In Q3 b, it is stated that in zerocoin the size of the proof statement to be proven scales with all zerocoins ever created.
If I understand correctly then the reason is from lec 9 slides slide 32: "Create zero-knowledge proof that: “You know a string r such that C=H(S, r) is one of the zerocoins "C" _1,…,"C" _𝑁 in the block chain”
i.e. all the coins are part of the statement.
Why do we need the coins to be part of the statement? the coins C_1,.. C_N are public and on the chain itself, so anyone can read them, why don't you generate a proof for the statement: “You know a string r such that C=H(S, r) is one of the zerocoins in the block chain"
Thanks