Three days on KeepHost. The most useful thing that happened was a bug we did not ship.
An independent review was pointed at the program, the circuit, the client and the relayer. One instruction: take the money, or lock it.
What it caught before deployment: the new fee would have broken the 0.1 SOL pool for everyone except token holders. The fee account is never funded, and the fee on that pool falls under Solana's rent-exempt minimum, so every deposit would have been rejected while holders, whose fee is zero, would have sailed through. A pool that works for insiders and fails for everyone else is the worst screenshot on this chain. It never reached mainnet.
What it cleared, if you write programs here: no under-constrained signal in the circuit. All seven binding signals survive compilation and all ten IC points in the verifying key are live, so a public input cannot be swapped against a fixed proof. The nine public inputs are in the same order on both sides. Every PDA is checked. No cross-pool substitution works. The tree insert was rewritten from scratch and matched leaf by leaf. No path moves a lamport out of a vault without a valid proof.
Also written since: association sets. A withdrawal can prove its deposit belongs to a set you choose the thing that keeps a shielded pool from being a mixer. The circuit carries the set root as a tenth public input. It ships with the next deploy.
That deploy waits on one thing, and it is not code. The proving key still comes from this project's own machines. Two contributions. Both ours. One person from outside, two minutes:
curl -L -o pot_in.ptau
keephost.fun/ceremony/pot15_…
npx snarkjs powersoftau verify pot_in.ptau
npx snarkjs powersoftau contribute pot_in.ptau pot_out.ptau --name="your handle" -v
github.com/KeepHost/system