# INTMAX Markdown version of https://l2beat.com/zk-catalog/intmaxprover ## Summary - Creator: INTMAX - Total Value Secured: $134.17 K (-6.31% compared to seven days ago) - Trusted setups for Gnark (Plonk): - Aztec Ignition, risk green (lowest risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Aztec Ignition is a trusted setup ceremony that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Used in: [INTMAX](https://l2beat.com/layer2s/projects/intmax) - Verifiers: 1 not verified - zkVM: Plonky2 (Plonk), Goldilocks (Field), App-specific circuits (Other) - Final wrap: Gnark (Plonk), BN254 (curve) ### About A zk proving system designed by INTMAX for client-side proving of private token transfers on INTMAX L2. ### Links - Website: https://intmax.io - Docs: https://intmax-wallet.gitbook.io/intmax-developers-hub/nodes/provers, https://eprint.iacr.org/2023/1082.pdf - Repository: https://github.com/InternetMaximalism/intmax2-zkp ## Value Secured The interactive TVS chart is shown on [the HTML page](https://l2beat.com/zk-catalog/intmaxprover#tvs). ## Proof System ### Description INTMAX prover is a zk proving system for privacy-preserving INTMAX L2 based on [Plonky2](https://github.com/0xPolygonZero/plonky2/tree/main) circuits, optimized for client side proving and using not only succinctness, but also zero knowledge properties of Plonky2. INTMAX circuits are proven with a STARK which is wrapped into a Plonk SNARK before settling onchain. ### Proof system Plonky2 implements a circuit aritmetization based on TurboPlonk over Goldilocks field, but it replaces KZG polynomial commitment scheme with a FRI-based polynomial testing scheme. In this way proving Plonky2 circuits requires no trusted setup, i.e. it is a STARK. However the circuit design is different from zkVM STARKs, so INTMAX custom logic is implemented as custom circuits rather than a zkVM program. #### Circuits INTMAX prover works with [several different circuits](https://github.com/InternetMaximalism/intmax2-zkp/blob/main/README.md) that could be proven by different entities in the network (e.g. [users, validity provers, aggregators](https://docs.network.intmax.io/developers-hub/intmax-nodes/provers)). This design support local proving and enables private transactions on the L2. Available circuits are: [validity](https://github.com/InternetMaximalism/intmax2-zkp/tree/main/src/circuits/validity) for proving public state transition, [balance](https://github.com/InternetMaximalism/intmax2-zkp/tree/main/src/circuits/balance) for proving correct updates of individual user accounts based on private information, [withdrawal](https://github.com/InternetMaximalism/intmax2-zkp/tree/main/src/circuits/withdrawal) for proving the validity of withdrawing funds from L2 to the host chain, [claim](https://github.com/InternetMaximalism/intmax2-zkp/tree/main/src/circuits/claim) for proving user eligibility for privacy mining program and [proof of innocence](https://github.com/InternetMaximalism/intmax2-zkp/tree/main/src/circuits/proof_of_innocence) for proving certain claims about deposits and withdrawals. #### Recursion and final wrap INTMAX circuits are based on recursive architecture, where generating a new STARK requires validating a previous STARK proof (e.g. processing a new balance update requires validating all previous balance updates). Several entities are responsible for providing these recursive proofs: users or [balance provers](https://docs.network.intmax.io/developers-hub/intmax-nodes/provers#balance-prover) for balance updates, [validity provers](https://docs.network.intmax.io/developers-hub/intmax-nodes/validity-prover) for validity circuit, [claim](https://docs.network.intmax.io/developers-hub/intmax-nodes/claim-aggregator) and [withdrawal](https://docs.network.intmax.io/developers-hub/intmax-nodes/withdrawal-aggregator) aggregators for processing claim and withdrawal proofs. Only claim and withdrawal proofs are posted onchain to be verified, all other proofs are verified only by the nodes in INTMAX network. Onchain proofs are wrapped in a [gnark](https://github.com/Consensys/gnark) implementation of Plonk over BN254 curve, which requires a trusted setup (see [below](https://l2beat.com/zk-catalog/intmaxprover#trusted-setups) for more details). ## Trusted Setups Risk levels follow the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). Yellow (medium risk): all contributions are published and the final output can be verified, the ceremony client is open source, there were at least 30 contributions, participation was open to the public and announced, and participants are publicly identified. Green (lowest risk): everything required for yellow, with at least 150 contributions. Red (highest risk): at least one requirement for yellow is not met. N/A: the proof system needs no trusted setup. ### Aztec Ignition - Risk: green (lowest risk) - Proof systems: Gnark (Plonk) Aztec Ignition is a trusted setup ceremony for KZG commitments over BN254 curve that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Github repo to download and verify the ceremony artifacts: [https://github.com/AztecProtocol/ignition-verification](https://github.com/AztecProtocol/ignition-verification). - Github repo with instructions for ceremony participants: [https://github.com/AztecProtocol/Setup](https://github.com/AztecProtocol/Setup). - Ceremony announcement with a call to participate: [https://aztec.network/blog/announcing-ignition](https://aztec.network/blog/announcing-ignition). ## Verifier IDs List of different onchain verifiers for this proving system. Unique ID distinguishes different deployments of the same verifier from different verifiers (e.g. different versions). ### Plonk: Gnark Consensys implementation of Plonk proving system written in Go. #### Intmax verifier Custom verifier ID: SHA256 hash of all VK_... values from the smart contract, abi packed in the same order they are defined. - Verifier ID: `0x664dceea25b57766a5b550cf25cca24a7305f36fd60a5835f9e0505bec14ce8e` - Source: https://github.com/InternetMaximalism/intmax2-zkp - Verification: not verified - Used in: [INTMAX](https://l2beat.com/layer2s/projects/intmax) **Known deployments** - [0x1d38545a33740Ab3480d9035bB3126914404423d](https://scrollscan.com/address/0x1d38545a33740Ab3480d9035bB3126914404423d#code) on Scroll, used in: [INTMAX](https://l2beat.com/layer2s/projects/intmax)