Proofnote · offline verification bench

Inspect one proof. Follow every binding.

Read the exact released artifact, run its complete BN254 Groth16 verification, then see what must connect that result to a Bitcoin Cash UTXO. No clone, server, or hidden request.

Pinned released artifact APNT import-created-note relation V4 source commit fcb8a55ffd9f425bf95bb936473d5bb325c62ff2
fixture canonical-groth16-proof-v4.json
fixture c23e9166b85d4ebe34ba5b820c06a674c4fecaed4b0db0ec375fa35e8c06613a
key examples/01-verify-a-proof/verification-key.json
key digest 4388a21c687fdd5f218d7e3d13190cac4c5355818d3605fd5fb811df468ee696
selector 4388a21c
1 · Identity
2 · Decode
3 · Key binding
4 · BN254 pairing
canonical-groth16-proof-v4.json Exact released bytes · SHA-256 c23e9166b85d4ebe34ba5b820c06a674c4fecaed4b0db0ec375fa35e8c06613a
Open immutable source ↗
{
  "preflight": {
    "version": 4,
    "classification": "public-safe canonical frozen V4 local Groth16 proving preflight",
    "caseId": "accepted",
    "relationIdentity": "apnt-import-created-note-relation-v4",
    "relationDomain": "bch-cloak-apnt-v0:import-created-note-relation-v4",
    "semanticContractCommitment": "5745166c8ec24a8bd07ca47629271092a17304be38e2dc54d8986dc684e3f234",
    "statementCommitment": "6ecb7d4927be447eb8534377fd176ff26a03c45e6f2c1ec63bd24e437bfcb747",
    "settlementProjectionCommitment": "808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3a",
    "proofSystem": "sp1",
    "proofProfile": "sp1-v6.1.0-groth16-bn254-v4",
    "proofMode": "groth16",
    "prover": "local-cpu",
    "networkProvingConfigured": false,
    "networkCredentialsRequired": false,
    "sp1CrateVersion": "6.3.1",
    "sp1CircuitVersion": "v6.1.0",
    "programVkeyHash": "007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1",
    "guestElfSha256": "97d6ada8066ba09ef2ef8a50653ac38340a143da0c70cb508c04a7362b2fa355",
    "guestElfBytes": 1099664,
    "canonicalInputCodec": "APNTPIV4",
    "canonicalInputSha256": "d6589e3c5dc638f6412d0dd234b07544e3674eb264b408dff144c8bf4da1cbe3",
    "canonicalInputBytes": 23531,
    "publicValuesCodec": "APNTIRV4",
    "publicValuesLayout": "raw-APNTIRV4-235-bytes",
    "publicValuesSha256": "817a73ecb25d27f62d804a8b463b49cdfa366112869e191a7a66d0a73e737f6f",
    "publicValuesLength": 235,
    "cashVmVerifierAvailable": false,
    "privateProvingInputPersisted": false
  },
  "proof": {
    "version": 4,
    "classification": "public-safe canonical V4 SP1 Groth16 proof artifact",
    "caseId": "accepted",
    "relationIdentity": "apnt-import-created-note-relation-v4",
    "relationDomain": "bch-cloak-apnt-v0:import-created-note-relation-v4",
    "semanticContractCommitment": "5745166c8ec24a8bd07ca47629271092a17304be38e2dc54d8986dc684e3f234",
    "statementCommitment": "6ecb7d4927be447eb8534377fd176ff26a03c45e6f2c1ec63bd24e437bfcb747",
    "settlementProjectionCommitment": "808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3a",
    "proofSystem": "sp1",
    "proofProfile": "sp1-v6.1.0-groth16-bn254-v4",
    "proofMode": "groth16",
    "prover": "local-cpu",
    "sp1CrateVersion": "6.3.1",
    "sp1CircuitVersion": "v6.1.0",
    "programVkeyHash": "007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1",
    "guestElfSha256": "97d6ada8066ba09ef2ef8a50653ac38340a143da0c70cb508c04a7362b2fa355",
    "guestElfBytes": 1099664,
    "groth16VerificationKeySha256": "4388a21c687fdd5f218d7e3d13190cac4c5355818d3605fd5fb811df468ee696",
    "groth16VerificationKeyBytes": 492,
    "groth16PublicInputLabels": [
      "program-vkey",
      "masked-sha256-public-values",
      "exit-code",
      "recursion-vkey-root",
      "proof-nonce"
    ],
    "groth16PublicInputsDecimal": [
      "222415768487493486795564065136532017683584458128510723541774616628839478449",
      "668668272647433752796367916061335396573248914621718748862383398065173397359",
      "0",
      "83960146348496814183195590144795274058764451818716359375255161226434597714",
      "0"
    ],
    "groth16PublicInputsBigEndian32": [
      "007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1",
      "017a73ecb25d27f62d804a8b463b49cdfa366112869e191a7a66d0a73e737f6f",
      "0000000000000000000000000000000000000000000000000000000000000000",
      "002f850ee998974d6cc00e50cd0814b098c05bfade466d28573240d057f25352",
      "0000000000000000000000000000000000000000000000000000000000000000"
    ],
    "publicValuesCodec": "APNTIRV4",
    "publicValuesLayout": "raw-APNTIRV4-235-bytes",
    "publicValuesBytes": "41504e54495256340431006263682d636c6f616b2d61706e742d76303a696d706f72742d637265617465642d6e6f74652d72656c6174696f6e2d7634240061706e742d696d706f72742d637265617465642d6e6f74652d72656c6174696f6e2d76345745166c8ec24a8bd07ca47629271092a17304be38e2dc54d8986dc684e3f234016ecb7d4927be447eb8534377fd176ff26a03c45e6f2c1ec63bd24e437bfcb747808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3a0d470200000004000000020000000200000001010101010101010101010101000000000000000001",
    "publicValuesSha256": "817a73ecb25d27f62d804a8b463b49cdfa366112869e191a7a66d0a73e737f6f",
    "publicValuesLength": 235,
    "proofBytes": "4388a21c0000000000000000000000000000000000000000000000000000000000000000002f850ee998974d6cc00e50cd0814b098c05bfade466d28573240d057f25352000000000000000000000000000000000000000000000000000000000000000028466c02f2df2cda719135a48b3deb3a0eefdebc053b7b6351053897e13b0191244f967b12dda24d4b3c20c32e376b0cc1f68ce2770a9b6bec6745d7fa0efd892a93b2837e9dd3e41fbc124ae42c0c23546b6bc9b2d97215c2c4620f28cbc1091d4d7005cf020fbc7039b389e6e3ef2e39515cebc2853af4efcaf9ce27ffee32178178c0c868c6aebf84342f8b325e15f97e5b50f9b59b339842c1262fb371e1125c118f1604206dce8651e86f75cecd97f53b84313f7bdbc1b9e1ba87ac14ca1953753b39d4d1e8c131abd7fb1ce4103fa39457f227601efab8951b4253d69325509366a36265bef4aa4f88da2b1f835c56ac532b9fce5aa8a9077d30d6bca4",
    "proofSha256": "92ebd58fe4b8e39dc5655b442e2dcf6968d08c612c88b1223f338c30d44391cd",
    "proofBytesLength": 356,
    "encodedProofBytesLength": 352,
    "rawProofBytesLength": 324,
    "proofNonce": "00000000",
    "nativeVerificationSucceeded": true,
    "cashVmVerifierAvailable": false,
    "chainValidated": false,
    "privateMaterialPublished": false,
    "privateProvingInputPersisted": false
  },
  "measurement": {
    "version": 4,
    "proofProfile": "sp1-v6.1.0-groth16-bn254-v4",
    "endToEndProofGenerationDurationMs": 480133,
    "nativeVerificationDurationMicros": 147601,
    "groth16WrappingIsIncluded": true,
    "isolatedGroth16WrappingDurationAvailable": false,
    "deterministicProofNonce": true,
    "deterministicProofBytesClaimed": false
  }
}
READY

Verify these bytes

The verifier checks the artifact, proof, public values, program key, verification key, selector, curve points, and complete pairing equation.

Measured herenot run
Deliveryone file · zero requests
What runs in this browser
Source fileloading
Verified fieldloading
Verification path

Loading the verification path…

A PASS establishes: this published proof verifies under this pinned key and these public values. It does not establish: guest semantic correctness, authenticated CashVM execution, BCH validation or inclusion, APNT or wallet acceptance, custody, spendability, privacy, or successive transfer.
Proof → transaction → note

What a proof-bound BCH spend must connect

The first two links below are exercised by this page. The remaining links describe the minimum on-chain construction boundary. They are not a claim that this V4 proof was consumed by a BCH transaction.

01 / RELATION

Program identity

The proof names the exact SP1 guest whose execution is being attested.

programVkeyHash
007de2035d65f1dd58a3cf0c930fde5c7c7c99443b26fc30c2cd7f26014a74b1
VERIFIED HERE
02 / STATEMENT

Public commitment

The Groth16 public inputs bind the proof to the released settlement projection.

settlementProjectionCommitment
808d03efd14c65e2779068b4db6cf388b4fa142a00a7f30f64ce4ef11bb05c3a
VERIFIED HERE
03 / TRANSACTION

Canonical projection

A builder derives one commitment from the exact BCH inputs, source outputs, values, and created outputs being authorized.

canonical tx fields
→ SHA-256
→ projection32
BUILDER TARGET
04 / VERDICT

Authenticated result

The spend must consume verifier-authenticated state for the same key and projection; a caller-supplied “true” is not proof evidence.

verifier identity
+ projection32
→ verdict input
ON-CHAIN BOUNDARY
05 / UTXO SEAL

Private-note backing

The covenant checks the verdict input and transaction projection while the created UTXO seal commits the note’s exit authority without exposing its private opening.

verdict input
+ created seal
+ note commitment
PROTOCOL BOUNDARY
Honesty boundary: this V4 artifact proves its released public statement under its pinned key. Its own record says cashVmVerifierAvailable: false and chainValidated: false. A proof-to-transaction equivalence claim needs separate authenticated CashVM and chain evidence for the same proof instance.
Safe public teaching boundary

A toy kernel, not the APNT recipe

The useful community example is a tiny relation that proves knowledge of a committed secret and binds that authorization to one synthetic BCH transaction projection. It can teach the complete handoff without publishing Proofnote’s note assignment, Recovery, fee, batching, or aggregation design.

PublishStatement schema, verifier key, one positive vector, deterministic tamper vectors, and a local CashVM transaction.
ProveKnowledge of a commitment opening plus equality to one public transaction-projection digest.
DemonstrateProof acceptance, authenticated verdict binding, covenant acceptance, then rejection when the transaction changes.
Keep privateAPNT relation internals, note-to-cell assignment, Recovery, change/fee policy, wallet state, prover orchestration, and aggregator machinery.
Run it · real proof, local transaction

See how a proof authorizes a UTXO spend

Example 06 uses a released transition proof and matching witness-redacted statement. It verifies the pairing, rebuilds the unsigned BCH transaction, and runs the released settlement covenant in Libauth CashVM. Every link is visible; the production verifier graph is not executed here, so its verdict boundary remains explicitly simulated.

What you can execute

One command, five ways to break it

The positive path uses only released public files. The negative controls change the proof binding, substitute a mismatched statement, alter the verdict commitment, change a covered source value, and break the P2SH32 covenant seal.

Proof356 bytes
Unsigned tx5,057 bytes
VMBCH_2026_05
Open the immutable runnable example ↗
Copy the agent workflow
Start from casablanca-labs/proofnote commit 21117d0927bb7f4f3c0d8f64a80f04e8a6596b69. Do not edit files. Inventory examples/06-simulate-proof-bound-cashvm/example.json and verify every pinned input digest. Install with the frozen lockfile, deny network access during execution, run the positive path and all five negative controls, then explain prove → verify → authenticate verdict → authorize spend. Stop before private material, wallet access, funding, signing, broadcast, chain, or unsupported end-to-end claims. Return exact exit codes, commitments, VM profile, and non-claims.
Cost is not one number

What makes proving slow—or fast

This released proof records 511,154 ms end-to-end proof generation and 146,171 μs native verification. They describe one artifact, not BCH in general and not a universal benchmark.

  • Proving time changes with circuit size, witness generation, recursion, backend, implementation, hardware, memory, and concurrency.
  • Proof size is a proof-system artifact; it is not the same as the verifier program or transaction size.
  • On-chain cost separates authenticated verifier execution from the SAC's transaction-binding work.

Honesty boundary: the lab performs a real pairing and a real local covenant execution, but represents the terminal verdict with a synthetic token. Full verifier-graph execution and live chain settlement are separate evidence.

Verifier lineage: mr-zwets/groth16_cashscript at 6a309f5… and mr-zwets/zk-verifier-bench at 227ddf5…. Proofnote's pinned artifacts and checks remain the authority for Proofnote claims.