# SP1 Turbo Markdown version of https://l2beat.com/zk-catalog/sp1turbo ## Summary - Creator: Succinct - Total Value Secured: $2.01 B (-1.89% compared to seven days ago) - Trusted setups for Gnark (Plonk): - Aztec Ignition, risk green (lowest risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Aztec Ignition is a trusted setup ceremony that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Used in: [Mantle](https://l2beat.com/layer2s/projects/mantle), [Celo](https://l2beat.com/layer2s/projects/celo), [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Katana](https://l2beat.com/layer2s/projects/katana), [RISE](https://l2beat.com/layer2s/projects/rise), [Lumia Prism](https://l2beat.com/layer2s/projects/lumia), [Taiko Alethia](https://l2beat.com/layer2s/projects/taiko), [Haust Network](https://l2beat.com/layer2s/projects/haust), [Silicon](https://l2beat.com/layer2s/projects/silicon), [Polygon zkEVM](https://l2beat.com/layer2s/projects/polygonzkevm), [Vector](https://l2beat.com/data-availability/projects/avail/vector), [Sophon](https://l2beat.com/layer2s/projects/sophon), [Pentagon Chain](https://l2beat.com/layer2s/projects/penchain), [Lens](https://l2beat.com/layer2s/projects/lens), [Facet](https://l2beat.com/layer2s/projects/facet), [Wirex Pay Chain](https://l2beat.com/layer2s/projects/wirex), [Forknet](https://l2beat.com/layer2s/projects/forknet), [Blobstream](https://l2beat.com/data-availability/projects/celestia/blobstream), [Ethscriptions](https://l2beat.com/layer2s/projects/ethscriptions) - Verifiers: 1 successful (verified by [L2BEAT](https://l2beat.com)) - Trusted setups for Gnark (Groth16): - SP1 Turbo Groth16 circuit-specific setup, risk red (highest risk) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): Succinct's internally run trusted setup for SP1 Turbo (release v5.0.0) Groth16 final wrap circuits. Phase 2 of the ceremony was run among 7 contributors to the SP1 project without public calls to participate. - Used in: [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Fluent](https://l2beat.com/layer2s/projects/fluent), [Facet](https://l2beat.com/layer2s/projects/facet) - Verifiers: 1 unsuccessful (checked by [L2BEAT](https://l2beat.com)) - zkVM: Plonky3 (STARK), RISC-V 32bit (ISA), Baby Bear (Field) - Final wrap: Gnark (Plonk), Gnark (Groth16), BN254 (curve) ### About SP1 Turbo is a zk proving system for RISC-V programs built by Succinct, release v5. ### Links - Website: https://www.succinct.xyz - Docs: https://docs.succinct.xyz/docs/v5/protocol/introduction - Repository: https://github.com/succinctlabs/sp1/tree/v5.0.0 - Social: https://x.com/SuccinctLabs, https://discord.com/invite/succinctlabs ## Value Secured The interactive TVS chart is shown on [the HTML page](https://l2beat.com/zk-catalog/sp1turbo#tvs). ## Proof System ### Description SP1 Turbo is a RISC-V zkVM using the [Plonky3](https://github.com/Plonky3/Plonky3) stack. The zkVM execution is proven recursively and is wrapped into a SNARK for final verification. It provides tools to generate onchain Groth16 or Plonk verifiers. SP1 targets [100 bits of security based on unproven proximity gaps conjecture](https://docs.succinct.xyz/docs/v5/sp1/security/security-model#conjectures-for-fris-security), so the actual security is likely lower. ### Proof system SP1 Turbo proves execution of a 32 bit RISC-V VM (RV32IM) using several ZK circuits connected by lookup arguments, as implemented in Plonky3. VM execution trace is split into several chunks that could be proven in parallel with a STARK proving system. The parallelized proofs are recursively checked by the next layer of STARK circuits. The correctness of the final STARK proof is verified with the final wrap SNARK program, the wrap SNARK proof is verified onchain. #### zkVM component Verifies execution of a RISC-V program in a zkVM. See [here](https://docs.succinct.xyz/docs/v5/sp1/security/rv32im-implementation) for more details on the exact RISC-V standard implemented. Uses [Plonky3](https://github.com/Plonky3/Plonky3) STARK toolkit with AIR arithmetization and FRI-based polynomial commitment scheme within the [BabyBear field](https://docs.succinct.xyz/docs/v5/sp1/security/security-model#hash-functions-and-the-random-oracle-model). #### Recursion circuits SP1 provides tools for recursive proof generation by [verifying proofs in a zkVM](https://docs.succinct.xyz/docs/v5/sp1/writing-programs/proof-aggregation#verifying-proofs-inside-the-zkvm). This uses the same toolkit as top-level proof system, but proves the correct verification of all proofs generated on the previous step. #### Final wrap SP1 supports Plonk (with KZG polynomial commitments) or Groth16 final SNARK wrap of the STARK proof for performant onchain proof verification ([link](https://docs.succinct.xyz/docs/v5/sp1/generating-proofs/proof-types#compressed)). The [gnark](https://github.com/Consensys/gnark) implementation of these proof systems over BN254 curve is used. For Plonk, Aztec Ignition trusted setup ceremony is used, for Groth16 Succinct run internal circuit-dependent phase 2 trusted setup, see [below](https://l2beat.com/zk-catalog/sp1turbo#trusted-setups) for more details. ## Milestones & Incidents - 2025-06-03 (incident): [[Disclosed vulnerability] Plonky3 final polynomial degree check vulnerability](https://x.com/SuccinctLabs/status/1929773028034204121). Release of SP1 V5.0.0 with a fix of a Plonky3 library issue that affected the security of SP1 zkVM. - 2025-03-28 (incident): [[Disclosed vulnerability] Plonky3 FRI size check vulnerability](https://x.com/SuccinctLabs/status/1905818676848406801). Fix of a Plonky3 library soundness issue that affected the security of SP1 zkVM. ## Trusted Setups Risk levels follow the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). Yellow (medium risk): all contributions are published and the final output can be verified, the ceremony client is open source, there were at least 30 contributions, participation was open to the public and announced, and participants are publicly identified. Green (lowest risk): everything required for yellow, with at least 150 contributions. Red (highest risk): at least one requirement for yellow is not met. N/A: the proof system needs no trusted setup. ### Aztec Ignition - Risk: green (lowest risk) - Proof systems: Gnark (Plonk) Aztec Ignition is a trusted setup ceremony for KZG commitments over BN254 curve that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation. - Github repo to download and verify the ceremony artifacts: [https://github.com/AztecProtocol/ignition-verification](https://github.com/AztecProtocol/ignition-verification). - Github repo with instructions for ceremony participants: [https://github.com/AztecProtocol/Setup](https://github.com/AztecProtocol/Setup). - Ceremony announcement with a call to participate: [https://aztec.network/blog/announcing-ignition](https://aztec.network/blog/announcing-ignition). ### SP1 Turbo Groth16 circuit-specific setup - Risk: red (highest risk) - Proof systems: Gnark (Groth16) SP1 Turbo Groth16 trusted setup builds on top of the first 54 contributions to the [Perpetual Powers of Tau](https://github.com/privacy-ethereum/perpetualpowersoftau) ceremony as its phase 1 setup. Phase 2 of the ceremony was run among 7 contributors to the SP1 project without public calls to participate. It generated setup parameters for Groth16 wrapper of SP1 zkVM. - Phase 1 ceremony (first 54 contributions are used): . - Ceremony info on Succinct docs page: [https://docs.succinct.xyz/docs/v5/sp1/security/security-model#options](https://docs.succinct.xyz/docs/v5/sp1/security/security-model#options). - Ceremony instructions and verification instructions: [https://github.com/succinctlabs/semaphore-gnark-11/tree/main](https://github.com/succinctlabs/semaphore-gnark-11/tree/main). - Link to transcript and other artifacts (Note: will immediately start downloading .tar.gz file): [https://sp1-circuits.s3.us-east-2.amazonaws.com/v4.0.0-rc.3-trusted-setup.tar.gz](https://sp1-circuits.s3.us-east-2.amazonaws.com/v4.0.0-rc.3-trusted-setup.tar.gz). ## Verifier IDs List of different onchain verifiers for this proving system. Unique ID distinguishes different deployments of the same verifier from different verifiers (e.g. different versions). ### Plonk: Gnark Consensys implementation of Plonk proving system written in Go. #### SP1 Turbo Plonk v5.0.0 - Verifier ID: `0xd4e8ecd2357dd882209800acd6abb443d231cf287d77ba62b732ce937c8b56e7` - Source: https://github.com/succinctlabs/sp1/tree/v5.0.0/crates - Verification: successful (verified by [L2BEAT](https://l2beat.com)) - Used in: [Mantle](https://l2beat.com/layer2s/projects/mantle), [Celo](https://l2beat.com/layer2s/projects/celo), [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Katana](https://l2beat.com/layer2s/projects/katana), [RISE](https://l2beat.com/layer2s/projects/rise), [Lumia Prism](https://l2beat.com/layer2s/projects/lumia), [Taiko Alethia](https://l2beat.com/layer2s/projects/taiko), [Haust Network](https://l2beat.com/layer2s/projects/haust), [Silicon](https://l2beat.com/layer2s/projects/silicon), [Polygon zkEVM](https://l2beat.com/layer2s/projects/polygonzkevm), [Vector](https://l2beat.com/data-availability/projects/avail/vector), [Sophon](https://l2beat.com/layer2s/projects/sophon), [Pentagon Chain](https://l2beat.com/layer2s/projects/penchain), [Lens](https://l2beat.com/layer2s/projects/lens), [Facet](https://l2beat.com/layer2s/projects/facet), [Wirex Pay Chain](https://l2beat.com/layer2s/projects/wirex), [Forknet](https://l2beat.com/layer2s/projects/forknet), [Blobstream](https://l2beat.com/data-availability/projects/celestia/blobstream), [Ethscriptions](https://l2beat.com/layer2s/projects/ethscriptions) **Known deployments** - [0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459](https://etherscan.io/address/0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459#code) on Ethereum, used in: [Mantle](https://l2beat.com/layer2s/projects/mantle), [Celo](https://l2beat.com/layer2s/projects/celo), [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Katana](https://l2beat.com/layer2s/projects/katana), [RISE](https://l2beat.com/layer2s/projects/rise), [Lumia Prism](https://l2beat.com/layer2s/projects/lumia), [Taiko Alethia](https://l2beat.com/layer2s/projects/taiko), [Haust Network](https://l2beat.com/layer2s/projects/haust), [Silicon](https://l2beat.com/layer2s/projects/silicon), [Polygon zkEVM](https://l2beat.com/layer2s/projects/polygonzkevm), [Vector](https://l2beat.com/data-availability/projects/avail/vector), [Sophon](https://l2beat.com/layer2s/projects/sophon), [Pentagon Chain](https://l2beat.com/layer2s/projects/penchain), [Lens](https://l2beat.com/layer2s/projects/lens), [Facet](https://l2beat.com/layer2s/projects/facet), [Wirex Pay Chain](https://l2beat.com/layer2s/projects/wirex), [Forknet](https://l2beat.com/layer2s/projects/forknet), [Blobstream](https://l2beat.com/data-availability/projects/celestia/blobstream), [Ethscriptions](https://l2beat.com/layer2s/projects/ethscriptions) - [0xFF5Adab685362DC4C33536a65aF5873738D1216B](https://etherscan.io/address/0xFF5Adab685362DC4C33536a65aF5873738D1216B#code) on Ethereum, used in: none - [0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459](https://arbiscan.io/address/0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459#code) on Arbitrum One, used in: [Blobstream](https://l2beat.com/data-availability/projects/celestia/blobstream) - [0x059adC0Db833f7cCb12dC41BE0017626337AfA63](https://etherscan.io/address/0x059adC0Db833f7cCb12dC41BE0017626337AfA63#code) on Ethereum, used in: none - [0x294a1Ee119C4B2510530572481A6a50892A9ae9f](https://etherscan.io/address/0x294a1Ee119C4B2510530572481A6a50892A9ae9f#code) on Ethereum, used in: none ##### Verification steps The regeneration process consumed around 50 GiB of memory on the peak. Also, due to some os indeterminism, the sp1 repo must be cloned into `/home/aurel/dev/sp1-wip/` directory, so we recommend creating `aurel` user on an Ubuntu 24.04 machine. 1. Create a new `aurel` user on a linux os and login as this user. 2. Install necessary dependencies: rust, sp1 toolkit, go. ``` sudo apt update sudo apt install build-essential golang-go curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh . .cargo/env cargo install --debug --locked cargo-make curl -L https://sp1up.succinct.xyz/ | bash sp1up ``` 3. Clone sp1 repo in the correct directory, set `SP1_ALLOW_DEPRECATED_HOOKS` for correct compilation and run the script to regenerate verifiers. ``` mkdir -p dev/sp1-wip/ cd dev/sp1-wip/ git clone https://github.com/succinctlabs/sp1.git cd sp1/crates/prover git checkout v5.0.0 # commit should be 38f0f143dece864e8bffafad64196a924f190336 export SP1_ALLOW_DEPRECATED_HOOKS=true # fixes compilation errors make build-circuits ``` The script will generate Plonk verifier smart contract with verification keys and the verifier hash in `build/plonk` dir. ### Groth16: Gnark Consensys implementation of Groth16 proving system written in Go. #### SP1 Turbo Groth16 v5.0.0 - Verifier ID: `0xa4594c59bbc142f3b81c3ecb7f50a7c34bc9af7c4c444b5d48b795427e285913` - Source: https://github.com/succinctlabs/sp1/tree/v5.0.0/crates - Verification: unsuccessful (checked by [L2BEAT](https://l2beat.com)) - Used in: [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Fluent](https://l2beat.com/layer2s/projects/fluent), [Facet](https://l2beat.com/layer2s/projects/facet) **Known deployments** - [0x50ACFBEdecf4cbe350E1a86fC6f03a821772f1e5](https://etherscan.io/address/0x50ACFBEdecf4cbe350E1a86fC6f03a821772f1e5#code) on Ethereum, used in: [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Fluent](https://l2beat.com/layer2s/projects/fluent), [Facet](https://l2beat.com/layer2s/projects/facet) - [0xC513d6E8C8f915B1DA2f6eAC4C6d755ff3d5f21D](https://arbiscan.io/address/0xC513d6E8C8f915B1DA2f6eAC4C6d755ff3d5f21D#code) on Arbitrum One, used in: none ##### Verification steps We performed the following steps, which according to the Succinct team should have lead to a successful regeneration of the verifier's hash. However these steps produced a verifier smart contract with `VERIFIER_HASH = 0xf7ba6320608dadd905f3483d51c2fa0fb55473e3136bdfb37c96a10f158ab9fe`, which differs from the value onchain. 1. Create a new `aurel` user on a linux os and login as this user. 2. Install necessary dependencies: rust, sp1 toolkit, go. ``` sudo apt update sudo apt install build-essential golang-go curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh . .cargo/env cargo install --debug --locked cargo-make curl -L https://sp1up.succinct.xyz/ | bash sp1up ``` 3. Clone sp1 repo in the correct directory, set `SP1_ALLOW_DEPRECATED_HOOKS` for correct compilation and run the script to regenerate verifiers. ``` mkdir -p dev/sp1-wip/ cd dev/sp1-wip/ git clone https://github.com/succinctlabs/sp1.git cd sp1/crates/prover git checkout v5.0.0 # commit should be 38f0f143dece864e8bffafad64196a924f190336 export SP1_ALLOW_DEPRECATED_HOOKS=true # fixes compilation errors make build-circuits ``` ## Program Hashes List of known guest zkVM programs used by this prover. Each program represents a piece of offchain execution that is verified onchain. The program hash serves as the program's unique identifier. ### Aggregation program of Ethscriptions ZK Fault Proofs Aggregates proofs of correct execution for several consecutive block ranges of the Ethscriptions L2 client. - Hash: `0x001d6dd65980c80ef8496f4a0bd9b2ccc1c9e66aeb122f841e0b90e322bbacdd` - Repository: https://github.com/0xFacet/ethscriptions-zk-fault-proofs/tree/251c5248cf92b544a3e6b1b4c0b98b0146dab1c6/programs/aggregation - Verification: successful - Used in: [Ethscriptions](https://l2beat.com/layer2s/projects/ethscriptions) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [ethscriptions-zk-fault-proofs](https://github.com/0xFacet/ethscriptions-zk-fault-proofs) repo: `git checkout ethscriptions` . Commit hash should be `251c5248cf92b544a3e6b1b4c0b98b0146dab1c6`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo run --bin config --release` to build the SP1 programs and generate and print verification key hashes. ### Range program of Ethscriptions ZK Fault Proofs Proves correct state transition function within the Ethscriptions L2 client over a range of consecutive L2 blocks. - Hash: `0x5a02c6f96d93f5ff1bfe8f5f2f7f158a3bc6ab7e294d3f7824507a1c67edf594` - Repository: https://github.com/0xFacet/ethscriptions-zk-fault-proofs/tree/251c5248cf92b544a3e6b1b4c0b98b0146dab1c6/programs/range/ethereum - Verification: successful - Used in: [Ethscriptions](https://l2beat.com/layer2s/projects/ethscriptions) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [ethscriptions-zk-fault-proofs](https://github.com/0xFacet/ethscriptions-zk-fault-proofs) repo: `git checkout ethscriptions` . Commit hash should be `251c5248cf92b544a3e6b1b4c0b98b0146dab1c6`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo run --bin config --release` to build the SP1 programs and generate and print verification key hashes. ### Aggregation program of OP Succinct Aggregates proofs of correct execution for several consecutive block ranges of OP L2 client. Data availability layer is set to Ethereum blobs. - Hash: `0x0083a8b50160475a7a5911c03dfdee30f6c8a83112a71c5c1125cfb96148b8c2` - Repository: https://github.com/0xFacet/zk-fault-proofs/tree/ad0ef0488e714212cb420ae04c9b242d9ef26f24/programs/aggregation - Verification: successful - Used in: [Facet](https://l2beat.com/layer2s/projects/facet) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [zk-fault-proofs](https://github.com/0xFacet/zk-fault-proofs) repo: `git checkout facet` . Commit hash should be `ad0ef0488e714212cb420ae04c9b242d9ef26f24`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo run --bin config --release` to build the SP1 programs and generate and print verification key hashes. ### Range program of OP Succinct Proves correct state transition function within an OP L2 client over a range of consecutive L2 blocks. Data availability layer is set to Ethereum blobs. - Hash: `0x43f01f7522e77ddc0bea30de6cb8075608a0d0c906660e4f5f430a1e5e170829` - Repository: https://github.com/0xFacet/zk-fault-proofs/tree/ad0ef0488e714212cb420ae04c9b242d9ef26f24/programs/range - Verification: successful - Used in: [Facet](https://l2beat.com/layer2s/projects/facet) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [zk-fault-proofs](https://github.com/0xFacet/zk-fault-proofs) repo: `git checkout facet` . Commit hash should be `ad0ef0488e714212cb420ae04c9b242d9ef26f24`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo run --bin config --release` to build the SP1 programs and generate and print verification key hashes. ### Pessimistic program of agglayer 0.3.3-post4 Verifies that a chain connected to Polygon Agglayer does not bridge out more tokens that were bridged in, thus preventing stealing tokens from other Agglayer chains. Also verifies aggchain proof for this chain. - Hash: `0x00eff0b6998df46ec388bb305618089ae3dc74e513e7676b2e1909694f49cc30` - Repository: https://github.com/agglayer/agglayer/tree/v0.3.3-post.4/crates/pessimistic-proof-program - Verification: successful - Used in: [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Katana](https://l2beat.com/layer2s/projects/katana), [Lumia Prism](https://l2beat.com/layer2s/projects/lumia), [Haust Network](https://l2beat.com/layer2s/projects/haust), [Silicon](https://l2beat.com/layer2s/projects/silicon), [Polygon zkEVM](https://l2beat.com/layer2s/projects/polygonzkevm), [Pentagon Chain](https://l2beat.com/layer2s/projects/penchain), [Forknet](https://l2beat.com/layer2s/projects/forknet) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [agglayer repo](https://github.com/agglayer/agglayer/tree/main): `git checkout v0.3.3-post.4`. Commit hash should be `df072abc86fa89e12b17204246325983272a1141` 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo make install-cargo-prove` to install the correct version of sp1 toolchain 4. From the root dir: `cargo make pp-elf` to generate pessimistic program elf from sources 5. From the pessimistic-proof/elf dir: `cargo prove vkey --elf riscv32im-succinct-zkvm-elf` to check the verification key of this elf ### Pessimistic program of agglayer v0.4.4 Verifies that a chain connected to Polygon Agglayer does not bridge out more tokens that were bridged in, thus preventing stealing tokens from other Agglayer chains. Also verifies aggchain proof for this chain. - Hash: `0x000055f14384bdb5bb092fd7e5152ec31856321c5a30306ab95836bdf5cdb639` - Repository: https://github.com/agglayer/agglayer/tree/v0.4.4/crates/pessimistic-proof - Verification: successful - Used in: [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Katana](https://l2beat.com/layer2s/projects/katana), [Lumia Prism](https://l2beat.com/layer2s/projects/lumia), [Haust Network](https://l2beat.com/layer2s/projects/haust), [Silicon](https://l2beat.com/layer2s/projects/silicon), [Polygon zkEVM](https://l2beat.com/layer2s/projects/polygonzkevm), [Pentagon Chain](https://l2beat.com/layer2s/projects/penchain), [Forknet](https://l2beat.com/layer2s/projects/forknet) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct tag in [agglayer repo](https://github.com/agglayer/agglayer/tree/main): `git checkout v0.4.4`. Commit hash should be `caac9f06bc7cb1cf89912dbb4dffa4d594a00bd5`. 2. Make sure docker is running by running `docker ps`. 3. From the root dir: `cargo make pp-elf` to generate pessimistic program elf from sources. 4. From the pessimistic-proof/elf dir: `cargo prove vkey --elf riscv32im-succinct-zkvm-elf` to check the verification key of this elf. ### Pessimistic program of agglayer v0.5.1 Verifies that a chain connected to Polygon Agglayer does not bridge out more tokens that were bridged in, thus preventing stealing tokens from other Agglayer chains. Also verifies aggchain proof for this chain. - Hash: `0x00d14f977a6ec393014f300ad78d0761dc29435d3fa1e2626fa466bd3343578e` - Repository: https://github.com/agglayer/agglayer/tree/v0.5.1/crates/pessimistic-proof - Verification: successful - Used in: [X Layer](https://l2beat.com/layer2s/projects/xlayer), [Katana](https://l2beat.com/layer2s/projects/katana), [Lumia Prism](https://l2beat.com/layer2s/projects/lumia), [Haust Network](https://l2beat.com/layer2s/projects/haust), [Silicon](https://l2beat.com/layer2s/projects/silicon), [Polygon zkEVM](https://l2beat.com/layer2s/projects/polygonzkevm), [Pentagon Chain](https://l2beat.com/layer2s/projects/penchain), [Forknet](https://l2beat.com/layer2s/projects/forknet) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct tag in [agglayer repo](https://github.com/agglayer/agglayer/tree/main): `git checkout v0.5.1`. Commit hash should be `f7bb86695b03d363c3d0d15ff7f2d8b386e58c91`. 2. Make sure docker is running by running `docker ps`. 3. From the root dir: `cargo make pp-elf` to generate pessimistic program elf from sources. 4. From the pessimistic-proof/elf dir: `cargo prove vkey --elf riscv64im-succinct-zkvm-elf` to check the verification key of this elf. ### Aggchain program of agglayer v1.1.2 Verifies state transition of an Agglayer-based chain either by checking a full validity proof or just by checking a registered sequencer signature. Also checks that L1 information on the chain aligns with the values stored on Agglayer. - Hash: `0x713f8a687452545141b6cd852472c67742a5c61474b97a136d0d107804affa1f` - Repository: https://github.com/agglayer/provers/tree/v1.1.2/crates/aggchain-proof-program - Verification: successful - Used in: [Katana](https://l2beat.com/layer2s/projects/katana) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [provers repo](https://github.com/agglayer/provers): `git checkout v1.1.2`. Commit hash should be `f8580024d771580217ded443f85e42919d682595`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo make install-cargo-prove` to install the correct version of sp1 toolchain 4. From the root dir: `cargo make ap-elf` to generate aggchain program elf from sources 5. Compute vkey hash bytes of the generated `crates/aggchain-proof-program/elf/riscv32im-succinct-zkvm-elf` using SP1 toolchain, e.g. by this simple rust script: ``` use sp1_sdk::{HashableKey, Prover, CpuProver}; fn main() { let elf_path = std::env::args().nth(1).expect("Provide elf_path"); let elf_bytes = std::fs::read(&elf_path).expect("File read error"); let prover = CpuProver::new(); let (_pk, vkey) = Prover::setup(&prover, &elf_bytes); let comm = vkey.hash_bytes(); let hex: String = comm.iter(). map(|b| format!("{:02x}", b)).collect(); println!("0x{}", hex); } ``` ### Aggchain program of agglayer v1.5.0 Verifies state transition of an Agglayer-based chain either by checking a full validity proof or just by checking a registered sequencer signature. Also checks that L1 information on the chain aligns with the values stored on Agglayer. - Hash: `0x374ee73950cdb07d1b8779d90a8467df232639c13f9536b03f1ba76a2aa5dac6` - Repository: https://github.com/agglayer/provers/tree/v1.5.0/crates/aggchain-proof-program - Verification: successful - Used in: [Katana](https://l2beat.com/layer2s/projects/katana) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [provers repo](https://github.com/agglayer/provers): `git checkout v1.5.0`. Commit hash should be `347a140649383d8f5aa5a14907a45cfa756426af`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo make ap-elf` to generate aggchain program elf from sources 4. Compute vkey hash bytes of the generated `crates/aggchain-proof-program/elf/riscv32im-succinct-zkvm-elf` using SP1 toolchain, e.g. by this simple rust script: ``` use sp1_sdk::{HashableKey, Prover, CpuProver}; fn main() { let elf_path = std::env::args().nth(1).expect("Provide elf_path"); let elf_bytes = std::fs::read(&elf_path).expect("File read error"); let prover = CpuProver::new(); let (_pk, vkey) = Prover::setup(&prover, &elf_bytes); let comm = vkey.hash_bytes(); let hex: String = comm.iter(). map(|b| format!("{:02x}", b)).collect(); println!("0x{}", hex); } ``` ### Aggchain program of agglayer v1.8.0 Verifies state transition of an Agglayer-based chain either by checking a full validity proof or just by checking a registered sequencer signature. Also checks that L1 information on the chain aligns with the values stored on Agglayer. - Hash: `0x6e38caa6114ac4b9779f647547de9e8f09e9f5cd6194e7134110760d3aa31b53` - Repository: https://github.com/agglayer/provers/tree/v1.8.0/crates/aggchain-proof-program - Verification: successful - Used in: [Katana](https://l2beat.com/layer2s/projects/katana) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [provers repo](https://github.com/agglayer/provers): `git checkout v1.8.0`. Commit hash should be `df2e48ad8432a863bdc0a939108d37a69f4bea4e` 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo make ap-elf` to generate aggchain program elf from sources 4. Compute vkey hash bytes of the generated `crates/aggchain-proof-program/elf/riscv32im-succinct-zkvm-elf` using SP1 toolchain, e.g. by this simple rust script: ``` use sp1_sdk::{HashableKey, Prover, CpuProver}; fn main() { let elf_path = std::env::args().nth(1).expect("Provide elf_path"); let elf_bytes = std::fs::read(&elf_path).expect("File read error"); let prover = CpuProver::new(); let (_pk, vkey) = Prover::setup(&prover, &elf_bytes); let comm = vkey.hash_bytes(); let hex: String = comm.iter(). map(|b| format!("{:02x}", b)).collect(); println!("0x{}", hex); } ``` ### Aggchain program of agglayer v1.9.2 Verifies state transition of an Agglayer-based chain either by checking a full validity proof or just by checking a registered sequencer signature. Also checks that L1 information on the chain aligns with the values stored on Agglayer. - Hash: `0x7767a8330ce68dac35265ba15d9eec6722b943cf00dc3b733779e1ae55696f70` - Repository: https://github.com/agglayer/provers/tree/v1.9.2/crates/aggchain-proof-program - Verification: successful - Used in: [Katana](https://l2beat.com/layer2s/projects/katana) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install sp1 toolchain: `curl -L https://sp1up.succinct.xyz/ | bash`, then `sp1up` 3. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) Verify: 1. Checkout the correct branch in [provers repo](https://github.com/agglayer/provers): `git checkout v1.9.2`. Commit hash should be `191952ce5551badd578063e475f9a4f3c5a9b0f4`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo make ap-elf` to generate aggchain program elf from sources 4. Compute vkey hash bytes of the generated `crates/aggchain-proof-program/target/elf-compilation/docker/riscv32im-succinct-zkvm-elf/release/aggchain-proof-program` using SP1 toolchain, e.g. by this simple rust script: ``` use sp1_sdk::{HashableKey, Prover, CpuProver}; fn main() { let elf_path = std::env::args().nth(1).expect("Provide elf_path"); let elf_bytes = std::fs::read(&elf_path).expect("File read error"); let prover = CpuProver::new(); let (_pk, vkey) = Prover::setup(&prover, &elf_bytes); let comm = vkey.hash_bytes(); let hex: String = comm.iter(). map(|b| format!("{:02x}", b)).collect(); println!("0x{}", hex); } ``` ### Aggchain program of agglayer v2.0.0 Verifies state transition of an Agglayer-based chain either by checking a full validity proof or just by checking a registered sequencer signature. Also checks that L1 information on the chain aligns with the values stored on Agglayer. - Hash: `0x679bc13716cdb49416a9ca9e297b10d76390df2c343690d4172676c207517915` - Repository: https://github.com/agglayer/provers/tree/v2.0.0/crates/aggchain-proof-program - Verification: successful - Used in: [Katana](https://l2beat.com/layer2s/projects/katana) #### Verification steps Prepare: 1. Install cargo make: `cargo install --debug --locked cargo-make` 2. Install docker [https://docs.docker.com/get-started/get-docker/](https://docs.docker.com/get-started/get-docker/) 3. Install pkg-config and OpenSSL development headers, e.g. on Debian/Ubuntu: `sudo apt-get install pkg-config libssl-dev` 4. Install protobuf compiler, e.g. on Debian/Ubuntu: `sudo apt-get install protobuf-compiler`. Make sure `protoc --version` works. Verify: 1. Checkout the correct branch in [provers repo](https://github.com/agglayer/provers): `git checkout v2.0.0`. Commit hash should be `5c51190e0c0edd1ee9ba8bc4383bd74f361760e7`. 2. Make sure docker is running by running `docker ps` 3. From the root dir: `cargo make ap-elf` to generate aggchain program elf from sources. The generated ELF should be at `crates/aggchain-proof-program/target/elf-compilation/docker/riscv64im-succinct-zkvm-elf/release/aggchain-proof-program`. 4. From the root dir: `cargo run -p aggkit-prover -- vkey` to compute vkey hash bytes for the aggchain program. This should print `0x679bc13716cdb49416a9ca9e297b10d76390df2c343690d4172676c207517915`. Note: `cargo prove vkey --elf ` prints a different SP1 vkey representation for this program, not the `hash_bytes()` program hash used here.