LibraryPrivacy2023Design paperCorpus record
Aztec: a privacy-preserving rollup design
Aztec. Aztec.
Aztec publishes a rollup whose state transitions are proved, and whose user state is encrypted so the settlement contract sees a proof rather than the plaintext balances.
A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.
Aztec publishes a rollup whose state transitions are proved, and whose user state is encrypted so the settlement contract sees a proof rather than the plaintext balances.
- Evidence
- Primary paper
- Re-measured
- No
- Assumptions
- 3
- Records linked
- 2
01 Claim ledger
What the paper is allowed to say
Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.
Claim 01 · Paper model
The defect
A private rollup still has a sequencer, a prover, and a data question. Privacy of amounts is not privacy of the operator set.
Claim 02 · Paper model
The proposal
Aztec publishes a rollup whose state transitions are proved, and whose user state is encrypted so the settlement contract sees a proof rather than the plaintext balances.
Claim 03 · Paper model
The mechanism
Notes, nullifiers, and a public kernel are the objects the docs use. A note is spent by revealing a nullifier, not by showing the note.
Claim 04 · Paper model
The bound
This note does not say the network is live, and it does not describe the earlier Aztec Connect deployment as if it were this design.
02 Three cuts
Observation, model, falsifier
A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.
01 The defect
Observation
What the study says
A private rollup still has a sequencer, a prover, and a data question. Privacy of amounts is not privacy of the operator set.
Model
What has to hold
You are reading Aztec's protocol docs. Noir is the language. This is the rollup.
Falsifier
What would retire it
What can the sequencer see that a later observer cannot?
02 The proposal
Observation
What the study says
Aztec publishes a rollup whose state transitions are proved, and whose user state is encrypted so the settlement contract sees a proof rather than the plaintext balances.
Model
What has to hold
You are reading Aztec's protocol docs. Noir is the language. This is the rollup.
Falsifier
What would retire it
What does the settlement contract see: which roots and which nullifiers?
03 The mechanism
Observation
What the study says
Notes, nullifiers, and a public kernel are the objects the docs use. A note is spent by revealing a nullifier, not by showing the note.
Model
What has to hold
No price, supply, yield, or adoption figure is added by this desk.
Falsifier
What would retire it
What does the settlement contract see: which roots and which nullifiers?
04 The bound
Observation
What the study says
This note does not say the network is live, and it does not describe the earlier Aztec Connect deployment as if it were this design.
Model
What has to hold
You are reading Aztec's protocol docs. Noir is the language. This is the rollup.
Falsifier
What would retire it
What does the settlement contract see: which roots and which nullifiers?
03 Sequence
One action, as an operating tape
- 01Notes, nullifiers, and a public kernel are the objects the docs use. A note is spent by revealing a nullifier, not by showing the note.
- 02The kernel proof composes application proofs. An application circuit that leaks an input will leak it no matter how private the kernel is.
- 03Settlement is still a contract on a public chain. The proof is public. The witness is what is supposed to stay hidden.
04 Load-bearing
The argument, and where a pitch drops it
What the name has to mean
The cut
Aztec publishes a rollup whose state transitions are proved, and whose user state is encrypted so the settlement contract sees a proof rather than the plaintext balances.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
This note does not say the network is live, and it does not describe the earlier Aztec Connect deployment as if it were this design.
What actually moves
The cut
The kernel proof composes application proofs. An application circuit that leaks an input will leak it no matter how private the kernel is.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
A later client, parameter or reward formula is a different object from this paragraph.
What a later deployment may change
The cut
Settlement is still a contract on a public chain. The proof is public. The witness is what is supposed to stay hidden.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
Privacy against the sequencer is a different claim from privacy against the settlement chain, and the docs must be read for which one they make.
05 Register
What has to be true
Model · Not re-measured
You are reading Aztec's protocol docs. Noir is the language. This is the rollup.
Model · Not re-measured
The document is the one at the source URL. A marketing page with the same brand is not this text.
Model · Not re-measured
No price, supply, yield, or adoption figure is added by this desk.
06 Divergence
What happened after the paper
Privacy against the sequencer is a different claim from privacy against the settlement chain, and the docs must be read for which one they make.
A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.
07 Pre-mortem
What to check before you use the idea
- 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.
08 Anatomy
The paper, in the order a builder needs
The problem it names
A private rollup still has a sequencer, a prover, and a data question. Privacy of amounts is not privacy of the operator set.
What the design proposes
- Notes, nullifiers, and a public kernel are the objects the docs use. A note is spent by revealing a nullifier, not by showing the note.
- The kernel proof composes application proofs. An application circuit that leaks an input will leak it no matter how private the kernel is.
- Settlement is still a contract on a public chain. The proof is public. The witness is what is supposed to stay hidden.
How the mechanism is specified
- Notes, nullifiers, and a public kernel are the objects the docs use. A note is spent by revealing a nullifier, not by showing the note.
- The kernel proof composes application proofs. An application circuit that leaks an input will leak it no matter how private the kernel is.
- Settlement is still a contract on a public chain. The proof is public. The witness is what is supposed to stay hidden.
What this page does not treat as proven
- This note does not say the network is live, and it does not describe the earlier Aztec Connect deployment as if it were this design.
- It states no anonymity-set size.
- Privacy against the sequencer is a different claim from privacy against the settlement chain, and the docs must be read for which one they make.
Why the desk still reads it
Aztec publishes a rollup whose state transitions are proved, and whose user state is encrypted so the settlement contract sees a proof rather than the plaintext balances.
09 Lexicon
Terms, opened into the record
- Note
- A private state element. Spending it reveals a nullifier, not the note.
- Kernel
- The circuit that composes application proofs into a rollup transition.
10 Repository
Every linked record on this page
Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.
Concepts
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
