Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

Verifiable Delay Functions (VDF) & Wesolowski Proofs Studio

Model time-lock cryptographic puzzles and non-parallelizable sequential computing. Simulate modular squaring chains \(x^{2^T} \pmod N\), Wesolowski \(O(1)\) succinct proofs, Fiat-Shamir prime challenges, and sub-millisecond verification.

Time-Lock Crypto Wesolowski Proofs O(1) Verification Non-Parallelizable
Number of non-parallelizable modular squarings
Mathematical group with hidden order \(|G|\)
Zero-knowledge succinct argument of delay
Evaluator sequential multiplier hardware class

VDF Sequential Evaluation & Verification Pipeline

Sequential Steps
262,144
T = 2^18 Squarings
Evaluation Latency
4.77 sec
Enforced Sequential Delay
Verification Latency
0.64 ms
7,450x Asymmetric Speedup
Proof Size (π)
256 Bytes
1 Group Element (O(1))
Parallelism Gain
1.00x
0% GPU Speedup (Safe)
Fiat-Shamir Prime (ℓ)
128-bit
Soundness 2^-128

Live Wesolowski Proof Mathematical State Trace

Cryptographic Parameter Mathematical Symbol Value / Formula Role in Security Protocol
Input Entropy Seed x ∈ G 0x7a89f3...b4c2 Beacon seed from RANDAO or lottery hash
Sequential Output y = x^(2^T) mod N 0x3d91ea...7f01 Result of 262,144 non-parallelizable squarings
Fiat-Shamir Prime ℓ = H_prime(x, y) 0xFFFFFFFFFFFF...C7 Random challenge prime drawn from random oracle
Quotient & Remainder 2^T = q · ℓ + r q = ⌊2^T / ℓ⌋, r = 2^T mod ℓ Long integer polynomial division
Succinct Proof π = x^q mod N 0x82f091...a54e (256 bytes) Verifier verifies: π^ℓ · x^r ≡ y (mod N) in 0.64 ms

Production VDF Implementation (Rust & Python)


      

VDF Cryptographic Design & Attack Resistance

1. Strict Non-Parallelizability Unlike PoW mining (hash guessing), where 1,000 GPUs compute 1,000 hashes in parallel, calculating \(x^{2^T} = ((((x^2)^2)^2)...)\) has an inherent depth of \(T\). Parallelization yields 0 speedup because step \(k+1\) cannot start until step \(k\) is fully resolved.
2. Soundness Under Unknown Order If an attacker knows the group order \(\phi(N)\), they can compute \(e = 2^T \bmod \phi(N)\) via Euler's totient theorem and evaluate \(x^e \pmod N\) in \(O(\log T)\) time! Hence, the RSA trusted setup must discard \(p\) and \(q\), or Class Groups with mathematically intractable orders must be used.
3. Sub-Millisecond Verification The verifier only performs two fast exponentiations \(\pi^\ell\) and \(x^r\) mod \(N\). This asymmetric property allows smart contracts on Ethereum L1 to verify a multi-hour proof in a single EVM transaction consuming fewer than 120,000 gas.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement