{"type":"video","version":"1.0","html":"<iframe src=\"https://www.loom.com/embed/265d5bbdf33d4a74a25919c6dce50e3a\" frameborder=\"0\" width=\"1280\" height=\"960\" webkitallowfullscreen mozallowfullscreen allowfullscreen></iframe>","height":960,"width":1280,"provider_name":"Loom","provider_url":"https://www.loom.com","thumbnail_height":960,"thumbnail_width":1280,"thumbnail_url":"https://cdn.loom.com/sessions/thumbnails/265d5bbdf33d4a74a25919c6dce50e3a-9e8f0d6fbd0350a9.gif","duration":1267.2213330000002,"title":"ZK Wormhole Circuits and Transfer Proofs","description":"This Loom explains the ZK circuit design for Wormhole addresses and proof of burn in the Quantus and related systems. It describes wormhole addresses as unspendable double hashes of secrets and shows how the system uses zero knowledge to prove ownership of the address and that a burn transfer was included in a specific block hash for remittance to a destination address. It then details how Plonky2 recursion aggregates many burn proofs into loops, rolled up seven at a time into one on chain proof, with transfer proofs stored in a four ary Poseidon tree whose root is included in block headers. The circuit includes constraints like splitting amounts minus fees, nullifier formation to prevent double spends, and fast proof performance noted as about 50 milliseconds. It also mentions canonicality checks for field element encoding and warns that soundness bugs could enable minting money."}