Difference between revisions of "AZTEC Protocol"

From CryptoWiki

m (1 revision imported)
 
(16 intermediate revisions by 2 users not shown)
Line 1: Line 1:
Aztec Network is a [[Layer Two|L2]] privacy layer on [[Ethereum (ETH)|Ethereum]]. It strives to enable affordable, private crypto payments via [[Zero-Knowledge Proofs|zero-knowledge proofs]]. Additionally it allows to deposit funds into a variety of [[Decentralized Finance (DeFi)|DeFi]] Protocols such as [[Lido (LDO)|Lido]], [[Element Finance (ELFI)|Element.Fi,]] etc.
== Basics ==
== Basics ==


Line 5: Line 7:
*[[Mainnet]] release: [https://medium.com/aztec-protocol/launching-aztec-2-0-rollup-ac7db8012f4b 15-3-2021]
*[[Mainnet]] release: [https://medium.com/aztec-protocol/launching-aztec-2-0-rollup-ac7db8012f4b 15-3-2021]


*AZTEC Protocol is an [[open source]] [[Zero-Knowledge Proofs|zero-knowledge]] protocol built on top of [[Ethereum]], making plug-and-play value transmission and asset governance privacy tools for developers and companies. 
*AZTEC Protocol is an [[open source]] [[Zero-Knowledge Proofs|zero-knowledge]] protocol built on top of [[Ethereum]], making plug-and-play value transmission and asset [[governance]] privacy tools for developers and companies. 
* Their CTO has contributed to two [[Open Source|open source]] projects with the aim of making cryptography cheaper on Ethereum:
* Their CTO has contributed to two [[Open Source|open source]] projects with the aim of making cryptography cheaper on Ethereum:
*#[http://email.mg2.substack.com/c/eJwlUMuOwyAM_JpyjHglGw4cdtXtb0QQnAaVQASmVfbrl7SSJT9n7PFsEO4pH3pPBUktkCfvNBPqS1FKnJaOjf1IfJmWDLAZHzTmCmSvNvjZoE_xBPRKkFVLOVrFexCLkKPioxVqcL0ZqJIz2EZzLplMdR7iDBqekI8UgQS9Iu7lIr4v_Nbs7nGttpvT1pJ5XUzBFsBza8Mt2GsIzTFGvOaUKdpTxiSXjHesu3I-XGUv-Pdt-L2pn4uk2513pdqCZn6cpCTrPxdaY88JUzxFvcvv6_DYQUd4lQCIkAl-PtP0Tm1mq9HjMUE0NoDTH8ipX_JBkLbEpUYXdWNOS1peKT_-ASYsdpo Optimisations to the evmone interpreter]
*#[http://email.mg2.substack.com/c/eJwlUMuOwyAM_JpyjHglGw4cdtXtb0QQnAaVQASmVfbrl7SSJT9n7PFsEO4pH3pPBUktkCfvNBPqS1FKnJaOjf1IfJmWDLAZHzTmCmSvNvjZoE_xBPRKkFVLOVrFexCLkKPioxVqcL0ZqJIz2EZzLplMdR7iDBqekI8UgQS9Iu7lIr4v_Nbs7nGttpvT1pJ5XUzBFsBza8Mt2GsIzTFGvOaUKdpTxiSXjHesu3I-XGUv-Pdt-L2pn4uk2513pdqCZn6cpCTrPxdaY88JUzxFvcvv6_DYQUd4lQCIkAl-PtP0Tm1mq9HjMUE0NoDTH8ipX_JBkLbEpUYXdWNOS1peKT_-ASYsdpo Optimisations to the evmone interpreter]
Line 12: Line 14:


== Launch ==
== Launch ==
* Have announced (9-2019) their upcoming multi-party computation set-up ceremony and opened to applications for 200 participants to take part in a global relay. The ceremony will build a ‘Reference String’, an echo of [[ZCash (ZEC)|ZCash’s]] <em>Powers of Tau </em>Ceremony, and will lead up to [[mainnet]] launch at the end of October. More details on how the ceremony works [http://sendy.tokeneconomy.co/sendy/l/BeAk0z1ILVuS6sJOlZEyOw/VdSG8923S7634ly96dSx3MvJzg/CfIj892MKv763pUEHUjdvOVdww here]. 
* Have announced (9-2019) their upcoming multi-party computation set-up ceremony and opened to applications for 200 participants to take part in a global [[relay]]. The ceremony will build a ‘Reference String’, an echo of [[ZCash (ZEC)|ZCash’s]] <em>Powers of Tau </em>Ceremony, and will lead up to [[mainnet]] launch at the end of October. More details on how the ceremony works [http://sendy.tokeneconomy.co/sendy/l/BeAk0z1ILVuS6sJOlZEyOw/VdSG8923S7634ly96dSx3MvJzg/CfIj892MKv763pUEHUjdvOVdww here]. 
* [[Vitalik]] [https://twitter.com/VitalikButerin/status/1174632632329441280 announced] his participation in the Ignition ceremony, using his own implementation of the MPC.
* [[Vitalik]] [https://twitter.com/VitalikButerin/status/1174632632329441280 announced] his participation in the Ignition ceremony, using his own implementation of the MPC.
 
*AZTEC has completed Ignition, the biggest MPC ceremony in history by number of participants. From [https://medium.com/aztec-protocol/aztec-crs-the-biggest-mpc-setup-in-history-has-successfully-finished-74c6909cd0c4 their blog] (7-1-2020):
* AZTEC has completed Ignition, the biggest MPC ceremony in history by number of participants. From [https://medium.com/aztec-protocol/aztec-crs-the-biggest-mpc-setup-in-history-has-successfully-finished-74c6909cd0c4 their blog] (7-1-2020):
''"600 sign-ups, 202 participants ran the software — of which 176 were valid, 30 participants stayed [[incognito]]. Most participants came from London''
''"600 sign-ups, 202 participants ran the software — of which 176 were valid, 30 participants stayed incognito. Most participants came from London''


''Confidential [[transactions]] on Ethereum are launching this month!''
''Confidential [[transactions]] on Ethereum are launching this month!''


''2 audits completed ([[Trail of Bits]] & [[ConsenSys]] Diligence), Ceremony finished, Codex computation finished this week → Deploy to Mainnet January 2020"''
''2 audits completed ([[Trail of Bits]] & [[ConsenSys]] Diligence), Ceremony finished, Codex computation finished this week → Deploy to [[MainNet|Mainnet]] January 2020"''
* [https://proofofwork.news/p/proof-of-work-78 From] [[Proof of Work (Mailing List)|Proof of Work]] #78 (29-10-2019):
* [https://proofofwork.news/p/proof-of-work-78 From] [[Proof of Work (Mailing List)|Proof of Work]] #78 (29-10-2019):
''"we’re doing final deploy tests for our [[mainnet]] protocol, preparing for our launch later this year."''
''"we’re doing final deploy tests for our [[mainnet]] protocol, preparing for our launch later this year."''
Line 28: Line 29:


*[[Bug bounty]] program can be found [insert here].
*[[Bug bounty]] program can be found [insert here].
*[https://l2beat.com/scaling/projects/aztecconnect/ From] [[L2beat]], regarding both [https://l2beat.com/scaling/projects/aztec/ Aztec] and Aztec Connect (31-10-2022):
''"Funds can be stolen if''
# ''the cryptography is broken or implemented incorrectly,''
# ''a [[Smart Contract (SC)|contract]] receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).''
''Users can be censored if''
# ''the operator refuses to include their [[Transaction (Tx)|transactions]] and users lack resources to propose [[Block|blocks]] themselves.''
''[[Maximal Extractable Value (MEV)|MEV]] can be extracted if''
# ''the operator exploits their [[centralized]] position and [[frontruns]] user transactions."''
* From competitor Railgun's [https://medium.com/@Railgun_Project/decentralized-layer-1-vs-centralized-layer-2-a-comparison-between-railgun-and-aztec-privacy-8f7a3a2a0c4b blog] comparing itself with Aztec (28-6-2022):
''"Aztec’s protocol and smart contracts have not been externally audited, and while their smart contracts and client-side libraries are open-source, their sequencer code is private.  Aztec is at least a year or two years away from a professional-ready, audited platform. Deployer keys could potentially be abused to steal funds, or a court order could force the team to change their code to reveal previously private information without prior warning to users. Aztec is as secure and private as its centralized team chooses it to be."''


===Bugs/Exploits===
===Bugs/Exploits===


* Aztec Connect [https://weekinethereum.substack.com/p/week-in-ethereum-news-october-28 published] (30-10-2023) a vulnerability postmortem, $450k bounty paid, and asked users to withdraw funds from zk.money
* From competitor Railgun's [https://medium.com/@Railgun_Project/decentralized-layer-1-vs-centralized-layer-2-a-comparison-between-railgun-and-aztec-privacy-8f7a3a2a0c4b blog] comparing itself with Aztec (28-6-2022):
''"Another vulnerability was [https://twitter.com/aztecnetwork/status/1535411207963742209 identified]."''
*[https://weekinethereum.substack.com/p/week-in-ethereum-news-october-30?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjo0MzMwMDA5NSwiXyI6IkZBQ3M5IiwiaWF0IjoxNjM2MDAxOTU5LCJleHAiOjE2MzYwMDU1NTksImlzcyI6InB1Yi0xMDcxIiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.lv4QI2gJ_Xvuo From] [[Week In Ethereum|Week in Ethereum]] (30-10-2021):
*[https://weekinethereum.substack.com/p/week-in-ethereum-news-october-30?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjo0MzMwMDA5NSwiXyI6IkZBQ3M5IiwiaWF0IjoxNjM2MDAxOTU5LCJleHAiOjE2MzYwMDU1NTksImlzcyI6InB1Yi0xMDcxIiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.lv4QI2gJ_Xvuo From] [[Week In Ethereum|Week in Ethereum]] (30-10-2021):


Line 38: Line 60:


=== Admin Keys ===
=== Admin Keys ===
* Had [[Astria]] [https://forum.aztec.network/t/proposal-integrating-the-astria-sequencing-layer/5326 proposing] to become its sequencing layer, 16 days later, no responses on it yet (22-4-2024).
*[https://twitter.com/aztecnetwork/status/1696227886091440228 Claims] the next version of Aztec will be fully decentralized (29-8-2023).
*[https://l2beat.com/scaling/projects/aztecconnect/ From] [[L2beat]] regarding both [https://l2beat.com/scaling/projects/aztec/ Aztec] and Aztec Connect (31-10-2022):
''"The system [https://etherscan.io/address/0x3f972e325cecd99a6be267fd36ceb46dca7c3f28#code#F18#L586 has] a [[centralized]] operator. Only specific [[Address|addresses]] appointed by the owner are permitted to propose new [[Block|blocks]] during regular [[Rollups|rollup]] operation. Periodically a special window is open during which anyone can propose new blocks. Users can be censored if the operator refuses to include their transactions and users lack resources to propose blocks themselves."''


=== DAO ===
=== DAO ===
Line 44: Line 72:


== zkTokens ==
== zkTokens ==
* Does not have a [[token]] itself, but releases [[Zk-SNARK's|zk]] Tokens. The first of which [https://medium.com/@tompocock/launching-aztec-c9fb271605d7 at the launch] (1-2-2020) was [https://medium.com/aztec-protocol/the-first-10-000-zkdai-d499a133b8a0 zkDai]. ''"Over the coming six weeks we’ll release other zk Tokens onto the network, and in two months’ time we will remove restrictions so you can make completely private custom assets from scratch."''
* Does not have a [[token]] itself, but releases [[Zk-SNARK's|zk]] [[Tokens]]. The first of which [https://medium.com/@tompocock/launching-aztec-c9fb271605d7 at the launch] (1-2-2020) was [https://medium.com/aztec-protocol/the-first-10-000-zkdai-d499a133b8a0 zkDai]. ''"Over the coming six weeks we’ll release other zk Tokens onto the network, and in two months’ time we will remove restrictions so you can make completely private custom assets from scratch."''
* From [https://www.trustnodes.com/2020/02/10/vitalik-buterin-takes-part-in-the-aztec-ceremony-of-zcash-and-monero-like-smart-contract-launch this article] by [[TrustNodes]] (10-2-2020):
* From [https://www.trustnodes.com/2020/02/10/vitalik-buterin-takes-part-in-the-aztec-ceremony-of-zcash-and-monero-like-smart-contract-launch this article] by [[TrustNodes]] (10-2-2020):
''"You need to deposit [[dai]] through the ZkDai (zkassetdetailed) contract, through a zero knowledge proof.” Aztec turns dai into what can be described as a smart contract database asset. You send the dai to Aztec, and you get zkdai which gives you a claim to the dai.''
''"You need to deposit [[dai]] through the ZkDai (zkassetdetailed) contract, through a zero knowledge proof.” Aztec turns dai into what can be described as a [[Smart Contract|smart contract]] database asset. You send the dai to Aztec, and you get zkdai which gives you a claim to the dai.''


''You can transfer this zkdai within the smart contract environment, but the [[blockchain]] won’t know until you convert it into dai. In the meantime you’re exchanging value in a very private manner. End users can’t quite play yet with Aztec because an app is not out, but devs can incorporate it through a [https://docs.aztecprotocol.com/ tutorial] of sorts."''
''You can transfer this zkdai within the [[Smart Contract|smart contract]] environment, but the [[blockchain]] won’t know until you convert it into dai. In the meantime you’re exchanging value in a very private manner. End users can’t quite play yet with Aztec because an app is not out, but devs can incorporate it through a [https://docs.aztecprotocol.com/ tutorial] of sorts."''


== Tech ==
== Tech ==
* From their [https://medium.com/aztec-protocol/aztec-is-going-open-source-71570db473e6 blog] (10-6-2021):
*[[Whitepaper]] can be found [insert here].
 
*Code can be viewed [insert here]. From their [https://medium.com/aztec-protocol/aztec-is-going-open-source-71570db473e6 blog] (10-6-2021): ''"Aztec initially realeased some of its prover code under the [https://medium.com/aztec-protocol/introducing-polaris-d4eb0c9da1b4 Polaris license] jointly created with [[StarkWare]]. Today we announce that all future releases of code from Aztec will be under the [[Open Source|open source]] Apache 2.0 license."''
''"Aztec initially realeased some of its prover code under the [https://medium.com/aztec-protocol/introducing-polaris-d4eb0c9da1b4 Polaris license] jointly created with [[StarkWare]]. Today we announce that all future releases of code from Aztec will be under the [open source] Apache 2.0 license."''
*Built on: [[Layer Two|L2]] on [[Ethereum (ETH)|Ethereum]]
*Programming language used: [[Solidity]]
===Transaction Details===
*Capacity ([[TPS]]):
*[[Latency]]:
===How it works===
*[https://l2beat.com/scaling/projects/aztecconnect/ From] [[L2beat]] regarding both [https://l2beat.com/scaling/projects/aztec/ Aztec] and Aztec Connect (31-10-2022):
''"Validity proofs ensure [[state]] correctness. Each update to the system state must be accompanied by a [[Zero-Knowledge Proofs|ZK Proof]] that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. Once the proof is processed on the [[Ethereum (ETH)|Ethereum]] blockchain the [[Layer Two|L2]] [[block]] is instantly [[finalized]].''  


''All the data that is used to construct the system state is published [[On Chain|on chain]] in the form of cheap calldata. This ensures that it will always be available when needed."''
*From their own [https://medium.com/@tompocock/launching-aztec-c9fb271605d7 launch blog] (1-2-2020):
*From their own [https://medium.com/@tompocock/launching-aztec-c9fb271605d7 launch blog] (1-2-2020):


''"Aztec has deployed the two core components of its technology today:''
''"Aztec has deployed the two core components of its technology today:''
# ''[https://github.com/AztecProtocol/specification Aztec Crypto Engine (ACE)] — our [[smart contract]] validator on Ethereum mainnet, checking the correctness of every private [[transaction]]''
# ''[https://github.com/AztecProtocol/specification Aztec Crypto Engine (ACE)] — our [[smart contract]] [[validator]] on Ethereum [[MainNet|mainnet]], checking the correctness of every private [[transaction]]''
# ''[https://docs.aztecprotocol.com/#/SDK/Getting%20started Privacy SDK] — abstracts away the complexities of Aztec’s cryptography, so developers can integrate privacy into their [[dapps]] with ease"''
# ''[https://docs.aztecprotocol.com/#/SDK/Getting%20started Privacy SDK] — abstracts away the complexities of Aztec’s cryptography, so developers can integrate privacy into their [[dapps]] with ease"''
=== Fees ===


=== Upgrades ===
=== Upgrades ===
Line 65: Line 103:
*[https://decrypt.co/88450/ethereum-privacy-provider-aztec-raises-17m-adds-bridges-developers?utm_source=telegram&utm_medium=social&utm_campaign=smt From] [[Decrypt (DCPT)|Decrypt]] (16-12-2021):
*[https://decrypt.co/88450/ethereum-privacy-provider-aztec-raises-17m-adds-bridges-developers?utm_source=telegram&utm_medium=social&utm_campaign=smt From] [[Decrypt (DCPT)|Decrypt]] (16-12-2021):


''"Aztec announced it is unrolling a set of tools, dubbed Aztec Connect, to let developers add its privacy feature to a wide variety of protocols by using a software bridge. "It allows users to confidentially access world-class [[Decentralized Finance (DeFi)|DeFi]] services on [[Ethereum (ETH)|Ethereum]] with up to 100x cost savings, all while strengthening Aztec’s existing [https://medium.com/aztec-protocol/infinite-privacy-new-anonymity-paradigms-with-aztec-network-1b02e84bbce2 privacy guarantees]. At launch, Aztec Connect extends the capabilities of zk.money, adding [[Whitelist|whitelisted]] functionality from select blue-chip DeFi partners," said the company in a blog post."''
''"Aztec announced it is unrolling a set of tools, dubbed Aztec Connect, to let developers add its privacy feature to a wide variety of protocols by using a software [[bridge]]. "It allows users to confidentially access world-class [[Decentralized Finance (DeFi)|DeFi]] services on [[Ethereum (ETH)|Ethereum]] with up to 100x cost savings, all while strengthening Aztec’s existing [https://medium.com/aztec-protocol/infinite-privacy-new-anonymity-paradigms-with-aztec-network-1b02e84bbce2 privacy guarantees]. At launch, Aztec Connect extends the capabilities of zk.money, adding [[Whitelist|whitelisted]] functionality from select blue-chip [[Defi|DeFi]] partners," said the company in a blog post."''


*Aztec 2.0 [https://medium.com/aztec-protocol/aztec-zkrollup-layer-2-privacy-1978e90ee3b6 went live] (12-10-2020):
*Aztec 2.0 [https://medium.com/aztec-protocol/aztec-zkrollup-layer-2-privacy-1978e90ee3b6 went live] (12-10-2020):
Line 74: Line 112:
#''Secure by design: all [[transactions]] are validated [[on-chain]]''
#''Secure by design: all [[transactions]] are validated [[on-chain]]''
#''Programmable Privacy with Noir — The private [[contract]] language"''
#''Programmable Privacy with Noir — The private [[contract]] language"''
=== Staking and Fernet ===
* From their [https://hackmd.io/@aztec-network/fernet docs] (9-2023):
''"Fair Election Randomized Natively on Ethereum Trustlessly (Fernet) is a protocol for random sequencer selection. In each iteration, it relies on a VRF to assign a random score to each sequencer in order to rank them. The sequencer with the highest score can propose an ordering for [[Transaction (Tx)|transactions]] and the [[block]] they build upon, and then reveal its contents for the chain to advance under soft finality. Provers must then assemble a proof for this block and submit it to [[Layer One|L1]] for the block to be finalised.''
''Sequencers are required to [[Staking|stake]] on L1 in order to participate in the protocol. Each sequencer registers a public key when they stake, which will be used to verify their VRF submission. After staking, a sequencer needs to wait for an activation period of N L1 blocks until they can start proposing new blocks. Unstaking also requires a delay to allow for [[slashing]] of dishonest behaviour."''


=== Validation ===
=== Validation ===
Line 79: Line 125:
''"[[bitcoiners]] would argue that because you can’t validate yourself, you can’t be sure zkdai or [[zcash]] has not been printed out of thin air.''
''"[[bitcoiners]] would argue that because you can’t validate yourself, you can’t be sure zkdai or [[zcash]] has not been printed out of thin air.''


''“That’s not actually true — the point of a parity check is to prove that each [[transaction]] has a net zero effect on supply,” says Tom Walton-Pocock, after further adding: “I think I’d return with the question ‘under what conditions can the parity check over Aztec’s encrypted balances fail?’."''
''“That’s not actually true — the point of a [[parity]] check is to prove that each [[transaction]] has a net zero effect on supply,” says Tom Walton-Pocock, after further adding: “I think I’d return with the question ‘under what conditions can the parity check over Aztec’s encrypted balances fail?’."''


=== Zk-Zk Rollup ===
=== Zk-Zk Rollup ===
Line 91: Line 137:
''Here are the benchmarks we’d like (in a perfect world):''
''Here are the benchmarks we’d like (in a perfect world):''
# ''~1s proof construction times on smartphones''
# ''~1s proof construction times on smartphones''
# ''~10s proof construction times for rollups (server-side)''
# ''~10s proof construction times for [[rollups]] (server-side)''
# ''~1,000tps on [[mainnet]]''
# ''~1,000tps on [[mainnet]]''
# ''3 layer recursion — proofs of proofs of proofs"''
# ''3 layer recursion — proofs of proofs of proofs"''
===Interoperability===
* [https://ournetwork.substack.com/p/ournetwork-issue-118?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjo1MjY3MDkwNiwiXyI6InE4L1VrIiwiaWF0IjoxNjUzMDQyNzc0LCJleHAiOjE2NTMwNDYzNzQsImlzcyI6InB1Yi0yMTM2MiIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.UE2XSsIgrPortaxRKTLEqwnrGp0my9DJJ10ffQfVPOU&s=r From] [[Our Network]] (23-4-2022):


"''In the next month, the team will launch [https://medium.com/aztec-protocol/private-defi-with-the-aztec-connect-bridge-76c3da76d982 Aztec Connect], the first private bridge to Ethereum [[Decentralized Finance (DeFi)|DeFi]], unlocking privacy and scale for leading [[Defi|DeFi]] projects like [[Element Finance (ELFI)|Element]] and [[Lido (LDO)|Lido]]."''
===Other Details===
==Oracle Method==
==Oracle Method==


==Privacy Method==
==Privacy Method==
*[https://newsletter.banklesshq.com/p/how-to-use-defi-privately?utm_source=substack&utm_medium=email From] [[Bankless DAO (BANK)|Bankless]] (7-9-2022):
''"When you make a deposit to shield crypto via zk.money, you receive encrypted notes on Aztec, e.g. zkETH or zkDAI.''


* [https://newsletter.banklesshq.com/p/how-to-send-private-payments-on-ethereum?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjozNTE1NzE1MSwiXyI6IkNDcGZjIiwiaWF0IjoxNjE4ODg2MDQ1LCJleHAiOjE2MTg4ODk2NDUsImlzcyI6InB1Yi0xNjAxNSIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.mLoVi From] [[Bankless]] (15-4-2021):
''If you send these notes to someone else who’s on zk.money they’ll receive zkETH/zkDAI on Aztec, and if you send the notes to someone who’s not on zk.money they’ll simply receive ETH/[[Maker DAO|DAI]] on the Ethereum L1. In the latter case your send is also private, since the recipient will only see that the funds came from the Aztec smart contract and not your address specifically."''
* [https://newsletter.banklesshq.com/p/under-the-radar-layer-2s?utm_source=substack&utm_medium=email From] Bankless (22-7-2022):
''"While complex, at a high-level this architecture functions similar to a [[UTXO]]-model and uses zk-proofs to transfer ownership of assets, while simultaneously protecting the identities of any parties involved."''
*[https://ournetwork.substack.com/p/ournetwork-issue-118?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjo1MjY3MDkwNiwiXyI6InE4L1VrIiwiaWF0IjoxNjUzMDQyNzc0LCJleHAiOjE2NTMwNDYzNzQsImlzcyI6InB1Yi0yMTM2MiIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.UE2XSsIgrPortaxRKTLEqwnrGp0my9DJJ10ffQfVPOU&s=r From] [[Our Network]] (23-4-2022):
''"Aztec's privacy-first zkRollup has also amassed a significant anonymity set, with the 0.1 [[Ethereum (ETH)|ETH]] deposit set ~60% of the size of [[Tornado Cash (TORN)|Tornado Cash]]'s for the same deposit amount."''
*[https://newsletter.banklesshq.com/p/how-to-send-private-payments-on-ethereum?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjozNTE1NzE1MSwiXyI6IkNDcGZjIiwiaWF0IjoxNjE4ODg2MDQ1LCJleHAiOjE2MTg4ODk2NDUsImlzcyI6InB1Yi0xNjAxNSIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.mLoVi From] Bankless (15-4-2021):


''"Beyond private [[Ethereum]] [[transactions]] on the platform, which help users protect their privacy and save on [[gas]] costs, Aztec can be used as your anonymous [[DeFi]] [[wallet]]. In other words, it can be used to wash and anonymize your funds if you’re ever trying to fund a new [[address]].''
''"Beyond private [[Ethereum]] [[transactions]] on the platform, which help users protect their privacy and save on [[gas]] costs, Aztec can be used as your anonymous [[DeFi]] [[wallet]]. In other words, it can be used to wash and anonymize your funds if you’re ever trying to fund a new [[address]].''
Line 105: Line 164:
''When sending zkETH from [http://zk.money/ zk.money] to a regular Ethereum address, the recipient will receive regular, "unshielded" ETH directly to the wallet. The trick here is that [[Etherscan]] will show the funds were sent from the 'Aztec [[Contract]]' and not the sender's address.''
''When sending zkETH from [http://zk.money/ zk.money] to a regular Ethereum address, the recipient will receive regular, "unshielded" ETH directly to the wallet. The trick here is that [[Etherscan]] will show the funds were sent from the 'Aztec [[Contract]]' and not the sender's address.''


''By using Aztec, you could fund new DeFi wallets without worrying someone may track your trail of breadcrumbs. Better yet, you could use zk.money to protect your funds!"''
''By using Aztec, you could fund new [[Defi|DeFi]] [[wallets]] without worrying someone may track your trail of breadcrumbs. Better yet, you could use zk.money to protect your funds!"''


==Compliance==
==Compliance==
==Their Other Projects==
==Their Other Projects==
=== Aztec Connect ===
* Went [https://twitter.com/aztecnetwork/status/1545046832597700611 live] (7-7-2022).
*[https://newsletter.banklesshq.com/p/under-the-radar-layer-2s?utm_source=substack&utm_medium=email From] [[Bankless DAO (BANK)|Bankless]] (22-7-2022):
''"Aztec Connect provides users with the ability to directly interact with [[Smart Contract (SC)|smart-contracts]] that are deployed on [[Layer One|L1]] from within the [[Layer Two|L2]]. This means that users can inherit Aztec’s privacy while also accessing the [[liquidity]] and composability of [[Decentralized Applications (DApps)|dapps]] on Ethereum. Further, Aztec users also pay minimal [[gas]] fees despite the direct interaction with L1 because, like with any rollup, gas fees are still batched and amortized across all transactors."''
*[https://ournetwork.substack.com/p/ournetwork-issue-118?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjo1MjY3MDkwNiwiXyI6InE4L1VrIiwiaWF0IjoxNjUzMDQyNzc0LCJleHAiOjE2NTMwNDYzNzQsImlzcyI6InB1Yi0yMTM2MiIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.UE2XSsIgrPortaxRKTLEqwnrGp0my9DJJ10ffQfVPOU&s=r From] [[Our Network]] (23-4-2022):
"''In the next month, the team will launch [https://medium.com/aztec-protocol/private-defi-with-the-aztec-connect-bridge-76c3da76d982 Aztec Connect], the first private bridge to Ethereum [[Decentralized Finance (DeFi)|DeFi]], unlocking privacy and scale for leading DeFi projects like [[Element Finance (ELFI)|Element]] and [[Lido (LDO)|Lido]]. Meanwhile, Aztec has crossed 4,200 shielded ETH in the system, with over $15m total [[Total Value Locked (TVL)|TVL]]."''
== Roadmap ==
== Roadmap ==
* From their [https://medium.com/aztec-protocol/aztec-fast-privacy-with-zk%C2%B2-rollup-7c742f45457 blog] (27-3-2020):
* From their [https://medium.com/aztec-protocol/aztec-fast-privacy-with-zk%C2%B2-rollup-7c742f45457 blog] (27-3-2020):
''"Our privacy roadmap is as follows:''
''"Our privacy [[roadmap]] is as follows:''
# ''✅ Balance privacy — hiding transaction amounts''
# ''✅ [[Balance]] privacy — hiding transaction amounts''
# ''⌛ User privacy (coming soon) — hiding ‘spender’ and ‘receiver’ info''
# ''⌛ User privacy (coming soon) — hiding ‘spender’ and ‘receiver’ info''
# ''✘ Code privacy — hiding asset/code being spent/run"''
# ''✘ Code privacy — hiding asset/code being spent/run"''


== Usage ==
== Usage ==
* [[JP Morgan|JPMorgan]]'s blockchain team [https://www.coindesk.com/jp-morgan-is-quietly-testing-cutting-edge-ethereum-privacy-tech trialed] Aztec during a series of ZKP tests in February 2018.
* [https://thedefiant.io/aztec-100m-raise From] [[The Defiant]] (16-12-2022):
''"Aztec’s privacy-enhancing protocol has more than 70,000 unique users who have deposited over 60,000 [[Ethereum (ETH)|ETH]] ($75M) in its [[Smart Contract (SC)|smart contracts]] since it launched in July, according to a [[Dune Analytics]] [https://dune.com/gm365/aztec-v2 dashboard]."''
*[https://newsletter.banklesshq.com/p/how-to-use-defi-privately?utm_source=substack&utm_medium=email From] [[Bankless DAO (BANK)|Bankless]] (7-9-2022):
''"zk.money has helped facilitate over 250,000 private crypto transactions to date. Aztec currently has ~$2.8M in total value locked (TVL) across mainly ETH and DAI deposits."''
*[https://newsletter.banklesshq.com/p/under-the-radar-layer-2s?utm_source=substack&utm_medium=email From] Bankless (22-7-2022):
''"Per L2 Beat, Aztec Connect currently has $3.12M in TVL."''
*[https://ournetwork.substack.com/p/ournetwork-issue-118?token=eyJ1c2VyX2lkIjoxMzk3OTAwLCJwb3N0X2lkIjo1MjY3MDkwNiwiXyI6InE4L1VrIiwiaWF0IjoxNjUzMDQyNzc0LCJleHAiOjE2NTMwNDYzNzQsImlzcyI6InB1Yi0yMTM2MiIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.UE2XSsIgrPortaxRKTLEqwnrGp0my9DJJ10ffQfVPOU&s=r From] [[Our Network]] (23-4-2022):
''"Aztec's first-party private payments app, zk.money, is nearing $100m in all-time deposits and 60k registered users, with steady growth since launch."''
*[[JP Morgan|JPMorgan]]'s blockchain team [https://www.coindesk.com/jp-morgan-is-quietly-testing-cutting-edge-ethereum-privacy-tech trialed] Aztec during a series of ZKP tests in February 2018.


=== Projects that use or built on it ===
=== Projects that use or built on it ===
* [[Element Finance (ELFI)|Element Finance]] ([https://twitter.com/element_fi/status/1545126922484604929 7-7-2022]).


==Competition==
==Competition==
Line 128: Line 207:
===Pros===
===Pros===
===Cons===
===Cons===
* [https://l2beat.com/scaling/projects/aztecconnect/ From] [[L2beat]] (31-10-2022):
''"The system has a [[centralized]] operator."''
== Team, Funding, Partners, etc. ==
== Team, Funding, Partners, etc. ==
* London based
* London based
Line 137: Line 221:


=== Funding ===
=== Funding ===
* [[ConsenSys]] [https://www.coindesk.com/consensys-backs-2-1-million-funding-round-for-ethereum-privacy-startup led] a $2.1 million funding round for Aztec in November 2019.  
*[[Espresso Systems]]; [https://medium.com/@espressosys/scaling-ethereum-without-compromise-5cdf035dd14b part] of their $28 Series B (21-3-2024).
* On their [https://www.aztecprotocol.com/ website] (11-2-2020):
*From their blog (16-12-2022):
Consensys, [[a_capital]], [[Coinbase (Company)|Coinbase]], [[Mov37]], [[Samos Investments]] and [[ef.]]
''"Aztec Network is proud to announce $100 million in Series B financing led by [[a16z crypto]], with participation from [[A Capital]], King River, [[Variant Fund|Variant]], [[SV Angel]], [[Hashkey Capital|Hash Key]], Fenbushi, and AVG."''
*[https://decrypt.co/88450/ethereum-privacy-provider-aztec-raises-17m-adds-bridges-developers?utm_source=telegram&utm_medium=social&utm_campaign=smt From] [[Decrypt (DCPT)|Decrypt]] (16-12-2021):


* From [https://www.trustnodes.com/2020/02/10/vitalik-buterin-takes-part-in-the-aztec-ceremony-of-zcash-and-monero-like-smart-contract-launch this article] by [[TrustNodes]] (10-2-2020):
"Raised $17 million. Crypto investment giant [[Paradigm]] led the latest funding round for Aztec, while other investors included [[Ethereal Ventures]] and [[Vitalik Buterin|Vitalk Buterin]] himself."
*On their [https://www.aztecprotocol.com/ website] (11-2-2020):
[[Consensys]], [[a_capital]], [[Coinbase (Company)|Coinbase]], [[Mov37]], [[Samos Investments]] and [[ef.]]
 
*From [https://www.trustnodes.com/2020/02/10/vitalik-buterin-takes-part-in-the-aztec-ceremony-of-zcash-and-monero-like-smart-contract-launch this article] by [[TrustNodes]] (10-2-2020):
''"So how are they going to make money?''
''"So how are they going to make money?''


''“On value capture we’re not passing detailed comment on that now (not least because the blockchain and zero-knowledge landscape is changing at a breathless pace at the moment). We will lay out our model publicly at a later date,” Walton-Pocock says."''
''“On value capture we’re not passing detailed comment on that now (not least because the blockchain and zero-knowledge landscape is changing at a breathless pace at the moment). We will lay out our model publicly at a later date,” Walton-Pocock says."''
 
* [[ConsenSys]] [https://www.coindesk.com/consensys-backs-2-1-million-funding-round-for-ethereum-privacy-startup led] a $2.1 million funding round for Aztec in November 2019.
* [https://decrypt.co/88450/ethereum-privacy-provider-aztec-raises-17m-adds-bridges-developers?utm_source=telegram&utm_medium=social&utm_campaign=smt From] [[Decrypt (DCPT)|Decrypt]] (16-12-2021):
 
"Raised $17 million. Crypto investment giant [[Paradigm]] led the latest funding round for Aztec, while other investors included [[Ethereal Ventures]] and [[Vitalik Buterin|Vitalk Buterin]] himself."
 
=== Partners ===
=== Partners ===


*Worked together with [[StarkWare]]. From their [https://medium.com/starkware/the-polaris-prover-license-aba912de9ea4 blog] (29-1-2021):
*Worked together with [[StarkWare]]. From their [https://medium.com/starkware/the-polaris-prover-license-aba912de9ea4 blog] (29-1-2021):


''"[https://starkware.co/starkware-polaris-prover-license/ Polaris license] under which StarkWare plans to release source code for its STARK prover; Aztec will use the same Polaris license for its [[PLONK]] provers (see their [https://medium.com/p/d4eb0c9da1b4/ post])."''
''"[https://starkware.co/starkware-polaris-prover-license/ Polaris license] under which [[Starkware|StarkWare]] plans to release source code for its [[STARK]] prover; Aztec will use the same Polaris license for its [[PLONK]] provers (see their [https://medium.com/p/d4eb0c9da1b4/ post])."''


* Has [https://minaprotocol.com/blog/meet-pickles-snark-enabling-smart-contracts-on-coda-protocol contributed] to Pickles (for snarks) on [[Mina (MINA)|Mina]] (19-8-202).
* Has [https://minaprotocol.com/blog/meet-pickles-snark-enabling-smart-contracts-on-coda-protocol contributed] to Pickles (for snarks) on [[Mina (MINA)|Mina]] (19-8-202).

Latest revision as of 01:10, 22 April 2024

Aztec Network is a L2 privacy layer on Ethereum. It strives to enable affordable, private crypto payments via zero-knowledge proofs. Additionally it allows to deposit funds into a variety of DeFi Protocols such as Lido, Element.Fi, etc.

Basics

Launch

  • Have announced (9-2019) their upcoming multi-party computation set-up ceremony and opened to applications for 200 participants to take part in a global relay. The ceremony will build a ‘Reference String’, an echo of ZCash’s Powers of Tau Ceremony, and will lead up to mainnet launch at the end of October. More details on how the ceremony works here
  • Vitalik announced his participation in the Ignition ceremony, using his own implementation of the MPC.
  • AZTEC has completed Ignition, the biggest MPC ceremony in history by number of participants. From their blog (7-1-2020):

"600 sign-ups, 202 participants ran the software — of which 176 were valid, 30 participants stayed incognito. Most participants came from London

Confidential transactions on Ethereum are launching this month!

2 audits completed (Trail of Bits & ConsenSys Diligence), Ceremony finished, Codex computation finished this week → Deploy to Mainnet January 2020"

"we’re doing final deploy tests for our mainnet protocol, preparing for our launch later this year."

Audits & Exploits

"Funds can be stolen if

  1. the cryptography is broken or implemented incorrectly,
  2. a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).

Users can be censored if

  1. the operator refuses to include their transactions and users lack resources to propose blocks themselves.

MEV can be extracted if

  1. the operator exploits their centralized position and frontruns user transactions."
  • From competitor Railgun's blog comparing itself with Aztec (28-6-2022):

"Aztec’s protocol and smart contracts have not been externally audited, and while their smart contracts and client-side libraries are open-source, their sequencer code is private. Aztec is at least a year or two years away from a professional-ready, audited platform. Deployer keys could potentially be abused to steal funds, or a court order could force the team to change their code to reveal previously private information without prior warning to users. Aztec is as secure and private as its centralized team chooses it to be."

Bugs/Exploits

  • Aztec Connect published (30-10-2023) a vulnerability postmortem, $450k bounty paid, and asked users to withdraw funds from zk.money
  • From competitor Railgun's blog comparing itself with Aztec (28-6-2022):

"Another vulnerability was identified."

"Aztec $50k bug bounty for double-spend vulnerability, emulating non-native field operations."

Governance

Admin Keys

  • Had Astria proposing to become its sequencing layer, 16 days later, no responses on it yet (22-4-2024).
  • Claims the next version of Aztec will be fully decentralized (29-8-2023).
  • From L2beat regarding both Aztec and Aztec Connect (31-10-2022):

"The system has a centralized operator. Only specific addresses appointed by the owner are permitted to propose new blocks during regular rollup operation. Periodically a special window is open during which anyone can propose new blocks. Users can be censored if the operator refuses to include their transactions and users lack resources to propose blocks themselves."

DAO

Treasury

zkTokens

  • Does not have a token itself, but releases zk Tokens. The first of which at the launch (1-2-2020) was zkDai. "Over the coming six weeks we’ll release other zk Tokens onto the network, and in two months’ time we will remove restrictions so you can make completely private custom assets from scratch."
  • From this article by TrustNodes (10-2-2020):

"You need to deposit dai through the ZkDai (zkassetdetailed) contract, through a zero knowledge proof.” Aztec turns dai into what can be described as a smart contract database asset. You send the dai to Aztec, and you get zkdai which gives you a claim to the dai.

You can transfer this zkdai within the smart contract environment, but the blockchain won’t know until you convert it into dai. In the meantime you’re exchanging value in a very private manner. End users can’t quite play yet with Aztec because an app is not out, but devs can incorporate it through a tutorial of sorts."

Tech

  • Whitepaper can be found [insert here].
  • Code can be viewed [insert here]. From their blog (10-6-2021): "Aztec initially realeased some of its prover code under the Polaris license jointly created with StarkWare. Today we announce that all future releases of code from Aztec will be under the open source Apache 2.0 license."
  • Built on: L2 on Ethereum
  • Programming language used: Solidity

Transaction Details

How it works

"Validity proofs ensure state correctness. Each update to the system state must be accompanied by a ZK Proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. Once the proof is processed on the Ethereum blockchain the L2 block is instantly finalized.

All the data that is used to construct the system state is published on chain in the form of cheap calldata. This ensures that it will always be available when needed."

"Aztec has deployed the two core components of its technology today:

  1. Aztec Crypto Engine (ACE) — our smart contract validator on Ethereum mainnet, checking the correctness of every private transaction
  2. Privacy SDK — abstracts away the complexities of Aztec’s cryptography, so developers can integrate privacy into their dapps with ease"

Fees

Upgrades

"Aztec announced it is unrolling a set of tools, dubbed Aztec Connect, to let developers add its privacy feature to a wide variety of protocols by using a software bridge. "It allows users to confidentially access world-class DeFi services on Ethereum with up to 100x cost savings, all while strengthening Aztec’s existing privacy guarantees. At launch, Aztec Connect extends the capabilities of zk.money, adding whitelisted functionality from select blue-chip DeFi partners," said the company in a blog post."

  1. "zkRollup based Layer 2 network, live on Ropsten
  2. Private sends by default — shield and send your ERC-20s privately
  3. 200x gas reduction compared to Aztec 1.0
  4. Secure by design: all transactions are validated on-chain
  5. Programmable Privacy with Noir — The private contract language"

Staking and Fernet

  • From their docs (9-2023):

"Fair Election Randomized Natively on Ethereum Trustlessly (Fernet) is a protocol for random sequencer selection. In each iteration, it relies on a VRF to assign a random score to each sequencer in order to rank them. The sequencer with the highest score can propose an ordering for transactions and the block they build upon, and then reveal its contents for the chain to advance under soft finality. Provers must then assemble a proof for this block and submit it to L1 for the block to be finalised.

Sequencers are required to stake on L1 in order to participate in the protocol. Each sequencer registers a public key when they stake, which will be used to verify their VRF submission. After staking, a sequencer needs to wait for an activation period of N L1 blocks until they can start proposing new blocks. Unstaking also requires a delay to allow for slashing of dishonest behaviour."

Validation

"bitcoiners would argue that because you can’t validate yourself, you can’t be sure zkdai or zcash has not been printed out of thin air.

“That’s not actually true — the point of a parity check is to prove that each transaction has a net zero effect on supply,” says Tom Walton-Pocock, after further adding: “I think I’d return with the question ‘under what conditions can the parity check over Aztec’s encrypted balances fail?’."

Zk-Zk Rollup

  • Is putting Zk's inside Zk's (24-4-2020):

"With this code, we can efficiently verify a SNARK inside another SNARK.

In ZK² Rollup, the spender makes a private transaction on their own device, keeping their data secret — this is a ‘proof computation’.

Instead of sending straight to Ethereum (too expensive), they send to a ‘rollup provider’, which aggregates 1,000s of transactions into a ‘rollup proof’. This collapses the gas cost on Ethereum, and makes our payments network scale.

Here are the benchmarks we’d like (in a perfect world):

  1. ~1s proof construction times on smartphones
  2. ~10s proof construction times for rollups (server-side)
  3. ~1,000tps on mainnet
  4. 3 layer recursion — proofs of proofs of proofs"

Interoperability

"In the next month, the team will launch Aztec Connect, the first private bridge to Ethereum DeFi, unlocking privacy and scale for leading DeFi projects like Element and Lido."

Other Details

Oracle Method

Privacy Method

"When you make a deposit to shield crypto via zk.money, you receive encrypted notes on Aztec, e.g. zkETH or zkDAI.

If you send these notes to someone else who’s on zk.money they’ll receive zkETH/zkDAI on Aztec, and if you send the notes to someone who’s not on zk.money they’ll simply receive ETH/DAI on the Ethereum L1. In the latter case your send is also private, since the recipient will only see that the funds came from the Aztec smart contract and not your address specifically."

  • From Bankless (22-7-2022):

"While complex, at a high-level this architecture functions similar to a UTXO-model and uses zk-proofs to transfer ownership of assets, while simultaneously protecting the identities of any parties involved."

"Aztec's privacy-first zkRollup has also amassed a significant anonymity set, with the 0.1 ETH deposit set ~60% of the size of Tornado Cash's for the same deposit amount."

  • From Bankless (15-4-2021):

"Beyond private Ethereum transactions on the platform, which help users protect their privacy and save on gas costs, Aztec can be used as your anonymous DeFi wallet. In other words, it can be used to wash and anonymize your funds if you’re ever trying to fund a new address.

When sending zkETH from zk.money to a regular Ethereum address, the recipient will receive regular, "unshielded" ETH directly to the wallet. The trick here is that Etherscan will show the funds were sent from the 'Aztec Contract' and not the sender's address.

By using Aztec, you could fund new DeFi wallets without worrying someone may track your trail of breadcrumbs. Better yet, you could use zk.money to protect your funds!"

Compliance

Their Other Projects

Aztec Connect

"Aztec Connect provides users with the ability to directly interact with smart-contracts that are deployed on L1 from within the L2. This means that users can inherit Aztec’s privacy while also accessing the liquidity and composability of dapps on Ethereum. Further, Aztec users also pay minimal gas fees despite the direct interaction with L1 because, like with any rollup, gas fees are still batched and amortized across all transactors."

"In the next month, the team will launch Aztec Connect, the first private bridge to Ethereum DeFi, unlocking privacy and scale for leading DeFi projects like Element and Lido. Meanwhile, Aztec has crossed 4,200 shielded ETH in the system, with over $15m total TVL."

Roadmap

  • From their blog (27-3-2020):

"Our privacy roadmap is as follows:

  1. ✅ Balance privacy — hiding transaction amounts
  2. ⌛ User privacy (coming soon) — hiding ‘spender’ and ‘receiver’ info
  3. ✘ Code privacy — hiding asset/code being spent/run"

Usage

"Aztec’s privacy-enhancing protocol has more than 70,000 unique users who have deposited over 60,000 ETH ($75M) in its smart contracts since it launched in July, according to a Dune Analytics dashboard."

"zk.money has helped facilitate over 250,000 private crypto transactions to date. Aztec currently has ~$2.8M in total value locked (TVL) across mainly ETH and DAI deposits."

  • From Bankless (22-7-2022):

"Per L2 Beat, Aztec Connect currently has $3.12M in TVL."

"Aztec's first-party private payments app, zk.money, is nearing $100m in all-time deposits and 60k registered users, with steady growth since launch."

  • JPMorgan's blockchain team trialed Aztec during a series of ZKP tests in February 2018.

Projects that use or built on it

Competition

Pros and Cons

Pros

Cons

"The system has a centralized operator."

Team, Funding, Partners, etc.

Funding

"Aztec Network is proud to announce $100 million in Series B financing led by a16z crypto, with participation from A Capital, King River, Variant, SV Angel, Hash Key, Fenbushi, and AVG."

"Raised $17 million. Crypto investment giant Paradigm led the latest funding round for Aztec, while other investors included Ethereal Ventures and Vitalk Buterin himself."

Consensys, a_capital, Coinbase, Mov37, Samos Investments and ef.

"So how are they going to make money?

“On value capture we’re not passing detailed comment on that now (not least because the blockchain and zero-knowledge landscape is changing at a breathless pace at the moment). We will lay out our model publicly at a later date,” Walton-Pocock says."

  • ConsenSys led a $2.1 million funding round for Aztec in November 2019.

Partners

"Polaris license under which StarkWare plans to release source code for its STARK prover; Aztec will use the same Polaris license for its PLONK provers (see their post)."