# Privacy Boost Markdown version of https://l2beat.com/zk-catalog/privacy-boost ## Summary - Creator: Sunnyside Labs - Total Value Secured: $1.44 M (+0.06% compared to seven days ago) - Trusted setups for Gnark (Groth16): - Privacy Boost v3, risk red (highest risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Circuit-specific trusted setup for the 12 Groth16 Privacy Boost epoch, forced withdrawal and gift claim circuits deployed in late September 2026. It was built on top of 80 Perpetual Powers of Tau phase 1 contributions, with a publicly announced phase 2 whose transcript and participant list have not yet been published. The proving system could be broken if either phase 1 or 2 is compromised. - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) - Verifiers: 2 successful (verified by [L2BEAT](https://l2beat.com)), 3 not verified - zkVM: BN254 (curve), Gnark (Groth16), R1CS (Arithmetization), App-specific circuits (Other) ### About A shielded pool for ERC-20 tokens on Base, designed for institutional users. Provides TEE-backed privacy, balancing better UX with worse privacy trust assumptions. ### Links - Website: https://www.privacyboost.io/ - Docs: https://docs.privacyboost.io/ - Repository: https://github.com/sunnyside-io/privacy-boost-protocol, https://github.com/sunnyside-io/privacy-boost-ceremony ## Value Secured The interactive TVS chart is shown on [the HTML page](https://l2beat.com/zk-catalog/privacy-boost#tvs). ## Proof System Privacy Boost uses **Groth16 over BN254**, with circuits written in Go against the [gnark](https://github.com/Consensys/gnark) R1CS frontend. There is no recursive proof aggregation; batching happens inside each circuit. There are five verifier families: - **Epoch**: private transfers, withdrawals and gateway withdrawals; 9 reviewed configurations. - **Deposit epoch**: standard deposit batches of 1, 4 or 14. - **Portal deposit epoch**: hidden-recipient portal deposit batches of 1 or 6. - **Forced withdrawal**: a permissionless delayed exit spending up to 13 notes, using a live auth key or spend approval checked at request time. - **Gift claim**: private gift claims/refunds and public gift exits, with registered batch sizes 1 and 3. For each of the verifier contracts, different configurations can be allowed with the according verifier keys. There are 17 verifier keys currently registered (9 epoch + 3 deposit + 2 portal + 1 forced withdrawal + 2 gift). ## Trusted Setups Risk levels follow the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). Yellow (medium risk): all contributions are published and the final output can be verified, the ceremony client is open source, there were at least 30 contributions, participation was open to the public and announced, and participants are publicly identified. Green (lowest risk): everything required for yellow, with at least 150 contributions. Red (highest risk): at least one requirement for yellow is not met. N/A: the proof system needs no trusted setup. ### Privacy Boost v3 - Risk: red (highest risk) - Proof systems: Gnark (Groth16) Circuit-specific trusted setup for 12 Groth16 circuits of the Privacy Boost protocol over the BN254 curve, run by Sunnyside Labs as its third production round (`prod-ceremony-2026-03`, release `ceremony/v0.0.5`). Its keys were registered onchain on 23 September 2026 and replace the second round keys of the epoch (9 shapes, down from 13), forced withdrawal and gift claim circuits, which were recompiled with gnark v0.16.3 after the EdDSA signature check was rewritten. The deposit and portal deposit circuits keep their second round keys. It reuses the first 80 contributions of the public [Perpetual Powers of Tau](https://github.com/privacy-ethereum/perpetualpowersoftau) ceremony (`pot28_0080`) as Phase 1. Phase 2 is a gnark-native MPC ceremony. At the time of writing, the round record still marks the round as in preparation, and neither the public verification bundle nor the bundle digests have been published, so the number of participants and contributions could not be checked. - Phase 1 ceremony (first 80 contributions are used): . - Ceremony repository and contributor tooling: [https://github.com/sunnyside-io/privacy-boost-ceremony](https://github.com/sunnyside-io/privacy-boost-ceremony) - Round record: [rounds/2026-03.md](https://github.com/sunnyside-io/privacy-boost-ceremony/blob/26122120d04f04f0abe59a7119b9c9a12e7c209a/rounds/2026-03.md) - Contributor release: [ceremony/v0.0.5](https://github.com/sunnyside-io/privacy-boost-ceremony/releases/tag/ceremony%2Fv0.0.5) - Offline verification procedure: [https://github.com/sunnyside-io/privacy-boost-ceremony/blob/main/PUBLIC_VERIFICATION.md](https://github.com/sunnyside-io/privacy-boost-ceremony/blob/main/PUBLIC_VERIFICATION.md) ## Verifier IDs List of different onchain verifiers for this proving system. Unique ID distinguishes different deployments of the same verifier from different verifiers (e.g. different versions). ### Groth16: Gnark Consensys implementation of Groth16 proving system written in Go. #### Privacy Boost epoch verifier, 9 circuits Verifies the batched private transfer and withdrawal proofs. The deployed verification keys have not yet been reproduced by L2BEAT. - Verifier ID: `Privacy Boost epoch verifier 23.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/5792c139b9529ed80643262d75b5489055be11b0/frontend/epoch_circuit.go - Verification: not verified - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0xB144eb785E2CCe17681395Cd475093C01AEeb11e](https://basescan.org/address/0xB144eb785E2CCe17681395Cd475093C01AEeb11e#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) #### Privacy Boost deposit verifier, 3 circuits Verifies the batched deposit epoch proofs. - Verifier ID: `Privacy Boost deposit verifier 09.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/9e3f34e1a91c20497bc7d8f47492761bc868843c/frontend/deposit_epoch_circuit.go - Verification: successful (verified by [L2BEAT](https://l2beat.com)) - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0xac60252EF8dbC139e0da63cE7F2a13D25a5B627d](https://basescan.org/address/0xac60252EF8dbC139e0da63cE7F2a13D25a5B627d#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) ##### Verification steps The deposit verifier stores verification keys for 3 different batched deposit circuits across 3 registered batch sizes (`d1`, `d4`, `d14`). The steps below reproduce all 3 verification keys from circuit sources and trusted setup files. They require about 24 GiB RAM with two parallel workers and ~35 GiB disk space. Helper scripts implementing all of the reproduction steps are in the [script archive](https://trusted-setup-hosting.l2beat.com/privacy/privacy-boost/privacy_boost_vk_digest_v2.zip). 1. Download the second production ceremony public bundle (about 9.8 GB, gzip-compressed despite the `.tar` name) and extract it. The archive used for this attestation hashes to `91ad38d7775259116d00e5288630aaec565fbec8ff38a76dc874c13412ae530a`. ``` curl -LO https://file.ceremony.privacyboost.io/prod-20260902-public.tar shasum -a 256 prod-20260902-public.tar tar xzf prod-20260902-public.tar ``` 2. Check that the ceremony's circuit matrix in `public/config.snapshot.json` matches the circuit shapes registered on the verifier, and that the manifest's `circuitSpecJson` for each circuit agrees with them and with `circuit-setup/configs/production.ceremony.config.json` in [privacy-boost-ceremony](https://github.com/sunnyside-io/privacy-boost-ceremony) at commit `e645b68d`. 3. Re-derive every key from the transcript. The circuits are the `frontend/` package of [privacy-boost-protocol](https://github.com/sunnyside-io/privacy-boost-protocol) at commit `9e3f34e1a91c`. Note that the ceremony coordinator compiled them with **gnark v0.15.0 and gnark-crypto v0.20.1**, as recorded in the build information embedded in the signed `ceremony/v0.0.x` release binaries. The public ceremony repository pins gnark v0.14.0 instead, which compiles to different constraint systems, so its `verify-public` command fails at the R1CS hash check. The script archive contains a per-circuit helper built against gnark v0.15.0 that recompiles each circuit's R1CS from its spec, checks it against the manifest, fetches and digest-checks the pinned Perpetual Powers of Tau artifact for the required power, recomputes the origin of the phase 2 transcript, verifies every contribution against its predecessor, and seals the proving and verifying keys, comparing them to the manifest commitments. ``` python3 run.py prepare python3 onchain.py python3 run.py run --jobs 2 ``` 4. For each circuit, encode the re-derived `.vk` into the onchain layout (negate `beta`, `gamma`, `delta`; interleave `G1.K`) and confirm its digest equals the value read from chain. The helper reads all registered keys at one finalized OP Mainnet block (equivalent to the Base deployment), recomputing the storage slots from the circuit parameters and cross-checking them against the getters. #### Privacy Boost forced withdrawal verifier, 1 circuit Verifies the client-side forced withdrawal proofs. The deployed verification keys have not yet been reproduced by L2BEAT. - Verifier ID: `Privacy Boost forced withdrawal verifier 23.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/5792c139b9529ed80643262d75b5489055be11b0/frontend/forced_withdraw_circuit.go - Verification: not verified - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0x40e93d3357A5A3d249437717Da936f6141ba85cE](https://basescan.org/address/0x40e93d3357A5A3d249437717Da936f6141ba85cE#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) #### Privacy Boost portal deposit verifier, 2 circuits Verifies the batched hidden-recipient portal deposit proofs. - Verifier ID: `Privacy Boost portal deposit verifier 09.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/9e3f34e1a91c20497bc7d8f47492761bc868843c/frontend/deposit_portal_circuit.go - Verification: successful (verified by [L2BEAT](https://l2beat.com)) - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0x0c8bb018a3d8DF4c5fC86518ca57F8E1445BCF63](https://basescan.org/address/0x0c8bb018a3d8DF4c5fC86518ca57F8E1445BCF63#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) ##### Verification steps The portal deposit verifier stores verification keys for 2 different batched portal deposit circuits across 2 registered batch sizes (`p1`, `p6`). The steps below reproduce both verification keys from circuit sources and trusted setup files. They require about 24 GiB RAM with two parallel workers and ~35 GiB disk space. Helper scripts implementing all of the reproduction steps are in the [script archive](https://trusted-setup-hosting.l2beat.com/privacy/privacy-boost/privacy_boost_vk_digest_v2.zip). 1. Download the second production ceremony public bundle (about 9.8 GB, gzip-compressed despite the `.tar` name) and extract it. The archive used for this attestation hashes to `91ad38d7775259116d00e5288630aaec565fbec8ff38a76dc874c13412ae530a`. ``` curl -LO https://file.ceremony.privacyboost.io/prod-20260902-public.tar shasum -a 256 prod-20260902-public.tar tar xzf prod-20260902-public.tar ``` 2. Check that the ceremony's circuit matrix in `public/config.snapshot.json` matches the circuit shapes registered on the verifier, and that the manifest's `circuitSpecJson` for each circuit agrees with them and with `circuit-setup/configs/production.ceremony.config.json` in [privacy-boost-ceremony](https://github.com/sunnyside-io/privacy-boost-ceremony) at commit `e645b68d`. 3. Re-derive every key from the transcript. The circuits are the `frontend/` package of [privacy-boost-protocol](https://github.com/sunnyside-io/privacy-boost-protocol) at commit `9e3f34e1a91c`. Note that the ceremony coordinator compiled them with **gnark v0.15.0 and gnark-crypto v0.20.1**, as recorded in the build information embedded in the signed `ceremony/v0.0.x` release binaries. The public ceremony repository pins gnark v0.14.0 instead, which compiles to different constraint systems, so its `verify-public` command fails at the R1CS hash check. The script archive contains a per-circuit helper built against gnark v0.15.0 that recompiles each circuit's R1CS from its spec, checks it against the manifest, fetches and digest-checks the pinned Perpetual Powers of Tau artifact for the required power, recomputes the origin of the phase 2 transcript, verifies every contribution against its predecessor, and seals the proving and verifying keys, comparing them to the manifest commitments. Reading the transcript lazily keeps the peak below 10 GB per circuit. ``` python3 run.py prepare python3 onchain.py python3 run.py run --jobs 2 ``` 4. For each circuit, encode the re-derived `.vk` into the onchain layout (negate `beta`, `gamma`, `delta`; interleave `G1.K`) and confirm its digest equals the value read from chain. The helper reads all registered keys at one finalized OP Mainnet block (equivalent to the Base deployment), recomputing the storage slots from the circuit parameters and cross-checking them against the getters. #### Privacy Boost gift claim verifier, 2 circuits Verifies the batched gift claim, refund and public gift exit proofs. The deployed verification keys have not yet been reproduced by L2BEAT. - Verifier ID: `Privacy Boost gift claim verifier 23.09.2026` - Source: https://github.com/sunnyside-io/privacy-boost-protocol/blob/5792c139b9529ed80643262d75b5489055be11b0/frontend/gift_claim_circuit.go - Verification: not verified - Used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost) **Known deployments** - [0x8f394a08A7544daf39aF38FEA5B2E348180bDC05](https://basescan.org/address/0x8f394a08A7544daf39aF38FEA5B2E348180bDC05#code) on Base Chain, used in: [Privacy Boost](https://l2beat.com/privacy/projects/privacy-boost)