A VISUAL FIELD GUIDE TO CLIENT-SIDE VALIDATION

Bitcoin sees the anchor. The receiver verifies the asset.

Six short films compare the architectures, trace their proof models, measure performance, and put formal verification inside its proper trust boundary.

06
FILMS 05:20 total runtime
1080P 30 frames per second
OPEN Research in motion

FIELD NOTE 01 / OVERVIEW

Four architectures. One comparison.

Shielded CSV, Taproot Assets, RGB, and Ultraviolet—compared by privacy, proof growth, Bitcoin footprint, and trust model.

01:00

THE PROTOCOLS / ONE AT A TIME

02 — 04

FIELD NOTE 02 / SHIELDED CSV

Private coins.
Public spend order.

The sender proves a valid private state transition, Bitcoin orders the spend, and the receiver gets a fresh coin plus a proof-carrying record.

  • 64 B on-chain footprint per transfer
  • O(1) receiver-side validation
  • PCD recursive proof-carrying data
00:45

FIELD NOTE 03 / TAPROOT ASSETS

Assets inside
Taproot outputs.

Asset commitments live beneath a Taproot output. Proof files move off-chain, trace lineage to genesis, and can travel over Lightning.

  • UTXO ownership and liveness
  • MS-SMT asset commitments
  • LN issued-asset channels
00:45

FIELD NOTE 04 / RGB

Contract state
Bitcoin never sees.

A single-use seal ties contract rights to a Bitcoin outpoint. The recipient receives a private consignment and replays the relevant history.

  • SEAL closes once on Bitcoin
  • CSV client-side validation
  • LOCAL contract state and history
00:45

FIELD NOTE 05 / MEASURED

Proof generation at phone speed.

The reference circuit contains 1,024 rows and 457 columns. Standard proofs complete in 70–84 ms on the measured laptop; hiding proofs trade more time and memory for privacy.

0.070–0.084s STANDARD PROVE
1.4ms STANDARD VERIFY
158.3KB STANDARD PROOF

Measured CPU benchmarks. Research software; not audited.

00:50

FIELD NOTE 06 / FORMAL VERIFICATION

The checker is part of the threat model.

Ultraviolet writes adversarial state models in Quint, checks their invariants with Apalache, replays generated traces against Rust, and applies Kani to selected production functions.

Then the July 2026 AI-assisted Collatz artifact shows the limit: two checkers accepted it through two different bugs. A green check proves only what the full toolchain actually checked.

7MODEL FILES
38MODEL CHECKS
3VERIFICATION TIERS
01:15

THE DESIGN QUESTION

How much history should
a receiver have to carry?

Ultraviolet explores constant-size receive proofs for private client-side validation on Bitcoin.