Ethereum finality proofs
Connecting
$0.02 an epoch, in < 21 seconds
Light clients backed by 900,000 validators, not 512
Reading the proof feed…
- —
- Epochs proven
- —
- Median time to proof
- —
- Median cost per epoch
- —
- Proof size
The epoch in flight
- —
- Stake attested
- —
- Finalised by zkasper
Where the prover time goes
Time to proof, epoch by epoch
One column per epoch, split into the five terms of the time to proof.
Every epoch
Time to proof is the only latency a consumer waits on: two thirds of the stake attested, to a postable proof of it. One epoch every 6.4 minutes, at $343 a month on one rented RTX 5090.
The feed lists no proven epochs yet.
Verified on another chain
A zkasper proof checked by a program on another chain, as the submitter read the receipt.
Why not the sync committee512 validators, and nothing at stake
Helios, SP1 Helios and Telepathy all verify the Altair sync committee: 512 validators, resampled every 27 hours.
Altair defines no slashing condition for those messages: a corrupted committee can sign a header for a chain that does not exist and lose nothing.
zkasper proves the Casper FFG link, not two supermajorities that merely happen to be consecutive. That is what puts stake at risk: a two-thirds coalition reversing a proven finalisation has to surround its own vote, and a third of the stake burns.
A million BLS signatures an epoch was out of reach in 2021.
| Property | Sync committee light clients | zkasper |
|---|---|---|
| Signers | Sync committee512, rotating ~27h | zkasper901,832 — every active validator |
| Forging one takes | Sync committeeTwo thirds of 512 keys | zkasperTwo thirds of 42.3M staked ETH, attesting |
| Reversing one costs | Sync committeeNothing. Altair defines no slashing for these messages. | zkasperA third of all staked ETH, slashed |
| Security assumption | Sync committeeAn honest majority of a 512 sample | zkasperThe two-thirds threshold Ethereum itself runs on |
On Solana the full set cannot be checked natively at any price. 901,832 compressed pubkeys are 43.3 MB against a 10 MiB account cap, and aggregating them costs about 301M compute units against a 1.4M limit per transaction. A proof is not the cheap route. It is the only one.
The pipelineStages, folded into one proof
zkasper keeps an accumulator parallel to the beacon chain’s SSZ tree: 22 levels of Poseidon2 over Goldilocks, against 40 of SHA-256.
-
Epoch diff
Carry the accumulator forward one epoch, tracking exact effective balances.
-
Committee
Fix the epoch’s 32 slot committees from the RANDAO mix of two epochs back.
-
Slot proof
Check one slot’s attestations in a single multi-pairing.
-
Justification
Fold an epoch’s work. Check the two-thirds threshold.
-
Finalisation
Pair two justifications: a checkpoint and its successor.
Group proofs run as their attestation slots arrive, each fold extending a running aggregate. At T one final proof absorbs the late arrivals and emits the result. About a quarter of the epoch is never proven: the threshold comes first. Target: Zisk.
Measured, not estimatedCircuit numbers
Measured on mainnet state: 901,832 active validators, 99.7% attesting balance.
- 4.85×
- Accumulator node vs SSZ node Poseidon2 at 7,462 cost units against SHA-256 at 36,207.
- 19.9×
- Public key aggregation Driving the raw curve-add precompile at 2,730, against 54,241 through the safe wrapper.
- 167×
- Accumulator work per slot A slot proof opens the validators that did not attest, not the ones that did.
- 4.5s
- One slot, proven Measured on an RTX 5090, warm prover, Zisk v1.1.0-alpha.
Cost units are Zisk trace area, hardware-independent. Every latency and price on this page comes from the running prover.
Built
- Five circuits, epoch diff to finalisation
- Poseidon2-Goldilocks accumulator
- One multi-pairing per slot
- Recursive composition, outputs bound
- Witness generator on live beacon data
- Streaming pipeline to the finality threshold
- Continuous mainnet proving
- Solana verifier on devnet: one transaction, 476,587 CU
Shipping next
- EVM verifier
- Every epoch posted on Solana
- Light client integration
Verify it yourselfNothing here has to be taken on trust
Checking a proof needs no key material and no Zisk install: the verifier is a crates.io library whose only key is a 32-byte constant. It runs in 15 ms.
scripts/verify_published_proof.shreads an epoch’sverifyblock, fetches its proof words from/v1/proofs/<epoch>and runszkasper_common::recursion::verify_childon them.- Rebuild the guest at that commit and Zisk version. Its key must equal
program_vk. - Ask any beacon node whether the proven root is that epoch’s checkpoint.
- Recompute the accumulator chain digest from the epoch list against
/v1/status.
The digest is what makes a series of proofs a chain rather than a pile.