Nullifiers never leave the client (#68): the wormhole spent check reads padded, shuffled buckets of UsedNullifiers instead of looking each nullifier up by key. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ftBXYuba8ARhQeF74oUgW