All Capabilities/Engineering/ENGINEERING / ZK & PROTOCOL
02.1 / ENGINEERING / ZK & PROTOCOL

Groth16, MPC, TEEs
& protocol primitives.

We design and ship production privacy stacks, zero-knowledge circuits, and low-level protocol primitives that verify cleanly within real on-chain compute budgets.

256 BGROTH16 PROOF PAYLOAD

Compact A(64B) + B(128B) + C(64B) BN254 proof verified in a single transaction.

~175k CUSOLANA PAIRING SYSCALLS

Native alt_bn128_addition, multiplication, and pairing checks on Solana L1.

3-of-3MPC + SEV-SNP ENCLAVE

Zero single-node plaintext exposure across storage and Merkle root generation.

01 / FOUNDER PERSPECTIVE

Why a single privacy primitive is never enough in production.

WHY MOST TEAMS STALL HERE

Many teams assume that dropping a basic ZK circuit into a protocol makes it "private." In practice, if plaintext inputs sit in a central database, if commitment roots are computed on an untrusted server, or if on-chain payouts transfer exact amounts straight to a recipient’s wallet, observers can still reconstruct the entire graph via timing and amount correlation.

HOW WE ENGINEER IT AT WEB3SPELL LABS

As we proved with Civitas on Solana, real protocol privacy requires defense-in-depth across storage, compute, proof verification, and settlement. We combine MPC secret-sharing (Nillion nilDB), hardware-attested TEE enclaves (nilCC AMD SEV-SNP), Circom Groth16 circuits verified via native syscalls, and settlement splitting, all within a sub-200k CU on-chain budget.

02 / TECHNICAL ARCHITECTURE & SCOPE

What we actually
design and ship.

No vague retainers or slide-deck theater. Every engagement in this practice is decomposed into concrete engineering and design workstreams.

01ZK CIRCUITS

Circom & Noir Zero-Knowledge Circuit Engineering

We write tightly constrained arithmetic circuits for confidential claims, solvency proofs, selective-disclosure identity (SoulPass), and private state transitions.

SPECIFICATIONS & ARTIFACTS
  • Poseidon hash commitments, depth-20 Merkle inclusion proofs & nullifier binding
  • Signal-tagging and recipient-binding constraints to prevent front-running
  • Browser-native WebAssembly witness generation + snarkjs Groth16 proving
02ON-CHAIN VERIFIERS

On-Chain Verifier Optimization (Solana & EVM)

A circuit is useless if verifying it exceeds block compute limits. We engineer custom on-chain verifiers that execute in a fraction of standard gas/CU budgets.

SPECIFICATIONS & ARTIFACTS
  • Solana Rust verifiers using solana_nostd_entrypoint & alt_bn128 syscalls
  • EVM Solidity/Yul BN254 pairing precompile verifiers
  • PDA/mapping nullifier registries with replay-protection invariants
03BLIND COMPUTE

MPC, TEE Enclaves & Ephemeral Rollups

We integrate zero-knowledge proofs with multi-party computation and Trusted Execution Environments for workloads that require multi-party private state.

SPECIFICATIONS & ARTIFACTS
  • Nillion nilDB (`%allot` secret-sharing across independent MPC nodes)
  • Nillion nilCC (AMD SEV-SNP hardware-attested enclaves for blind batch compute)
  • MagicBlock Ephemeral Rollups & TEE-backed private payment splitting
04PROTOCOL DESIGN

0-to-1 Protocol Mechanism & Whitepaper Engineering

We partner with founders at the earliest stage to formalize cryptographic relations, game-theoretic incentives, and formal whitepapers that stand up to institutional scrutiny.

SPECIFICATIONS & ARTIFACTS
  • Formal mathematical specification of commitments, invariants, and payoff matrices
  • Account abstraction (ERC-4337 / EIP-7702) & gasless relayer architectures
  • Authoritative technical whitepapers and architecture dossiers
03 / EXECUTION CADENCE

How an engagement
runs week by week.

Direct Slack/Telegram channel with our founders and engineers, weekly shippable milestones, and clean handoff to your internal team.

01Week 1–2

Threat Model & Cryptographic Spec

We define exactly what must remain private or verifiable, what each actor is allowed to see, and the formal circuit constraints.

OUTPUTCryptographic Spec & Threat Matrix
02Week 3–5

Circuit & Enclave Implementation

We write the Circom/Noir circuits, configure the MPC/TEE pipelines, and benchmark client-side proving times.

OUTPUTCompiled Circuits & Proving Pipeline
03Week 5–7

On-Chain Verifier & Nullifier State

We build the Solana or EVM verifier contract, nullifier storage, and token settlement hooks.

OUTPUTOn-Chain Verifier & Settlement Suite
04Week 7–8

End-to-End Integration & Benchmarks

We wire the browser prover, relayer, and on-chain verifier into a unified SDK and verify compute/gas benchmarks.

OUTPUTProduction ZK Protocol & Benchmarks
WHO THIS IS BUILT FOR
  • Teams building confidential payroll, private DeFi, dark pools, or compliant selective-disclosure identity
  • Protocols integrating Nillion, MagicBlock, Aztec/Noir, or custom Groth16 circuits on Solana or EVM
  • Founders who need a rigorous cryptographic whitepaper translated into working, benchmarked code
TANGIBLE DELIVERABLES
  • Auditable Circom / Noir circuit source code & R1CS constraint tests
  • Solana (Rust) or EVM (Solidity) Groth16 on-chain verifier contract
  • MPC / TEE enclave worker scripts & hardware attestation verifiers
  • Browser WebWorker proving SDK & gasless relayer service
  • Formal cryptographic whitepaper & compute-unit benchmark dossier
PRODUCTION STACK & TOOLING
Circom 2.1.6 / SnarkJSGroth16 / BN254Solana alt_bn128 SyscallsPoseidon CommitmentsNillion nilDB & nilCC (SEV-SNP)MagicBlock TEEERC-4337 / EIP-712
SHIPPED PROOF · CIVITAS PROTOCOL

Civitas

Explore the Civitas dossier to inspect our 4-layer privacy stack, exact Poseidon/Groth16 equations, and 175k CU Solana on-chain verification trace.

READY WHEN YOU ARE

Bring us your
hardest problem.

Whether you need a focused 4-week intervention in groth16, mpc, tees or a complete 0-to-Hero protocol build, you work directly with our founders and senior engineers.

Start a project