Ethereum finality proofs

Connecting

$0.02 an epoch, in < 21 seconds
Light clients backed by 900,000 validators, not 512

Reading the proof feed…

Why not the sync committee512 validators, and nothing at stake
the lit dot ≈ the 512 of the sync committee 2,048 dots = 901,832 active validators, ~440 each

Helios, SP1 Helios and Telepathy all verify the Altair sync committee: 512 validators, resampled every 27 hours.

Altair defines no slashing condition for those messages: a corrupted committee can sign a header for a chain that does not exist and lose nothing.

zkasper proves the Casper FFG link, not two supermajorities that merely happen to be consecutive. That is what puts stake at risk: a two-thirds coalition reversing a proven finalisation has to surround its own vote, and a third of the stake burns.

A million BLS signatures an epoch was out of reach in 2021.

Property Sync committee light clients zkasper
Signers Sync committee512, rotating ~27h zkasper901,832 — every active validator
Forging one takes Sync committeeTwo thirds of 512 keys zkasperTwo thirds of 42.3M staked ETH, attesting
Reversing one costs Sync committeeNothing. Altair defines no slashing for these messages. zkasperA third of all staked ETH, slashed
Security assumption Sync committeeAn honest majority of a 512 sample zkasperThe two-thirds threshold Ethereum itself runs on

On Solana the full set cannot be checked natively at any price. 901,832 compressed pubkeys are 43.3 MB against a 10 MiB account cap, and aggregating them costs about 301M compute units against a 1.4M limit per transaction. A proof is not the cheap route. It is the only one.

The pipelineStages, folded into one proof

zkasper keeps an accumulator parallel to the beacon chain’s SSZ tree: 22 levels of Poseidon2 over Goldilocks, against 40 of SHA-256.

  1. Epoch diff

    Carry the accumulator forward one epoch, tracking exact effective balances.

  2. Committee

    Fix the epoch’s 32 slot committees from the RANDAO mix of two epochs back.

  3. Slot proof

    Check one slot’s attestations in a single multi-pairing.

  4. Justification

    Fold an epoch’s work. Check the two-thirds threshold.

  5. Finalisation

    Pair two justifications: a checkpoint and its successor.

Group proofs run as their attestation slots arrive, each fold extending a running aggregate. At T one final proof absorbs the late arrivals and emits the result. About a quarter of the epoch is never proven: the threshold comes first. Target: Zisk.

Measured, not estimatedCircuit numbers

Measured on mainnet state: 901,832 active validators, 99.7% attesting balance.

4.85×
Accumulator node vs SSZ node Poseidon2 at 7,462 cost units against SHA-256 at 36,207.
19.9×
Public key aggregation Driving the raw curve-add precompile at 2,730, against 54,241 through the safe wrapper.
167×
Accumulator work per slot A slot proof opens the validators that did not attest, not the ones that did.
4.5s
One slot, proven Measured on an RTX 5090, warm prover, Zisk v1.1.0-alpha.

Cost units are Zisk trace area, hardware-independent. Every latency and price on this page comes from the running prover.

Built

  • Five circuits, epoch diff to finalisation
  • Poseidon2-Goldilocks accumulator
  • One multi-pairing per slot
  • Recursive composition, outputs bound
  • Witness generator on live beacon data
  • Streaming pipeline to the finality threshold
  • Continuous mainnet proving
  • Solana verifier on devnet: one transaction, 476,587 CU

Shipping next

  • EVM verifier
  • Every epoch posted on Solana
  • Light client integration
Verify it yourselfNothing here has to be taken on trust

Checking a proof needs no key material and no Zisk install: the verifier is a crates.io library whose only key is a 32-byte constant. It runs in 15 ms.

  1. scripts/verify_published_proof.sh reads an epoch’s verify block, fetches its proof words from /v1/proofs/<epoch> and runs zkasper_common::recursion::verify_child on them.
  2. Rebuild the guest at that commit and Zisk version. Its key must equal program_vk.
  3. Ask any beacon node whether the proven root is that epoch’s checkpoint.
  4. Recompute the accumulator chain digest from the epoch list against /v1/status.

The digest is what makes a series of proofs a chain rather than a pile.