# Stwo Markdown version of https://l2beat.com/zk-catalog/stwo ## Summary - Creator: Starkware - Total Value Secured: $521.30 M (+8.06% compared to seven days ago) - Trusted setups for Stwo (STARK): - Transparent setup, risk N/A (no trusted setup) per the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381): No trusted setup and no additional setup-related trust assumptions. - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet), [Paradex](https://l2beat.com/layer2s/projects/paradex) - Verifiers: 1 successful - zkVM: Stwo (STARK), Cairo ASM (ISA), Mersenne31 (Field) ### About Stwo is a circle STARK optimized for proving performance, representing the next generation of Starkware prover after Stone. ### Links - Docs: https://zksecurity.github.io/stwo-book/introduction.html - Repository: https://github.com/starkware-libs/stwo?tab=readme-ov-file, https://github.com/starkware-libs/stwo-cairo, https://github.com/keep-starknet-strange/awesome-stwo - Social: https://x.com/StarkWareLtd ## Value Secured The interactive TVS chart is shown on [the HTML page](https://l2beat.com/zk-catalog/stwo#tvs). ## Proof System ### Description Stwo is the next iteration of Starkware zkVM STARK system. It is intended to prove the execution of programs written in [Cairo language](https://www.starknet.io/cairo-book/title-page.html) and compiled into Cairo assembly (cASM) byte code, however it also allows writing custom AIR to be proven. Stwo verifies STARK proofs directly onchain without any final SNARK wraps and thus requires no trusted setup. Stwo targets 96 bits of cryptographic security + 30 bits of PoW grinding security (e.g. see constructor params on [this contract](https://etherscan.io/address/0x3d57526c1C8D63fa2A8704487Df65e9000166c8E#code)). Here PoW grinding refers to a challenge that prover needs to compute every time they generate a proof. An honest prover performs the work only once but a malicious prover has additional computational load with every attempted forging of a proof. ### Proof system Stwo proof system is a zkVM working with AIR arithmetizations over Mersenne31 field. [This stwo-cairo toolkit](https://github.com/starkware-libs/stwo-cairo/tree/main) allows compiling Cairo program traces to the AIR arithmetization, however it is possible to create custom AIRs to be proven by Stwo, see more [here](https://zksecurity.github.io/stwo-book/air-development/index.html). Stwo offers several innovations to optimize proving time. Firstly, its use of small Mersenne31 field compared to previous version [felt252 field](https://docs.starknet.io/archive/cairo-101/felt/) is much better aligned with CPU arithmetics, also operations over M31 could be highly optimized as explained [here](https://zksecurity.github.io/stwo-book/how-it-works/mersenne-prime.html). Secondly, Stwo implements a circle STARK as introduced in [this paper](https://eprint.iacr.org/2024/278). Thirdly, Stwo prover now uses Blake2 hash function instead of Poseidon, which is more efficient. #### Circle STARKs Circle STARKs replace interpolation domain without any structure with an interpolation domain with a structure of a circle domain, where points of interpolation are chosen from a complex unit circle over Mersenne31 field. It allows using Circle FFT algorithm, which speeds up the interpolation step in STARK proving, as well as Circle FRI algorithm for low-degree polynomial testing. #### StarkNet Operating System (SNOS) The base layer of Stwo proving L2s is a Cairo program called [SNOS](https://docs.starknet.io/architecture/os/) that proves the correct STF from one state to another given the list of transactions. SNOS execution includes checking transaction inputs (e.g. state), executing transactions and processing state diffs. The source code of the Starknet OS can be foundĀ [here](https://github.com/starkware-libs/cairo-lang/tree/ee7ce74e1159a349d4b77a5f952241b50b1692de/src/starkware/starknet/core/os). #### Recursive aggregation Proofs of SNOS executions of several consecutive blocks are recursively aggregated. The correctness of this aggregation is checked by [applicative bootloader](https://github.com/starkware-libs/cairo-lang/blob/8e11b8cc65ae1d0959328b1b4a40b92df8b58595/src/starkware/cairo/bootloaders/applicative_bootloader/applicative_bootloader.cairo#L15) program, which also verifies the correct relation of corresponding SNOS inputs and outputs. Applicative bootloader proofs are aggregated across several blockchains and proven by [SHARP](https://docs.starknet.io/architecture/sharp/#what_is_sharp). The SHARP STARK proof is verified onchain without any SNARK wraps. ### Trusted setup Stwo is a STARK (transparent SNARK) that does not perform a wrap in a SNARK, so it does not require any trusted setup. ## Trusted Setups Risk levels follow the [Trusted Setups Risk Framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). Yellow (medium risk): all contributions are published and the final output can be verified, the ceremony client is open source, there were at least 30 contributions, participation was open to the public and announced, and participants are publicly identified. Green (lowest risk): everything required for yellow, with at least 150 contributions. Red (highest risk): at least one requirement for yellow is not met. N/A: the proof system needs no trusted setup. ### Transparent setup - Risk: N/A (no trusted setup) - Proof systems: Stwo (STARK) Transparent proving systems require no trusted setups and have no additional setup-related trust assumptions. ## Verifier IDs List of different onchain verifiers for this proving system. Unique ID distinguishes different deployments of the same verifier from different verifiers (e.g. different versions). ### STARK: Stwo State of the art implementation of Circle STARK zkVM, created by Starkware to prove Cairo programs, including state transition of Starknet. #### Stwo GPS statement verifier 2026_13_4 Custom verifier ID: SHA256 hash of the address of the immutable GPS statement verifier in hex string format '0x...'. - Verifier ID: `0x243611f51b76871574612cc0f140acb660c684a66b74e37b7547474c6683659a` - Source: https://etherscan.io/address/0x4956bda1d23F75B988644329c5B06BD1494a72b6#code - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet), [Paradex](https://l2beat.com/layer2s/projects/paradex) **Known deployments** - [0x4956bda1d23F75B988644329c5B06BD1494a72b6](https://etherscan.io/address/0x4956bda1d23F75B988644329c5B06BD1494a72b6#code) on Ethereum, used in: [Starknet](https://l2beat.com/layer2s/projects/starknet), [Paradex](https://l2beat.com/layer2s/projects/paradex) ##### Verification steps The immutable Solidity sources are verified on Etherscan and expose every selected CPU verifier, memory-page registry, outer bootloader contract, and bootloader configuration word. Source verification of the Solidity contracts does not by itself reproduce the Cairo programs hidden behind the recursive-verifier allowlist commitment. ## Program Hashes List of known guest zkVM programs used by this prover. Each program represents a piece of offchain execution that is verified onchain. The program hash serves as the program's unique identifier. ### Outer bootloader Cairo program StarkWare_GpsStatementVerifier_2026_13 Top-level Cairo program executed by SHARP. - Hash: `3427958597398434235135013788958741576989752718219267963615783564775551242024` - Repository: https://github.com/starkware-libs/cairo-lang/tree/56407b69f3f19f69302a8623baa8c5f71f967eed/src/starkware/cairo/bootloaders/bootloader - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet), [Paradex](https://l2beat.com/layer2s/projects/paradex), [Sorare](https://l2beat.com/layer2s/projects/sorare), [edgeX v1](https://l2beat.com/layer2s/projects/edgex), [tanX](https://l2beat.com/layer2s/projects/tanx), [Myria](https://l2beat.com/layer2s/projects/myria) #### Verification steps These steps reproduce the current 1,166-felt SHARP outer bootloader on Linux. Dependencies: Git, Bazelisk configured to use Bazel 7.4.1, JDK 21, GMP development headers, Python 3, and Foundry `cast`. 1. Check out the exact public source revision: ```bash git clone https://github.com/starkware-libs/cairo-lang.git cd cairo-lang git checkout 56407b69f3f19f69302a8623baa8c5f71f967eed ``` The Cairo compiler version at this revision is `0.15.0a0`. The entrypoint is `src/starkware/cairo/bootloaders/bootloader/bootloader.cairo`. 2. Build the official proof-mode target: ```bash USE_BAZEL_VERSION=7.4.1 bazelisk build \ //src/starkware/cairo/bootloaders/bootloader:bootloader_program ``` The destination for the compiled program will be printed by the build script, the instruction array will be in the `"data"` json field in hex format. The target uses `--proof_mode --debug_info_with_source`. 3. Check that the compiled instruction array is identical to the one pinned by the immutable Ethereum contract at `0x24105e6697AdD9B4B1BDE04079a91BDFCCa24A47`, which could be fetched by calling: ```bash cast call 0x24105e6697AdD9B4B1BDE04079a91BDFCCa24A47 \ 'getCompiledProgram()(uint256[1166])' \ --rpc-url "$ETHEREUM_RPC_URL" \ --json > /tmp/sharp_outer_bootloader_onchain.json ``` ### Supported simple bootloader programs commitment StarkWare_GpsStatementVerifier_2026_13 Pedersen commitment to the ordered list of accepted simple-bootloader executable hashes. - Hash: `3442855748187296636739564186904728563385971901122957091055928358173521721079` - Repository: https://github.com/starkware-libs/cairo-lang/tree/1c5dace6fbd1dc9d1ae2eb878dc1dd85f23512ab/src/starkware/cairo/bootloaders/simple_bootloader - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet), [Paradex](https://l2beat.com/layer2s/projects/paradex), [Sorare](https://l2beat.com/layer2s/projects/sorare), [edgeX v1](https://l2beat.com/layer2s/projects/edgex), [tanX](https://l2beat.com/layer2s/projects/tanx), [Myria](https://l2beat.com/layer2s/projects/myria) #### Verification steps The steps below are supposed to be run on linux OS. They could also be run on macOS, but several tweaks need to be made: update from `lru-dict==1.1.8` to `lru-dict==1.3.0` in `scripts/requirements.txt` and update `python_interpreter` in `bazel_utils/python/stub.sh` to the correct location. 1. Install [bazel](https://bazel.build) version 7.4.1 and `gmp` library using [brew](https://brew.sh): ``` brew install bazelisk USE_BAZEL_VERSION=7.4.1 bazelisk version brew install gmp # or sudo apt-get install libgmp-dev ``` 2. On linux, install JDK if you don't have it: `sudo apt install openjdk-21-jre`. 3. Check out the correct commit of repo: ``` git clone https://github.com/starkware-libs/cairo-lang.git cd cairo-lang git checkout 1c5dace6fbd1dc9d1ae2eb878dc1dd85f23512ab ``` 4. Update `cairo-lang/src/starkware/cairo/bootloaders/BUILD` file by appending [this snippet](https://l2beat.com/files/starkware_proghash_artifacts/56407b69f3f19f69302a8623baa8c5f71f967eed/BUILD_ADDITION) at the end. 5. Copy [this hash_bootloaders.py script](https://l2beat.com/files/starkware_proghash_artifacts/1c5dace6fbd1dc9d1ae2eb878dc1dd85f23512ab/hash_bootloaders.py) that computes bootloader hashes into `cairo-lang/src/starkware/cairo/bootloaders/`. 6. Execute the script above by `USE_BAZEL_VERSION=7.4.1 bazel run //src/starkware/cairo/bootloaders:cairo_hash_bootloaders_exe`. The output of the script should contain the correct hash. ### Applicative bootloader Cairo program StarkWare_GpsStatementVerifier_2026_13 Runs an aggregator program, checks that its input matches the recursively unpacked task outputs, and relabels the resulting fact with the domain-separated aggregator program hash. - Hash: `2358844945297786488640123814540854423585455959362109345448922524567546993330` - Repository: https://github.com/starkware-libs/cairo-lang/tree/1c5dace6fbd1dc9d1ae2eb878dc1dd85f23512ab/src/starkware/cairo/bootloaders/applicative_bootloader - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet), [Paradex](https://l2beat.com/layer2s/projects/paradex), [Sorare](https://l2beat.com/layer2s/projects/sorare), [edgeX v1](https://l2beat.com/layer2s/projects/edgex), [tanX](https://l2beat.com/layer2s/projects/tanx), [Myria](https://l2beat.com/layer2s/projects/myria) #### Verification steps The steps below are supposed to be run on linux OS. They could also be run on macOS, but several tweaks need to be made: update from `lru-dict==1.1.8` to `lru-dict==1.3.0` in `scripts/requirements.txt` and update `python_interpreter` in `bazel_utils/python/stub.sh` to the correct location. 1. Install [bazel](https://bazel.build) version 7.4.1 and `gmp` library using [brew](https://brew.sh): ``` brew install bazelisk USE_BAZEL_VERSION=7.4.1 bazelisk version brew install gmp # or sudo apt-get install libgmp-dev ``` 2. On linux, install JDK if you don't have it: `sudo apt install openjdk-21-jre`. 3. Check out the correct commit of repo: ``` git clone https://github.com/starkware-libs/cairo-lang.git cd cairo-lang git checkout 1c5dace6fbd1dc9d1ae2eb878dc1dd85f23512ab ``` 4. Update `cairo-lang/src/starkware/cairo/bootloaders/BUILD` file by appending [this snippet](https://l2beat.com/files/starkware_proghash_artifacts/56407b69f3f19f69302a8623baa8c5f71f967eed/BUILD_ADDITION) at the end. 5. Copy [this hash_bootloaders.py script](https://l2beat.com/files/starkware_proghash_artifacts/1c5dace6fbd1dc9d1ae2eb878dc1dd85f23512ab/hash_bootloaders.py) that computes bootloader hashes into `cairo-lang/src/starkware/cairo/bootloaders/`. 6. Execute the script above by `USE_BAZEL_VERSION=7.4.1 bazel run //src/starkware/cairo/bootloaders:cairo_hash_bootloaders_exe`. The output of the script should contain the correct hash. ### Supported recursive Cairo verifier programs commitment StarkWare_GpsStatementVerifier_2026_13_4 Pedersen commitment to the ordered allowlist of Cairo programs that may recursively verify and unpack nested SHARP proofs. - Hash: `2549868507195840500193135872505150687001846773665388230794631345999578394351` - Repository: https://github.com/starkware-libs/cairo-lang/blob/cf9bf972bede402a125e8638bb258e77563ae933/src/starkware/cairo/bootloaders/bootloader/supported_program_hashes.json - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet), [Paradex](https://l2beat.com/layer2s/projects/paradex), [Sorare](https://l2beat.com/layer2s/projects/sorare), [edgeX v1](https://l2beat.com/layer2s/projects/edgex), [tanX](https://l2beat.com/layer2s/projects/tanx), [Myria](https://l2beat.com/layer2s/projects/myria) #### Verification steps This value is not a hash of a single program. It is a Pedersen hash chain committing to the ordered 30-entry `supported_cairo_verifier_program_hashes` list from [supported_program_hashes.json](https://github.com/starkware-libs/cairo-lang/blob/cf9bf972bede402a125e8638bb258e77563ae933/src/starkware/cairo/bootloaders/bootloader/supported_program_hashes.json) at cairo-lang `cf9bf972bede402a125e8638bb258e77563ae933` (v0.14.3). The list contains the program hashes of all Cairo verifier programs that the SHARP bootloader accepts for recursive proof verification: - 21 entries are Stone Cairo verifiers built from the same cairo-lang commit: 7 layouts (`dex`, `recursive`, `small`, `starknet`, `starknet_with_keccak`, `dynamic`, `recursive_with_poseidon`), each hashed with the pedersen (entries 1-7), poseidon (11-17) and blake (21-27) program hash function. - 9 entries are Stwo Cairo verifiers built from [stwo-cairo](https://github.com/starkware-libs/stwo-cairo/tree/sharp-7.4.RC3) at tag `sharp-7.4.RC3` (commit `9b93cc39c87838cee3132ee1f8237590700f0689`): 3 feature builds (`poseidon252_verifier` with poseidon output packing, `qm31_opcode` with poseidon output packing, `qm31_opcode` with blake output packing), each hashed with pedersen (entries 8-10), poseidon (18-20) and blake (28-30). 1. Reproduce the 21 Stone verifier hashes following [these steps](https://l2beat.com/files/starkware_proghash_artifacts/cf9bf972bede402a125e8638bb258e77563ae933/stone_verifier_steps.md). 2. Reproduce the 9 Stwo verifier hashes following [these steps](https://l2beat.com/files/starkware_proghash_artifacts/cf9bf972bede402a125e8638bb258e77563ae933/stwo_verifier_steps.md). You will need [this stwo_features.patch](https://l2beat.com/files/starkware_proghash_artifacts/cf9bf972bede402a125e8638bb258e77563ae933/stwo_features.patch) and [this hash_stwo_verifiers.py helper script](https://l2beat.com/files/starkware_proghash_artifacts/cf9bf972bede402a125e8638bb258e77563ae933/hash_stwo_verifiers.py). 3. From the cairo-lang checkout, using a python 3.9 environment with `scripts/requirements.txt` installed, compute the commitment to the now-verified list: ``` PYTHONPATH=src python -c " import json from starkware.cairo.common.hash_state import compute_hash_on_elements doc = json.load(open('src/starkware/cairo/ bootloaders/bootloader/supported_program_hashes.json')) print(compute_hash_on_elements([int(h, 16) for h in doc['supported_cairo_verifier_program_hashes']])) " ``` The output should be the program hash. ### Starknet OS Proves correct state transition for a range of consecutive Starknet transactions. - Hash: `2733003247060056328192560178934419513655729851806095615814023997114795707702` - Repository: https://github.com/starkware-libs/sequencer/blob/c294a8ba263834d45cf525217d8700f5de24a260/crates/apollo_starknet_os_program/src/cairo/starkware/starknet/core/os/os.cairo#L69 - Verification: successful - Used in: [Paradex](https://l2beat.com/layer2s/projects/paradex) #### Verification steps 1. Install python and pip. 2. Install rust: `curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh`. 3. Checkout the correct version of [https://github.com/starkware-libs/sequencer/tree/main](https://github.com/starkware-libs/sequencer/tree/main): `git checkout c294a8ba263834d45cf525217d8700f5de24a260`. 4. Install required python dependencies: `python3 -m venv sequencer_venv`, then `. sequencer_venv/bin/activate && pip install -r scripts/requirements.txt`. 5. Run `UPDATE_EXPECT=1 cargo test -p apollo_starknet_os_program test_program_hashes` to regenerate program hashes in `crates/apollo_starknet_os_program/src/program_hash.json`. The `"os"` value of this file will be equivalent to dec value of the hash. ### Aggregation program for SHARP prover Aggregates proofs of correct execution for several consecutive transaction ranges generated by Starknet OS. - Hash: `2571508110958925737463010241874806654058743535666147712534445437599630018294` - Repository: https://github.com/starkware-libs/sequencer/blob/c294a8ba263834d45cf525217d8700f5de24a260/crates/apollo_starknet_os_program/src/cairo/starkware/starknet/core/aggregator/main.cairo#L15 - Verification: successful - Used in: [Paradex](https://l2beat.com/layer2s/projects/paradex) #### Verification steps 1. Install python and pip. 2. Install rust: `curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh`. 3. Checkout the correct version of [https://github.com/starkware-libs/sequencer/tree/main](https://github.com/starkware-libs/sequencer/tree/main): `git checkout c294a8ba263834d45cf525217d8700f5de24a260`. 4. Install required python dependencies: `python3 -m venv sequencer_venv`, then `. sequencer_venv/bin/activate && pip install -r scripts/requirements.txt`. 5. Run `UPDATE_EXPECT=1 cargo test -p apollo_starknet_os_program test_program_hashes` to regenerate program hashes in `crates/apollo_starknet_os_program/src/program_hash.json`. The `"aggregator_with_prefix"` value of this file will be equivalent to dec value of the hash. ### Starknet OS Proves correct state transition for a range of consecutive Starknet transactions. - Hash: `2006389624453304912912750132846114593020263069652857561377702883656839453432` - Repository: https://github.com/starkware-libs/sequencer/tree/APOLLO-0.14.3-RC.11/crates/apollo_starknet_os_program/src/cairo/starkware/starknet/core/os - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet) #### Verification steps 1. Install python and pip. 2. Install rust: `curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh`. 3. Checkout the correct version of [https://github.com/starkware-libs/sequencer/tree/main](https://github.com/starkware-libs/sequencer/tree/main): `git checkout APOLLO-0.14.3-RC.11`. Commit hash should be `5114457ad4b5d6d1764b520dfa40b9e826f48854`. 4. Install required python dependencies: `python3 -m venv sequencer_venv`, then `. sequencer_venv/bin/activate && pip install -r scripts/requirements.txt`. 5. Run `UPDATE_EXPECT=1 cargo test -p apollo_starknet_os_program test_program_hashes` to regenerate program hashes in `crates/apollo_starknet_os_program/src/program_hash.json`. The `"os"` value of this file will be equivalent to dec value of the hash. ### Aggregation program for SHARP prover Aggregates proofs of correct execution for several consecutive transaction ranges generated by Starknet OS. - Hash: `1050253032170513549151251823521174837478197699740478552102884446098263561922` - Repository: https://github.com/starkware-libs/sequencer/tree/APOLLO-0.14.3-RC.11/crates/apollo_starknet_os_program/src/cairo/starkware/starknet/core/aggregator - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet) #### Verification steps 1. Install python and pip. 2. Install rust: `curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh`. 3. Checkout the correct version of [https://github.com/starkware-libs/sequencer/tree/main](https://github.com/starkware-libs/sequencer/tree/main): `git checkout APOLLO-0.14.3-RC.11`. Commit hash should be `5114457ad4b5d6d1764b520dfa40b9e826f48854`. 4. Install required python dependencies: `python3 -m venv sequencer_venv`, then `. sequencer_venv/bin/activate && pip install -r scripts/requirements.txt`. 5. Run `UPDATE_EXPECT=1 cargo test -p apollo_starknet_os_program test_program_hashes` to regenerate program hashes in `crates/apollo_starknet_os_program/src/program_hash.json`. The `"aggregator_with_prefix"` value of this file will be equivalent to dec value of the hash. ### Virtual Starknet OS Proves correct execution of a single Starknet transaction against a recent finalized block, used for client-side proving (e.g. STRK-20 privacy pool actions). The Starknet OS only accepts client proof facts whose program hash is in its hardcoded allowlist, which contains exactly this hash. - Hash: `2373625305120835200243020426311988160128377108314438505880592663683179928225` - Repository: https://github.com/starkware-libs/sequencer/tree/APOLLO-0.14.3-RC.11/crates/apollo_starknet_os_program/src/cairo/starkware/starknet/core/os - Verification: successful - Used in: [Starknet](https://l2beat.com/layer2s/projects/starknet) #### Verification steps 1. Install python and pip. 2. Install rust: `curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh`. 3. Checkout the correct version of [https://github.com/starkware-libs/sequencer/tree/main](https://github.com/starkware-libs/sequencer/tree/main): `git checkout APOLLO-0.14.3-RC.11`. Commit hash should be `5114457ad4b5d6d1764b520dfa40b9e826f48854`. 4. Install required python dependencies: `python3 -m venv sequencer_venv`, then `. sequencer_venv/bin/activate && pip install -r scripts/requirements.txt`. 5. Run `UPDATE_EXPECT=1 cargo test -p apollo_starknet_os_program test_program_hashes` to regenerate program hashes in `crates/apollo_starknet_os_program/src/program_hash.json`. This compiles the `virtual_os` program from the in-tree Cairo sources (the `__virtual.cairo` file variants of the Starknet OS) and the `"virtual_os"` value of this file will be equivalent to this hash. If the build fails because `sccache` is not installed, prefix the command with `RUSTC_WRAPPER=""`. 6. To check that this hash is enforced by the L1-registered Starknet OS, confirm it equals `ALLOWED_VIRTUAL_OS_PROGRAM_HASHES_0` in `crates/apollo_starknet_os_program/src/cairo/starkware/starknet/core/os/constants.cairo` (the allowlist has length 1 at this tag). The Starknet OS only accepts client-side proof facts whose program hash is in this allowlist.