The original product vision includes an anonymous, single-use access credential system verified on-chain. Research which ZK proving system/circuit language fits best given Soroban's BN254 host function constraints (g1_msm, pairing_check) — Noir/UltraHonk (used in the original prototype), Circom, or alternatives.
Deliverable: A written comparison covering circuit complexity, Soroban verification cost, and tooling maturity, with a clear recommendation.
The original product vision includes an anonymous, single-use access credential system verified on-chain. Research which ZK proving system/circuit language fits best given Soroban's BN254 host function constraints (g1_msm, pairing_check) — Noir/UltraHonk (used in the original prototype), Circom, or alternatives.
Deliverable: A written comparison covering circuit complexity, Soroban verification cost, and tooling maturity, with a clear recommendation.