Related protocols and standards
EIP-196 / EIP-197
Ethereum precompiles for BN254 operations and pairings. The choice of curve here mirrors widely deployed systems.
Tornado Cash
Ethereum privacy pool that introduced practical nullifier + commitment constructions for asset mixing.
Zcash Sapling
Mature shielded transaction system whose note / nullifier / Merkle design strongly informs this protocol.
Semaphore
Protocol for anonymous signalling that popularised nullifier-based anonymity sets.