Trusted setup looks clarified now, but I’d still like to understand the remaining security model.
When will the PoseidonT3/hasher source be published and verified?
Have the ZK circuits, verifier, ShieldedPool, relayer flow, and token/lending contracts been externally audited?
Can any admin, upgrade, pause, emergency, or parameter-change permission affect the pool, verifier, hasher, curve, lending logic, relayer, or USDS/sUSDS reserves?
Also, are the circuits, proving keys, verification keys, and frontend note-generation logic open source and reproducibly tied to the deployed verifier?
The transfer demo is helpful, but I want to separate “shielded transfers work” from “the full protocol security model is trustless and externally verifiable.”