Kaspa One Stop

In brief

This page is source-sensitive. Treat application, covenant, proof, and readiness wording as bounded by the listed public sources and Open Questions.

What this page explains#

The RISC Zero Succinct source path is a verifier-specific review of image IDs, journal digest, seal, control proof, claim, and supported hash assumptions. This page sits in ZK, Groth16, And RISC Zero Succinct. It gives the topic a plain-language handle first, then shows the working idea, the mechanism, the source trail, and any limits that still matter. This category separates proof verification from application validity. Groth16 and RISC Zero Succinct can verify selected statements, while covenant scripts, successor checks, source limits, and accepted evidence still carry separate responsibility.

The writing follows a simple Kaspa documentation pattern: answer the practical question first, then link outward for details. The closest public sources for this page are RK-ZK-RISC0, RK-ZK-RISC0-RCPT, RK-ZK-RISC0-CLAIM, RK-ZK-RISC0-ERRORS, RK-ZK-TAGS. Local notes can help choose what to explain, but public-facing references resolve to upstream websites, repositories, papers, release pages, or docs.

How to think about it#

The practical model starts by naming the layer that owns the topic: wallet use, node operation, consensus, transaction validation, Toccata script behavior, tooling, or research. From there, the page shows which public source can support the explanation and where the explanation becomes incomplete.

For RISC Zero Succinct Kaspa Verifier Source Path, the model is built around these anchors: mod.rs carries stack parsing and verifier entry behavior; rcpt.rs carries receipt integrity and control-root verification; receipt_claim.rs carries image and journal claim binding; unsupported hash or control paths fail by source-defined rules; negative tests are part of evidence. This model is useful, but it does not encode every constant, branch, error type, or edge case. Those details belong in the source path and the source notes.

How it works#

1. mod.rs carries stack parsing and verifier entry behavior. Script validation still owns the surrounding transaction rule. Even if a proof verifies, the script must receive the expected stack items, check the relevant transaction context, and enforce the successor output or state commitment that the application requires.

2. rcpt.rs carries receipt integrity and control-root verification. RISC Zero Succinct material has a different shape from circuit-specific Groth16. The image ID, journal or digest, receipt/seal data, claim data, and verifier assumptions define what execution claim is being checked. The Kaspa-facing page must then connect that checked claim to script stack format, compute cost, covenant binding, negative cases, and accepted-state evidence.

3. receipt_claim.rs carries image and journal claim binding. A proof output is useful only when the application binds it to the old state, new state, covenant ID or script context, and public input or journal. Without that binding, a valid proof may still be irrelevant to the UTXO transition being spent.

4. unsupported hash or control paths fail by source-defined rules. RISC Zero Succinct material has a different shape from circuit-specific Groth16. The image ID, journal or digest, receipt/seal data, claim data, and verifier assumptions define what execution claim is being checked. The Kaspa-facing page must then connect that checked claim to script stack format, compute cost, covenant binding, negative cases, and accepted-state evidence.

5. negative tests are part of evidence. RISC Zero Succinct material has a different shape from circuit-specific Groth16. The image ID, journal or digest, receipt/seal data, claim data, and verifier assumptions define what execution claim is being checked. The Kaspa-facing page must then connect that checked claim to script stack format, compute cost, covenant binding, negative cases, and accepted-state evidence.

This mechanism section separates proof verification from application validity. A verifier result still needs script binding, covenant checks, transaction validity, and accepted-state evidence before an app claim is closed.

How to check it#

StepCheckEvidence gate
1Check mod.rs carries stack parsing and verifier entry behavior.Read RK-ZK-RISC0, RK-ZK-RISC0-RCPT, RK-ZK-RISC0-CLAIM; verify proof format, tag, cost, public input or journal binding, and script failure cases.
2Check rcpt.rs carries receipt integrity and control-root verification.Read RK-ZK-RISC0, RK-ZK-RISC0-RCPT, RK-ZK-RISC0-CLAIM; verify proof format, tag, cost, public input or journal binding, and script failure cases.
3Check receipt_claim.rs carries image and journal claim binding.Read RK-ZK-RISC0, RK-ZK-RISC0-RCPT, RK-ZK-RISC0-CLAIM; verify proof format, tag, cost, public input or journal binding, and script failure cases.
4Check unsupported hash or control paths fail by source-defined rules.Read RK-ZK-RISC0, RK-ZK-RISC0-RCPT, RK-ZK-RISC0-CLAIM; verify proof format, tag, cost, public input or journal binding, and script failure cases.
5Check negative tests are part of evidence.Read RK-ZK-RISC0, RK-ZK-RISC0-RCPT, RK-ZK-RISC0-CLAIM; verify proof format, tag, cost, public input or journal binding, and script failure cases.

When using this page for ZK material, separate proof verification from application validity. Check the verifier path, proof format, public inputs or journal, compute cost, covenant binding, failure cases, and accepted evidence before claiming a transition is valid.

  • 06-risc-zero-succinct-overview
  • zk-groth16-risczero
  • 08-proof-binding-to-covenant-state
Source-linkedReviewed 2026-07-09 · 6 public sources · 1 open questionEvidence and sources
Evidence and sources6 public sources · reviewed 2026-07-09
RISC Zero ReceiptsPublic source
dev.risczero.com/api/zkvm/receipts
Technical details

Reference key: RISCZERO-RECEIPTS

Recheck this public source before relying on exact current details.