d72656c6174696f6e2d76345745166c8ec24a8bd07ca47629271092a17304be38e2dc54d8986dc684e3f234016ecb7d4927be447eb8534377fd176ff26a03c45e6f2c1ec63bd24e437bfcb747808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3a0d470200000004000000020000000200000001010101010101010101010101000000000000000001",
"publicValuesSha256": "817a73ecb25d27f62d804a8b463b49cdfa366112869e191a7a66d0a73e737f6f",
"publicValuesLength": 235,
"proofBytes": "4388a21c0000000000000000000000000000000000000000000000000000000000000000002f850ee998974d6cc00e50cd0814b098c05bfade466d28573240d057f25352000000000000000000000000000000000000000000000000000000000000000028466c02f2df2cda719135a48b3deb3a0eefdebc053b7b6351053897e13b0191244f967b12dda24d4b3c20c32e376b0cc1f68ce2770a9b6bec6745d7fa0efd892a93b2837e9dd3e41fbc124ae42c0c23546b6bc9b2d97215c2c4620f28cbc1091d4d7005cf020fbc7039b389e6e3ef2e39515cebc2853af4efcaf9ce27ffee32178178c0c868c6aebf84342f8b325e15f97e5b50f9b59b339842c1262fb371e1125c118f1604206dce8651e86f75cecd97f53b84313f7bdbc1b9e1ba87ac14ca1953753b39d4d1e8c131abd7fb1ce4103fa39457f227601efab8951b4253d69325509366a36265bef4aa4f88da2b1f835c56ac532b9fce5aa8a9077d30d6bca4",
"proofSha256": "92ebd58fe4b8e39dc5655b442e2dcf6968d08c612c88b1223f338c30d44391cd",
"proofBytesLength": 356,
"encodedProofBytesLength": 352,
"rawProofBytesLength": 324,
"proofNonce": "00000000",
"nativeVerificationSucceeded": true,
"cashVmVerifierAvailable": false,
"chainValidated": false,
"privateMaterialPublished": false,
"privateProvingInputPersisted": false
},
"measurement": {
"version": 4,
"proofProfile": "sp1-v6.1.0-groth16-bn254-v4",
"endToEndProofGenerationDurationMs": 480133,
"nativeVerificationDurationMicros": 147601,
"groth16WrappingIsIncluded": true,
"isolatedGroth16WrappingDurationAvailable": false,
"deterministicProofNonce": true,
"deterministicProofBytesClaimed": false
}
}
The verifier checks the artifact, proof, public values, program key, verification key, selector, curve points, and complete pairing equation.
loadingloadingLoading the verification path…
The first two links below are exercised by this page. The remaining links describe the minimum on-chain construction boundary. They are not a claim that this V4 proof was consumed by a BCH transaction.
The proof names the exact SP1 guest whose execution is being attested.
programVkeyHash
007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1VERIFIED HEREThe Groth16 public inputs bind the proof to the released settlement projection.
settlementProjectionCommitment
808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3aVERIFIED HEREA builder derives one commitment from the exact BCH inputs, source outputs, values, and created outputs being authorized.
canonical tx fields
→ SHA-256
→ projection32BUILDER TARGETThe spend must consume verifier-authenticated state for the same key and projection; a caller-supplied “true” is not proof evidence.
verifier identity
+ projection32
→ verdict inputON-CHAIN BOUNDARYThe covenant checks the verdict input and transaction projection while the created UTXO seal commits the note’s exit authority without exposing its private opening.
verdict input
+ created seal
+ note commitmentPROTOCOL BOUNDARYcashVmVerifierAvailable: false and chainValidated: false. A proof-to-transaction equivalence claim needs separate authenticated CashVM and chain evidence for the same proof instance.The useful community example is a tiny relation that proves knowledge of a committed secret and binds that authorization to one synthetic BCH transaction projection. It can teach the complete handoff without publishing Proofnote’s note assignment, Recovery, fee, batching, or aggregation design.
Example 06 uses a released transition proof and matching witness-redacted statement. It verifies the pairing, rebuilds the unsigned BCH transaction, and runs the released settlement covenant in Libauth CashVM. Every link is visible; the production verifier graph is not executed here, so its verdict boundary remains explicitly simulated.
The witness stays private. The proof commits to the program identity and public result, including one transaction-projection commitment.
witness + relation
→ proof + public valuesThe pinned key, proof points, and five public scalars must satisfy the complete BN254 Groth16 pairing equation.
proof + key + public values
→ verified resultThe authenticated verifier graph—not the caller and not the SAC—must produce the terminal verdict token for that result.
verified result
→ authenticated verdict NFTThe SAC re-derives the exact BCH transaction projection and accepts only when the verdict commitment matches.
verdict projection = tx projection
→ UTXO spendThe positive path uses only released public files. The negative controls change the proof binding, substitute a mismatched statement, alter the verdict commitment, change a covered source value, and break the P2SH32 covenant seal.
Start from casablanca-labs/proofnote commit 21117d0927bb7f4f3c0d8f64a80f04e8a6596b69. Do not edit files. Inventory examples/06-simulate-proof-bound-cashvm/example.json and verify every pinned input digest. Install with the frozen lockfile, deny network access during execution, run the positive path and all five negative controls, then explain prove → verify → authenticate verdict → authorize spend. Stop before private material, wallet access, funding, signing, broadcast, chain, or unsupported end-to-end claims. Return exact exit codes, commitments, VM profile, and non-claims.
This released proof records 511,154 ms end-to-end proof generation and 146,171 μs native verification. They describe one artifact, not BCH in general and not a universal benchmark.
Honesty boundary: the lab performs a real pairing and a real local covenant execution, but represents the terminal verdict with a synthetic token. Full verifier-graph execution and live chain settlement are separate evidence.
Verifier lineage: mr-zwets/groth16_cashscript at 6a309f5… and mr-zwets/zk-verifier-bench at 227ddf5…. Proofnote's pinned artifacts and checks remain the authority for Proofnote claims.