# Privacy Boost Markdown version of https://l2beat.com/privacy/projects/privacy-boost ## Summary - Total Value Locked: $1.44 M (+0.02% compared to seven days ago) - Assets tracked: 18 - Buckets tracked: 18 - Deposits 7D: 583 (-12.0% compared to the previous seven days) - Deposits 30D: 2.76 K - Deposits Total: 20.57 K - Tracked on: Base Chain - Attributes: ZK, TEE, Transfers, DeFi, Any amount ### Risks - Trusted setup: Privacy Boost v3 (sentiment: bad). Privacy Boost v3: Circuit-specific trusted setup for the 12 Groth16 Privacy Boost epoch, forced withdrawal and gift claim circuits deployed in late September 2026. It was built on top of 80 Perpetual Powers of Tau phase 1 contributions, with a publicly announced phase 2 whose transcript and participant list have not yet been published. The proving system could be broken if either phase 1 or 2 is compromised. - Exit window: None (sentiment: bad). The pool and both registries sit behind transparent proxies whose ProxyAdmins are owned by the admin multisig, which can upgrade them with no delay. Users get no window to exit before a change takes effect. This protocol does not pass the walkaway test: users cannot fully use it if all centralized protocol participants disappear. If the TEE operators disappear, no new deposits or private transfers can be processed and the system enters exit-only mode. - Privacy: Link privacy. Public observer: Link private (sentiment: good); Chain analyst: Link exposed (sentiment: bad); Network observer: Link private (sentiment: good); Privileged insider: Link exposed (sentiment: bad); Future adversary: Link exposed (sentiment: bad). - Reproducibility: Partially reproducible (sentiment: warning). ZK circuits guaranteeing user fund security are published, but the epoch, forced withdrawal and gift claim verification keys deployed in September 2026 have not yet been reproduced by L2BEAT. The TEE sources guaranteeing privacy are not yet published. TEE logic could not be verified for correctness. ### About A shielded pool for ERC-20 tokens on Base, designed for institutional users. Provides TEE-backed privacy, balancing better UX with worse privacy trust assumptions. ### Links - Website: https://www.privacyboost.io/ - Docs: https://docs.privacyboost.io/ - Repository: https://github.com/sunnyside-io/privacy-boost-protocol, https://github.com/sunnyside-io/privacy-boost-ceremony - Contracts explorer (Disco): https://disco.l2beat.com/ui/p/privacy-boost ## Protocol description Privacy Boost is a shielded pool for registered ERC-20 tokens on Base, aimed at institutional users. The operator's TEE setup has to be trusted for privacy and liveness, while ZKPs ensure validity and an exit path against a malicious or faulty operator. ### Architecture Deposited tokens are represented as notes whose Poseidon2 commitments are appended to an onchain Merkle tree, and spending a note publishes its nullifier. Users can privately transfer deposited tokens to other users. The TEE collects user-approved transfers and withdrawals, batches them into epochs, and a permissioned relay submits each epoch onchain with a Groth16 proof that checks correctness. Accounts can authorize spending with registered approval keys or with explicit onchain spend approvals, including batches and approval-only smart-wallet accounts. Epoch proofs use current auth roots or roots superseded no more than 10 minutes ago. Users can locally prove a forced withdrawal of up to 13 notes. The contract checks that the referenced auth key or spend approval is live and unexpired when the request is submitted, and records the authorized withdrawal and fee. Anyone can execute it 3 days later if the notes remain unspent, without cooperation from the TEE or relays. The account owner can cancel a pending request. Users can locally generate and deploy portal deposit EIP-7702 addresses. Anyone can send ERC-20 to such a portal address, the tokens are regularly swept into Privacy Boost escrow for the hidden recipient. Gift notes can be claimed by recipients or refunded by senders after a bound deadline, either privately through a relay or through a permissionless public gift exit. Proof-authorized withdrawals can also call approved external gateways for DeFi operations. If the operator disappears, no new deposits or private transfers can be processed and the pool effectively enters this exit-only mode, in which the zero-knowledge guarantees alone are sufficient to recover funds. ### Privacy considerations All private data exists in plaintext inside the operator's TEE. This privacy depends on the hardware security of the TEE against actors with physical access (side-channel and microarchitectural attacks could expose the full plaintext ledger), as well as vendor vulnerabilities. The source code running within the TEE is not published. A permissionless forced withdrawal publishes the commitments of the spent notes and the registered account ID, publicly linking the exit of specific notes with the EOA that registered auth keys. It is a fallback mechanism that reclaims the user's tokens but strips the privacy. Practical privacy also depends on the timing and amounts of deposits and withdrawals, as well as on the frontend used to interact with the pool. Normal withdrawals and transfers within the private pool are not submitted as onchain transactions via RPC nodes, but directly to the TEE, thus not leaking anything to the RPC. Users are advised to research [OPSEC best practice](https://l2beat.com/publications/privacy-best-practices). ### Fees Standard deposits are free of protocol fees. Portal deposits can charge a separate sweeper fee, capped at 10% and currently set to 0%, and have token-specific minimum sweep amounts. Withdrawals, including forced withdrawals and public gift exits, pay a 0.4% fee forwarded to the treasury; a forced withdrawal records the fee at request time. ### Deposit and withdrawal statistics The pool's own events do not carry per-transfer amounts, so L2BEAT counts every ERC-20 transfer into the pool as a deposit and every transfer out of it as a withdrawal. Besides regular deposits, portal sweeps and withdrawals, this includes refunds of cancelled deposit requests, withdrawal fees forwarded to the treasury, and both legs of DeFi operations executed through approved gateways. ### Compliance Registered auditors can query the Audit API of the TEE to fetch the balance and transaction history of any address. The TEE serves such requests without user consent, but is supposed to emit a record of every access on the AuditGateway smart contract, so that users can publicly verify whether and when their private data was disclosed. The source code running within the TEE is not published, so it is impossible to verify the onchain audit attestation mechanism. ## Privacy **What the protocol promises:** Hides everything inside the ledger, including which deposits fund a withdrawal. Deposits and withdrawals are public. On public blockchains like Ethereum, all actions transparent by default. A privacy protocol can at best cut the link between addresses or offer privacy while deposited. The colour says whether a careful user can keep the link, amount or recipient private against that adversary: green yes, yellow only outside supported options or by accepting another leak, red no. Fields marked at risk stay private only under the condition in their note. ### Public observer Link private (sentiment: good) **Who:** Everyone with a block explorer and some basic tools. Sees every public onchain event, but does no correlation beyond following links. Examples: A curious counterparty, an employer, a journalist. Transfers inside publish only encrypted notes. Deposits and withdrawals show address, token and amount. Each epoch's calldata pairs every exit with the nullifiers and the input/output shape of the transfer that funded it. **Advice:** Exit through the operator's relay; a forced exit reveals your account and the notes you spend. A public gift exit names the destination. **Inside** - Sender: private - Recipient: private - Amount: private. Leaked for gateway DeFi legs. - Asset: private. Leaked for gateway DeFi legs. - Link: private. Epoch calldata ties each exit to the nullifiers and shape of one transfer. **Sources** - [PrivacyBoost](https://l2beat.com/privacy/projects/privacy-boost#PrivacyBoost) - [Epoch calldata: withdrawals, nullifiers and transfer shapes](https://github.com/sunnyside-io/privacy-boost-protocol/blob/23907eeebf0e50cd18da42a287671189e61ecb0f/contracts/src/interfaces/IPrivacyBoost.sol#L828-L852) - [Forced withdrawal publishes account, destination and notes](https://github.com/sunnyside-io/privacy-boost-protocol/blob/23907eeebf0e50cd18da42a287671189e61ecb0f/contracts/src/interfaces/IPrivacyBoost.sol#L582-L592) - [Gift claim and refund are indistinguishable](https://github.com/sunnyside-io/privacy-boost-protocol/blob/23907eeebf0e50cd18da42a287671189e61ecb0f/contracts/src/interfaces/IPrivacyBoost.sol#L694-L707) ### Chain analyst Link exposed (sentiment: bad) **Who:** Scrapes all public data and correlates it: timing, amounts, gas and wallet fingerprints, address clusters. Examples: Chain analytics firms, ZachXBT, data brokers. The anonymity set is small, so most withdrawals can be linked to their funding deposits by amount and timing. **Advice:** There is currently no crowd to hide in. Keep funds inside and transfer often, withdraw amounts that match no deposit, and never exit to an address that has deposited. **Inside, compared with a public observer** - Sender: at risk - Recipient: at risk - Amount: at risk. Bounded by the public deposit and exit amounts. - Asset: at risk - Link: at risk. The anonymity set is too small for care to hide the link. **Sources** - [Operator heartbeat address](https://basescan.org/address/0xf977237b7d978dde922ee4909619740c73d8a49b) - [Withdrawal fee in basis points](https://l2beat.com/privacy/projects/privacy-boost#PrivacyBoost) ### Network observer Link private (sentiment: good) **Who:** Sits between the user and the chain and sees web2 traffic only: RPC providers, relayers and broadcasters, indexers, ISPs. Learns IP addresses, timing, browser fingerprints, ciphertext and what becomes public. Assumes Tor to send transactions and, where the client has an RPC setting, an own node to read the blockchain. Examples: Infura or Alchemy, a Tornado relayer, a wallet vendor selling telemetry, Google captcha or analytics in the dapp frontend. All shielded actions go to the operator's server as an encrypted envelope, and note keys stay in a local vault. Only the operator's relay submits epochs onchain, so nothing of yours reaches a public node. **Inside, compared with a public observer** - Amount: private - Asset: private - Link: private **Sources** - [SDK package, closed Rust core](https://www.npmjs.com/package/@sunnyside-io/privacy-boost) - [Server info endpoint](https://base.privacyboost.io/api/v1/info) - [Single permitted relay](https://l2beat.com/privacy/projects/privacy-boost#PrivacyBoost) ### Privileged insider Link exposed (sentiment: bad) **Who:** Holds a protocol operator role or receives keys or plaintext by design: upgrade admin, sequencer, decryption or view key holder, TEE vendor, association set provider, hosted prover, note registry. Examples: A compliance backdoor key, a DAO with an upgrade key, a KMS committee, an ASP operator. The operator runs the enclave that holds every transfer in plaintext and the key to every onchain note. The client fetches that key from the operator's web endpoint and the published SDK checks no enclave attestation, so a substituted key would read every note unnoticed. Appointed auditors can pull any account's history without consent, and the audit log is written by the operator's own unpublished code. **Advice:** Treat everything in the pool as visible to the operator. A forced exit is the only path that does not need it, and it is public. **Inside, compared with a public observer** - Sender: exposed - Recipient: exposed - Amount: exposed - Asset: exposed - Link: exposed **Sources** - [AuditGateway](https://l2beat.com/privacy/projects/privacy-boost#AuditGateway) - [Admin and operator multisigs](https://l2beat.com/privacy/projects/privacy-boost#permissions) - [TEE key is fetched from the operator endpoint](https://www.npmjs.com/package/@sunnyside-io/privacy-boost) - [Notes wrap an ephemeral key for the TEE alongside the receiver](https://github.com/sunnyside-io/privacy-boost-protocol/blob/23907eeebf0e50cd18da42a287671189e61ecb0f/contracts/src/interfaces/IStructs.sol#L36-L56) ### Future adversary Link exposed (sentiment: bad) **Who:** Harvest now, decrypt later. Holds every byte ever written onchain plus any retained logs, and future cryptanalysis such as a large quantum computer that breaks elliptic-curve key exchange and pairings, but not hashes, symmetric ciphers or lattices. Examples: First well-funded insiders, then everyone in a potential post-quantum future. Every note wraps its key to the enclave's long-lived elliptic-curve public key as well as the receiver's. A quantum computer, or a leak of that one key, decrypts the entire history. **Inside, compared with a public observer** - Sender: exposed - Recipient: exposed - Amount: exposed - Asset: exposed - Link: exposed **Sources** - [Ciphertext layout](https://l2beat.com/privacy/projects/privacy-boost#PrivacyBoost) - [Every output and deposit ciphertext carries a TEE-wrapped key](https://github.com/sunnyside-io/privacy-boost-protocol/blob/23907eeebf0e50cd18da42a287671189e61ecb0f/contracts/src/interfaces/IStructs.sol#L36-L125) ## Value Locked The interactive value chart is shown on [the HTML page](https://l2beat.com/privacy/projects/privacy-boost#privacy-tvl). ## Flows The interactive flows chart is shown on [the HTML page](https://l2beat.com/privacy/projects/privacy-boost#privacy-flows). ## Assets Breakdown | Asset | Deposits 7D | Deposits 30D | Deposits Total | Value Locked | | --- | --- | --- | --- | --- | | wstETH | 1 ($49.86) | 3 ($1.35 M) | 5 ($1.35 M) | $1.37 M | | USDC | 16 ($231.68 K) | 46 ($278.74 K) | 90 ($318.76 K) | $52.29 K | | gtwethb | 0 ($0.00) | 4 ($12.53 K) | 5 ($12.54 K) | $13.79 K | | WETH | 565 ($183.31 K) | 2.69 K ($209.17 K) | 20.45 K ($247.96 K) | $2.55 K | | bbqUSDC | 0 ($0.00) | 0 ($0.00) | 2 ($797.87) | $787.94 | | gtusdcf | 0 ($0.00) | 2 ($239.73) | 5 ($19.35 K) | $241.67 | | AAPLc | 0 ($0.00) | 0 ($0.00) | 1 ($7.19) | $7.40 | | USDT | 0 ($0.00) | 7 ($15.80) | 7 ($15.80) | $5.00 | | CSUSDC | 0 ($0.00) | 1 ($4.59) | 2 ($9.19) | $4.59 | | edgeUSDC | 1 ($1.90) | 1 ($1.90) | 1 ($1.90) | $1.91 | | BRETT | 0 ($0.00) | 0 ($0.00) | 1 ($0.24) | $0.23 | | AERO | 0 ($0.00) | 0 ($0.00) | 0 ($0.00) | — | | Basecat | 0 ($0.00) | 0 ($0.00) | 0 ($0.00) | — | | cbBTC | 0 ($0.00) | 0 ($0.00) | 0 ($0.00) | — | | cbXRP | 0 ($0.00) | 0 ($0.00) | 0 ($0.00) | — | | EURC | 0 ($0.00) | 1 ($0.03) | 1 ($0.03) | — | | SOL | 0 ($0.00) | 0 ($0.00) | 0 ($0.00) | — | | TOSHI | 0 ($0.00) | 0 ($0.00) | 0 ($0.00) | — | | Total | 583 ($415.05 K) | 2.76 K ($1.85 M) | 20.57 K ($1.95 M) | $1.44 M | ## Risk summary ### Funds can be stolen if 1. the zk proof system is broken, allowing invalid spends or withdrawals. 2. the [trusted setup](https://l2beat.com/privacy/projects/privacy-boost#trusted-setups) is compromised or all ceremony participants collude, allowing invalid spends or withdrawals. 3. the admin multisig deploys a malicious [upgrade](https://l2beat.com/privacy/projects/privacy-boost#upgrades-and-governance) or registers a malicious verifying key. ### Funds can be lost if 1. a user loses their note secrets, or loses access to both the account-owner wallet and any usable authorization keys. ### Privacy can be lost if 1. the TEE is compromised. 2. a registered auditor fetches the user's balance and transaction history through the Audit API. 3. a user exits through a forced withdrawal, which publicly links the spent notes and the withdrawal address to the account that registered the approval key. ## Upgrades & Governance Privacy Boost is controlled by the 3/4 admin multisig, which can upgrade the pool, registries and AuditGateway without delay. It can replace all five proof verifiers and register or replace their verification keys, set withdrawal and portal sweep fees up to 10% each, configure portal minimum sweeps, and change the treasury, operator and gateway route manager. The external-call gateway owner manages target/selector policies, selects its guardian, and can pause or unpause execution. The guardian can pause and remove policies. Stranded gateway tokens can only be swept back to the pool while paused. ## Trusted setup Risk levels follow the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). Yellow (medium risk): all contributions are published and the final output can be verified, the ceremony client is open source, there were at least 30 contributions, participation was open to the public and announced, and participants are publicly identified. Green (lowest risk): everything required for yellow, with at least 150 contributions. Red (highest risk): at least one requirement for yellow is not met. N/A: the proof system needs no trusted setup. ### Privacy Boost v3 - Risk: red (highest risk) - Proof systems: Gnark (Groth16) Circuit-specific trusted setup for 12 Groth16 circuits of the Privacy Boost protocol over the BN254 curve, run by Sunnyside Labs as its third production round (`prod-ceremony-2026-03`, release `ceremony/v0.0.5`). Its keys were registered onchain on 23 September 2026 and replace the second round keys of the epoch (9 shapes, down from 13), forced withdrawal and gift claim circuits, which were recompiled with gnark v0.16.3 after the EdDSA signature check was rewritten. The deposit and portal deposit circuits keep their second round keys. It reuses the first 80 contributions of the public [Perpetual Powers of Tau](https://github.com/privacy-ethereum/perpetualpowersoftau) ceremony (`pot28_0080`) as Phase 1. Phase 2 is a gnark-native MPC ceremony. At the time of writing, the round record still marks the round as in preparation, and neither the public verification bundle nor the bundle digests have been published, so the number of participants and contributions could not be checked. - Phase 1 ceremony (first 80 contributions are used): . - Ceremony repository and contributor tooling: [https://github.com/sunnyside-io/privacy-boost-ceremony](https://github.com/sunnyside-io/privacy-boost-ceremony) - Round record: [rounds/2026-03.md](https://github.com/sunnyside-io/privacy-boost-ceremony/blob/26122120d04f04f0abe59a7119b9c9a12e7c209a/rounds/2026-03.md) - Contributor release: [ceremony/v0.0.5](https://github.com/sunnyside-io/privacy-boost-ceremony/releases/tag/ceremony%2Fv0.0.5) - Offline verification procedure: [https://github.com/sunnyside-io/privacy-boost-ceremony/blob/main/PUBLIC_VERIFICATION.md](https://github.com/sunnyside-io/privacy-boost-ceremony/blob/main/PUBLIC_VERIFICATION.md) ## Verifier IDs ### Privacy Boost epoch verifier, 9 circuits Verifies the batched private transfer and withdrawal proofs. The deployed verification keys have not yet been reproduced by L2BEAT. - Verifier ID: `Privacy Boost epoch verifier 23.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/5792c139b9529ed80643262d75b5489055be11b0/frontend/epoch_circuit.go - Verification: not verified - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0xB144eb785E2CCe17681395Cd475093C01AEeb11e](https://basescan.org/address/0xB144eb785E2CCe17681395Cd475093C01AEeb11e#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) ### Privacy Boost deposit verifier, 3 circuits Verifies the batched deposit epoch proofs. - Verifier ID: `Privacy Boost deposit verifier 09.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/9e3f34e1a91c20497bc7d8f47492761bc868843c/frontend/deposit_epoch_circuit.go - Verification: successful (verified by [L2BEAT](https://l2beat.com)) - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0xac60252EF8dbC139e0da63cE7F2a13D25a5B627d](https://basescan.org/address/0xac60252EF8dbC139e0da63cE7F2a13D25a5B627d#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) #### Verification steps The deposit verifier stores verification keys for 3 different batched deposit circuits across 3 registered batch sizes (`d1`, `d4`, `d14`). The steps below reproduce all 3 verification keys from circuit sources and trusted setup files. They require about 24 GiB RAM with two parallel workers and ~35 GiB disk space. Helper scripts implementing all of the reproduction steps are in the [script archive](https://trusted-setup-hosting.l2beat.com/privacy/privacy-boost/privacy_boost_vk_digest_v2.zip). 1. Download the second production ceremony public bundle (about 9.8 GB, gzip-compressed despite the `.tar` name) and extract it. The archive used for this attestation hashes to `91ad38d7775259116d00e5288630aaec565fbec8ff38a76dc874c13412ae530a`. ``` curl -LO https://file.ceremony.privacyboost.io/prod-20260902-public.tar shasum -a 256 prod-20260902-public.tar tar xzf prod-20260902-public.tar ``` 2. Check that the ceremony's circuit matrix in `public/config.snapshot.json` matches the circuit shapes registered on the verifier, and that the manifest's `circuitSpecJson` for each circuit agrees with them and with `circuit-setup/configs/production.ceremony.config.json` in [privacy-boost-ceremony](https://github.com/sunnyside-io/privacy-boost-ceremony) at commit `e645b68d`. 3. Re-derive every key from the transcript. The circuits are the `frontend/` package of [privacy-boost-protocol](https://github.com/sunnyside-io/privacy-boost-protocol) at commit `9e3f34e1a91c`. Note that the ceremony coordinator compiled them with **gnark v0.15.0 and gnark-crypto v0.20.1**, as recorded in the build information embedded in the signed `ceremony/v0.0.x` release binaries. The public ceremony repository pins gnark v0.14.0 instead, which compiles to different constraint systems, so its `verify-public` command fails at the R1CS hash check. The script archive contains a per-circuit helper built against gnark v0.15.0 that recompiles each circuit's R1CS from its spec, checks it against the manifest, fetches and digest-checks the pinned Perpetual Powers of Tau artifact for the required power, recomputes the origin of the phase 2 transcript, verifies every contribution against its predecessor, and seals the proving and verifying keys, comparing them to the manifest commitments. ``` python3 run.py prepare python3 onchain.py python3 run.py run --jobs 2 ``` 4. For each circuit, encode the re-derived `.vk` into the onchain layout (negate `beta`, `gamma`, `delta`; interleave `G1.K`) and confirm its digest equals the value read from chain. The helper reads all registered keys at one finalized OP Mainnet block (equivalent to the Base deployment), recomputing the storage slots from the circuit parameters and cross-checking them against the getters. ### Privacy Boost forced withdrawal verifier, 1 circuit Verifies the client-side forced withdrawal proofs. The deployed verification keys have not yet been reproduced by L2BEAT. - Verifier ID: `Privacy Boost forced withdrawal verifier 23.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/5792c139b9529ed80643262d75b5489055be11b0/frontend/forced_withdraw_circuit.go - Verification: not verified - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0x40e93d3357A5A3d249437717Da936f6141ba85cE](https://basescan.org/address/0x40e93d3357A5A3d249437717Da936f6141ba85cE#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) ### Privacy Boost portal deposit verifier, 2 circuits Verifies the batched hidden-recipient portal deposit proofs. - Verifier ID: `Privacy Boost portal deposit verifier 09.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/9e3f34e1a91c20497bc7d8f47492761bc868843c/frontend/deposit_portal_circuit.go - Verification: successful (verified by [L2BEAT](https://l2beat.com)) - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0x0c8bb018a3d8DF4c5fC86518ca57F8E1445BCF63](https://basescan.org/address/0x0c8bb018a3d8DF4c5fC86518ca57F8E1445BCF63#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) #### Verification steps The portal deposit verifier stores verification keys for 2 different batched portal deposit circuits across 2 registered batch sizes (`p1`, `p6`). The steps below reproduce both verification keys from circuit sources and trusted setup files. They require about 24 GiB RAM with two parallel workers and ~35 GiB disk space. Helper scripts implementing all of the reproduction steps are in the [script archive](https://trusted-setup-hosting.l2beat.com/privacy/privacy-boost/privacy_boost_vk_digest_v2.zip). 1. Download the second production ceremony public bundle (about 9.8 GB, gzip-compressed despite the `.tar` name) and extract it. The archive used for this attestation hashes to `91ad38d7775259116d00e5288630aaec565fbec8ff38a76dc874c13412ae530a`. ``` curl -LO https://file.ceremony.privacyboost.io/prod-20260902-public.tar shasum -a 256 prod-20260902-public.tar tar xzf prod-20260902-public.tar ``` 2. Check that the ceremony's circuit matrix in `public/config.snapshot.json` matches the circuit shapes registered on the verifier, and that the manifest's `circuitSpecJson` for each circuit agrees with them and with `circuit-setup/configs/production.ceremony.config.json` in [privacy-boost-ceremony](https://github.com/sunnyside-io/privacy-boost-ceremony) at commit `e645b68d`. 3. Re-derive every key from the transcript. The circuits are the `frontend/` package of [privacy-boost-protocol](https://github.com/sunnyside-io/privacy-boost-protocol) at commit `9e3f34e1a91c`. Note that the ceremony coordinator compiled them with **gnark v0.15.0 and gnark-crypto v0.20.1**, as recorded in the build information embedded in the signed `ceremony/v0.0.x` release binaries. The public ceremony repository pins gnark v0.14.0 instead, which compiles to different constraint systems, so its `verify-public` command fails at the R1CS hash check. The script archive contains a per-circuit helper built against gnark v0.15.0 that recompiles each circuit's R1CS from its spec, checks it against the manifest, fetches and digest-checks the pinned Perpetual Powers of Tau artifact for the required power, recomputes the origin of the phase 2 transcript, verifies every contribution against its predecessor, and seals the proving and verifying keys, comparing them to the manifest commitments. Reading the transcript lazily keeps the peak below 10 GB per circuit. ``` python3 run.py prepare python3 onchain.py python3 run.py run --jobs 2 ``` 4. For each circuit, encode the re-derived `.vk` into the onchain layout (negate `beta`, `gamma`, `delta`; interleave `G1.K`) and confirm its digest equals the value read from chain. The helper reads all registered keys at one finalized OP Mainnet block (equivalent to the Base deployment), recomputing the storage slots from the circuit parameters and cross-checking them against the getters. ### Privacy Boost gift claim verifier, 2 circuits Verifies the batched gift claim, refund and public gift exit proofs. The deployed verification keys have not yet been reproduced by L2BEAT. - Verifier ID: `Privacy Boost gift claim verifier 23.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/5792c139b9529ed80643262d75b5489055be11b0/frontend/gift_claim_circuit.go - Verification: not verified - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0x8f394a08A7544daf39aF38FEA5B2E348180bDC05](https://basescan.org/address/0x8f394a08A7544daf39aF38FEA5B2E348180bDC05#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) ## Updates Each date links the update on the HTML page, which also shows its contract diffs. ### [2026-10-01 10:55 UTC](https://l2beat.com/privacy/projects/privacy-boost?update=4a45e933) (18 changes) Switched privacy boost discovery to base from op mainnet. ### [2026-09-28 14:00 UTC](https://l2beat.com/privacy/projects/privacy-boost?update=7e3ac8d8) (high severity, 18 changes) Redeployed identical PrivacyBoost implementation (https://disco.l2beat.com/diff/oeth:0x9CB144D35748932EC44950d0837248fcF8747828/oeth:0x319785d27Bd9889248804FA803FAC3e58D9ca002) together with redeploying three verifiers (Groth16EpochVerifier, Groth16ForcedVerifier and Groth16GiftClaimVerifier). These three verifiers have different verification keys because forced withdrawal and gift claim circuits were recompiled with gnark v0.16.3 after the EdDSA signature check was rewritten to a double-base scalar multiplication ([PR #10](https://github.com/sunnyside-io/privacy-boost-protocol/pull/10)) and some circuit shapes are no longer supported. New circuits also introduce a new trusted setup. Trusted setup artifacts are not yet published so the verification keys could not be regenerated. ### [2026-09-15 09:31 UTC](https://l2beat.com/privacy/projects/privacy-boost?update=b6c9f26f) (4 changes) Added a new member to the admin ms: 2/3 -> 3/4. ### [2026-09-07 13:21 UTC](https://l2beat.com/privacy/projects/privacy-boost?update=19595947) (high severity, 100 changes) Feature upgrade: replaces PrivacyBoost/AuthRegistry logic and all three verifiers, adds portal and gift features + verifiers, an external-call gateway, and expands the token registry to 11 assets. Auth snapshots are **removed**. New keys remain unverified because the trusted setup records are not yet published. external call gateway: whitelisted defi interactions portal: reusable recipient addresses gift: claim to a custom address (private or public) using a 'gift note' AuthRegistry: https://disco.l2beat.com/diff/oeth:0xcCdF755866c708A4a8D0002DC3f1a574226DF38b/oeth:0xA2072F7B4b261F997035f9522648c7c5bAF9370a TokenRegistry: https://disco.l2beat.com/diff/oeth:0x238e6ec4968c9b00b16293139951c23815Ca1134/oeth:0x86A891632594Ae26834275925Eb4Fde37F1eBb19 AuditGateway: https://disco.l2beat.com/diff/oeth:0xfEfb6bD314680BDbc1B00FE2eA5A038655Bb4478/oeth:0x384D1460107D88b1a21CA202825583c19cb6A808 PrivacyBoost: https://disco.l2beat.com/diff/oeth:0x0b9B98d3B95D74487C481e7830ab440896aE62E5/oeth:0x9CB144D35748932EC44950d0837248fcF8747828 ### [2026-08-21 08:53 UTC](https://l2beat.com/privacy/projects/privacy-boost?update=16a592bd) (14 changes) Initial discovery of privacy boost. ## Permissions Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/privacy-boost ### Base Chain #### Actors ##### OperatorMultisig Addresses: [0x420A8a682892bae85cba7fb0e5Cd806807C5Bf95](https://basescan.org/address/0x420A8a682892bae85cba7fb0e5Cd806807C5Bf95) A Multisig with 2/3 threshold. - Can interact with ExternalCallGateway - pause the gateway and remove external call policies - Can interact with AuthRegistry - manage the allowlist of relays that can submit key operations to the AuthRegistry on behalf of users - Can interact with PrivacyBoost - approve or revoke external gateway routes used by proof-authorized withdrawals - manage the allowlist of relays that submit epochs to the pool Participants (3): [0x769ef261964f1eDe0a554b74e9bB900d3Fb4AF1E](https://basescan.org/address/0x769ef261964f1eDe0a554b74e9bB900d3Fb4AF1E), [0x90d3EbF1bbE3075F41772bB6f0A54e6038C84244](https://basescan.org/address/0x90d3EbF1bbE3075F41772bB6f0A54e6038C84244), [0xfEa8d7D07365a1A429319EF7A7a265CB4F530237](https://basescan.org/address/0xfEa8d7D07365a1A429319EF7A7a265CB4F530237) ##### AdminMultisig Addresses: [0x78DFf7F33E3d5edD68D13D6d1fE23078062866f7](https://basescan.org/address/0x78DFf7F33E3d5edD68D13D6d1fE23078062866f7) A Multisig with 3/4 threshold. - Can upgrade **with no delay** - TokenRegistry [via: TokenRegistryProxyAdmin] - AuthRegistry [via: AuthRegistryProxyAdmin] - PrivacyBoost [via: PrivacyBoostProxyAdmin] - AuditGateway [via: AuditGatewayProxyAdmin] - Can interact with ExternalCallGateway - set the guardian, install or remove external call policies, pause or unpause the gateway, and sweep stranded tokens back to the pool while paused - Can interact with Groth16PortalDepositVerifier - register and replace the Groth16 verification keys used to validate portal deposit epoch proofs - Can interact with TokenRegistry - register new ERC-20 tokens to be accepted by the PrivacyBoost pool - Can interact with Groth16ForcedVerifier - register and replace the Groth16 verification keys used to validate forced withdrawal proofs - Can interact with AuthRegistry - set the operator address of the AuthRegistry - Can interact with PrivacyBoost - replace all five proof verifiers, set withdrawal and portal sweep fees (each up to 10%), set token-specific portal minimum sweeps, and change the treasury, operator and gateway route manager - Can interact with AuditGateway - manage the list of registered auditors and set the auditLogger address of the AuditGateway - Can interact with Groth16GiftClaimVerifier - register and replace the Groth16 verification keys used to validate gift settlement and public gift exit proofs - Can interact with Groth16DepositVerifier - register and replace the Groth16 verification keys used to validate deposit epoch proofs - Can interact with Groth16EpochVerifier - register and replace the Groth16 verification keys used to validate epoch proofs Participants (4): [0xcf01AB4fa0C5796811Ad939daB8dEd833cf90683](https://basescan.org/address/0xcf01AB4fa0C5796811Ad939daB8dEd833cf90683), [0x769ef261964f1eDe0a554b74e9bB900d3Fb4AF1E](https://basescan.org/address/0x769ef261964f1eDe0a554b74e9bB900d3Fb4AF1E), [0xB30347E816B525453468cC95C17231Ab04a0C0A9](https://basescan.org/address/0xB30347E816B525453468cC95C17231Ab04a0C0A9), [0xfEa8d7D07365a1A429319EF7A7a265CB4F530237](https://basescan.org/address/0xfEa8d7D07365a1A429319EF7A7a265CB4F530237) ##### TreasuryMultisig Addresses: [0x04484B6065A43fa286e05E9C28a6c4Db77d917f8](https://basescan.org/address/0x04484B6065A43fa286e05E9C28a6c4Db77d917f8) A Multisig with 2/3 threshold. Participants (3): [0x769ef261964f1eDe0a554b74e9bB900d3Fb4AF1E](https://basescan.org/address/0x769ef261964f1eDe0a554b74e9bB900d3Fb4AF1E), [0x90d3EbF1bbE3075F41772bB6f0A54e6038C84244](https://basescan.org/address/0x90d3EbF1bbE3075F41772bB6f0A54e6038C84244), [0xfEa8d7D07365a1A429319EF7A7a265CB4F530237](https://basescan.org/address/0xfEa8d7D07365a1A429319EF7A7a265CB4F530237) ##### EOA 1 Addresses: [0x6Bd37032571F47e50f312542ae05D548B69DC9B0](https://basescan.org/address/0x6Bd37032571F47e50f312542ae05D548B69DC9B0) - Can interact with AuthRegistry - submit account key registrations, rotations and revocations with valid owner signatures - Can interact with PrivacyBoost - submit private transfer, withdrawal, deposit, portal deposit and gift settlement epochs with validity proofs, and simulate gateway withdrawals ##### EOA 2 Addresses: [0xE7F9E649b5406bf0751EA242CAc712151e1c73eB](https://basescan.org/address/0xE7F9E649b5406bf0751EA242CAc712151e1c73eB) - Can interact with AuditGateway - log audit queries performed by registered auditors on the AuditGateway ## Smart contracts Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/privacy-boost ### Base Chain #### ExternalCallGateway Addresses: [0x02Eb6E5779f5780A5ABB354341962d9312b7ABe6](https://basescan.org/address/0x02Eb6E5779f5780A5ABB354341962d9312b7ABe6#code) Gateway executing pool-authorized external calls against an allowlist of target addresses and function selectors, with optional input/output token constraints. Enforces proof-bound settlement receipts and redeposits returned funds into the pool. - Roles: - **guardian**: OperatorMultisig - **owner**: AdminMultisig #### Groth16PortalDepositVerifier Addresses: [0x0c8bb018a3d8DF4c5fC86518ca57F8E1445BCF63](https://basescan.org/address/0x0c8bb018a3d8DF4c5fC86518ca57F8E1445BCF63#code) Groth16 verifier for PrivacyBoost portal deposit epoch proofs. Verification keys are stored in SSTORE2 data contracts. - Roles: - **owner**: AdminMultisig #### AuthRegistryProxyAdmin Addresses: [0x321e0edAb1b628aEF03DBe19CC9C7dAB844f84bc](https://basescan.org/address/0x321e0edAb1b628aEF03DBe19CC9C7dAB844f84bc#code) Admin contract of the AuthRegistry proxy. - Roles: - **owner**: AdminMultisig #### TokenRegistryProxyAdmin Addresses: [0x32b0998c86d33b1b6898F486dC78D80FaA27095f](https://basescan.org/address/0x32b0998c86d33b1b6898F486dC78D80FaA27095f#code) Admin contract of the TokenRegistry proxy. - Roles: - **owner**: AdminMultisig #### TokenRegistry Addresses: [0x3A0bea3a715881793cFD698dDEBcF03784f0bE03](https://basescan.org/address/0x3A0bea3a715881793cFD698dDEBcF03784f0bE03#code), [0x2D90FB53C5194E2Dd9a3dc4D4Cf71253799e555E](https://basescan.org/address/0x2D90FB53C5194E2Dd9a3dc4D4Cf71253799e555E#code) (Implementation (Upgradable)), [0x32b0998c86d33b1b6898F486dC78D80FaA27095f](https://basescan.org/address/0x32b0998c86d33b1b6898F486dC78D80FaA27095f#code) (Admin) **Past upgrades** (Count of upgrades: No upgrades, Last upgrade: N/A, Avg upgrade interval: N/A) - 2026-09-02 19:24 UTC, deployment of [TokenRegistry](https://basescan.org/address/0x3A0bea3a715881793cFD698dDEBcF03784f0bE03#code): transaction [0x9a59d1b1a8f3dadc2f78b3741ac3b477bc00f039fd22c45a1da9ce0e1488b2a1](https://basescan.org/tx/0x9a59d1b1a8f3dadc2f78b3741ac3b477bc00f039fd22c45a1da9ce0e1488b2a1), implementations: [0x2D90FB53C5194E2Dd9a3dc4D4Cf71253799e555E](https://basescan.org/address/0x2D90FB53C5194E2Dd9a3dc4D4Cf71253799e555E#code) Registry mapping compact token IDs to the ERC-20 tokens accepted by the PrivacyBoost pool. - Roles: - **admin**: TokenRegistryProxyAdmin; ultimately AdminMultisig - **owner**: AdminMultisig Can be upgraded by: AdminMultisig with no delay #### Groth16ForcedVerifier Addresses: [0x40e93d3357A5A3d249437717Da936f6141ba85cE](https://basescan.org/address/0x40e93d3357A5A3d249437717Da936f6141ba85cE#code) Groth16 verifier for PrivacyBoost forced withdrawal proofs. Verification keys are stored in SSTORE2 data contracts. - Roles: - **owner**: AdminMultisig #### AuthRegistry Addresses: [0x4daC7dA2c8cA097B3e0FF42aBFCebd2833196eB3](https://basescan.org/address/0x4daC7dA2c8cA097B3e0FF42aBFCebd2833196eB3#code), [0xECBB712DC58156228187587783286B0662Bc06da](https://basescan.org/address/0xECBB712DC58156228187587783286B0662Bc06da#code) (Implementation (Upgradable)), [0x321e0edAb1b628aEF03DBe19CC9C7dAB844f84bc](https://basescan.org/address/0x321e0edAb1b628aEF03DBe19CC9C7dAB844f84bc#code) (Admin) **Past upgrades** (Count of upgrades: No upgrades, Last upgrade: N/A, Avg upgrade interval: N/A) - 2026-09-02 19:24 UTC, deployment of [AuthRegistry](https://basescan.org/address/0x4daC7dA2c8cA097B3e0FF42aBFCebd2833196eB3#code): transaction [0xbc1b2d84d7c1c8379f51ad1b4dfb79891b544ab497bae54485badd192dd7b7a7](https://basescan.org/tx/0xbc1b2d84d7c1c8379f51ad1b4dfb79891b544ab497bae54485badd192dd7b7a7), implementations: [0xECBB712DC58156228187587783286B0662Bc06da](https://basescan.org/address/0xECBB712DC58156228187587783286B0662Bc06da#code) Registry of PrivacyBoost account authorization keys and onchain spend approvals. Supports BabyJubJub keys authorized by account-owner signatures, approval-only accounts and revocable batches of spend approvals. Tracks current and recently superseded auth roots; forced withdrawals validate live auth records directly. - Roles: - **admin**: AuthRegistryProxyAdmin; ultimately AdminMultisig - **allowedRelays**: EOA 1 - **operator**: OperatorMultisig - **owner**: AdminMultisig Can be upgraded by: AdminMultisig with no delay #### PrivacyBoost Addresses: [0x71A0fD3C76E3E937d8275A3cb6a467b70123bD40](https://basescan.org/address/0x71A0fD3C76E3E937d8275A3cb6a467b70123bD40#code), [0x508798455053B0b8BF892454a2A73d88891d9fFd](https://basescan.org/address/0x508798455053B0b8BF892454a2A73d88891d9fFd#code) (Implementation (Upgradable)), [0xd4C0599a5d9A2CcA46Ee05a03405B3ad3407b15e](https://basescan.org/address/0xd4C0599a5d9A2CcA46Ee05a03405B3ad3407b15e#code) (Admin) **Past upgrades** (Count of upgrades: 1, Last upgrade: 10d 1h ago, Avg upgrade interval: 15d 14h) - 2026-09-23 22:24 UTC, upgrade of [PrivacyBoost](https://basescan.org/address/0x71A0fD3C76E3E937d8275A3cb6a467b70123bD40#code): transaction [0x016cebde28f09c82a06bdf92d6bbb4631e39767d8ec96c337f1e1eb478324af6](https://basescan.org/tx/0x016cebde28f09c82a06bdf92d6bbb4631e39767d8ec96c337f1e1eb478324af6), implementations: [0x508798455053B0b8BF892454a2A73d88891d9fFd](https://basescan.org/address/0x508798455053B0b8BF892454a2A73d88891d9fFd#code) ([diff](https://disco.l2beat.com/diff/base:0x2944dB0B9500c3F82Af6b231ff83cf4c5B8f5037/base:0x508798455053B0b8BF892454a2A73d88891d9fFd)) - 2026-09-02 19:37 UTC, deployment of [PrivacyBoost](https://basescan.org/address/0x71A0fD3C76E3E937d8275A3cb6a467b70123bD40#code): transaction [0xb57d5d9d8b938eb5567222a01bbddfba9b327ffe0b5219fdb7a410f1f4c006fd](https://basescan.org/tx/0xb57d5d9d8b938eb5567222a01bbddfba9b327ffe0b5219fdb7a410f1f4c006fd), implementations: [0x2944dB0B9500c3F82Af6b231ff83cf4c5B8f5037](https://basescan.org/address/0x2944dB0B9500c3F82Af6b231ff83cf4c5B8f5037#code) Main contract of the PrivacyBoost pool. Escrows ERC-20 tokens and verifies relay-submitted private transfer, withdrawal, deposit, portal deposit and gift settlement proofs. Supports approved external gateway calls and permissionless exits through delayed forced withdrawals or public gift exits. - Roles: - **admin**: PrivacyBoostProxyAdmin; ultimately AdminMultisig - **allowedRelays**: EOA 1 - **gatewayRouteManager**: OperatorMultisig - **operator**: OperatorMultisig - **owner**: AdminMultisig Can be upgraded by: AdminMultisig with no delay #### AuditGateway Addresses: [0x7Bb891f7D7c78A8d6770cb273aBC603A148824b6](https://basescan.org/address/0x7Bb891f7D7c78A8d6770cb273aBC603A148824b6#code), [0x27776Ed100A4D1C6e1479319BE6eB2e262F7CEc4](https://basescan.org/address/0x27776Ed100A4D1C6e1479319BE6eB2e262F7CEc4#code) (Implementation (Upgradable)), [0xB32ef2884794999e1E260a3f68368A24CEF25b35](https://basescan.org/address/0xB32ef2884794999e1E260a3f68368A24CEF25b35#code) (Admin) **Past upgrades** (Count of upgrades: No upgrades, Last upgrade: N/A, Avg upgrade interval: N/A) - 2026-09-02 19:37 UTC, deployment of [AuditGateway](https://basescan.org/address/0x7Bb891f7D7c78A8d6770cb273aBC603A148824b6#code): transaction [0xcd03e41021bbf07f85cf52f45650313df42320ba0e64e9b439d8ba5a7b5b514a](https://basescan.org/tx/0xcd03e41021bbf07f85cf52f45650313df42320ba0e64e9b439d8ba5a7b5b514a), implementations: [0x27776Ed100A4D1C6e1479319BE6eB2e262F7CEc4](https://basescan.org/address/0x27776Ed100A4D1C6e1479319BE6eB2e262F7CEc4#code) Manages the list of auditors authorized to query private user data through the Audit API of the TEE, and stores an onchain log of every audit access so that users can publicly verify whether and when their private data was disclosed. - Roles: - **admin**: AuditGatewayProxyAdmin; ultimately AdminMultisig - **auditLogger**: EOA 2 - **owner**: AdminMultisig Can be upgraded by: AdminMultisig with no delay #### AuthPoseidon Addresses: [0x8b72188D4A15661E0a3D232ACecCA7A26757C42D](https://basescan.org/address/0x8b72188D4A15661E0a3D232ACecCA7A26757C42D#code) Poseidon2 hashing helper used by AuthRegistry to compute account IDs, authorization leaves, spend approval commitments and Merkle tree nodes. #### Groth16GiftClaimVerifier Addresses: [0x8f394a08A7544daf39aF38FEA5B2E348180bDC05](https://basescan.org/address/0x8f394a08A7544daf39aF38FEA5B2E348180bDC05#code) Groth16 verifier for PrivacyBoost gift settlement and public gift exit proofs. Verification keys are stored in SSTORE2 data contracts. - Roles: - **owner**: AdminMultisig #### Groth16DepositVerifier Addresses: [0xac60252EF8dbC139e0da63cE7F2a13D25a5B627d](https://basescan.org/address/0xac60252EF8dbC139e0da63cE7F2a13D25a5B627d#code) Groth16 verifier for PrivacyBoost deposit epoch proofs. Verification keys are stored in SSTORE2 data contracts. - Roles: - **owner**: AdminMultisig #### Groth16EpochVerifier Addresses: [0xB144eb785E2CCe17681395Cd475093C01AEeb11e](https://basescan.org/address/0xB144eb785E2CCe17681395Cd475093C01AEeb11e#code) Groth16 verifier for PrivacyBoost private transfer and withdrawal epochs. Keys are indexed by (max transfers, inputs per transfer, outputs per transfer). The nested key registry is not enumerable and emits no registration events; discovery monitors the reviewed production circuit configurations. - Roles: - **owner**: AdminMultisig #### AuditGatewayProxyAdmin Addresses: [0xB32ef2884794999e1E260a3f68368A24CEF25b35](https://basescan.org/address/0xB32ef2884794999e1E260a3f68368A24CEF25b35#code) Admin contract of the AuditGateway proxy. - Roles: - **owner**: AdminMultisig #### PrivacyBoostProxyAdmin Addresses: [0xd4C0599a5d9A2CcA46Ee05a03405B3ad3407b15e](https://basescan.org/address/0xd4C0599a5d9A2CcA46Ee05a03405B3ad3407b15e#code) Admin contract of the PrivacyBoost proxy. - Roles: - **owner**: AdminMultisig