# Lighter Markdown version of https://l2beat.com/zk-catalog/lighterprover ## Summary - Creator: Lighter - Total Value Secured: $1.29 B (-2.29% compared to seven days ago) - Trusted setups for Gnark (Plonk): - Aztec Ignition, risk green (lowest risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Aztec Ignition is a trusted setup ceremony that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Used in: [Lighter](https://l2beat.com/layer2s/projects/lighter), [Lighter on Robinhood](https://l2beat.com/layer2s/projects/lighter-robinhood) - Verifiers: 1 successful (verified by [L2BEAT](https://l2beat.com)), 2 not verified - zkVM: Plonky2 (Plonk), Goldilocks (Field), App-specific circuits (Other) - Final wrap: Gnark (Plonk), BN254 (curve) ### About A ZK proving system designed by Lighter for proving their DEX L2 focused on trading perpetuals. ### Links - Website: https://lighter.xyz - Docs: https://docs.lighter.xyz - Repository: https://github.com/elliottech/lighter-prover/tree/main, https://github.com/elliottech ## Value Secured The interactive TVS chart is shown on [the HTML page](https://l2beat.com/zk-catalog/lighterprover#tvs). ## Proof System ### Description Lighter prover is a zk proving system for Lighter L2 based on [Plonky2](https://github.com/0xPolygonZero/plonky2/tree/main) circuits. It verifies the logic for regular state transition of Lighter L2, as well as state transitions in the “desert mode” when L2 is shut down and users exit, using different sets of circuits. The circuits are proven with a STARK which is wrapped into a Plonk SNARK before settling onchain. ### Proof system [Plonky2](https://github.com/0xPolygonZero/plonky2) implements a circuit aritmetization based on TurboPlonk over Goldilocks field, but it replaces KZG polynomial commitment scheme with a FRI-based polynomial testing scheme. In this way proving Plonky2 circuits requires no trusted setup, i.e. it is a STARK. However Lighter wraps these STARK in a [gnark](https://github.com/Consensys/gnark) implementation of Plonk over BN254 curve, which requires a trusted setup. #### Lighter Circuits The proof system operates on Lighter STF circuits and desert mode circuits. All published circuits are available [here](https://github.com/elliottech/lighter-prover/tree/main). Lighter proof system defines circuits for proving all transactions, including internal, L1 and L2 transactions. The full list of available transactions that define Lighter STF can be seen [here](https://github.com/elliottech/lighter-prover/tree/main/circuit/src/transactions). Transaction circuits use custom implementations for arithmetic operations ([bigint](https://github.com/elliottech/lighter-prover/tree/main/circuit/src/bigint), [uint](https://github.com/elliottech/lighter-prover/tree/main/circuit/src/uint)), cryptographic primitives ([ecdsa](https://github.com/elliottech/lighter-prover/tree/main/circuit/src/ecdsa) on the Secp256k1 curve, [eddsa](https://github.com/elliottech/lighter-prover/tree/main/circuit/src/eddsa) on the ECgFp5 curve, [keccak](https://github.com/elliottech/lighter-prover/tree/main/circuit/src/keccak), [poseidon_bn128](https://github.com/elliottech/lighter-prover/tree/main/circuit/src/poseidon_bn128)) and other helper circuits. #### Desert circuits Lighter also provides [desert exit circuits](https://github.com/elliottech/lighter-prover/tree/main/desertexit) that allow users to permissionlessly exit L2 when it is in the desert mode. Users can use desert circuit to generate a proof of ownership of all their positions locally, which could be submitted on L1 for withdrawing funds. #### Recursion Lighter prover implements recursive aggregation of transaction proofs to make the whole pipeline more efficient and parallelizable. First, fixed-size blocks of consecutive transactions are processed and proven by [BlockTx circuit](https://github.com/elliottech/lighter-prover/blob/main/circuit/src/block_tx_constraints.rs), which can be done on separate machines. Next, arbitrary number of BlockTx proofs are aggregated into a single proof by [BlockTxChain circuit](https://github.com/elliottech/lighter-prover/blob/main/circuit/src/block_tx_chain_constraints.rs), which includes continuity checks across all BlockTx proofs. ## Trusted Setups Risk levels follow the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). Yellow (medium risk): all contributions are published and the final output can be verified, the ceremony client is open source, there were at least 30 contributions, participation was open to the public and announced, and participants are publicly identified. Green (lowest risk): everything required for yellow, with at least 150 contributions. Red (highest risk): at least one requirement for yellow is not met. N/A: the proof system needs no trusted setup. ### Aztec Ignition - Risk: green (lowest risk) - Proof systems: Gnark (Plonk) Aztec Ignition is a trusted setup ceremony for KZG commitments over BN254 curve that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Github repo to download and verify the ceremony artifacts: [https://github.com/AztecProtocol/ignition-verification](https://github.com/AztecProtocol/ignition-verification). - Github repo with instructions for ceremony participants: [https://github.com/AztecProtocol/Setup](https://github.com/AztecProtocol/Setup). - Ceremony announcement with a call to participate: [https://aztec.network/blog/announcing-ignition](https://aztec.network/blog/announcing-ignition). ## Verifier IDs List of different onchain verifiers for this proving system. Unique ID distinguishes different deployments of the same verifier from different verifiers (e.g. different versions). ### Plonk: Gnark Consensys implementation of Plonk proving system written in Go. #### Lighter verifier Custom verifier ID: SHA256 hash of all VK_... values from the smart contract, abi packed in the same order they are defined. - Verifier ID: `0x83147f4163d7731f85f475fb56f316f1f46443d3601cb3494465d27790533fec` - Verification: not verified - Used in: [Lighter](https://l2beat.com/layer2s/projects/lighter) **Known deployments** - [0xc4c2067ece6e33e50a30087ec14096715e56aE11](https://etherscan.io/address/0xc4c2067ece6e33e50a30087ec14096715e56aE11#code) on Ethereum, used in: [Lighter](https://l2beat.com/layer2s/projects/lighter) ##### Verification steps The sources for the verifier circuits are not published and thus the verifier cannot be independently regenerated. #### Lighter on Robinhood verifier Custom verifier ID: SHA256 hash of all VK_... values from the smart contract, abi packed in the same order they are defined. - Verifier ID: `0x0b3f7515b28812264c235ac2bba289e19a42cecfbceb2eef9856bd6f591a2308` - Verification: not verified - Used in: [Lighter on Robinhood](https://l2beat.com/layer2s/projects/lighter-robinhood) **Known deployments** - [0xCBF92533F5816c6Ee0e4250F4E138b3f49962EF2](https://robin.etherscan.io/address/0xCBF92533F5816c6Ee0e4250F4E138b3f49962EF2#code) on Robinhood Chain, used in: [Lighter on Robinhood](https://l2beat.com/layer2s/projects/lighter-robinhood) #### Lighter Desert verifier Custom verifier ID: SHA256 hash of all VK_... values from the smart contract, abi packed in the same order they are defined. - Verifier ID: `0xc8ffb171b6ebf0bba84df27eaa1021550c5242b146739c704221b456203630a9` - Source: https://github.com/elliottech/lighter-prover/tree/23d1596b832db24f1007e20220ba1556d23b0c68/desertexit/circuits - Verification: successful (verified by [L2BEAT](https://l2beat.com)) - Used in: [Lighter](https://l2beat.com/layer2s/projects/lighter), [Lighter on Robinhood](https://l2beat.com/layer2s/projects/lighter-robinhood) **Known deployments** - [0x866418061d4C1168e1c8E8f6facE79675395E008](https://etherscan.io/address/0x866418061d4C1168e1c8E8f6facE79675395E008#code) on Ethereum, used in: [Lighter](https://l2beat.com/layer2s/projects/lighter) - [0x56aeED6920DBB9E198C2C0072147A45684A06E10](https://robin.etherscan.io/address/0x56aeED6920DBB9E198C2C0072147A45684A06E10#code) on Robinhood Chain, used in: [Lighter on Robinhood](https://l2beat.com/layer2s/projects/lighter-robinhood) ##### Verification steps The verification process below is based on the `build.sh` [script](https://github.com/elliottech/lighter-prover/blob/23d1596b832db24f1007e20220ba1556d23b0c68/desertexit/build.sh) in the lighter-prover repo. It consumed around 100 GiB of memory at the peak, so we recommend rerunning it on a machine with 128 GiB of RAM. The steps below are for Ubuntu 22.04 OS. 1. Install rust, gcc, go version 1.21 and later. ``` curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh . .cargo/env sudo apt update sudo apt install build-essential sudo apt install jq # one way to install latest go on Ubuntu 22.04 wget https://go.dev/dl/go1.21.0.linux-amd64.tar.gz sudo tar -xvf go1.21.0.linux-amd64.tar.gz sudo mv go /usr/local export GOROOT=/usr/local/go export GOPATH=$HOME/go export PATH=$GOPATH/bin:$GOROOT/bin:$PATH source ~/.profile ``` 2. Run the correct version of the script to regenerate the keys. ``` git clone https://github.com/elliottech/lighter-prover.git cd lighter-prover/desertexit git checkout 23d1596b832db24f1007e20220ba1556d23b0c68 chmod +x build.sh ./build.sh ``` The script will generate the `desertwrapper::....sol` file in the `lighter-prover/desertexit/artifacts` directory that contains the verifier smart contract with the verification keys.