Anatomy of a private withdrawal. Every claim below is on-chain.
What this transaction contains:
→ A groth16 proof, generated in the user's browser, verified by the Entrypoint contract
→ Public signals: newCommitment, nullifierHash, withdrawnValue, stateRoot, ASPRoot, context
→ context binds the proof to exactly one recipient and one fee. Nothing else can be claimed
→ nullifierHash is recorded, the note is burned. Double-spend is impossible
→ Recipient receives 0.009 ETH as a plain, ordinary transfer
→ 0.15% protocol fee routed to treasury inside the same transaction
→ Change re-enters the pool as a fresh commitment, instantly spendable
What this transaction does not contain:
× The sender's address
× The depositor's address
× Any link between the two
Gas paid by the relayer. 507,398 gas. One proof. Zero identity.
Block 75,816,251 · Robinhood Chain (chain ID 4663)
Verify it yourself:
https://robinhoodchain.blockscout.com/tx/0x8f72723622a0e5437e698fc95794874cbc8c469486d1fcc2d97511668a0ec743
http://privora.cash
Post #22
96