Featured Developer Sponsor • Zero-Token Protection
64 Bytes (2 G1)
Constant Proof Size (O(1))
~180,000 Gas
EVM Verification Cost (1 Pairing Check)
65,536 Gates
Polynomial Degree Bound (Domain Size N)
1.8 ms
Client Verification Latency
1. Arithmetization Circuit & Elliptic Curve Pairing Parameters
Fiat-Shamir challenge derived from transcript hash: z = H(transcript).
1. PLONK Gate Identity: qL·a(X) + qR·b(X) + qO·c(X) + qM·(a(X)·b(X)) + qC = 0 mod p
2. KZG Quotient Polynomial: q(X) = (f(X) - y) / (X - z)
3. Pairing Check: e(π, [s - z]₂) == e(C - [y]₁, [1]₂) ⟹ Valid iff f(z) = y
2. KZG Quotient Polynomial: q(X) = (f(X) - y) / (X - z)
3. Pairing Check: e(π, [s - z]₂) == e(C - [y]₁, [1]₂) ⟹ Valid iff f(z) = y
Click "Evaluate Bilinear Pairing" to run client-side KZG verification.
// Generated ZK Verifier code
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement