On this page
(ZKPs) are one of the most important cryptographic inventions of the last 40 years — and they are transforming blockchain. A ZKP lets you prove something is true without revealing the underlying information. This enables both privacy (prove you're eligible without revealing your identity) and scaling (prove a batch of 1,000 transactions is valid without re-executing them on-chain). zk-rollups are among the most active areas of scaling work in crypto, and ZK is the foundation of private payments. Understanding ZK is understanding where crypto is heading.
Standard Explanation
A zero-knowledge proof is a cryptographic protocol where a “prover” convinces a “verifier” that a statement is true, without revealing any information beyond the truth of the statement itself. The concept was introduced by Goldwasser, Micali, and Rackoff in 1985 — a theoretical breakthrough that took decades to become practical.
The three properties
A valid zero-knowledge proof must satisfy three properties:
- Completeness: If the statement is true, an honest prover can convince an honest verifier. (True things can be proven.)
- Soundness: If the statement is false, no cheating prover can convince an honest verifier (except with negligible probability). (False things can't be faked.)
- Zero-knowledge: The verifier learns nothing beyond the fact that the statement is true. (No information leaks.)
The classic example: Where's Waldo?
A simple analogy: you want to prove you know where Waldo is on a page, without revealing his location. You take a large piece of cardboard with a small hole cut in it, place it over the page so Waldo shows through the hole, and show it to the verifier. They can see Waldo (proving you know where he is), but the cardboard covers everything else, so they can't tell where on the page he is (zero knowledge). The proof is complete (you showed Waldo), sound (you can't fake Waldo), and zero-knowledge (they learned nothing about his location).
Real ZKPs use mathematics instead of cardboard, but the principle is the same: reveal just enough to prove the claim, and nothing more.
From theory to practice: zk-SNARKs
For decades, ZKPs were a theoretical curiosity — too slow and complex for practical use. That changed in the 2010s with the development of zk-SNARKs (Zero-Knowledge Succinct Non-interactive ARguments of Knowledge). “Succinct” means the proof is tiny (a few hundred bytes) and fast to verify (milliseconds), even if the statement being proven is complex. “Non-interactive” means the prover generates a proof that the verifier can check without back-and-forth communication.
Vitalik Buterin wrote one of the most influential accessible explanations of how zk-SNARKs work, breaking down the mathematics into understandable steps. The key insight is that the computation to be proven is converted into a polynomial equation, and the proof attests that the equation holds — without revealing the inputs. The math is deep (involving elliptic curves, pairings, and polynomial commitments), but the result is practical: a tiny proof that a complex computation was done correctly.
zk-SNARKs require a “trusted setup” — a ceremony where initial parameters are generated and then destroyed. If the setup is compromised, fake proofs can be created. zk-STARKs (Scalable Transparent ARguments of Knowledge) don't require a trusted setup (they're “transparent”), and they're post-quantum secure, but the proofs are larger. Both are used in production: zk-SNARKs by zcash, zkSync, and Polygon zkEVM; zk-STARKs by StarkNet and RiscZero.
Two applications: privacy and scaling
ZKPs are useful for two completely different problems in crypto:
Privacy
On a public blockchain, every transaction is visible to everyone. ZKPs let you prove that a transaction is valid (you have the funds, you're authorized to spend them) without revealing the sender, recipient, or amount. Zcash was the first major privacy coin to use zk-SNARKs for shielded transactions. used ZKPs to break the link between Ethereum sender and recipient (until OFAC sanctioned it — sanctions the Treasury later lifted — see the Tornado Cash deep dive). For the full privacy landscape, see the Privacy Coins module.
Scaling
A processes thousands of transactions off-chain and posts a single ZK proof to the base layer (Ethereum) attesting that all the transactions are valid. The base layer doesn't need to re-execute the transactions — it just verifies the proof (which takes milliseconds). This scales throughput by 100x or more while inheriting the base layer's security. zk-rollups (zkSync Era, Polygon zkEVM, StarkNet, Linea, Scroll) are a central pillar of Ethereum's scaling roadmap.
Earlier rollups (Optimistic rollups like Arbitrum and Optimism) assume transactions are valid and allow a 7-day challenge period for anyone to submit a fraud proof. zk-rollups prove validity cryptographically — no challenge period needed, withdrawals are faster, and the security doesn't depend on watchers catching fraud. The trade-off is that generating ZK proofs is computationally expensive (though this is improving rapidly with specialized hardware and better proving systems).
The current landscape (2024–2026)
ZK technology is evolving rapidly. Key developments:
- zkEVMs: Rollups that can run Ethereum smart contracts directly (Polygon zkEVM, zkSync Era, Scroll, Linea) — meaning any Ethereum dApp can deploy on a zk-rollup without rewriting code.
- Proof generation is getting cheaper: Specialized hardware (GPUs, FPGAs, ASICs) and better proving systems (Plonky2, HyperPlonk, STARKs) are making proof generation faster and cheaper.
- Account abstraction + ZK: Smart accounts that use ZK proofs for authentication — e.g., prove you're a member of a group without revealing which member.
- ZK bridges: Using ZK proofs to verify cross-chain state cryptographically, without trusting a validator set. This could solve the bridge security problem (see the Bridge Hacks deep dive).
The honest limitations
- Trusted setup (for SNARKs): If the ceremony is compromised, fake proofs are possible. STARKs avoid this but have larger proofs.
- Proof generation cost: Generating a ZK proof is computationally expensive. This is improving but still a bottleneck.
- Complexity: ZK proofs are among the most complex cryptographic constructions in production. Bugs in proving systems or circuits can be catastrophic and hard to detect.
- Regulatory tension: Privacy-preserving ZK applications face regulatory pressure (as Tornado Cash showed). ZK scaling applications face less, but the line between “privacy” and “scaling” ZK is blurry.
Key takeaways
- A zero-knowledge proof lets you prove a statement is true without revealing the underlying information. The concept was introduced in 1985 (Goldwasser, Micali, Rackoff) and took decades to become practical.
- zk-SNARKs (succinct, non-interactive proofs) made ZK practical for blockchain: tiny proofs, fast verification, no back-and-forth. zk-STARKs avoid the trusted setup but have larger proofs.
- ZK enables two major crypto use cases: privacy (prove a transaction is valid without revealing sender/recipient/amount — Zcash, Tornado Cash) and scaling (prove a batch of transactions is valid without re-executing them — zk-rollups).
- zk-rollups are among the most prominent Ethereum scaling technologies: 100x+ throughput, inherited L1 security, no challenge period. zkEVMs let any Ethereum dApp deploy on a zk-rollup without code changes.
- ZK technology is evolving rapidly (cheaper proofs, ZK bridges, account abstraction). Limitations include trusted setup (for SNARKs), proof generation cost, complexity, and regulatory tension for privacy applications.