In our fix, when commitment is used, we add a dummy constraint during the circuit compilation time which is then randomized by the prover at proving time. This approach allows us to keep the existing G16 verification equations with minimal prover overhead.