# Noir

**URL:** https://forum.aztec.network/c/noir/7.md

[Latest](https://forum.aztec.network/latest.md) · [Categories](https://forum.aztec.network/categories.md) · [Tags](https://forum.aztec.network/tags.md)

---

## [About the Noir category](https://forum.aztec.network/t/about-the-noir-category/40)

<div class="topic-metadata">

**Author:** [@joshc](https://forum.aztec.network/u/joshc)\
**Replies:** 0\
**Last updated:** [December 15, 2022, 6:01pm UTC](https://forum.aztec.network/t/about-the-noir-category/40 "2022-12-15T18:01:50Z")

</div>

Use this category to discuss topics related to Noir (book, GitHub).

---

## [Review my Noir - Ed25519 signature verification](https://forum.aztec.network/t/review-my-noir-ed25519-signature-verification/8604)

<div class="topic-metadata">

**Author:** [@willemolding](https://forum.aztec.network/u/willemolding)\
**Replies:** 0\
**Last updated:** [June 29, 2026, 5:51am UTC](https://forum.aztec.network/t/review-my-noir-ed25519-signature-verification/8604 "2026-06-29T05:51:02Z")

</div>

I’ve built an IRTF RFC-8032 compliant implementation of Ed25519 signature verification in Noir. This was able to reuse a lot of existing pieces so ended up being fairly straightforward (but expensive in terms of gate cou…

---

## [noir-rlwe-gadgets — verifiable BFV encryption (RLWE) in Noir, with an on-chain UltraHonk verifier](https://forum.aztec.network/t/noir-rlwe-gadgets-verifiable-bfv-encryption-rlwe-in-noir-with-an-on-chain-ultrahonk-verifier/8591)

<div class="topic-metadata">

**Author:** [@aryaethn](https://forum.aztec.network/u/aryaethn)\
**Replies:** 0\
**Last updated:** [June 15, 2026, 12:39pm UTC](https://forum.aztec.network/t/noir-rlwe-gadgets-verifiable-bfv-encryption-rlwe-in-noir-with-an-on-chain-ultrahonk-verifier/8591 "2026-06-15T12:39:50Z")

</div>

I’ve published noir-rlwe-gadgets, a Noir library that proves a BFV ciphertext is a well-formed encryption of a bounded message — both secret-key (the Greco statement) and public-key (the fhEVM-style input statement, wher…

---

## [On the usability differences between Poseidon and Poseidon2](https://forum.aztec.network/t/on-the-usability-differences-between-poseidon-and-poseidon2/8233)

<div class="topic-metadata">

**Author:** [@noirztec](https://forum.aztec.network/u/noirztec)\
**Replies:** 11\
**Last updated:** [January 10, 2026, 11:04am UTC](https://forum.aztec.network/t/on-the-usability-differences-between-poseidon-and-poseidon2/8233 "2026-01-10T11:04:59Z")

</div>

Looking at the Poseidon2 constants in here, unlike the Poseidon constants (which support t ≤ 17), they are fixed at t = 4. I would like to use the Poseidon2 hash for a simple circuit over the bn254 field, but I also fou…

---

## [How do I generate a proof in noir\_js](https://forum.aztec.network/t/how-do-i-generate-a-proof-in-noir-js/8135)

<div class="topic-metadata">

**Author:** [@qbzzt](https://forum.aztec.network/u/qbzzt)\
**Replies:** 2\
**Last updated:** [October 13, 2025, 3:01pm UTC](https://forum.aztec.network/t/how-do-i-generate-a-proof-in-noir-js/8135 "2025-10-13T15:01:12Z")

</div>

I want to generate a proof inside a Node server, and then submit it onchain for verification. I create the witness and result: \`\`\`js noirResult = await noir.execute({ \<parameters go here\> }) \`\`\` But I …

---

## [UltraPlonk/Honk is failing while trying to run it in hardhat](https://forum.aztec.network/t/ultraplonk-honk-is-failing-while-trying-to-run-it-in-hardhat/8136)

<div class="topic-metadata">

**Author:** [@Shivannsh](https://forum.aztec.network/u/Shivannsh)\
**Replies:** 1\
**Last updated:** [October 1, 2025, 3:15pm UTC](https://forum.aztec.network/t/ultraplonk-honk-is-failing-while-trying-to-run-it-in-hardhat/8136 "2025-10-01T15:15:34Z")

</div>

It seems like the issue is that UltraPlonkBackend tries to use web workers for multithreading by default, but in Node.js environments like Hardhat, the worker thread initialization fails because threads.workerData is und…

---

## [Sumcheck fail in Ultrahonk](https://forum.aztec.network/t/sumcheck-fail-in-ultrahonk/8112)

<div class="topic-metadata">

**Author:** [@pardis-toolabi](https://forum.aztec.network/u/pardis-toolabi)\
**Replies:** 0\
**Last updated:** [September 2, 2025, 2:38pm UTC](https://forum.aztec.network/t/sumcheck-fail-in-ultrahonk/8112 "2025-09-02T14:38:14Z")

</div>

Hi every one, We are working on a noir circuit with bb and ultra honk, where we came across the “0x9fc3a218” custom error in verifying the proof on chain, which is the Sumcheck fail in Ultrahonk, the verifier generatio…

---

## [Benchmark for Verification Cost Across Noir Proof Backends?](https://forum.aztec.network/t/benchmark-for-verification-cost-across-noir-proof-backends/8061)

<div class="topic-metadata">

**Author:** [@yappo](https://forum.aztec.network/u/yappo)\
**Replies:** 0\
**Last updated:** [July 8, 2025, 1:05am UTC](https://forum.aztec.network/t/benchmark-for-verification-cost-across-noir-proof-backends/8061 "2025-07-08T01:05:29Z")

</div>

Hi all, I’m exploring Noir for zk circuit development and noticed it supports multiple proof system backends like UltraHonk, UltraPlonk, Groth16, and Plonk. I was wondering – is there any benchmark comparing their provi…

---

## [Counter Contract Tutorial](https://forum.aztec.network/t/counter-contract-tutorial/6551)

<div class="topic-metadata">

**Author:** [@mundabor](https://forum.aztec.network/u/mundabor)\
**Replies:** 3\
**Last updated:** [June 19, 2025, 6:57pm UTC](https://forum.aztec.network/t/counter-contract-tutorial/6551 "2025-06-19T18:57:46Z")

</div>

I installed and ran the aztec sandbox, followed the quickstart and installed the noir-lsp extension in cursor. Now I’m trying to follow the Counter Contract tutorial, but I’m getting a ton of errors when I try to compile…

---

## [Is the \`index\` of a \`MemOp\` always a single witness index?](https://forum.aztec.network/t/is-the-index-of-a-memop-always-a-single-witness-index/7649)

<div class="topic-metadata">

**Author:** [@atonable-strobe](https://forum.aztec.network/u/atonable-strobe)\
**Replies:** 0\
**Last updated:** [April 4, 2025, 4:53pm UTC](https://forum.aztec.network/t/is-the-index-of-a-memop-always-a-single-witness-index/7649 "2025-04-04T16:53:15Z")

</div>

The ACVM code allows the index field to be an Expression involving of multiple witness indices (see below). However, in all the Noir code that I’ve compiled, the index Expression is always a single witness index. Can t…

---

## [When I integrate Noir into my Rust, how do I ensure that I am using the right cryptographic functions that Noir uses in Rust? How ](https://forum.aztec.network/t/when-i-integrate-noir-into-my-rust-how-do-i-ensure-that-i-am-using-the-right-cryptographic-functions-that-noir-uses-in-rust-how/7583)

<div class="topic-metadata">

**Author:** [@wu-s-john](https://forum.aztec.network/u/wu-s-john)\
**Replies:** 1\
**Last updated:** [March 23, 2025, 10:27pm UTC](https://forum.aztec.network/t/when-i-integrate-noir-into-my-rust-how-do-i-ensure-that-i-am-using-the-right-cryptographic-functions-that-noir-uses-in-rust-how/7583 "2025-03-23T22:27:18Z")

</div>

So, right now, I am programming a Solana program right now. So, I need to program my code in Rust. I am basically trying to construct a membership proof using Merkle Trees. Namely, I am using BabyJubJub as my scalar fiel…

---

## [Is there a way to run a noir crypto primitives and functions in Rust without proofs? How do I construct witnesses for my proof easily](https://forum.aztec.network/t/is-there-a-way-to-run-a-noir-crypto-primitives-and-functions-in-rust-without-proofs-how-do-i-construct-witnesses-for-my-proof-easily/7579)

<div class="topic-metadata">

**Author:** [@wu-s-john](https://forum.aztec.network/u/wu-s-john)\
**Replies:** 0\
**Last updated:** [March 21, 2025, 8:54pm UTC](https://forum.aztec.network/t/is-there-a-way-to-run-a-noir-crypto-primitives-and-functions-in-rust-without-proofs-how-do-i-construct-witnesses-for-my-proof-easily/7579 "2025-03-21T20:54:58Z")

</div>

Hi everyone, Currently, I am trying to build a Solana Smart contract with Noir. So, I would like to generate my proofs locally via the command line and then use a verifier written in Rust to easily verify my generated p…

---

## [Need some suggestion in setting up a Noir circuit](https://forum.aztec.network/t/need-some-suggestion-in-setting-up-a-noir-circuit/7558)

<div class="topic-metadata">

**Author:** [@keccak256](https://forum.aztec.network/u/keccak256)\
**Replies:** 0\
**Last updated:** [March 17, 2025, 1:14pm UTC](https://forum.aztec.network/t/need-some-suggestion-in-setting-up-a-noir-circuit/7558 "2025-03-17T13:14:25Z")

</div>

Within the smart contract of a project which I’m building, for a function to be called I should be able to pass a proof of doing another transaction, what’s the best way to do this Noir? Kinda noob in ZK, so can someone…

---

## [Noir vs Other zk Languages](https://forum.aztec.network/t/noir-vs-other-zk-languages/6264)

<div class="topic-metadata">

**Author:** [@udonnelly](https://forum.aztec.network/u/udonnelly)\
**Replies:** 7\
**Last updated:** [February 21, 2025, 10:06pm UTC](https://forum.aztec.network/t/noir-vs-other-zk-languages/6264 "2025-02-21T22:06:58Z")

</div>

What are the key benefits of learning Noir as opposed to other zk languages ​​like Cairo for someone new to zk-SNARKs?

---

## [Which plonky2 repo to use with noir?](https://forum.aztec.network/t/which-plonky2-repo-to-use-with-noir/7425)

<div class="topic-metadata">

**Author:** [@illuzen](https://forum.aztec.network/u/illuzen)\
**Replies:** 0\
**Last updated:** [January 21, 2025, 2:49pm UTC](https://forum.aztec.network/t/which-plonky2-repo-to-use-with-noir/7425 "2025-01-21T14:49:48Z")

</div>

I see the noir docs recommend which pulls in which is a fork (1 commit ahead, 31 commits behind) of which has since released it’s version 1.0.0… and all of these say they are unaudited and should not be used in…

---

## [Yul exception:Could not create stack layout after 1000 iterations.](https://forum.aztec.network/t/yul-exception-could-not-create-stack-layout-after-1000-iterations/7111)

<div class="topic-metadata">

**Author:** [@fabriziogianni7](https://forum.aztec.network/u/fabriziogianni7)\
**Replies:** 2\
**Last updated:** [November 12, 2024, 12:35pm UTC](https://forum.aztec.network/t/yul-exception-could-not-create-stack-layout-after-1000-iterations/7111 "2024-11-12T12:35:16Z")

</div>

Hey there :slight\_smile: I wrote a fairly simple circuit and I generated a UltraVerifier for it: Now, when I try to deploy the contract I got the following error: Yul exception:Could not create stack layout after 1000 …

---

## [How do I hash a file of arbitrary size?](https://forum.aztec.network/t/how-do-i-hash-a-file-of-arbitrary-size/6989)

<div class="topic-metadata">

**Author:** [@qbzzt](https://forum.aztec.network/u/qbzzt)\
**Replies:** 2\
**Last updated:** [November 7, 2024, 6:34pm UTC](https://forum.aztec.network/t/how-do-i-hash-a-file-of-arbitrary-size/6989 "2024-11-07T18:34:19Z")

</div>

I need to prove that a person knew a file with a publicly known blake3 hash. The way I’d like to do it is to provide the file as a private parameter, the blake3 hash as a public parameter, and a signed message as another…

---

## [Privacy smart contract coding](https://forum.aztec.network/t/privacy-smart-contract-coding/2483)

<div class="topic-metadata">

**Author:** [@yp945](https://forum.aztec.network/u/yp945)\
**Replies:** 3\
**Last updated:** [October 21, 2024, 9:32am UTC](https://forum.aztec.network/t/privacy-smart-contract-coding/2483 "2024-10-21T09:32:40Z")

</div>

Can I specify separate privacy or public function when writing a smart contract? Similar to Aleo, where privacy is executed locally to generate proofs and public data is stored on the chain. The privacy and public functi…

---

## [Can't generate proof with larger input](https://forum.aztec.network/t/cant-generate-proof-with-larger-input/6148)

<div class="topic-metadata">

**Author:** [@ani](https://forum.aztec.network/u/ani)\
**Replies:** 3\
**Last updated:** [October 1, 2024, 7:59pm UTC](https://forum.aztec.network/t/cant-generate-proof-with-larger-input/6148 "2024-10-01T19:59:14Z")

</div>

Hi, I’m trying to generate proof with Noir JS for a linear regression circuit, but the issue is for same circuit (with dataset size changed) with fewer data size, the proof is generated and verified correctly, but when I…

---

## [AES-128-GCM proofs](https://forum.aztec.network/t/aes-128-gcm-proofs/5932)

<div class="topic-metadata">

**Author:** [@0xJepsen](https://forum.aztec.network/u/0xJepsen)\
**Replies:** 1\
**Last updated:** [August 6, 2024, 4:00pm UTC](https://forum.aztec.network/t/aes-128-gcm-proofs/5932 "2024-08-06T16:00:44Z")

</div>

I am interested in exploring noir to make some aes proofs as they are used in TLS. I notice that the standard lib has support for AES in CBC mode. The mode I would like to use is Galois Counter Mode which is a subset of …

---

## [Proving Correct Generation of an ECDH Secret Share Using Ethereum Private and Public Keys in ZKP](https://forum.aztec.network/t/proving-correct-generation-of-an-ecdh-secret-share-using-ethereum-private-and-public-keys-in-zkp/5922)

<div class="topic-metadata">

**Author:** [@shuffle](https://forum.aztec.network/u/shuffle)\
**Replies:** 3\
**Last updated:** [August 4, 2024, 4:30pm UTC](https://forum.aztec.network/t/proving-correct-generation-of-an-ecdh-secret-share-using-ethereum-private-and-public-keys-in-zkp/5922 "2024-08-04T16:30:32Z")

</div>

Hello everyone, I’m reaching out with a specific question regarding ZKP in the context of generating an ECDH secret share using Ethereum keys. My goal is to determine if it is possible to prove, within a ZKP circuit, t…

---

## [How to use pedersen hash/commitment?](https://forum.aztec.network/t/how-to-use-pedersen-hash-commitment/2611)

<div class="topic-metadata">

**Author:** [@shuffle](https://forum.aztec.network/u/shuffle)\
**Replies:** 2\
**Last updated:** [July 26, 2024, 8:57am UTC](https://forum.aztec.network/t/how-to-use-pedersen-hash-commitment/2611 "2024-07-26T08:57:05Z")

</div>

I’ve been exploring Pedersen hash/commitment and encountered some challenges while attempting to generate the same hash in both JavaScript and Noir. Despite my efforts, I haven’t achieved the desired outcome. Here the …

---

## [Generating Random Numbers - PrivateKeys](https://forum.aztec.network/t/generating-random-numbers-privatekeys/5921)

<div class="topic-metadata">

**Author:** [@YashBit](https://forum.aztec.network/u/YashBit)\
**Replies:** 1\
**Last updated:** [July 24, 2024, 8:40pm UTC](https://forum.aztec.network/t/generating-random-numbers-privatekeys/5921 "2024-07-24T20:40:46Z")

</div>

Hi, How can I create a RandomKey of 32 bytes to use in an encryption algorithm in Noir? Best, Yash.

---

## [Contract storage member](https://forum.aztec.network/t/contract-storage-member/2665)

<div class="topic-metadata">

**Author:** [@hhanh00](https://forum.aztec.network/u/hhanh00)\
**Replies:** 4\
**Last updated:** [December 21, 2023, 8:52pm UTC](https://forum.aztec.network/t/contract-storage-member/2665 "2023-12-21T20:52:07Z")

</div>

When I compile the tutorial code with nargo build, I hit the following error. error: cannot find \`storage\` in this scope ┌─ /Users/anonymous/aztec-packages/yarn-project/noir-contracts/src/contracts/counter\_contract/…

---

## [Preprocessing Arguments for Noir Circuits](https://forum.aztec.network/t/preprocessing-arguments-for-noir-circuits/5153)

<div class="topic-metadata">

**Author:** [@LucasAschenbach](https://forum.aztec.network/u/LucasAschenbach)\
**Replies:** 3\
**Last updated:** [March 28, 2024, 1:01pm UTC](https://forum.aztec.network/t/preprocessing-arguments-for-noir-circuits/5153 "2024-03-28T13:01:21Z")

</div>

Circuits must be fixed in size. However, one is often faced with dynamically sized objects which then require either recursion or dedicated circuits for every single size. At ETHGlobal London last weekend we were workin…

---

## [Safecat: a CLI tool to for digital signatures using Baby Jubjub Elliptic and Poseidon](https://forum.aztec.network/t/safecat-a-cli-tool-to-for-digital-signatures-using-baby-jubjub-elliptic-and-poseidon/4122)

<div class="topic-metadata">

**Author:** [@neiman](https://forum.aztec.network/u/neiman)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 3:27pm UTC](https://forum.aztec.network/t/safecat-a-cli-tool-to-for-digital-signatures-using-baby-jubjub-elliptic-and-poseidon/4122 "2024-02-27T15:27:15Z")

</div>

Hi everyone! I wrote a Rust project for generating, signing, and verifying digital signatures using EdDSA Baby Jubjub Elliptic Curve signatures and a Poseidon hash function. The outputs of this tool work with Noir, so …

---

## [Can't verify proof (RuntimeError: unreachable)](https://forum.aztec.network/t/cant-verify-proof-runtimeerror-unreachable/2703)

<div class="topic-metadata">

**Author:** [@shuffle](https://forum.aztec.network/u/shuffle)\
**Replies:** 3\
**Last updated:** [January 18, 2024, 6:16pm UTC](https://forum.aztec.network/t/cant-verify-proof-runtimeerror-unreachable/2703 "2024-01-18T18:16:32Z")

</div>

Hello Everyone, I have a nestJS project with noir\_js & backend\_barretenberg V0.19.4 I can generate a proof but I can’t verify it. const proof = await noir.generateFinalProof(inputs); const verify = await noir.v…

---

## [Question: Merkle root generation](https://forum.aztec.network/t/question-merkle-root-generation/516)

<div class="topic-metadata">

**Author:** [@porco](https://forum.aztec.network/u/porco)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 9:15pm UTC](https://forum.aztec.network/t/question-merkle-root-generation/516 "2024-01-03T21:15:37Z")

</div>

How could I successfully construct the correct values of the Merkle root, note hash path, and note commitment that actually works with Merkle-tree-involving stdlib functions and uses in Noir? For example 1: noir/merkle…

---

## [How to get pub\_X and Pub\_Y from metamask to use in verify ECDSA Signature?](https://forum.aztec.network/t/how-to-get-pub-x-and-pub-y-from-metamask-to-use-in-verify-ecdsa-signature/2671)

<div class="topic-metadata">

**Author:** [@Jumaru](https://forum.aztec.network/u/Jumaru)\
**Replies:** 3\
**Last updated:** [December 22, 2023, 8:26pm UTC](https://forum.aztec.network/t/how-to-get-pub-x-and-pub-y-from-metamask-to-use-in-verify-ecdsa-signature/2671 "2023-12-22T20:26:30Z")

</div>

According Noir docs the function has the following signature: fn verify\_signature(\_public\_key\_x : \[u8; 32\], \_public\_key\_y : \[u8; 32\], \_signature: \[u8; 64\], \_message: \[u8\]) -\> bool How can this be used with metamask sig…

---

## [How do I iterate over vectors?](https://forum.aztec.network/t/how-do-i-iterate-over-vectors/2628)

<div class="topic-metadata">

**Author:** [@moonmanfunnyman](https://forum.aztec.network/u/moonmanfunnyman)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 1:48am UTC](https://forum.aztec.network/t/how-do-i-iterate-over-vectors/2628 "2023-12-12T01:48:14Z")

</div>

I have this code, I want to iterate over this vector and do calculations and comparisions there but I can’t because it’s giving me the error for “loop bound couldn’t be determined during compile time” Thanks in advan…

[Next page](https://forum.aztec.network/c/noir/7.md?page=1)
