# Linea Markdown version of https://l2beat.com/zk-catalog/lineaprover ## Summary - Creator: Consensys - Total Value Secured: $375.58 M (-0.58% compared to seven days ago) - Trusted setups for Gnark (Plonk): - Aztec Ignition, risk green (lowest risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Aztec Ignition is a trusted setup ceremony that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Aleo stage I trusted setup, risk yellow (medium risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Trusted setup for KZG commitments over BLS12-377 curve, initially run as Aleo's Stage I setup. Ceremony has 106 participants and was publicly open for participation. - Celo Plumo, risk yellow (medium risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Trusted setup for KZG commitments over BW6-761 curve, initially run for Celo Plumo. Ceremony has 55 participants and was publicly open for participation. - Used in: [Linea](https://l2beat.com/layer2s/projects/linea) - Verifiers: 1 successful, 1 not verified - zkVM: Linea (Plonk), EVM (ISA), BLS12-377 (curve), BW6-761 (curve), Koala Bear (Field) - Final wrap: Gnark (Plonk), BN254 (curve) ### About Linea proving system is designed for proving EVM code execution and mainly used for proving Linea L2 state transitions. ### Links - Website: https://linea.build/blog/the-linea-prover-explained - Docs: https://eprint.iacr.org/2022/1633.pdf, https://docs.linea.build/technology/prover - Repository: https://github.com/Consensys/linea-monorepo/tree/main/prover, https://github.com/Consensys/gnark?tab=readme-ov-file ## Value Secured The interactive TVS chart is shown on [the HTML page](https://l2beat.com/zk-catalog/lineaprover#tvs). ## Proof System ### Description [Linea prover](https://github.com/Consensys/linea-monorepo/tree/main/prover) implements a zkEVM by creating a custom arithmetization of EVM state transition (including precompiles) and proving it in a series of recursive SNARKs (i.e. without implementing a zkVM). The proof is wrapped into a Plonk with KZG for efficient onchain verification. Linea prover targets 128 bits of security. ### Proof system Linea prover includes Wizard-IOP framework for extending polynomial IOPs with more powerful queries, Arcane compiler of Wizard-IOP into polynomial IOP and Vortex list polynomial commitment (LPC) scheme. Wizard-IOP represents an extension of polynomial IOP with a wider range of queries, including inclusion check, permutation check, range check etc. Vortex LPC is a batchable polynomial commitment that is based on [Ligero](https://eprint.iacr.org/2022/1608) with lattice-based hash functions. To achieve succinct proof size, Linea prover performs multiple rounds of self-recursion by arithmetizing the Vortex verifier in the Wizard-IOP framework. [Since April 2026](https://linea.build/blog/small-fields-faster-proving-on-linea-toward-real-time-finality), the zkEVM arithmetization is done over KoalaBear 31-bit field for performance reasons, utilizing its degree 4 extension for commitment openings. During the recursive rounds Plonk+KZG schemes over curves BW6, BLS12-377, and BN254 are used, creating a dependency on 3 trusted setups, see [below](https://l2beat.com/zk-catalog/lineaprover#trusted-setups) for more details. Linea prover also introduces [limitless mode](https://github.com/Consensys/linea-monorepo/tree/main/prover/backend/execution/limitless), which segments the proving process into parallelizable jobs. #### EVM circuits This level of Linea prover produces execution proof and data availability proof after several rounds of self-recursive compression. Both of these are Plonk based proofs over KoalaBear field and BLS12-377 curve. Execution proof validates the correct execution of transactions within the EVM, including knowledge of correct EVM traces, correctness of precompiles and consistency of public inputs. Data availability proof links compressed blob data, decompressed payloads, and execution-data commitments for EVM execution circuits. #### Aggregation circuits At this stage several proofs generated by execution and compression circuits are recursively verified within the aggregation circuit, which also checks the “connection” of all public inputs across all circuits. It leverages a composite proof system that combines several Plonk circuits on the BW6 and BLS12-377 curves with a goal of performant recursion. #### Final wrap In the end the Linea proof is wrapped in a [gnark](https://github.com/Consensys/gnark) implementation of Plonk over BN254 curve for even more efficiency onchain. For Plonk, Aztec Ignition trusted setup ceremony is used, see [below](https://l2beat.com/zk-catalog/lineaprover#trusted-setups) for more details. ## Trusted Setups Risk levels follow the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). Yellow (medium risk): all contributions are published and the final output can be verified, the ceremony client is open source, there were at least 30 contributions, participation was open to the public and announced, and participants are publicly identified. Green (lowest risk): everything required for yellow, with at least 150 contributions. Red (highest risk): at least one requirement for yellow is not met. N/A: the proof system needs no trusted setup. ### Aztec Ignition - Risk: green (lowest risk) - Proof systems: Gnark (Plonk) Aztec Ignition is a trusted setup ceremony for KZG commitments over BN254 curve that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Github repo to download and verify the ceremony artifacts: [https://github.com/AztecProtocol/ignition-verification](https://github.com/AztecProtocol/ignition-verification). - Github repo with instructions for ceremony participants: [https://github.com/AztecProtocol/Setup](https://github.com/AztecProtocol/Setup). - Ceremony announcement with a call to participate: [https://aztec.network/blog/announcing-ignition](https://aztec.network/blog/announcing-ignition). ### Aleo stage I trusted setup - Risk: yellow (medium risk) - Proof systems: Gnark (Plonk) Ceremony generated trusted setup for KZG commitments over BLS12-377 curve, it was originally run as stage I setup for Aleo blockchain and later reused for Linea prover. Ceremony has 106 participants. - Repo with ceremony instructions [https://github.com/AleoNet/aleo-setup](https://github.com/AleoNet/aleo-setup) - Link to the ceremony details: [https://setup.aleo.org](https://setup.aleo.org/) ### Celo Plumo - Risk: yellow (medium risk) - Proof systems: Gnark (Plonk) Ceremony generated trusted setup for KZG commitments over BW6-761 curve, it was originally run for Celo Plumo and later reused for Linea prover. Ceremony has 55 participants. - Repo with ceremony instructions: [https://github.com/celo-org/snark-setup?tab=readme-ov-file](https://github.com/celo-org/snark-setup?tab=readme-ov-file) - Link to the ceremony details: [https://celo.org/plumo](https://celo.org/plumo) (it is broken. Archived version here: [https://web.archive.org/web/20221201203227/https://celo.org/plumo](https://web.archive.org/web/20221201203227/https://celo.org/plumo)) - Links to ceremony transcript: [https://console.cloud.google.com/storage/browser/plumoceremonyphase1/chunks](https://console.cloud.google.com/storage/browser/plumoceremonyphase1/chunks) - Link to ceremony verification code: [https://github.com/Consensys/gnark-ignition-verifier/blob/feat/celo_parser/celo/main.go](https://github.com/Consensys/gnark-ignition-verifier/blob/feat/celo_parser/celo/main.go) ## Verifier IDs List of different onchain verifiers for this proving system. Unique ID distinguishes different deployments of the same verifier from different verifiers (e.g. different versions). ### Plonk: Gnark Consensys implementation of Plonk proving system written in Go. #### Linea Plonk Type 0 Custom verifier ID: SHA256 hash of all VK_... values from the smart contract, abi packed in the same order they are defined. - Verifier ID: `0xbe73a8003797063d70b44eba376a814caf3399361069b5e5e43660cc435c27c9` - Verification: not verified - Used in: [Linea](https://l2beat.com/layer2s/projects/linea) **Known deployments** - [0xAFF26999780901ee8B48f0a1271a177ff46fD53F](https://etherscan.io/address/0xAFF26999780901ee8B48f0a1271a177ff46fD53F#code) on Ethereum, used in: [Linea](https://l2beat.com/layer2s/projects/linea) #### Linea Plonk Type 1 Custom verifier ID: SHA256 hash of all VK_... values from the smart contract, abi packed in the same order they are defined. - Verifier ID: `0x6ffac481bc247d3ebf14238058f222f104b3b0c0d1617625c41b859045984621` - Source: https://github.com/Consensys/linea-monorepo/tree/477b0a4288fc54da185a992c47772c377d3ac1e9/prover - Verification: successful - Used in: [Linea](https://l2beat.com/layer2s/projects/linea) **Known deployments** - [0x09ac9f7E5Fb37e241e0B1e52aaF01eFE0a488a77](https://etherscan.io/address/0x09ac9f7E5Fb37e241e0B1e52aaF01eFE0a488a77#code) on Ethereum, used in: [Linea](https://l2beat.com/layer2s/projects/linea) ##### Verification steps The regeneration process requires approximately 1 TiB of memory and approximately 400 GiB of disk space for trusted setup files and generated artifacts. It takes around 2 hours, excluding fetching 132 GiB of trusted setup assets. We have verified the steps below on an Ubuntu machine. 1. Install build prerequisites: `build-essential` and the latest version of Go. 2. Optionally, set up additional swap RAM. We used: ``` sudo apt install zram-tools vim /etc/default/zramswap # set algo to zstd, % to 20 and priority to 100 sudo systemctl stop zramswap sudo systemctl start zramswap ``` 3. Check out tag `releases/prover/v1.0.5` (commit `477b0a4288fc54da185a992c47772c377d3ac1e9`) of [linea-monorepo](https://github.com/Consensys/linea-monorepo): ``` git clone https://github.com/Consensys/linea-monorepo.git cd linea-monorepo git checkout releases/prover/v1.0.5 ``` 4. Download trusted setup files (132 GiB) from the L2BEAT hosting server into the `prover/prover-assets/kzgsrs` dir: ``` cd prover/prover-assets/kzgsrs wget -r -np -nH --cut-dirs=1 -R "index.html*" https://trusted-setup-hosting.l2beat.com/files/ ``` 5. Build the circuits and the verifier contract, this step takes several hours: ``` # from the linea-monorepo/prover dir make setup ``` The generated verifier smart contract can be found in the `prover/prover-assets` directory, under the `emulation/Verifier.sol` subdirectory.