Docs / Commitment tree
Protocol
The commitment tree
Where commitments are stored and how proofs refer to them.
On this page
Append-only by design
Every new commitment, from shrouds, transfers and change outputs, is appended as the next leaf of a Merkle tree of depth 24. Nothing is ever removed: spent notes stay in the tree and are excluded only by their nullifiers. That keeps an exit from revealing which leaf was spent.
Recent roots
Each insertion produces a new root. The contract keeps a ring of the 100 most recent roots, so proofs made a few blocks earlier still verify. Which root a wallet chooses can itself leak timing; see the root timing note.